Sally Does Data

Privacy Policy

Draft v0.1 — effective upon public launch. Pending attorney review. Written to be read by humans.

What we collect

  • Account basics: email, name, birth year, password (stored only as a hash).
  • Your files, when you upload them — plus thumbnails we generate.
  • File fingerprints and metadata: cryptographic hashes, visual similarity hashes of whole images, camera data (EXIF), dates, GPS coordinates embedded in files, and file paths you register via the CLI.
  • Your enrichments: titles, descriptions, tags (including names you type for people), ratings, collections.
  • Service logs: IP address and basic request logs kept briefly for security.

What we deliberately do NOT do

  • No face recognition, face detection, or biometric processing of any kind.
  • No selling of your personal information. Ever.
  • No using your content to train AI models.
  • No third-party advertising trackers on the product.

Who can see your stuff

Everything is private by default. Items become visible to others only when you share a collection by link (anyone with the link can view those items) or, in the future, when you explicitly opt individual items into community or open-data programs. Support staff access your content only when needed to fix a problem you report.

Where it lives

On servers in the United States (DigitalOcean). Transfers are encrypted in transit (HTTPS). Passwords are hashed with scrypt; API tokens are stored only as hashes.

Your controls

  • Export everything (CSV, JSON-LD) anytime from the Export page.
  • Delete your account from Settings — data is purged within 30 days (up to 90 in backups).
  • Revoke API tokens and sharing links anytime.

Children

Sally is not for children under 13, and we delete accounts we learn belong to them.

Contact

Privacy questions or requests: hello@sallydoesdata.com. We answer within 30 days.