Privacy Policy
Last updated: September 27, 2026
Face Composer (the web tool at easymoat.com/watchface/) and The Face (the Garmin Connect IQ watch face) are operated by Easymoat (sole proprietor: Yoshicchi, Japan). This policy explains what data they handle, why, and the choices you have. By using them you agree to this policy.
1. No account
There is no account and no password. The only identifier is your watch's Device ID, an 8-character code shown in the watch's settings under Watch Face → Customize. It is generated by the Connect IQ platform for this app and is not linked to your Garmin account, your name or your email. On an updated The Face, signing in to Face Composer also asks for the 6-digit Web code shown in the watch's settings menu, as proof that you have the watch; a sign-in lasts up to 30 days, and Sign out web on the watch ends every sign-in at once. The proof of sign-in is kept only in your browser.
2. What we store, and why
- Dials (layouts): the parts you place, their positions, sizes, colours and settings. Stored on our server under your Device ID so the watch can fetch them. Up to 30 in your Collection.
- Photos: the pictures you add in Face Composer (up to 1024 px, as uploaded) and the 32-colour cut-outs made from them for the watch. Stored under your Device ID. We never use them for anything else and never show them to anyone unless you share a dial.
- Settings: units, clock format, the tickers and teams you choose, and the size presets.
- Forecast location: if you press "Use this computer's place", the approximate position your browser reports (rounded to about 1 km) is stored so the weather parts have a place. You can replace it with the watch's own GPS position or clear it at any time in the Setup section.
- Watch check-ins: the time your watch last fetched a dial, so Face Composer can tell you whether it is connected.
- Purchase records: when you buy the 1-Year Pass, Stripe sends us the Device ID you entered and the email address used at checkout, so we can attach the Pass to that Device ID, email you a confirmation with a reference key, and contact you about your purchase.
- Author name and shared dials (when sharing is available): the name you choose to show, the dials you publish or send, and the Device IDs you send them to. Device IDs are never shown to other users.
- Watch verification data (only for a watch running an updated The Face): one-way fingerprints of the watch's own identifier and of a secret the watch holds (neither is stored), when the watch was registered or re-registered, whether and when it was frozen because another device claimed the same Device ID, a sign-in version number, the date (not the time) of the watch's most recent connection, and the minute in which the last Web code was used (so a code cannot be reused). The value a Web code is made from is not stored. With this in place, your saved forecast location is used only for your own watch and your signed-in browsers.
- PulseLink link (optional): if you link a PulseLink watch, we store that watch's PulseLink Device ID together with when the link was made and with which version. While linked, the approximate position of that PulseLink watch is used, each time it is needed, as the place for the weather parts, and the picture from PulseLink Cam can be shown on your dial. We keep no history of those positions. Linking requires the Web code shown on the PulseLink watch, so only its owner can link it. Unlink removes the link at any time; Sign out web on the PulseLink watch removes it too.
3. What we do not collect
No Garmin account data, no activity history, no location tracking (a linked PulseLink watch's position is used only for the weather, never recorded), no contacts, no advertising identifiers. Body metrics shown on the dial (heart rate, steps, Body Battery and so on) are read on the watch and never leave it.
4. Third-party services
- Stripe processes payments. We never see or store your card details. Stripe privacy policy.
- Yahoo Finance (prices), public sports data feeds (scores) and Open-Meteo (forecasts) receive only the ticker, team or rounded location needed for the request, never your Device ID.
- Render hosts our server (US region). GitHub Pages serves this website.
5. Sharing between users
When sharing is enabled, a dial you publish or send is copied as a snapshot (layout and photo cut-out) into the recipient's Collection together with your author name. Unpublishing removes it from the gallery but not from Collections that already received it. Dials you receive are shown to you only.
6. Retention and deletion
Data stays as long as it is needed for your watch to work. The Start the dial over button in Face Composer removes your dials and photos from our server. To erase everything stored under your Device ID, including purchase records, email easymoat@gmail.com from the address used at checkout, or quote the Device ID. Erasing your data also removes the watch verification data listed in section 2. Server logs are kept for up to 30 days.
7. Children
Face Composer and The Face are not directed at children under 13.
8. Changes
We will post any changes on this page with a new date.
9. Contact
Questions and requests: easymoat@gmail.com