Privacy
Updated 16 September 2026
CountlessFaces helps people preserve historical photographs and research the people, places and dates they depict. This notice covers the website, including its protected test environment. Social media platforms linked from our legal notice have their own privacy notices.
Your choices
You can browse without an account. External maps, wider place search and photographs loaded from Wikimedia are blocked until you allow them. Photographs hosted by CountlessFaces remain available according to their visibility settings. We currently use no audience analytics, advertising pixels or automated face recognition.
Refusing optional services does not prevent contact, reporting or privacy requests. You can withdraw consent in the footer at any time. Withdrawal stops future optional requests; it does not undo processing already carried out lawfully.
Who is responsible?
Georg Abendlichc/o POSTFLEX PFX-741-858
Emsdettener Straße 10
48268 Greven
Germany
Email: contact@countlessfaces.com. You can also use our contact form. See the legal notice for provider details.
What we process and why
| Activity | Data and purpose | Legal basis |
|---|---|---|
| Delivering and protecting the website | IP address, request information, browser information and security counters to serve pages, prevent abuse and maintain availability. Application request logging is disabled; infrastructure providers may keep their own operational logs. | Article 6(1)(f) GDPR: providing a reliable, secure service. |
| Accounts and requested features | Email, nickname, password hash, verification records and sessions; profile details you choose to provide; uploads, drafts, saved photographs, watches and private notes. | Article 6(1)(b) GDPR: providing the requested account service. |
| Shared archive and collaboration | Photographs, inscriptions, names, dates, locations, sources, suggestions, comments and attributed change history. The purpose is historical research, reliable attribution and resolving conflicting information. | Article 6(1)(f) GDPR where applicable, subject to the interests and rights of affected living people. Permission to use copyright does not establish a privacy basis. |
| Moderation and reports | Relevant content, reporter contact details, explanations, evidence, decisions, delivery records and appeals. | Article 6(1)(c) GDPR where a legal obligation applies; otherwise Article 6(1)(f) for preventing abuse and handling disputes. |
| Optional services | External maps and archive images, place searches, and storing your date-language preference. | Article 6(1)(a) GDPR: your consent. Optional device storage also requires consent under § 25(1) TDDDG where applicable. |
Required form fields are marked with *. Without the information necessary for an account, delivery or enquiry, we cannot provide that particular feature. Optional profile details can be left blank. We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
Photographs and information about other people
Contributors may supply information from family albums, inscriptions, personal research and published sources. The individual record shows its contributor and any sources provided. These may include names in different scripts, dates, relationships, location information or tentative identifications.
Person records marked living or with unknown status are restricted to the record’s creator and moderators. A birth year more than 100 years ago does not automatically establish death. Deceased status does not require a known death date. Making a previously restricted record public requires moderator review.
Restricting a person record does not erase someone from a photograph or from free-text descriptions. If a photograph or other information affects you, request removal or report a concern, or make a privacy request. You do not need an account. Moderators consider the publication basis and the interests of the people depicted, including children and sensitive family circumstances.
Do not upload intimate or sensitive information about living people merely because a photograph is old or you own its copyright. Information revealing, for example, religion, health or political opinions needs an applicable additional legal basis where Article 9 GDPR applies. Calling the service a historical archive does not automatically provide an exemption.
Who can see contributions?
Approved public photographs, public person records and public edits can be viewed by other visitors and may be copied or indexed once the site is publicly accessible. Your nickname identifies your contributions. Email addresses and private working notes are not published as part of your profile. Country, age and biography are private unless you choose to show them in Profile privacy. Real names and expertise are also shown only according to your profile choices. You can turn these visibility settings off at any time.
Private and scheduled photographs remain subject to their access restrictions after image review. Moderators can access material needed for review. Original files are retained separately from display copies; originals may contain embedded metadata. Public display copies have metadata removed. Do not include unnecessary private details in scans or inscriptions themselves.
Reports and removal requests are visible to authorized moderators and the reporter through their account or private case link. Affected contributors receive the information needed to understand the decision. Reporter contact details are not automatically published to the community. Disclosure to authorities or other recipients can occur where legally required.
Contact and privacy requests
We process the email address, message and any name or subject you enter to handle your enquiry under Article 6(1)(f) GDPR, or Article 6(1)(b) for a contractual enquiry. Privacy-rights requests are handled under Article 6(1)(c). The form saves your enquiry in our private EU database. Only the designated privacy administrator can read general enquiries and privacy requests. Scaleway’s Paris Transactional Email service sends receipts and responses to the address you supply.
Email sent to contact@countlessfaces.com, privacy@countlessfaces.com or reports@countlessfaces.com is routed by Cloudflare into the operator’s private CountlessFaces inbox. Message content and metadata are stored in our EU database, and original messages and attachments in private EU object storage. Only the designated owner can access this inbox. Scaleway sends replies; messages are not forwarded to a personal Gmail inbox.
Full form messages are not forwarded to the operator’s consumer Gmail account. An operator email alert, if configured, includes only a case reference and a link to the protected inbox. A keyed hash of the connection IP and request counters limit abuse. Counters older than two days are removed when further form requests arrive. Requests receive a reference and private status link once saved. Keep that link private. Failed email delivery does not discard the request. Provider acceptance does not prove inbox delivery or that a human has read the message.
Service providers and international processing
- Cloudflare hosts the application, database and image storage, receives our business email and stores the private owner inbox. Database and object storage use explicit EU jurisdictions. Network delivery, security and support may involve processing elsewhere. Cloudflare’s data-processing terms describe its transfer safeguards, including the EU–US Data Privacy Framework and standard contractual clauses where applicable. See its privacy policy.
- Scaleway sends account, service and correspondence emails using its Paris-region Transactional Email service. See email processing information and contractual terms.
EU storage is not a promise that every processing operation takes place exclusively in the EU. You may contact us for information about the applicable safeguards. Outgoing links load the other website only when you follow them.
Optional external content
If enabled, your browser connects directly to these services. They receive your IP address and browser/request information. Map requests reveal the area being viewed; wider place searches send the entered query, and reverse place search sends the chosen pin coordinates. Avoid entering private addresses when they are not needed. Local place suggestions remain available without this permission.
- OpenFreeMap, operated by Hyperknot Software Kft., Hungary: map styles and tiles. Its policy describes temporary IP logging for security incidents.
- OpenStreetMap Foundation: fallback map tiles. Requests include our website origin as referrer, rather than the full page address.
- Photon by komoot: wider place search and place labels. This uses the public Photon service. See komoot’s privacy information.
- Wikimedia: externally hosted sample photographs. Wikimedia operates internationally, including in the United States.
We do not send your CountlessFaces account details to these services. Enabling content does not authorize unrelated analytics or marketing.
Cookies and storage on your device
| Storage | Purpose and duration |
|---|---|
| Account authentication cookies | Necessary for requested sign-in. Email/password sign-in uses a browser-session cookie by default; browsers may restore session cookies. “Keep me signed in” permits persistence for up to 14 days. The underlying server session expires after up to 14 days and may be renewed while active. Sign-out invalidates it. |
| Visitor-mode cookie | Remembers a moderator’s explicit choice to view the site as a visitor for up to eight hours. |
| Cloudflare Access cookies | Control access to this protected test website. Their duration depends on the Access session and security configuration. See Cloudflare’s cookie documentation. |
| countlessfaces.privacy (local storage) | Remembers accepted and refused categories, notice version and choice time for 180 days. Necessary to respect your decision. A changed notice version requests a new choice. |
| countlessfaces.dateLanguage (local storage) | Optional date-language preference, stored for up to 180 days only with permission. Otherwise the preference lasts for the current page session. |
| Temporary navigation state (session storage) | Technical markers prevent navigation/reload loops. They do not track browsing across websites and expire with the tab session. |
Storage strictly necessary for a service you request is used under § 25(2)(2) TDDDG. Your privacy choice can also be removed through your browser’s storage controls. Ordinary browser caching may retain downloaded site files. No consent to future trackers is bundled into today’s choice: a new purpose or provider requires updated information and a new choice.
How long we keep information
Account details are kept while needed to provide the account. Drafts, private notes and saved items remain until you delete them or they are removed through an account/privacy request. Authentication and verification records stop authorizing access when they expire; expiry alone does not mean every database record has already been deleted.
Published archive records, attribution and evidence are intended for long-term preservation, subject to privacy rights, corrections and removal decisions. A withdrawn or removed photograph may leave a neutral reference page. Hiding content is not the same as erasing originals, history or backups; an erasure request is reviewed across these copies as well.
Enquiries, moderation cases and privacy correspondence are retained only for handling the matter, necessary follow-up, applicable legal retention duties or establishing, exercising or defending legal claims. The appropriate period depends on the case. Erasure is currently an operator-reviewed process rather than an automatic account-wide purge. Where data must be retained, its use is restricted to that purpose.
Your rights
Subject to the applicable conditions, you can request access, correction, erasure, restriction and data portability. You can object to processing based on legitimate interests for reasons relating to your situation and withdraw consent at any time. You may request information about personal data supplied by someone else, not just information from your own account.
Use our privacy-request form, email or postal address. We may request proportionate information to verify identity. Requests normally receive a response within one calendar month; any permitted extension must be explained within that initial period. Account holders can download their account data from their profile; this does not limit the right to request a fuller response.
You may complain to a supervisory authority, including the State Commissioner for Data Protection of Lower Saxony, or the authority where you live, work or believe an infringement occurred.