Effective August 10, 2026
Privacy policy
Cwupid scores photos and can save a photo with its report when you ask it to. This policy explains what is collected, where it goes, and how to delete it.
Information we collect
- Account information. When you create an email-and-password account, we collect your name and email address and store a salted, cryptographically hashed password verifier; we do not store the password itself. When you sign in with Google, Facebook, or Apple, we receive the provider-specific account ID and the basic profile fields you approve, such as name, email address, and profile image. We do not receive your provider password.
- Photos and reports. An unsaved upload is used to produce the requested score or feedback and is discarded after the request. When you select Save photo and report, we retain that image and its associated score report in your private account history.
- Billing and credits. When billing is enabled, Cwupid stores an order identifier, pack and amount, Stripe Checkout Session and Payment Intent identifiers, verified Stripe event identifiers, and an append-only history of credit grants, uses, and compensating refunds. Cwupid does not receive or store your full card number.
- Service and security data. We process limited technical information such as IP address, browser user agent, request time, session activity, and error or rate-limit events to operate and protect the service.
How we use information
We use account data to sign you in, keep saved history separate by account, provide deletion controls, prevent abuse, and troubleshoot the service. We use uploaded photos only to produce features you request and, when explicitly saved, to provide your account history.
Service providers and sharing
- Cloudflare hosts the website, account database, sessions, and private saved-image storage.
- Amazon Web Services runs the on-demand image-scoring service.
- OpenAI processes an image and score context only when you request AI-written feedback or use a Photo Studio feature that requires visual selection or writing.
- Stripe hosts Checkout and processes payment and receipt information when you choose to buy credits.
- Google, Meta, or Apple processes the sign-in flow you choose. Cwupid does not send your uploaded photos to a login provider.
We do not sell personal information or saved photos, and we do not use them for targeted advertising.
Retention
OAuth state is single-use and expires after 10 minutes. Account sessions expire after 30 days unless you sign out sooner. Password sign-in attempts are rate limited, and the associated pseudonymous security records are normally removed after 24 hours. Unsaved image bytes are discarded after processing. Saved photos, reports, account profile data, and a password verifier remain until you delete an item or delete your account. After account deletion, minimal payment identifiers, the pseudonymous credit ledger, disputes, and security records may be retained only as needed for accounting, fraud prevention, dispute handling, and legal obligations. The live-launch retention period will be finalized through jurisdiction-specific legal review.
Your choices
You can decline optional provider fields, avoid saving a result, delete individual saved results from the account dialog, sign out, or permanently delete the account and its saved images and reports at /delete-account.
Children
Cwupid is not directed to children under 13, and we do not knowingly collect account information from children under 13.
Changes and contact
Material changes will be posted here with a revised effective date. Questions or privacy requests can be sent to cwupid@cwupid.com.