Legal

Privacy Policy

tagme is built to tag you in photos, not to track, profile or monetise you. Here is exactly what we collect and why.

Last updated: September 2026  ·  Effective: September 2026
Contents
  1. Who we are
  2. Minimum age
  3. What we collect
  4. How we use it
  5. Biometric data
  6. Phone & SMS
  7. Photos & group content
  8. Third parties
  9. Your rights
  10. EU / GDPR
  11. Security
  12. Cookies
  13. Changes
01

Who We Are

tagme is operated by Shayaan Kashif, doing business as tagme ("we," "us," or "our"), covering the tagme mobile app and the website at plstag.me. For any privacy questions, reach us at [email protected].

By creating an account you agree to this policy. If you don't agree, please don't use the service.

02

Minimum Age

tagme is for users aged 13 and older. We don't knowingly collect data from anyone under 13. If you think a child under 13 has created an account, email us and we'll delete it promptly.

03

What We Collect

Data Details
Account info Username, email, phone number, bcrypt-hashed password, optional display name and bio
Phone number Required at registration; used for SMS verification and account recovery. see Section 6
Device contacts (optional) Names and phone numbers from your contact list, only if you choose to share them. see Section 6
Photos Photos you upload to groups or set as a profile picture
Biometric / face data Mathematical face embeddings derived from uploaded photos via AWS Rekognition. see Section 5
Server logs IP address, device type, pages accessed, timestamps. retained 90 days
Push token Expo push token if you enable notifications
04

How We Use It

We don't use your data for advertising. We don't sell your personal information.

05

Biometric Data

Illinois residents. BIPA

If you're an Illinois resident, completing signup and consenting to face enrollment constitutes the written release required under the Illinois Biometric Information Privacy Act (740 ILCS 14). You may revoke consent and request deletion of your biometric data at any time by deleting your account or emailing [email protected].

What it is: a numeric vector ("face embedding") that represents your facial geometry, generated by AWS Rekognition from photos you upload. We don't store raw pixel data as biometric data. only the vector.

Why: to automatically identify and tag you in photos uploaded to your groups.

Who can auto-tag you: you are only auto-tagged by people within your own network on tagme. members of groups you have joined, and your friends. You are never auto-tagged by the general public or by all tagme users. Because your face is only enrolled after you consent, and because tag suggestions must be confirmed by you before they appear, you retain control over who on tagme can identify you.

Retention: kept for as long as your account exists. Deleted from AWS Rekognition within 30 days of account deletion.

No sale: we don't sell, lease, trade, or otherwise profit from biometric data.

Processor: AWS Rekognition (Amazon Web Services) processes face data on our behalf under a data processing agreement. AWS doesn't use your data to train its own models. See the AWS Privacy Notice.

Security: face embeddings are stored in an AWS Rekognition collection secured by IAM access controls. They are not stored on our server or in our database beyond the reference ID.

06

Phone Number, SMS & Contact-Based Tagging

Phone number at registration: creating a tagme account requires a phone number. We use it to send a one-time verification code (OTP) by text message to confirm you control the number, and as a way to secure and recover your account. We don't use your phone number for marketing, and we don't sell it.

SMS consent

By providing your phone number and completing verification, you consent to receive text messages from tagme at that number. All texts from tagme are user-initiated. someone who knows you took a specific action on tagme (verifying your own number, or tagging you in a photo) that prompted the text. tagme does not send unsolicited messages or run outreach campaigns to numbers independent of a specific user action. Message types: (1) one-time verification codes, and (2) if you turn on contact-based tagging, a one-time notification text sent to a person you've tagged who isn't yet on tagme. Message frequency varies based on your activity. Message and data rates may apply. Reply STOP to any tagme text to opt out at any time, or HELP for help. Carriers are not liable for delayed or undelivered messages. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. text messaging originator opt-in data and consent are not shared with anyone outside the parties strictly necessary to deliver these messages (our SMS delivery provider and mobile carriers).

Contact-based tagging: if you choose to share your device contacts with tagme, we access the names and phone numbers in your contact list solely to (a) help you find friends already on tagme and (b) let you tag an unidentified face in a group photo with a contact who isn't yet a tagme user. Sharing your contacts is optional. you can decline the permission prompt or revoke it later in your device settings, and doing so does not affect your existing account.

What happens when you tag a non-user: this text exists only because you took that specific action. it is a one-time, user-triggered message, never an ongoing or unprompted campaign. We send that phone number exactly one SMS ("You've been tagged on tagme. download the app to see it"). We don't send them further messages unless they create an account and separately opt in to notifications. We retain the contact's phone number only for as long as needed to send that single message and to honor any opt-out, and we delete it once the tag or underlying photo is removed.

Non-user rights: anyone who receives a tagme text. whether or not they ever create an account. can reply STOP to be permanently suppressed from future messages, or email [email protected] to request deletion of their contact information from our systems.

Retention: your phone number is kept for as long as your account exists and deleted within 30 days of account deletion. Contact data for people who aren't tagme users is retained only until the one-time notification is sent (or the tag is removed) and is never used for any other purpose.

07

Photos & Group Content

Photos you upload are stored on our server and visible to members of the group you upload to. They are not publicly accessible by default. Deleting a photo or your account removes the photo, all derivatives (thumbnails, medium sizes), and any linked face embeddings from our systems.

08

Third Parties

Party Role Data shared
AWS Rekognition Face recognition processor Face images and embeddings
Oracle Cloud Hosting All data stored on their servers
Cloudflare CDN / DNS Network traffic in transit
SMS delivery provider Sends verification codes and one-time tag-notification texts Phone number and message content. never used for marketing by the provider
Legal Compliance Disclosed only if required by law or court order

No advertisers. No data brokers. No analytics SDKs.

09

Your Rights

Email [email protected] or use in-app controls to:

We'll respond within 30 days.

10

EU / EEA Users (GDPR)

Legal basis: we process personal data on the basis of (a) contract performance. to provide the service you signed up for; and (b) consent. for biometric data, which you may withdraw at any time.

Data transfers: your data is stored and processed in the United States. By using the service, you acknowledge transfer to the US, which may not have equivalent protections to those in your country.

Your rights include access, rectification, erasure, restriction, portability, and the right to object. You also have the right to lodge a complaint with your local supervisory authority. Contact us at [email protected].

11

Security

All data in transit is encrypted via HTTPS / TLS through Cloudflare. Passwords are bcrypt-hashed and never stored in plaintext. Biometric data is access-controlled via AWS IAM. No method of storage or transmission is 100% secure. we can't guarantee absolute security, but we take it seriously.

12

Cookies & Local Storage

The website uses no tracking cookies. The mobile app stores your login token in device secure storage. We don't use third-party analytics or advertising SDKs.

13

Changes

If we make material changes. especially to how we handle biometric data. we'll notify you via email or an in-app notice before the change takes effect. The date at the top of this page reflects the most recent update.

Questions?

Email us any time at [email protected]. We actually read it.