Privacy policy
This policy describes what Sherlock AI Face Search collects and why. It is written to match how the product actually works, not to describe an ideal we do not meet.
What runs where
Face detection, alignment, and faceprint generation run entirely in your browser using models your device downloads once (about 16 MB total). Your photo is never transmitted to our servers by default. The only data that reaches us during a search is the faceprint: a list of 512 floating-point numbers. We cannot reconstruct your photo from it.
Faceprint retention
The query faceprint is transient. It is used to run the search and is not persisted afterward. We store the search results (image URLs and source pages) so you can revisit a past search, but we store neither the photo nor the embedding by default.
Account data
If you create an account we store your email, credit balance, plan, and a Stripe customer reference. Authentication is handled by Supabase. Payments are handled by Stripe; we never see your card number.
Biometric data and the law
A faceprint is biometric data. In the EU it is a special category under GDPR Article 9. In Illinois it is governed by the Biometric Information Privacy Act. We geo-block Illinois and Texas until we meet those statutes. See the biometric notice for specifics.
Deletion and removal
You can delete your account and all associated data from your account page at any time. To keep a face out of search results entirely, submit a request at /remove — no account required.
What we do not do
We do not sell data, we do not attach names or contact details to faces, and we do not build profiles. The product returns images and source URLs only.