Privacy Policy
Privacy Policy — Internal Draft, Not for Publication
This draft reflects the planned local MVP only. The Service is not authorized for public or production use. It must be reviewed and updated with the verified operator identity, governing privacy role, selected providers, deployment regions, retention evidence, and effective date before publication.
1. Scope
This Privacy Policy describes how Matcha Filter Remover (the “Service”) plans to handle information when an adult user uploads an authorized image to reduce a visible filter or create a more natural-looking version.
The Service is designed for users aged 18 or older. It is not directed to children, and users must not upload images of minors for face-focused transformation.
2. Information We Plan to Process
Images and image-processing data
- The image you choose to upload.
- A normalized private copy created after file validation and re-encoding.
- A corrected or generated-naturalized output.
- Technical image attributes such as type, size, dimensions, and coarse validation results.
- A generated job identifier, processing status, selected correction strength, result type, consent-policy version, and deletion/expiry timestamps.
We do not plan to store the original client filename, EXIF/GPS metadata, face embeddings, inferred age, gender, ethnicity, or other demographic inferences. The implementation must verify that metadata is removed before this statement may be published as a current fact.
Session, security, and abuse-prevention data
The planned guest experience may use a signed HttpOnly session cookie, an opaque browser identifier, request identifiers, and rotated salted risk hashes derived from limited network/device signals. The application does not plan to persist raw IP addresses or raw user-agent strings in its application database. Cloudflare may process network information as part of hosting, security, and delivery under its own service terms.
Account data — only if accounts are enabled later
If optional accounts are enabled, the Service may process an email address or external authentication subject, internal user ID, session records, job ownership links, entitlement status, and account deletion status. The authentication and email providers have not been selected; account features must remain disabled until this Policy is updated.
Payment data — only if paid features are enabled later
Paid features are not currently authorized. If enabled, the Service may receive limited checkout, customer, order, subscription, currency, amount, refund, dispute, chargeback, entitlement, and webhook-event records from the payment provider. Payment card details would be handled by the checkout provider and should not be stored by the Service. The payment role, tax handling, subprocessors, retention schedule, and refund terms must be confirmed before checkout is activated.
Support and rights requests
If you contact support@matchafilterremover.net, the Service may process your email address, message, request details, and the information reasonably needed to respond. Do not email original images unless specifically requested through an approved secure process.
Analytics — currently disabled
GSC, GA4, Microsoft Clarity, and Plausible are planned inventory items, but no live analytics activation is authorized for this draft.
- Google Search Console is intended for search-performance and site-verification data and is not a session-replay script.
- GA4, if enabled, would receive only coarse consented funnel events.
- Microsoft Clarity is disabled for the P0 tool because the upload, preview, comparison, result, and private states are sensitive.
- Plausible may be considered for privacy-minimized page and funnel measurement after its actual configuration is reviewed.
Analytics must never receive image bytes or previews, filenames, object keys, signed or private URLs, EXIF, free-text prompts, provider details or raw errors, email addresses, moderation details, or sensitive inferences. Where consent is required, non-essential analytics must not load until the user affirmatively consents. Refusing or withdrawing analytics consent must not disable the core tool.
3. How Information Is Planned to Be Used
Information may be processed only to:
- validate, normalize, process, deliver, and delete an authorized image job;
- show job status and a private downloadable result;
- enforce ownership, security, abuse, quota, cost, and acceptable-use controls;
- diagnose failures using sanitized technical records;
- provide support and respond to privacy, copyright, or abuse reports;
- maintain account entitlements and payment records if paid features are later approved;
- comply with legal obligations and protect users, rights holders, and the Service;
- measure coarse product performance only after analytics and consent approval.
The Service does not obtain permission to publish uploads or outputs, place them in a public gallery, use them in marketing examples, or use them to train models.
4. Planned Processing Flow and Service Providers
The planned P0 flow is:
1. A same-origin upload streams through a Cloudflare Worker.
2. Cloudflare Images validates, decodes, and re-encodes the image.
3. Only the normalized private intermediate and private output are stored in randomized Cloudflare R2 objects.
4. Cloudflare D1 stores minimal job, consent, status, deletion, security, and entitlement metadata; Cloudflare Queues carries opaque job messages without image bytes.
5. A private Worker route checks the owning guest or account before delivering a result.
Cloudflare therefore processes image and network data even though the Service plans not to persist the raw original.
A generative image provider has not been selected. The generative path must remain disabled. Before it is enabled, this Policy must identify the provider and disclose the data sent, purpose, plan, processing locations, subprocessors, retention, deletion, and whether provider terms permit any training or product-improvement use. The Service will not make a “no training” or exact provider-deletion promise without verified contractual and technical evidence.
Creem is the target payment provider for local/test research only. It is not an active public checkout provider under this draft. Authentication, transactional email, customer support, and consent-management providers are also not yet selected.
5. Retention and Deletion
The following are implementation targets, not verified public service-level commitments:
- raw upload: processed as a stream and not persisted by the application;
- normalized input: delete as soon as technically safe after a successful output and target deletion no later than 60 minutes after a terminal job state;
- output: target automatic deletion no later than 24 hours after success;
- failed, cancelled, or partial media: delete as soon as technically safe, targeting 60 minutes;
- minimal job and provider-request metadata: up to 30 days;
- guest session and abuse counters: proposed shorter schedules, subject to necessity and implementation review;
- support communications: schedule not yet confirmed;
- payment, tax, fraud, refund, dispute, chargeback, and webhook records: only for the period required by confirmed legal, accounting, security, and contractual obligations.
These exact periods must not be published as current facts until remote cleanup, storage, logs, analytics, and provider behavior have been verified.
A “Delete now” request is designed to revoke result access immediately and schedule private media deletion. Provider-side deletion may follow different verified terms and must be disclosed before provider processing is enabled.
If accounts are enabled, account deletion will remove account mappings, job ownership links, media, and non-required profile data. Limited payment, tax, fraud, security, or legal records may be retained when required and separated from unnecessary profile and media data.
6. Legal Bases and Choices
The applicable legal basis depends on the user’s location and the final operator setup. Planned bases may include performing the user-requested service, legitimate interests in security and abuse prevention, legal obligations, and consent for non-essential analytics where required.
Users may be able to:
- delete an active job through the product;
- refuse or withdraw non-essential analytics consent without losing core functionality;
- request access, correction, deletion, or other applicable privacy rights by emailing support@matchafilterremover.net;
- appeal or report a content/safety decision through the support or reporting process once implemented.
The Service may need to verify a request without asking for unnecessary image data. Rights vary by location, and some records may be exempt from deletion where retention is legally required.
7. Security
The planned safeguards include private object storage, randomized object keys, owner/session authorization, short-lived upload authorization, same-origin controls, input validation, private no-store downloads, limited logs, idempotent deletion, cost/abuse controls, and restricted payment ledgers. No service can guarantee absolute security. Production use is blocked until these controls are implemented and tested.
8. Children and Sensitive Uses
The Service is for adults aged 18 or older. It does not knowingly offer face-focused transformation of minors’ images and does not perform age inference or biometric identity matching. Users must not upload minors, non-consenting identifiable people, non-consensual intimate imagery, or requests intended to expose, sexualize, harass, reveal hidden content, or infer a person’s “real face.” Suspected prohibited use may be blocked, investigated with minimized records, and reported where legally required.
9. International Processing
Cloud and other providers may process data in countries other than the user’s country. The final operator, provider regions, data-transfer mechanism, and contractual safeguards are not yet confirmed. Production processing must remain blocked until this section can be completed with verified facts and human legal review.
10. Changes and Contact
Material changes to image processing, providers, retention, payments, analytics, or user rights require an updated Policy and, where appropriate, renewed consent before the change takes effect.
Questions, privacy requests, copyright notices, and abuse reports may be sent to support@matchafilterremover.net.
This internal draft must not be published until the operator identity, effective date, verified providers, legal bases, transfers, retention evidence, and rights workflow are completed and approved.
- docs/prd.md
- docs/legal/g1-compliance-review.md
- docs/gate-evidence/G1-backend/backend-technical-feasibility-architecture-20260812.md
- docs/owner/pipeline-scope-authorization-20260812.md