2026-08-03
Privacy
A face photo is biometric data. This page says exactly what we take, where it goes and how long we keep it.
What we hold
- Your email address and a hash of your password. We never store the password itself.
- The photo you upload, stored on our server outside any public directory.
- The report: matched page URLs, similarity scores and the thumbnails returned by the search engine.
- Payment records: amount, currency, and Stripe's identifiers. Card details go straight to Stripe and never reach our servers.
Who else sees your photo
- Running a search sends your photo to the third-party provider that operates the face-matching index. Their handling of it is governed by their own policy, and we will tell you who they are on request.
- Stripe processes the payment and receives your email address.
- Nobody else. We do not sell data, and we do not add your photo to any index.
How long we keep it
- Your photo and report stay until you delete them or close your account.
- Deleting a search removes the photo from disk and the report from the database.
- Payment records are kept as long as tax and accounting rules require.
Your rights
- You can ask for a copy of your data, correct it, or have it erased. Write to us and we will action it.
- In the EU and UK, biometric data is special category data under GDPR Art. 9 and we process it only on your explicit consent — the consent you give by uploading a photo, which you can withdraw at any time by deleting it.
Cookies
- A session cookie to keep you signed in, a language cookie for your TR/EN choice, and an anonymous id that ties a photo you upload before registering to the account you then create. None of these can be switched off — the site does not work without them.
- Google Analytics runs only if you allow it. We ask before loading it, and if you decline or ignore the question, nothing is sent to Google at all. Your searches, your reports and your photos are never included in what it measures.
- No advertising cookies, ever.