Legal
Privacy Policy
1. The short version
- The app passes your photo to the search engine that runs your search and reads back the results. We keep no copy at any point.
- Your scan history lives on your device, not in an account we can read.
- You can use the app without giving us your name or email. Accounts are anonymous by default.
- We never sell your data and never use it for advertising or tracking.
- You can delete everything from Settings inside the app, at any time.
The rest of this policy is the detail behind those five lines.
2. Your face photo (face data)
The photo of your face is face data: the most sensitive thing the app touches. So it gets its own section, covering what we collect, every use we make of it, who it is disclosed to, how long it exists anywhere, and how to delete it or revoke consent.
What we collect, and when
One photograph of your face per scan: a selfie you take with the front camera, or a photo you choose from your library. You submit it deliberately, each time, to search for your own face. The app never collects face data in the background, and there is no way to search for anyone else. A free preview runs entirely on your device. Nothing leaves your phone for a preview.
Every use we make of it
Exactly one. For a full scan, the app transmits your photo over an encrypted connection to a third-party reverse face-search engine that maintains the search index. The engine runs the search you asked for and returns the matches you see. Delete My Face is the interface between you and that engine: we pass your photo through to run your search, and we keep no copy of it.
We never use your face data for advertising, analytics, tracking, training AI or face-recognition models, identifying other people, or any purpose other than the search you requested. We never sell it. Section 4 makes those promises one by one.
Who it is disclosed to
One third party: the search engine, which receives your photo solely to run your search. Nobody else ever receives your face data. Not Apple, not our payment or subscription providers, not advertisers, not data brokers. Section 5 lists every party we share anything with, and states our commitment that any third party receiving your face data protects it to the same standard as this policy.
What we do not collect
We do not store your photo. We do not create or keep face templates, faceprints or any biometric database. The photo you submit is handled for exactly as long as it takes to run the search you asked for, and for no other purpose.
How long it exists (retention)
We do not retain your photo or your results on our servers. The image passes through in memory to reach the search engine and is never written to storage on our side. The moment your search completes or fails, we instruct the search engine to delete the uploaded photo, and an automated cleanup job re-issues any deletion that did not go through, within hours. Your results are written to a short-lived delivery record so your phone can collect them, and that record is deleted as soon as your device confirms receipt, or automatically within six hours, whichever comes first.
After that, the only copy of your scan and its results is the one on your own device, which you control.
Section 6 puts every retention period in one table. Deleting your face data, and revoking consent for its collection and use, are covered in section 7.
3. Other information we collect
| What | When | Why |
|---|---|---|
| Anonymous account ID | On first launch | To hold your scan credits server-side so they cannot be tampered with. It is a random identifier and is not tied to your name or email. |
| Purchase history | If you buy credits or a plan | To grant what you paid for and restore it if you reinstall. Handled through Apple and our subscription provider. We never see your card details. |
| Email address and Apple account connection | Only if you join the white-glove waitlist or sign in with Apple | To tell you when white glove launches, and to recognize your account if you signed in. Optional and explicit; nothing else in the app asks for an email. |
| Diagnostics and crash data | If a crash or error occurs | To find and fix bugs. This does not include your photo or your results. |
You do not need to create an account, provide a name, or provide an email to scan your face and use the removal guides.
4. What we never do
- We never sell, rent, lease, trade or profit from your photo or your data.
- We never use your data for advertising, ad targeting, or tracking across apps or websites.
- We never offer people search. There is no name lookup, no reverse search of other users, and no identification feature.
- We never disclose your photo except as set out in section 5.
- We never use your scan results to build a profile of you.
6. How long anything exists
| Data | Retention |
|---|---|
| Your scan photo | Not retained by us. Transmitted to run your search and not stored on our servers afterwards. |
| Your scan photo at the search engine | Deleted when your search completes or fails: we call the engine's deletion API immediately, and an automated cleanup job re-issues any deletion that did not go through, within hours. |
| Scan results delivery record | Deleted on device confirmation of receipt, or automatically within six hours, whichever is first. |
| Scan history and match results | Stored on your device only, until you delete them or uninstall the app. |
| Anonymous account and credit balance | Until you delete your data, or after 24 months of inactivity. |
| Waitlist email address | Until the service launches and you are notified, or until you ask us to remove it. |
| Purchase records | As long as required for tax, accounting and audit obligations. |
Where a row says not retained, there is nothing to destroy: the data is gone the moment your search completes.
7. Deleting your data and revoking consent
Deleting your face data
There is usually nothing for you to ask us to delete. We keep no copy of your photo, and the search engine's copy is deleted automatically when your search ends, without you doing anything. The scan photos and results saved on your device are under your control: swipe to delete any scan in History, or remove everything at once as described next.
Deleting everything
Open the app, go to Settings, and choose Delete my data. This removes your anonymous account record, your remaining credit balance, your waitlist entry if you have one, and your on-device scan history, including every scan photo and result stored on your device.
Deletion is permanent and cannot be undone. Purchases already consumed are not refunded by deleting your data. If you would rather we did it for you, email help@deletemyface.com and we will confirm once it is done.
Revoking consent
Your face data is collected and used only when you start a scan. Every scan is a separate, deliberate choice, and nothing is collected between scans. You can revoke your consent to any further collection or use of your face data at any time: simply stop scanning, and no face data will be collected again. To erase what already exists, use Delete my data as above, or email help@deletemyface.com and we will handle it for you. Revoking consent costs nothing and does not close your account: unused credits stay until you choose to delete your data.
8. Your rights
You can ask us, at any time, to show you what we hold about you, correct it, give you a copy of it, or erase it. Deletion you do not even have to ask for: it is a button in Settings. Email help@deletemyface.com for the rest and we will respond within 30 days.
We honor these rights for everyone, wherever you live, because drawing a map of who deserves privacy is not a business we want to be in. Because accounts are anonymous, we may need you to confirm a request from the device holding the account.
9. Security
Traffic between the app, our servers and the search engine is encrypted in transit. Scan credits are validated server-side so they cannot be modified on a device. Access to production systems is limited to people who need it.
No system is perfectly secure. The strongest protection here is structural rather than technical: we do not keep your photo, so there is no library of faces for anyone to steal from us.
10. Children
Delete My Face is not intended for children. You must be at least 18 years old, or the age of majority where you live, to use it. We do not knowingly collect data from minors. If you believe a minor has used the app, email us and we will delete the data.
11. Changes and contact
If we change this policy we will update the date at the top. If a change materially affects how your photo is handled, we will tell you in the app before it takes effect.
Delete My Face
help@deletemyface.com
We read every email. If something in this policy is unclear or looks wrong, tell us and we will fix it.