privacy policy.

last updated: may 2026

the short version

we don't store your photos. ever. they're deleted from our servers immediately after AI analysis. we collect the minimum data needed to run the service. we don't sell your data. that's it.

what we collect

  • email address — for authentication via magic link. stored in our auth provider (Supabase).
  • uploaded photos — temporarily stored during AI processing only. deleted immediately after analysis completes, whether successful or failed. we cannot recover deleted photos.
  • analysis results — the AI-generated scores and feedback are stored so you can view your results later. no photos are retained.
  • analytics cookies — Google Analytics (only if you accept cookies). used to understand traffic patterns. no personal identification.
  • advertising pixel — Reddit Pixel for ad conversion tracking. fires page visit and conversion events (sign-up, purchase). if you arrived via a Reddit ad, this helps us measure campaign performance. no photos or scores are shared with Reddit.

photo handling

this is the part you care about. your uploaded photo is:

  • uploaded to encrypted temporary storage
  • sent to the AI model for analysis
  • deleted permanently immediately after processing
  • never viewed by any human
  • never used for AI training
  • never shared with third parties

the image path in our database is nullified after deletion. there is no mechanism to recover a deleted photo.

AI processing

photos are analyzed using Anthropic's Claude AI via their API. Anthropic's API does not use submitted data for model training. the image is transmitted via encrypted connection (TLS) and is not stored by Anthropic after processing.

CSAM & safety scanning — we take this seriously

before any image reaches the AI analyzer, it runs through automated CSAM (Child Sexual Abuse Material) detection via the Sightengine workflow (configured with minor detection, deepfake detection, nudity classification, gore, self-harm, hate, and weapon models). Anthropic's content classifier provides a second independent layer at the analyze step.

if either layer flags the image, the upload is rejected immediately, your account is logged, and — for CSAM hits — we report to:

  • the National Center for Missing & Exploited Children (NCMEC) via CyberTipline
  • Anthropic's Safeguards Team (we capture and retain the Anthropic message identifier of every call so abuse notifications can be matched to a specific upload, user, and IP)
  • relevant law enforcement as required by jurisdiction

our retention policy for moderation logs is the inverse of the photo policy: we keep the metadata (timestamps, IP, user-agent, scan results, request identifiers, the per-upload acknowledgment you submitted) indefinitely for audit, legal defense, and cooperation with investigations — even after the underlying image is deleted from our storage and after your account is closed.

text moderation

chat messages, comments, and other user-generated text are automatically scanned by OpenAI's Moderation API. content classified as sexual abuse of minors, harassment, threats, or other policy violations is hidden, the row is logged, and the account may be suspended. OpenAI does not retain submitted moderation text beyond the scan call.

user reports

any logged-in user can report content. reports include the reporter's identity, the entity being reported, the reason, and any optional details, plus reporter IP and user-agent. reports go to a human reviewer.

cookies & tracking

we use essential cookies for authentication (session management). we use Google Analytics cookies only if you explicitly accept them via the cookie consent banner. you can decline analytics cookies with no impact on functionality.

we also use the Reddit Pixel for advertising conversion measurement. this pixel tracks page visits and conversion events (sign-ups, purchases) to help us understand which ads are working. your email may be hashed and sent to Reddit for advanced matching if you're logged in. no photos, scores, or analysis results are ever shared with Reddit or any ad platform.

data deletion

you can delete your analysis results at any time from your profile page. photos are already deleted automatically. to delete your account entirely, contact us.

age requirement

this service is strictly for users 18 years and older. by using ratemyd., you confirm you are at least 18.

contact

questions about your data? email us at privacy@ratemyd.app