A note on method before we start: everything below comes from the engines’ own published policies as we read them in August 2026. Policies change — sometimes quietly — so treat this as a snapshot, and check the source documents if a detail matters to you. We’ll quote sparingly and characterize fairly. The point isn’t that any of this is secret; it’s that almost nobody reads it.
PimEyes: opting out costs you an ID
PimEyes’ policy is unusually candid about what the index actually is: it describes collecting “fingerprints of faces found on the Internet” — their word for faceprints, harvested from public pages. Photos you upload to run a search are cached for up to 30 days. Opt-out requests get processed within 96 hours, which is genuinely fast for this industry.
The part most people don’t expect: to get out of the index, you submit a photo of yourself and an anonymized scan of your government ID. To stop a company from processing your face, you send it your face and your papers. There’s a defensible logic (they need to verify you’re removing yourself, not someone else) — but the asymmetry is striking: getting in required nothing from you at all.
Also notable: PimEyes states it “does not offer any services in Illinois”. Remember that detail — Illinois comes up again.
FaceCheck.ID: the engine that says it isn’t biometric
FaceCheck’s policy contains the most philosophically bold sentence of the five. A search engine whose entire product is finding faces states that it “does not create, store, or process biometric data” used for identifying individuals. How? Definitionally: it describes its matching as “similarity analysis” of “visual patterns” producing “non-invertible visual descriptors” — not facial recognition, not identification, and therefore — the argument goes — not biometric data at all.
If that move sounds familiar, it should: it’s the same definitional argument we covered when Meta insisted “bone structure analysis” isn’t facial recognition. Whether a court would agree that a face-matching index contains no biometric data is, to put it gently, an open question — biometric statutes tend to define the category by what the data does, not what the company calls it.
Credit where due: the policy also makes commitments most engines don’t — no IP logging, uploaded photos deleted after 24 hours, no third-party analytics trackers, an instant takedown form, and a stated policy of not indexing children’s faces. Whatever you make of the biometric argument, those are real, checkable commitments in writing.
Clearview AI: the privacy policy behind a login
Here’s one we didn’t expect to write: we couldn’t fully read Clearview’s privacy policy, because the complete document sits behind a sign-in to their platform. The public-facing page offers navigation, a slogan — “search, not surveillance” — and a link that asks you to log in to read the rest. A privacy policy you must create an account to read is a genre unto itself.
What is public is the rights-request page, and its structure tells its own story: a state-by-state patchwork. Residents of eleven US states get the full request suite (access, deletion, correction, opt-out). Utah residents get a shorter menu. Illinois residents get their own dedicated opt-out form — the fingerprints of a certain biometric statute are all over that. And if you live anywhere else, or outside the United States? The page lists nothing for you.
Your rights against the most famous face-scraper on earth depend, quite literally, on your mailing address.
ClarityCheck: the lookup site that pings your phone
ClarityCheck — a Delaware company offering people lookups with reverse image search — has the most modern-looking policy of the five, GDPR-structured and unusually specific. Which makes its casual admissions all the more striking: the policy describes using “OSINT techniques” and real-time HLR lookups. An HLR lookup is a live query against the phone network itself — the kind of tooling you’d associate with investigators, described matter-of-factly in the fine print of a consumer website.
Then there’s the tracking detail: email tracking is active by default — except for recipients in France and Italy, where regulators require consent first. Read that again: the same company, the same emails, but whether you get asked depends on whether your country’s enforcer has been aggressive about it. Nothing in these documents maps the limits of goodwill quite like a carve-out for exactly two countries.
Fair credits, because the policy earns some: uploaded search images are deleted within 7 days and not used for advertising, cached reports auto-delete after 120 days, and erasure requests create standing “suppression records” so you don’t quietly reappear in their results — which is more honest about re-appearance than most of this industry manages.
Social Catfish: the quiet part, in writing
Social Catfish is a people-search service with reverse image search bolted on, and its policy is the most bluntly honest of the five — because US state privacy laws now force disclosure tables. For category after category of licensed and scraped data — names, aliases, profile images, past addresses, phone numbers, age, gender, job history — the policy repeats one sentence: it has “disclosed and sold this information since January 01, 2022”.
Sold to whom? To its own customers — the people running searches. That’s the part worth sitting with: when a people-search site says “we don’t sell your data to third parties,” the sale you should worry about is the product itself. Every search result is the transaction. Your profile isn’t leaked to the highest bidder; it’s retailed, one lookup at a time.
Fairness notes: images uploaded by searchers are used only for the search and aren’t sold, and the company voluntarily extends privacy-request rights to residents of all US states, not just the legally required ones. Both are better than the industry floor.
What five policies teach you: the three dodges
Read side by side, the five documents keep reaching for the same three moves:
- The definition dodge. “It’s not biometric data, it’s similarity analysis.” “It’s search, not surveillance.” If the category has legal consequences, redefine yourself out of the category. The data does exactly what it did before the renaming.
- The geography dodge. No service in Illinois. No People search in the EEA, UK, or Illinois. A dedicated Illinois form. Nothing so precisely maps where biometric law works as the list of places face-search engines refuse to operate. Strong law doesn’t make the products safer — it makes them leave.
- The defaults dodge. Protections switch on only where a regulator forces them. Consent-first email tracking for exactly two countries; rights-request forms for exactly eleven states; no service in exactly one. The privacy you get is a function of the privacy your legislature demanded — goodwill covers the remainder thinly.
None of this means opt-outs are pointless — the opposite. These documents are legally binding commitments, and the opt-out processes in them are real and usable. It means the fine print rewards reading, the processes differ wildly engine to engine, and each one has its own forms, its own verification demands, and its own timelines. That’s doable once. The engines re-crawl, though — which is why we treat removal as maintenance, not a one-time errand.
We read the fine print for a living.
FacePrivacy files opt-out requests with the major face-search engines — each through its own process — and works to keep you out as they re-crawl. You skip the forms, the ID hoops, and the re-filing.
Protect your face →