Sherlock Ai

Legal

Privacy Policy

Effective 25 July 2026 · Version 1.0

1. Summary

Sherlock Ai has no accounts. We never ask for your name, email address or phone number, and we cannot connect a search to a real person.

  • The photo you pick is sent to our search provider to run one search, then deleted. We never store it.
  • Your search history and result thumbnails are stored only on your device. We cannot read them.
  • We keep a random identifier generated by your device so we know how many search credits you have. It is not linked to your identity.
  • We do not sell data, run advertising, or build identity profiles.
  • We do not use your photos to train any model.

This summary is for orientation only; the sections below are the operative terms.

2. Who we are

Sherlock Ai (the “App”) is developed and operated by Mustafa Demir, an individual developer established in the Republic of Türkiye, acting as the data controller for the processing described here.

Contact: support@facesearchai.app

3. Your photo and facial data

A face image is biometric data. Under the EU/UK GDPR it is a special category of personal data, and several jurisdictions (for example Illinois' BIPA and Texas' CUBI in the United States) regulate it specifically. We treat it accordingly.

What happens during a search

  • You pick a photo and position the face inside the reticle. The App crops and resizes it on your device before anything leaves it.
  • The cropped image is sent over an encrypted connection to our backend, which immediately forwards it to FaceCheck.ID, our third-party face search provider.
  • FaceCheck.ID compares it against its index of publicly available images and returns matching pages with a similarity score.
  • As soon as the search completes, fails, times out, or you cancel it, our backend instructs FaceCheck.ID to delete the uploaded image.
  • Our backend never writes the image to a database, disk or log. It exists only in the memory of the request that carries it.

What we do not do

  • We do not generate, store or compare face templates ourselves.
  • We do not attempt to identify, name or profile the person in the photo.
  • We do not retain the photo after the search, and we do not use it for training, analytics or any secondary purpose.

Your consent

Before your first search the App asks you to confirm, explicitly and separately, that you understand your photo will be uploaded to FaceCheck.ID and deleted right afterwards. That confirmation is your explicit consent under Article 9(2)(a) GDPR. You can withdraw it at any time by ceasing to use the search feature and deleting your data (section 9); withdrawal does not affect searches already completed.

You also confirm that you have the right to search the photo you submit. See section 3 of the Terms of Use.

4. What else we process

Data Why Where it lives
Device identifier — a random UUID generated on your device To hold your credit balance, apply daily search limits, and run the invite programme. It is not derived from any hardware ID and tells us nothing about you. Your device, your iCloud Keychain (so credits survive a reinstall), and our server
Credit balance and purchase grants To know how many searches you have left Our server (Upstash Redis)
Search state — an internal search ID, status and timestamp To let the App poll for a result and to charge exactly one credit per completed search Our server, deleted automatically after 1 hour
Purchase receipts To unlock credits and subscriptions Apple and RevenueCat. We never see your payment card, billing address or Apple ID.
Invite code and referral counts To credit you when a friend joins with your code Our server
Crash reports and diagnostics To find and fix crashes Google Firebase Crashlytics
Aggregate usage events — screens opened, features used To understand which parts of the App are used. Not tied to your identity and never containing your photo or results. Google Firebase Analytics
Push notification token To tell you when a long-running search has finished, if you allow notifications OneSignal and Apple Push Notification service
Search history, result links and thumbnails So you can revisit past searches Your device only. Never uploaded to us.

We do not operate advertising SDKs, we do not track you across other apps or websites, and we do not sell or share personal information as those terms are defined by the California Consumer Privacy Act.

5. Legal bases for processing

  • Explicit consent (Art. 6(1)(a) and 9(2)(a) GDPR) — for processing the facial image you submit, and for push notifications.
  • Performance of a contract (Art. 6(1)(b)) — for the credit ledger, purchases and the invite programme, which are the service you asked for.
  • Legitimate interests (Art. 6(1)(f)) — for rate limiting, abuse prevention and crash diagnostics, so the service stays available and stable. We have balanced these against your rights and use the minimum data required.

6. Who receives data

We use a small number of processors, each for one clearly bounded purpose. None of them receives more than what is listed here, and none of them is permitted to use it for their own purposes beyond their own terms.

  • FaceCheck.ID — receives the cropped photo to run the search. See facecheck.id for their own policies.
  • Vercel — hosts our backend and this website.
  • Upstash — stores the credit ledger and search state.
  • Apple and RevenueCat — process purchases and subscription status.
  • Google Firebase — crash reporting and aggregate analytics.
  • OneSignal — delivers push notifications.

This website loads no third-party fonts, scripts, trackers or cookies. It sets no cookies at all.

7. How long we keep things

Data Retention
The photo you submit Deleted from the search provider immediately after the search ends. Never stored by us.
Search state record Automatically deleted 1 hour after the search starts
Credit balance, invite code Kept while the identifier is in use, so your paid credits remain available
Daily rate-limit counters Reset each day
Crash reports Retained by Firebase Crashlytics for up to 90 days
Search history on your device Until you delete it or uninstall the App

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to withdraw consent, and to data portability. EU/UK residents may also lodge a complaint with their local supervisory authority. California residents have the rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of.

Because we deliberately hold no identifying information, we usually cannot locate “your” data from an email alone. To exercise a right against server-side data, send us your device identifier: open Account in the App and tap the RevenueCat ID row to copy it in full. Without it we have no way to tell your record apart from anyone else's — a limitation of the privacy design, not a refusal.

We respond to requests within 30 days.

9. Deleting your data

  • On your device: open Account → Delete my data to erase your search history, thumbnails and stored preferences. Uninstalling the App also removes them.
  • On our server: email us with your device identifier and we will delete the credit ledger entry, invite mapping and any counters tied to it. Note that this also destroys any unused paid credits.
  • Your photo: nothing to do — it is already gone.

If you have used iCloud Keychain, your device identifier may be restored from iCloud after a reinstall. To break that link, delete your data as above and then remove the App's keychain entry from your iCloud settings.

10. International transfers

Our processors operate in the United States and the European Union, so your data may be processed outside your country of residence. Where data leaves the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable to each processor.

11. Children

Sherlock Ai is not intended for anyone under 17 and we do not knowingly process data from children. If you believe a child has used the App, contact us and we will delete the associated records.

12. Changes to this policy

If we change how we handle data we will update this page and its effective date. For changes that materially affect you, we will also surface a notice inside the App before the change takes effect.

13. Contact

Privacy enquiries

support@facesearchai.app

For takedown or removal requests about a page that appeared in your results, use the report channel instead — it explains what we can and cannot remove.