Finding your photos by face
Biometric data policy · Version 2026-09-23 · Last updated: 23 September 2026
This feature has been available since 31 August 2026. It only runs for an event once that
event's host has switched it on, and only for a guest who has agreed on the consent screen.
1. What the feature does
At a big event your photos end up scattered across hundreds of shots taken by other
people. This feature lets you find the ones you appear in. You take a selfie, and
ShareCam compares it against the photos in that one event album and shows you
the matches.
That is the feature's only purpose. Your face is never used to identify you anywhere
else, in any other album, or for anything other than showing you your own matches.
2. What face data is created
Comparing faces requires turning a face into numbers. ShareCam creates a
face signature — a mathematical description of the geometry of a face.
Under Illinois law this is a "scan of face geometry"; under EU and UK law it is
biometric data within the meaning of Article 9 GDPR; under Turkish law it is
a special category of personal data under Article 6 KVKK. We treat it as sensitive
personal data everywhere, whatever the local law happens to require.
Two different kinds of signature exist, and they are governed by different rules:
-
Album signatures. When the feature is switched on for an event, a signature
is created for each face that appears in the photos in that album. These are what your
selfie is compared against. They are stored for as long as the album exists
(see section 5).
-
Your search signature. The signature made from the selfie you take in order to
search. This one is transient: it is used to run your search and then destroyed
(see section 5).
3. Where it is processed, and who else sees it
Being straight about this matters more than sounding good, so plainly:
this processing happens on our servers, not on your phone.
Your selfie is sent to ShareCam and passed to our face-matching provider.
- ShareCam (independent developer, Türkiye) — operates the service.
- Google Firebase — our servers, database and file storage. The database and
the servers that run the search are in Frankfurt, Germany (europe-west3);
photo and video files are stored in St. Ghislain, Belgium (europe-west1).
- Amazon Web Services — the face-matching engine. Region:
Frankfurt, Germany (eu-central-1).
Both providers act as our processors under written data-processing terms. They may not use
your face data for their own purposes. Face data is not sent anywhere else, is not sold, is
not shared with advertisers or analytics providers, and is
never used to train any AI model — not ours and not anyone else's.
If you are in Türkiye, note that Frankfurt is outside Türkiye and this is therefore a
transfer abroad under Article 9 KVKK. We rely on your explicit consent for this transfer:
the consent screen tells you where your selfie goes and who processes it before you agree,
and your face data is then protected under the EU's data protection law (GDPR) rather than
directly under Turkish law. If you would rather not have your face data leave the country,
do not use this feature — everything else in the album works without it.
4. What it is never used for
- Not to identify you across different events. Signatures are locked to a single album
and comparison across albums is not possible in our system.
- Not to train, improve, tune or evaluate any AI or machine-learning model.
- Not for advertising, profiling, scoring, age or gender estimation, emotion detection,
or any other inference about you.
- Not to build a list of who attended, and not to tell a host who appears in which photo.
- We do not sell, lease, trade or otherwise profit from face data, and we will not
disclose it except where we are legally compelled to.
5. Retention and destruction schedule
This is our written retention schedule. We follow it; we do not keep face data longer.
-
Your search signature is destroyed as soon as your search finishes, and in
every case within 24 hours of being created. The selfie image itself is
discarded at the same time and is never added to the album.
-
Album signatures are destroyed when the album is deleted, which happens
automatically when the event's storage period ends (7 days to 1 year depending on the
host's package), or immediately if the host deletes the event.
-
Outer limit. All face data is destroyed when the purpose described in
section 1 has been satisfied, or within 3 years of your last interaction
with ShareCam, whichever comes first.
-
Immediate destruction on request. If you withdraw (section 6), your data is
deleted straight away rather than waiting for any of the above.
-
If the host switches the feature off, every album signature for that event is
destroyed. Switching it back on rebuilds them from scratch; nothing is retained in between.
- Destruction covers backups and logs on our normal backup cycle, which completes within
30 days.
6. Saying no, and changing your mind
-
It is off unless you turn it on. Nothing is done with your face until you
read the consent screen and tap to agree. There is no pre-ticked box and consent is
never bundled into our Terms.
-
Declining costs you nothing. You can still join the event, browse,
download and use every other part of the album exactly as before. We will never make
album access conditional on agreeing to this — under Article 7(4) GDPR consent obtained
that way would not be valid consent at all, and we think it is wrong regardless.
-
You can withdraw at any time, from the same screen or by writing to us.
Withdrawal deletes your signatures and removes you from any matches, and is as easy as
giving consent in the first place.
-
You may also ask us for a copy of the face data we hold about you, or ask us to correct
or delete it. Write to
[email protected]; we answer within
30 days and there is no charge.
7. Whose faces are in the album
We will not pretend this away. To let you search the album, signatures have to be created
for the faces in the album's photos — including people who never opened ShareCam and never
agreed to anything. That is a real limitation of any feature of this kind, and it is
why we do the following:
- The feature is off by default for every event. A host has to switch it on.
- Turning it on requires the host to confirm that they will tell their guests. We give
them wording to put on the invitation and on a sign at the event.
- Guests who join in a web browser are told on the join screen when an album has it
switched on, before they upload anything.
- Signatures are never shown to anyone. There is no "people" list, no name suggestions and
no way for a host to look someone up.
- Anyone who appears in an album can write to us and have their signatures deleted, whether
or not they use ShareCam.
8. Where the feature is not offered
The feature is switched off for anyone in Illinois, Texas and Washington in
the United States. Those states have dedicated biometric privacy statutes, and we would
rather withhold a convenience feature than operate in a grey area. We check this at the
moment you would give consent, and if we cannot tell where you are, the feature stays off.
It is also switched off in a small number of countries whose rules require biometric data
to stay inside the country: currently China, Russia and Vietnam. Everywhere else, including
the European Union, the United Kingdom and Türkiye, the feature is available on the basis of
your explicit consent.
We are also honest about the limits of that check: it is based on your internet connection,
so it can be wrong if you use a VPN. We therefore also ask you to confirm where you are.
Please answer that honestly — it is there to protect you as much as us.
9. Roles and responsibilities
For each event, the host is the data controller — it is their album, their guest
list, and their decision whether to use this feature. ShareCam is the processor,
acting on the host's instructions and on the terms in our
Terms of Service. For our own account and billing data we are the
controller; that is covered in the Privacy Policy.
10. Questions and complaints
Write to [email protected] and a human
will answer. If you are in the EU or EEA you may also complain to your national data
protection authority; in the UK, to the ICO; in Türkiye, to the Kişisel Verileri Koruma
Kurumu (KVKK).