Privacy Policy
FindFace is operated by Rockhammer Labs LLC, which is the data controller for the personal data described here. Face-search data is sensitive, and the product architecture starts from one rule: the safest data is data we never collect.
Privacy by architecture
FindFace is designed to minimize collection of face-search data. Your browser detects the face and produces a standardized, metadata-free crop before anything is uploaded. The original photo you select is never sent to our servers or to any provider — only the crop is.
What your browser does
- The photo you select stays in browser memory while face detection runs on your device.
- On the website, a metadata-free crop may be held in tab session storage so sign-in or payment can return you to the same search. Closing the tab discards it.
- In the Chrome extension, right-clicking an image grants temporary access to that tab. If the image host blocks a direct read, the extension captures the visible tab locally, immediately crops it to the selected image, and discards the full screenshot. The selected image is held only in browser session storage until the side panel receives it or the browser closes.
- No image is uploaded until you start a search.
What we collect when you use the service
- Account: your email address, and the account identifier supplied by the sign-in provider you choose.
- Search: the face crop, the search results returned for it, and a low-resolution blurred thumbnail for your own history.
- Billing: your plan, credit balance and ledger, and the payment provider’s order and subscription identifiers. Card details are entered on the payment provider’s own pages and are never seen or stored by FindFace.
- Operations: request and error logs containing status, timing, and error codes.
Retention
- The uploaded face crop is deleted as soon as the search completes, and in no case is kept longer than 24 hours.
- The original photo is never uploaded: face detection and cropping happen in your browser.
- History thumbnails are low-resolution and blurred, and are deleted after 30 days.
- Search results — source URLs, domains, and scores — are deleted after 30 days.
- After 30 days only a record that a search occurred remains, used for usage counts. It contains nothing identifying who was searched for.
- Face embeddings and landmark arrays are never retained.
- Deleting a search removes its results immediately, subject to narrow legal obligations.
Who processes your data
FindFace runs on third-party infrastructure, and the face crop is by necessity shared with the visual-search provider — that is what performs the search. The list below is what the service actually uses today.
- FaceCheck.ID — visual search. Receives the face crop in order to find visually similar public pages.
- Supabase — database and authentication, including your email address.
- Google Identity Services — optional Google sign-in. When you are signed out, Google may offer its browser-managed One Tap prompt if your browser has an active Google session.
- Cloudflare — website hosting and private object storage for the crop and history thumbnail.
- Modal — the compute that runs a search.
- Lemon Squeezy — payments and subscriptions. It, not FindFace, handles your card details.
- Sentry — error monitoring. It receives error codes and stack traces, not query images.
- Umami — optional, privacy-focused website analytics hosted at umami.lingather.ai. It is loaded only after you allow analytics and only on public marketing and guide pages.
Analytics limits
- If you allow analytics, Umami records anonymous page views, referrer, browser, operating system, device type, approximate country, and web-performance measurements on public pages.
- Umami receives neither URL query strings nor URL hashes. It is not loaded on search results, account, billing, or administration pages, and it never receives query images or result URLs.
- FindFace uses no advertising tracker. Session replay is not enabled anywhere in the product.
- You can decline analytics without losing functionality and change your choice later through Cookie settings in the footer.
- Operational logs contain task status, timing, and error codes rather than query media.
Chrome Web Store Limited Use
FindFace’s use of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use that information only to provide or improve the extension’s user-facing sign-in and face-search functions; we do not sell it, use it for advertising or credit decisions, or permit human access except with specific user consent, for security, to comply with law, or in aggregated and anonymized form for internal operations.
Your controls
- Delete a search and associated product history.
- Request account deletion.
- Request correction or access where applicable.
- Submit an abuse or removal request related to FindFace’s own processing.
Contact
Rockhammer Labs LLC is the controller for the data described here. Write to support@rockhammerlabs.com for any privacy question, access or deletion request, or to reach a person about a search involving you. This page is updated when the processing it describes changes; the date beside it is the date of the last such change.