Privacy Policy
Face Seek: AI Face Search, operated by Baan Software.
1. Who we are
Face Seek (“the App”) is operated by Baan Software, a company registered in Singapore (“we”, “us”, “our”). We are the data controller for the personal information described in this policy.
Contact for privacy matters: faceseek@baansoftware.com
2. What this policy covers
This policy explains what information we collect when you use Face Seek, why we collect it, how long we keep it, who we share it with, and what rights you have.
Face Seek performs reverse image search on publicly indexed web images. It is not a background check service, a people-search database, or an identity verification service. Results must not be used for decisions about employment, housing, credit, insurance, or any other purpose regulated by consumer reporting laws.
3. Information we collect
3.1 Photos you submit
When you run a search, you choose a photo from your camera or your photo library. The App detects faces in it on your own device, and sends the photo you selected to our server, which immediately forwards it to our search provider (see section 7) to run the search.
We do not store your photo. It passes through our server in memory and is never written to our databases or file storage. Our search provider holds it for as long as the search record exists on their side; deleting a search in the App instructs them to delete it.
3.2 Facial feature data (biometric information)
To match a face, a search engine converts the face in a photo into a mathematical representation — a numerical vector, sometimes called a face embedding or faceprint. Under several privacy laws this is classified as biometric information and receives special protection.
This conversion is performed by our search provider, not by us. We never receive, see, or store a face vector. The App also runs an on-device face detector (Google ML Kit) so you can pick which face to search; that detector finds the position of a face in the image and runs entirely on your phone. It does not produce a faceprint and nothing from it leaves your device.
Facial feature data is used only to run the search you asked for. We do not use it to build a profile of you, we do not sell it, and we do not add it to any database that other users can search.
See section 6 for the full retention and destruction schedule.
3.3 There is no account
Face Seek does not ask you to register, and we do not collect your name, email address, or a password. When you first open the App it is issued an anonymous identifier by our payments provider. That identifier is what your purchases, your credit balance and your search records are keyed to. It is specific to your install; it does not identify you as a person and we cannot use it to contact you.
On first use the App also obtains a secret token from our server and stores it on your device. The token is what proves a request is yours, so that nobody who guesses your identifier can read your results or spend your credits. We store only a one-way hash of it, never the token itself.
3.4 Purchase information
Subscriptions and purchases are processed by Apple and Google through RevenueCat. We never receive or store your payment card details. We receive a transaction identifier, the product purchased, and your subscription status.
3.5 Search records
For each search we store a record on our servers: the anonymous identifier above, the status of the search, the links and thumbnail images returned by the provider, and whether the results have been unlocked. This is what lets the App show you a result after you close and reopen it. Thumbnails of the results are copied to our content delivery network so the App can display them. Both are deleted after 30 days, or immediately when you delete the search in the App. See section 6.
3.6 Technical logs
Our servers write operational logs: request paths, response codes, timings and error traces. These are used to keep the service running, to debug faults, and to detect abuse and automated scraping. They are retained for 30 days.
3.7 Analytics and crash reports
The App uses Google Firebase Analytics and Firebase Crashlytics. These collect device model, operating system version, app version, language, approximate region derived from your IP address, and events describing how the App is used — screens opened, a search started, a purchase completed. Crashlytics additionally collects a stack trace and device state when the App crashes.
These tools never receive your photos, your search results, or the contents of a search. We use them to understand which parts of the App are used and to fix faults. Firebase assigns its own installation identifier, which is separate from the identifier in section 3.3.
3.8 What we do not collect
We do not collect your precise location. We do not read your contacts, messages, calendar, or health data. We do not scan your photo library beyond the specific image you choose to submit. The App contains no advertising SDK, we do not run ads, and we do not share anything for advertising purposes.
4. How we use your information
| Purpose | Data used |
|---|---|
| Running the face search you requested | Photo |
| Delivering and ranking results | Facial feature vector, computed and held by our search provider |
| Showing you a search you ran earlier | Search record, anonymous identifier |
| Managing your coin balance and subscription | Anonymous identifier, purchase status |
| Preventing abuse, fraud, and automated scraping | Technical logs, anonymous identifier, device token |
| Fixing faults and keeping the service available | Technical logs, crash reports |
| Understanding how the App is used, and improving it | Device and usage information, analytics events |
| Complying with legal obligations | Any of the above, where legally required |
We do not use your photos or facial feature data to train any model, our own or anyone else's, and we do not sell personal information.
5. Legal basis for processing (EEA, UK, Switzerland)
| Processing | Legal basis |
|---|---|
| Processing facial feature data | Your explicit consent under Article 9(2)(a) GDPR, given before your first search |
| Running searches, managing purchases | Performance of a contract, Article 6(1)(b) |
| Abuse prevention, security, service availability | Legitimate interests, Article 6(1)(f) |
| Legal and regulatory compliance | Legal obligation, Article 6(1)(c) |
You may withdraw your consent to biometric processing at any time by emailing faceseek@baansoftware.com, or by deleting the App. Withdrawing consent stops all future searches and triggers deletion of the data described in section 6. It does not affect processing that has already taken place.
6. Retention and destruction schedule
This section is our published retention schedule for biometric identifiers, as required under the Illinois Biometric Information Privacy Act and comparable laws.
| Data | Where it lives | Retention |
|---|---|---|
| Photo you submit | Our search provider | Never stored by us. It is held in memory on our server only for the seconds it takes to forward it, and is never written to our storage. Our provider holds it for the life of the search on their side; deleting the search in the App instructs them to delete it. |
| Facial feature vector | Our search provider | Computed and held by our search provider to run the match. We never receive or store it. |
| Face positions from on-device detection | Your device | Held in memory while you choose a face. Never sent anywhere. |
| Search record: result links, thumbnails, status | Our servers | 30 days, then deleted automatically. Deleting the search in the App deletes it immediately. |
| Result thumbnail images | Our content delivery network | 30 days, then deleted automatically. Deleting the search in the App deletes them immediately. |
| Search history shown in the App | Your device | Stored on your device. Clearing it in the App removes the local copy; the server record still expires on the 30-day schedule above. |
| Coin balance and free-search counter | Our servers | Kept while you use the App, so purchases are not lost. Deleted within 30 days of a deletion request. |
| Purchase records | RevenueCat, Apple, Google | Held by those providers under their own terms, and by us for as long as tax and accounting law requires. |
| Technical logs | Our servers | 30 days, then deleted automatically. |
| Analytics events and crash reports | Google Firebase | Crash reports for 90 days. Analytics events for 14 months, then deleted by Firebase. They contain no photos and no search results. |
| Device token | Your device, and as a one-way hash on our servers | Held while the App is installed. Deleted with the rest of your data on request. |
Biometric identifiers are destroyed at the earlier of: the completion of the purpose for which they were collected, or three years after your last interaction with us.
7. Who we share information with
We share personal information only with service providers who process it on our behalf under contract:
| Provider | Purpose | Data shared |
|---|---|---|
| Amazon Web Services (United States) | Hosting, compute, storage, content delivery | Photos in transit, search records, thumbnails, technical logs |
| FaceCheck.ID | Image matching across publicly indexed web images | The photo you submit, and the facial feature vector they derive from it |
| RevenueCat | Subscription and purchase management | Anonymous identifier, transaction identifiers, subscription status |
| Google Firebase | Analytics and crash reporting | Device and usage information, crash diagnostics. Never photos or search results |
| Apple, Google | Payments and app distribution | Your purchase, handled entirely by them |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We may disclose information if required by a valid legal order, or where necessary to protect our rights or someone's safety.
8. International transfers
We are based in Singapore and our servers run in the United States, so your data is transferred out of the country you are in. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses together with supplementary technical measures. For transfers out of Singapore, we take reasonable steps to satisfy ourselves that each recipient is bound to a standard of protection comparable to the Personal Data Protection Act 2012.
9. Your rights
Regardless of where you live, you may:
- Request a copy of the personal information we hold about you
- Ask us to correct inaccurate information
- Ask us to delete your information
- Withdraw your consent to biometric processing
- Ask us to restrict or object to certain processing
- Receive your data in a portable format
The fastest route for deletion is in the App: deleting a search removes its record, its thumbnails, and instructs our search provider to delete the photo. To exercise any other right, or to have everything associated with your install removed, email faceseek@baansoftware.com — see Delete My Data for what to include. We respond within 30 days.
Because we hold no name, email address, or account for you, we may need the anonymous identifier shown in the App under Settings in order to find your data.
9.1 If you are in the EEA or UK
You also have the right to lodge a complaint with your national supervisory authority.
9.2 If you are in California
You have the rights described above under the CCPA as amended by the CPRA, including the right not to receive discriminatory treatment for exercising them. Facial feature data is treated as sensitive personal information and is used solely to perform the service you requested. We do not sell or share personal information as those terms are defined under California law.
9.3 If you are in Illinois, Texas, or Washington
We obtain your written consent before any biometric identifier is collected or processed, we publish the retention and destruction schedule in section 6, and we do not sell, lease, trade, or otherwise profit from biometric identifiers.
9.4 If you are in Singapore
We are a Singapore organisation and the Personal Data Protection Act 2012 applies to us. You have the right to request access to the personal data we hold about you and information about how it has been used or disclosed in the past year, and the right to request correction of an error or omission. Requests go to the address below, and we respond within 30 days.
10. Photos of other people
Face Seek allows you to search using a photo that may contain a person other than yourself. You are responsible for ensuring you have a lawful basis to submit that photo. Do not use Face Seek to locate, monitor, harass, stalk, or intimidate anyone. See our Acceptable Use Policy.
If a photo of you has been submitted by someone else and you want us to confirm or delete any related record, contact faceseek@baansoftware.com and we will act within 30 days.
11. Children
Face Seek is rated 17+ and is not directed to anyone under 18. We do not knowingly collect information from minors. If you believe a minor has provided us with information, contact faceseek@baansoftware.com and we will delete it.
Do not submit photos of minors.
12. Security
Data is encrypted in transit using TLS and at rest. Our storage is private and reachable only by the service itself; access to production systems is restricted and logged. No system is perfectly secure, but we take reasonable and appropriate measures given the sensitivity of the data involved.
13. Changes to this policy
We will post any changes on this page and update the date at the top. If a change materially affects how we process biometric data, we will ask for your consent again before it takes effect.
14. Contact
Baan Software
faceseek@baansoftware.com