Privacy Policy
In force since August 29, 2026. Applies to reverse-video-search.com and to every account created on it. It complements, and does not replace, the Terms of Service.
The three things people are usually surprised by
The frames you search are sent to third-party engines. That is what the product does: a reverse image search is a query sent to Google Lens, Yandex or Bing. Those companies receive the image and process it under their own privacy policies, which we do not control.
To make that possible, each frame is stored at a public, unauthenticated URL. The engines fetch the image over the open internet by URL; they cannot use a login. The address contains a random identifier and is not listed anywhere, but anyone who has the link can open it. Do not upload anything you could not tolerate being fetched by a third party.
If you upload a video showing someone else, you are the one deciding to process their data. We provide the tool; the purpose is yours. Section 7 explains what that means for you in practice.
1. Who is responsible for your data
The controller for the processing described here is RM ECOM, sole proprietorship of Emile Moureau, 18 rue Goubet, 75019 Paris, France, contactable at emiledevcontact@gmail.com.
We are not required to appoint a Data Protection Officer and have not appointed one. The address above is the single point of contact for every request described in section 12; there is no separate privacy desk to be redirected to.
2. What this policy covers
It covers the website, the web application, the account system, the reverse search itself, the social video downloader and the transactional emails we send you. It does not cover the third-party sites a search result links to: following a result takes you to a service we have no relationship with.
3. What we collect
3.1 What you give us
- Account data: email address, display name, and a password stored only as a bcrypt hash. Accounts created with Google or with a magic link have no password at all.
- Your Google account identifier and the name and email on it, if you sign in with Google.
- The videos, video links and images you submit, and the frames extracted from them.
- Anything you write to us by email.
3.2 What your use of the service generates
- Searches: which frames were searched, on which engines, when, what the engines returned, and the resulting matches and hashes.
- Credits: your balance and a ledger row for every grant, deduction and refund, each stamped with the version of the Terms in force at that moment.
- Consent records: each time you accept the Terms, we store what you were shown, when, and the technical context - see section 5.
- Saved downloads, if you use the downloader: the source link, the media file, and the metadata the provider returned.
- Emails we sent you and whether they were delivered.
3.3 What is collected automatically
On sign-in, payment and other sensitive actions we record the event with a truncated IP address (IPv4 reduced to its /24 network, IPv6 to its /48), a salted HMAC-SHA256 hash of the full address, the country reported by our network provider, and your browser user-agent string.
We keep the truncated form and the hash rather than the address itself. The hash lets us recognise that two events came from the same connection - which is what detects fraud and answers a payment dispute - without our database ever holding a full IP address to lose or to be compelled to produce.
3.4 What we receive from others
- Stripe tells us that a payment succeeded, which plan, and the subscription status. We never receive or store your card number - it does not pass through our servers.
- Google tells us your email, name and account identifier when you choose to sign in with Google.
- If you arrived through an affiliate link, we record which code brought you.
4. Why we process it, and on what legal basis
4.1 To provide the service - performance of our contract
Creating and maintaining your account, running the searches you ask for, storing their results so you can reopen them, holding your credit balance, and sending the transactional emails that confirm what you bought. Without this data there is no service to provide.
4.2 To take payment - contract and legal obligation
Billing, invoicing and accounting. Invoices are kept because French commercial and tax law requires it, not because we chose to.
4.3 To keep the service safe and to defend ourselves - legitimate interest
Rate limiting, abuse and fraud detection, and keeping evidence of consent and of account activity so that a payment dispute, an abuse complaint or a legal claim can be answered with facts. Our interest in not being defrauded, and in being able to prove what a user agreed to, is balanced against your privacy by the IP truncation described in 3.3 and by the retention limits in section 10.
4.4 To meet legal obligations
Responding to valid requests from a competent authority, and keeping the records the law requires us to keep.
We do not sell personal data, we do not share it with data brokers, and we do not use it to build advertising profiles.
5. Consent records, and why they exist
Each time you accept the Terms - at sign-up and again before every paid order - we store the version you were shown, the exact wording of the clauses displayed, a cryptographic hash of that wording, the date and time, the page you were on, the interface language, the truncated IP and hash from 3.3, the country and the user-agent.
This is deliberate and we would rather say so plainly than bury it: the purpose is to be able to prove, later, what you were told before you paid. It is the same record that protects you, because it also proves what we committed to. It is processed on the basis of our legitimate interest in establishing and defending legal claims, and it is one of the few categories we keep after you close your account (see section 10).
6. The content you upload, and where it goes
6.1 Storage
Frames and images are stored in Cloudflare R2 object storage under a random key, served from a dedicated domain. As explained at the top of this page, that URL is public and unauthenticated by necessity: the reverse-image engines fetch the image over the internet by URL and cannot authenticate. The link is unguessable and never listed, but it is not access-controlled.
6.2 Transmission to search engines
Running a search sends the frame URL to the engines you selected through our search provider. Those engines fetch the image and process it under their own terms and privacy policies. We cannot make them delete it, and deleting the frame on our side does not remove anything they may have retained.
6.3 Optional AI features
If you use the location-guess feature, the frame is additionally sent to a third-party model provider to be described. It is used to answer your request and is not used by us to train anything.
6.4 Public gallery
Searches are private to your account by default. A video appears in the public Explore gallery only where it has been explicitly marked as visible. If you find one of your searches there and want it removed, email us and we will remove it.
7. When you upload someone else's image, you are the controller
For the content you submit, we act as your processor: we process it on your instructions, to deliver the search you asked for. You are the controller of any personal data contained in it, including the faces, voices, locations and identifying details of anyone appearing in a video you did not create.
That is not a technicality we use to shift blame; it follows from the fact that you, not us, decide whose image gets searched and why. It means you are responsible for having a lawful basis for that processing, and for the consequences of using the results.
You must not use the service to identify, locate, monitor or expose a person against their interests. Uploading intimate images without the consent of the person depicted, or content involving minors, is prohibited outright, will be reported where the law requires it, and will get the account terminated. Section 12 of the Terms lists the prohibited uses in full.
8. Who else receives data
We use the following service providers. Each receives only what it needs for its function, and none is authorised to use it for its own purposes.
| Recipient | What it receives and why | Where |
|---|---|---|
| Cloudflare | Runs the application and stores uploaded frames and downloaded media (R2). Sees traffic and the country an IP resolves to. | Global network, US company |
| Neon | Hosts the Postgres database: accounts, searches, credits, consent records. | US company |
| Stripe | Takes payments, holds card data, manages subscriptions and invoices. Card numbers never reach us. | US / Ireland |
| SerpAPI | Relays reverse image searches to Google Lens, Yandex and Bing. Receives the frame URL. | US company |
| Google, Yandex, Microsoft (Bing) | The search engines themselves. Fetch and process the frame image. | US / international |
| RapidAPI provider | Resolves a social video link into a downloadable file, for the downloader feature only. | US company |
| AI model providers | Describe a frame for the optional location-guess feature. | US companies |
| Amazon Web Services (SES) | Sends transactional email. Receives your address and the message. | US company |
| Google Identity | Authenticates you if you choose to sign in with Google. | US / international |
We will also disclose data where a competent authority makes a valid legal demand, and to our advisers where necessary to establish or defend a legal claim. If the business is ever sold or transferred, account data may pass to the acquirer, who would remain bound by this policy.
9. Transfers outside the European Union
Most of the providers above are established in the United States, so your data is transferred there. Those transfers rest on the European Commission's Standard Contractual Clauses, on the EU-US Data Privacy Framework where the provider is certified under it, or on the fact that the transfer is necessary to perform the contract you asked us to perform.
We will not pretend this is risk-free. US law gives US authorities powers over data held by US companies that EU law does not. If that is unacceptable for a particular video, the remedy is not to upload it - a reverse image search cannot be run without sending the image to the engines that hold the indexes.
10. How long we keep things
- Account data: for as long as the account exists, then deleted or anonymised within 30 days of closure.
- Searches, frames and results: for as long as the account exists, or until you delete them. Deleting a search removes it and its frames from our storage; it cannot remove anything a search engine retained.
- Downloaded media: until you delete it, or until the account closes.
- Credit ledger and consent records: five years from the event, matching the general limitation period for a civil claim in France. Kept even after an account closes - a record proving what a former customer agreed to is worthless if it disappears with the account it concerns.
- Invoices and accounting records: ten years, as required by the French Commercial Code.
- Access events (truncated IP, hash, country, user-agent): thirteen months, the ceiling the CNIL applies to connection logs.
- Emails you send us: three years from our last exchange.
11. Security
Passwords are stored only as bcrypt hashes and are never recoverable. Traffic runs over TLS. Access to the production database and to the object storage is restricted to the operator of the service. Card data never touches our servers. IP addresses are truncated and hashed before storage rather than kept in full.
No system is perfectly secure, and we would rather not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the CNIL within 72 hours and inform you where the law requires it.
12. Your rights
Under the GDPR you may ask us to:
- confirm what we hold about you and give you a copy (access);
- correct anything inaccurate (rectification);
- delete your data (erasure), subject to the records we are legally obliged to keep;
- restrict or object to a processing based on our legitimate interest, including the consent and access records described in sections 3.3 and 5;
- receive your account data in a portable, machine-readable form;
- give directions on what should happen to your data after your death.
Write to emiledevcontact@gmail.com. We answer within one month, extendable by two months for a complex request, and we will tell you if we extend. We may ask for proof of identity where a request is not obviously coming from the account holder - it is the only way to stop an impersonator obtaining your data.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr.
13. Cookies
We use no advertising cookies, no analytics cookies and no third-party trackers. There is nothing here to consent to, which is why you are not shown a banner. The cookies the site sets are:
- access_token, access_token_expiration, refresh_token, refresh_token_expiration - keep you signed in. Strictly necessary; deleting them signs you out.
- rvs_ref - remembers the affiliate code you arrived with, so the affiliate is credited. Strictly necessary to perform our contract with the affiliate.
- NEXT_LOCALE, where set - remembers your interface language.
Your browser also stores some of your work locally (a draft search and its history). That never leaves your device unless you save the search to your account.
14. Automated decisions
We take no decision producing legal effects about you by automated means alone. The search results and the optional location guess are outputs of statistical systems, presented as leads for you to evaluate; they are not judgements about a person, they are frequently wrong, and nothing on this site should be treated as an identification. Section 4 of the Terms says the same at greater length.
15. Children
The service is not intended for anyone under 15, and accounts must be created by an adult. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
16. Changes to this policy
We may update this policy. The date at the top always reflects the version in force. Where a change materially affects how we use data you have already given us, we will tell you by email before it takes effect.
17. Contact
Any question about this policy, and any request under section 12: emiledevcontact@gmail.com.