Legal
Privacy Policy
Last updated: June 30, 2026
1. Who We Are
CloakBioGuard is operated by WellnessLabs LLC. This Privacy Policy explains what information we collect, how we use and share it, and what rights you have when you use our site and services, including our done-for-you face-search removal service.
2. Data We Collect
We collect only the information needed to provide, secure, and improve the service:
- Account data: Google account identifier (sub), email address, and basic profile data if provided by Google.
- Payment data: Stripe checkout and payment metadata (for example, session ID, amount, package, payment status). We do not store full card numbers.
- Service usage data: credit balances, payment state, anti-abuse and rate-limit signals, and operational logs.
- Uploaded images: images you submit for scan or protection processing.
- Removal-service intake (sensitive): if you use the removal service, a photo of your face and a photo of a government-issued ID. You may redact your ID number, address, and date of birth; your name and ID photo must remain visible because the third-party engines require them to verify your identity. We collect this solely to verify it is you and to submit opt-out / removal requests on your behalf, and an email address for status updates.
3. Biometric and Sensitive Information
A face photo and government ID are sensitive personal information, and a face photo may be considered biometric information under some laws. We handle this data narrowly:
- We use your face photo and ID only to verify your identity and to submit removal requests to face-search engines on your behalf, with your authorization.
- We do not create, store, or sell biometric templates or faceprints for identity matching, and we do not use your images to train AI models.
- We store this intake data in a private, access-controlled location and delete it promptly after your removal requests are filed (see Data Retention).
4. How We Process Scan and Protection Images
When you upload an image to the scan or protection tools, we process it to run those workflows and return results to you.
- Images are processed on Google Cloud infrastructure.
- We do not use customer images to train AI models.
- We do not create or store biometric templates intended for identity matching.
- Original and processed image artifacts are automatically removed after the retention window used for workflow completion and reliability.
5. Removal Service and Third-Party Disclosure
To fulfill a removal request, we submit your face photo and ID to third-party face-search engines through their official opt-out / removal processes — currently PimEyes and FaceCheck.ID. This disclosure is necessary to perform the service you have asked for and is made only with your authorization.
These engines are independent third parties with their own privacy practices, which we do not control. We submit only what each engine requires to process your opt-out. We do not sell your information, and we do not share your removal-intake data for advertising.
6. Account-Based Credits
Purchased credits are linked to your signed-in account. Credits may not follow across accounts. We may store technical signals (such as device or request identifiers) for abuse prevention and system integrity.
7. How We Use Information
- Provide scan, protection, and removal services.
- Verify your identity and submit opt-out / removal requests on your behalf.
- Process payments and manage account credits.
- Detect fraud, abuse, and security issues.
- Comply with legal obligations and enforce our Terms.
- Send operational notifications you request (for example, removal status updates).
8. Sharing and Subprocessors
We do not sell personal information. We share data only with trusted service providers and, for the removal service, the engines needed to fulfill your request:
- Google Cloud (hosting, processing, storage).
- Stripe (payment processing and fraud checks).
- Face-search engines you ask us to remove you from (currently PimEyes and FaceCheck.ID), solely to submit your opt-out.
- Analytics and operational tooling providers used for product and reliability monitoring.
9. Data Retention
We retain different categories of data for different periods:
- Removal intake (face photo and ID): stored privately and deleted promptly after your removal requests are filed; not retained beyond what is needed to complete and confirm those requests.
- Scan/protection image artifacts: short-lived retention tied to processing workflows.
- Account and payment records: retained as needed for billing, fraud prevention, and compliance.
- Security and abuse logs: retained for operational defense and legal obligations.
10. Security
We use technical and organizational safeguards, including encryption in transit, private and access-controlled storage for removal intake, controlled service access, and production security controls designed to reduce unauthorized access and misuse.
11. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of personal data, and to object to or withdraw consent for certain processing, including processing of biometric or sensitive information. You may request deletion of your removal-intake data or other account data by contacting us. Withdrawing authorization may prevent us from completing a removal in progress.
12. Children's Privacy
Our service is not directed to children, and the removal service requires you to be at least 18. We do not knowingly collect personal data from children under 13.
13. International Transfers
If you access the service from outside the United States, your data may be processed in the United States or other jurisdictions where our providers operate. Third-party engines you ask us to remove you from may also operate in other jurisdictions.
14. Policy Updates and Contact
We may update this Privacy Policy from time to time. We will update the effective date when changes are made.
Questions or privacy requests: privacy@cloakbioguard.com.