Privacy

Updated October 2, 2026

Your photos

Photo decoding, face detection, box adjustments, effects and export run on your device. BlurFaces does not upload your photos, previews, filenames or face locations. We do not put them in analytics, URLs, browser storage, app logs or remote error reports.

The editor holds the image and the edited file in memory. Clear photo, replace the photo or close the tab to release the active session. This does not delete the original file, your downloads, screenshots, browser/OS caches or files already handed to another app.

Downloads and sharing

Exports are newly encoded images at the original, oriented pixel dimensions. The original file remains unchanged. Original EXIF/GPS, camera, timestamp and descriptive metadata are not copied. Encoders may add their own format information; exports are not promised to contain no metadata of any kind. JPG flattens transparent areas onto white; PNG and supported WebP exports preserve transparency.

Download preserves your original filename stem and adds _blurfacesapp before the output extension, for example photo_blurfacesapp.jpg. BlurFaces does not add branding to image metadata. Share gives that edited file, including its filename, to your chosen operating-system share destination. The destination can process or upload it under its own policy. Cancelling the share sheet does not trigger a download.

Current services and storage

Umami analytics is available only after you choose Allow analytics. It stays off by default.Advertising areas are placeholders; no Google ad/consent or remote crash-reporting script loads. The app sets no cookies. When analytics choices are available, it saves only your allowed/denied choice in localStorage under blurfaces.analytics-consent.v1. No photo or face data is saved in browser storage. Light mode is fixed and does not save a preference.

When the public site is hosted on Cloudflare Pages, Cloudflare serves ordinary web requests and may process IP addresses, request URLs and browser headers for delivery, security and operational logs. Those requests contain no app-uploaded photo data. See Cloudflare’s privacy policy. A local development preview is served from your computer.

Optional analytics

With your permission, Umami Cloud receives coarse usage events. It loads from https://cloud.umami.is/script.js and sends events to https://gateway.umami.is/api/send. The app event allowlist is:

App events sent only with analytics permission
EventAllowed fields
pageviewAllowlisted page path and known search engine origin only
image_loadedAn image was opened; no image properties
faces_detectedFace count and a duration bucket: under 1s, 1–3s, or over 3s
face_manual_addCount of manually added boxes
style_appliedPixelate, blur, block or emoji
image_exportedDownload/share, actual output format, enabled box count and first-export flag

Events must not include photos, filenames, face coordinates, image-derived text, original metadata, a photo/session identifier or raw timings. Counts are capped at 1,000 (1,000 means 1,000 or more). Hidden-face counts are enabled boxes, including manually added boxes; they are not a guarantee of anonymization or a count of unique people. The first-export flag is a boolean kept locally per opened image, not an identifier. We send only known public page paths (other paths become /other), no URL query/hash, and only a known search engine origin, never a referring page/query. Automatic click, performance, session enrichment and cross-page tracking features are disabled. Umami receives your IP address and ordinary browser headers for delivery and can derive aggregate visit/session information and coarse location. Its response may contain an ephemeral cache token used by its tracker; we do not supply a person or photo identifier. We do not claim that aggregate analytics is perfectly anonymous. You can decline or withdraw permission on Cookie settings. Do Not Track and Global Privacy Control keep analytics off. Withdrawing prevents new app events; it does not delete counts already sent. Offline events and events while the tracker is unavailable are dropped, never stored for later delivery. See Umami’s privacy policy.

Planned ads and consent

We plan to use Google AdSense and Google’s consent message where required. These are not enabled yet. Ad/consent services can use cookies or similar storage and process browser/connection information. Before enabling them, we will list the active domains and choices here and on Cookie settings. Photos and face locations must never be supplied to those services.

See Google’s advertising information. The editor will remain usable without accepting optional services.

Questions and changes

Contact BlurFaces through @blurfacesapp on X about this notice or privacy requests. Visiting X is subject to X’s own policy. Please do not send private photos. We will update this notice when our services change.

Verify local processing · Terms ·Open the editor