Website broken or underperforming? Rescue packages from RM199 / S$99.
Resources

Build Notes

What AI photo restoration can fix — and what it can get wrong

What AI restoration repaired reliably on our own damaged family photos, where it altered identity or invented detail, and the limits we accepted before releasing a public beta.

Shane Hau 12 min readPublished 3 August 2026Updated 8 September 2026

That difference decides how a restored photo should be used. Damage repair is usually safe to accept and share. Reconstructed identity detail should be treated as an interpretation: keep the original file, compare the two side by side at full size, and check the face before printing, framing or sending a result to family. If a photograph is the only surviving record of someone, prefer a conservative result over a sharper one.

The rest of this article is the first-party evidence behind that conclusion. Memory Haus is our own public-beta restoration product, so every ACCEPT, CAUTION and REJECT example below comes from photographs we tested ourselves, alongside the privacy, payment and capability limits we chose to publish rather than hide.

1. A simple first attempt at family-photo repair

Fading, scratches and creases can make family photos difficult to view and share. Memory Haus tests a narrow consumer workflow: upload, generate, compare and download. The original photograph must remain the source of truth because a generative result can reconstruct historically incorrect detail.

Talk To Ah Ma explores heritage-language connection through a generated virtual-grandmother conversation with Singapore Hokkien, Mandarin translation and pronunciation help. It generates new persona-style replies; it does not retrieve a real relative's voice, memories or identity.

2. Bound the restoration flow

  • Accept only supported JPEG, PNG and WebP uploads within the current size limit.
  • Reject arbitrary external image URLs and reserve a free use or paid credit before the model call.
  • Ask the third-party model to repair damage without modernising, beautifying or changing identity-related details.
  • Return the generated result for browser comparison and download.
  • Confirm the reservation on success and attempt a refund after a failed run.

3. Accountless does not mean stateless

The browser holds an opaque wallet identifier and a one-time recovery code until it is acknowledged. Server state tracks balance, recovery-code hash, daily usage, orders and credit transactions. Losing both browser state and the recovery code can make cross-device recovery impractical, and the recovery code should be treated as a secret.

4. Payment verification is manual

A purchase creates a pending internal order and sends the user to a hosted PayPal payment link. The user then submits a transaction ID; credits remain pending until an operator verifies and approves it. This is not webhook-confirmed automatic fulfilment, and operator delay or error is possible. This article intentionally omits exact pack prices because product surfaces must remain the current source of truth.

5. Explain uploaded-photo processing precisely

The reviewed wallet data does not store originals or results, but the restoration request passes through the Memory Haus server and uploads the photo to a third-party processor before the result returns. That is not proof of instant deletion, zero retention or no infrastructure metadata. Users should avoid highly sensitive material and keep the original file.

6. Real-photo evidence: three difficult before/after pairs

These are Founder-approved original files and their supplied Memory Haus outputs, published without beautifying, manual retouching, cropping-away damage or substitution. This deliberately difficult qualitative sample is not a benchmark, accuracy rate or success-rate claim. Generated or inferred detail is not verified historical detail.

Review criterionVisible disposition
Damage removal; structure and identity preservation; invented-detail risk; artifactsACCEPT, CAUTION or REJECT — with failures as visible as successful outputs

MH-E1 — ACCEPT, with a generative-restoration caveat

Original MH-E1 damaged family portrait with dense scratches, cracks, stains and edge damage.
MH-E1 original, Founder-approved first-party evidence. It establishes the visible source damage; it does not establish personal identities, dates or any detail later inferred by a model.
Exact supplied Memory Haus MH-E1 restoration output, showing a cleaned three-person family portrait.
MH-E1 output, reviewed 25 August 2026 — ACCEPT. Damage removal and overall structure are strong, and identity preservation is visually plausible against the visible source. Fine facial, clothing, furniture and background detail obscured by damage is inferred/generated, not verified historical fact. Output SHA-256: c05151901004440eb2828ff09237c51742a92c9c7c8ffc2dfb05ba3b73cc1aa5.

MH-E2 — CAUTION

Original MH-E2 damaged four-person family portrait with severe peeling, surface loss and large missing regions.
MH-E2 original, Founder-supplied first-party evidence. The visible missing regions mean a clean result cannot prove historical fidelity.
Supplied Memory Haus MH-E2 restoration output showing a cleaned four-person portrait.
MH-E2 output, reviewed 25 August 2026 — CAUTION. Visual cleanup and core composition are strong, but extensive missing source regions require material inference; a clean appearance is not proof of historical accuracy. The Founder source files were independently verified against the locked hashes; these repository copies passed through the task attachment pipeline and are published as visual/qualitative first-party evidence, not cryptographic file identity.

MH-E3 — REJECT

Original MH-E3 low-detail family portrait with folds and tears crossing faces.
MH-E3 original, Founder-approved first-party evidence. The face-crossing damage and low detail leave too little reliable source information for a faithful reconstruction.
Exact supplied Memory Haus MH-E3 restoration output, showing a polished but substantially reinterpreted family portrait.
MH-E3 output, reviewed 25 August 2026 — REJECT. Although visually polished, it substantially reinterprets faces, age/detail, clothing and background beyond the low-detail input. This is a semantic/historical fidelity failure, not merely an artifact issue. Output SHA-256: b28c63a935b2d14e4ea8e2f42cd55de2fb9dfefde9a2d3d0b818e64b1ce76a10.

7. Keep Talk To Ah Ma's fictional boundary visible

  • Replies can be inaccurate or culturally imperfect and may include invented conversational memories.
  • Recent chat context is sent to the server-side AI gateway; visible history remains in the current browser.
  • Daily limits and best-effort abuse controls involve server-side usage metadata.
  • Voice output is configuration-dependent and is not a dependable baseline feature.
  • The feature is not grief therapy, mental-health support, language certification or oral history.

8. Known limitations and operational risks

  • Restoration quality varies and identity or missing detail can change.
  • There is no verified gallery or completed broad real-photo evidence set.
  • Photos are sent to a third-party processor; effective retention and deletion timing are not established here.
  • Supported formats and upload size are bounded by the current route.
  • Wallet recovery depends on local state and a secret recovery code.
  • Payment confirmation is manual and may remain pending.
  • Talk To Ah Ma is generated fiction with usage and capability limits.
  • No paying-customer, revenue, retention or stable unit-economics evidence is claimed.

9. What we learned

The hard restoration requirement is not make it sharper; it is improve damage without rewriting identity. The accountless wallet also shows why no signup is not a complete privacy description: durable credits, recovery, orders and external processing still need explanation.

Official sources

Written by Shane Hau, founder of TS Haus Digital Solutions. Last updated 8 September 2026.