Doom Face
How It Works Doom Face+

PRIVACY POLICY

Last updated: 2026-09-02

The short version: when Doom Face catches you, it automatically takes a front-camera photo and uploads it to the public Doom Map, using an approximate (not exact) location. You turn this on deliberately when you set up the app. You can delete any of your Doom Faces at any time.

WHO OPERATES DOOM FACE

Doom Face is operated by [OPERATOR LEGAL NAME - TO BE CONFIRMED], based in the United Kingdom, at [REGISTERED OFFICE ADDRESS - TO BE CONFIRMED]. This notice is written to meet UK GDPR and the Data Protection Act 2018.

WHAT WE COLLECT AND WHY

Your Doom Face photograph

When Doom Face's on-device detection decides you've been caught, your phone's front camera takes one photograph automatically. This only happens in apps you've chosen to monitor, after you've enabled the feature during setup. The photo uploads to our storage and, unless you delete it, appears on the public Doom Map.

Approximate location

Doom Face reads your device's coarse location at the moment of capture and immediately fuzzes it on your own phone, before anything is sent anywhere - your exact coordinates never leave your device and are never received or stored by our servers. What we do receive and store is the already-fuzzed, approximate location, which is what the public map displays.

Session and catch metadata

We store which app you were caught in (e.g. "TikTok"), how long that scrolling session lasted, and when the catch happened. This is what powers your Evidence history, your Doom Count and your Stats screen.

Anonymous installation identity

Doom Face does not use accounts, emails or logins. Each install of the app generates a random, anonymous installation ID and a secret credential (hashed before we ever store it) that authenticates that install's own requests. We have no way to connect that ID to your name, email, or any other identity unless you tell us yourself.

Server logs

Our API logs each request it handles (method, path, status code, response time, and an internal request ID) for debugging and abuse prevention. We do not persist your IP address as part of this data.

PUBLIC DOOM MAP

Your latest ready Doom Face is shown on the public Doom Map to anyone who visits doomface.me or uses the app - that's the product. The map shows your photo, the app you were caught in, how long you scrolled, roughly when it happened, and your approximate location. It never shows your name, your exact coordinates, or any way to identify which real person a face belongs to beyond the photo itself.

PHOTO RETENTION — FREE VS DOOM FACE+

On the free tier, only your most recent Doom Face photograph is kept. When a new catch replaces it as your latest, the previous photo enters a 24-hour grace period and then its image file is permanently deleted from our storage. The record of that catch - the app, duration, timestamp and its contribution to your Doom Count - is kept regardless; only the photograph itself is removed. Doom Face+ (a one-time purchase, not yet launched at the time of writing) keeps every photograph you're ever caught in, for as long as your account exists.

DELETING YOUR DATA

You can delete any individual Doom Face from the Evidence screen at any time. This permanently removes the photograph and its thumbnail from our storage and takes it off the public map immediately. Because Doom Face has no account system, there is currently no separate "delete my account" action beyond deleting your Doom Faces individually - uninstalling the app stops any further capture, but existing rows tied to your installation ID persist until you delete them or contact us.

WHERE YOUR DATA IS HOSTED

Photographs and thumbnails are stored on Amazon Web Services S3, in AWS's London (eu-west-2) region. Our application server and database run on infrastructure we operate ourselves. We do not use any other third-party data processor at this time.

GOOGLE PLAY BILLING

Doom Face+ is not yet available. When it launches, purchases will be handled entirely by Google Play - we never see or store your card details. Our server only receives a purchase token from Google, which it uses to verify the purchase directly with Google's own servers before unlocking Doom Face+.

ANALYTICS

Doom Face does not currently use any analytics or tracking software, in the app or on this website.

COOKIES

doomface.me does not set cookies. There's no login, no tracking, and no non-essential storage - so there's nothing to ask your consent for, and no banner.

SECURITY

All traffic to our servers is encrypted (HTTPS/TLS). Your installation's credential is hashed before storage, the same way a password would be - we cannot read it back out. Access to our production systems is restricted to the operator.

CHILDREN

Doom Face is not intended for anyone under 16. We don't knowingly collect data from children, and the app is not designed or marketed for them.

YOUR RIGHTS

Under UK GDPR you have the right to access, correct, delete or object to the processing of your data. In practice, for Doom Face: deletion is self-service in the app (above); because there is no account or login, we can only act on a request tied to a specific installation token, since that's the only way we can verify a request actually belongs to that data. For anything the app doesn't let you do yourself, contact us at [SUPPORT EMAIL - TO BE CONFIRMED].

CHANGES TO THIS POLICY

If this policy changes materially, we'll update the date at the top of this page. Continued use of Doom Face after a change means you accept the updated policy.

Terms of Service → · Back to Doom Face

doomface.me Privacy Terms © 2026 Doom Face