FaceAssure, in plain words

Your face stays on your device.

FaceAssure is a privacy-preserving age estimation product that estimates how old you look on your device (in your browser tab). It is age estimation - not a selfie upload to a stranger's server, and not facial recognition.

  • No photo upload
  • Not “who you are”
  • Only an age signal goes back

Start here

How on-device age estimation works

Think of a calculator: the numbers go in, the maths happens on the calculator, and only the answer is written down. FaceAssure is that pattern for age, running in a modern browser.

Camera in this tabFrames and liveness checks stay on your device

  1. Camera in this tab

    You grant camera permission. FaceAssure’s page - often embedded in the site/app you are visiting (usually an iframe) - guides your lighting and framing, and those pixels stay in the browser for the check.

  2. The model runs locally

    A small model, loaded onto the device, reads facial patterns associated with age. This is the “edge AI” part: no photo of your face is sent to a data centre.

  3. A receipt...

    During the estimation process, Privately receives a receipt (result) of the check: how long the estimate took, frame timings, and anonymous diagnostics about the device and the estimation. No photo and no face data are ever sent, and nothing on that receipt can be traced back to a person.

  4. ...then a stamp

    Privately then stamps (signs) the result so the website can tell it is genuine.

  5. A result, not a picture

    The stamped result reaches the website that asked: a pass or fail against its age gate, or an age band. A result of the check - not a copy of your face, not your photo or any other information about you that could be used to identify you.

Three things this is (and isn’t)

People worry a camera check means their photo is copied, stored, or sold. While this may be true for some age assurance providers, FaceAssure never sends your photo to a server.

The selfie is not uploaded

Frames from the camera are used for estimation here. This is the opposite of “take a photo, send it to a server.”

It is not identifying you

The question is “about how old does this face look?”, not “which person in a database is this?”

Only an age signal goes back

The site that asked can get a result - pass/fail or an age range - so it can gate content. That ticket is not your face.

What stays and what leaves the device?

“Your face stays on the device” is true of the image. Some non-photo information can still move, because otherwise the website could not know the estimation took place.

What stays on the device

  • Camera frames (captured/live), and the face image and associated data used for estimation
  • The biometric patterns the model looks at (they are not shipped as a mugshot)

What actually leaves the device

  • An estimated age result: pass/fail against a gate, or an age range
  • Anonymous diagnostics about the estimation - how long the estimate took, frame timings, device class - which Privately uses to sign the result and to monitor quality. No photo, no face data, nothing that identifies you
  • A transaction id so the result can be tied to this result, which cannot be used to identify you

Compared with sending a photo to the cloud

Many age assurance providers work like this: your app or site captures a picture and uploads it to a vendor. The vendor’s computers look at the image. You have to trust their storage, staff access, and subprocessors with a picture of a face.

Typical cloud age assurance provider FaceAssure
Where the looking happens Vendor data centre Your browser / device
What you send Often the image or video itself Not the face image for inference
What the website gets A score or age band (and they already sent a photo) A result token or age band
Main trust question “Who keeps my picture, and for how long?” “Who sees the age result, and is this really on-device?”

Common questions

Short answers. Open any of them - they work even if JavaScript is off.

Does FaceAssure upload my face to a server?

FaceAssure is built so facial age estimation runs in the browser on your device. Production flows are described as not transmitting or storing the face image for inference. The selfie is not the thing being sent to “the cloud” as with a typical photo-upload age API.

If my face stays here, what does leave the device?

The website that asked can receive an estimated age result (pass/fail against a gate, or an age range), usually as a signed token. Privately also receives a receipt of the check: how long the estimate took, frame timings, and anonymous diagnostics about the device and the estimation, plus a transaction id that ties this result to this check and cannot be used to identify you. No photo, no face data, and nothing that identifies you leave the device.

What if there is a data leak?

A typical photo-upload age check can leave a picture of your face on a vendor’s servers, so a breach there could leak a selfie. FaceAssure is built so the face image is not sent or stored for the estimate. A leak of Privately’s servers would not contain your photo. What can leave the device is an age result and anonymous diagnostics that cannot identify you - there is no face database to steal.

Can the website I was visiting see my camera or my photo?

The check UI is hosted by Privately (often in its own page or iframe). The integrating site is meant to receive the age result, not a copy of your face. You should still only run age checks on sites you trust to request an age signal.

Is this facial recognition? Does it identify me?

No. Age estimation looks at patterns associated with age. It is not matching you against a watchlist or creating an identity profile from your face. It does not prove your legal name.

When you say “AI”, do you mean ChatGPT or some other chatbot?

No. “AI” here means a small machine-learning model that does one job: estimate how old a face looks. It is not a chatbot like ChatGPT. It does not chat, write text, or answer questions. It only looks at facial patterns associated with age, on your device.

Does the AI model stay on my device forever?

No. The model is loaded onto the device only to run the age estimation. It is not kept there afterwards, and is immediately discarded after the estimation is complete.

Does Privately use any face data to train the model?

No. FaceAssure does not send face images or face data off the device, and Privately does not use people’s checks to train the model.

Are third parties involved?

The model files and page can be loaded from a content network (a CDN). Privately’s privacy policy lists infrastructure and security subprocessors. That is not the same as sending your selfie to an advertising network. Bot-protection tools may see browser signals, not your face image.

Is it accurate? Is it certified?

Age estimation is a statistical guess with error, especially near age gates. FaceAssure has been assessed under schemes such as ACCS age assurance requirements and ISO/IEC 27566-1, and Privately publishes GDPR-related certification claims. Certificates describe a product version at a point in time - they are not a promise that every check is perfect.

Should children use this?

This site does not run a check. Platforms choose when to ask for age assurance. FaceAssure is an age-estimation method, not parental consent by itself. Caregivers should treat camera age checks like any other camera permission: know which service is asking, and why.

About FaceAssure and this site

FaceAssure is Privately SA’s facial age-estimation product. It runs as a fully managed browser experience. Privately is a Swiss company (Lausanne) working on on-device age assurance and related privacy-preserving safety tools.

age-estimation.info is a static explainer for FaceAssure. It does not open your camera and does not perform an age check. Optional Google Analytics runs only if you allow it. For product, legal, and integration truth, use Privately’s own sites.