Skip to main content
AI Rate Face
Data processing

Your photo’s path, without vague privacy language.

All free analysis stays on your device. Only the credit-powered Full Report uses cloud photo processing, and only after sign-in, sufficient wallet balance and explicit consent.

18 free tools process locallyPaid photo is not storedFull Report text is savedUpdated: August 15, 2026
An adult portrait card moving from a personal device through transient processing to a report card
Local preparation · transient paid processing · report returned

Short version

Free: no account and no photo upload. Full Report: Google account, sufficient wallet credits, explicit cloud-processing consent, transient photo processing, and saved report text without the photo.

Free analysis: local data flow

  1. You choose a JPG, PNG, WebP, HEIC or HEIF image — or, on the two multi-photo tools, two or three of them. HEIC/HEIF files are converted to JPEG locally in your browser before analysis.
  2. The browser decodes it into an in-memory canvas and loads the site-hosted MediaPipe runtime and Face Landmarker model.
  3. Face detection, landmarks, image-quality checks, geometry calculations and result rendering run on your device.
  4. On the multi-photo tools, every image is measured in turn on the same device; nothing is uploaded to compare them.
  5. The images and full result remain in the tab until you reset, reload or close it. A file is created only when you choose download.

The free analyzer does not call a photo-analysis API. Loading the model and WebAssembly files is an ordinary static-asset request and does not transmit the selected photo.

Processors and purpose

PartyData handledPurposeBoundary
Your browserSelected image, landmarks, local resultsRun every free tool and paid preflightFree photo stays here.
CloudflareNetwork metadata; paid account, billing IDs, report JSON and transient paid photoSite delivery, Worker execution and D1 storageApplication code does not persist the photo.
Google OAuthBasic profile, verified email and OAuth exchange dataOptional account sign-inNo Drive, Contacts or Gmail scopes requested.
StripeCheckout, payment method, billing and transaction dataHosted payment and signed payment eventsOur application does not receive full card details.
OpenRouterPaid prompt, resized photo, response and request metadataRoute the Full Report requestRequests require zero-data-retention and deny data collection.
Configured model providerPaid prompt and resized photoReturn structured report dataOnly an eligible privacy-filtered endpoint is requested.

Current provider documents remain authoritative: OpenRouter zero-data-retention routing, Stripe security, and Cloudflare privacy.

What the application stores

  • Free use: no application photo or result record.
  • Account: Google profile name, verified email, optional avatar, linked-provider record and seven-day session records. OAuth tokens are encrypted before database storage.
  • Billing: Stripe Checkout and Payment Intent identifiers, amount, currency, product and payment status. Full card details stay with Stripe.
  • Credit wallet: current balance and an append-only ledger for top-ups, report spending, automatic returns and refund adjustments.
  • Full Report: scores, observations, recommendations, version, provider model identifier and timestamps. No photo.
  • Consent and webhook records: versioned confirmation events and bounded Stripe event-processing records for audit and idempotency.

Account and saved report data remain until the user deletes the account or asks us to act, subject to legal retention requirements. Pseudonymous payment records may need longer retention for tax, accounting, fraud prevention, disputes or law. Provider-side retention follows each provider’s policy.

Security controls

  • same-origin checks for browser mutation requests;
  • bounded JSON and image payloads with limited MIME types;
  • Google OAuth through Better Auth with signed, secure cookies and server-side sessions;
  • encrypted OAuth tokens in D1;
  • Stripe-hosted Checkout and raw-body webhook signature verification;
  • idempotent payment fulfillment and atomic credit debit/return records;
  • secrets in Worker secret bindings, never browser code or versioned configuration;
  • Cache-Control: no-store on account, billing and report API responses.

Your controls

  • Use every free tool without creating an account or transmitting a photo.
  • Do not purchase or submit a Full Report if you do not want the named processors to handle the image.
  • Decline optional analytics.
  • Delete local free results immediately in the tab.
  • Delete your account and saved report text from the Account page, subject to billing-record limits.
  • Contact contact@airateface.com about a privacy concern.