FaceWorld · newfaceworld.com

Privacy Policy

This policy explains what personal data FaceWorld collects when you create an account, sign in and use the services inside the platform, why we collect it, who it is shared with, and how you stay in control of it.

  • Effective date: 21 August 2026
  • Last updated: 21 August 2026
  • Applies to: newfaceworld.com and connected FaceWorld services

1. Who we are

FaceWorld (newfaceworld.com) operates the FaceWorld platform and is the controller of the personal data described in this policy. FaceWorld is a single platform made up of several connected services: FaceCity, the identity and single sign-on layer that holds your account, plus the services you can enter with that one account — AI chat and assistants, the FaceCoin wallet, messaging, TV and media, a marketplace of AI engines, and other services added over time.

You can reach us at any time about privacy at support@newfaceworld.com.

2. Scope of this policy

This policy covers the personal data processed by FaceCity — account creation, sign-in (including Sign in with Google), profile, sessions and devices, verification for citizen and business status — and the profile data FaceCity passes to the other FaceWorld services so that a single account works everywhere.

Individual services inside the platform process additional data that is specific to what they do: the content of your chats, your wallet balance and transactions, the media you upload, the missions you start. Where such a service publishes its own notice, that notice adds to this one; where it does not, this policy applies.

Third-party sites and applications that we link to are not covered by this policy. Their own privacy notices apply.

3. Data we collect

We collect only what the platform actually needs to run. The list below reflects what our systems really store.

3.1 Account data

  • Email address — your unique identifier for the account, and how we send verification and security messages.
  • Whether and when your email was verified.
  • Password — never stored as text. We store an Argon2id hash from which the password cannot be recovered. Accounts created through Google sign-in have no password at all until you set one.
  • First name and last name (optional when you register with an email address; taken from your Google profile when you sign in with Google).
  • Display name — the public name other people in FaceWorld see.
  • Avatar image, if you upload one or if one comes from your Google profile.
  • Language / locale preference.
  • Public account id — a short shareable identifier; our internal database id is never exposed to other users.
  • Account status and role — member, citizen or business — which decides what you may access across the platform.
  • Timestamps for account creation, last update and, if you close your account, deletion.

We do not ask for a phone number, a date of birth or a home address in order to open an ordinary account. Those are collected only in the identity verification described in section 3.5, and only if you choose to apply for citizen or business status.

3.2 Sign-in and security data

  • Linked Google account — see section 4.
  • Sessions — for each active session: the sign-in method used, the IP address and browser user-agent recorded at sign-in, an approximate location derived from that IP address, creation and last-seen times, and whether the session has been revoked.
  • Devices — a device name and platform, a fingerprint derived from your browser's user-agent string, first and last time seen, and whether you marked the device as trusted.
  • One-time codes sent by email for verification, password reset and email change. Only a hash of the code, its purpose, its expiry, the number of attempts and the requesting IP address are stored.
  • Two-factor authentication — if you enable it, an encrypted TOTP secret and hashed one-time recovery codes.
  • Failed sign-in counters and temporary lock-out times, used to stop brute-force attacks.
  • Security audit log — security-relevant events such as successful and failed sign-ins, password changes and account linking, with the IP address, user-agent and session involved. You can read your own audit log in your account settings.
  • QR sign-in sessions — short-lived records used when you sign in on one device by scanning a code with another.

3.3 Profile shared with the other FaceWorld services

So that one account works across the whole platform, FaceCity sends a small profile snapshot to the connected FaceWorld services when your profile changes. That snapshot contains exactly: your account id, email address, whether the email is verified, display name, first and last name, avatar URL and language preference. Nothing else is pushed — not your password hash, not your session history, not your verification documents.

3.4 Notifications

If you allow browser or app notifications, we store the push token issued by Google Firebase Cloud Messaging for that browser or device, so we can deliver the notification. You can withdraw the permission in your browser or device settings at any time.

3.5 Identity verification (optional)

If you apply for citizen status you provide, and we store in encrypted form: full legal name, date of birth, country, residential address, identity document type, document number and document expiry date, and a phone number.

If you apply for business status you provide, and we store in encrypted form: company name, registration number, tax identification number, country, incorporation date, legal address, business type, website, the names of directors, a contact email address and a phone number, together with the description of your business you submit with the application.

These records are encrypted at the field level in our database and are used only to review your application and to meet the legal obligations attached to it. If you never apply, we never hold them.

3.6 Payments inside the platform

Fees inside FaceWorld — for example the fee attached to a citizenship or business application — are settled in the platform's own units through the FaceCoin wallet service. FaceCity records the identifier of the wallet order and its outcome. We never see or store your card number, bank details or any other payment instrument: where real money enters or leaves, it is handled by the wallet service and by regulated payment providers under their own terms.

3.7 Technical data

Like any web service, our servers process the IP address, request time, requested address, user-agent and referrer of requests reaching them, and keep short-lived operational logs for reliability, abuse prevention and debugging.

4. Signing in with Google

"Continue with Google" is an optional way to create your FaceWorld account or to sign in to an existing one. Here is exactly what happens and what we receive.

4.1 How the sign-in works

  1. You press Continue with Google on our sign-in page. Your browser is sent to a FaceCity endpoint, which generates a one-time state value and a PKCE code verifier, keeps them for ten minutes only, and forwards you to Google's own consent screen.
  2. We request the standard OpenID Connect scopes openid, email and profile — nothing more. We do not request access to Gmail, Drive, Contacts, Calendar or any other Google service data.
  3. You authenticate with Google. Your Google password is never seen by us — it is entered on Google's own pages.
  4. Google returns you to FaceCity with a one-time authorization code. Our server exchanges that code, together with the PKCE verifier, for a short-lived access token and immediately uses it once to read your basic profile from Google's OpenID Connect user-info endpoint.
  5. We then create or open your FaceWorld account and issue our own FaceCity session.

4.2 What we receive from your Google account

Received from GoogleWhat we do with it
Google account identifier (sub)Recognises you as the same person on every later sign-in. It is the link between your Google account and your FaceWorld account.
Email address and its verified stateBecomes the email address of your FaceWorld account and the address for security messages. Because Google has already verified it, we do not ask you to verify it again.
Given name and family name, full namePre-fills your profile and your display name so you can start without a set-up form. You can change both afterwards.
Profile picture URLBecomes your initial FaceWorld avatar. You can replace or remove it.
Language preferenceSets the interface language.

The profile response returned by Google is stored alongside the link to your Google account so that we can reconcile a later change to it. We do not store your Google access token or any refresh token: the access token is used once, inside the sign-in request, to read the profile above, and is then discarded. We cannot act on your Google account afterwards.

What we never do with data from your Google account. Data received from Google is used only to create your account, to identify you when you return, and to show your name and picture inside FaceWorld. We do not sell it. We do not share it with advertisers, data brokers or any third party for advertising, profiling or marketing purposes. We do not use it to train, fine-tune or evaluate artificial intelligence or machine-learning models. We do not use it for automated decisions that produce legal effects for you.

4.3 If the email already belongs to a FaceWorld account

If a FaceWorld account with a password already exists for the email address returned by Google, we do not merge the two silently. The sign-in stops and you are asked to confirm the link deliberately, using a link token that is valid for five minutes.

4.4 Disconnecting Google

You can unlink your Google account from FaceWorld in your account settings. To keep you from being locked out, you must set a password first. Unlinking deletes the stored link and the Google profile snapshot attached to it; your FaceWorld account, and the name, avatar and email already saved on it, remain. You can also revoke our access from your Google Account under Security → Your connections to third-party apps & services.

5. Connected third-party accounts

If you use FaceWorld as a creator, you can connect the accounts you already have on other platforms so that you can publish to them from one place and see their numbers side by side. This is entirely optional. Nothing is connected unless you connect it, and you can disconnect at any time.

5.1 Which platforms, and how connecting works

The platforms you can connect are YouTube, Instagram, Facebook Pages, X, LinkedIn and TikTok.

Every connection is made through that platform's own OAuth consent screen. You sign in on the platform's pages and see exactly which permissions are being requested before you agree. We never see, receive or store your password for any of these platforms. What we receive is an access token — a revocable key, limited to the permissions you granted — and, on some platforms, a refresh token that keeps the connection alive.

Two platforms can only be connected in a specific form, because the platforms themselves allow nothing else: Instagram requires a professional (business or creator) account, and Facebook can only be connected as a Page, never as a personal timeline.

5.2 What we do with that access

  • Publish on your instruction. We post content to a connected account only when you tell us to — by publishing or cross-posting from inside FaceWorld. We never post on your behalf on our own initiative, and we never edit or delete anything you published elsewhere.
  • Read your own content. We read the list of posts and videos on the accounts you connected, so your work appears in your FaceWorld library and feed.
  • Read the statistics of your own content and account — views, likes, comments, shares, follower and post counts — so we can show you unified analytics across platforms.
  • Read basic account information — the account or channel id, handle, display name and account type — so we can show you which account is connected.

We do not read your private messages, we do not read other people's accounts, and we do not use the access for anything beyond the features described above.

5.3 What we store from a connected account

  • The connection itself — platform, the account id on that platform, handle, account name, account type, the permissions you granted, and the encrypted tokens with their expiry.
  • An index of your content — the post or video id on the platform, its permalink, kind, title, a short excerpt, a stable poster or thumbnail link where the platform provides one, duration, language, visibility, publication time and the times we first and last saw it. We do not store your media files: video and audio stay on the platform and are shown through its own player or link. Where a platform gives only a temporary, privacy-aware media link, we deliberately do not store it.
  • Statistics snapshots — counters for each post and for the account, with the time each snapshot was taken, so that charts over time are possible.

We follow each platform's rules on how long its data may be kept. If a post is deleted, hidden, protected or made private on the platform, it is removed from FaceWorld too — within 24 hours for X, as its developer policy requires. Data authorised through the YouTube API is refreshed or deleted on a rolling 30-day cycle, and audiovisual content from YouTube is never cached.

5.4 How the tokens are stored

Access and refresh tokens are encrypted before they are written to the database, with a key held outside it. They are never included in any API response — our response models have no token field at all — and if the encryption key is missing the service refuses to store a token rather than keep it in the clear.

5.5 Disconnecting and revoking access

You can disconnect a platform in FaceWorld at any time. When you do, we revoke the token at the platform where the platform supports revocation, and we erase our copy of the tokens either way; content read from that account stops being shown. We keep only a revoked, token-less record of which account was connected, so the disconnection itself is traceable.

You can also withdraw our access from the platform's side, which works independently of us:

  • Google and YouTube — https://security.google.com/settings/security/permissions
  • Instagram and Facebook — Settings → Business integrations / Apps and websites
  • X — Settings → Security and account access → Apps and sessions → Connected apps
  • LinkedIn — Settings → Data privacy → Permitted services
  • TikTok — Settings → Security & permissions → Manage app permissions

5.6 YouTube API Services

FaceWorld uses YouTube API Services to connect your channel, read your own videos and their statistics, and — once the required audit is passed — to upload on your instruction. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service.

Google's handling of the data involved is described in the Google Privacy Policy. You can revoke FaceWorld's access to your Google and YouTube data at any time on the Google security settings page: https://security.google.com/settings/security/permissions.

5.7 Limited Use of Google user data

FaceWorld's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Specifically, data obtained through Google APIs is not sold; is not transferred to third parties for advertising, marketing or any other purpose unrelated to providing the features you asked for; is not used to develop, train, improve or evaluate artificial-intelligence or machine-learning models; and is not read by humans, except with your explicit consent, where necessary for security purposes such as investigating abuse, where required by law, or on aggregated and anonymised data used for internal operations.

6. Deleting your data and disconnecting accounts

This section explains, in plain terms, how to have your data deleted. It applies to your FaceWorld account and to any third-party accounts you connected.

6.1 Disconnect a platform yourself

Sign in to FaceWorld, open the connected accounts screen and press Disconnect next to the platform. This takes effect at once: we revoke the token at the platform where revocation is supported, delete our stored tokens, and stop showing content read from that account. You can also revoke our access from the platform's own settings, as listed in section 5.5.

6.2 Request deletion of your data

Write to support@newfaceworld.com from the email address registered on your FaceWorld account, with the subject line "Data deletion request", and tell us what you want removed:

  • Only the data of a connected platform — name the platform. We delete its tokens, the index of its content and its statistics snapshots from our systems.
  • Your whole account — we disconnect every connected platform and delete or irreversibly anonymise the account data described in this policy.

We acknowledge a request within 5 working days and complete it within 30 days. We may first need to confirm your identity, so that nobody else can delete your data. Records we are legally obliged to keep — for example accounting entries, or verification records held under a legal obligation — are retained for the period the law requires and are deleted when it ends.

6.3 Requests coming from a platform

Where a platform provides its own deletion channel — for example when you remove our application from your Meta account — the request reaches us automatically through the data-deletion endpoint we registered with that platform. We verify its signature, erase the data belonging to that platform account, and return a confirmation code with a status page where the outcome of that request can be checked. Media was never stored by us in the first place; the connection record survives only as a revoked, token-less row identifying which platform account was disconnected.

7. How we use your data

  • To run your account — create it, authenticate you, keep you signed in across the platform's services, and let you edit your profile.
  • To keep the platform secure — detect and stop brute-force attempts, unauthorised access and abuse; let you review and revoke your own sessions and devices; keep the security audit log.
  • To deliver the services you use — a single identity across AI, wallet, messaging, media and marketplace services.
  • To communicate with you about the service — verification and one-time codes, security alerts, and important changes to the service or to these documents.
  • To run the creator features — publish to the platforms you connected when you ask us to, keep your content library in step with them, and show you unified statistics.
  • To review verification applications and grant citizen or business status.
  • To meet our legal obligations and to establish, exercise or defend legal claims.
  • To improve reliability — aggregated, non-identifying diagnostics about errors and performance.

We do not run behavioural advertising on the platform, and we do not build advertising profiles of our users.

9. Who we share data with

We do not sell personal data, and we do not share it with advertisers. We share it only in the following situations.

  • Services inside FaceWorld. The profile snapshot described in section 3.3 is passed to the connected FaceWorld services so that one account works everywhere.
  • Other users. Your display name, avatar and public account id are visible to other people inside the platform. Your email address is not shown to other users by FaceCity.
  • Infrastructure and service providers, acting on our instructions and bound to confidentiality:
    ProviderPurposeData involved
    Cloud hosting and managed database providerRuns the application and stores its dataAll data described in this policy
    SendGrid (Twilio)Sends verification, one-time-code and account emailsEmail address, name, the content of the message
    Cloudflare R2Stores uploaded files such as avatarsThe uploaded file and its metadata
    Google Firebase Cloud MessagingDelivers push notifications, if you enable themPush token, notification content
    Google LLC (Sign in with Google)Authenticates you when you choose Google sign-inThe exchange described in section 4
    FaceCoin wallet serviceSettles fees inside the platformAccount id, order identifier, amount
    Regulated payment providersProcess real-money top-ups and payouts through the walletPayment details you give them directly; we do not receive card data
  • Platforms you connected. When you publish or cross-post, the content you chose is sent to that platform, where it is handled under that platform's own terms and privacy policy. Nothing is sent to a connected platform unless you ask for it. See section 5.
  • Legal and safety. We may disclose data where we are legally required to, or where it is necessary to investigate fraud or abuse, to enforce our Terms of Use, or to protect the rights and safety of our users or the public.
  • Corporate transactions. If the platform or part of it is transferred to another entity, data may be transferred with it; you will be told before the transfer takes effect.

10. International transfers

FaceWorld is available worldwide and the providers listed above operate data centres in several countries, so your data may be processed outside the country you live in. Where such a transfer leaves a jurisdiction that restricts it — for example the European Economic Area or the United Kingdom — we rely on an appropriate safeguard, normally the European Commission's Standard Contractual Clauses or an adequacy decision covering the destination, together with technical measures such as encryption in transit and at rest. You can ask us for details of the safeguard applied to a particular transfer.

11. How long we keep data

  • Account and profile data — for as long as your account exists.
  • Sessions and refresh tokens — until they expire or you revoke them; revoked records are kept briefly for security review.
  • One-time codes — minutes; they are stored only as hashes and are unusable after expiry.
  • Devices — while the device remains associated with your account.
  • Security audit log — retained for a limited period so that you and we can investigate suspicious activity.
  • Identity and business verification records — for as long as the status they support is held, and afterwards for the period required by the applicable legal obligation.
  • Connected accounts — tokens until you disconnect or they expire; the content index and statistics snapshots while the connection exists and within the limits each platform sets, including YouTube's rolling 30-day refresh-or-delete cycle.
  • Payment and fee records — for the period required by accounting and tax rules.
  • After account deletion — the account is first marked as deleted and loses access immediately; the underlying records are then erased or irreversibly anonymised, except where we must keep specific records to comply with the law or to defend a legal claim.

12. Your rights

Depending on where you live, you have some or all of these rights:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of data that is wrong or incomplete.
  • Erasure — deletion of your account and the data attached to it.
  • Portability — an export of the data you gave us, in a structured, commonly used, machine-readable format.
  • Restriction and objection — to ask us to pause processing, or to object to processing we base on our legitimate interests.
  • Withdrawal of consent — for anything we do on the basis of your consent.
  • Complaint — to your local data-protection authority.

How to use these rights

Several of them you can exercise yourself, immediately, while signed in:

  • View and edit your name, display name, language and avatar in your profile settings.
  • See every active session and sign it out, individually or all at once.
  • See the devices linked to your account and withdraw their trusted state.
  • Read your own security audit log.
  • Turn two-factor authentication on or off, change your password and change your email address.
  • Unlink your Google account, as described in section 4.4.

For a full export of your data or for deletion of your account, write to support@newfaceworld.com from the email address of the account. We answer within 30 days. We may need to confirm your identity first, so that nobody else can obtain or delete your data.

13. Cookies and session tokens

We use the minimum needed to keep you signed in. We do not use advertising cookies and we do not embed third-party advertising or analytics trackers on the platform.

  • Refresh token cookie — a strictly necessary cookie set when you sign in, so that your session can be renewed without asking for your password again. It is HTTP-only, so scripts in the browser cannot read it, and it rotates on every renewal: an attempt to reuse an old one revokes the whole session chain.
  • Access token — short-lived and held only in the memory of the open tab. Closing the tab discards it.
  • Local storage — small preferences such as interface language and theme.
  • Sign-in state — the one-time state and PKCE values used during Google sign-in, kept on our server for ten minutes and then deleted.

Blocking the session cookie in your browser will prevent you from staying signed in.

14. How we protect data

  • All traffic runs over HTTPS.
  • Passwords are stored as Argon2id hashes; one-time codes and recovery codes only as hashes.
  • Identity and business verification records, and two-factor secrets, are encrypted at the field level in the database.
  • Sessions are protected by rotating refresh tokens with reuse detection, and can be revoked by you at any moment.
  • Sign-in attempts are rate-limited and accounts lock temporarily after repeated failures.
  • Google sign-in uses PKCE and one-time state values to defend against interception and cross-site request forgery.
  • Access to production data inside our team is limited to the people who need it.

No online service can promise absolute security, but if a breach affects your personal data and the law requires it, we will notify you and the competent authority without undue delay.

15. Age requirement

FaceWorld is intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from children. If we learn that an account belongs to someone under 18, we will close it and delete the associated data. A parent or guardian who believes a child has given us data should write to support@newfaceworld.com.

16. Changes to this policy

We may update this policy as the platform develops or as the law changes. The effective date at the top always shows the current version. If a change materially affects your rights or the way we use your data, we will tell you in advance — by email to the address on your account, or by a notice inside the platform — before it takes effect. Continuing to use FaceWorld after a change means you accept the updated policy.

17. Contact us

For any privacy question, request or complaint, including requests to access, correct, export or delete your data, write to support@newfaceworld.com. Please send your message from the email address registered on the account so we can identify you.

See also our Terms of Use, which govern your use of FaceWorld.