privacy policy.
last updated: july 2026
the short version
we don't store your photos. ever. they're deleted from our servers immediately after AI analysis. we collect the minimum data needed to run the service. we don't sell your data. that's it.
what we collect
- email address — for authentication via magic link. stored in our auth provider (Supabase).
- uploaded photos — temporarily stored during AI processing only. deleted immediately after analysis completes, whether successful or failed. we cannot recover deleted photos.
- analysis results — the AI-generated scores and feedback are stored so you can view your results later. no photos are retained.
- analytics cookies — Google Analytics (only if you accept cookies). used to understand traffic patterns. no personal identification.
- advertising pixel — Reddit Pixel for ad conversion tracking. fires page visit and conversion events (sign-up, purchase). if you arrived via a Reddit ad, this helps us measure campaign performance. no photos or scores are shared with Reddit.
- technical & security data — at sign-up and when you interact with the service we process your IP address and browser user-agent. for ban-evasion detection we store a one-way cryptographic hash of your sign-up IP (never the address itself) so a user we have removed cannot simply return on a fresh account. see "security & abuse prevention" below.
photo handling
this is the part you care about. your uploaded photo is:
- uploaded to encrypted temporary storage
- sent to the AI model for analysis
- deleted permanently immediately after processing
- never viewed by any human
- never used for AI training
- never shared with third parties
the image path in our database is nullified after deletion. there is no mechanism to recover a deleted photo.
AI processing
photos are analyzed using Anthropic's Claude AI via their API. Anthropic's API does not use submitted data for model training. the image is transmitted via encrypted connection (TLS) and is not stored by Anthropic after processing.
CSAM & safety scanning — we take this seriously
before any image reaches the AI analyzer, it runs through automated CSAM (Child Sexual Abuse Material) detection via the Sightengine workflow (configured with minor detection, deepfake detection, nudity classification, gore, self-harm, hate, and weapon models). Anthropic's content classifier provides a second independent layer at the analyze step.
if either layer flags the image, the upload is rejected immediately, your account is logged, and — for CSAM hits — we report to:
- the National Center for Missing & Exploited Children (NCMEC) via CyberTipline
- Anthropic's Safeguards Team (we capture and retain the Anthropic message identifier of every call so abuse notifications can be matched to a specific upload, user, and IP)
- relevant law enforcement as required by jurisdiction
our retention policy for moderation logs is the inverse of the photo policy: we keep the metadata (timestamps, IP, user-agent, scan results, request identifiers, the per-upload acknowledgment you submitted) indefinitely for audit, legal defense, and cooperation with investigations — even after the underlying image is deleted from our storage and after your account is closed.
text moderation
chat messages, comments, and other user-generated text are automatically scanned by OpenAI's Moderation API. content classified as sexual abuse of minors, harassment, threats, or other policy violations is hidden, the row is logged, and the account may be suspended. OpenAI does not retain submitted moderation text beyond the scan call.
user reports
any logged-in user can report content. reports include the reporter's identity, the entity being reported, the reason, and any optional details, plus reporter IP and user-agent. reports go to a human reviewer.
security & abuse prevention
to keep the platform safe — especially to enforce removals and stop banned users from returning — we process limited technical data:
- at sign-up we store a one-way cryptographic hash of your IP address (HMAC), your browser user-agent and your email domain. we do not store your raw sign-up IP. the hash lets us detect when a removed account tries to come back from the same network, but cannot be reversed to your address.
- when you upload media or file a report, the associated moderation record stores your IP, user-agent and scan metadata (see the CSAM & safety scanning section) for audit and legal-defense purposes.
legal basis: we rely on our legitimate interest (GDPR Art. 6(1)(f)) in preventing fraud, abuse, and child sexual abuse material, and in enforcing our terms. this interest — particularly child safety — outweighs the limited privacy impact of the pseudonymised data described here.
retention: sign-up IP hashes are automatically deleted after 90 days, except where they are linked to a banned account, which we retain longer as an abuse record. moderation and CSAM logs are retained as described in their sections.
your rights
if you are in the EU/EEA or UK you have the right to access, correct, export, or request deletion of your personal data, and to object to processing based on legitimate interest. you can delete your account and associated data at any time (see "data deletion").
one limit applies: to prevent abuse and comply with the law, we retain certain safety records after account deletion — moderation logs, CSAM acknowledgments, and ban-evasion signals tied to a banned account — with your account identifiers replaced by a snapshot. this is necessary for our legitimate interest in safety and for cooperation with investigations, and overrides erasure for those specific records only.
to exercise any right, email privacy@ratemyd.app.
cookies & tracking
we use essential cookies for authentication (session management). we use Google Analytics cookies only if you explicitly accept them via the cookie consent banner. you can decline analytics cookies with no impact on functionality.
we also use the Reddit Pixel for advertising conversion measurement. this pixel tracks page visits and conversion events (sign-ups, purchases) to help us understand which ads are working. your email may be hashed and sent to Reddit for advanced matching if you're logged in. no photos, scores, or analysis results are ever shared with Reddit or any ad platform.
data deletion
you can delete your analysis results at any time from your profile page. photos are already deleted automatically. to delete your account entirely, contact us.
age requirement
this service is strictly for users 18 years and older. by using ratemyd., you confirm you are at least 18.
contact
questions about your data? email us at privacy@ratemyd.app