Trust center
Privacy Policy
Effective July 23, 2026
Short version: the free analysis stays in your browser. For a paid report, you explicitly consent to one zero-data-retention model request. We never store the original photo, and derived facial report data expires after 30 days.
Who this policy covers
This policy applies to AI Face Analyzer at aifaceanalyzer.online. The service is intended only for adults aged 18 or older who use their own photo or a photo they have the right to use.
Free local analysis
When you choose a photo for a free analysis, a MediaPipe face-landmark model runs in your browser. The photo and resulting landmark calculations do not need to be transmitted to our server. We may collect an analytics event that an analysis completed and the selected tool mode, but that event does not contain the photo or face landmarks.
Temporary browser storage
If you choose to buy a report, the selected photo and measurements may be placed in your browser’s IndexedDB so the process can resume after Stripe checkout. This browser copy expires after two hours and is cleared after a successful upload. It remains on the device you are using and is not readable by Stripe.
Paid report processing
After payment is confirmed by a signed webhook and you provide explicit consent, the photo is sent once to our visual model provider through OpenRouter routing configured to require zero data retention, deny data collection and use a provider that supports the requested parameters. The selected model is Google Gemini 2.5 Flash. AI Face Analyzer processes the photo in server memory for the request and does not write the original image to storage.
No technical control can eliminate every infrastructure risk. Zero-data-retention means the chosen provider endpoint contractually and technically accepts the request without retaining prompt or image content for later use; it does not mean the internet connection itself ceases to exist.
Data we retain
- Account data supplied through Google sign-in: name, email address and profile image URL.
- Order records: order number, amount, currency, payment status, purchase-consent version and Stripe identifiers required for fulfillment, payment returns, disputes and accounting.
- Derived report data: facial ratios, report text, model version, generation state and timestamps.
- Basic product analytics such as analysis completion, checkout start, purchase, report generation and PDF download.
Derived facial measurements and report content are retained for 30 days after generation, then removed by a protected cleanup process. Financial order records may be retained as required for legal, tax, fraud-prevention and dispute purposes.
What we do not infer
The report is instructed not to infer or state age, race, ethnicity, nationality, gender identity, health, medical conditions, mental state, emotion, identity or socioeconomic status. We do not provide face recognition, medical diagnosis, skin diagnosis or procedure recommendations.
Service providers
We use Google for authentication, Stripe for payment processing, OpenRouter and its selected ZDR model endpoint for paid report generation, a PostgreSQL hosting provider for account/report data, Vercel or an equivalent web host, and Google Analytics 4 for product analytics. Each provider processes limited data for its assigned function under its own terms.
Your choices and rights
You can decline the paid model transfer and continue using the free local tools. You may request access to or deletion of stored derived report data, subject to records we must retain. If payment is returned because the report could not be delivered, any derived facial data for that report is deleted.
Security and children
We use authenticated account access, HTTPS, server-controlled pricing, signed payment webhooks and restricted administrative jobs. No system is perfectly secure. The service is not directed to children, and we do not knowingly accept photos for analysis from users under 18.
Contact and changes
For privacy or deletion requests, email [email protected]. We may update this policy as the service changes; the effective date above identifies the current version.