Skip to content
DejaWhere

Draft — pending legal review

This text is a working draft and is not yet in effect. It will change before launch.

DejaWhere Biometric Information Policy

Version: 0.1 (draft) Last updated: 2026-10-03 Effective date: [TO FILL — not before launch]

This policy explains how DejaWhere handles biometric data in its optional People feature (face recognition in the cloud). It is written to meet the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington biometric identifiers law (RCW 19.375) and the Washington My Health My Data Act where it applies, and to sit alongside GDPR Article 9 and the Israeli Protection of Privacy Law. It is part of, and read with, our Privacy Policy and Terms of Service.


The short version

  • People is off until you turn it on. We only create face data after you say yes on a screen of its own.
  • Adults only. People is available only to accounts aged 18 or over.
  • We never sell, rent, trade or disclose face data. Not for advertising, not to data brokers, not to anyone.
  • Your faces are compared only with your own photos. Never with anyone else's photos and never with any outside database. We never recognise celebrities or public figures.
  • We delete it when you turn People off (within 24 hours), and in any case no later than 3 years after your last interaction with DejaWhere.

1. Who we are

DejaWhere is operated by [TO FILL — legal entity name, company number, registered address] ("DejaWhere", "we", "us"). Contact: see Section 12.

2. What biometric data we collect

When you turn on People in the cloud, our servers analyse the faces in the photos and videos you have backed up (for a video, in key frames) and create a face template for each face: a string of numbers that measures the face so we can tell whether two faces are probably the same person. A face template is a biometric identifier. We also keep the groups the templates form, and the names you give them.

We do not:

  • identify anyone against any database, or recognise celebrities or public figures;
  • match your faces with other users' photos or with the photos or templates of any other account;
  • estimate a person's age, gender, ethnicity, emotion or health from a face;
  • create face data from your photos unless People is on.

The faces we analyse include other people who appear in your photos (see Section 9).

3. Why we collect it

For one purpose only: to group the faces in your own photos and videos into people, so that you can name them and find "all photos with Maya". We do not use face data for advertising, profiling, AI training, security or any other purpose, and we do not use it to decide anything about a person.

4. Your explicit consent

  • We ask for your consent on a screen of its own, before any face is analysed. It states in plain words what is collected, why, how long we keep it and how it is destroyed, and links to this policy.
  • The screen has a "Not now" button as easy to press as "Find people". Consent is never bundled with Backup, a subscription, sign-up or the Terms, and nothing is pre-ticked.
  • We record what you agreed to (the text version), and when. If the consent text changes materially, People pauses until you accept again.
  • Before collecting any biometric identifier we also give you this written policy, with the purpose and the length of time we will keep the data, as the law requires.
  • You can withdraw consent at any time (Section 7). Declining or withdrawing never reduces your plan, your Backup or any other feature.

5. No sale, no disclosure

We do not sell, lease, trade or otherwise profit from face data. We do not disclose, redisclose or disseminate it to any person or company, except:

  1. with your consent, which we do not ask for any other purpose today;
  2. where a valid legal process requires it (for example a court order or a lawful warrant), in which case we limit what we give to what the order requires and, where the law allows, tell you first;
  3. to our own infrastructure providers acting only as our processors under contract, to store the encrypted data (for example our cloud hosting). Our face model runs on our own servers: no face data goes to any other company for analysis, and no AI vendor receives it.

Authorised staff may see your photos and People groups only as the Privacy Policy (Section 9) describes: on a stated reason, with multi-factor authentication, in short logged sessions.

6. Retention and destruction schedule

We keep face data only as long as needed for the purpose in Section 3, and never more than 3 years after your last interaction with DejaWhere. We permanently destroy it at the earliest of:

EventWhen it is destroyed
You turn People off (withdraw consent)Within 24 hours, all templates and groups (names stay on your phone only if you choose)
You delete the photo or videoIts face templates are destroyed with it; the copies are gone from storage within 24 hours
You use "Delete my backup"Within 24 hours
You delete your accountYour encryption key is destroyed, which makes the data unreadable at once, and the stored files are removed within 14 days (usually 24 hours)
Your subscription ends and the photos are removed (see the Privacy Policy, Section 3.4a)When those photos are removed
You do not sign in for 24 monthsAfter 24 months, with a warning first [confirm]
Any other case: 3 years after your last interaction with DejaWhereAt the latest at that point, whatever else is true
The purpose is satisfied or ends (for example we stop offering People)Promptly

Destruction means deleting the templates and the groups from our databases and storage, and from the media worker. Copies in our own backups of the database expire within 14 days. Our consent record (what you agreed to and when) is kept for 5 years after consent ends [lawyer to confirm], as proof of compliance, and contains no face data.

7. Withdrawing consent and your rights

  • In the app: turn People off in the Privacy Center or in the Backup settings. We delete your face data within 24 hours.
  • By email: write to the address in Section 12 and we will do it for you.
  • Your other rights. You can see which faces we hold groups for, name or merge or remove them, export the names and labels with your backup, and ask us for a copy of what we hold about you. The rights in Section 11 of the Privacy Policy apply.
  • If you live in Illinois, Texas or Washington (or elsewhere with a similar law), you have the rights these laws give you, and we will honour them. We will not retaliate against you for using them.

8. Security

We protect face data at least as well as we protect the rest of your Backup, and with more care than our own most sensitive data. Templates and groups are encrypted with your personal key and stored on our servers in the EU [confirm region]; they are encrypted in transit; access is restricted, logged and requires multi-factor authentication; and destroying your key makes them unreadable at once. We tell affected users and the authorities of a breach as the law requires. We apply the same standard of care we use for other confidential and sensitive information we hold.

9. People who do not use DejaWhere (non-users' faces)

Your photos may show other people who have not agreed to anything and who have no account. We cannot ask them for consent. So:

  • Their faces are grouped only inside your own library and only you see the groups. They are never matched with any other account's photos.
  • We do not identify them, we do not link a face to a real-world identity, and we do not use their data for any purpose beyond showing you your own groups.
  • Please name people with care and, where it matters, tell them. If a person asks us to remove their face from your library or to confirm what we hold, write to us (Section 12) and we will help, to the extent we can find them, which may require their photo and your help.
  • If you turn People off or delete the photos, their face data is destroyed too, under Section 6.

10. Where and for whom People is available

  • Minimum age 18. People is offered only to accounts aged 18 or over, and is switched off for anyone who is under 18.
  • Availability. People ships with DejaWhere at launch. We may turn it off in a place, in whole or in part, where local law requires, while we check it. If we turn it off for you, we destroy your face data under Section 6.
  • On your phone only (without Backup). An on-device mode keeps face templates on your phone and not on our servers. It has its own, lighter consent, and turning it off erases the data on the phone. This policy's server-side promises do not apply to it, because we never receive that data.

11. Changes to this policy

If we change this policy in a way that matters (for example a new purpose, a new kind of recipient or a longer retention period), we will tell you in the app or by email before the change takes effect, and we will ask for your consent again before using your face data in a new way. The version history is below.

  • 0.1 (2026-10-03). First draft, for People in the cloud at launch.

12. Contact

DejaWhere — [TO FILL — legal entity, address] Privacy and biometric data requests: privacy@dejawhere.app [confirm domain] Data protection contact: [TO FILL]