On-device face grouping
The faceprint never leaves your device.
Your photos live in your archive; that is what Phossil is for. Face grouping is different: with your agreement, your photos are analyzed locally, on your own device, laptop, desktop, or phone. The sensitive biometric data used to group similar faces across your collection never leaves that device, never reaches the internet, and is never seen by anyone but you.
What a biometric identifier is
A biometric identifier is a measurement of the body precise enough to identify a person: a fingerprint, an iris pattern, a scan of face geometry. Unlike a password, it cannot be changed if it leaks. That permanence is why laws such as Illinois’s BIPA and Europe’s GDPR place face geometry in their most protected category, and why the question that matters for any face feature is not whether it works but where the biometric data lives.
For faces, the identifier is the faceprint: a numeric encoding of facial geometry produced by a neural network. The face itself appears in your photos; the faceprint is the derived measurement that makes automated recognition possible. The two are legally and technically distinct, and this page is precise about which one it means.
How face recognition works, and how we differ
Every face recognition system performs the same three steps: detect a face, derive its faceprint, and compare that faceprint against others. The engineering question is where those steps run and where the faceprints are kept.
Most services upload the photo, derive the faceprint on their servers, and store it in a central database so future photos can be matched against it. The provider holds a permanent biometric record of every face in every photo.
Phossil runs the same class of neural network, on your hardware. Detection, derivation, and matching all execute locally; the recognition models ship inside the app and are pinned to versions we audit. No server-side faceprint database exists, because no faceprint is ever transmitted. The architecture has a cost: faceprints never sync, so each of your devices repeats its own work. We chose that cost. Recognition without possession is the strongest privacy posture this technology permits, and it is the one we built.
What stays on your device, and what reaches us
The faceprint, a 128-dimensional vector measured from the geometry of a face, is derived and stored on your device and never uploaded. It is not an image and cannot be reversed into one.
From face grouping itself, exactly three non-biometric details join your archive, each serving organization and dating:
- a rough age estimate for each face, used to work out when a photo was taken;
- the position of the face within the photo, a simple box;
- the name you choose for a person, when you decide to name one.
That is the whole list.
How the architecture enforces it
The recognition engine runs inside a sandboxed worker whose network interfaces are removed, not merely unused. The models are bundled and version-pinned; nothing is fetched from outside services. A transmission path does not exist to be misused.
This is enforced in engineering, not policy: every release of Phossil must pass an automated gate proving the recognition engine cannot transmit. A build that fails it does not ship.
The redaction, shown
Phossil’s dating engine reads clothing, print stock, and setting from a photo on our servers. When face grouping is enabled, your device obscures every detected face region before that copy is transmitted. This is the difference between the copy you keep and the copy our servers receive:
Face fully visible. Stored in your archive, shown to the people you share with.
Face region obscured on your device before transmission. Clothing, setting, and print characteristics remain readable for dating.
What the age estimate is for
Phossil estimates how old a person appears in a photo. Alone, that number means little. Paired with the year the person was born, it becomes an estimate of when the photo was taken, and undated photographs begin to order themselves. A mother born in 1948 who appears about thirty in an undated summer photo places that photo in the late 1970s. The estimate is labeled as an estimate wherever it appears, as automated inferences should be.
The rules we hold
- Off until you say yes. Face grouping is off until you enable it, and we ask before anything biometric happens.
- No central store. A faceprint exists only on the device that derived it. On a new device, derivation runs again locally.
- Deletion is immediate. Disabling the feature, switching accounts, or deleting your data each wipes the faceprints from your device at once. After three years of disuse they are deleted automatically.
- Fail closed. Illinois, Texas, and Washington maintain the strictest biometric statutes in the country. Face grouping is not offered there, and if your location cannot be confirmed as outside those states, the feature remains off.
- Never sold, never used to train AI. Children’s faces are treated exactly like everyone else’s.
The laws we built against
Illinois BIPA requires clear disclosure and consent before a faceprint is created. Phossil names the faceprint as what it is, biometric information, and obtains your consent before one exists. GDPR classifies face geometry as special-category data requiring explicit consent; that standard is applied to every user, regardless of jurisdiction. The EU AI Act requires that automated inferences about a person, such as an age estimate, be disclosed as automated; Phossil labels the estimate wherever it appears.
Questions, answered plainly
Can you see my photos? Your photos live in your archive on our servers; that is what Phossil is for, and the people you share with see them there. The faceprint is different. It is made and kept only on your device, and it is never uploaded to us.
What if I switch phones? Faceprints never sync between devices. On a new phone, face grouping derives them again locally; nothing biometric travels between your devices or through our servers.
What is a faceprint, really? A faceprint is a list of 128 numbers your device measures from the shape of a face. It is not a photo and cannot be turned back into one. Two pictures of the same person produce similar lists, which is how your device gathers them together, without anyone else ever seeing the numbers.
Our promise
We understand how personal your family photos are, and we are grateful for the trust. Privacy shapes every decision we make here, and we intend to keep protecting your moments, smiles, and stories for years to come.
Start your archiveFace grouping is always optional, and always yours to switch off.