Skip to content
LetMeRate logoLETMERATE
Legal

Privacy Policy

The plain-language version of how LetMeRate handles your data — what we store, what we never see, and how you can delete it all.

Last updated: August 8, 2026

1. What we process

Face analysis (the scan): photos you capture for analysis are processed locally in your browser using MediaPipe. The analyzer does not store raw scan photos on our servers. Only pre-computed geometric scores are sent to our API when you request a report. Community feed (the social layer): if you post a photo to the community feed, the photo, your chosen demographics (age, gender, ethnicity, country), and the numeric ratings (1–10) you give and receive are stored on our servers. The feed contains no text comments or messages.

2. Data minimization

We collect only what the product needs: an anonymous device identifier, your optional demographics, feed posts, and numeric ratings. We do not collect your name, email address, or payment details — payments, when available, are processed by a third-party payment provider that handles billing data on its own servers.

3. Where data is stored

Community-feed data is stored on our servers in a hosted database. The hosting region is documented in this policy and may change as we scale; we will update this page if the region changes. Raw scan photos from the analysis flow are never uploaded.

4. Who we share data with

We never sell your data. We do not share it with advertisers or data brokers. If we use a third-party service (e.g., a content-moderation provider to scan uploaded feed photos for unsafe content, or an LLM to generate report text from pre-computed scores), that service receives only the minimum data required for its function, and we list it here. No third party receives your identity or contact information, because we do not collect it.

5. Your rights (right-to-erasure)

You can delete your active feed post at any time from the My Photo tab (Delete post). You can also delete your entire account — all posts, ratings, and demographic data — from the app; the deletion is permanent and propagates to our database. To exercise any GDPR right (access, rectification, erasure, portability), contact hello@letmerate.com and we will respond within 30 days.

6. Children

LetMeRate is intended for users aged 18 and over. We do not knowingly collect data from children under 13, and we do not target minors. If you believe a child has provided us data, contact us and we will delete it promptly.

7. Security

All traffic is served over TLS. Sessions are authenticated with signed JWT tokens; every API endpoint requires them. Rate limits and content moderation protect the feed. Our security posture is described in detail on the Security page.

8. Changes to this policy

We may update this policy as the product evolves. Material changes will be announced on this page and, where feasible, in the app. Continued use after changes constitutes acceptance.

Questions about this policy? Contact hello@letmerate.com.