This document explains what data FaceMirror collects during a FaceMirror session, how it is processed, stored, and shared. The document follows the principles of the EU General Data Protection Regulation (GDPR).
FaceMirror service operator. Contact email: contact@facemirror.online.
The service needs access to your microphone for the spoken part of the session (up to 5 minutes). The camera is not used, and no image of you is captured. The audio recording passes through the FaceMirror server to a speech recognition service (OpenAI Whisper) and is not stored by FaceMirror.
After the spoken part ends, the audio is converted to text (words with their timing) by the external service. The resulting text is stored and used to generate your report; there is no comparison with other sessions. The transcription may incidentally contain personal information mentioned during the session (such as names, places, or other identifying details); this content is treated as personal data and retained for the full data retention period.
Numerical indicators are calculated: when each word was spoken relative to the rhythm beats, intervals between the starts of consecutive words, speech rate, the loudness (energy) of your voice over time, and vocabulary characteristics. Voice pitch is not measured. The metrics are stored and used to generate the report.
After the spoken part you answer 50 short statements about yourself (IPIP-BFM-50, a public-domain questionnaire). Your answers are stored; the summary scores are calculated on our server. They are used together with the behavioral metrics in your report. There are no norms or percentiles.
Gender, age range, education and your current state are required to start; field of work, native language and goals are optional. The questionnaire is stored with the session. In your next session it is pre-filled by email only after your invitation code has been accepted. Age range, education, current state, field of work, native language and goals are passed as context to the provider that generates the report and Deep Dive (section 7); gender is not passed. The questionnaire is also used for session analytics.
An email address is required: you cannot start a session without it. Your report and a link to the report page are sent to this address (see “Report access by link”). No newsletters or marketing.
FM3 request logs — of the web server and of the application — do not contain the IP address. The IP address is used only in server memory: for rate limiting and regional access restrictions. The country is derived from the IP address when the result is submitted and is stored with the result; the IP address itself is not stored. The browser type is not recorded by the FaceMirror application.
The report access code is sent to you by email. The link to the report page carries it in the address fragment (after “#”): the fragment is not sent to the server, and the page removes it from the address immediately. We store a hash of the code and an encrypted copy — only to send the same code again in a later email. Access works for 21 days; data deletion or access revocation ends it sooner.
This is exactly what FaceMirror stores after a completed session:
| Data type | What is stored |
|---|---|
| Email address | Links your sessions with each other (there are no user accounts). Deleted on request (section 9) or 36 months after the session (section 6). |
| Your spoken responses | Text transcript only, with word timing. The audio recording is not stored. |
| Voice analysis | Numerical loudness (energy) values, including how they change over time during the session. No audio recording, no voice pitch. |
| Timing and rhythm | When words were spoken relative to the rhythm beats; intervals between words. |
| Questionnaire answers | Your answers to the profile questionnaire and to the 50 self-report statements. |
| Session metadata | Timestamp, language, technical quality indicators, consent version and time. |
| Your report | The text of the report created with AI; for the EXTRA level, Deep Dive results for the topics you chose. |
| Report access by link | A hash of the access code and its encrypted copy (only to send the same code again). Access lasts 21 days, after which the copy is erased; the record is deleted 36 months after the session or when your data is deleted. |
Audio is sent to a speech recognition service for transcription only; we do not retain audio recordings. Sharing with third parties is described in section 7.
The audio recording after conversion to text. No video or image is captured at all.
Speech transcription text, numerical metrics, questionnaire answers, profile questionnaire, email, consent record, the report and Deep Dive results, a hash of the access code and its encrypted copy.
36 months after the session, direct identifiers (email) and the links and means of access controlled by FaceMirror are deleted: report access codes, the link between invitation codes and the session together with the email tag, and technical session keys. Behavioral data and related information — the transcript, speech and voice metrics, questionnaire and profile answers, country, the report and Deep Dive results, and the consent record — are kept in de-identified form for research and improving FaceMirror. We do not promise to rule out matching by time (for example, by the date of an email). Deletion on request — section 9. Deleted data may remain in database backups for some time until they are replaced on schedule. The report email stays in the recipient’s inbox.
External service providers are used. Data shared with each is minimal and limited to the processing purpose.
The audio recording is transferred via the FaceMirror server to the Whisper API for conversion to text.
The transcribed text, numerical metrics, questionnaire answers and part of the profile questionnaire (age range, education, current state, field of work, native language, goals; not gender) are transferred to the Claude API to create the report; for Deep Dive — the patterns found in the session, the chosen topic and profile context (field of work, native language, goals; for the “sports” topic — age range).
The email address, the report text, a link to the report page and the access code are transferred to Brevo to deliver the email. As a provider, Brevo may process technical data about email delivery and interaction with the email.
Data is stored in a managed Supabase database. The FaceMirror server accesses the database through dedicated functions; public access is blocked. The database is shared with the FaceMirror 2 service.
The FaceMirror application runs on a rented server of IONOS SE (Germany) that carries all traffic of the service.
At any time you may:
Requests are sent to contact@facemirror.online and processed within no more than 30 calendar days; deletion is completed within the same period. We locate your data by the email address used in the session. Deletion on request covers the sessions linked to that email: the sessions, their results, reports, Deep Dive results and access codes are deleted; invitation codes remain in the ledger with no link to you. After de-identification (section 6) a session can no longer be found by email. Before processing, we confirm that the request comes from the owner of the email address.
The service is not intended for individuals under 18. If you are a legal representative of a minor under 18 whose data was uploaded without your consent — contact the operator, data will be deleted.
The service is not intended for personal identification, medical diagnosis, psychological assessment, or decisions affecting user rights.
This report was created with AI (Anthropic Claude). It is intended for self-observation and is not a clinical assessment.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale of personal information.
FaceMirror does not sell your personal information as defined under the CCPA.
To exercise your rights, contact: contact@facemirror.online.
Material changes are published on this page with a new effective date. For a new session, the current version of the consent is shown.
Email for all questions: contact@facemirror.online