Answer
Is Face Recognition in Photo Galleries Safe for Guests?
It depends entirely on where the selfie goes and what the server keeps. On clientgallery.io the selfie never leaves the guest's phone, and what is stored is attached to the gallery's photos rather than to the guest.
Updated September 2026
On clientgallery.io, the guest's selfie is processed on the guest's own device. It is never uploaded, never stored, and never seen by anyone, including us. The comparison against the gallery also runs in the guest's browser. What sits on our server is a set of numeric face descriptors attached to the gallery's photos, not a stored record of the guest. The feature is off unless the photographer switches it on for that gallery.
That is the part that favours us, and it is a real architectural difference rather than a promise. But a page that stopped there would be a sales page. There are three things a guest cannot do on our system today, and a guest with a serious privacy question needs to know all three before tapping anything. They are in the body of this page, not hidden at the bottom.
The rest of this page is the mechanism, the limits, and an honest comparison against the one competitor whose official policy actually documents biometric handling.
What happens when a guest taps the button
Face search on clientgallery.io has two halves that happen at different times, on different machines. Almost every privacy question about this feature is really a question about which half you are asking about.
| Step | Where it runs | What leaves the device | What is kept |
|---|---|---|---|
| The photographer uploads the gallery | The photographer's browser | Proof JPEGs, and numeric descriptors for the faces in them | The descriptors, attached to each photo in that gallery |
| The guest takes a selfie | The guest's own device | Nothing. The selfie is not uploaded | Nothing. The selfie is not stored anywhere |
| The selfie is matched against the gallery | The guest's browser | Nothing new. The gallery descriptors come down and are compared locally | Nothing. The result is a filtered view of photos |
The practical consequence is worth stating in the plainest possible way. We do not have a copy of the guest's face. We never received one. There is no image of the guest on our server that came from the selfie step, because that step never sends an image anywhere.
What is actually stored, and what it is attached to
The stored thing is a list of numbers per detected face, computed from the gallery's photos in the photographer's browser at upload time. It is attached to the photo, not to a person. Nobody types a name next to it. Nothing links it to an account, an email address or a phone. It exists so that a comparison can happen without shipping a face somewhere to be identified.
- It is gated by the gallery password on the server. If the photographer has set a password on the gallery, the descriptors are behind it in the same way the gallery page, the whole-gallery ZIP, the full-resolution ZIP and the comments are. Face search on a section link does not exist at all; it works on the parent gallery link only.
- It dies with the photo. Delete the photo and its descriptors go. Delete the gallery and all of them go. There is no separate face table that outlives the images.
- It is off unless the photographer chose it. Face search is off by default and switched on per gallery. A photographer who never touches the setting never generates the feature for a client.
One honest note on the password, because it matters more than the face feature itself. A gallery password gates the gallery page and the things listed above. It does not retroactively protect an individual proof image URL that somebody already has, because those URLs are public and do not expire. That is a property of the whole gallery, not of face search, and you should know it either way.
Three things a guest cannot do here
These are the limits. They are not edge cases and they are not coming later in this page as a footnote. If you are asking this question on behalf of a client, an organiser or a compliance department, this section is the one that decides your answer.
- There is no guest-facing delete control. A guest cannot open the gallery and self-serve a request to remove face data. There is no button for it. The photographer controls the gallery, and deleting a photo or the gallery is what removes the descriptors.
- There is no consent checkbox. Consent here is the guest reading the explanation on the screen, which appears before any selfie is given, and choosing to continue or not. We do not collect a recorded, auditable agreement, and we do not pretend that a tap is one.
- Switching face search off is not a purge. Turning the setting off for a gallery stops the feature working. It is not, by itself, a deletion of descriptors that were already computed for the photos in that gallery. If the goal is removal rather than switching off, the photo or the gallery has to go.
We would rather write those three sentences than let somebody discover them after promising a guest something we do not do.
How this compares with the one competitor who publishes a policy
Pic-Time's privacy policy is the only competitor page we could find that documents biometric handling in its own words. On several points it documents more than we operate, and the fair thing is to say so rather than to grade ourselves.
On what is stored, Pic-Time describes a 512-dimensional numerical feature vector, an abstract mathematical embedding used solely for clustering and search within the specific Gallery
, and states that It is never used, or will be used, to verify a person's identity or to enable face recognition outside the context of the relevant Gallery
. On defaults it says the feature is by default disabled, if enabled it is at Photographers explicit opt-in consent
. It also describes obtaining a written or electronic release
, states that on withdrawal Face Grouping will be disabled and associated biometric data will be deleted
, and for selfie search that Once the Guest leaves the Gallery the Face Data is deleted
.
| Question | clientgallery.io | Pic-Time, as published |
|---|---|---|
| Where the guest's selfie is processed | On the guest's device. Not uploaded, not stored | Handled as Face Data, deleted once the guest leaves the gallery |
| What is stored against the gallery | Numeric descriptors attached to the photos, computed in the photographer's browser | A 512-dimensional feature vector, described as used solely for clustering and search within that gallery |
| Default state | Off, switched on per gallery by the photographer | Disabled by default, enabled at the photographer's explicit opt-in |
| Documented consent flow | None. An on-screen explanation shown before any selfie is given, and the guest's choice to continue | A written or electronic release is described |
| Withdrawal and deletion path | No guest-facing control. Deleting the photo or gallery removes the descriptors | On withdrawal, face grouping is disabled and associated biometric data is deleted |
| Where face search sits in the plan | Included on the one plan, $10 a month or $100 a year | Selfie search is part of Smart Search on the Advanced plan, $50 monthly or $42 a month billed annually |
Read that table honestly and it splits. Our architecture keeps the selfie on the guest's device, which is a meaningful advantage and not a wording choice. Their policy documents a consent release and an explicit withdrawal-deletion path that we do not have. If your requirement is a recorded consent and a documented deletion request, they publish that and we do not, and you should weigh that accordingly.
What a photographer should do before switching it on
The feature is off until you turn it on, so the decision is genuinely yours, per gallery. Three habits cover almost every situation.
- Ask the person who owns the event. The couple, the organiser, the company running the conference. They know their guests and their own obligations better than you do.
- Tell guests it is there and what it does. One line in the delivery email is enough: there is a button to find your own photos with a selfie, the selfie stays on your phone, and you do not have to use it.
- Leave it off when you are unsure. The gallery works perfectly without it. A guest who cannot use face search scrolls, which is what they did before the feature existed. There is no cost to leaving it off and there is a real cost to switching it on for a group that would not have wanted it.
Corporate, medical, legal, minors, and anything involving people who did not choose to be at the event are the obvious cases for leaving it off. So is any gallery where you would not be comfortable explaining the feature out loud to the room.
This is not legal advice
Rules on biometric data differ by jurisdiction, and they differ in ways that change the answer rather than just the paperwork. What counts as biometric data, whether consent has to be recorded before processing, who is responsible for obtaining it, and what a deletion request must produce are not the same everywhere.
This page describes how our feature is built. It does not tell you whether using it is lawful for your shoot, in your region, for your client. A photographer working under a specific biometric statute should get advice from someone qualified in that jurisdiction rather than relying on any vendor page, ours included. A vendor has an interest in the answer being yes.
Sources
- Pic-Time privacy policy, quoted phrases on face data, the 512-dimensional feature vector, default state, written or electronic release, withdrawal deletion, and selfie-search deletion. https://www.pic-time.com/privacypolicy (fetched 8 September 2026)
- Pic-Time pricing, the Advanced plan price and Smart Search including selfie search. https://www.pic-time.com/pricing (fetched 8 September 2026)
- clientgallery.io behaviour described here was read in the product's own code on 8 September 2026: on-device selfie processing, in-browser comparison, descriptors computed at upload and attached to photos, server-side gating by the gallery password, deletion with the photo or gallery, the per-gallery off-by-default switch, and the plan price.
Frequently asked
Is my selfie uploaded when I search for my photos?
No. On clientgallery.io the selfie is processed on your own device and the comparison against the gallery also runs in your browser. The selfie is never uploaded, never stored and never seen by anyone. The only thing that comes down to your device is the numeric descriptors for the gallery's photos.
What does the gallery store about my face?
Nothing that came from your selfie. What is stored is a set of numeric face descriptors computed from the gallery's own photos in the photographer's browser when the photos were uploaded. They are attached to the photos, not to you, and they carry no name, email or account.
Can I ask for my face data to be deleted?
Not through a control in the gallery. clientgallery.io has no guest-facing delete request today, which is a real limit and worth knowing before you tap the button. The descriptors are deleted when the photo or the gallery is deleted, and that is the photographer's action. Ask the photographer.
Do I have to agree to anything before using face search?
There is no consent checkbox. Consent is you reading the explanation on the screen, which appears before you give a selfie, and choosing to continue or not. We do not record an auditable agreement, so we do not describe this as a consent flow. Pic-Time's published policy does describe a written or electronic release, which we do not have.
If the photographer turns face search off, is the face data gone?
No. Turning the setting off for a gallery stops the feature from working, but it is not by itself a purge of descriptors already computed for that gallery's photos. Removal happens when the photo or the gallery is deleted.
Is face search on by default?
No. It is off by default and switched on per gallery by the photographer. Pic-Time's policy states the same default position for its face feature, describing it as disabled by default and enabled at the photographer's explicit opt-in.
Should I use face search for a corporate or sensitive event?
Leave it off if you are unsure. The gallery works normally without it. Ask the client or the organiser first, tell guests it exists and what it does, and get qualified advice if you work under a specific biometric statute. This page describes how the feature is built and is not legal advice.
Your client galleries, under your name
Unlimited galleries, your branding, one-click Pixieset import, and a Lightroom plugin, all on a flat 10 $/month with everything included. Your first gallery is free.
Create your studio, first gallery free