ClarityCheck, a people-search service that offers reverse image lookup, left a database containing more than 9 million image files accessible online, according to WIRED. The report cites findings from independent security researcher Jeremiah Fowler, who said the files included photographs of people’s faces and were stored in an unsecured Amazon S3 bucket. The database contained roughly 450 GB of images, WIRED reports, including apparent profile photos, screenshots, and other images of adults, teenagers, and children. The files were organized in folders named “faces” and “profiles,” and Fowler said they could be reached through a URL that appeared in ClarityCheck’s publicly available website code. The finding is especially sensitive because ClarityCheck markets the feature as a private reverse image search. According to WIRED, the site tells users that their reverse image search is “private and secure,” while its photo-search page says it can help identify a person in a photo and find social media profiles. The broader ClarityCheck service also says it can search by phone number, email address, vehicle identification number, and name. WIRED also reports that a second misconfiguration exposed people’s email addresses and phone numbers. The provided source material does not include additional details on the scale or structure of that second exposure, so the central documented issue remains the image database described by Fowler. ClarityCheck secured the image database after WIRED contacted the company in July, according to the report. Fowler told WIRED that the database appeared to have been exposed for months and that his initial efforts to alert the company were unsuccessful. The company pushed back on the wording of the report. In a statement to WIRED, ClarityCheck said it appreciated Fowler’s efforts and “acted immediately to restrict access” once the matter reached the appropriate teams. But it disputed the characterization that the data was publicly exposed, saying an ordinary member of the public would not have found it and that access required a specific, unindexed URL not discoverable through normal use of the service or a general web search. That distinction matters, but it does not remove the risk described in the report. WIRED’s account says the URL was present in public website code and that the bucket was unsecured; ClarityCheck’s response says discovery required non-obvious knowledge of the URL. The difference, as described by WIRED and disputed in part by ClarityCheck, is between public accessibility through a specific URL and ordinary public discovery. The biometric angle raises the stakes. Fowler warned WIRED that people whose faces appeared in the database may not have known their images had been uploaded to ClarityCheck at all, because the service is designed to identify others. He also raised the possibility that automated systems could crawl exposed images and extract faces, including from photos of children. Who benefits: Security teams and privacy reviewers get another concrete case study for auditing object storage, public website code, and data-retention paths. Users benefit only if services respond by tightening access controls and reducing unnecessary storage of uploaded images. Who's exposed: ClarityCheck faces reputational scrutiny from a report involving face images, children, and contact information. People whose photos were uploaded may have had no direct relationship with the service, according to Fowler’s warning in WIRED.