Privacy Policy
Last updated: July 2026
profesh helps you find the photos you appear in within a Google Drive album, using face matching. This policy explains what we collect, how we use it, and the choices you have — with particular care for the biometric data involved.
Information we collect
- Selfies you upload, used to build a face profile for matching.
- The Google Drive album link you provide, and the photos we read from it to search.
- An optional email address, only if you give one, to notify you when results are ready.
- Basic technical data (IP address, request logs) for security, rate-limiting, and abuse prevention.
Biometric information
To find you, we compute a mathematical representation (a “face embedding”) from your selfies and from faces in the album photos. These embeddings are biometric identifiers. We use them solely to match faces for your request. We never use them to identify you on other services, build a searchable database of faces, sell them, or disclose them to third parties for their own purposes.
Consent. We create these embeddings only after you submit a search, which is your express consent to this processing. You can withdraw consent at any time by contacting us; withdrawal stops future processing and triggers deletion of any data still held.
Retention & destruction schedule. Face embeddings are transient — they are held only in memory for the duration of a search and are not stored afterward. Uploaded selfies and generated results are permanently deleted within a few days of your job completing, or sooner on request.
How we use your information
We use your data only to run your search and return your results, to email you (if you opted in) when they’re ready, and to keep the service secure and reliable. We do not use your data for advertising, profiling, or training general-purpose models.
Legal basis
Where the GDPR or similar laws apply, our legal basis for processing your selfies and face embeddings (special-category biometric data) is your explicit consent. For technical data used to secure the service, our basis is our legitimate interest in preventing abuse.
Retention & deletion
Uploaded selfies and results are automatically deleted a short time after your job completes (by default within a few days). Embeddings are not retained after matching. You can request earlier deletion at any time via our contact page.
Sharing & third parties
We access the Google Drive folder you link in order to read its photos, and we run face matching on cloud compute infrastructure that acts as our processor under confidentiality obligations. We do not sell your data or share it for advertising. We may disclose information if required by law or to protect the rights and safety of users.
Security
Data is transmitted over encrypted connections and access is limited to what’s needed to run your search. Because we retain data only briefly, the window in which it exists is deliberately small. No method of transmission or storage is perfectly secure, but we work to protect your information commensurate with its sensitivity.
Your rights & choices
Providing selfies is required to use the service; providing an email is optional. Depending on where you live, you may have the right to access, correct, delete, or export your data, to withdraw consent, and to lodge a complaint with your data protection authority. Exercise any of these through our contact page.
Children
The service is not directed to children and is intended for adults. Do not upload selfies of, or attempt to identify, minors. We do not knowingly collect data from children; if you believe a child’s data has been submitted, contact us and we will delete it.
International transfers
Your data may be processed on servers located in other countries. Where required, we rely on appropriate safeguards for such transfers. Given the brief retention period, data does not persist in any region beyond your search.
Changes & contact
We may update this policy; material changes will be reflected by the date above. Questions or requests? Reach us via our contact page.