Legal information
Privacy Policy
Last updated: 20 September 2026
The short version: your photo never leaves your device. We have no accounts, no cookies and no advertising. We never receive your face, and we do not want it.
We do store minimal payment-entitlement state when you buy access. Below, we explain exactly what is stored and why.
Omogle is operated by Kickoff Ventures Pte Ltd.
Your photo is never uploaded
When you choose a photo, your browser decodes it into the memory of the tab you are looking at. A face-landmark model then runs on your own device and measures the image there. The measurements, the score and the report are all computed on your device.
No part of the photo reaches our servers or anyone else. The face model runs inside your browser, and the page makes no request that carries image data.
The image stays in the current browser tab while you view the result. It is released when you choose another photo or leave the page. If you choose the unchecked checkout-draft option before payment, this browser also stores a metadata-free image copy in IndexedDB for 30 minutes so you can return after payment. You can continue without saving instead and choose your photo again after payment.
We never collect biometric data
While it measures your photo, the face model produces a set of geometric points. Those points exist only in the memory of your browser tab, and only for as long as the analysis runs. They are never transmitted. If you choose the unchecked checkout-draft option, IndexedDB temporarily stores the metadata-free image copy, score, six measurements, face shape, measurement guides, random run, scan and tab identifiers, a random write identifier to protect newer drafts during cleanup, and expiry information. The app deletes that draft when checkout cannot open, you reset the scan, or on the next visit after expiry; nothing is sent to the operator, Worker, Stripe or PostHog.
We do not collect, capture, receive, store, sell, lease, trade or otherwise profit from biometric identifiers or biometric information. We hold no face template and no face geometry record. There is nothing about your face for us to disclose, retain or destroy.
What we collect: usage counts and purchaser analytics
We use PostHog to count page opens and how many people reach each step of the tool. We configure it to store nothing on your device: no cookies, no persistent PostHog browser storage, no session recording and no automatic click tracking. An unpaid visit therefore cannot be recognised by PostHog on a later visit or on another site.
Each visit receives a random identifier that exists only while the tab is open. It is not derived from your face. If Stripe confirms a purchase and returns the purchaser email, we identify that visit to PostHog using the email so the earlier checkout steps and the purchase belong to the same purchaser profile.
These are all the events we record, and everything each one carries:
- $pageview — you opened a page on this site. PostHog receives the page address and the automatic technical details described below, but no photo, face data, score or measurement.
- $pageleave — you closed or left a page on this site. It carries the same page address and automatic technical details as $pageview, and nothing else. We use it only to measure how long a visit lasted.
- $identify — after Stripe confirms a purchase, PostHog links the visit to the purchaser email. The profile receives that email, purchased_at as the confirmation time, and plan as either single or subscription. It receives no card, billing, photo, face, score or measurement information.
- photo_selected — you chose a photo. No other information.
- face_detected — the tool found a usable face. No other information.
- analysis_failed — the selected photo did not produce a score. It is sent once for each photo that fails, whatever the cause. No image detail or measurement is sent.
- detection_no_face, detection_no_pose, detection_multiple_faces, detection_extreme_yaw, detection_extreme_pitch, detection_low_resolution and detection_degenerate_geometry — which one of the seven on-device quality checks refused the photo. The name is all we receive: no image, no face detail, no measurement and no score.
- retry_prompted — the tool showed a guided retry after one of five photo checks. It carries only failure_reason as extreme_yaw, extreme_pitch, low_resolution, no_face or multiple_faces. It sends no angle, dimension, filename, image, face detail, measurement or score.
- photo_rejected — the file you chose was not a JPG, PNG or WebP image, was empty, or was above the size limit. The filename, the file type and the file size stay on your device.
- photo_undecodable — your browser could not read the file as an image, or the image held too many pixels. No image detail is sent.
- analysis_errored — an unexpected error stopped the analysis. No error message, image detail or measurement is sent.
- score_computed — the on-device calculation finished. The score itself and all measurements stay on your device.
- result_offer_control_assigned, result_offer_preview_assigned, result_offer_control_viewed, result_offer_preview_viewed and report_preview_opened — the result offer experiment records assignment, actual offer visibility, and sample opening. These events contain no variant property, score, measurement, photo, guide, or persistent identifier beyond the existing random run identity used by all events.
- another_photo_clicked — you chose to start another analysis. No other information.
- pricing_viewed — the purchase options came into view on your screen. It records only that they were shown, not what you did next.
- pricing_dock_viewed — the mobile sticky purchase bar came into view on your screen. It records only that it was shown.
- score_offer_clicked — you chose a paid option from the offer under your score. No other information.
- sticky_upgrade_clicked — you chose a paid option from the mobile sticky purchase bar. No other information.
- header_unlock_opened — you opened the purchase panel in the site header. It records only that the panel was shown.
- header_upgrade_clicked — you chose a paid option from the header panel. No other information.
- header_restore_opened — you opened the restore panel in the site header. It records only that the panel was shown.
- header_restore_accepted and header_restore_rejected — whether the restore link you pasted had a valid form. The link, the access token and any part of either is not sent.
- header_account_opened — you opened the account menu in the site header. It records only that the menu was shown.
- header_access_removed — you deleted your access from this device. No token, link or purchase reference is sent.
- upgrade_clicked, checkout_started, checkout_cancelled, purchase_completed and report_unlocked — the five steps and outcomes of a purchase. After a confirmed purchase, these events are attributed to the identified purchaser profile described above.
- checkout_rejected, checkout_unreachable and checkout_url_untrusted — the payment page did not open, and which of the three causes stopped it. No error message, address or payment detail is sent.
- purchase_restored and unlock_retry_succeeded — access was restored or a payment confirmation retry succeeded. No session reference, restore credential or token is sent.
- restore_link_copied — you copied the private restore link after purchase. The link and access token are not sent.
- share_link_copied — you copied the public, campaign-tagged homepage link. The event contains no copied address, report, score or measurement.
- paid_report_viewed and paid_report_loaded — the full-report flow opened and its content loaded on your device. The score and measurements are not sent.
- report_load_failed and report_retry_clicked — the paid report did not load or you retried it. No report data, token or failure detail is sent.
- single_plan_selected and monthly_plan_selected — you chose one of the two paid options. No other information.
- single_purchase_completed and subscription_purchase_completed — Stripe confirmed the selected purchase type. The event is attributed to the purchaser profile after identification, but contains no card or billing details.
- single_report_delivered — the one-report credit displayed its complete report. No report data is sent.
- billing_portal_opened and billing_portal_failed — Stripe’s subscription-management page opened or could not be opened. No portal link, token or failure detail is sent.
- history_enabled and history_disabled — you opted into or deleted private history on this device. No history data is sent.
- comparison_viewed and consistency_check_viewed — you opened the local comparison or consistency display. No scores or measurements are sent.
- report_printed — you opened the browser print or PDF flow. The report itself is not sent to analytics.
- report_overlay_viewed and report_pdf_downloaded — you used the local measurement overlay or downloaded a locally generated PDF. No guide, photo, report or filename is sent.
- report_explanation_helpful and report_explanation_not_helpful — the event name records the chosen helpful/not-helpful button and carries no text, score, measurement, photo, guide, or report content.
- verification_retake_started and verification_retake_delivered — you began or received the included verification retake. No score, measurement or photo detail is sent.
- baseline_started and baseline_completed — you began or completed a three-photo baseline in browser memory. No baseline value or photo detail is sent.
- progress_dashboard_viewed — you opened the private local progress charts. No score, measurement, setup label or history data is sent.
- history_exported and history_imported — you downloaded or opened a local history file. The file and everything in it remain on your device.
- photo_protocol_started and photo_protocol_completed — you began or completed the local Photo Optimization Protocol. No task or completion date is sent.
What reaches our analytics provider automatically
Like any web request, these events arrive at PostHog with your IP address, the address of the page you are on, and the browser and operating system your device reports. PostHog uses the IP address to derive an approximate country. We do not use it for anything else.
After a successful purchase, PostHog also receives the purchaser email, the plan as single or subscription, and the time the purchase was confirmed. Anonymous visitors do not receive a PostHog person profile.
The page address we send is the site name and the path only. We remove the query string and anything after the “#” before the event leaves your browser, so a payment reference or a restore link can never reach our analytics.
Each event also carries the campaign values that were already in the link you clicked, such as utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid and fbclid, and the address of the site that linked you to us. We use these only to learn which channels bring people here. We remove the query string from that linking address too, so search terms you typed on another site do not reach us. If you arrive by typing our address or from a bookmark, there is no linking address to send.
We never combine any of this with information about your face, because we hold none.
The live visitor counter
While a page here is open, visible and in recent use, your browser sends a small signal to our API about once a minute. The signal carries one random identifier, so that each open tab is counted once and the site can show how many people are using it at that moment. If you stop using the page, the signals stop a few minutes later.
The identifier comes from your browser’s random generator when the page loads. It is not derived from your face, your photo, your purchase or your analytics visit, and it exists only in the memory of the open tab.
Our server keeps only that identifier and the time of its last signal, computes one number from them, and deletes them about three minutes after the signals stop. Only the count is ever shown. Nothing is stored on your device for this feature.
What is stored on your device
If you buy access, your browser saves an access token, the plan type, and the Stripe Checkout session reference in local storage. A one-report delivery identifier is held in local storage for idempotent retry. If you open a restore link, local storage also holds that link’s token, and a marker that the token still waits for our server, until the server accepts or refuses it. These values contain no photo, landmark, score, measurement, filename or image metadata.
For an optional checkout draft, session storage holds one random per-tab handle so the draft can be opened only in its originating tab. It contains no photo, face, score, measurement, report, purchase or identity information and lasts only for that browser tab session.
Monthly subscribers may opt into private local history. If enabled, local storage contains only a random scan identifier, timestamp, score, the six measurements, and optional labels you enter for camera, lighting, expression and setup, for at most 50 scans. Entries older than 365 days are pruned. Photos, filenames, MIME types, dimensions, landmarks, measurement guides and object URLs are never placed in history.
The optional 30-day protocol stores only its start date, task identifiers and completion dates. History is off by default. You can delete one entry, use “Delete all toolkit data,” export or import a validated local JSON file, or clear site data in browser settings.
If you choose a PDF with your annotated photo, the browser writes that PDF to the download location you choose. A PDF without the photo is also available. Both are created locally and never sent to us.
Payments
Stripe handles payment completely. You enter your card details on a page that Stripe hosts, not one that we host. We never see or store your card number.
Stripe collects what it needs to take the payment and send you a receipt, which includes your email address and billing details. Stripe handles that information as its own controller, under its own privacy policy.
When the browser confirms a successful Checkout session, our Cloudflare Worker retrieves the purchaser email from Stripe and returns it with the access entitlement. The browser sends that email, the plan and the confirmation time to PostHog for purchaser identification. A Stripe or PostHog error does not block the paid report.
Our Cloudflare Worker stores the minimum state needed to enforce purchases: plan type; Stripe customer, Checkout-session and subscription references; paid-through time; single-credit expiry; up to two single-delivery identifiers and their times; normalized subscription status; and processed webhook event identifiers. It does not store the returned email, request body, photo, filename, image metadata, landmark, measurement, score or analytics identity.
Stripe sends signed webhook notices for subscription payment and status changes. The Worker verifies each notice and retrieves current subscription state before updating access. Entitlement tokens and restore links are credentials and are never logged.
Hosting
Cloudflare serves this site. Like any web host, Cloudflare processes the technical details of each request, including the IP address and the browser type, in order to deliver the page and to protect the site from abuse.
What we do not do
The site also has:
- No accounts. There is nothing to sign up for.
- No advertising, and no ad networks.
- No selling or sharing of personal information.
- No email marketing. Stripe uses your email for payment and receipts, and we send it to PostHog only to identify purchaser analytics as described above.
- No cross-site tracking, and no third-party tracking pixels.
Children
This site is not intended for children under 13, and we do not knowingly collect information from them. If you are under 18, you must have the card holder’s permission before you buy anything.
Your rights
Depending on where you live, you may have the right to see, correct, export or delete the personal information a business holds about you, and to object to how it is used.
We have no account for you, no photo and no measurements. If you purchase, PostHog holds a purchaser profile linked to the email Stripe returned; you may ask us about or request deletion of that analytics profile using the contact address below.
For anything Stripe holds as part of your payment, you can contact Stripe directly, or write to us at support@omogleai.com and we will help.
Where information is processed
Our hosting provider, our analytics provider and our payment provider run servers in several countries, including the United States. The limited information described on this page may be processed there.
Changes to this policy
If we change how the tool handles data, we will change this page and update the date at the top.
If a future change affects the photo-privacy promise above, we will flag it at the top of this page.
Contact
Write to support@omogleai.com.