Face & Biometric Data Notice

Effective date: July 27, 2026  ·  This is the document the Mend app refers to as the "Biometric Policy".

This notice explains, in plain language, what happens to photos and videos that contain faces when you use Mend: AI Photo & Video Editor ("Mend", the "App"). Mend is operated from Lithuania, European Union (see our Privacy Policy for controller contact details).

The short version

1. What Mend does with a photo that contains a face

When you upload a photo or video and request an AI transformation, the following happens:

  1. Your photo is uploaded over an encrypted connection to a private storage bucket that only your account can access.
  2. The photo is automatically checked by OpenAI's content-moderation service (via a time-limited private link) to block prohibited content before any generation runs.
  3. The photo (again via a time-limited private link) and the effect's text instructions are sent to fal.ai, the AI infrastructure provider that runs the generative model producing your result.
  4. The generated result and a thumbnail are stored in your private gallery until you delete them or delete your account.
  5. Your original uploaded photo is automatically and permanently deleted from our storage 24 hours after upload — or sooner if you delete the generation or your account first.

Some effect instructions ask the AI model to "preserve the likeness" of the people in your photo. This is an aesthetic instruction so that your result still looks like you — it does not involve measuring, extracting, or storing any facial features, and it produces no data that could be used to recognize you elsewhere.

2. What Mend does NOT do

Mend explicitly does not:

The Mend app contains no face-detection or face-analysis software. Our instructions to our AI providers are limited to producing the transformation you requested.

3. Where this sits legally

Biometric-privacy laws — such as the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, Washington's biometric law, and Article 9 of the EU GDPR — regulate data that is created or used to identify a person: for example scans of face geometry, faceprints, and face-recognition templates.

Even though we believe these identification-based laws do not apply to Mend's generative processing, we voluntarily apply similar safeguards anyway: a published written notice (this document), explicit consent before processing, no sale of or profit from your photos, security measures, and user-controlled deletion.

4. Consent and the face-photo notice

Before you can use AI features, the App requires you to give explicit consent to AI processing of your photos and videos. Your consent is recorded on our servers together with the consent version and a timestamp (and technical metadata such as the network address it was given from, which is removed if you delete your account). In addition, the App shows a one-time face-photo notice before your first upload, reminding you that photos containing faces are processed only to create the transformation you chose.

If you do not consent, do not upload photos of yourself or others. If you upload photos that include other identifiable people, you are responsible for making sure they are comfortable with — and where required by law, have consented to — their photo being processed as described here.

5. Who receives your photo

Only the following processors receive photo data, and only to deliver the service you requested:

Provider Role What it receives Location
Supabase Private cloud storage and database Your uploads (deleted 24 hours after upload), generated results, and thumbnails, in access-controlled private buckets EU (Ireland)
fal.ai Runs the generative AI models A time-limited private link to your upload, the effect instructions, and a pseudonymous account identifier used for abuse prevention United States
OpenAI Automated content-safety moderation and prompt safety A time-limited private link to your upload and, for custom effects, your prompt text — with no account identifier attached United States

Neither provider is permitted to use your photos for anything other than providing their service to us. Under their published API terms, fal.ai and OpenAI state that API content is not used to train their models. Each provider retains API data only per its published policies (for example, OpenAI may retain moderation inputs for a limited period for abuse monitoring). See the fal.ai Privacy Policy, the fal.ai media-retention documentation, and the OpenAI Privacy Policy.

6. Retention and deletion

We do not promise deletion timelines we cannot control at third parties: once a provider has processed your photo, any residual retention on their side is governed by their published policies linked above.

7. Your rights and how to withdraw consent

We aim to answer data requests within 30 days, consistent with the GDPR.

8. If our practices ever change

If Mend ever introduced features that create biometric identifiers or identify people from photos (we have no plans to), we would update this notice first, ask for new, explicit consent before any such processing, and comply with the biometric laws that would then apply. Material changes to this notice will be announced in the App or by email, with the effective date updated above.

9. Contact

Summary: your face is used to make the picture you asked for — and for nothing else.