Image Privacy FAQ
Can't find what you need? Get in touch at support@hail.to.
Getting started
How does Image Privacy work?
Add someone to your People Locker using a clear reference photo and select their privacy level. Hail then checks each new image you upload. When it recognises that person, their privacy settings are applied before the content is shared.
Advanced Rules can apply organisation-wide protection to detected faces. Time Machine Scan can find and protect people in previously published images.
Where should I start?
Add a few people to your People Locker and check that the results are accurate. Then review Advanced Rules to determine whether your organisation needs additional protection. Consent Forms and Time Machine Scans can be used later as required.
Why can’t I access Image Privacy from the menu?
Image Privacy is currently available only to New Zealand organisations.
If it is enabled for your organisation, everyone can see it in the menu, but only Consent Officers can open it. Other users see a padlock.
Ask an account owner or administrator to grant you Consent Officer access from the Members page. Contact support@hail.to if you want Image Privacy enabled.
People and reference photos
Do I need a reference photo?
Yes. Hail needs a reference photo before it can recognise someone.
For the best results, use a clear, recent photo containing only that person. They should be facing the camera in good lighting, with nothing covering their face.
How recent should a reference photo be?
The more recent, the better. Photos older than approximately two years may reduce matching accuracy, particularly for children whose appearance can change quickly.
Can I add more than one photo for each person?
Yes. Additional reference photos may improve recognition, particularly if the person’s appearance has changed.
Can I protect someone who has not completed a consent form through Hail?
Yes. You can add anyone to your People Locker and select their privacy level, whether or not they have completed a Hail Consent Form.
Your organisation remains responsible for ensuring it has the appropriate authority, consent or lawful basis to collect and use that person’s information.
What happens if someone changes their mind?
Update the person’s privacy level from their person page. New uploads will follow the updated setting immediately.
Run a Time Machine Scan if you need to apply the updated preference to previously published content.
How protection works
What happens if Hail is not certain that it has found the correct person?
Hail assigns a confidence percentage to possible matches and presents uncertain matches for human review. You decide whether to confirm or reject each match before any protection is applied.
Does Image Privacy delete my images?
No. Image Privacy protects people by covering their faces before content is shared. Original images remain unchanged in your media library.
Images are deleted only when an authorised user chooses to delete them.
Can I choose how faces are covered?
Yes. Select a Default Face Cover from the Advanced Rules tab. Available options include:
- Blur
- Pixelate
- Emoji
- Custom overlay image
Individual people can use a different face cover when required. Using the default setting is recommended for consistency across your organisation.
What is the difference between People Locker and Advanced Rules?
People Locker protects specific individuals who have been added to it.
Advanced Rules apply protection to every detected face, either when content is shared to social media or everywhere the image is used.
Both can operate together. When more than one rule applies, the strongest applicable protection is used.
What is the difference between People Locker and Time Machine?
People Locker automatically protects people in new images uploaded after they have been added.
Time Machine finds and protects those people in previously published images.
People locker: Going forward
Time Machine: Back in time
Existing content
Why isn’t an image published last year protected automatically?
Image Privacy checks images when they are uploaded. An image published before someone was added to the People Locker was not checked against that person.
Run a Time Machine Scan to find and protect them in previously published images.
Does a Time Machine Scan change my images automatically?
No. It identifies possible matches and presents them for review. You decide whether to protect, remove, delete or leave each image unchanged.
Is there a cost?
Yes. Time Machine Scans are charged per scan according to the number of images within the selected date range.
The exact price is displayed before you confirm the scan. You can cancel at that stage without proceeding.
How long are scan results retained?
Scan results are retained for 30 days. Download the PDF report within that period if you need to keep a record.
What happens to images already published on Facebook or Instagram?
Hail cannot change an image in a post that is already live on another platform.
A Time Machine Scan can identify where an image was shared. You can then remove or replace it on that platform and mark the result as reviewed in Hail.
Consent
Can I collect consent from parents or staff?
Yes. Consent Forms can be emailed to:
- A Hail Mail list
- Individual email addresses
- Contacts imported through a supported student management system
Responses return to Hail. Once approved, the selected privacy preferences are applied automatically.
Do people need to reconfirm their consent?
They can. Set a Consent Expiry period under Advanced Rules. Available periods range from six months to three years.
Hail will notify Consent Officers when reconfirmation is due for people in the People Locker.
What happens if someone does not reconfirm?
The person is hidden for a one-month grace period and a reminder is sent. If they still do not respond, they are removed from Image Privacy.
Detection accuracy
Will Image Privacy detect side-on, partially blocked or unclear faces?
Detection and matching work best when a face is:
- Clearly visible
- Reasonably well lit
- Facing the camera or close to front-facing
- Large enough to distinguish in the image
- In focus
Accuracy may be reduced when a face is side-on, blurred, shadowed, very small, covered or partially blocked.
When Hail is uncertain, it presents the possible match for human review in the People Locker.
What happens if someone changes their hairstyle or wears glasses or a hat?
Image matching primarily uses facial features rather than hair. A different hairstyle, glasses or a hat will not necessarily prevent recognition if the person’s key facial features remain visible.
Accuracy may be reduced when glasses, hats, lighting, facial angle or other obstructions conceal parts of the face. Uncertain matches are presented for human review.
How well does Image Privacy recognise students as they grow older?
Face matching can become less accurate as children grow and their appearance changes, particularly over several years or during puberty.
Review reference photos annually and replace them sooner when a person’s appearance changes significantly. Consent reconfirmation settings under Advanced Rules can be used to schedule regular reviews. The default reconfirmation period is one year.
Privacy and data
Is my data secure?
Hail treats reference photos, consent preferences and Image Privacy data as sensitive information.
This information is used only to provide Image Privacy features. Face data is not:
- Used to identify unknown people
- Matched across different organisations
- Used to infer personal characteristics
- Used for surveillance, attendance, behaviour monitoring or profiling
- Used to train AI models
How are photos and student data in the People Locker protected?
Access is restricted to authorised users within the organisation, including users assigned the Consent Officer role. Only account owners and administrators can grant that role.
Hail’s safeguards include:
- Role-based access controls
- Audit logging
- Encryption in transit and at rest
- Secure AWS cloud infrastructure in Australia
- Regular security assessments
- Breach detection and response processes
- A dedicated security lead
- Three ST4S certifications
No system can guarantee complete security. Hail applies technical and organisational safeguards intended to protect the information it holds.
What is Image Privacy not designed for?
Image Privacy is designed to support privacy and safety. It is not designed for:
- Surveillance
- Attendance tracking
- Behaviour monitoring
- Profiling
- Identifying unknown people
Who is responsible for how Image Privacy is used?
Your organisation is responsible for deciding when to use Image Privacy and what action to take based on its results.
This includes ensuring that your organisation has the appropriate authority, consent or lawful basis and keeps suitable records. Notes can be recorded against individual people and Time Machine Scans for this purpose.
For anything privacy-specific, you can reach our privacy team at privacy@hail.to.