FaceRead AI (faceread.live)
FaceRead AI ("Company," "we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website faceread.live and related services.
Data Received: Facial photo + extracted features
Purpose: Generate personality narrative text
Retention: Up to 30 days (default policy), 0 days with ZDR option
Data Usage: Not used for AI training (Enterprise Terms) ✓
Security: Encrypted transmission & storage ✓
Data Received: Facial photo
Purpose: Extract facial features and geometry
Retention: Up to 30 days (non-enterprise), Session-only (guest users)
Security: Encrypted transmission & storage ✓
Data Received: Payment information only (NOT photos or analysis)
Purpose: Process credit card payments securely
Compliance: PCI DSS Level 1 certified ✓
Note: You never directly share card info with us
Data Received: User accounts, analysis results, session data
Purpose: Store user data and application state
Photo Storage: Temporary storage during analysis (deleted within 24 hours)
Security: Row-level security, encrypted at rest ✓
Compliance: SOC 2 Type II, GDPR compliant ✓
Data Received: All application data including uploaded photos, biometric features, analysis results, user accounts, and HTTP requests
Purpose: Host and serve the entire FaceRead web application
Data Location: US West (California, USA)
Infrastructure: Node.js 22.x runtime, up to 8 vCPU / 8GB memory
Security: Automatic HTTPS (faceread.live), encrypted transmission & storage ✓
Important: Railway hosts the application server that temporarily processes your photos before sending to AI services (OpenAI/xAI)
Your facial geometry (facial features, proportions, patterns) extracted from your photograph qualifies as "biometric information" under:
| Data | Retention | Destruction Method |
|---|---|---|
| Original Photo | Deleted within 24 hours | Secure deletion (cryptographic erasure) |
| Facial Features | Deleted immediately after analysis | Automatic purge from all systems |
| Analysis Results | Retained 180 days | Then automatically deleted |
For Illinois Residents:
For EU/EEA Residents:
| Data Type | Retention Period | Purpose/Reason |
|---|---|---|
| Facial photos | 24 hours maximum | Analysis processing only |
| Facial features | Immediately | Temporary extraction for analysis |
| Analysis results | 180 days | User access to downloadable results |
| Transaction records | 7 years | Tax compliance and legal records |
| IP logs/access logs | 30 days | Security and abuse prevention |
Request a copy of your personal data
Request correction of inaccurate data
"Right to be Forgotten" - Request deletion
Receive data in machine-readable format
Object to processing based on legitimate interests
Withdraw biometric processing consent anytime
Know what information is collected and how it's used
Request deletion of personal information
Opt-out of sale or sharing (we don't sell data)
We cannot discriminate for exercising rights
Email Request: Send to cimbolicproductions@gmail.com
Response Timeline: Within 30 days (GDPR) or 45 days (CCPA)
Verification: We may request identity confirmation
In the unlikely event of a data breach, we will notify affected users and relevant authorities within the legally required timeframes (GDPR: 72 hours to supervisory authority, CCPA: without unreasonable delay).
For privacy inquiries, rights requests, or concerns:
Last Updated: January 11, 2026 • Version 1.0 • Effective Date: January 11, 2026
Also see our Terms of Service