cwupid

Effective September 22, 2026 · replaces the version of August 27, 2026

Privacy policy

Cwupid scores photographs, saves them to your private portfolio, and lets account holders collaborate through galleries. This policy explains what is collected, how face-related information is processed, where information goes, how long it is kept, and how to delete it.

Information we collect

How we use information

We use account data to sign you in, keep saved history separate by account, provide deletion controls, administer complimentary invitations, enable gallery collaboration, respond to reports, enforce blocks and safety rules, prevent abuse, and troubleshoot the service. We use uploaded photos only to produce features you request and, when saved to your portfolio or added to a gallery, to provide that account or gallery feature.

Face data and portrait-photo processing

What Cwupid collects and derives. When you request scoring, feedback, or Photo Studio, Cwupid receives the full photo you selected. Automated processing detects the number and location of people, a primary-person bounding box, a face bounding box and detector confidence, and a temporary 512-pixel crop of the primary person. It temporarily calculates an image feature representation and a face feature representation, and estimates a broad female or male reference category with a confidence value so the score can be read against the corresponding calibration group. The result can include the detected-person count, primary-person box, reference category and confidence, score and percentile, model version, and optional regional attribution for the face, body, background, and full image. The live upload pipeline does not retain face landmarks. Cwupid does not create or retain a reusable face template, identify a person, verify identity, compare identities, or use face data for authentication.

Planned and permitted use. Cwupid uses this information only to provide the score, report, feedback, regional explanation, college-context comparison, or Photo Studio selection the user explicitly requests; to save that result to the user's private portfolio, automatically on the app's Use Cwupid page and otherwise when the user chooses; and to prevent abuse or diagnose a failed request. A score is an experimental prediction about response to a photograph. It is not a measurement of a person's attractiveness, identity, character, or worth. Cwupid does not use uploaded photos or derived face information for advertising, marketing profiles, data brokerage, surveillance, identity recognition, or training its scoring or feedback models.

Sharing and storage locations. A photo submitted through the Cwupid API is handled the same way as one submitted on the website, including its deletion once the scoring job reaches a terminal state and the promise above that it is never used to train Cwupid's models. Cloudflare processes the upload at Cwupid's edge, holds a queued upload in private R2 object storage, and stores the photos and reports saved to a user's portfolio. Amazon Web Services runs Cwupid's private scoring service. The AWS service uses request-scoped temporary files and memory for the original image, crop, bounding boxes, detection values, feature representations, gender-reference estimate, and result. OpenAI receives the selected image and score context when Cwupid writes the included or detailed feedback, and receives the selected Studio images and score context for Photo Studio selection and writing. Cwupid sends those OpenAI API requests with response storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days, and may retain an image longer if automated safety systems flag potential child sexual abuse material for manual review. Cwupid does not opt in to using API data to train OpenAI models. No uploaded photo or derived face information is shared with advertisers, analytics providers, data brokers, login providers, Stripe, Twilio, or Resend.

Retention. A queued upload in Cloudflare storage is deleted when its scoring or Studio job succeeds, fails, or is abandoned. On AWS, the original request file and temporary crop are deleted before the response is completed; bounding boxes, detector outputs, face and image feature representations, and gender logits exist only for that request and are then discarded. Cwupid does not log those bytes or representations. OpenAI's provider retention is described above. A photo scored on the app's Use Cwupid page is saved automatically; one the user removes from the portfolio, or one scored elsewhere and not saved, is not retained after processing. If a photo and report are saved, Cwupid retains the saved photo and returned report fields until the user deletes that photo or account. A separately controlled encrypted operational backup can retain a saved photo or report for up to 30 days after it is deleted from the live account, after which it is removed and is not restored to the live service.

Consent and deletion. Before the first off-device analysis in the iOS app, Cwupid explains this processing and asks the user to confirm that they own the photo or have permission to upload and analyze it, that every identifiable person shown agreed to that use, and that the image does not depict a minor. The user can decline and no analysis is sent. The user can withdraw consent for future processing by not submitting another image. A saved photo and its stored face-related report fields can be deleted from the photo's detail screen. The user can delete the entire account in the app under Profile, Account, Delete account or at /delete-account. Account deletion cancels queued work and removes live saved images, reports, profile data, and galleries.

Service providers and sharing

We do not sell personal information or saved photos, and we do not use them for targeted advertising.

Retention

OAuth state is single-use and expires after 10 minutes. Account sessions expire after 30 days unless you sign out sooner. Password sign-in attempts are rate limited, and the associated pseudonymous security records are normally removed after 24 hours. A password reset link can be used once and expires one hour after it is issued; requesting a new password signs out every other session. Reset request records are rate limited and the associated pseudonymous security records are normally removed after 24 hours. Phone verification challenges expire after 10 minutes; Cwupid removes account-linked phone profile data when you delete the account but retains the keyed redemption fingerprint needed to prevent repeated promotional claims. Where that number completed an invitation, Cwupid also keeps a keyed record that the invitation was counted, so that deleting an account cannot reset the four-invitation limit; that record identifies no one and holds no phone number, email address, or name. Twilio separately retains verification data under its own service policy. A pending complimentary credit grant expires within the period chosen by the administrator and may be revoked sooner. An autonomous outreach authorization can last no longer than 180 days from the date permission was recorded and can be revoked sooner. Outreach records are retained to manage the campaign and preserve decline or opt-out history; a person may ask Cwupid to remove their pre-account outreach details. Photo and face-related retention is stated in the dedicated Face data and portrait-photo processing section above. Saved photos, score reports, galleries, account profile data, and a password verifier remain until you delete the item or account. Safety reports and their limited text snapshots may be retained after the reported content or either account is deleted when needed to finish an investigation, enforce safety rules, prevent repeat abuse, resolve disputes, or comply with law. When you delete an account, Cwupid removes its promotional email, Instagram username, and internal outreach note. Minimal payment identifiers, the pseudonymous credit ledger and redemption record, disputes, safety and security records may be retained only as needed for accounting, fraud and abuse prevention, dispute handling, and legal obligations. The analytics visitor identifier and its cookie last one year from your most recent visit unless you clear your browser storage; the visit record it belongs to holds no name, email address, or photo, and is kept after an account is deleted only as a pseudonymous count of how people reached the site.

Your choices

You can decline optional provider fields, avoid saving a result or remove one that was saved automatically, keep a gallery private, delete individual saved results, report gallery content, block another account, sign out, or permanently delete your account and its saved images and galleries at /delete-account. You can opt out of website analytics entirely by turning on Global Privacy Control or Do Not Track in your browser, or by clearing its cookies and local storage for this site. Contact [email protected] about an urgent safety report or a privacy request.

Children

Cwupid is not directed to children under 13, and we do not knowingly collect account information from children under 13.

Changes and contact

Material changes will be posted here with a revised effective date. Questions or privacy requests can be sent to [email protected].