Legal
Privacy Policy
Version 2.7 — Effective September 27, 2026.
The Short Version
A summary to help you find your way. The numbered sections below are the policy, and they govern.
Your face photos are never stored on our servers. Each one is held in memory for the seconds our AI providers need to analyze it, then discarded. Your photos, scores and profile live on your device, and in your own iCloud or Google Drive if you turn on backup. Our servers hold your account: your email address, subscription, consent record, marketing preference, scan counts and sign-in records (Section 2).
We never sell your data, use it for advertising, or track you across other apps and websites. We never train AI on your photos, and our agreements bar our AI providers from doing so. We never use your face to identify you, or your skin tone to infer your race or ethnicity. You can export your data, delete any scan, or delete your account from inside the app.
1. Who We Are
Skin Intelligence Inc., 329 Howe St #2031, Vancouver, BC V6C 3N2, Canada, is the controller responsible for your personal information. This policy covers the Skin Intelligence app and website; Pick used without an account has its own Pick Privacy Policy.
Our Privacy Officer, who is also our designated Data Protection Officer, handles every privacy question and request. The published business contact information is: Data Protection Officer, Skin Intelligence Inc. · privacy@skinintelligence.ai · +1 604 600 0360.
Skin Intelligence is a cosmetic skincare app. It is not a medical device and does not diagnose, treat, cure, monitor or prevent any skin disease or condition.
2. What We Hold, and Where It Lives
Most of your data stays on your device. Anything on your device is also copied to your own iCloud or Google Drive if you turn on backup (Section 7); we never receive that copy.
- Account data — on our servers. Your email address; your subscription (plan, status and payment platform); your consent record (each acceptance and withdrawal, with its version and date); your marketing-email preference; your scan counters, used to apply plan limits and prevent abuse; and your sign-in records, including the network (IP) address each sign-in came from, kept for account security.
- Profile — on your device. Your name, age range, gender and experience level, which you enter, and your skin type and skin tone, which each scan detects and you can change. Skin tone is a cosmetic shade used only to personalize your routine, never to determine or infer your race or ethnicity; because some laws may treat it as sensitive, we handle it as sensitive information.
- Your Preferences — on your device. Choices such as Maternity & Nursing or Recent Facial or Laser. When you build a routine, only the resulting list of excluded ingredient codes is sent to us; it names no preference or reason, is held in memory for that request only, and is never used to infer why an ingredient was excluded.
- Face scans — on your device. Your photos and the skin scores produced from them. Photos pass through our servers only to be analyzed (Section 4).
- Product photos — for My Shelf and Pick while you are signed in. Google's AI reads each photo to extract the product's brand, name, category, size and ingredient list. We store neither the photos nor what is read from them; your shelf stays on your device, and Pick works out its verdict there.
- Device and usage data. Your device model and type, operating system version, and how you use the app (features used, steps completed, session length), to improve the app and find device-specific faults.
- Approximate location. Our hosting provider works out your approximate location from your connection. We use only your country — for prices, checkout, app-store buttons, converted product prices and ingredient strength limits — and, to apply the availability limits in Section 10, your state or province.
Some profile fields travel with a request and are held in memory for that request only: your age range and gender with each scan, to improve accuracy; and your skin type, skin tone, experience level, focus areas, routine pace and ingredient swaps when you build a routine. Your name is never sent to our servers.
3. How We Use It
We use your data to:
- Run your account and subscription.
- Analyze your scans and show how your skin changes over time.
- Build your cosmetic skincare routine.
- Read the product labels you photograph.
- Keep the service secure and prevent abuse of the free allowances.
- Improve the app, using analytics not linked to your name, email or account (Section 5).
- Send marketing emails, only if you opt in; you can opt out in your profile or through the link in any marketing email. Essential service messages — sign-in codes, renewal reminders, security notices and changes to our terms — are sent regardless.
We do not use your photos, scores or any personal data to train AI models, and our agreements prohibit our AI providers from doing so. If we ever want to, we will first ask for your separate, explicit opt-in consent.
Legal basis. Where your country's law requires one, we rely on:
- Our contract with you — to provide the service you asked for: your account, scans, routine, label reading and subscription. Without this data we cannot provide that service.
- Your consent — for processing your face photos (and skin tone, where treated as sensitive), sending them to our AI providers in the United States, backup to your own cloud storage, and marketing emails. Each is a separate choice you can withdraw at any time.
- Our legitimate interests — security, preventing abuse of the free allowances, and improving the app through analytics not linked to you, weighed against your rights and freedoms. You can object at any time.
- Legal obligations — keeping required records and answering lawful requests.
Automated results. Your skin scores come from AI models, and your routine from a rule-based engine. They are cosmetic suggestions, and you decide what to do with them. They have no legal or similarly significant effect on you — on your finances, employment, housing, insurance, education, healthcare or access to essential services — and you can re-scan, change your inputs or delete any result at any time.
4. Your Face Scans and Our AI Partners
When you take a scan, your photo goes from your device to our servers, which send it, with your age range and gender, to our AI providers:
- OpenAI OpCo, LLC (United States)
- Google, contracted through Google Cloud Canada Corporation, via Google Cloud Vertex AI (processed in the United States)
Our servers hold your photo in memory only while it is analyzed, then discard it; it is never stored, logged or retained. The providers return your scores, skin type and skin tone, and brief written observations that are discarded once your scores are made — never your photo.
Our agreements bar both providers from training or fine-tuning any model on your photos, and from sharing them with anyone other than the subprocessors that run their own infrastructure. Neither keeps your photo once your results are made: OpenAI has signed zero-retention terms, so your photo and the request are not logged or kept for abuse monitoring or human review, and Google may not store your photo outside our account longer than producing your result requires.
Exceptions: both providers automatically check images for child sexual abuse material, and we cannot switch this off. If a check flags an image, the provider may keep it for review and report it to the National Center for Missing and Exploited Children, as United States federal law requires. A provider may also keep an image where another law requires it. We control neither.
Face photos may be biometric or sensitive data under some laws. We use them only for your cosmetic analysis — never to identify you or verify your identity — and create no face template or embedding. The points your phone uses to frame your face are never stored and never leave your device. We never sell, lease or trade your photos or any biometric data, or receive anything of value for them. Our Biometric Data Policy covers their retention, deletion and protection.
5. Who Else Handles Your Data
Besides our AI providers, these companies handle limited data for us:
- Supabase (Canada) — stores your account data.
- Google Cloud (Canada) — stores encrypted daily backups of your account data, deleted within 30 days.
- Vercel, Inc. (United States) — runs our servers and website, so your photos pass through it on their way to analysis. On our website only, it counts visitors without cookies (page views, referring sites, and visitor country or region), using a code that resets daily and cannot identify or follow you; your IP address is not stored.
- Stripe, Inc. (United States) — web payments. It receives your email, account identifier, plan and payment details, and collects your card and billing address directly at checkout.
- RevenueCat, Inc. (United States) — App Store and Google Play subscriptions. It receives your account identifier, purchase, subscription status, the store's purchase record, and basic device information (such as model, operating system version and locale) collected by its software. Never your email.
- Apple and Google — billing for store purchases, under their own terms.
- PostHog, Inc. (United States) — product analytics not linked to your name, email or account, such as page views and counts of in-app actions. It uses your IP address to work out your country and region, then discards it. Session recording is off.
- Functional Software, Inc. (Sentry) (United States) — error reports (error type, technical trace, request details and a shortened error message), set to exclude photos, scores, profile data, payment details and email addresses. Session replay is off.
- Resend, Inc. (United States) — sends sign-in codes and service emails, using only your email address.
Apart from passing through Vercel's servers, your face photos, scores and profile reach none of these companies. Except where Apple or Google bills a store purchase as the seller under its own terms, each is bound by contract to protect your data to a standard comparable to this policy and applicable law, and to use it only to serve us. This is the complete list of third parties we share your data with, apart from the subprocessors that run our AI providers' own infrastructure; if we add or replace one, we update this list and record the change in this policy's version history.
The app and website use local storage to keep you signed in and remember preferences such as dark mode. We use no advertising cookies and no cross-site tracking.
6. International Transfers
If you live outside Canada and the United States, your data leaves your country when you use the service: your face photo, with your age range and gender, goes to the United States for the seconds its analysis takes; your account data is stored in Canada; and the payment, subscription, analytics, error and email providers in Section 5 are in the United States. Product photos you ask us to read, and the profile details a routine needs, also pass through the United States for that request only. Nothing else leaves your device unless you back it up to your own cloud storage.
We rely on two things, independently: your consent, given as a separate item before your first scan and revocable at any time in the app; and the written agreements summarized below.
The United States' Data-Protection System, in Plain Terms
The United States has no single, comprehensive federal data protection law of the kind found in Canada, Japan, South Korea, Brazil, Singapore or the European Union; protection comes from sector-specific federal laws, state laws and contracts. Japan, Georgia and most other countries whose law asks have not recognized it as offering equivalent or adequate protection. While your data is there, US courts, law enforcement and government or national-security authorities may access it under US law, and your routes to challenge that access or obtain a remedy may be weaker than at home. We cannot control or prevent such access.
The Protection Your Data Still Has There — a Written Summary
Our agreements require OpenAI and Google to use your face photo only to produce the results you asked for; never to train or fine-tune models with it; to keep nothing once those results are made; to disclose it to no one but the subprocessors running their own infrastructure; to protect it with appropriate security; and to help us answer your requests. Every other provider in Section 5 is bound by equivalent written commitments for the limited data it receives. Together these are intended to give your data protection comparable to the law of your own country, and we review them if that stops being so. The one thing no contract can remove is the child-safety check in Section 4.
7. How Long We Keep It
- Face photos, scores and profile — on your device until you delete them; never kept on our servers.
- Account data — while your account is open, then deleted 30 days after you ask us to delete it.
- Our encrypted daily backups — 30 days. Our hosting provider's backups — about 7 days.
- Error reports — 90 days.
- Analytics events — as long as needed for product analytics. Neither these nor error reports are linked to you, so a deletion or access request cannot reach them.
- Unfinished sign-ups, which hold only an email address — 30 days.
- A scrambled (hashed) copy of your email address, kept only to stop repeat free-scan claims — up to 24 months.
We also keep a change log of your account fields (which field changed, its old and new values, when and by whom) for accuracy and security. It holds no email address and is deleted with your account.
Deleting data. You can delete any scan, or all of them, in the app; uninstalling the app or clearing its data removes them from your device for good. When you delete your account, it is deactivated at once and you have 30 days to cancel by signing back in; then your account data is permanently deleted. Backup copies roll off in the normal cycle and are never used to restore a deleted account except in disaster recovery. The scans on this device are deleted immediately, and we try to remove your cloud backup — please check your own cloud storage too. Apart from records the law requires us to keep, such as proof that you agreed to a renewing subscription, the only thing we keep is the hashed email above, which cannot be reversed or used to contact you, as the law allows for preventing fraud. Stripe, Apple, Google and RevenueCat keep their records under their own policies.
Cloud backup. If you turn it on, your data goes directly from your device to your own iCloud or Google Drive: your scans and scores, profile details (name, age range, gender, skin type and skin tone), My Shelf, My Calendar, routine and app settings, and a copy of your account details (email, plan, subscription status, latest consent acceptance with its date and version, and marketing preference). We never receive or access it; Apple's or Google's terms govern it.
8. Your Rights
Depending on where you live, you have the right to access your personal data; correct it; delete it; receive it in a structured, commonly used, machine-readable format; withdraw consent at any time (without affecting earlier processing); object to processing based on our legitimate interests, including analytics (which, not being linked to you, stops from then on); and complain to your data protection authority.
In the app, from your Profile, you can export your data as a ZIP file (account details and consent record, profile, preferences, routine, My Shelf, My Calendar, and scan scores and photos, in standard JSON and image formats), withdraw consent, delete scans and delete your account.
For anything else, email privacy@skinintelligence.ai. You need no account to make a request. We do not charge for requests exercising US state privacy rights; for other requests, any fee will be limited to what applicable law permits. We may ask you to verify your identity, and you may use an authorized agent, whom we may ask for proof of your written permission. We respond within the time your law sets — for US state residents, 45 days, extendable once by 45 days where reasonably necessary, with notice.
Appeals. If we decline your request, email privacy@skinintelligence.ai with the subject "Privacy Appeal". We decide within 45 days; if we deny your appeal, you may contact your state Attorney General or privacy regulator. This applies in every US state whose law provides an appeal, including Texas.
Complaints. Write to the same address; we acknowledge a complaint within 30 days and respond without undue delay. You can also complain to your data protection authority (Sections 12 and 13).
9. Security
No system is completely secure, but we take reasonable steps to protect your data. It is encrypted in transit and at rest: our hosting provider encrypts your account data, and on iPhone and Android the operating system's encryption protects what the app stores. Access controls limit data to authorized personnel.
Breaches. If a breach is likely to put your rights at risk, we act without undue delay. For Canadian users, where there is a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada (and, for Alberta residents, Alberta's Information and Privacy Commissioner) and notify affected individuals as soon as feasible. For US residents, we notify you and state authorities as your state's breach law requires. Elsewhere, we notify you and your data protection authority where and when your law requires.
Government requests. We require valid legal process, push back on requests that are overbroad or improper, disclose no more than we are compelled to, and tell you where the law allows. Your photos, scores and preferences never rest on our servers, so there is very little to produce.
Vulnerabilities. Report one to support@skinintelligence.ai with the subject "Security". We will not bring a claim against you, or refer you for prosecution, for good-faith research that stays within our own app, website and API, does not access, change or delete anyone else's data, does not degrade the service, and gives us a reasonable chance to fix the problem before you make it public.
10. Who Can Use Skin Intelligence
You must be 18 or older. We do not knowingly collect personal information from anyone younger; if we find we have, we promptly delete that account and its data.
Skin Intelligence is not available to residents of Illinois, Washington or Quebec. We restrict access from all three, and by agreeing to our Terms you confirm you are not a resident of any of them. These measures cannot catch everyone — for example, where a location is hidden — so if you live in one of them, please do not use Skin Intelligence. If we identify a resident's account, we deactivate it and delete its data (Section 7).
Illinois — We do not knowingly offer the service to, collect personal information from, or process biometric identifiers or biometric information of Illinois residents. Every scan is re-checked on our servers when you take it, and refused before any image is read or analyzed if it comes from a blocked location.
Quebec — Skin Intelligence is offered in English only.
11. U.S. State Privacy Notices
Your rights in Section 8 apply in every US state with a comprehensive privacy law, to the extent that law applies to us. In every state, we do not sell your personal or sensitive data, share it for cross-context behavioural advertising, use it for targeted advertising, or profile you with legal or similarly significant effects — so there is nothing to opt out of, and you are treated as opted out by default, including when your browser sends a Global Privacy Control signal. We process face photos, and skin tone where it may be considered sensitive, only with your opt-in consent and only where strictly necessary to provide the service (in Maryland, we collect them only where strictly necessary and never sell sensitive data). We never discriminate against you for using your rights.
California
To the extent the California Consumer Privacy Act applies to us, you may know the categories and specific pieces of personal information we have collected, delete it (subject to Cal. Civ. Code § 1798.105(d), such as the hashed email in Section 7) and correct it. We handle your face photos, and your skin tone to the extent it may relate to racial or ethnic origin, as sensitive personal information, used solely to provide the analysis and routine you ask for — never to infer characteristics about you, or for profiling, advertising, enrichment or AI training. We do not track you across other websites, so we do not respond to Do Not Track signals.
Texas
Your face photos may be sensitive data under the Texas Data Privacy and Security Act, and we process them only with your consent. Under the Texas Capture or Use of Biometric Identifier Act, we inform you and obtain your consent before any photo is captured, keep no biometric identifier after the analysis completes, never sell or lease your photos, and disclose them only to the AI providers analyzing them for us, under contracts that prohibit any other use (apart from the child-safety checks in Section 4).
Colorado
Biometric data is sensitive data under the Colorado Privacy Act, and we process it only with your consent. Before collection, Colorado law requires us to tell you that: your face photos may be biometric identifiers; we collect them solely to generate your cosmetic skin analysis results; we disclose them only to our AI providers (OpenAI and Google), only to perform that analysis; and we do not retain them — they are processed in server memory and immediately discarded, and the copies you keep stay on your device (and your own cloud backup, if on) until you delete them. We obtain your consent before your first scan, and never sell biometric identifiers or use them to identify you. Our Biometric Data Policy, available from Privacy & Data in the app and our website footer, sets out our retention schedule, deletion practices and incident response.
Connecticut
Because we treat your face photos as biometric data, we do not release the images themselves in response to an access request; we will confirm that we collected them and tell you how they were used. The photos themselves stay on your device, and you can export them from the app at any time. We have sold no personal data, so there is no list of buyers to give. If we deny your appeal, you may contact the Connecticut Attorney General (portal.ct.gov/ag).
Nevada
Your face photos and skin scores may be consumer health data under Nevada law. Our Consumer Health Data Privacy Policy, available from Privacy & Data in the app and our website footer, explains how we handle that data and your rights over it.
12. Canadian Residents
Skin Intelligence Inc. is a federal corporation under the Canada Business Corporations Act, with its registered office in British Columbia, and your account data is hosted in Canada. Our Privacy Officer (privacy@skinintelligence.ai) is the person responsible for your personal information under PIPEDA and the British Columbia and Alberta Personal Information Protection Acts.
Some of your information is handled by service providers in the United States: your face photos, briefly, by our AI providers, and your email, subscription, analytics and error data by the providers in Section 5. Written agreements require them to protect it to a comparable level, but while it is outside Canada, that country's courts, law enforcement and national-security authorities may access it. Our policies and practices for providers outside Canada are those in Sections 4 to 6, available on request; our Privacy Officer will answer any question about them.
We maintain an internal Privacy Impact Assessment under PIPEDA, reviewed whenever our processing changes materially and available to regulators on request. You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) and, in British Columbia or Alberta, to that province's Information and Privacy Commissioner.
13. Other Countries
This section adds what particular countries require, and supplements the rest of this policy — especially Section 6.
Japan (APPI)
Your data is transferred to the United States, to OpenAI OpCo, LLC and to Google (contracted through Google Cloud Canada Corporation, processing on its US infrastructure). The Personal Information Protection Commission has not designated the United States as having an equivalent standard of protection. Section 6 describes its protection system and the measures the recipients take. We give you this information, and ask for your consent to the transfer, before your first scan.
South Korea (PIPA)
We entrust the processing of your data abroad to perform our contract with you. (1) Data: your facial image, age range and gender. (2) Country, time and method: the United States, when you take each scan, over an encrypted connection. (3) Recipients: OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, United States (Data Protection Officer, privacy@openai.com); and Google, contracted through Google Cloud Canada Corporation, on its US infrastructure (through the contact route at policies.google.com). (4) Purpose and retention: generating your cosmetic skin analysis results, kept no longer than that request (Section 4). (5) Refusing: decline the image-transfer item on our consent screen, or withdraw it later in the app; you keep your account and your data, but skin scanning needs the transfer.
Georgia
The United States does not provide the data-protection safeguards Georgian law requires, and no adequacy recognition applies to it; the resulting risks are in Section 6. We make the transfer on your consent, given in written electronic form by ticking the separate image-transfer item on our consent screen after this information is shown to you. We keep a written record of it — the wording, its version, and the date and time — and you can withdraw it at any time in the app.
Singapore and Brunei Darussalam
The two parts of Section 6 headed "The United States' Data-Protection System, in Plain Terms" and "The Protection Your Data Still Has There — a Written Summary" together form the written summary, required by Singapore's Personal Data Protection Act and Brunei Darussalam's Personal Data Protection Order, of the extent to which your transferred data is protected to a comparable standard. Our designated individual's business contact information is in Section 1.
India (DPDP Act)
This policy and our consent notice are in English. Email privacy@skinintelligence.ai naming any language in the Eighth Schedule to the Constitution of India, and we will send that version free of charge, normally within seven days, and correct any error you report. You can withdraw consent in the app as easily as you gave it. For a grievance, write to our Privacy Officer at the same address; we respond within the period the Act and its Rules require, after which you may complain to the Data Protection Board of India.
Brazil (LGPD)
Your facial image is sensitive personal data. We process and transfer it internationally on your consent, asked for specifically and separately after you are told the transfer is international and where it goes (Section 6), and use it only for the results you ask for. You can withdraw consent in the app at any time, and complain to the Autoridade Nacional de Proteção de Dados (gov.br/anpd).
Australia, Hong Kong SAR, Kenya, Kuwait, Namibia, Trinidad and Tobago, Ukraine, the United Arab Emirates, and Jordan
Sections 1, 6 and 8 apply to you in full. You may also complain to your national privacy authority — in Australia the Office of the Australian Information Commissioner, in Hong Kong the Privacy Commissioner for Personal Data, in Kenya the Office of the Data Protection Commissioner, in Ukraine the Ombudsperson, in the United Arab Emirates the UAE Data Office, and in Jordan the Personal Data Protection Unit.
14. Changes and Contact
We may update this policy. For material changes, we will tell you in the app and ask you to accept them before you continue scanning; the version you accepted before stays readable in the app, so you can see exactly what changed.
Skin Intelligence Inc. 329 Howe St #2031, Vancouver, BC V6C 3N2, Canada Email: privacy@skinintelligence.ai