Original research / 30 policies / 5 criteria

Where Your Selfie Goes: 30 Face App Policies, Read

Every claim on this page traces to one row of a downloadable dataset, coded from each company's own privacy policy. Our own policy is row one, coded by the same rubric.

Of 30 face-rating and beauty-app privacy policies read on their own pages, 3 state they may train on your photos, 13 are silent on training, 11 offer no stated deletion path, and 20 show no policy date.

Where does an uploaded selfie actually go?

An uploaded selfie goes to one of three places, and the policy tells you which if you read it. In this sample of 30, 6 tools state the photo never leaves your device, 16 state some server retention rule, and 8 accept uploads while stating no retention period at all. Several route the photo onward: AttractivenessTest.net sends it to third-party AI providers it names as OpenRouter and Google Gemini, TheFaceReport sends AI-tool photos to Google's Gemini API, and Lookmax Analyzer sends its optional paid preview to OpenAI. Each of those disclosures is in the tool's own policy, quoted in the dataset.

The strangest finding is the policy with nothing in it. FaceRate.ai rates faces from uploaded photos, and its privacy policy, fetched in full, does not contain the word photo. It covers email handling. What happens to the face you send is not addressed anywhere in the document.

Who says they can train AI on your photos?

Three policies grant themselves training rights in plain words, and 13 of 30 say nothing about training at all. PinkMirror states: "We may use uploaded photos to train or improve machine-learning models." Qoves states it may use your data "to refine machine learning algorithms and various programs." AttractivenessTest.com permits itself anonymized, aggregated data derived from processing images to improve its models, the narrowest of the three grants. Ten policies state some form of we-do-not-train, several with qualifiers worth reading: PFPMaker says it does not "currently" train, and Nanorater rules out training a public model without permission.

The silent 13 include tools that collect the most. Maxxing.me's policy describes collecting facial imagery and facial-geometry biometric data, lists broad sharing with service providers, ad networks and business partners, and states no retention period and no training position. Umax retains selfies and biometric data for as long as the account exists, under a policy dated October 2023, and takes no position on training.

How long do they keep your photo?

Stated retentionTools
Never uploaded (on-device claim)Face Shape Detector, ImageToolsHub, PrettyScale.com, Pretty Scale Me, Lookmax Analyzer (analysis), How Normal Am I, and this site's free scan
2 hoursTheFaceReport (free upload tools)
24 hoursAILabTools (result URL), this site (paid photo, after delivery)
24 to 48 hoursFaceApp, Cutout.pro
7 daysLooksmaxxing AI (images and reports)
Up to 30 daysAttractivenessTest.com (shared results only)
Until you delete it or the accountPinkMirror, Clipfly (input), PFPMaker (account uploads), Umax (selfies and biometrics)
No period stated8 tools, including Maxxing.me, Qoves, Media.io, Overchat AI, Vidnoz and Golden Ratio Face

Golden Ratio Face's policy lists "images uploaded by users" as a category of processed data and then states no retention period, no training position and no deletion path for them. Reversely's policy is silent on retention while its product FAQ separately claims automatic deletion after analysis; the two documents do not match, and the dataset records both.

Three companies, one identical policy

Fotor, Clipfly and Facewow, three brands run by different companies, ship word-for-word identical policy sections built around the same defined term, "Face Data," with the same AWS storage clauses and the same pledge not to train "any other AI products." The same template pattern appeared in our earlier audit of what these tools measure, where Fotor and Clipfly listed identical scoring dimensions in identical order. A privacy promise written by a template is still binding, but it was not written about the product you are using.

Can you delete your photo?

11 of 30 policies give no stated deletion path for an uploaded photo. Thirteen state one, ranging from automatic purges (TheFaceReport's hourly job, FaceApp's 48-hour cache limit, Looksmaxxing AI's 7-day auto-delete) to self-serve dashboards (PinkMirror, Clipfly) to a written right to request removal. The remaining six make deletion moot by never taking the photo. Only 10 of 30 policies display any last-updated date, so for two thirds of these tools there is no way to know whether the promises you read are older than the product's current features.

Method

  • Sample: the 25 tools from our AI face rater audit, plus FaceApp, Perfect Corp, Qoves, Reversely and the How Normal Am I documentary project, 30 external tools total.
  • Every policy was fetched from the tool's own site on September 2, 2026. The dataset records the exact URL and fetch date per row.
  • Coding is text-only: a policy is coded yes or no only where its own words state it. Anything not addressed is coded silent, and silence is reported as silence, never inferred either way.
  • Ambiguous language stays silent. Boilerplate like improving our services was not coded as training permission.
  • Our own policy is row one of the dataset, coded by the same rubric: free scan on-device with no upload, paid photo deleted within 24 hours of delivery, no training, Stripe as the named payment processor.
  • The full coded table is downloadable at /data/selfie-privacy-audit.csv, 31 rows including ours.

Limits

This is an audit of what policies say, not of what companies do. A policy can be violated, and a good practice can go unwritten. Policies also change without notice, which is why every row carries its fetch date and 20 of 30 carrying no date of their own is itself a finding. Perfect Corp's multi-product policy was coded conservatively from its consumer privacy page. PinkMirror's product pages were unreachable on the fetch date; its policy page answered and is coded from that text. If reading this raises something heavier than curiosity about where a photo went, the support resources on the am I pretty page are there for exactly that.

The free scan on this site was built so this audit could not apply to it: the photo is processed by a published formula in your browser and never uploaded, a claim you can verify in your browser's network tab. The full privacy wording is on the privacy page.

Questions people actually ask

Do face rating apps train AI on your photos?

Three of 30 audited policies state they may use your photos or derived data to train machine-learning models: PinkMirror, Qoves and, for aggregated data, AttractivenessTest.com. Thirteen more say nothing about training either way, which is not a promise of anything.

How long do face apps keep your photo?

Stated retention in the 30 audited policies ranges from 2 hours to the lifetime of your account. Eight policies accepting uploads state no retention period at all, and six tools state the photo never leaves your device.

Can you ask a face app to delete your photo?

Only 13 of 30 audited policies state a deletion path, automatic or on request. Eleven policies give no stated way to delete an uploaded photo, and six avoid the question by never uploading it.

What is the safest way to try a face rating tool?

The safest configuration is on-device processing, where the photo never leaves your browser. Six of the 30 audited tools claim it. It is verifiable from your browser's network tab, which shows whether an upload happens.

It measures geometry, not worth. The number tells you where you start. It never tells you what you are.

The standing rule
on every page
of this site

Put this guide to work on your own photo

Run the free scan
Free, in your browser, nothing uploads