UMNI

Privacy

Your photos stay with you

UMNI is a face-covering tool for event photos. This page explains what happens to a picture after you upload it, how faces are found, and what is not done with your data.

The short version

  • Photos are read in your browser. They are not uploaded to UMNI for covering.
  • Face detection runs on this device. It does not send pixels to a cloud AI.
  • Your photos are not used to train an AI model.
  • Download writes a new file on your device. We do not keep a copy.

Where photos live

When you choose pictures from your camera roll or computer, the files are opened locally in this tab. Covers, blur, move, resize, copy, and paste all happen on that local copy. Closing the tab clears the working photos from memory. Nothing is stored on an UMNI server as part of this covering workflow.

How faces are found

UMNI uses MediaPipe face models (BlazeFace and Face Landmarker) that already exist. They run in the browser with TensorFlow Lite. The photo is scanned on your device, including zoomed-in tiles for small faces in group shots. Those models were trained by Google before this app existed. UMNI only runs them. It does not send your event photos back to train, fine-tune, or update any model.

What leaves the device

Loading the app fetches the UMNI website and the MediaPipe runtime files needed to detect faces. Those requests do not include your photos. After that, detection, covering, and export stay on this device. If you share a downloaded picture later — WhatsApp, email, Drive — that is your choice, outside UMNI.

What we ask of you

Review every face before you share. Automatic detection can miss people who are turned away, looking down, or far in the back. Add, move, or remove covers by hand when that happens. UMNI is a covering aid for social workers and event staff, not a guarantee that a photo is fully anonymised.

Last updated 21 August 2026.