Privacy Policy

Privacy Policy — Internal Draft, Not for Publication

This draft reflects the planned local MVP only. The Service is not authorized for public or production use. It must be reviewed and updated with the verified operator identity, governing privacy role, selected providers, deployment regions, retention evidence, and effective date before publication.

1. Scope

This Privacy Policy describes how Matcha Filter Remover (the “Service”) plans to handle information when an adult user uploads an authorized image to reduce a visible filter or create a more natural-looking version.

The Service is designed for users aged 18 or older. It is not directed to children, and users must not upload images of minors for face-focused transformation.

2. Information We Plan to Process

Images and image-processing data

We do not plan to store the original client filename, EXIF/GPS metadata, face embeddings, inferred age, gender, ethnicity, or other demographic inferences. The implementation must verify that metadata is removed before this statement may be published as a current fact.

Session, security, and abuse-prevention data

The planned guest experience may use a signed HttpOnly session cookie, an opaque browser identifier, request identifiers, and rotated salted risk hashes derived from limited network/device signals. The application does not plan to persist raw IP addresses or raw user-agent strings in its application database. Cloudflare may process network information as part of hosting, security, and delivery under its own service terms.

Account data — only if accounts are enabled later

If optional accounts are enabled, the Service may process an email address or external authentication subject, internal user ID, session records, job ownership links, entitlement status, and account deletion status. The authentication and email providers have not been selected; account features must remain disabled until this Policy is updated.

Payment data — only if paid features are enabled later

Paid features are not currently authorized. If enabled, the Service may receive limited checkout, customer, order, subscription, currency, amount, refund, dispute, chargeback, entitlement, and webhook-event records from the payment provider. Payment card details would be handled by the checkout provider and should not be stored by the Service. The payment role, tax handling, subprocessors, retention schedule, and refund terms must be confirmed before checkout is activated.

Support and rights requests

If you contact support@matchafilterremover.net, the Service may process your email address, message, request details, and the information reasonably needed to respond. Do not email original images unless specifically requested through an approved secure process.

Analytics — currently disabled

GSC, GA4, Microsoft Clarity, and Plausible are planned inventory items, but no live analytics activation is authorized for this draft.

Analytics must never receive image bytes or previews, filenames, object keys, signed or private URLs, EXIF, free-text prompts, provider details or raw errors, email addresses, moderation details, or sensitive inferences. Where consent is required, non-essential analytics must not load until the user affirmatively consents. Refusing or withdrawing analytics consent must not disable the core tool.

3. How Information Is Planned to Be Used

Information may be processed only to:

The Service does not obtain permission to publish uploads or outputs, place them in a public gallery, use them in marketing examples, or use them to train models.

4. Planned Processing Flow and Service Providers

The planned P0 flow is:

1. A same-origin upload streams through a Cloudflare Worker.

2. Cloudflare Images validates, decodes, and re-encodes the image.

3. Only the normalized private intermediate and private output are stored in randomized Cloudflare R2 objects.

4. Cloudflare D1 stores minimal job, consent, status, deletion, security, and entitlement metadata; Cloudflare Queues carries opaque job messages without image bytes.

5. A private Worker route checks the owning guest or account before delivering a result.

Cloudflare therefore processes image and network data even though the Service plans not to persist the raw original.

A generative image provider has not been selected. The generative path must remain disabled. Before it is enabled, this Policy must identify the provider and disclose the data sent, purpose, plan, processing locations, subprocessors, retention, deletion, and whether provider terms permit any training or product-improvement use. The Service will not make a “no training” or exact provider-deletion promise without verified contractual and technical evidence.

Creem is the target payment provider for local/test research only. It is not an active public checkout provider under this draft. Authentication, transactional email, customer support, and consent-management providers are also not yet selected.

5. Retention and Deletion

The following are implementation targets, not verified public service-level commitments:

These exact periods must not be published as current facts until remote cleanup, storage, logs, analytics, and provider behavior have been verified.

A “Delete now” request is designed to revoke result access immediately and schedule private media deletion. Provider-side deletion may follow different verified terms and must be disclosed before provider processing is enabled.

If accounts are enabled, account deletion will remove account mappings, job ownership links, media, and non-required profile data. Limited payment, tax, fraud, security, or legal records may be retained when required and separated from unnecessary profile and media data.

6. Legal Bases and Choices

The applicable legal basis depends on the user’s location and the final operator setup. Planned bases may include performing the user-requested service, legitimate interests in security and abuse prevention, legal obligations, and consent for non-essential analytics where required.

Users may be able to:

The Service may need to verify a request without asking for unnecessary image data. Rights vary by location, and some records may be exempt from deletion where retention is legally required.

7. Security

The planned safeguards include private object storage, randomized object keys, owner/session authorization, short-lived upload authorization, same-origin controls, input validation, private no-store downloads, limited logs, idempotent deletion, cost/abuse controls, and restricted payment ledgers. No service can guarantee absolute security. Production use is blocked until these controls are implemented and tested.

8. Children and Sensitive Uses

The Service is for adults aged 18 or older. It does not knowingly offer face-focused transformation of minors’ images and does not perform age inference or biometric identity matching. Users must not upload minors, non-consenting identifiable people, non-consensual intimate imagery, or requests intended to expose, sexualize, harass, reveal hidden content, or infer a person’s “real face.” Suspected prohibited use may be blocked, investigated with minimized records, and reported where legally required.

9. International Processing

Cloud and other providers may process data in countries other than the user’s country. The final operator, provider regions, data-transfer mechanism, and contractual safeguards are not yet confirmed. Production processing must remain blocked until this section can be completed with verified facts and human legal review.

10. Changes and Contact

Material changes to image processing, providers, retention, payments, analytics, or user rights require an updated Policy and, where appropriate, renewed consent before the change takes effect.

Questions, privacy requests, copyright notices, and abuse reports may be sent to support@matchafilterremover.net.

This internal draft must not be published until the operator identity, effective date, verified providers, legal bases, transfers, retention evidence, and rights workflow are completed and approved.