The Face Report

Privacy Policy

Last updated: September 3, 2026

The Face Report ("we," "us," or "our") operates the website at https://thefacereport.com. This Privacy Policy explains how we collect, use, and protect your information when you use our facial analysis services.

By using The Face Report, you agree to the practices described here. If you do not agree, please do not use our services.

1. Information We Collect

Facial geometry (free tools)

For our on-device geometric tools (face shape, symmetry, golden ratio, facial ratios, jawline, canthal tilt, eye shape, side profile, pupillary distance, attractiveness and PSL scoring, and the hairstyle finder), the facial landmarks are detected in your browser using MediaPipe Face Mesh. If you use the in-app camera, the live preview frames are analysed the same way, on your device only, to guide your framing; they are never stored or sent anywhere. Your photo itself is never uploaded to or stored on our servers for these tools. When you run one of these tools we do save the derived measurements it produces - your symmetry, proportion and ratio scores, and the per-feature points used to draw your result - to your results record so you can return to them. We do not store the full 478-point face mesh. If you would prefer to store nothing, you can delete your results at any time at Delete my data.

Perceived age & visible-attribute inference

On the tools that use AI vision - the Perceived Age estimator, the Full Analysis page, Skin Analysis, Color Analysis, and the free AI preview image shown on your results page - we send your photo to Google's Gemini API to produce that tool's result (an age estimate, skin-appearance observations, a seasonal color verdict, or a preview image). On the age and full-analysis tools it also infers a small set of visible attributes used to personalise recommendations and produce aggregate analytics. The inferred attributes are: apparent sex (male / female / unsure), Fitzpatrick skin tone, hair colour / type / length, eye colour, presence of facial hair, and presence of glasses. We do not infer or store your race or ethnicity. These attributes are inferred from the image - we never ask you to declare them.

The photo you upload is deleted within 2 hours by an automated hourly job - unless you purchase a report, in which case a private, downscaled copy of your photo and close-up crops of your features are stored as part of that report (see the paid-report section below). Alongside your analysis record we store the inferred attributes above and a one-way hash (SHA-256) of your photo. The hash cannot be turned back into your photo; we use it only to recognise a re-uploaded image and avoid reprocessing it. These inferred records are kept for 2 days, then deleted by the next successful automated hourly purge for everyone - logged in or not - and under-18 records are purged on a recurring hourly schedule (see the retention schedule below).

Facial analysis data (paid Full Report)

When you spend tokens to generate the Full Report, your photo is sent to Google's Gemini API for qualitative analysis and to generate your AI styling concept. The written report text is generated by Anthropic (Claude) from your analysis and photo. Hairstyle visualizations are rendered by Gemini as well; our earlier hairstyle renderer, Replicate, is still named in the consent notice but no product currently on sale sends your photo there. When you request a report PDF, your email, your generated images, and your analysis are sent to our PDF provider. All of these transmissions are encrypted in transit. The temporary upload itself is deleted within 2 hours. The report you purchased is different: the text results (scores, recommendations, inferred attributes), the AI-generated visualization images, and a private downscaled copy of your original photo plus feature close-ups (stored so before-and-after comparisons and feature figures in your report keep working) are saved so you can return to them. Free scan results are kept for 2 days, then deleted by the next successful automated daily purge; a purchased report is kept until you delete it (or delete your account), and in any case no longer than 12 months after it is created. See §5 for the full list of these providers and what each receives.

Account information

When you create an account, we collect only your email address. Sign-in is by a one-time login link sent to that address - we do not store a password. Account data is managed by Supabase. You can also give us just your email - with no account - to receive or save your results; see the retention schedule below for how long it is kept.

Feedback surveys

Occasionally we ask a short, optional survey (for example, why you decided not to buy). If you answer, we store your choices and any free-text you write, linked to the email you provided, and set the fr_survey_offer cookie so we don't ask again. Survey answers are used only to improve the product and are deleted together with your email when you delete your data.

Payment information

Payment processing is handled entirely by Stripe. We never see or store your credit card number. From Stripe we receive your Stripe customer ID, your purchase history, and the email address you enter at checkout, which we use to deliver your purchase and create your account. We also attach order details to the checkout session - a reference to your analysis and, if you arrived from an ad, the ad-click identifiers described under Advertising measurement below - so we can fulfil the order and measure our marketing.

Automatically collected data

Beyond what you actively submit, we and our providers automatically collect the following:

  • Cookies and local identifiers. We set first-party cookies that record your cookie choice, your biometric-processing consent, the result of the age screen, whether you used the email gate, and referral attribution (fr_ref, 7 days). If you arrive from an ad or campaign link we also set fr_acq, a 90-day first-party cookie recording where you came from (ad-click identifiers such as gclid/fbclid, campaign tags, the referring site, and your landing page) so we can attribute purchases to our marketing. If we show you a one-question feedback survey we set fr_survey_offer so we don't ask twice. We also set fr_anon_session, a session identifier that lasts up to 1 year and lets us link your saved results, any email you provide, and any referral activity back to the same anonymous session so you can return to your results. If you accept analytics cookies, the Meta pixel also sets its advertising-measurement cookies (_fbp, and _fbc after clicking one of our Facebook ads) and Google Analytics sets its _ga cookies. Separately from cookies, we use your browser's storage on your own device: session storage (cleared when you close the tab) to hand a photo from one tool to the next and to remember one-time prompts, and local storage to keep you in the same variant of any product experiment and to avoid counting a purchase twice. None of this is sent to us.
  • Device and network data. We store your browser's user-agent string, and we use your IP address for abuse prevention and rate-limiting (kept only as a one-way, salted hash that expires within a day). We use a coarse, country-level location signal derived from your IP to decide which features, payments, and consent prompts to show in your region.
  • Product-usage events. We record in-app events (which tools and pages you use, where people get stuck, and result values such as a tool's overall score, your color season, or an individual measurement like your symmetry score, canthal-tilt angle, or pupillary distance) to understand aggregate usage.
  • Analytics providers. We use Google Analytics (GA4) for aggregate product analytics (page views and the in-app events above, which can include the result and measurement values described there - no photo, no session replay or screen recording) and Microsoft Clarity for aggregate usage analytics (page views, clicks, scrolls, referrers and the search terms that led you here). Clarity is configured to mask the entire page, so no on-screen text or image - including your photo or result - is uploaded to it. In the EEA and UK both load only after you accept analytics cookies.
  • Advertising measurement. We use the Meta (Facebook) pixel and Meta's Conversions API to measure whether our ads led to a visit or purchase. Meta receives page views, checkout events, and - on purchase - a one-way hashed version of your email address. It never receives your photo, your analysis, or any biometric data. In the EEA and UK the pixel loads only after you accept analytics cookies.

We do not sell your data, and we never share your photo, analysis results, or any biometric data with advertising platforms.

Referrals (invite links)

If you choose to invite friends to unlock a reward, we generate a unique invite link for you. When someone opens your link we set a short-lived attribution cookie (fr_ref, 7 days) in their browser, and if they complete their own free analysis we record that the referral succeeded. To count referrals fairly we store an opaque session identifier and a one-way, salted hash of the visitor's IP address - never their name, email, or photo. Separately, to prevent abuse and rate-limit requests across the site, we briefly store a one-way, salted hash of a visitor's IP address in our rate-limiting records - never the raw address - and those records expire automatically within a day. You only ever see a count (e.g. "2 of 3 friends joined"), never who joined. This referral data is pseudonymous, used solely to operate and protect the rewards feature (our legitimate interest in preventing fraud), and is removed when you delete your data or when a referred person deletes theirs.

2. Biometric Data Notice

Certain jurisdictions (including Illinois under BIPA, Washington under MHMDA, and the EU under GDPR) classify facial geometry as biometric or special category data. We take this seriously:

  • Geometric tools: Facial landmarks are computed locally in your browser; your photo is never uploaded. Some derived geometric measurements are saved to your results record (see §1).
  • AI tools (perceived age, attribute inference, paid analysis, hairstyle and other image tools): Your photo is temporarily transmitted (encrypted) to our AI providers - Google Gemini (analysis, age estimate, and all image generation, including hairstyles) and Anthropic / Claude (written report text). Replicate is named in the consent notice as a hairstyle renderer but no product currently on sale sends your photo there. When you request a report PDF, a copy of your email, your generated images, and your analysis is sent to our PDF provider. We ask for your explicit consent before your first AI upload - never on a pre-checked box.
  • We do not sell, lease, trade, or otherwise profit from biometric or inferred-attribute data to any third party.
  • AI training: Google Gemini and Anthropic process our inputs under their paid APIs and do not use them to train their models. Replicate processes your image solely to generate the visualization you requested. We do not authorise any provider to train on your facial data.

Retention schedule

  • The photo you upload: deleted within 2 hours of upload, enforced by an automated hourly job. (Free geometric tools never upload your photo at all.) If you purchase a report, a private downscaled copy and feature close-ups are kept as part of that report and follow the purchased- report row below - deletable by you at any time, never longer than 12 months.
  • Inferred attributes & the photo hash: stored with your analysis for 2 days, then deleted by the next successful automated hourly purge - for logged-out and logged-in users alike - with self-reported and detected under-18 records purged on a recurring hourly schedule.
  • Generated report images & results: the AI-generated visualizations and your scores/recommendations from a free scan are kept for 2 days, then deleted by the next successful automated daily purge; for a purchased report they are kept until you delete them (or delete your account/data), and in any case no longer than 12 months after creation - enforced by an automated daily job.
  • Consent records: kept as proof of consent until you delete your data, at which point they are removed too. A consent record that was never linked to an account is deleted automatically 1 year after it was recorded - the lifetime of the session cookie that could identify it.
  • If you give us your email (to receive or save your results): it is stored alongside that analysis until you delete your data or unsubscribe. We use it to send your results, service emails about a purchase or an unfinished checkout, and - only if you opt in - occasional styling tips, which may mention our own related apps (never third-party products). If you opt in to the tips, we also keep a one-line summary of your free result (for example your face shape, score range, or color season) with your email so the tips can reference it; that summary is deleted when the tips series ends, when you unsubscribe, or when you delete your data. After a purchase we may also send a few emails about getting the most from what you bought. Every such email except receipts and login links includes an unsubscribe link, and your email is never sold or shared.

Withdraw consent & delete your data, yourself: you can permanently delete everything we hold about you - and withdraw your biometric-processing consent - at any time from Delete my data. This removes your analyses, inferred attributes, photo hash, email, consent records, and referral data - no email required. You can also contact contact@thefacereport.com.

3. How We Use Your Information

  • To provide facial analysis results and recommendations
  • To personalise recommendations (e.g. skincare ingredients, hairstyles, color palettes) using the visible attributes inferred from your photo
  • To generate your AI styling concept (paid feature)
  • To manage your account and token balance
  • To store your analysis history so you can track progress
  • To produce aggregate, de-identified analytics and statistics (e.g. distributions of analysis scores, face shapes, or inferred attributes across users) used to improve the product and to publish anonymous research, statistics, or educational content. Any published figures are reported only in aggregate and never include personal data, photos, or individual results.
  • To respond to support requests

We do not use your data for advertising or to sell to third parties, and we do not make automated decisions with legal or similarly significant effects about you. To keep your results and rewards available across visits, we do link your anonymous activity to a session identifier for up to one year, as described in §1, and we record which ad or campaign link brought you here (the 90-day fr_acq attribution cookie) to measure our marketing. We do not build advertising profiles from your photo, analysis, or biometric data.

4. Data Retention

  • Uploaded photos: deleted within 2 hours of upload, except the private copy kept with a report you purchased (deletable anytime, max 12 months). An automated hourly job enforces the deletion (see the retention schedule).
  • Generated report images & analysis results: the AI visualizations, scores, recommendations, and inferred attributes from a free scan are kept for 2 days, then deleted by the next successful automated daily purge; a purchased report is kept until you delete it (or delete your account), and in any case no longer than 12 months after creation. Logged-out analyses are linked to a random browser session id and, if you used the email gate, to the email you provided - so they are pseudonymous, not fully anonymous. The results page for a free scan is viewable by anyone who has its exact link (that is how your emailed results link works without a login); paid report content on that page is shown only to its owner. Results can be removed sooner anytime via Delete my data.
  • Pseudonymous product-usage events: raw event rows are kept for today plus the previous two complete UTC days. They are deleted only after their daily de-identified aggregates pass an exact parity check.
  • Aggregate analytics: de-identified statistics derived from inferred attributes contain no personal identifiers and may be retained indefinitely.
  • Account & consent data: retained until you request deletion. Database records are removed when you delete; any copies in our hosting provider's routine backups are purged on that provider's rolling backup schedule.

5. Third-Party Services

We use the following third-party services:

  • Supabase - Authentication and database hosting (EU/US servers).
  • Google Gemini API - AI facial analysis, apparent-age estimation, and image generation. Receives your photo. We use the paid API, under which inputs are not used to train Google's models.
  • Anthropic (Claude) - AI generation of your written Full Report. Receives your photo and analysis. Inputs submitted via its API are not used to train Anthropic's models.
  • Replicate - AI hairstyle image generation for a report product that is no longer on sale. It would receive your photo only if that product were re-enabled; no live tool sends your photo there today.
  • Railway (PDF report service) - Generates your downloadable report PDF. Receives your email address, your AI-generated report images, and your analysis to assemble the PDF.
  • Cloudflare R2 - Encrypted storage of generated report images. Cloudflare also serves the static analysis-runtime files (MediaPipe) for our on-device tools from our own assets domain, so loading them reaches no third-party CDN.
  • Stripe - Payment processing.
  • Resend - Transactional and opt-in marketing email (login links, report delivery, and glow-up or color styling tips - which may mention our own apps - for those who opt in).
  • Slack (Salesforce) - Internal operator notifications. Our team receives alerts about purchases and system errors that may include your email address, an account identifier, and any short feedback text you submit about your report (never your photo or analysis).
  • Google Analytics (GA4) - Aggregate product-usage analytics (not used for advertising); in the EEA/UK it loads only after you accept analytics cookies.
  • Microsoft Clarity - Aggregate usage analytics (page views, clicks, scrolls, referrers and search terms). All page content is masked before upload, so it never receives your photo, result, or any on-screen text. In the EEA/UK it loads only after you accept analytics cookies.
  • Meta (Facebook) - Advertising measurement via the Meta pixel and Conversions API: page views, checkout events, and on purchase a one-way hashed email address (never your photo, analysis, or biometric data). In the EEA/UK the pixel loads only after you accept analytics cookies.
  • Amazon Associates - some of our style guides include affiliate links to Amazon products. If you click one, Amazon knows you came from our site and sets its own cookies; we earn a commission on qualifying purchases. No photo or analysis data is shared with Amazon.
  • Vercel - Website hosting; provides the coarse, country-level location signal used for regional gating.

Each service processes data according to their own privacy policies. We select services that meet high data protection standards.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data and account
  • Export your data in a portable format
  • Withdraw consent for biometric data processing at any time
  • Object to processing of your data

You can delete your data and withdraw consent yourself at Delete my data. To exercise any other right - access, correction, a portable export, or objection - contact us at contact@thefacereport.com and we will respond within 30 days. Parents/guardians: if you believe your child has used the service, contact the same address and we will delete the child's data on request.

7. Children's Privacy

The Face Report is intended for adults aged 18 and older. Before you can use our AI tools (the perceived-age estimate, Full Analysis, Skin Analysis, Color Analysis, and image generation), you must confirm your age by entering your year of birth, which we validate on our servers before your photo is sent to any AI provider - we store only whether you are old enough, not the year itself. Age is self-reported - we do not verify it against identification - so someone who enters a false year could bypass this check.

Our AI also estimates apparent age from your photo as one of its outputs. If your self-reported age is under 18, the AI tools do not run for you - you can still use our on-device geometric tools, which never upload your photo. If the apparent-age estimate indicates a likely minor, we do not save the inferred attributes from that photo.

We do not direct this service to children under 13, and it is not designed for them. We do not seek to collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 - including a facial image or facial geometry - we will delete it. If you are a parent or guardian and believe your child has provided us personal information, contact contact@thefacereport.com and we will delete the child's data on request.

How minor-related data is removed: uploaded photos are deleted within 2 hours by an automated job; inferred-attribute records placed in an under-18 age band are purged automatically on a recurring (hourly) schedule rather than instantaneously; and you can delete everything yourself at any time from Delete my data.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on our website. The "Last updated" date at the top reflects the most recent revision.

9. Contact

The Face Report is operated by Known by One, LLC · 131 Continental Dr, Suite 305, Newark, DE 19713, which is the data controller for the personal data described in this policy.

For questions about this Privacy Policy or your data, contact us at:

contact@thefacereport.com