Legal
Privacy Policy
Last updated: August 6, 2026
What the photo identifier collects
We collect the photo you upload and, if you provide them, the state and type of place where the specimen was found. When you pay, Stripe collects your payment details and email address. We receive the email address, payment status, and transaction identifiers, but never your full card number.
How analysis works
Before payment, we only check whether the image file opens as a JPG, PNG, or WebP and is no larger than 10 MB. This check does not assess whether the specimen is visible or identifiable. After Stripe confirms payment, we prepare a resized copy without photo metadata and send it to OpenAI for analysis. If OpenAI is unavailable, we may send the prepared copy to Google Gemini as a fallback. No human expert reviews the photo. We do not send your payment information or email address with the photo.
How we use your information
We use the information to process payment, create your report, deliver its unique link, prevent abuse, provide support, and maintain legally required transaction records. We do not use the photo, email, or location context to build advertising audiences.
First-party service measurement
We record a small set of service events—public guide and identifier page views, guide identification-link clicks, valid uploads, checkout starts, verified payments, delivered reports, technical failures, successful refunds, refund API failures, report printing, and repeat-identification starts—to understand reliability and unit economics. Campaign tags are limited to short source and page labels. These records never include photos, email addresses, report links or access tokens, health details, precise locations, model-written report text, Stripe error text, full referrer URLs, form entries from free browser tools, or browser user-agent strings. Private report pages do not record page views and do not load third-party analytics. Measurement can be disabled without affecting the service, and event records are scheduled for deletion after 400 days.
Optional report feedback
A completed report may ask whether it helped you decide what to do next and may accept one short optional comment. Please do not submit symptoms, medical history, contact details, or other health information. Feedback is tied only to the private report, is never added to public analytics, and is deleted with the report under the same 30-day schedule.
No sale of identification data
We do not sell, rent, enrich, or share your tick photo, email address, report, or location context with pest-control companies or data brokers. If we later offer introductions to service providers, that would require a separate, explicit opt-in that names what will be shared.
Retention
Unpaid uploads are scheduled for deletion 24 hours after upload. Paid photos and reports are scheduled for deletion 30 days after upload. We may retain limited payment records longer for fraud prevention, accounting, tax, and legal obligations.
Service providers
Stripe processes checkout and payment data. OpenAI processes the prepared photo after payment; Google Gemini may process it if the fallback is needed. Our hosting and email providers store or transmit the data needed to operate and deliver the service. These providers act on our behalf under their own security and privacy terms.
Your choices
Email us to request a copy or early deletion of your photo and report. Deleting a report makes its private link stop working.