Double Taken

Privacy

Last updated 12 September 2026

This describes how Double Taken handles personal data. It is not legal advice.

What we collect

If you sign in we store your email, session cookie, credit balance, optional billing IDs from Stripe, and case files (labels you type, verdict text, source URLs, and scores). We do not keep the upload as a long-term photo store: the file is sent to search providers, then dropped from our servers.

Who sees the photo

To run a search we send the image to FaceCheck.ID (face matches on public web images) and TinEye (copies of the same file). They process the image under their own terms. We do not sell your data, run ads on it, or publish a public page about the person you looked up.

Other processors

Hosting and database: Vercel and Neon. Email: Resend. Payments: Stripe. They only get what they need to run those services (for example Stripe gets your email at checkout).

Cookies and sign-in

We use an httpOnly session cookie to keep you signed in. Magic-link emails include a one-time token that expires in about 20 minutes.

Safety-buddy shares

If you create a share link, that person can see that case (verdict and source links) until the link expires (about 48 hours). If they sign in from the invite, you can each receive a credit. Do not send a case to someone who should not see it.

Retention

We keep account and case records so you can reopen them and so credits stay accurate. You can email us to ask us to delete your account. We may keep limited records where the law requires it (for example billing).

Age

You must be 18 or older. Do not submit photos of minors.

Contact

Privacy questions: hello@doubletaken.com.