The short version
Your photographs are encrypted in your browser before they are uploaded, with a key that never leaves your device. Our servers store ciphertext and no key, so the stored server data alone cannot open a photograph. Code RateMyFaceAI delivers to this site can use the browser-held key through WebCrypto while it is present. We store the scoring inputs: point coordinates, image dimensions, selected gender and ancestry, and which front points you moved. Measurements and scores are computed when the analysis loads, not stored. You can delete the inputs and encrypted photographs, and your whole account, at any time.
Washington and Nevada require a separate policy for consumer health data. Ours is at Consumer Health Data Privacy Policy, and it applies to everyone.
1. Who is responsible for your data
Tim Schneider, a sole proprietor based in California, USA, operates ratemyfaceai.app and is the controller of the personal data described here. Contact us at privacy@ratemyfaceai.app.
2. What we collect
- Account data. Your email address, and if you sign in with Google, the name and profile picture Google returns. We never receive your Google password.
- Photographs. Encrypted in your browser before they are uploaded, with a key we never receive. See section 7.
- Analysis inputs. The positions of the points placed on your photographs, each photograph's natural pixel dimensions, and which front points you moved. We compute ratios, measurements, and scores from those inputs whenever your analysis loads; we do not store those results.
- Profile inputs. The gender and ancestry options you select, which change which reference ranges your measurements are scored against.
- Subscription data. Which tier you are on and when it renews. Stripe handles the payment itself and we never receive your full card number.
- Technical data. Standard server logs, including IP address and browser type, kept for security and debugging.
3. Facial geometry and biometric law
The coordinates of the points placed on your face are a scan of face geometry. That makes them biometric data under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington My Health My Data Act, the Nevada consumer health data law, the biometric provisions of the Colorado, Oregon, and Montana privacy acts, and Article 9 of the UK and EU GDPR. We treat them that way for everyone, wherever you live.
We do not serve Illinois. BIPA is the one biometric statute a private plaintiff can sue under directly, so we block access from Illinois rather than operate there. Everything in this section nonetheless follows BIPA, because it is the strictest of the statutes above and meeting it means meeting the rest. See our Terms of Service.
Notice and consent before collection. Before we receive anything, we tell you in writing that we will create and store a scan of your face geometry, what it is for, and how long we keep it, and we ask you to agree by ticking a box that is not ticked for you. That request is separate from accepting these policies. Nothing reaches us until you agree. Placing points in your browser sends us nothing.
One purpose only. We use it to compute your measurements and show you your own analysis. Nothing else. We do not use it to identify you, to match you against another person or any database, to train a model, to advertise, or to profile you.
We never profit from it. We do not sell, lease, trade, or otherwise profit from your biometric data, and we never will. You pay us for an analysis; we are not paid by anyone for your data. We disclose it to no one except the processor that hosts our database, which is listed in section 6.
Withdrawing consent is as easy as giving it. Delete an analysis or close your account, both from your account page, and the underlying measurements are destroyed on the schedule in section 8. You may also email us. Withdrawing costs nothing and does not affect anything we lawfully did beforehand.
Standard of care. We store and transmit your biometric data using the reasonable standard of care for our industry, and in a manner at least as protective as we use for any other confidential information we hold.
4. What we use it for
- Running the analysis you asked for, and showing you the results.
- Saving your analyses so you can return to them.
- Creating and securing your account, and sending sign-in links.
- Taking payment and giving you access to the tier you bought.
- Keeping the Service working, secure, and free from abuse.
- Meeting our legal obligations.
We do not use your photographs or measurements for advertising, profiling, or automated decisions with a legal effect on you.
5. Our legal bases (UK and EU users)
- Explicit consent for your photographs and facial measurements, under Article 9(2)(a).
- Performance of a contract for your account, your subscription, and delivering the Service.
- Legitimate interests for security, fraud prevention, and keeping the Service running.
- Legal obligation for tax and accounting records.
6. Who we share it with
We do not sell, lease, trade, or otherwise profit from your data, and we do not share it for cross-context behavioural advertising. We share it only with the providers we need to run the Service:
- Convex hosts our database, our backend, and the encrypted photographs. For photographs, it receives ciphertext and no key. It also stores the analysis inputs listed in section 2.
- Vercel hosts the website.
- Google handles sign-in if you choose it.
- SendGrid delivers your sign-in emails.
- Stripe processes payments.
Each acts on our instructions under a data processing agreement. We may also disclose data if the law requires it, or to protect our rights or someone's safety.
If the Service is ever sold, your account and payment records could transfer to the buyer as part of that sale. Your biometric data would not. We would either destroy it before the transfer or ask you first and transfer it only if you agree. BIPA and the statutes that follow it do not treat a change of owner as your consent, and neither do we.
We never train models on your data. Not on your analysis inputs or computed results. This is not a setting you have to find and switch off, and it is not something we ask permission for and then assume. There is no opt-in. Our processors are contractually barred from training their own models on your data too.
7. Your photographs are encrypted with a browser-held key
The first time you save an analysis, your browser generates an encryption key and keeps it on your device. It is never sent to us in any form: not the key, not a wrapped copy, not anything we could derive it from. Your photographs are encrypted with that key before they are uploaded, so our servers store ciphertext and no key that can decrypt it.
The key is non-extractable, which means page scripts cannot export its raw bytes. Same-origin code RateMyFaceAI delivers to your browser can still ask WebCrypto to use the key, including to display your photographs. The protection described here is therefore an at-rest server guarantee: an administrator, a server-data breach, or a legal demand gets ciphertext and no server-held key, not a claim that code running in your signed-in browser is cryptographically unable to use the local key.
What this means for you in practice: your photographs are tied to the browser you used. If you clear your browsing data or sign in on another device, our servers cannot recover the key or decrypt those photographs. Your saved analysis still loads with its measurements and scores because the saved coordinates, dimensions, and scoring inputs let your browser compute them again. You will need to upload the photograph again to see the points drawn on your face.
The analysis inputs we store are held in our database and returned only to the account that created them. No other user can reach them.
8. Retention and destruction schedule
This is our published retention schedule and our guidelines for permanently destroying biometric identifiers, required by BIPA section 15(a). It binds us for every user, not only in the states that demand it.
- Photographs: stored only as ciphertext with no server-held key, and destroyed on the same schedule as the analysis inputs below. The browser-held key is removed whenever you clear your browsing data.
- Your point coordinates and scoring inputs, meaning the scan of face geometry: destroyed when the purpose for collecting them is satisfied, and in every case no later than 12 months after your last visit. Deleting an analysis or closing your account destroys them within 30 days. Withdrawing your consent destroys them within 30 days.
- Account data: your email address and sign-in records, until you close your account, then deleted within 30 days.
- Payment and tax records: kept as long as tax law requires, typically 6 to 7 years. These contain no biometric data.
- Server logs: up to 90 days. These contain no biometric data.
The 12-month limit is the strictest deadline any of the applicable statutes sets, so it is the one we apply everywhere. Destruction is permanent and irreversible, is carried out automatically on a schedule rather than by request, and extends to backups on their normal rotation. We do not keep an archived, anonymized, or aggregated copy of your face geometry after destruction.
9. Your rights
You can ask us to:
- Give you a copy of your data, or export it in a portable format.
- Correct anything inaccurate.
- Delete your data, including every measurement and score.
- Restrict or object to our processing.
- Withdraw your consent to facial measurement, at any time, as easily as you gave it.
- Get a list of the third parties we have disclosed your data to.
- Appeal, if we refuse any of the above.
Email privacy@ratemyfaceai.app and we will respond within 30 days, extending once by 30 days only where a request is genuinely complex, and telling you why. We will never charge you for exercising a right or give you a worse service for it.
If we refuse a request, we will tell you why and how to appeal, and we will answer the appeal within 45 days. If we deny the appeal we will give you a way to complain to your state attorney general. Colorado, Oregon, Montana, Texas, Washington, and Nevada residents each have this appeal right, and we extend it to everyone.
If you are in the UK or the EU you may also complain to your data protection authority. California residents have the same rights under the CCPA and CPRA, and we do not sell or share personal information as those laws define it.
10. The Service is not for children
RateMyFaceAI is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a minor has used the Service, email us and we will delete the account and its measurements.
11. International transfers
Our providers may process data in the United States and elsewhere. Where data leaves the UK or the EEA, we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
12. Cookies
We use cookies only to keep you signed in and to keep your session secure. We do not use advertising or third-party tracking cookies, so there is no consent banner to click through.
13. Changes to this policy
If we change how we handle your data in a way that materially affects you, we will email you and update the date at the top of this page before the change takes effect.
14. Contact
Privacy questions or requests: privacy@ratemyfaceai.app. See also our Terms of Service and our Consumer Health Data Privacy Policy.