THANKQR / TRUST ARCHIVEDOCUMENT 06 · CURRENT
Trust, privacy & useful detail

Face Processing & Find Me

How ThankQR uses face detection and reference matching inside private event galleries.

REVISED / 16 July 2026
TECHNICAL PLATE / FIND ME

A portrait becomes
a private search.

REFERENCE SIGNALEVENT BOUNDARY

The feature narrows one private collection. It is not a public identity search.

01A face enters
INPUT / GUEST CONTROLLED

Reference

A guest chooses a clear image and selects the face they want to find.

02The image becomes a map
PROCESS / PRIVATE SIGNAL

Geometry

Distinctive facial relationships are translated into a matchable numerical encoding and the original image is discarded

03The event is searched
OUTPUT / LIKELY MOMENTS

Compare

That encoding is compared only with faces detected inside the relevant private event.

BOUNDARY NOTE / 001

Guests can remove saved Find Me references and results. Event deletion and account purge flows remove their related face data.

READ THIS FIRST

ThankQR includes optional face-powered features to help guests find themselves in event galleries and help hosts organize photos.

This page explains what we process, when it happens, and how guests can control or delete account-linked Find Me data.

01

What is processed

When photos are uploaded, ThankQR may detect faces in the image and generate internal face-related metadata such as face regions and matchable encodings used for event organization and Find Me results.

When a guest uploads a reference image in Find Me, ThankQR analyzes that image to detect candidate faces and compare the selected face against photos within the relevant event.

02

What the feature does

Find Me returns likely matching event photos. With a separate explicit choice, a signed-in guest can save a reusable reference profile for that event only.

Hosts may also see grouped face clusters in their event dashboard to help moderate, organize, or review event media.

03

What the feature does not do

ThankQR does not use face data for advertising, public identity lookup, generalized surveillance, or unrelated profiling.

Face data is not exposed as a public API for third-party identification.

04

Controls and deletion

Guests must explicitly consent before a reference image is analysed. Saving a reusable profile requires a second explicit choice. Either choice can be withdrawn from Find Me; withdrawing search consent also removes the event’s reusable profile and transient search data.

Photos deliberately saved to My Photos are ordinary gallery selections rather than biometric templates and remain until the guest removes them separately. Guest-account deletion deletes account-linked face profiles during purge.

Hosts may remove event photos, reject pending uploads, or delete event content, which can also remove associated face detections for that media.

05

Retention

Face detections and face-group metadata are retained only as long as the related event media remains in the service or until a valid deletion, purge, or moderation action removes it.

One-time encrypted reference data and search results expire within 24 hours. Reusable reference profiles are event-scoped and are deleted on withdrawal, account purge, or the applicable event lifecycle deletion.

Minimal consent evidence is retained for up to three years for accountability. It records the purpose, wording versions, decision, event and timestamps but contains no biometric values.

06

Questions

If you have a question about Find Me, face-processing disclosures, or deletion of account-linked face data, contact enquiries@thank-qr.com.