Loading
Loading CorosLink Faces content.Loading
Loading CorosLink Faces content.How we use personal data and the choices available to you. Effective July 19, 2026.
CorosLink Contributors (open-source project) decides why and how CorosLink Faces processes personal data and is the data controller. Contact akerrules@gmail.com for privacy questions or rights requests. This email is the project's primary public privacy contact; additional legal contact details will be published where applicable law requires them.
Service delivery (contract). We use your Auth0 subject, name, email, email-verification status, profile, watch selections, saved faces, download history, reviews, and uploads to create your account and provide the features you request. Required account data comes from you and Auth0. If required data is not provided, creator and account features cannot operate.
Security and community safety (legitimate interests). We process upload hashes and scan results, security events, rate-limit identifiers, reports, moderation decisions, and audit records to prevent malware and abuse, enforce the terms, protect users, and establish or defend legal claims. We do not store raw IP addresses in the application database for upload or report rate limiting; keyed non-reversible values are used instead. Hosting providers may still process IP addresses in ordinary security and request logs.
Optional analytics (consent). Vercel Analytics measures page views and interactions only after you choose “Accept analytics.” Analytics is off by default, refusal does not limit the service, and you can withdraw consent through “Privacy choices” in the footer.
Legal obligations. We may preserve and disclose limited records when law requires it or when necessary for legal claims.
Profile handles, display names, avatars, profile text, reviews, watch-face listings, and published artwork are public by design. Do not include private information in public fields or uploaded artwork. Public profile usernames, listing text, tags, and supported image assets are sent to OpenAI's moderation service to detect disallowed content. ZIP archives, passwords, account credentials, and creator email addresses are not sent to OpenAI for this moderation. Automated checks can reject or hold content for review, but they do not make decisions that produce legal or similarly significant effects.
Reports store the reported content, category, details, optional contact email, status, and moderator actions. Signed-in reports are associated with the reporting account. Reports remain private to authorized moderators and relevant service providers.
Necessary Auth0 session and transaction cookies provide sign-in and security and normally expire with the configured session. Download receipt cookies prove eligibility to review a downloaded face and expire after 30 days. The coroslink-theme cookie stores a theme for one year. The coroslink-consent-v1 cookie stores analytics acceptance or refusal for 180 days. Upload drafts are kept in local browser storage until submission, replacement, or manual browser-data deletion. Optional analytics does not load before consent.
Auth0 provides authentication; Vercel provides hosting, Blob storage, queues, sandboxed scanning, and optional analytics; Neon provides the database; and OpenAI provides content moderation. These providers process data only for the service functions described above under their applicable contracts. Some processing may occur outside the EEA. Where required, transfers must rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Contact us for information about the safeguard relevant to your data. The operator must verify current provider regions, data-processing agreements, subprocessors, and transfer impact assessments before EU launch.
Upload intents without a file are deleted after 24 hours. Quarantine ZIPs for rejected or failed uploads and unreferenced quarantine objects are deleted after 72 hours. Failed publication objects are deleted after 24 hours. A creator deletion removes the listing immediately and deletes its release, preview, and associated quarantine archive after a 7-day recovery period. Download receipt cookies expire after 30 days, consent choices after 180 days, and theme choices after one year.
Account and content data remains while the account or listing is active. On account deletion, direct profile identifiers and preference data are erased or pseudonymized immediately. A pseudonymous account key, package hashes, security scans, upload/publication history, reports, and lifecycle audit events may remain only while needed for security, moderation, legal obligations, or legal claims. The operator must adopt and enforce maximum database, backup, provider-log, and analytics retention periods before EU launch; this notice does not invent periods that are not yet enforced by code or provider configuration.
Settings lets you correct profile details, download a JSON copy of your product data, and delete the local CorosLink account. Account deletion hides listings, pseudonymizes direct profile identifiers, deletes saved faces, watch selections, helpful votes, and authored reviews, and starts the published-file deletion process. Auth0 separately controls the upstream identity; email us to request erasure there as well.
Subject to applicable conditions, you can request access, correction, erasure, restriction, or portability of your personal data and object to processing based on legitimate interests. You can withdraw consent at any time. We respond without undue delay and normally within one month, and may ask for information needed to verify identity. If a request is refused, we will explain why and tell you about available complaint and judicial-remedy options.
You may complain to the data protection authority in the EU/EEA country where you live or work, or where you believe an infringement occurred. You are not required to contact us before complaining.
CorosLink Faces is not directed to children and does not knowingly seek children's personal data. The operator must set and enforce an age-eligibility rule that accounts for the digital-consent age in each supported EU country before enabling public self-service signup.
We will update the effective date and provide appropriate notice before a material change takes effect. This notice describes the current product; it is not a substitute for the operator's required records of processing, processor contracts, security procedures, or legal review.