Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how SightRadar ("we", "us", "our") handles personal data in connection with the SightRadar — Face Recognition API and the sightradar.com website and developer console (the "Service"). Because face data is biometric and sensitive, we keep our practices deliberately narrow: we process what you send us to provide the Service, and nothing more.
1. Roles: who controls the data
For images and faces you submit through the API (“Customer Content”), you are the data controller and we are your data processor — we act on your instructions and process that content only to return results to you. You are responsible for having a lawful basis and, where required, consent to process the individuals depicted.
For your own account information (the data we collect to run your developer account and bill you), we are the controller.
2. Data we collect
- Account data: your email address and authentication identifiers (we use Firebase Authentication to sign you in).
- Billing data: your credit balance and transaction history. Card details are collected and stored by our Merchant of Record, Dodo Payments — not by us.
- Customer Content: images you submit and the face embeddings (numeric vectors) derived from them, stored in collections you create.
- Usage and technical data: API call metadata (timestamps, operation type, credits charged, request IDs) and standard logs used for billing, security, and debugging.
3. How we handle face images and embeddings
When you index or search a face, we detect faces in the image and convert each into a mathematical embedding. For indexing, the embedding is stored in your collection so future searches can match against it. For detection, comparison, and search-by-image, the image is processed transiently to compute a result and is not retained as part of a collection.
Embeddings are namespaced to your account and logically isolated. They are never pooled, shared with other customers, or used to train general-purpose models. We do not sell personal data.
4. Why we process data (purposes)
- To provide the face-recognition operations you call;
- To maintain your account, authenticate you, and meter and bill usage;
- To secure the Service, prevent abuse, and debug issues;
- To comply with legal obligations.
5. Sharing and sub-processors
We share data only with service providers that help us run the Service, under appropriate contractual safeguards:
- Dodo Payments — payment processing and Merchant of Record;
- Firebase Authentication (Google) — sign-in and account identity;
- Cloud infrastructure providers — hosting the API, database, and vector store.
We may disclose data where required by law, or to protect our rights, users, and the public.
6. Retention
Customer Content stays in your collections until you delete it via the API or console, or until your account is closed. Account and billing records are kept for as long as needed to run your account and to meet legal, tax, and accounting obligations. When you delete a collection or face, the associated embeddings are removed from the vector store in the ordinary course.
7. Security
We protect data with encryption in transit, scoped API keys, per-account tenant isolation, and access controls on our infrastructure. No system is perfectly secure, but we design the Service so that one customer's data is never reachable by another.
8. Your rights and your end users' rights
Depending on your jurisdiction, individuals have rights to access, correct, delete, or restrict the processing of their personal data. Because we act as a processor for Customer Content, requests from a depicted individual should generally be directed to you, the controller; we will assist you in fulfilling them. For your own account data, contact us at privacy@sightradar.com.
9. International transfers
Our infrastructure may process data in regions outside your country. Where we transfer personal data across borders, we rely on appropriate safeguards consistent with applicable data-protection law.
10. Children's data
The Service is a developer tool, not a consumer product, and is not directed to children. We do not knowingly collect personal data directly from children for our own purposes. If your use case involves processing images of minors, you are responsible for having verifiable lawful authority and any consents required by law in the relevant jurisdiction before submitting that data through the API.
11. Changes to this policy
We may update this Privacy Policy as the Service evolves. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to you.
12. Contact
Privacy questions or requests? Email privacy@sightradar.com or use our Contact page.