Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.
There is a particular kind of irony in a privacy promise that becomes the headline of a data exposure story. ClarityCheck, a people-search platform that tells users their reverse image searches are “private and secure,” left more than 9 million image files, including photographs of faces belonging to adults, teenagers, and children, sitting in an unsecured cloud bucket that anyone with a URL could access. The reassurance on the website was not just hollow. It pointed in precisely the wrong direction.
The findings come from independent security researcher Jeremiah Fowler, who discovered that ClarityCheck had stored roughly 450 GB of images in an Amazon S3 bucket with no access controls. The files were organised into folders labelled “faces” and “profiles,” and the bucket’s URL was embedded directly in the company’s publicly available website code, meaning it required no hacking skill or special knowledge to reach. A second misconfiguration separately exposed users’ email addresses and phone numbers.
What People-Finder Tools Actually Collect
To understand why this exposure is more serious than a typical data leak, it helps to understand what ClarityCheck is designed to do. The platform sits within a growing category of so-called people-finder or people-search services, which claim to aggregate public records, web data, and other databases to build profiles of individuals. ClarityCheck specifically advertises the ability to search by phone number, email address, vehicle identification number, and name. Its photo-search feature promises to “identify anyone in a photo” and locate social media profiles “in seconds.”
That capability description matters here. The service is not merely storing profile pictures for display purposes. It is building a searchable index that links faces to identities. When the underlying image database is left open, the exposure is not just of photographs in the abstract. It is of a facial recognition asset, a collection of images that were uploaded specifically because they carry identifying information, now accessible to any third party who stumbled across the URL.
The presence of folders named “faces” and “profiles” suggests the data was structured for machine processing, not just human browsing. That structural detail raises questions about what downstream systems were consuming these images and whether any of that processing continued while the bucket remained open.
The Gap Between Marketing and Security Practice
The ClarityCheck case illustrates a pattern that recurs across consumer data services: the marketing language around privacy is often written by people who have no visibility into the engineering decisions being made on the backend. A company can genuinely believe its product is secure while a misconfigured storage bucket sits exposed for an indeterminate period.
Unsecured Amazon S3 buckets have been at the centre of data exposures for years, across industries ranging from healthcare to financial services. The configuration error is not exotic. Amazon’s own tooling flags publicly accessible buckets and has introduced default settings to block public access. That ClarityCheck’s bucket remained open despite these guardrails suggests the misconfiguration was either deliberate for operational reasons or simply overlooked during setup and never audited afterward.
The second misconfiguration, which exposed email addresses and phone numbers separately from the image database, compounds the concern. These are precisely the data points ClarityCheck uses as search inputs. Users who submitted their own contact details to run searches on others may find their information was itself exposed in the process.
Why This Matters Beyond One Misconfigured Bucket
For readers in Malaysia and Singapore, the ClarityCheck exposure is a useful prompt to think about a category of service that operates largely outside formal regulatory scrutiny in either country. People-search platforms typically source their data from public records, social media scraping, and user-submitted content. They do not always fall neatly under the consent and collection frameworks that govern more conventional data processors.
Malaysia’s Personal Data Protection Act and Singapore’s Personal Data Protection Act both impose obligations on organisations that collect and process personal data, including biometric and photographic data. But enforcement against foreign-operated platforms that serve local users remains a practical challenge for the Personal Data Protection Department in Malaysia and the Personal Data Protection Commission in Singapore. Neither regulator has direct jurisdiction over a US-based service that has not established a local presence.
The broader issue is that reverse image search and facial identification tools are proliferating faster than the legal frameworks designed to contain their risks. When these tools also handle the data carelessly, the combination creates exposure that users have almost no practical way to detect or remedy. A person whose photograph was uploaded to ClarityCheck by someone else, which the platform’s design explicitly enables, had no knowledge their image was sitting in an open S3 bucket and no mechanism to request its removal.
Fowler’s research is a reminder that the people-finder industry’s central value proposition, finding information about individuals quickly and easily, is structurally in tension with the privacy of the individuals being found. When the operational security of these platforms fails to match their marketing, the people most at risk are not the paying users running searches. They are the subjects of those searches, who never consented to be indexed in the first place.
Read More: GrapheneOS Is Coming to Motorola, But Privacy Will Cost You More Than a Pixel