You are reading an archived version of our legal texts (version 2.0.0, in force from 2026-07-31). It is not the text currently in force.

Biometric data

Corpus compliant

Facial recognition is the heart of this service, and it is the most sensitive thing we do. This page says exactly what is measured, why, for how long, and how to make it stop.

1. Selfie Processing

To help you find your photos after an event, Shareft compares your face to the photos uploaded by the photographer. You submit a reference selfie through our web interface; this selfie is converted into a temporary mathematical fingerprint used only for this comparison.

This fingerprint is then compared against the event photos indexed by the photographer. If there's a match, the photos are shown to you.

2. Retention and Deletion

<strong>Your comparison selfie is deleted from our servers immediately after the search completes.</strong> Its facial fingerprint is only computed transiently to run the search and is not stored. If a search never completes, an automatic sweeper deletes the orphaned selfie within 1 hour at most. The facial vectors of the event photos live as long as the event and are deleted with it.

We keep no long-term archive of faces and do not build a global identity database.

3. Explicit Consent

Facial recognition search is optional: no processing happens without your explicit consent. Before uploading a selfie, you must check a box confirming you understand what will be done with your image.

4. Confidentiality of Results

To limit misuse of the technology, we never show a confidence score or any other technical facial-analysis data, to either participants or photographers. The system returns only a binary result: a match was found, or it wasn't.

5. Hosting and Compliance

Shareft offers localized hosting options for institutional clients and large events, so that data stays within the event's legal jurisdiction where this is required.

To exercise your rights of access or deletion, write to <email>{privacyEmail}</email>. We answer within one month.

The legal basis, regime by regime

In Côte d'Ivoire, law no. 2013-450 of 19 June 2013 subjects biometric processing to prior authorisation by the data protection authority; our authorisation or acknowledgement number is {artciAuthorizationNumber}. In the European Union, a facial template is data under Article 9 of the GDPR and we rely on explicit consent under Article 9(2)(a). In United States states with a dedicated biometric statute — Illinois, Texas and Washington among them — prior written consent is required; our terms of use forbid photographers from running facial search for events held there, because our current consent flow is not built to satisfy those statutes.

Retention and destruction policy

This section is our published retention and destruction schedule, and it is deliberately reachable without signing in. A facial template is kept for as long as the photographs of the event it belongs to are kept, and is destroyed together with them — that is the retention of the plan the photographer bought, plus a seven-day grace period. A comparison selfie is destroyed as soon as the search has run, whether or not it matched; orphaned selfies are swept every fifteen minutes. Destruction covers both our own records and the templates held by our recognition provider.

If you never search for your photos

A facial template is created for every face in an event's photographs, at the moment they are uploaded — not at the moment someone searches. Most people in a set of photographs never visit this site at all, and they are the majority of the people this page concerns. Their templates follow the same retention and the same destruction as everyone else's, and they have the same rights, which they can exercise by writing to {privacyEmail}.

The matching is automated

Comparison is carried out entirely by software, with no human reviewing your face. The threshold is set deliberately high, so the system prefers returning nothing to returning someone else's photographs. The outcome is binary: photographs are returned, or none are. No measurement, score or template is ever displayed to the photographer or to you.

Why there is no less intrusive way

The purpose is narrow: letting one person retrieve their own photographs out of several hundred, without handing them everyone else's. The alternatives do not reach it. Asking guests to name themselves requires the photographer to know and label every face, which recreates a far more identifying record. Publishing the whole gallery openly exposes every guest to every other guest, which is more intrusive, not less. Sorting by time or table only narrows the set and still shows strangers. Facial comparison, isolated per event, deleted with the event, and never revealed as a measurement, is the least intrusive way we have found to reach that purpose — and where a photographer disagrees, they can run the event as an open gallery with no facial processing at all.

Making it stop

Write to {privacyEmail}, telling us which event you were at — the name or the date is enough. You can ask what we hold, ask us to delete it, and object to your face being processed at all. It is free, you do not have to give a reason, and we answer within one month. You may also complain directly to a supervisory authority: ARTCI in Côte d'Ivoire, the authority where you live in the European Union, or your state's attorney general in the United States.

Read the version currently in force

Shareft — Smart event photo delivery