Privacy
How VIZO handles your data.
VIZO exists to help you find photos of yourself without exposing your face to other people. This page explains, in plain language, what data we collect, why we collect it, who can see it, and how you can ask us to remove it.
What VIZO is
VIZO is a private photo-discovery tool. You sign in with Google, upload one reference photo of your own face, and VIZO searches the albums a VIZO administrator has added (via public Lightroom or Google Drive share links) for matches that look like you. VIZO does not publish your photo, your face reference, or your search history to anyone.
What data we collect
To operate the service, VIZO stores the following categories of data:
- Account data from Google. Your Google identifier (subject), your verified email address, your display name, and your Google profile picture URL. We use these to recognize you on return visits, to decide whether your email is allowed to sign in, and to display your name in the interface.
- Your face reference. The reference photo you upload, plus a mathematical fingerprint (a face embedding) computed from it by the open-source InsightFace model running on our server. The embedding is what the system actually compares against photos in albums; the photo itself is used to display your reference in your settings. We do not share the photo or the embedding with any third party.
- Search activity. When you open an album and VIZO searches it for matches, the search request and the results it returned are recorded so we can show them to you and so we can detect abuse.
- Session data. A random opaque token stored in an HTTP-only cookie identifies your signed-in session. The server record behind that token records when the session started and when it last authenticated.
- Operational data. Standard web-server access logs (IP address, user agent, request path) and a periodic heartbeat that confirms the service is healthy.
VIZO does not use advertising cookies, analytics cookies, or any third-party tracking scripts. The only cookie the site sets is the session cookie described above.
How we use your data
The data above is used only to provide VIZO: to authenticate you, to decide which albums you are allowed to see, to search those albums for matches that look like your reference, and to keep the service running reliably. We do not sell your data, we do not share it with advertisers, and we do not use it to train any model.
Your face reference is never compared against albums you have not been granted access to. Even within an album you can access, the matching happens server-side against the album's own photos; VIZO never reads other users' face references.
Who else can see your data
A small number of VIZO administrators (people whose email addresses are listed in the platform's ADMIN_EMAILS configuration) can see your account email, your display name, and your face reference thumbnail for the purpose of operating the service (for example, to set your reference on your behalf if you ask them to, or to troubleshoot a search that is not working). Administrators cannot see your raw face embedding or your search history.
Beyond the VIZO service itself, the following processors are involved in running the service and may receive limited technical data as a result:
- Google. Provides sign-in (OpenID Connect) and, for albums sourced from Google Drive public shares, fetches publicly available metadata.
- Adobe. For albums sourced from Adobe Lightroom public shares, VIZO fetches publicly available metadata from the Lightroom API.
- Cloudflare. Hosts the public web frontend as a static export and terminates TLS for the API.
- Hosting infrastructure. The backend service and its database run on a single virtual private server. Backups of the database are written to a volume on the same host.
Cookies
VIZO sets a single cookie named session. It is an HTTP-only, secure cookie that holds a random opaque token; the cookie itself carries no personal data. It expires when your session ends (for example, when you sign out) or after a long idle period defined by the server.
We do not set advertising cookies, analytics cookies, or any third-party cookies.
Retention and backups
While your account is active, we keep your account data, face reference, and search history so that the service continues to work. You can remove your face reference at any time from your Face settings; removing it stops VIZO from being able to find matches for you, but does not delete your account.
The database is backed up automatically on a regular schedule. A backup may therefore continue to contain a record of your account, face reference, or search activity for up to the retention period of the most recent backup after deletion. Backups are stored on the same host as the live database and are protected by the same access controls.
Your rights
Depending on where you live, you may have rights to access, correct, or delete the personal data we hold about you, or to restrict or object to certain processing. You can exercise most of these rights yourself by signing in and removing your face reference or signing out. For anything else (account deletion, data export, complaints), contact us at the address listed below; we will respond within a reasonable timeframe.
Security
VIZO is operated by a single maintainer on a single virtual private server. We protect your data with HTTPS-only transport, HTTP-only secure session cookies, server-side session validation, CSRF protection on state-changing requests, and the database-level access controls of the underlying Postgres instance. No system is perfectly secure; if you ever believe your account has been compromised, sign out and contact us.
Biometric processing
VIZO offers an optional self-service verification flow that lets you add or replace your own reference photo without help from an administrator. If you choose to use it, the flow processes the following data entirely on your device:
- Face landmarks. A short timeline of 478-point face landmark coordinates is computed in your browser by an open-source MediaPipe model. These coordinates never leave your device.
- Head-motion signals. A four-element timeline summarising yaw, pitch, roll, and stillness for the duration of the verification challenge. The timeline is combined with the landmarks to form the evidence set; only its one-way HMAC signature is sent to the server.
- Code 128 barcode. The decoded text of the Code 128 barcode on your student or member card. The text is sent to the server so a future feature can verify your membership in a specific group.
VIZO does not upload your face photo, your face embedding, or your raw landmark array during the verification flow. The server only stores the one-way HMAC signature of the canonical evidence set, the decoded barcode text, the verification method, and the time the verification succeeded.
The verification token issued after a successful flow is single-use, opaque to the client, and expires 24 hours after it is issued. The token is consumed the moment you use it to upload a new reference photo; you must run the flow again to upload a replacement.
Before any camera access is requested, the flow shows a plain consent screen describing the above. The screen has two buttons: I agree proceeds, and Decline returns you to your settings without touching the camera. You may decline at any time.
You may request deletion of your verification record, your decoded barcode, and your reference photo at any time. Contact a VIZO administrator to make this request; the request is processed within the same retention window that applies to the rest of your account.
Changes to this policy
If we make material changes to this policy, we will update this page and link to the new version from the footer of the site. Continued use of VIZO after a material change indicates that you accept the updated policy.
Contact
For privacy questions, data requests, or complaints, please contact the VIZO operator through the channels listed on the VIZO deployment record in the project repository.