Privacy Notice
Last updated: 1 August 2026
This notice explains what happens to information when you use ChinFace App. It is written in plain English and describes how the service actually works today.
1. Who we are
ChinFace App is provided through chinface.app.
If you have any questions about this notice or about how your information is handled, you can contact us at support@chinface.app.
2. The most important point: your recording stays on your device
Your camera and microphone recording is processed entirely in your browser. ChinFace App does not upload, receive or store your recording or exported video.
When you record, choose a character and effects, and save your video, all of that happens locally on your own device:
- Camera and microphone capture, face tracking and video composition all run inside your browser.
- The final video is created on your device and is then either downloaded to your device or passed to your device’s operating system so you can share it. We do not choose where it goes and we do not keep a copy.
- While you are working on a recording, a temporary copy is saved in your browser’s local storage (IndexedDB) so that a page refresh or browser restart does not lose your work. This temporary copy expires after 12 hours.
- It is removed sooner if you choose Retake/reset, or if you clear your browser storage.
This local temporary copy lives only on your device. It is notserver storage — ChinFace App never receives it.
This does not mean that no information at all is processed. To deliver the website and the in-browser tools, our hosting and content-delivery providers process limited technical information, which is described below.
3. Information processed when you use the site
There is an important difference between information that stays on your device and information that is processed by service providers so the site can work.
Stored locally on your device (never sent to us as a record):
- a randomly generated guest device identifier;
- usage counters, including how many exports you have made today;
- your chosen visual theme;
- the temporary 12-hour copy of an in-progress recording.
Processed by service providers so the site can function:
- routine technical request information handled by our hosting provider (Vercel) — for example your IP address, browser/device information, the page requested, and the date and time — used to deliver and secure the site;
- aggregate page-view statistics collected by Vercel Web Analytics — the page or route you requested, the site you arrived from, filtered query parameters, approximate location (such as country and city), device type, operating system and browser — used only to count visits and see which pages are used. We have configured it to exclude our sign-in and team pages entirely, so page views for /admin, /login and /signup (and any pages beneath them) are never sent;
- requests to load public character packs and decorative assets, which are read from our stored application data;
- standard connection information received by the content-delivery networks that provide the in-browser face-tracking components (see section 6);
- if you email us, the information you choose to include in that message;
- authentication information for the ChinFace team only — this applies to our own admin sign-in and not to visitors or guests.
4. Why we use information, and our lawful bases
Under UK data-protection law we rely on the following lawful bases.
To provide the service you ask for (performance of a service / contract):
- delivering the website and the in-browser recording experience;
- remembering functional choices such as your theme;
- applying daily usage limits so the service stays available;
- enabling local recovery of an in-progress recording after a refresh.
Our legitimate interests:
- operating, securing and maintaining the service;
- preventing abuse and misuse;
- diagnosing and fixing faults;
- responding to support enquiries;
- keeping public character packs and assets available;
- understanding how the site is used through aggregate, cookieless page-view statistics.
Legal obligations:
- complying with applicable legal requirements and lawful requests where we are required to do so.
We use privacy-friendly, aggregate page-view analytics (Vercel Web Analytics) to see how many people visit the site and which pages they use. It counts page views only, and our sign-in and team pages (/admin, /login and /signup) are excluded from it. It does notuse cookies, does not build a profile of you, and does not follow you across other websites or apps. Nothing about you is attached to a page view — not your guest identifier, not your usage counters, and no information about what you made. We do notuse your information for advertising, and the service contains no advertising, marketing trackers or session recording. Granting your browser permission to use the camera is not permission for us to upload anything — no upload of your recording takes place.
5. Local storage and cookies
ChinFace App uses a small amount of browser storage to make the tool work. It does not use analytics cookies, advertising cookies, tracking pixels or fingerprinting.
Our page-view analytics is cookieless. It does not store an identifier in your browser: Vercel works out a temporary hash from the incoming request instead, and that hash is discarded after 24 hours. This is why there is no cookie banner — there is nothing to consent to storing on your device for analytics.
Guests do not receive an authentication cookie. The only cookie the application sets is used for the ChinFace team’s own admin sign-in.
Clearing your browser storage removes the guest identifier, usage counters, theme choice and any locally retained recording. Clearing storage may also reset your guest usage information (for example, your daily export count).
Technical detail: exactly what is stored
| Name | What it stores | Kept until |
|---|---|---|
| chinface_guest_id | A randomly generated device identifier used for guest features and usage-limit filtering. | You clear your browser storage. |
| chinface_usage | Guest usage counters, including your daily export usage. | You clear your browser storage. Daily counters reset as part of the app’s day-based limit logic. |
| chinface.theme | Your chosen visual theme. | You clear your browser storage. |
| IndexedDB (in-progress recording) | A temporary copy of your recording and the time it was saved. | 12 hours, or when you Retake/reset, or when you clear your browser storage. |
| chinface_auth (team/admin only) | Sign-in for the ChinFace team. Set as httpOnly, secure in production, with SameSite Lax. Not used by guests. | 7 days, or when the team member signs out. |
6. Who information may be shared with
We use a small number of service providers to run ChinFace App. Across all of them, no provider receives your recording through the ChinFace application.
- Vercel hosts and delivers the website. It may process ordinary technical request information such as your IP address, browser/device information, the page requested, and the date and time. Vercel also provides the cookieless, aggregate page-view analytics described in sections 3 and 5. It never receives a ChinFace recording through the application.
- Supabase stores public character packs, generated decorative assets and related application records, which our server routes read. It does not receive or store guest recordings or exported videos. As a guest you normally only read public assets and do not create database records.
- jsDelivr and Google Storage are content-delivery networks. Your browser downloads the MediaPipe face-tracking runtime and model from them. They may receive standard connection information such as your IP address, browser type and the request time. No camera recording, microphone audio or exported video is sent to them.
- OpenAI is used by the ChinFace team to create decorative characters and backgrounds from text prompts. Your recording is never sent to OpenAI.
- Namecheap Private Email receives messages you choose to send to support@chinface.app. Those messages may include your email address, the contents of your message, and any attachments you add. There is no marketing email or newsletter sign-up.
- Legal authorities, where we are required to share information by law.
Some providers may process technical information outside the UK. Where required, we rely on the safeguards made available by those providers.
7. How long information is kept
- Temporary local recording: up to 12 hours on your device, then removed automatically (or sooner if you Retake/reset or clear browser storage).
- Local preferences and usage information (theme, guest identifier, usage counters): kept on your device until you clear your browser storage.
- Daily usage counters:reset according to the app’s daily limit logic.
- Team/admin authentication cookie: 7 days, or until the team member signs out.
- Analytics visitor hash: worked out by Vercel from the incoming request and automatically discarded after 24 hours. Only the aggregate page-view statistics remain after that.
- Support emails: kept only as long as reasonably needed to respond, keep an appropriate support record, and meet any legal obligations.
- Infrastructure logs:retained according to operational needs and our providers’ settings.
8. Children
ChinFace App is not intended for children under 13.
- Children under 13 must not use ChinFace App.
- If you are aged 13 to 17, you may only use ChinFace App with permission from a parent or legal guardian.
- You must have permission to record every person who appears in a recording.
- Parents and guardians are responsible for supervising a minor’s use of the service.
Parents and guardians with any concerns can contact us at support@chinface.app.
9. Your rights
Depending on your circumstances, UK data-protection law may give you rights to:
- access information held about you;
- have inaccurate information corrected;
- have information deleted;
- restrict how information is used;
- object to certain uses;
- ask for information to be provided in a portable form.
Because your recordings and exported videos stay on your own device, ChinFace App cannot retrieve, provide or delete them for you — we never hold them. You control them directly on your device.
To make a request, contact support@chinface.app.
10. Complaints
If you are unhappy with how your information has been handled, you can complain to the UK Information Commissioner’s Office (ICO). You can find out how at ico.org.uk/make-a-complaint. We would also welcome the chance to address your concerns first at support@chinface.app.
11. Changes to this notice
We may update this notice when the service changes. When we do, we will update the “Last updated” date shown at the top of this page.