Lovelies
Privacy notice

Lovelies privacy policy

Lovelies helps people find photos that may include them by using a consented face profile and a private matched-photo gallery. This policy describes the product data flows implemented in the app and web portals.

Control stays visible

Users can refuse face matching, withdraw consent, request deletion, and report an incorrect match from their profile privacy controls or support route.

Consent firstPrivate galleryDeletion route

Information collected

Lovelies may collect account identifiers, phone verification state, consent records, derived photo-profile samples, profile status, matched photos, gallery actions, subscription entitlement state, dispute requests, support requests, and operational activity needed to provide and protect the service.

How information is used

Information is used to authenticate users, manage biometric consent, create and revoke face profiles, match consenting profiles to uploaded photos, show gallery previews, process disputes, operate subscriptions, prevent abuse, and maintain service health.

Automatic photo identity — Biometric consent

Photo matching is optional and requires explicit consent. The sole enrollment path captures three live front-camera selfies: straight, left, and right. Each image is checked on the device for one clear face, quality, pose, and same-person consistency. The app does not use a motion or anti-spoof challenge or request access to the device Photos library.

Face data use and retention

Raw selfie images are never uploaded. Each temporary camera file is deleted and its in-memory pixels are cleared after local analysis. With consent, only derived face vectors plus privacy-safe model, quality, and processing metadata are synchronized to match the user against photographer-uploaded event photos. Derived profile data is retained while consent remains active. Withdrawing consent or deleting the photo profile immediately stops future matching and deletes user-linked vectors, sample evidence, sync receipts, scan telemetry, and matching jobs. A non-biometric deletion tombstone and security/privacy audit evidence may remain.

Sharing and processors

Supabase stores account, consent, derived profile, match, and audit records in the configured eu-west-1 project. Cloudflare provides API edge services, private R2 event-photo storage, queues, rate limiting, and private event-photo processing. Messaging providers handle phone verification and support messages. These providers act only to deliver the service; raw enrollment selfies and derived vectors are not provided to messaging providers, advertisers, data brokers, or unrelated third parties. Personal information is not sold. Sharing happens only when the user invokes the native share sheet.

Security

The platform uses private storage, signed media access, audit events, access controls, encrypted transport, rate limits, and scoped admin routes. The Android app disables cloud backup and device transfer for local app data.

Deletion and support

Users can request account deletion, face profile deletion, consent withdrawal, privacy export, or incorrect-match review from the app privacy center or the published support channel.

Account deletion