Privacy Policy
How we collect, use, and protect your data.
The FacePrivacy service is operated by UnFind LLC, a Wyoming limited liability company, doing business as (“d/b/a”) FacePrivacy. References to “FacePrivacy”, “we”, “us”, or “our” in this policy mean UnFind LLC, which is the data controller for the personal data described here. We are committed to protecting your privacy. This policy explains how we collect, use, store, and protect your personal and biometric data when you use our services.
1. Information We Collect
We collect information you provide directly: account details (email, name), identity information (legal name, photo) for removal requests, and payment information processed by our payment provider. We may also collect usage data (e.g. how you use our site) and technical data (e.g. IP address, browser type).
2. How We Use Your Information
We use your information to provide our removal service, to create and manage your account, to process payments, to communicate with you, to advertise and to measure our advertising — including through technologies that track users across other companies’ apps and websites, as described in Section 7 — and to improve our services. We use your photo and identity details only to submit removal requests to third-party databases where you have requested removal.
3. Biometric and Facial Data
The face photographs you upload (a front photo and a side-profile photo), and any biometric data derived from them, are sensitive personal information. This section explains specifically how we collect, use, store, share, and retain that data. We do not sell your biometric data, and we never use it to train any model or for advertising or analytics.
What we collect. Two self-captured photographs of your face — a front photo and a side profile — and, only when a particular facial-recognition service requires proof of identity to process a removal, a government-issued identity document (which we anonymize). We do not generate or store our own facial-recognition template (“faceprint”); the photographs are reference images.
Why we store it. We store your face photographs so that we can (1) submit opt-out and removal requests to facial-recognition search engines on your behalf, and (2) re-submit those requests on a recurring basis. Facial-recognition engines continually re-scrape the public web, so a face that has been removed can reappear; keeping your reference photograph available lets us detect that and re-file the removal for as long as you are our customer. Without the stored photograph we could not provide the ongoing, recurring removal service you subscribe to.
How long we store it, and why. We retain your face photographs for as long as you have an account with us. Keeping the reference photograph available is what lets us re-file removals when an engine re-indexes you, which is the service itself. You can have it destroyed at any time, and we act on that promptly. When you delete your account, or ask us to delete your data, we permanently delete your face photographs and any identity documents from our production systems within thirty (30) days, and encrypted backups containing them are overwritten on our normal backup-rotation cycle (no longer than thirty (30) additional days) and are not restorable after that window. You can trigger deletion yourself at any time from within the app (Settings → Account → Delete Account) or from the web dashboard.
Where it is stored. Your face photographs are stored encrypted at rest in Cloudflare R2 object storage, operated by Cloudflare, Inc. Cloudflare acts as a passive infrastructure processor under contract: it stores the encrypted data on our behalf, retains it only for as long as we retain it (it is deleted when we delete it), and does not access the content except as needed for network delivery. Cloudflare does not use your face data for its own purposes.
Which third parties we share it with, and why. We share your face photograph with two categories of third party, and no others:
- The facial-recognition search engines you ask us to remove you from — for example PimEyes, Clearview AI, FaceCheck.ID, Lenso.ai, and the others listed on our Database List. We send a reference photograph to each engine because their opt-out and removal processes require an image to identify which face to remove. We disclose only the minimum necessary to process the removal you requested.
- Cloudflare, Inc. — our hosting and storage provider, as described above, for the sole purpose of storing the data securely on our behalf.
We do not share your face data with advertisers, data brokers, analytics providers, our subscription processor (RevenueCat), or our sign-in provider (Firebase Authentication). Those parties never receive your photographs or biometric data.
Whether those third parties also store your face data, and their practices. The facial-recognition engines receive your reference photograph in order to locate and remove your face from their index. Their handling of that image is governed by each engine’s own privacy policy (linked from our Database List). In practice these engines fall into two groups: some process the reference image only transiently to perform the match and do not retain it; others retain a limited record or hash of it specifically so they can keep you suppressed — i.e. prevent your face from being re-added, which is in your interest. Where an engine retains such a record, it does so for its own stated retention period under its own privacy policy; because these are independent operators we do not control their retention, and we encourage you to review the privacy policy of any engine on our Database List for its specific storage practices. Cloudflare, as noted, stores the encrypted photographs only for as long as we do and does not access their content.
3.1 Biometric Notice, Consent, Retention and Destruction
This subsection is our written notice about biometric data, and our publicly available retention and destruction schedule. It restates, in one place, what the rest of Section 3 describes: what we collect, why, for how long, when it is destroyed, and what you have agreed to.
What biometric data we collect. Two self-captured photographs of your face — one front-facing and one side profile. Where a particular facial-recognition service will not process a removal without proof of identity, we also collect a government-issued identity document, which we anonymize. We do not generate, derive, or store a facial-recognition template or “faceprint” of our own; the photographs are held as reference images.
The specific purpose. One purpose only: to submit, and repeatedly re-submit, opt-out and removal requests to facial-recognition search engines on your behalf. Facial-recognition engines re-scrape the public web continuously, so a face that has been removed can reappear; your reference photograph is what lets us detect that and re-file. We do not use your biometric data to train any model, and we do not use it for advertising, analytics, or profiling.
How long we keep it. For as long as you have an account with us. The reference photograph is what makes a re-filing possible, so it is retained while you are a customer.
When it is destroyed. On either of these, whichever comes first:
- When you ask us to delete your data.
- When you delete your account (see Section 6.1) — which you can do yourself, at any time, from the app or the web dashboard.
In both cases destruction happens within thirty (30) days. We may also destroy it earlier on our own initiative, as described below.
Destruction means the photographs and identity documents are permanently deleted from our production systems and object storage, including any superseded copies from earlier uploads. Encrypted backups containing them are overwritten on our ordinary rotation cycle — no longer than thirty (30) additional days — after which they are not restorable.
Your consent, taken before collection. We collect no biometric data until you have given informed, affirmative electronic consent. At sign-up, before any photograph can be uploaded, you must separately tick each of the following. None is pre-ticked, and the account cannot proceed without them:
- “I am 18 years of age or older”
- “I consent to FacePrivacy storing my photo securely for the purpose of facial recognition database removal”
- “I confirm this is my real identity and authorize FacePrivacy to submit data removal requests using my information”
- “I agree to the Terms of Service and Privacy Policy”
Each consent is recorded against your account with the date it was given. You may withdraw consent at any time by deleting your account or by contacting us; withdrawal stops further processing and triggers destruction on the schedule above. Because the reference photograph is the only thing that makes a removal filing possible, withdrawing consent ends the service.
Consent before disclosure. We do not disclose, redisclose, or otherwise disseminate your biometric data without your consent. The consent you give at sign-up authorizes exactly one disclosure: sending your reference photograph to the facial-recognition engines you have asked us to remove you from, because their opt-out processes require an image to identify which face to remove. The only other party that ever holds it is Cloudflare, Inc., as our storage processor. We disclose it to no one else, and we will not disclose it for any new purpose without asking you first. We would also disclose it if compelled by a valid warrant, subpoena, or court order, which is the one basis available to us that is not your consent.
We do not sell or profit from your biometric data. We do not sell, lease, trade, or otherwise profit from your face photographs, your identity documents, or any biometric data derived from them. Our only revenue is the subscription fee you pay us. No advertiser, data broker, analytics provider, or AI training pipeline receives any of it — see Section 7 for what our advertising and analytics providers do receive, which is never biometric data.
Security. We protect your biometric data using a reasonable standard of care, and at least the same standard we apply to other confidential and sensitive information. See Section 5.
4. Sharing of Information
We may share your information with service providers (e.g. hosting, payment processing) under strict agreements. When we submit removal requests, we share only the information necessary with the relevant databases or their agents, in line with their removal processes. We do not sell your personal information to third parties.
Our website also shares limited data with advertising and analytics providers, as described in Section 7. That data never includes biometric or facial information. The sharing of your photographs with the facial-recognition engines you ask us to remove you from is a separate matter, governed by Section 3.
5. Security
We protect your data using a reasonable standard of care, and we handle biometric data to at least the same standard we apply to other confidential and sensitive information. In practice that means:
- In transit: everything you send us travels over TLS. Photographs are never uploaded in the background or without your explicit action.
- At rest: photographs and identity documents are stored encrypted in Cloudflare R2 object storage. They are not publicly addressable and are served only through authenticated, per-user requests.
- Access control: account access is protected by a hashed password or a provider sign-in (Apple or Google); we never receive your provider password. Administrative access to customer data is limited to staff who need it to operate the removal service.
- Separation: our subscription processor, sign-in provider, email provider, and analytics and advertising providers each receive only the narrow data described in Sections 7 and 10.9. None of them receives biometric data.
- Deletion: when data is destroyed it is removed from production storage, including superseded copies from earlier uploads, and backups are overwritten on the cycle described in Section 3.1.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, or port your data, or to object to or restrict processing. You may also have the right to withdraw consent. Contact us to exercise these rights. EU/UK users have additional rights under GDPR. The right to delete your account and your biometric data is available to everyone, everywhere, regardless of location — see Section 6.1.
6.1 Deleting Your Account and Your Data
You can have your account and everything in it permanently deleted, at any time, for any reason, without giving an explanation. You do not need an active subscription to do this.
- On the web: sign in, open your dashboard, go to the Account tab and choose Delete my account. This takes effect immediately.
- In the FacePrivacy app: Account → Delete account. This also takes effect immediately; nothing needs to be requested from us.
- By request: contact us using the details in Section 9 and ask us to delete your account. We action deletion requests promptly and in any event within thirty (30) days.
If you subscribed through the iOS app, cancel with Apple first. Apple owns that billing relationship and does not permit us to cancel an App Store subscription on your behalf, so deleting your account does not stop it renewing. Cancel it on your device under Settings → [your name] → Subscriptions → FacePrivacy, or at apps.apple.com/account/subscriptions, before deleting. If you subscribed through the Android app, the same applies to Google Play: cancel it under Play Store → your profile → Payments & subscriptions → Subscriptions → FacePrivacy, or at play.google.com/store/account/subscriptions, before deleting. If you pay us directly by card or through PayPal, we cancel your subscription for you as part of the deletion.
What deletion removes. Your face photographs and side-profile photographs, including any superseded copies from earlier uploads; any identity document you uploaded, redacted or original; any file you attached to a removal request; your removal history; your support messages; and your account record itself. If you pay us directly, by card or through PayPal, your subscription is cancelled at the same time so you are not billed again. If you subscribed through the iOS app, Apple owns that billing relationship and does not permit us to cancel it on your behalf: deleting your account here does not stop an App Store subscription renewing, and you must cancel it yourself under Settings → [your name] → Subscriptions, ideally before deleting. The same is true of a subscription bought through the Android app: Google owns it, and you cancel it in the Play Store under Payments & subscriptions.
What we may briefly retain, and why. Encrypted backups containing deleted records are overwritten on our ordinary rotation cycle, no longer than thirty (30) additional days, and are not restorable on request after that window. We may also keep the minimum transaction records we are required by law to keep for tax and accounting purposes; those records do not contain biometric data. Removal requests already delivered to a third-party engine cannot be recalled from that engine — their handling is governed by their own privacy policy, as described in Section 3.
Deletion is permanent and cannot be undone. See our account deletion page for the step-by-step version.
Deletion we carry out ourselves. We may also delete your face photographs, your side-profile photographs, any identity document you provided, and any file you attached to a removal request without being asked — if we close or suspend your account for any reason, or if we ever stop offering the service. The result is the same as a deletion you request: the photographs and documents are permanently removed from our production systems and object storage, including any superseded copies from earlier uploads, and encrypted backups containing them are overwritten on our ordinary rotation cycle, no longer than thirty (30) additional days, after which they are not restorable.
We also delete photographs you replace. When you upload a new reference photograph, the one it replaces is deleted rather than kept alongside it, so we hold your current reference images and nothing older.
7. Cookies, Analytics, and Advertising
We use advertising and analytics technologies that track users across other companies’ apps and websites. We would rather state that plainly than leave it to be inferred from the detail below. We share limited data with Meta so that Meta can connect your visit, and any subscription you start, to the advertisement you clicked and to the profile Meta already holds about you. That is what the Meta Pixel and Conversions API are for, and it is how we know which advertisements are worth paying for.
Today this runs on our website. We may extend the same measurement to our mobile applications, to other advertising and analytics providers, and to other measurement techniques, and this policy is written to cover that. Where it does apply to a mobile application, the App Store and Google Play privacy disclosures for that application describe what it does at that time; we will update those disclosures before any such change takes effect. None of this ever includes your face photographs, your identity documents, or any biometric data — that limit is absolute and is set out in Section 3.
We use cookies and similar technologies on our website. They fall into three groups:
- Essential — signing you in, security, and remembering your plan selection through checkout. These are always on.
- Analytics — Google Analytics 4 and Clicky, used to understand which pages are read and where people get stuck.
- Advertising — the Meta (Facebook) Pixel and Meta’s Conversions API, used to measure which advertisements bring people to us.
What we send to Meta. From your browser: page views and conversion events, such as beginning a registration or starting a subscription. In addition, when a subscription payment completes, our server sends Meta a one-way hashed (SHA-256) form of your email address, together with your IP address, your browser’s user-agent string, and Meta’s own advertising cookie identifiers, so that Meta can match the sale to the advertisement you clicked. Meta cannot read your email address back out of the hash, but Meta can match that hash against an account it already holds with the same address. This is ordinary conversion measurement, and we would rather state it plainly than leave it implied.
What advertising and analytics providers do not receive. Meta, Google, and Clicky never receive your face photographs, your side-profile photograph, any identity document, any biometric data, or the list of facial-recognition engines you have asked us to remove you from. Their access is limited to page views, conversion events, and the hashed email described above.
That limit applies to advertising and analytics only. We do send your reference photograph to the facial-recognition engines you ask us to remove you from — that is the service you are paying for, and a removal cannot be filed without an image. Section 3 sets out exactly which engines receive it, why, what they do with it afterwards, and how long we retain it.
Where this runs. These technologies run on our website, including the signed-in account area, where they record conversion events such as completing registration or starting a subscription. They are not present in our iOS or Android applications.
Your choice. If you decline in our cookie banner, no analytics or advertising code loads at all. See our Cookie Policy for further detail.
7.1 “Sale” and “Sharing” Under State Privacy Laws
We do not sell your personal information for money. We do, however, share it for advertising: our use of the Meta Pixel and Conversions API, and any comparable advertising or measurement technology we adopt, is “sharing” personal information for cross-context behavioral advertising as the California Consumer Privacy Act uses that term, and processing for “targeted advertising” under comparable laws in Virginia, Colorado, Connecticut, and other states. Treat this as applying to our advertising and analytics generally, not only to the specific providers named above. You may opt out at any time by declining in our cookie banner.
We never sell or share biometric or facial data under any of these definitions, for any purpose.
8. Changes
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. Continued use of our services after changes constitutes acceptance of the updated policy.
9. Contact
For privacy-related questions or to exercise your rights, contact us through our website or at the contact details provided there.
10. FacePrivacy for iOS — App-Specific Information
This section applies in addition to the rest of this Privacy Policy when you use the FacePrivacy iOS application (the “App”) downloaded from the Apple App Store. In any conflict between this section and a general section above, this section controls for iOS-specific behavior.
10.1 Data the App Collects
The App collects the same categories of information described in Section 1, plus the following items that exist because of the iOS platform:
- Account data: your email address and a hashed password, or an Apple-issued user identifier if you sign in with Apple. We never receive your Apple ID password.
- Identity and biometric data: the face and side photographs you upload, and any government-issued identity document you upload when a database asks for proof of identity, as described in Section 3.
- Subscription state: whether you hold a valid subscription, the subscription tier, and an opaque Apple transaction identifier returned by StoreKit. Apple processes the payment; we do not receive your credit card number, the last four digits of your card, your billing address, or your Apple ID password.
- Push notification token: if you grant push permission, iOS issues us a device token used solely to deliver in-app status notifications (for example, “an engine has asked for an ID”). We do not use the token for advertising.
- Diagnostic and usage data: crash reports and basic interaction analytics, kept in a form that does not identify you to us. The App does not embed a third-party advertising SDK. It does ask, through Apple’s App Tracking Transparency prompt, for permission to use your device’s advertising identifier (IDFA) to measure our advertising. If you allow it, the identifier and the email address you register with are sent to Meta from our server when you register and when you subscribe, so that an App Store sale can be matched to the advertisement that led to it — the same measurement Section 7 describes for the website. If you decline, no identifier is used and you lose nothing in the App. This is why our App Store privacy disclosure declares Contact Info and Identifiers as used for tracking.
10.2 Camera and Photo Library Access
The App requests permission to use your device’s camera and, optionally, your photo library only when you initiate an action that needs them — capturing your face or side photo, or attaching an identity document to a removal request. Captured images are uploaded over TLS to our servers and used for the same purposes described in Section 3. No image is uploaded in the background, none is uploaded without your explicit confirmation, and none is shared with third parties outside the scope of fulfilling a removal request you have asked us to make.
10.3 Push Notifications
Push notifications are off by default. If you grant permission, we deliver service notifications related to your account — an engine has requested action from you, a removal has been confirmed, a payment has failed, and similar operational events. You can revoke notification permission at any time in iOS Settings → Notifications → FacePrivacy.
10.4 In-App Purchases and Subscription Data
All in-app purchases on iOS are processed by Apple through the App Store and StoreKit. Apple is responsible for the payment transaction and the storage of payment instruments associated with your Apple ID. We receive only a non-financial transaction receipt that confirms your subscription status. Your right to a refund of an in-app purchase is governed by Apple’s App Store policies; refund requests for App Store purchases must be made to Apple, not to us, at reportaproblem.apple.com.
We use RevenueCat, Inc. as a sub-processor to validate the App Store transaction receipt and to deliver real-time subscription lifecycle events (renewal, cancellation, billing issue) to our backend. RevenueCat receives the opaque App Store transaction identifier, the product identifier you purchased, the country code of the App Store account, and an internal user identifier that we generate for you — never your name, email, photographs, or any biometric data. RevenueCat acts as a data processor under our instructions and is contractually bound to retain the data only as long as needed to provide the subscription service. Their full privacy policy is linked above.
10.5 Sign in with Apple and Google
If you choose Sign in with Apple, Apple supplies us a unique account identifier and, depending on the option you choose at sign-up, either your real email address or an Apple-relayed forwarding address that masks it. We treat the relayed address with the same care as a direct email address and use it only for transactional service messages and, with your separate consent, marketing email.
If you choose Sign in with Google, the App routes the OAuth handshake through Google’s Firebase Authentication service, which we use as a sub-processor for identity verification only. Firebase returns to us your Google account email address and a stable Firebase user identifier. We never receive your Google password, your contacts, your calendar, your Drive content, or any other Google profile data beyond your email. Firebase Authentication is configured without analytics SDKs in the App, so Google does not receive in-App behavior data from us.
10.6 Data Stored On Your Device
The App stores a session token in the iOS keychain so you remain signed in between launches, and a small cache of removal status data to render the dashboard offline. No biometric template, government ID, or payment data is stored on your device beyond the lifetime of an upload screen.
10.7 Account and Data Deletion
Apple App Store Review Guideline 5.1.1(v) requires that accounts created in an app can be deleted from within that app. You can delete your FacePrivacy account — including all uploaded photographs, identity documents, and removal history — from the iOS app under Settings → Account → Delete Account, or from the web dashboard at any time. Deletion is permanent and removes the underlying records from our production database within thirty (30) days. Backup copies are overwritten on our normal rotation cycle and are not restorable on request after that window.
10.8 Children
The App is not directed to children and is rated 17+ on the App Store because facial-recognition opt-out paperwork is an adult-only workflow. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information through the App, contact us and we will delete the account.
10.9 Third-Party Services and Sub-Processors
The App uses Apple frameworks (StoreKit for purchases, UserNotifications for push, AuthenticationServices for Sign in with Apple) and our own backend at faceprivacy.ai. In addition, the App relies on the following named sub-processors, each of which receives only the specific data described and is contractually bound to use it solely to provide their part of the service:
- RevenueCat, Inc. — receives the App Store transaction identifier, product identifier, country code, and an internal user identifier so we can verify your subscription status across reinstalls and devices. Does not receive your photographs, identity documents, or removal history. See Section 10.4.
- Google LLC (Firebase Authentication) — processes the Sign in with Google OAuth handshake only when you choose that sign-in method. Receives your Google account email and returns a stable user identifier. Does not receive any other Google profile data, does not receive in-App behavior data, and is not embedded as an analytics SDK. See Section 10.5.
- Cloudflare, Inc. — operates the network edge, the application worker, and the R2 object store where your photographs and identity documents are kept encrypted at rest. Cloudflare is a passive infrastructure provider and does not access the content of the data we store with them outside of network delivery.
- Cloudflare, Inc. (D1) — hosts the database that records your account, subscription state, and removal history. As with R2 above, Cloudflare acts as a passive infrastructure processor and does not access the content of the database outside of operating the service.
- Resend, Inc. — delivers the transactional and reminder emails the App sends on your behalf. Receives your email address and the body of the message being sent.
The App does not embed any third-party advertising SDK, third-party tracking SDK, third-party crash reporter that shares data with the SDK vendor, or analytics SDK that calls home. With your permission through the App Tracking Transparency prompt, the App uses the advertising identifier (IDFA) together with your registered email address for advertising measurement as described in Section 7 — sent to Meta from our server, not through an SDK in the App — and our App Store privacy disclosure declares Contact Info and Identifiers as used for tracking on that basis. Decline the prompt and no identifier is used. What never leaves this limit is your face: no advertising or analytics provider receives your photographs, your identity documents, or any biometric data, ever. The forwarding addresses used by the App when filing removal requests go directly to the relevant facial-recognition database operators — these are listed in Section 4 of this Privacy Policy and on our public Database List.
10.10 Apple’s Role
Apple distributes the App but is not a party to your relationship with us. Questions about how we process your data should be directed to us using the contact information in Section 9, not to Apple. Questions about how Apple processes data it collects about you through the App Store, your Apple ID, and Apple Pay should be directed to Apple under Apple’s Privacy Policy.