Skip to content
LetMeRate logoLETMERATE
Security

Your face never leaves your device

LetMeRate is a zero-data product: photos and facial geometry are computed locally in your browser. Here is the honest security posture — what we hold, what we don't, and how to report a problem.

On-deviceScan analysis — raw photos not stored by the analyzerJWTAuthenticated sessions on all server endpoints0Breaches — no incidents to date

Certifications & Compliance

GDPR-aligned by design: data minimization, privacy by default, and a right-to-erasure endpoint (delete your account and every post). Face analysis runs on-device with no third-party processors. Community-feed data is stored on our own servers and is never sold to third parties.

Data Encryption

The site and API are served over TLS (HTTPS). Session tokens are HMAC-signed JWTs, never sent as plaintext. Database connections use TLS where supported. Your scan is processed locally; feed photos are transmitted over TLS to our servers.

Data Residency

On-device analysis means raw scans never leave your device. Community-feed data (posted photos, demographics, numeric ratings) lives on our servers; the hosting region is documented in the Privacy Policy. We do not sell or share data with data brokers.

Access Controls

Every server endpoint requires a signed session token (JWT); the PRO flag is enforced server-side, never trusted from the client. API abuse is throttled with per-IP rate limits. Administrative access is least-privilege and audited.

Vulnerability Disclosure

Found a weakness? Write to security@letmerate.com — we treat every report seriously and respond fast. We follow responsible disclosure: no blackmail, no threats, just a clear report and a fix. A formal bug bounty programme is planned as the product grows.

Penetration Testing

The API attack surface is small and authenticated: SSRF guards on image loading, remote-URL rejection on the feed, content-moderation fail-closed, and per-IP rate limits. As the product scales, we'll commission independent third-party penetration tests and link the most recent report here.

Incident History

None · zero incidents

LetMeRate has never suffered a data breach, leak, or security incident. We commit to full transparency: every incident, its date, impact, and resolution will be documented on this page within 72 hours of confirmation — and affected users will be notified directly.

Found a vulnerability?

We're a small team that takes security personally. Send a clear, responsible disclosure and we'll fix it fast — and credit you for it.

PGP key available on request · never share photos in disclosure