privacy
what happens to your photos.
last updated: 8 september 2026 · cookdpics.com
cookd is software that grades the technical quality of photographs — angle, lighting, crop, expression, background, distance. it does not evaluate the person in them. this page says, in plain words, what we do with the files you give us and what we don't.
the short version
- we do not store your photos. not on our servers, not anywhere.
- your photos are read once by an ai provider, on a paid key that does not train on customer data. the provider may hold a copy for up to 30 days for abuse checks. that is their policy; we say so here because it's true.
- no account, no email, no cookies, no trackers, no analytics scripts. that is why there is no cookie banner.
- the only time we learn your email is if you buy something — and then it comes from the payment provider, not from us.
what your browser does before anything is sent
when you press "run it", your own browser shrinks each photo to about 1000 pixels on the long side and re-saves it as a jpeg. redrawing the image this way removes the file's hidden metadata — including gps location and camera details — before it leaves your device. the original files never leave your device at all.
what our server does
the shrunk copies go to our server, which passes them to the ai provider (currently google's gemini api, on a paid key with data-training switched off) and asks for a description of each frame's technical quality. the server keeps two things: a fingerprint of each file (a hash — a long number that cannot be turned back into the photo) and the text of the read. that lets us give the same answer for the same file next time. the photo bytes themselves exist in our server's memory only for the seconds of the request, and are then gone.
if a photo is declined — because it looks like it may show someone under 18, or nudity — we keep only the fact that this fingerprint was declined, so the same file isn't sent to the provider again. we never keep the photo.
what the ai provider does
the provider processes the image to produce the read. under the paid terms we use, they do not use your images to train models. they may retain inputs for a short period — up to 30 days — to check for abuse of their service. we can't shorten that; we can only tell you about it, so we are.
what we log
for each request: a request id, how many photos it had, how long it took, what it cost us, and any error code. we don't log your ip address beyond the rate-limiting our hosting does on its own (cloudflare), and we don't tie requests to a person.
what stays in your browser
your ranking and, if you head to checkout, small thumbnails of your photos are kept in your browser's session storage — on your device, for this tab only — so the fix list can reopen when you come back from paying. close the tab and it's gone. we can't see it.
we also remember your colour choice (the accent switch in the footer) in local storage. that's it.
payments
payments are handled by our payment provider (solidgate) on their pages. we never see your card. they send us the fact that a payment happened, the product, and the email you gave them, so we can deliver what you bought and handle refunds. see refunds.
age
cookd is for adults. you confirm you are 18 or older before running a set, and that the photos are yours and show no one under 18. if our checks think a photo may show a minor, the whole set is declined and nothing is kept.
your rights
because we don't keep your photos or an account, there is usually nothing to delete. if you bought something and want the payment record or the emailed report removed, email us and we'll do it. we answer from the support address.
changes
if this changes, the date at the top changes with it. we will not make it worse quietly.