Skip to content

Privacy Policy

Updated on October 7, 2026 · 11 min read

Read this page in Portuguese

Quick answer

You upload a photo that is yours, or that you are authorized to use. A face pre-analysis runs in your browser and is not sent to us. On our server an automatic safety check refuses photos showing a possible minor, nudity or no face (refused photos are not stored); then we extract an image vector, compare it with publicly accessible web pages and show you the result. You keep an account (Google or an email code) where your credits and reports live. An accepted image is stored encrypted for up to 7 days, then deleted. You can exercise your rights, including erasure and withdrawal of consent, by emailing the contact below.

On this page

1. Who is the controller#

The controller of your personal data is StopCatfish Tecnologia Ltda. (company registration: 00.000.000/0001-00), which operates the service "StopCatfish". [LEGAL REVIEW] Contact for privacy matters and data protection requests: privacidade@stopcatfish.com. If an EU or UK representative is required, details will be added here. [LEGAL REVIEW]

2. How the service works#

  1. Upload and sign in

    You sign in (Google or an email code), upload a photo (JPG, PNG, WEBP, up to 15 MB) and confirm that the photo is of you or that you are authorized by the person pictured.

  2. Local face pre-analysis

    Your browser runs a face detection for visualization only. This analysis stays on your device and is never sent to us.

  3. Safety check on our server

    Before anything else, a model estimates the age of every face and a classifier checks for nudity or explicit sexual content. If any face appears to be under 21, if the estimate is not reliable, if the content is explicit or if there is no face, the photo is refused and discarded immediately, without being stored. [LEGAL REVIEW]

  4. Deep search on our server

    We extract an image vector and compare it with publicly accessible web pages. This takes a few minutes.

  5. Summary and email

    You see a summary on screen and receive an email with a link to it.

  6. Unlock with a credit

    The full report is unlocked with 1 credit. Credits are bought in packs and live in your account.

3. Data we process#

  • Account. Your email address and, if you sign in with Google, the name and profile photo Google shares with us. We also keep session data so you stay signed in (essential cookies only).
  • Image you upload. Used for the safety check, the search and to verify your report. If it is accepted, an encrypted copy is stored for up to 7 days for report verification and security audits, then deleted automatically.
  • Safety check. The estimated age of each face and the explicit-content scores. When a photo is refused as a possible minor or as explicit, we keep an incident record with the image's fingerprint (SHA-256 and perceptual hash), the scores, your IP address, email and the time, never the photo. [LEGAL REVIEW]
  • Derived biometric vector. A numeric representation of the visual features of the image, which may include facial features. It is biometric data when used to uniquely identify a person.
  • Email address. Used to deliver the link to your results and for service messages about your search.
  • Search results. The matches and the summary shown to you. They stay linked to your account while the scan data is retained. Our team may review an analysis to check its quality; we do this only to verify the report, never to identify or contact the people in the images.
  • Credits and orders. The packs you buy, the credits you hold and spend, and the status of each payment. Payments are processed by CommerceGate; card data never touches our servers.
  • Event log, technical logs and IP address. IP address, user-agent, time and service events (for example: photo upload, sign-in, order, payment, denied access attempts), used for security, abuse prevention, troubleshooting and service statistics.
  • Where your visit came from. Two first-party cookies, sc_vid (a random browser id) and sc_src (the campaign you came from and the ad click id), kept for 30 days. [LEGAL REVIEW]
  • Referral program. If you arrived through a referral link, the first-party cookie sc_ref keeps the link's code for up to 30 days (or until you sign in). When you create your account we record which account referred you and, on your first purchase, the referrer's bonus. The referrer only sees numbers (how many people signed up and bought), never your name or email. [LEGAL REVIEW]
  • Consent record. The wording and version of the consent you accepted, and when.

Metadata in the image (EXIF, including GPS location) is stripped in your browser before upload when your browser supports it. Do not rely on this for sensitive photos; remove location data yourself if in doubt.

4. Why we process it and legal bases#

You can withdraw consent at any time (GDPR Art. 7(3)). Withdrawal does not affect processing done before it. Because the biometric vector is needed to run the search, withdrawing consent means we stop processing and delete it.

5. How long we keep data#

The image you upload is stored encrypted for up to 7 days, to complete and verify your report and for security audits, and is then deleted automatically. Results stay linked to your account while the scan data is retained. Photos refused by the safety check are not stored; the incident record (hashes, scores, IP address and email, without the photo) is kept for security and to answer the authorities. [LEGAL REVIEW] Account details are kept while your account exists. Payment and tax records are kept for the period required by law. IP addresses and user-agents are removed from the event log after 90 days; the events themselves, without them, are kept for service statistics. [LEGAL REVIEW] The sc_vid, sc_src and sc_ref cookies expire after 30 days (sc_ref is deleted earlier, when you sign in). We will not keep biometric data longer than needed for the purpose for which it was collected.

6. Who we share data with#

  • Hosting and infrastructure providers that run the service for us.
  • Payment processor: CommerceGate processes card payments (USD/EUR) and PIX (Brazil). Card data goes straight to them and never touches our servers. They act under their own terms and privacy policies for payment data.
  • Sign-in providers: if you choose Google sign-in, Google tells us your email, name and photo.
  • Email delivery providers that send the results link.
  • Bot protection: when enabled, Cloudflare Turnstile checks that the photo form and the sign-in code request come from a person; Cloudflare processes your IP address and browser signals for that check under its own privacy policy. [LEGAL REVIEW]
  • Ad network: if you came from an ad and made a purchase, we tell the ad network only the ad click id, the order value and the currency, so it knows the ad led to a sale. We never send your email, name, photo or results. [LEGAL REVIEW]
  • Authorities, when required by law. Where there are signs of child sexual abuse or exploitation, we report to the competent authorities: NCMEC for traffic from the United States, and SaferNet Brasil and the Federal Police (Polícia Federal) in Brazil. [LEGAL REVIEW]

We do not sell your personal data, and we do not share it for cross-context behavioral advertising.

7. International transfers#

Our providers may process data outside your country, including outside the EU/EEA and the UK. Where required, transfers rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses (GDPR Art. 46) and the UK equivalents. [LEGAL REVIEW] List of providers and locations: [LEGAL REVIEW]

8. Your rights#

EU/EEA (GDPR) and UK (UK GDPR)

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to solely automated decisions with legal or similarly significant effects (Art. 22). You can also withdraw consent at any time (Art. 7(3)) and lodge a complaint with your supervisory authority (Art. 77); in the UK, that is the Information Commissioner's Office (ICO). We do not make solely automated decisions with legal or similarly significant effects about you.

California (CPRA) notice at collection

If you are a California resident, in the preceding 12 months we collected the following categories: identifiers (email address, account name and photo if you use Google sign-in, IP address), biometric information (image vector), commercial information (credit purchases and spending) and internet activity (technical logs), for the purposes in section 4. We do not sell or share personal information as those terms are defined in the CCPA/CPRA. You may request to know, delete or correct your personal information, and to limit use of sensitive personal information, without retaliation. [LEGAL REVIEW]

Illinois (BIPA-style written release and retention schedule)

Before we process a biometric vector, you give an informed written consent through the checkbox and consent text shown at upload, which states the purpose (a single search) and the retention approach. We destroy biometric identifiers when the initial purpose has been satisfied or within the period stated in this policy, and in any event within three years of your last interaction. The uploaded image is deleted within 7 days at most, and the vector is deleted with the scan data. [LEGAL REVIEW]

To exercise any right, email privacidade@stopcatfish.com. We may ask you to verify your identity. We aim to reply within one month (or the period required by the law that applies to you).

9. Children#

The service is not for people under 18. Never upload a photo of a minor, even if you are a parent or guardian.

Zero tolerance. Every photo goes through an automatic age estimation before the search. A photo showing a possible minor is refused and discarded without being stored; we keep only the incident record (hashes, IP address, email and time). Two such incidents on the same account permanently block that account and its email (incidents without an account are reviewed by our team), and cases with signs of abuse are reported to the authorities (NCMEC for US traffic; SaferNet Brasil and the Federal Police in Brazil). [LEGAL REVIEW]

10. Face detection in your browser#

The face pre-analysis that draws boxes or landmarks on your photo runs locally in your browser for visualization. Its output never leaves your device. Only the image you choose to submit is sent to our server over an encrypted connection (TLS). We do not claim end-to-end encryption.

11. Cookies#

We use essential cookies and similar storage needed for the service to work (for example, language and your signed-in session) and two first-party measurement cookies: sc_vid (a random browser id) and sc_src (the campaign you came from and the ad click id), kept for 30 days, to learn which campaigns bring visits and purchases. Visitors who arrive through a referral link also get the first-party cookie sc_ref, with the link's code, for up to 30 days. We do not use third-party cookies or third-party advertising trackers. Where the law requires consent for these cookies, we will ask for it. [LEGAL REVIEW]

12. Security#

Uploads are protected by TLS. Accepted photos are kept in an encrypted vault (AES-256), outside the web server and with no public address, and are deleted automatically after 7 days; only our administration can access them, and every access is logged. No system is perfectly secure, and we cannot guarantee absolute security.

13. Changes to this policy#

We may update this policy. The update date is shown at the top of the page, and material changes will be announced in the service. Where consent is needed for a new purpose, we will ask again.

14. Contact#

Privacy and data protection: privacidade@stopcatfish.com. General support and refunds: suporte@stopcatfish.com. See also the Terms of Use.

Frequently asked questions

Do you keep my photo?

The image you upload is stored encrypted for up to 7 days, to complete and verify your report and for security audits, and is then deleted automatically. Photos refused by the safety check are not stored. Results stay linked to your account while the scan data is retained.

Is my face analysis sent to your servers?

No. The face pre-analysis that shows boxes on your photo runs in your browser and never leaves your device. Only the image you submit is uploaded for the search.

What is the legal basis for processing my face?

Your explicit consent (GDPR Art. 9(2)(a)), given before each search. You can withdraw it at any time by emailing us.

How do I ask you to delete my data?

Email privacidade@stopcatfish.com from the address you used for the search, and we will handle your erasure request under GDPR Art. 17 or the law that applies to you.

Can I upload a photo of my child?

No. The service is for people aged 18 or over, and you must never upload a photo of a minor.

Sources

  1. GDPR, Regulation (EU) 2016/679 (EUR-Lex)
  2. ICO: individual rights under UK GDPR
  3. California Attorney General: CCPA
  4. Illinois Biometric Information Privacy Act, 740 ILCS 14 (ilga.gov)
  • Terms of UseUse this service only with your own photo or with the explicit authorization of the person pictured, and only if you are 18 or older. Identifying or locating strangers is prohibited, and there is zero tolerance for any content involving minors. You see how many matches were found before paying, and nothing is charged if there are none; the full report unlocks with 1 credit (packs from $9.90 / €9.90). We cannot guarantee that every occurrence of an image will be found.
  • How to find where your photos are used onlineStart with free reverse image search (Google Lens, Bing Visual Search, TinEye) to find copies of a specific photo, then use a similarity search to look for other pictures that show your face. Only search for your own photos, or those of someone who has explicitly authorized you. No tool covers the whole internet, so treat every result as a lead to verify, not as proof.