We rate the photo. Never the person.

Privacy Policy

Short version: your photo never leaves your device. We built ratemy.photos so the one thing you’d worry about most — a stranger’s server looking at your pictures — simply isn’t part of the deal. Here’s the honest, plain-English rundown.

Your photos

Every photo you drop into ratemy.photos is analyzed entirely on your own device, in your browser, using a small AI model that runs locally. Your photo is never uploaded, never transmitted to our servers or anyone else’s, and never stored by us — we simply never receive it. When you close or refresh the page, it’s gone, exactly like it never happened.

Sharing your result

If you choose to share or download a result card, that card is generated on your device too. By default it contains your score and breakdown only — not your original photo. There’s an optional toggle to include your photo on the card; that’s entirely your choice, and we still never see or receive that image ourselves — it’s drawn straight onto the card inside your browser.

The waitlist

If you join our waitlist, we collect your email address, the time you signed up, and which version of this consent text you agreed to. We send a confirmation email (double opt-in) before adding you to any list — until you click confirm, your address sits in a pending state and receives nothing else. If you don’t confirm within 7 days, that confirmation link expires and the signup is never added to any list. Once confirmed, we keep your entry only until we email you at launch — or until you ask us to delete it sooner, whichever comes first. To stop automated abuse of the signup form, we also briefly derive a one-way, salted hash of your IP address that rotates daily and is kept for at most 24 hours — it’s never stored alongside your email, never added to the waitlist table, and can’t be reversed back into an IP address. Legal basis: your consent (GDPR Art. 6(1)(a)) for the waitlist itself; the anti-abuse hash runs under our legitimate interest in keeping the signup form working for everyone (GDPR Art. 6(1)(f)). You can withdraw consent and ask us to delete your data at any time by emailing hallo@panomity.de — we’ll remove it without asking why.

No cookies, no trackers

We don’t use cookies. We don’t run third-party analytics, advertising trackers, or fingerprinting scripts of any kind — v1 of ratemy.photos ships with zero third-party tracking. We also don’t store your IP address in the waitlist table itself — see the next two sections for the only two places an IP address briefly passes through at all. All of this runs on Panomity’s own server in Germany — nothing is transferred to third countries or handed to third-party processors.

Server access logs

Like virtually every website, the web server this site runs on automatically logs incoming requests as part of normal, standard operation — and that log includes your IP address. This is a separate, purely technical process from everything else in this policy: it isn’t linked to your waitlist entry, doesn’t touch your photos, and nobody looks at it unless something’s gone wrong (security incidents, abuse, troubleshooting). These logs are kept for 10 days — rotated and compressed — for security purposes, and then deleted automatically on a rolling basis.

The AI model on your device

To avoid re-downloading several megabytes of AI model every time you use ratemy.photos, your browser stores the model files locally using standard web storage (Cache Storage and/or IndexedDB) — the same kind of technology most websites use to load faster on repeat visits. This only ever holds the AI model itself (identical for every visitor, no personal data in it) — never your photos, never anything else. Under applicable law (§25 TDDDG) this counts as strictly necessary technical storage, so it doesn’t require a cookie-consent banner — but we’re telling you anyway, because that’s the whole point of this page. You can clear it any time in your browser’s site-data settings; your next visit will simply re-download the model.

Ad slots

This page reserves space for ads in the future. As of this policy’s date, those slots are empty and load nothing — no scripts, no trackers, no third-party requests. If that changes, this policy will change first, and this section will say so plainly.

Your rights

Under GDPR you have the right to access, correct, or delete any personal data we hold about you (which, for most visitors, is little to nothing beyond the short-lived technical logs described above), the right to withdraw consent at any time, and the right to lodge a complaint with your local data protection supervisory authority. To exercise any of these, email hallo@panomity.de.

Changes to this policy

If this policy changes in a way that affects what we collect, we’ll update the date at the top and, for material changes, note it clearly on the site. We won’t quietly start collecting more than what’s described here.

Data controller

Panomity GmbH, Seilergasse 34, D-85570 Markt Schwaben, Germany. Handelsregister: HRB 264411, Amtsgericht München. Managing Director: Sascha Endlicher, M.A. Contact: hallo@panomity.de.

That’s the whole policy — no fine print hiding behind the fine print. Questions? hallo@panomity.de.