Privacy Policy

Last updated: 6 September 2026

Mosawer is a platform for professional photographers. A photographer publishes an event gallery on it, guests open the gallery, and a guest who wants to can find their own photos by taking a selfie.

This policy explains what personal data passes through Mosawer, who is responsible for which part of it, how long each part is kept, and what you can ask us to do about it. It applies to mosawer.app, to every gallery and portfolio published through it (including photographers' own domains), and to our mobile and desktop applications.

It is written to meet the Personal Data Protection Law of the Kingdom of Saudi Arabia, issued by Royal Decree M/19 of 9/2/1443H, as amended by Royal Decree M/148 of 5/9/1444H, and its Implementing Regulation, because most of the people whose data passes through Mosawer are in the Kingdom.

This policy is published in Arabic and English. Where the two differ, the Arabic text alone governs. It takes effect on 1 October 2026.

1. Who we are

Mosawer is operated by:

  • Legal name: Mosawer LLC
  • Registered address: 30 N Gould St, Ste N, Sheridan, WY 82801, United States
  • Country of establishment: the United States of America. We are established outside the Kingdom of Saudi Arabia and we process the personal data of people in the Kingdom from outside it.
  • Personal data protection contact: [email protected]

We build and run the software. We are not a photography studio: we do not shoot events, we do not own the photographs on the platform, and we do not sell them on our own account. You do not need an account to write to us.

2. Definitions

  • «Personal data»: any data, whatever its source or form, that identifies you specifically or makes identifying you possible, directly or indirectly.
  • «Processing»: any operation carried out on personal data by any means: collecting, recording, storing, using, disclosing, transferring and destroying.
  • «Sensitive data»: the categories the Law treats as sensitive, including biometric data used to identify a person.
  • «Face template»: a string of numbers describing the features of a face. It is not a picture, it is the form in which face data is stored for matching on Mosawer, and it is sensitive personal data under the Law.
  • «Controller»: the party that decides the purpose of the processing and the way it is carried out.
  • «Processor»: the party that processes personal data for the benefit of a controller and on its behalf.
  • «Data subject»: the individual the personal data belongs to.
  • «The Law»: the Personal Data Protection Law and its Implementing Regulation.
  • «The competent authority»: the Saudi Data and Artificial Intelligence Authority (SDAIA).
  • «Mosawer», «the platform», «we»: mosawer.app and its applications, operated by Mosawer LLC.
  • «The photographer»: the account holder who publishes photographs and galleries through the platform. Note the two names sit close together in Arabic: «مصوّر» is the platform, «المصوّر» is the customer.
  • «Guest»: anyone who opens a gallery or a portfolio without an account.
  • «Find Me»: the feature that lets a guest find their own photos in an album by taking a selfie. It is called «ابحث عني» in Arabic, and that is its name in all four of our documents.

3. Who is responsible for what

Two different kinds of data run through Mosawer, and responsibility for them does not all sit in one place. Below we say, for each kind, who decided that it would be processed and how, and where that was us, we say so, including where it would be more convenient not to.

Your account and the website. When you open an account, subscribe, sign in, write to support, or browse mosawer.app, we decide why that data is collected and how it is used. For that data we are the controller.

The photographs and the people in them. The photographer decides which event to shoot, what to upload, what to publish and who may see it. For the photographs themselves the photographer is the controller and we are the processor.

Face templates are different, and we will not dress it up. We compute a face template for every face we detect in every photograph uploaded to Mosawer. That happens automatically, on our decision, using a model we choose, whether or not the photographer ever offers face search to a single guest, and today the photographer cannot switch it off. Because we decide that this processing happens at all and how it is done, we are a controller for it alongside the photographer, and we answer for it to you directly. The photographer remains responsible for having the right to take and publish the photograph. We are responsible for having made a biometric record out of it.

The photographer's registered name and contact details are shown on every gallery and on their profile page, and we will give them to you on request.

The right to take those photographs sits between the photographer, the event organiser and the people at the event. The photographer confirms to us that they hold it. We hold no consents and no releases for anyone appearing in a photograph, and we cannot grant permission over a photograph that is not ours.

The selfie you give to Find Me. If you are a guest and you use Find Me, you hand the selfie to us, not to the photographer. We decide how it is handled and how long it lives, and we destroy it on our own clock. For that selfie and the search template made from it, we are the controller, which is why the promises in "Find Me and face data" are ours to keep, and why you can hold us to them directly.

4. What we collect

If you have an account:

  • Your name, email address, username, profile picture, and the city, country, gender and language you choose to set. We record the date you accepted our terms.
  • Your password, stored as a one-way hash that cannot be turned back into the password, or, if you sign in with Google, the sign-in tokens that provider gives us.
  • If you turn on two-step verification: the secret behind your authenticator app, and your backup codes.
  • Your sign-in sessions, each with the IP address and browser you signed in from.
  • Verification records used for email confirmation, password resets, one-time codes and the sign-in flow.
  • Your subscription: the customer record held by our payments provider, the plan you are on, and the billing events they send us.
  • If you turn on selling: your account identifier with the marketplace payments provider. Your identity documents go to that provider directly; we never hold them.
  • Computers you pair with the desktop uploader: a device name, the machine's hostname, its platform and version, and when it last connected.
  • A record of support and administrative actions taken on your account, including the email addresses involved.

Your work:

  • Albums and their settings, including the album name, your client's name, and the gallery password if you set one.
  • Photographs, their filenames, and the metadata the camera embedded in them. That can include the date and time, the camera, the artist and copyright fields, keywords, and the GPS coordinates of where the photo was taken. This metadata travels with the photo when the gallery is opened. If you do not want the location published, remove it before you upload.
  • Versions we generate: previews, thumbnails and watermarked copies.
  • A numerical description of what each photo shows, so photos can be searched by content inside the platform, and face templates for the faces detected in them.
  • Your public profile and portfolio: display name, biography, avatar, the contact email and phone number you choose to publish, links, your subdomain or custom domain, and your directory listing.

If you are a guest in a gallery:

  • Whatever you type into a photographer's contact or booking form, which can include your name, email address, phone number and dates. We do not keep your IP address with it, in any form.
  • If you ask to be told about new photos: your email address or phone number, your language, and one reference face template. See "Find Me and face data".
  • If you buy a photo: your name and email address, and the order and its items. Card details go to the payments provider and never reach us.
  • Share links you create, and the photos behind them.
  • Cookies: a signed anonymous identifier for your browser so that one guest's usage limits are not counted against everyone else on the venue's network, proof that you passed a gallery password, and your language and theme. See the Cookie Policy.
  • Usage events: that a gallery was opened, a photo viewed or downloaded, a face search run, a profile visited. These carry no IP address and no browser string.

Automatically, from everyone:

  • Your IP address is held briefly in a short-lived counter, to count requests and block abuse. The counter expires within seconds to minutes.
  • Network and server logs held by the providers that run our infrastructure.
  • Error reports when something breaks: what failed, the page it happened on, and the browser it happened in. No recording of your screen is ever made.

We do not ask for your national identity number, your date of birth, your health, your religion, or your political views. If you send them to us in a message, we do not want them and we will not keep them.

Where we ask for something you must give us to receive the service, we say so at the point we ask, and we say what happens if you do not. Everything else is optional and refusing it costs you nothing but the feature it powers.

5. Data that reaches us from someone else

Most of what we hold about a guest reaches us from the photographer, not from the guest. The photographs you appear in, the face templates computed from them, and anything an event organiser passed to a photographer about you all arrive that way.

Where the Law requires it, we or the photographer will tell you, within thirty days of receiving your data, what categories we hold and where they came from. For the people in an event photograph we rely on the exemption the Law provides where individual notification would be impossible or would need disproportionate effort (a photographer cannot write to four hundred wedding guests), and the photographer discharges the duty instead by telling people at the event, which they warrant to us that they do. That exemption excuses the notice. It does not excuse the lawful basis.

You can ask us at any time what we hold about you and who gave it to us, and we will answer within thirty days.

6. Find Me and face data

Find Me has two halves, and you should know both.

The search is optional. It starts only when a guest opens it, takes a selfie and presses the button. You should know what happens after that. For three hours from that moment we keep the template made from your selfie, and every new photograph the photographer adds to that album during those hours is compared against it, so a photo of you that arrives late still reaches you. That comparison runs on our servers while you are not there, and it stops when the three hours end and the template is destroyed. If you also asked to be told about new photos, the same comparison runs against your reference template whenever photographs are added to that album, until you erase it or ninety days pass without it being used. Apart from those two, nothing about Find Me runs in the background, and no face search is ever run on a visitor who did not start one.

The index is not optional. Before any guest can search, the album has to be searchable, so a template is computed for every face we detect in every photograph uploaded to Mosawer, including the faces of people who never open the gallery. That is processing of sensitive personal data, we decide that it happens, and we say so plainly rather than describing it as something the photographer switched on.

What happens to the selfie. It reaches us over an encrypted connection and is turned into a face template: a string of numbers describing the features of a face, not a picture. The selfie image itself is never written to our storage. It is discarded in the same request that created the template.

What is kept, and for how long. The search template lives for three hours and is then destroyed. Nothing else about the selfie survives at all.

If you ask to be told about new photos. Then we keep the email address or phone number you gave us, your language, and one reference template so that a new photo of you can be recognised when it is uploaded. That template is erased ninety days after we last used it, and every message we send you resets the clock. If you unsubscribe or use the erase link, it is erased immediately, and your address is kept afterwards for one purpose only: so that we never contact you again.

The faces in a photographer's photographs. Those templates are used only to match within the album the photo belongs to; we do not search across albums or across photographers, and there is no way to search Mosawer for a person. They are deleted with the photograph, and because deleting a photo or an album puts it in a recycle bin first, that is completed up to thirty-one days later. You can also ask us to erase the templates of your own face from a named gallery without going through anyone: see "If you appear in a photograph".

What we do not do. We do not sell face templates, share them with advertisers or data brokers, or give them to the photographer. A photographer sees matched photos, never the numbers. We do not use anyone's selfie or anyone's photographs to train or improve face-recognition models. We do not use face data to identify a person for any purpose other than showing that person their own photos.

The matching is automatic: a computer compares numbers and returns the photos that are close enough. It produces no decision about you beyond which photos you are shown. A wrong match is an error in personal data, not merely a product fault. If you think it got it wrong, write to us, a person will look at it, and you can ask us to correct it under this policy.

Face data is sensitive personal data under the Law, and the only lawful basis available for it is explicit consent. For the selfie, you give that consent at the moment you use the feature, for that search alone. You never give it by accepting these documents, and you can withdraw it at any time. The erase link in every message we send you does exactly that. For the templates computed from a photographer's photographs, see "Why we are allowed to process".

Many galleries are set so that photographs stay blurred until a guest matches by face. We will be straight about whose choice that is: blurring is switched ON by default on every new event gallery, by us. A photographer can turn it off, but if he never touches the setting it is our default that is running.

You never have to give us your face to see a photograph of yourself, and we will be exact about how that works today rather than comfortable. A link sent to you by the photographer opens the sharp photographs with no face search at all. The gallery password on its own does not: it lets you into the gallery, where a blur-gated album keeps its photographs blurred until you either match by face or are sent such a link. We think that is too narrow a set of keys for a setting we turn on by default, and we are widening it. Until we have, if a gallery will not show you a photograph of yourself without a face search, write to [email protected] and we will get you the photographs without one. You do not need the photographer's agreement for that, and we will not ask him for it.

7. If you appear in a photograph

The photographs on Mosawer belong to the photographers who took them, and each photographer is the controller for the people in their own photographs. The permission to photograph an event is arranged between the photographer, the organiser and the people at the event. It is not ours to give and not ours to take away.

If you want a photograph of you removed, or hidden, or corrected, go to the photographer who published it. Their registered name and contact details are on the gallery and on their profile page.

Write to us as well, at [email protected]. We will pass your request to the photographer within three working days, tell you who they are (their registered name and their contact details), so you can deal with them directly, and follow it up. The photographer is the controller, and the Law gives them thirty days from your request to answer you, extendable once by a further thirty days only if they tell you before the first period ends and give you the reason. If those thirty days pass without them acting and the Law gives you the right you are asking for, we will act on it ourselves.

Some photographers publish photographs into a public discovery feed that we operate on mosawer.app, where anyone can browse them. That feed is our surface, not theirs. If you appear in a photograph there and want it out of the feed, write to [email protected] and we will remove it from the feed ourselves, without going through the photographer and without needing his agreement. Removing a photograph from the feed does not remove it from the photographer's own gallery. For that, go to him, and tell us.

Separately, and without needing anyone's agreement, every message we send you carries an "Erase my data" link. Using it erases your reference face template, stops every further message, and does so across every gallery on Mosawer, not only the one that wrote to you. It also removes the notifications that carried your address to a photographer.

It does not remove the photographs themselves. It also does not remove the face templates we computed from those photographs. There is one for every face we detected in every photograph, they are what an album is searched with, and today they are deleted only when the photograph is deleted. If you want those erased too, write to [email protected] and tell us which gallery. We will erase them within thirty days, whether or not the photographer agrees, and after that you cannot be found in that album by face. The photograph itself stays until the photographer removes it. The link also does not remove anything you typed into a photographer's own contact form; for that, go to the photographer, and tell us.

8. How we process on a photographer's instruction

This section is our processing agreement with every photographer. There is no separate document to sign, and these terms form part of the Terms of Service.

  • Purpose. We process a photographer's data only to host, process, publish and deliver their photographs, and to run the features they switch on. Nothing else.
  • Data and people. Photographs and their metadata; the face templates derived from them; what guests type into that photographer's forms; subscribers' contact details and reference templates; buyers' order details. The people concerned are the photographer's clients, the attendees of their events and the visitors to their galleries.
  • Duration. For as long as the photographer's account and albums exist, plus the recycle-bin and backup windows described under Retention. On deletion we destroy the data or, if asked before deletion, return it.
  • Instructions. We act only on the photographer's instructions: the settings they choose in the product, and anything they send us in writing. If we believe an instruction breaks the Law, we tell them, and we may decline it.
  • Powers we keep in our own right. Three things are not the photographer's to instruct, because we exercise them as a controller and not as their processor: we compute face templates from uploaded photographs and we answer for that processing ourselves; we act on a data subject's request when the photographer does not act within the time the Law gives them; and we remove or make private specific content on a credible complaint from someone in a photograph. We tell the photographer whenever we use any of them.
  • Confidentiality. Everyone with access is bound to confidentiality, and that obligation survives the end of their work with us.
  • Sub-processors. We use the categories of provider listed under Sharing. Any photographer may ask us for the current named list at any time and we will send it. Before adding a new provider that would touch their data we notify them with reasonable notice, and they may object on reasonable data-protection grounds within thirty days; if we cannot resolve the objection, they may cancel their subscription and we will refund the unused part of the period.
  • Incidents and requests. We notify the photographer without undue delay of any breach affecting their data, with what they need in order to notify the competent authority. We help them answer requests from data subjects, and we forward any request that reaches us first.
  • Other countries' laws. We are established outside the Kingdom and are subject to the law of the place where we are registered. If a law that binds us compels disclosure, we disclose only what it compels, and where we are permitted to, we tell the photographer first. A disclosure required by Saudi law does not need the prior consent of the person concerned, but we notify the photographer.
  • Checking us. Once a year, and on request, a photographer may ask us for the information they need to assess our compliance, and we will answer within thirty days.
  • Transfers. Where the Law requires a safeguard for moving their data outside the Kingdom, we will enter into the Standard Contractual Clauses issued by the Competent Authority under the Regulation on Personal Data Transfer Outside the Kingdom with the photographer, as controller to processor, and keep them on file.

9. Why we are allowed to process

Every purpose has a stated basis under the Law:

  • Running your account and giving you the service you subscribed to. Basis: performance of the agreement you are party to.
  • Billing, invoices and tax records. Basis: performance of the agreement, and a legal requirement.
  • Keeping the platform safe: usage limits, abuse and fraud prevention, security records. Basis: our legitimate interest, and never applied to sensitive data.
  • Counting how features are used so we can improve them. Basis: our legitimate interest, on data that carries no IP address and no browser string.
  • Find Me: the selfie and the search template made from it. Basis: your explicit consent, given at the point of use.
  • Notifications about new photos, and the reference template behind them. Basis: your explicit consent, withdrawable from every message.
  • Face templates computed from a photographer's photographs. Basis: this is sensitive data, and the only basis available for it is the explicit consent of the person whose face it is. Responsibility for it is shared: the photographer must obtain that consent from the people at the event, in advance, and must be able to show us how; we must not build the index for an album where he cannot say that he has. Where that consent was not obtained, the processing is not lawful, and neither of us may rely on the other's word for it. If you are in a photograph and did not consent, write to [email protected] and we will erase the templates computed from it within thirty days.
  • Marketing messages to photographers. Basis: consent, withdrawable at any time, and never a condition of the service.
  • Answering the competent authority, a court, or another lawful order. Basis: a legal requirement.

The Law does not allow legitimate interest to be used for sensitive data, and we do not use it there. Where consent is the basis, it is asked for separately from accepting these documents, it covers one purpose at a time, and withdrawing it does not affect the lawfulness of what was processed before.

Where we rely on legitimate interest, we have carried out and documented the balancing assessment the Law requires, and we will provide it to the competent authority on request.

10. How long we keep things

These are the periods that actually run, not intentions:

  • The Find Me search template: three hours. The selfie image itself is never stored.
  • A subscriber's reference face template: erased ninety days after we last used it. Every message we send resets the clock. Once you unsubscribe, your address remains on a suppression list so we do not contact you again.
  • Photographs and albums: for as long as the photographer keeps them. Deleting a photo or an album moves it to a recycle bin, which is emptied of everything older than thirty days, so removal completes within about thirty-one days.
  • The face templates computed from those photographs: destroyed with the photograph they were computed from, through the same recycle bin, so removal completes within about thirty-one days of the photographer deleting it. They are also destroyed twelve months after the last time anyone searched that album by face, or twelve months after its most recent photograph if nobody ever searched it. Nothing else goes: the album, the photographs and every download stay exactly as they are, and only face search stops. A photographer can ask us to build the index again for an album still being delivered. You can also ask us to erase the templates of your own face at any time, and we act on that whatever the photographer does.
  • Your account: asking us to delete it starts a thirty-day window, after which the account and everything attached to it is destroyed. We keep a record that the deletion happened: the date, a one-way hash of the email address, and, for each provider we use, whether we asked it to erase its copy, whether erasure there is a manual step still owed, or whether its own retention schedule applies, as our proof of exactly what was done.
  • A zip file prepared for a download link: the link stops working after seven days. The file itself is kept in our object storage and is not yet deleted on a clock, which is a gap we are closing. It contains only photographs that are already in the album it was made from, and it can only be reached through a signed link that has expired.
  • Encrypted backups: fourteen daily and eight weekly rotations, so at most about eight weeks. They are encrypted on our own server before they leave it. Something you delete may still exist inside a backup until that backup rotates out. If we ever restore from a backup, we re-apply every destruction that had already been carried out before the restored data is put back into service.
  • Sign-in sessions, including the IP address and browser they record: they stop working as credentials after seven days. The record itself is kept until the account is deleted, and is destroyed with it. There is no shorter automatic clock on it today.
  • What a guest typed into a photographer's form: kept for the photographer until they delete the form, the album or their account, because a booking enquiry is his business record and we do not delete it on a clock. The erase link does reach it: if you ask us to erase your data, every form response carrying your address goes with the rest.
  • Usage events, including that a face search was run: held by the product-analytics provider named by function in «Who else sees your data». They carry no IP address and no browser string, and the period they are kept for is set with that provider rather than by us, so we describe it that way rather than quote a number this page cannot enforce.
  • Purchase records: a buyer's name, email address, and the order and its items: six years from the end of the tax period they fall in, as commercial and tax records, then destroyed.
  • A paired computer: it stops being trusted after ten days without contact, and the pairing record stays with the account until the account is deleted.
  • Administrative and support records: kept as our audit trail. When an account is deleted, the entry survives with its reference to that account removed, so what remains records that an action was taken and no longer records who it was taken about. There is no automatic clock on the entry itself today.

When a purpose ends and no legal requirement keeps the data alive, we destroy it. When you withdraw consent and consent was the only basis, we destroy it then.

11. Who else sees your data

We do not sell personal data. We do not share it for advertising, and there is no advertising on Mosawer.

Some of the work is done by service providers who process personal data on our instruction, under contract, and only for what we ask. We disclose them by the job they do rather than by product name:

  • Cloud infrastructure and hosting: runs the platform, the database and the processing jobs.
  • Object storage and content delivery: holds the photographs and their versions, holds the encrypted backups of our database, and delivers photographs to whoever is allowed to see them.
  • Network, security and certificates: every request passes through it; it filters abuse and issues the certificates for photographers' domains.
  • Email delivery: sends our messages to the address they are addressed to.
  • Subscription payments: takes the photographer's payment and issues the invoice. It acts as the merchant and is a controller in its own right for what it must keep.
  • Marketplace payments: only where a photographer turns on selling. It takes buyers' payments, pays photographers, and verifies the photographer's identity directly; those documents never reach us.
  • Sign-in with an identity provider: only if a photographer chooses to sign in that way.
  • Error monitoring: receives a report when something breaks, including on a photographer's gallery. It records no images, no video and no screen recording of any kind, so a selfie, a face or a photograph cannot reach it. Reports are held by that provider on its own schedule and carry no identity of ours, which also means we cannot pick one person's report out of it to destroy on request.
  • Product analytics: runs on mosawer.app only. It is deliberately not loaded on a photographer's gallery, subdomain or custom domain. Anonymous visitors get no profile, and a signed-in photographer is identified by an internal account number, with no name and no email address.
  • Uptime monitoring: receives a signal that a job ran, and no personal data.
  • Professional advisers, such as lawyers, accountants and auditors, under a duty of confidentiality.

Of these, exactly two ever hold face templates: the hosting provider that runs our database, and the object-storage provider that holds that database's encrypted backups. No analytics, email or payment provider receives face data, and our error-monitoring provider is configured so that it cannot.

We also disclose personal data where the Law requires it (to the competent authority, to a court, or under a lawful order), and we disclose only what is required. Where we are permitted to tell you first, we do.

If the company is sold, merged or reorganised, personal data may pass to the new owner under the same commitments. Any Standard Contractual Clauses then in force, and the commitments in this policy, pass with it, and we will say so before it happens.

Photographers, as controllers, can ask us at any time for the current named list of the providers behind these categories, and we will send it.

12. Data leaving the Kingdom

We will say this plainly: Mosawer is operated from the United States of America, and personal data is stored and processed outside the Kingdom. Our infrastructure and object storage run in Germany and in the United States. Email delivery runs in the European Union. Subscription and marketplace payments run in the United States and the European Union. Error monitoring and product analytics run in the United States. The current list, provider by provider, is at mosawer.app/subprocessors.

The transfer takes place so that we can operate the service: a photographer's gallery, delivered to the guests he invited. Where the person whose data is transferred is a guest using Find Me, the transfer serves something they asked for. Where the person appears in a photograph and asked us for nothing, it does not, and we will not pretend it does. For that data we rely on the safeguards below and on nothing else.

Not every international provider will enter into a Saudi instrument, and we will not imply otherwise. Where a provider will enter into the Standard Contractual Clauses issued by the Competent Authority under the Regulation on Personal Data Transfer Outside the Kingdom, we do, and we will tell anyone who asks which of our providers have and which have not. Where a provider will not, we say so rather than leave you to assume: for those transfers we rely on the data protection terms that provider does offer, on encryption in transit and at rest, and on sending the least data that will do. The Regulation also requires a written assessment of the risk of transferring sensitive data outside the Kingdom on a continuing basis. That assessment is being carried out and is not yet recorded, and we will give its date to anyone who asks as soon as it is. We transfer the minimum needed, and no transfer is made in a way that prejudices national security or the vital interests of the Kingdom.

We do not require you to consent to a transfer as the price of using the service, and we do not treat browsing the site as agreement to one.

13. Your rights, and how to use them

The Law gives you the right to:

  • know the legal basis and the purpose for which your data is processed;
  • access your data;
  • obtain a copy of it in a readable, clear format;
  • correct, complete or update it;
  • request its destruction;
  • withdraw your consent at any time, where consent was the basis;
  • stop receiving marketing messages.

We do not claim to give you more than the Law does. What we add beyond it is the erase link in every message we send, which works without an account and without asking anyone's permission.

To use any of them, write to [email protected]. We will verify who you are before we act, because acting on someone else's request about your data would be the worse failure. We answer within thirty days. If a request genuinely needs longer, we may take one further thirty days, and we will tell you before the first period ends and say why. We record every request we receive, including one made by voice.

We may refuse only where a request is repetitive, clearly unfounded, or would take disproportionate effort, and we will tell you the reason.

If your request concerns a photograph, the photographer is the controller: see "If you appear in a photograph". We will still receive your request, pass it on, and follow it up, and where it concerns the face templates computed from that photograph, or a photograph in our public discovery feed, we act on it ourselves.

If you have an account, you can delete it yourself from Settings. That starts the thirty-day window described under Retention. We do not have a self-service export button; ask us and we will send you a copy.

If we get it wrong, tell us first, and you also have the right to complain to the competent authority, the Saudi Data and Artificial Intelligence Authority (SDAIA), through the complaints channel published on its website, sdaia.gov.sa.

14. Children

Mosawer accounts are for people aged eighteen and over, or older where the law of your country sets the age of full legal capacity higher. We do not knowingly open an account for anyone younger, and we do not verify age at sign-up, so if you tell us an account belongs to a child, we act on it.

Find Me is not for children. Anyone under eighteen should not use it without their guardian, and a guardian who uses it for a child does so as that child's guardian and on their behalf.

Children do appear in event photographs, and a face template is computed for every face we detect, a child's included. The photographer must have the guardians' explicit consent before an album containing children is indexed, and confirms that to us.

If you are a guardian and you want a photograph of your child removed, go to the photographer and write to us as well. We will pass it on, follow it up, and act ourselves if the photographer does not. If you want the face templates of your child erased, write to [email protected] and name the gallery: we erase them within thirty days, whether or not the photographer agrees, and you do not have to go through him first.

If we learn that we hold a child's data without a proper basis, we destroy it.

15. How we protect data

Everything travels over encrypted connections. Backups are encrypted on our own server before they leave it, and the process refuses to run without its key. Account passwords are stored as a one-way hash that cannot be turned back into the password. Two-step verification is available to every photographer and we recommend it.

Access to production data is limited to a small number of people, is granted only where the work requires it, and administrative actions on an account are recorded. Requests are rate-limited to make automated abuse expensive. Galleries can be closed behind a password, and photographers control who sees what.

One thing you should know rather than discover: a gallery password is not an account password. We store gallery passwords encrypted, in a form we can decrypt on the photographer's behalf, because photographers need to look them up and pass them to their clients. Do not reuse a personal password there.

No service can promise absolute security, and we will not pretend otherwise. What we can promise is that we design for the smallest amount of data, the shortest life for it, and the fewest people able to reach it.

16. If something goes wrong

If a personal data breach occurs, we notify the competent authority within seventy-two hours of becoming aware of it. If we cannot give the full picture in that time, we notify within the deadline anyway and complete it as soon as we can, with the reason for the delay. Where the authority's notification platform is not open to an entity established outside the Kingdom, we notify through its published contact channels within the same seventy-two hours and keep the record of having done so.

We notify you directly, in plain language and without undue delay, where the breach may damage your data or affect your rights and interests. Where the data belongs to a photographer's gallery, we notify that photographer as the controller and give them what they need for their own notification.

For the people in a photograph we hold no contact details at all (a face template carries no name, no address and no phone number), so we cannot write to them individually. In that case we notify the competent authority within the same seventy-two hours, we notify every photographer whose albums are affected, and we publish a notice on mosawer.app and on every affected gallery.

We keep a record of every incident and of what we did about it.

17. Cookies

The cookies we set are limited to what makes the service work and what remembers your choices: an anonymous signed identifier for your browser so that usage limits are counted per visitor and not per venue network, proof that you passed a gallery password, your sign-in session, and your language and theme.

Product analytics runs on mosawer.app only and never inside a photographer's gallery, subdomain or custom domain.

The full list, with what each one does and how long it lasts, is in the Cookie Policy.

18. Changes to this policy

We update this policy when the product changes or the law does. The effective date is shown with it.

If a change materially affects your rights or how we use your data, we tell you before it takes effect (by email, or by a notice inside the product), and where the change requires your consent, we ask for it rather than assume it.

19. Contact us

For anything in this policy (a question, a request about your data, a complaint, or a photograph you want taken down) write to [email protected]. That address also reaches the person responsible for personal data protection. You do not need an account to use it.

Mosawer LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States, the United States of America.

If we do not resolve it, you may complain to the competent authority, the Saudi Data and Artificial Intelligence Authority (SDAIA), through the complaints channel published on its website, sdaia.gov.sa.