Back to home

Legal

Privacy Notice

This notice explains how we process personal information when you use the deepface.dev website, public test studio, dashboard, and API.

Effective date: August 11, 2026

1) Who we are

deepface.dev is a product of Tech Local (Pty) Ltd (reg. no. 2025/315373/07), 18 Rosyth Road, Nahoon, East London, Eastern Cape, 5241, South Africa.

Privacy questions and data rights requests can be sent to hello@deepface.dev.

2) Roles and responsibilities

We act as the controller for account, billing, and website data. When you send face data to our API, we generally act as a processor on your behalf. You are responsible for determining a lawful basis to collect and submit that data and for meeting notice and consent requirements in your region.

For the public test studio on the marketing site, we act as the controller for preview access, quota enforcement, and abuse-prevention data used to protect the service.

Information Officer (POPIA): Devin Stickells, Director, hello@deepface.dev.

3) What we collect

  • Account data: name, email, company, role, and authentication details.
  • Billing data: billing address, tax information, PayFast payment status, and invoices (payment card data is processed by the payment provider, not stored by us).
  • API content: face images, embeddings, vectors, labels, and metadata you submit for verification, embedding generation, or vector comparison.
  • Usage data: request timestamps, endpoints, usage volume, latency, response size, and diagnostics for reliability and abuse prevention.
  • Preview identity data: a signed tester identity cookie plus hashed IP and user-agent values used to enforce public preview limits and detect abuse.
  • Support communications:messages you send to our team by email or chat.
  • Consent preferences: your opt-in/opt-out settings for analytics tracking, session replay, product updates emails, and marketing emails.

4) How we use data and legal bases

  • Provide the service: run verification, embedding, and vector comparison workflows (contract).
  • Secure the platform: detect abuse, protect accounts, and maintain reliability (legitimate interests, legal obligations).
  • Manage billing: process credit top-ups, invoices, payment reconciliation, and tax records (contract, legal obligations).
  • Customer support: answer requests and troubleshoot issues (contract, legitimate interests).
  • Product improvement:analytics and replay (enabled by default for authenticated users, and adjustable in account settings) to improve product quality and troubleshooting (consent/preference management).
  • Marketing: according to your saved communication preferences (consent/preference management).

5) Biometric and face data

Face images and embeddings are biometric data in many jurisdictions. We process this data only on your instructions and do not use customer data to train models. You are responsible for obtaining any required notices, consents, or lawful bases before submitting face data to our API.

The same rule applies when you use the public test studio: submitted images are processed to return the requested result and to enforce preview-abuse controls, not to train models.

Content submitted to synchronous API requests is not retained after processing completes. Content submitted to an enabled asynchronous workflow is held temporarily in the processing queue and is cleared immediately after success or final failure. Unfinished queued content is automatically cleared within 24 hours.

6) Sharing and subprocessors

We use a limited set of vendors for hosting, storage, authentication, payment processing, monitoring, and communications. They may process data on our behalf under confidentiality and data protection terms. We maintain our current list on the Subprocessors page.

7) International data transfers

Our providers may process data in the regions where they operate, which can include the United States, the EU, and South Africa. Where required, we rely on safeguards such as Standard Contractual Clauses.

8) Retention

Async job results and limited non-content job metadata may remain available for up to 7 days so customers can retrieve results. Raw error and security records are retained for up to 180 days, detailed API usage records for up to 18 months, and derived billing and accounting records for up to 5 years. These periods may be extended where required by law, an active dispute, a fraud investigation, or a documented legal hold. Our payment processor may independently retain payment and transaction information for up to 7 years where required by its legal, regulatory, and contractual obligations. Signed preview identity cookies can remain on your device for up to 12 months unless you clear them earlier; their server-side quota hashes are retained for no more than 180 days.

Consent-controlled PostHog product analytics is configured without person profiles, persistent browser identity, GeoIP enrichment, or deepface.dev user and account identifiers. Only allowlisted, non-account-linked interaction metadata is sent. PostHog may retain that event metadata under its standard service controls; it is not submitted API content or a detailed API usage record. Separately enabled, masked session replays are retained for up to 30 days.

We do not use submitted API content for analytics, advertising, model training, monitoring samples, or any unrelated purpose. Temporary processing files use ephemeral infrastructure and are deleted when the request completes.

9) Your rights

Depending on your location, you may request access, correction, deletion, restriction, or portability of your personal data. To exercise these rights, contact hello@deepface.dev.

Authenticated users can manage communication and telemetry consents in account settings. You can withdraw consent at any time, and we will apply the new preference to future processing.

For more information about our use of cookies, see our Cookie Policy.

10) Changes to this notice

We may update this notice as our services evolve. The effective date above reflects the latest version.