We built tagme to be a place where you're automatically tagged in photos — not tracked, profiled, or monetised. Here's exactly what we collect and why.
tagme operates the tagme mobile app and the website at plstag.me. For any privacy questions, reach us at [email protected].
By creating an account you agree to this policy. If you don't agree, please don't use the service.
tagme is for users aged 13 and older. We don't knowingly collect data from anyone under 13. If you think a child under 13 has created an account, email us and we'll delete it promptly.
| Data | Details |
|---|---|
| Account info | Username, email, bcrypt-hashed password, optional display name and bio |
| Photos | Photos you upload to groups or set as a profile picture |
| Biometric / face data | Mathematical face embeddings derived from uploaded photos via AWS Rekognition — see Section 5 |
| Server logs | IP address, device type, pages accessed, timestamps — retained 90 days |
| Push token | Expo push token if you enable notifications |
We don't use your data for advertising. We don't sell your personal information.
If you're an Illinois resident, completing signup and consenting to face enrollment constitutes the written release required under the Illinois Biometric Information Privacy Act (740 ILCS 14). You may revoke consent and request deletion of your biometric data at any time by deleting your account or emailing [email protected].
What it is: a numeric vector ("face embedding") that represents your facial geometry, generated by AWS Rekognition from photos you upload. We don't store raw pixel data as biometric data — only the vector.
Why: to automatically identify and tag you in photos uploaded to your groups.
Who can auto-tag you: you are only auto-tagged by people within your own network on tagme — members of groups you have joined, and users who follow you. You are never auto-tagged by the general public or by all tagme users. Because your face is only enrolled after you consent, and because tag suggestions must be confirmed by you before they appear, you retain control over who on tagme can identify you.
Retention: kept for as long as your account exists. Deleted from AWS Rekognition within 30 days of account deletion.
No sale: we don't sell, lease, trade, or otherwise profit from biometric data.
Processor: AWS Rekognition (Amazon Web Services) processes face data on our behalf under a data processing agreement. AWS doesn't use your data to train its own models. See the AWS Privacy Notice.
Security: face embeddings are stored in an AWS Rekognition collection secured by IAM access controls. They are not stored on our server or in our database beyond the reference ID.
Photos you upload are stored on our server and visible to members of the group you upload to. They are not publicly accessible by default. Deleting a photo or your account removes the photo, all derivatives (thumbnails, medium sizes), and any linked face embeddings from our systems.
| Party | Role | Data shared |
|---|---|---|
| AWS Rekognition | Face recognition processor | Face images and embeddings |
| Oracle Cloud | Hosting | All data stored on their servers |
| Cloudflare | CDN / DNS | Network traffic in transit |
| Legal | Compliance | Disclosed only if required by law or court order |
No advertisers. No data brokers. No analytics SDKs.
Email [email protected] or use in-app controls to:
We'll respond within 30 days.
Legal basis: we process personal data on the basis of (a) contract performance — to provide the service you signed up for; and (b) consent — for biometric data, which you may withdraw at any time.
Data transfers: your data is stored and processed in the United States. By using the service, you acknowledge transfer to the US, which may not have equivalent protections to those in your country.
Your rights include access, rectification, erasure, restriction, portability, and the right to object. You also have the right to lodge a complaint with your local supervisory authority. Contact us at [email protected].
All data in transit is encrypted via HTTPS / TLS through Cloudflare. Passwords are bcrypt-hashed and never stored in plaintext. Biometric data is access-controlled via AWS IAM. No method of storage or transmission is 100% secure — we can't guarantee absolute security, but we take it seriously.
The website uses no tracking cookies. The mobile app stores your login token in device secure storage. We don't use third-party analytics or advertising SDKs.
If we make material changes — especially to how we handle biometric data — we'll notify you via email or an in-app notice before the change takes effect. The date at the top of this page reflects the most recent update.
Email us any time at [email protected]. We actually read it.