Privacy policy
Last updated 28 July 2026.
What this service does
Photographers upload event photographs. The system detects faces in those photographs and stores a mathematical signature — an embedding — for each one. A guest submits a selfie, the same kind of signature is computed from it, and the two are compared to find the photographs that guest appears in.
This is face similarity matching within a single event. It is not identification, and it does not tell us who anyone is.
Guest selfies
- A selfie is only ever processed after the guest has explicitly consented on the event page.
- The image file is deleted as soon as its signature is computed — before the results are shown. A cleanup job removes anything left behind by an interrupted upload.
- The signature is used for that one search, inside that one event, and is never compared against any other event.
- No profile is created. Guest sessions are anonymous and expire.
- Selfies are never used to train any model.
Event photographs
Photographs belong to the photographer who uploaded them. Face signatures derived from them are stored alongside the event and are deleted automatically when the photograph or the event is deleted. Signatures never leave the server and are never returned by any part of the interface.
How long events stay available
Events are removed from the public directory after their listing period — a minimum of 30 days from creation, depending on the photographer's package. Once that period passes, guest search for that event stops and it no longer appears anywhere publicly.
Photographs are not deleted when this happens. They remain in the photographer's account until the photographer chooses to delete them. Deleting an event erases its photographs and every derived face signature permanently.
- Basic — listed for 30 days
- Standard — listed for 60 days
- Premium — listed for 90 days
What else we store
- Account details for photographers: email address, name, organization, and a hashed password. Passwords are never stored in a readable form.
- Guest visits are recorded without identity. IP addresses and browser identifiers are stored only as irreversible hashes, for abuse prevention.
- Administrative actions are written to an audit log, including any access to privacy-sensitive reports.
Accuracy
Face matching is probabilistic. It can miss photographs a guest appears in, and it can occasionally return a photograph of someone else who looks similar. Photographers can tune the strictness for their own events. If you find a photograph of yourself that you want removed, contact the photographer who ran the event — they control the gallery.
Third parties
Face detection and matching run on this server using open models. No photograph and no selfie is sent to any third-party recognition service. There is no advertising and no analytics tracking of guests.
Requests and contact
To ask what is held about you, or to have something removed, contact the photographer who ran your event, or the service operator. Requests concerning a specific photograph are always handled by the photographer who owns it.
