The Face Report

Privacy Policy

Last updated: July 15, 2026

The Face Report ("we," "us," or "our") operates the website at https://thefacereport.com. This Privacy Policy explains how we collect, use, and protect your information when you use our facial analysis services.

By using The Face Report, you agree to the practices described here. If you do not agree, please do not use our services.

1. Information We Collect

Facial geometry (free tools)

For our geometric tools (Face Shape Detector, Symmetry Test, Golden Ratio scoring, Harmony Score), the facial landmarks are detected in your browser using MediaPipe Face Mesh. Your photo itself is never uploaded to or stored on our servers for these tools. When you run one of these tools we do save the derived measurements it produces — your symmetry, proportion and ratio scores, and the per-feature points used to draw your result — to your results record so you can return to them. We do not store the full 478-point face mesh. If you would prefer to store nothing, you can delete your results at any time at Delete my data.

Perceived age & visible-attribute inference

On certain tools (Perceived Age estimator, the Full Analysis page), we send your photo to Google's Gemini API to estimate perceived age and infer a small set of visible attributes used to personalise recommendations and produce aggregate analytics. The inferred attributes are: apparent sex (male / female / unsure), Fitzpatrick skin tone, hair colour / type / length, eye colour, presence of facial hair, and presence of glasses. We do not infer or store your race or ethnicity. These attributes are inferred from the image — we never ask you to declare them.

The photo you upload is deleted within 2 hours by an automated hourly job. Alongside your analysis record we store the inferred attributes above and a one-way hash (SHA-256) of your photo. The hash cannot be turned back into your photo; we use it only to recognise a re-uploaded image and avoid reprocessing it. These inferred records are kept for 2 days, then deleted by the next successful automated hourly purge for everyone — logged in or not — and under-18 records are purged on a recurring hourly schedule (see the retention schedule below).

Facial analysis data (paid Full Report)

When you spend tokens to generate the Full Report, your photo is sent to Google's Gemini API for qualitative analysis and to generate your AI styling concept. The written report text is generated by Anthropic (Claude) from your analysis and photo. If you generate hairstyle visualizations, your photo is also sent to Replicate to render them. When you request a report PDF, your email, your generated images, and your analysis are sent to our PDF provider. All of these transmissions are encrypted in transit. We do not keep the photo you upload — it is deleted within 2 hours. The report it produces is different: the text results (scores, recommendations, inferred attributes) and the AI-generated visualization images are saved so you can return to them. Free scan results are kept for 2 days, then deleted by the next successful automated daily purge; a purchased report is kept until you delete it (or delete your account), and in any case no longer than 12 months after it is created. See §5 for the full list of these providers and what each receives.

Account information

When you create an account, we collect your email address and password (hashed, never stored in plain text). Account data is managed by Supabase. You can also give us just your email — with no account — to receive or save your results; see the retention schedule below for how long it is kept.

Payment information

Payment processing is handled entirely by Stripe. We never see or store your credit card number. We receive only your Stripe customer ID and purchase history.

Automatically collected data

Beyond what you actively submit, we and our providers automatically collect the following:

  • Cookies and local identifiers. We set first-party cookies that record your cookie choice, your biometric-processing consent, the result of the age screen, whether you used the email gate, and referral attribution (fr_ref, 7 days). We also set fr_anon_session, a session identifier that lasts up to 1 year and lets us link your saved results, any email you provide, and any referral activity back to the same anonymous session so you can return to your results. If you accept analytics cookies, the Meta pixel also sets its advertising-measurement cookies (_fbp, and _fbc after clicking one of our Facebook ads).
  • Device and network data. We store your browser's user-agent string, and we use your IP address for abuse prevention and rate-limiting. We use a coarse, country-level location signal derived from your IP to decide which features, payments, and consent prompts to show in your region.
  • Product-usage events. We record in-app events (which tools and pages you use, and where people get stuck) to understand aggregate usage.
  • Analytics providers. We use Google Analytics (GA4) for aggregate product analytics (page views and in-app events only — no session replay or screen recording); in the EEA and UK it loads only after you accept analytics cookies.
  • Advertising measurement. We use the Meta (Facebook) pixel and Meta's Conversions API to measure whether our ads led to a visit or purchase. Meta receives page views, checkout events, and — on purchase — a one-way hashed version of your email address. It never receives your photo, your analysis, or any biometric data. In the EEA and UK the pixel loads only after you accept analytics cookies.

We do not sell your data, and we never share your photo, analysis results, or any biometric data with advertising platforms.

Referrals (invite links)

If you choose to invite friends to unlock a reward, we generate a unique invite link for you. When someone opens your link we set a short-lived attribution cookie (fr_ref, 7 days) in their browser, and if they complete their own free analysis we record that the referral succeeded. To count referrals fairly we store an opaque session identifier and a one-way, salted hash of the visitor's IP address — never their name, email, or photo. Separately, to prevent abuse and rate-limit requests across the site, we briefly store a visitor's IP address in our rate-limiting records. You only ever see a count (e.g. "2 of 3 friends joined"), never who joined. This referral data is pseudonymous, used solely to operate and protect the rewards feature (our legitimate interest in preventing fraud), and is removed when you delete your data or when a referred person deletes theirs.

2. Biometric Data Notice

Certain jurisdictions (including Illinois under BIPA, Washington under MHMDA, and the EU under GDPR) classify facial geometry as biometric or special category data. We take this seriously:

  • Geometric tools: Facial landmarks are computed locally in your browser; your photo is never uploaded. Some derived geometric measurements are saved to your results record (see §1).
  • AI tools (perceived age, attribute inference, paid analysis, hairstyle and other image tools): Your photo is temporarily transmitted (encrypted) to our AI providers — Google Gemini (analysis, age estimate, image generation), Anthropic / Claude (written report text), and Replicate (hairstyle images). When you request a report PDF, a copy of your email, your generated images, and your analysis is sent to our PDF provider. We ask for your explicit consent before your first AI upload — never on a pre-checked box.
  • We do not sell, lease, trade, or otherwise profit from biometric or inferred-attribute data to any third party.
  • AI training: Google Gemini and Anthropic process our inputs under their paid APIs and do not use them to train their models. Replicate processes your image solely to generate the visualization you requested. We do not authorise any provider to train on your facial data.

Retention schedule

  • The photo you upload: deleted within 2 hours of upload, enforced by an automated hourly job. (Free geometric tools never upload your photo at all.)
  • Inferred attributes & the photo hash: stored with your analysis for 2 days, then deleted by the next successful automated hourly purge — for logged-out and logged-in users alike — with self-reported and detected under-18 records purged on a recurring hourly schedule.
  • Generated report images & results: the AI-generated visualizations and your scores/recommendations from a free scan are kept for 2 days, then deleted by the next successful automated daily purge; for a purchased report they are kept until you delete them (or delete your account/data), and in any case no longer than 12 months after creation — enforced by an automated daily job.
  • Consent records: kept as proof of consent until you delete your data, at which point they are removed too.
  • If you give us your email (to receive or save your results): it is stored alongside that analysis until you delete your data or unsubscribe. We use it to send your results and — only if you opt in — occasional glow-up or color styling tips, never sold or shared.

Withdraw consent & delete your data, yourself: you can permanently delete everything we hold about you — and withdraw your biometric-processing consent — at any time from Delete my data. This removes your analyses, inferred attributes, photo hash, email, consent records, and referral data — no email required. You can also contact contact@thefacereport.com.

3. How We Use Your Information

  • To provide facial analysis results and recommendations
  • To personalise recommendations (e.g. skincare ingredients, hairstyles, color palettes) using the visible attributes inferred from your photo
  • To generate your AI styling concept (paid feature)
  • To manage your account and token balance
  • To store your analysis history so you can track progress
  • To produce aggregate, de-identified analytics and statistics (e.g. distributions of analysis scores, face shapes, or inferred attributes across users) used to improve the product and to publish anonymous research, statistics, or educational content. Any published figures are reported only in aggregate and never include personal data, photos, or individual results.
  • To respond to support requests

We do not use your data for advertising or to sell to third parties, and we do not make automated decisions with legal or similarly significant effects about you. To keep your results and rewards available across visits, we do link your anonymous activity to a session identifier for up to one year, as described in §1; we do not build advertising or marketing profiles.

4. Data Retention

  • Uploaded photos: deleted within 2 hours of upload. An automated hourly job enforces this (see the retention schedule).
  • Generated report images & analysis results: the AI visualizations, scores, recommendations, and inferred attributes from a free scan are kept for 2 days, then deleted by the next successful automated daily purge; a purchased report is kept until you delete it (or delete your account), and in any case no longer than 12 months after creation. Logged-out analyses are linked to a random browser session id and, if you used the email gate, to the email you provided — so they are pseudonymous, not fully anonymous — and can be removed sooner anytime via Delete my data.
  • Pseudonymous product-usage events: raw event rows are kept for today plus the previous two complete UTC days. They are deleted only after their daily de-identified aggregates pass an exact parity check.
  • Aggregate analytics: de-identified statistics derived from inferred attributes contain no personal identifiers and may be retained indefinitely.
  • Account & consent data: retained until you request deletion. Database records are removed when you delete; any copies in our hosting provider's routine backups are purged on that provider's rolling backup schedule.

5. Third-Party Services

We use the following third-party services:

  • Supabase — Authentication and database hosting (EU/US servers).
  • Google Gemini API — AI facial analysis, apparent-age estimation, and image generation. Receives your photo. We use the paid API, under which inputs are not used to train Google's models.
  • Anthropic (Claude) — AI generation of your written Full Report. Receives your photo and analysis. Inputs submitted via its API are not used to train Anthropic's models.
  • Replicate — AI hairstyle / image generation. Receives your photo to render the visualization you requested.
  • Railway (PDF report service) — Generates your downloadable report PDF. Receives your email address, your AI-generated report images, and your analysis to assemble the PDF.
  • Cloudflare R2 — Encrypted storage of generated report images.
  • Stripe — Payment processing.
  • Resend — Transactional and opt-in marketing email (login links, report delivery, and glow-up or color styling tips for those who opt in).
  • Slack (Salesforce) — Internal operator notifications. Our team receives alerts about purchases and system errors that may include your email address and an account identifier (never your photo or analysis).
  • Google Analytics (GA4) — Aggregate product-usage analytics (not used for advertising); in the EEA/UK it loads only after you accept analytics cookies.
  • Meta (Facebook) — Advertising measurement via the Meta pixel and Conversions API: page views, checkout events, and on purchase a one-way hashed email address (never your photo, analysis, or biometric data). In the EEA/UK the pixel loads only after you accept analytics cookies.
  • Vercel — Website hosting; provides the coarse, country-level location signal used for regional gating.

Each service processes data according to their own privacy policies. We select services that meet high data protection standards.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data and account
  • Export your data in a portable format
  • Withdraw consent for biometric data processing at any time
  • Object to processing of your data

You can delete your data and withdraw consent yourself at Delete my data. To exercise any other right — access, correction, a portable export, or objection — contact us at contact@thefacereport.com and we will respond within 30 days. Parents/guardians: if you believe your child has used the service, contact the same address and we will delete the child's data on request.

7. Children's Privacy

The Face Report is intended for adults aged 18 and older. Before you can use our AI tools (the perceived-age estimate, Full Analysis, and image generation), you must confirm your age by entering your year of birth, which we validate on our servers before your photo is sent to any AI provider — we store only whether you are old enough, not the year itself. Age is self-reported — we do not verify it against identification — so someone who enters a false year could bypass this check.

Our AI also estimates apparent age from your photo as one of its outputs. If your self-reported age is under 18, the AI tools do not run for you — you can still use our on-device geometric tools, which never upload your photo. If the apparent-age estimate indicates a likely minor, we do not save the inferred attributes from that photo.

We do not direct this service to children under 13, and it is not designed for them. We do not seek to collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 — including a facial image or facial geometry — we will delete it. If you are a parent or guardian and believe your child has provided us personal information, contact contact@thefacereport.com and we will delete the child's data on request.

How minor-related data is removed: uploaded photos are deleted within 2 hours by an automated job; inferred-attribute records placed in an under-18 age band are purged automatically on a recurring (hourly) schedule rather than instantaneously; and you can delete everything yourself at any time from Delete my data.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on our website. The "Last updated" date at the top reflects the most recent revision.

9. Contact

For questions about this Privacy Policy or your data, contact us at:

contact@thefacereport.com