You are reading an archived version of our legal texts (version 1.0.0, in force from 2026-07-23). It is not the text currently in force.
Biometric Data and Facial Recognition
Corpus legacy
This page explains how Shareft handles data from facial recognition: what we collect, how long we keep it, and what we never do with it.
1. Selfie Processing
To help you find your photos after an event, Shareft compares your face to the photos uploaded by the photographer. You submit a reference selfie through our web interface; this selfie is converted into a temporary mathematical fingerprint used only for this comparison.
This fingerprint is then compared against the event photos indexed by the photographer. If there's a match, the photos are shown to you.
2. Retention and Deletion
<strong>Your comparison selfie is deleted from our servers immediately after the search completes.</strong> Its facial fingerprint is only computed transiently to run the search and is not stored. If a search never completes, an automatic sweeper deletes the orphaned selfie within 1 hour at most. The facial vectors of the event photos live as long as the event and are deleted with it.
We keep no long-term archive of faces and do not build a global identity database.
3. Explicit Consent
Facial recognition search is optional: no processing happens without your explicit consent. Before uploading a selfie, you must check a box confirming you understand what will be done with your image.
4. Confidentiality of Results
To limit misuse of the technology, we never show a confidence score or any other technical facial-analysis data, to either participants or photographers. The system returns only a binary result: a match was found, or it wasn't.
5. Hosting and Compliance
Shareft offers localized hosting options for institutional clients and large events, so that data stays within the event's legal jurisdiction where this is required.
To exercise your rights of access or deletion, contact our data protection officer at <email>[email protected]</email>.