Security & Trust

Effective June 6, 2026 · Last updated June 6, 2026

Facet handles work that hasn’t been released yet. This page is a plain-language account of how we protect it: where it lives, who can reach it, how it’s encrypted, how long we keep it, and what we do if something goes wrong. It describes behavior and posture, not the internals of how attribution works.

Your content stays yours

You retain all ownership of everything you upload. We receive only a limited license to host and process your media in order to provide the service to you — nothing more.

We never use your content to train, develop, or improve any machine learning or AI model. Facet uses a third-party analysis provider for some forensic features; that integration is currently switched off, and when enabled it receives only redacted technical measurements derived from a trace — never your original files, and never for any model training.

Encryption

  • In transit: every connection is encrypted with TLS 1.2 or 1.3. A plain-text (non-HTTPS) request to our API is redirected to HTTPS rather than answered over that connection, so no content is returned unencrypted — though the address you asked for does cross the network before the switch. This website is served over HTTPS by our hosting provider. A plain-text request made directly to our storage layer is refused outright.
  • At rest: your originals and issued copies are stored with AES-256 encryption, and our database is encrypted at rest. Encryption is applied to every stored object, and attempts to disable it are blocked at the storage layer.

Who can access your content

Facet staff cannot view or download your uploaded files or issued copies through any internal tool. Our administrative tools are limited to account information — things like your organization name, plan, and usage counts — and have no path to your media. Every administrative change is written to an audit log (append-only by application convention) that records who did it and when.

Where your content lives

Your content is hosted on Amazon Web Services in a single region (US, us-east-1). We rely on a small set of vetted service providers, each of which sees only what it needs to do its job:

Service providers (subprocessors)

  • Amazon Web Services — hosting, storage, and database. Stores your content.
  • Vercel — hosts the web application. Sees web traffic, not your media files.
  • Clerk — sign-in and account identity, including sign-in emails. Sees your email and login activity.
  • Stripe — billing. Sees your billing email and name.
  • Resend — product emails (for example, a delivery link to a recipient). Sees recipient email addresses and the media title — not your image files.
  • Anthropic — analysis provider for certain forensic features. Currently inactive. When enabled, receives only redacted technical measurements — never your original content.

We do not use any third-party analytics or session-tracking service. Operational monitoring stays within our AWS environment.

How long we keep your content

  • Originals and issued copies: kept until you delete them — they do not expire on their own.
  • Marked copies made in the Facet iOS app: deleted from our servers 30 days after you create them. Your own copy on your device is unaffected, and the original you started from is kept like any other original.
  • Files submitted for tracing (a suspect copy you upload to check): automatically deleted after 90 days.
  • Operational logs: 30 days. Database backups: 14 days.

Deleting your content

You can remove a source file or erase an item entirely from your dashboard, with a 30-day recovery window before an erase becomes permanent. [DELETION PERMANENCE — PENDING: confirm the erase pipeline executes end-to-end in the live environment before stating that deletion is irreversible]. Until that is confirmed, we do not promise that deletion is final.

Durability — keep your own copies

Facet traces leaks; it recovers attribution from a suspect copy on its own and does not need your original on file to do so. For that reason Facet is a distribution-and-tracing tool, not a backup service. Please keep your own copies of anything important. [DURABILITY COMMITMENT — PENDING: decision on the “no silent loss/deletion” commitment and its wording].

Audits and certifications

[CERTIFICATION STATUS — UNCONFIRMED]. Whether Facet holds a third-party security certification is not confirmed either way. It is an open question in our internal trust record, it is not something a review of our code could settle, and we make no claim in either direction until an owner has answered it.

Reporting a security issue

If you believe you’ve found a vulnerability, please tell us at security@facetlabs.io. We investigate every report and will acknowledge it. Please give us a reasonable chance to fix an issue before disclosing it publicly.

If something goes wrong

We maintain internal incident-response procedures with defined severity levels and rapid credential revocation. [CUSTOMER-NOTIFICATION COMMITMENT — PENDING: our commitment to notify affected customers, and the timeframe (e.g. within 72 hours of confirmation), is being finalized]. Our aim is to tell you what happened, what we did, and anything you need to do.

Questions

For any question about security or your data, contact [PRIVACY / SECURITY CONTACT EMAIL]. See also our Privacy Policy and Terms of Service.