FACE CHECK ← Back to home

Privacy & data handling

Last updated 15 June 2026

This is a plain-language summary of how Face Check handles your data, written to be accurate and readable. It will be superseded by formal, counsel-reviewed terms before general availability; where the two differ, the final terms govern.

Who we are

Face Check is operated by Appanzee Inc. (appanzee.com), the data controller for the service. Face Check is a forensic-audit tool: it scans a video you provide for faces and searches public sources for matching images. It surfaces candidates for review — it never asserts an identity as fact.

What we collect

  • Your account: the work email you sign in with. We use it only to send your single-use sign-in link and service notices — no passwords, no marketing lists.
  • How you found us: if you arrive from one of our ads or a referring link, we record the campaign tags on that link (the utm_* parameters, an ad click id, and the referring site) and attach them to your account. This is marketing measurement only — it lets us see which campaigns bring people to Face Check; it is never sold or shared.
  • What you upload: the source video you submit, an audit name, and your confirmation that you have a lawful basis to process the footage.
  • What we derive from it: sampled still frames, cropped face images, face clusters, the results returned by our search engine, and an append-only audit log of actions taken.
  • Technical: inside the app, one session cookie to keep you signed in, plus basic server logs. Our public marketing pages also set analytics and advertising cookies (see “Analytics on our public site” below) — the signed-in app and your reports do not.

How your video is analysed — and what leaves our servers

Your video is processed on our servers. We do not send your video file to any third party. What we do send, drawn from it:

  • Still frames and cropped faces → Google (Gemini vision API). To detect and describe the faces and figures in your footage, we send individual frames and face crops to Google's Gemini API. For content our on-device detector can't resolve on its own — for example stylised or animated frames — we send the full frame. This processing is subject to Google's API terms.
  • A candidate name (text) → Google Search and Wikidata. If the analysis proposes a possible public-figure name, we check that name against public web sources to confirm or refute it. A refuted name is dropped; a confirmed one is still presented as a candidate for your review, never a determination.
  • A named finding's face crop → TinEye (higher tiers only). To corroborate where an identified face already appears online, we send that crop to TinEye's reverse-image-search API. This is supporting evidence, never an identity claim, and is subject to TinEye's terms.

Face embeddings — the numeric vectors used to group and compare faces — are computed in memory and are never stored. The primary search engine is the Google Gemini vision API described above; the TinEye corroboration runs only on higher subscription tiers. (Google Cloud Vision remains retired.)

Who processes data on our behalf

  • Google — Gemini vision API (frame and face analysis) and Google Search grounding (name verification).
  • TinEye — reverse-image-search corroboration on higher tiers; receives a named finding's face crop only.
  • Wikidata / Wikimedia Commons — public reference portraits used to verify a proposed name.
  • Mailgun — delivers your sign-in and service emails; receives your email address only.
  • Stripe — processes subscription payments. You enter your card on Stripe's own hosted checkout, so your card number never touches our servers; we receive only your subscription status and the billing email you provide.
  • Google Analytics & Meta — traffic and ad measurement on our public marketing pages only (see “Analytics on our public site”).
  • Our hosting provider — runs the service and stores your data at rest.

Each operates under its own terms; we don't control their practices.

Analytics on our public site

On our public marketing pages (the home page, the blog, and this policy) we use Google Tag Manager to load Google Analytics (GA4) and the Meta pixel. They measure traffic and help us understand which ads bring people here; they set cookies and share usage data (such as the pages you view) with Google and Meta under their respective terms.

These tags run only on our public pages — never inside the signed-in app and never on your Due Diligence Reports. You can opt out with Google's Analytics opt-out and your browser / Meta ad-preference controls; a site-wide consent control is on our near-term roadmap.

Keeping and deleting your data

  • You can delete an audit at any time. Deletion removes its source video, sampled frames, face crops, and search results from our active systems.
  • For accurate billing, a small append-only usage ledger is kept even after an audit is deleted. It records what was charged — not your video, frames, or faces.
  • The audit log (who did what, and when) is retained as an integrity record.

Your responsibilities and your rights

You confirm, when you create an audit, that you have a lawful basis to process the footage. You remain the controller of your video; we process it on your instruction. You can request access to, export of, or deletion of your data — contact us and we'll help.

Changes & contact

We'll post any change to this page and update the date above. Questions or requests: contact Appanzee Inc. through appanzee.com.

© 2026 Appanzee Inc. Face Check
FACE CHECK

The audit trail for AI-generated video.

How it works Blog Run an audit
Engine-returned metadata only — never an identity claim. Every finding carries a hash, a timestamp, and the engine that returned it. Independent verification recommended for any identification.
© 2026 Appanzee Inc. Privacy
A forensic-audit record for review — not a determination of identity.