Effective September 22, 2026 · replaces the version of August 27, 2026
Privacy policy
Cwupid scores photographs, saves them to your private portfolio, and lets account holders collaborate through galleries. This policy explains what is collected, how face-related information is processed, where information goes, how long it is kept, and how to delete it.
Information we collect
- Account information. When you create an email-and-password account, we collect your name, email address, and the unique public Cwupid username you choose, and store a salted, cryptographically hashed password verifier; we do not store the password itself. Your Cwupid username can be visible to other account holders in gallery ownership, contributions, and invitations; your account email is not displayed as gallery identity. When you sign in with Google, Facebook, Instagram, or Apple, we receive the provider-specific account ID and the basic profile fields you approve. Depending on the provider, those fields may include your name, email address, profile image, Instagram username, and professional account type. Instagram Login does not give Cwupid your Instagram password or email address. We do not receive any provider password.
- Early-user outreach. An authorized Cwupid administrator may import Instagram usernames for people who directly agreed to receive automated outreach and later record an email address a person voluntarily sends in a reply. Autonomous mode works only when the exact username has a current, unrevoked authorization; the server checks it before a recipient is claimed and when a send is recorded. A global delivery log prevents the same username from being selected automatically again. The visible local companion sends the prepared message through the administrator’s signed-in browser. It may inspect the visible thread for an email the recipient chose to share, reserve complimentary credits for that email without sending a claim link, and remove that processed chat from the administrator’s inbox after saving the durable result. Cwupid stores the username, selected email, credit-grant status, delivery status, and deletion status, but not the reply text. It does not discover candidates, inspect unrelated inbox conversations, scrape Instagram profiles, call Meta’s Graph API, or bypass platform controls.
- Complimentary credit grants. When our team offers complimentary access, we store the email address you gave us, an optional Instagram username, how you contacted us, an internal outreach note, the grant’s amount and status, and an audit record. If an account already uses that email, the credits are added immediately. Otherwise, the grant waits for an account created with that exact email and is applied automatically when the account signs in. No claim link is sent for a new email-bound grant. Previously issued private invitation links remain usable until redeemed, revoked, or expired; Cwupid stores only their one-time secret’s cryptographic hash. We use this information to deliver and administer the offer, prevent duplicate claims, and record consent and fulfillment.
- Password recovery. When you ask for a password reset link, Cwupid stores only the cryptographic hash of the one-time token, the account it belongs to, a keyed fingerprint of the requesting IP address, and the times the link was issued, expires, and was used. The link itself exists only in the email we send to the address on the account.
- Phone verification. If you claim a new-account offer, Twilio receives the mobile number needed to deliver and check the one-time code. Cwupid stores only the number’s last four digits and keyed fingerprints of the number, account, and requesting IP address. We do not store the full phone number or the verification code.
- Photos and reports. An unsaved upload is used only to produce the score, feedback, or Photo Studio result you requested. Scoring runs on a queue, so the image is held in private storage from submission until the job finishes, and is then deleted automatically. A photo you score on the Use Cwupid page of the signed-in app is saved automatically, together with its report, to your private portfolio; its result carries a Remove from portfolio control that deletes it again. Anywhere else, a photo is saved only when you select Save photo and report. A saved photo and its report are kept in your private account history. Scoring also produces a report on the photograph itself — its aesthetics, quality, lighting, colour, and composition — and we retain that report, together with a one-way cryptographic fingerprint of the image it was computed from, whether or not you save the photo. The fingerprint is what lets a saved photo find the report already produced for it, and lets a report that failed be produced again at no charge; it cannot be turned back into the image. Deleting a saved photo, or your account, deletes these reports with it.
- Galleries and safety reports. A gallery can contain photos, titles, captions, descriptions, public usernames, and collaborator roles. Private galleries are available only to their members. Public galleries are available immediately to anyone with their link. If you report a gallery or photo, we store the reason, optional details, opaque account and content identifiers, and a limited text snapshot so the report can still be investigated if the original content is edited or deleted. Blocking is stored as a relationship between account identifiers and ends gallery collaboration between those accounts; each account can view its own blocked-account list and unblock an account.
- Billing and actions. When billing is enabled, Cwupid stores your plan and payment provider; Stripe customer, Checkout Session, subscription, invoice, Payment Intent, and verified event identifiers for website purchases; or Apple product, transaction, original transaction, app-account token, environment, status, and expiration information for App Store purchases. We keep an append-only history of action grants, uses, cap adjustments, and compensating refunds. Cwupid does not receive or store your full card number or Apple Account payment details.
- Website analytics. To learn how many people reach Cwupid and where they stop, we store a randomly generated visitor identifier in a first-party cookie named
cw_vidand in your browser’s local storage, and record the first page you landed on, the website that linked you here, any campaign labels in the link, your country, whether you are on a phone or a computer, a keyed fingerprint of your IP address, and the times you first reached the Try view, saw the sign-up prompt, opened the sign-up form, and created an account. The identifier is random, is not derived from anything about you, is never shared, and is used only to count one browser once and to connect an account to the visit that created it. We use no third-party analytics service, and this data is never used for advertising or sold. If your browser sends a Global Privacy Control or Do Not Track signal, Cwupid records none of it and sets no identifier. - Service and security data. We process limited technical information such as IP address, browser user agent, request time, session activity, and error or rate-limit events to operate and protect the service.
How we use information
We use account data to sign you in, keep saved history separate by account, provide deletion controls, administer complimentary invitations, enable gallery collaboration, respond to reports, enforce blocks and safety rules, prevent abuse, and troubleshoot the service. We use uploaded photos only to produce features you request and, when saved to your portfolio or added to a gallery, to provide that account or gallery feature.
Face data and portrait-photo processing
What Cwupid collects and derives. When you request scoring, feedback, or Photo Studio, Cwupid receives the full photo you selected. Automated processing detects the number and location of people, a primary-person bounding box, a face bounding box and detector confidence, and a temporary 512-pixel crop of the primary person. It temporarily calculates an image feature representation and a face feature representation, and estimates a broad female or male reference category with a confidence value so the score can be read against the corresponding calibration group. The result can include the detected-person count, primary-person box, reference category and confidence, score and percentile, model version, and optional regional attribution for the face, body, background, and full image. The live upload pipeline does not retain face landmarks. Cwupid does not create or retain a reusable face template, identify a person, verify identity, compare identities, or use face data for authentication.
Planned and permitted use. Cwupid uses this information only to provide the score, report, feedback, regional explanation, college-context comparison, or Photo Studio selection the user explicitly requests; to save that result to the user's private portfolio, automatically on the app's Use Cwupid page and otherwise when the user chooses; and to prevent abuse or diagnose a failed request. A score is an experimental prediction about response to a photograph. It is not a measurement of a person's attractiveness, identity, character, or worth. Cwupid does not use uploaded photos or derived face information for advertising, marketing profiles, data brokerage, surveillance, identity recognition, or training its scoring or feedback models.
Sharing and storage locations. A photo submitted through the Cwupid API is handled the same way as one submitted on the website, including its deletion once the scoring job reaches a terminal state and the promise above that it is never used to train Cwupid's models. Cloudflare processes the upload at Cwupid's edge, holds a queued upload in private R2 object storage, and stores the photos and reports saved to a user's portfolio. Amazon Web Services runs Cwupid's private scoring service. The AWS service uses request-scoped temporary files and memory for the original image, crop, bounding boxes, detection values, feature representations, gender-reference estimate, and result. OpenAI receives the selected image and score context when Cwupid writes the included or detailed feedback, and receives the selected Studio images and score context for Photo Studio selection and writing. Cwupid sends those OpenAI API requests with response storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days, and may retain an image longer if automated safety systems flag potential child sexual abuse material for manual review. Cwupid does not opt in to using API data to train OpenAI models. No uploaded photo or derived face information is shared with advertisers, analytics providers, data brokers, login providers, Stripe, Twilio, or Resend.
Retention. A queued upload in Cloudflare storage is deleted when its scoring or Studio job succeeds, fails, or is abandoned. On AWS, the original request file and temporary crop are deleted before the response is completed; bounding boxes, detector outputs, face and image feature representations, and gender logits exist only for that request and are then discarded. Cwupid does not log those bytes or representations. OpenAI's provider retention is described above. A photo scored on the app's Use Cwupid page is saved automatically; one the user removes from the portfolio, or one scored elsewhere and not saved, is not retained after processing. If a photo and report are saved, Cwupid retains the saved photo and returned report fields until the user deletes that photo or account. A separately controlled encrypted operational backup can retain a saved photo or report for up to 30 days after it is deleted from the live account, after which it is removed and is not restored to the live service.
Consent and deletion. Before the first off-device analysis in the iOS app, Cwupid explains this processing and asks the user to confirm that they own the photo or have permission to upload and analyze it, that every identifiable person shown agreed to that use, and that the image does not depict a minor. The user can decline and no analysis is sent. The user can withdraw consent for future processing by not submitting another image. A saved photo and its stored face-related report fields can be deleted from the photo's detail screen. The user can delete the entire account in the app under Profile, Account, Delete account or at /delete-account. Account deletion cancels queued work and removes live saved images, reports, profile data, and galleries.
Service providers and sharing
- Cloudflare hosts the website, account database, sessions, and private saved-image storage.
- Amazon Web Services runs the on-demand image-scoring service.
- OpenAI processes an image and score context when Cwupid writes included or detailed feedback, and processes Studio images and score context when Photo Studio performs visual selection or writing. Cwupid disables response storage for these API requests. OpenAI may retain abuse-monitoring logs for up to 30 days and does not train on API data unless a customer opts in; Cwupid does not opt in.
- Stripe hosts Checkout and processes website subscription payment and receipt information.
- Apple processes App Store subscription payments and provides signed transaction and subscription-status information when you purchase in the iOS app.
- Resend delivers account email, including a password reset link and the notice that a password was changed, to the address on your account.
- Twilio sends and checks a one-time SMS code when you choose to verify a phone number for an account offer.
- Google, Meta, or Apple processes the sign-in flow you choose. Cwupid does not send your uploaded photos to a login provider.
We do not sell personal information or saved photos, and we do not use them for targeted advertising.
Retention
OAuth state is single-use and expires after 10 minutes. Account sessions expire after 30 days unless you sign out sooner. Password sign-in attempts are rate limited, and the associated pseudonymous security records are normally removed after 24 hours. A password reset link can be used once and expires one hour after it is issued; requesting a new password signs out every other session. Reset request records are rate limited and the associated pseudonymous security records are normally removed after 24 hours. Phone verification challenges expire after 10 minutes; Cwupid removes account-linked phone profile data when you delete the account but retains the keyed redemption fingerprint needed to prevent repeated promotional claims. Where that number completed an invitation, Cwupid also keeps a keyed record that the invitation was counted, so that deleting an account cannot reset the four-invitation limit; that record identifies no one and holds no phone number, email address, or name. Twilio separately retains verification data under its own service policy. A pending complimentary credit grant expires within the period chosen by the administrator and may be revoked sooner. An autonomous outreach authorization can last no longer than 180 days from the date permission was recorded and can be revoked sooner. Outreach records are retained to manage the campaign and preserve decline or opt-out history; a person may ask Cwupid to remove their pre-account outreach details. Photo and face-related retention is stated in the dedicated Face data and portrait-photo processing section above. Saved photos, score reports, galleries, account profile data, and a password verifier remain until you delete the item or account. Safety reports and their limited text snapshots may be retained after the reported content or either account is deleted when needed to finish an investigation, enforce safety rules, prevent repeat abuse, resolve disputes, or comply with law. When you delete an account, Cwupid removes its promotional email, Instagram username, and internal outreach note. Minimal payment identifiers, the pseudonymous credit ledger and redemption record, disputes, safety and security records may be retained only as needed for accounting, fraud and abuse prevention, dispute handling, and legal obligations. The analytics visitor identifier and its cookie last one year from your most recent visit unless you clear your browser storage; the visit record it belongs to holds no name, email address, or photo, and is kept after an account is deleted only as a pseudonymous count of how people reached the site.
Your choices
You can decline optional provider fields, avoid saving a result or remove one that was saved automatically, keep a gallery private, delete individual saved results, report gallery content, block another account, sign out, or permanently delete your account and its saved images and galleries at /delete-account. You can opt out of website analytics entirely by turning on Global Privacy Control or Do Not Track in your browser, or by clearing its cookies and local storage for this site. Contact [email protected] about an urgent safety report or a privacy request.
Children
Cwupid is not directed to children under 13, and we do not knowingly collect account information from children under 13.
Changes and contact
Material changes will be posted here with a revised effective date. Questions or privacy requests can be sent to [email protected].