Privacy Policy

Skin Care AI · Last updated 23 August 2026

This policy describes what the Skin Care AI iOS app actually does, not a summary of it. The app shows the same description on its own “Where your data goes” screen, and the two are kept in step: if the behaviour changes, both change with it.

Who is responsible

The controller of the data described here, in the sense of Article 4(7) GDPR, is:

Adem İnce
Gewerbepark Lindach
84489 Burghausen, Germany
Telephone: +49 1577 2534564

One line still missing: the house number on Gewerbepark Lindach. A German business address is held to Impressum-grade accuracy, and an address without its number is incomplete.

Privacy questions and requests: support@skincareai.beauty

What leaves your device

A photograph, per scan and per barcode

Each skin scan sends a single front-facing photograph to our analysis service, which passes it through OpenRouter, Inc. to an AI model run by Google — or by OpenAI, if Google cannot answer — which reads it and returns your score and notes. Those are the third parties; there are no others in this path. The head-turning ring shown during a scan is a guidance animation: it captures nothing, stores nothing and transmits nothing. Exactly one frame per scan leaves the device.

None of this happens until you say so. The first scan is behind a consent you give explicitly, and the page you are reading now is linked from it. You can revoke that permission later in the app, and scanning stops when you do.

Scanning a product barcode sends the frame it was read from in the same way, so the label can be identified rather than guessed at from the number.

Neither photograph is stored by our service or by us. Both are held only for as long as the request takes to answer, and neither is written to any log.

A random installation identifier

An identifier generated the first time the app runs. It counts scans against a daily limit so a single copy of the app cannot run up the bill. It is not your name, your device identifier or your Apple Account. It is stored in the iOS keychain, so it stays on that phone: it is never included in a backup and never moves to another device. It does survive deleting and reinstalling the app, which is deliberate — otherwise the daily limit could be reset by reinstalling.

Your language and country

Sent with each request so the report comes back in the language you read, and so product suggestions can name what is available where you are. The country is the two-letter region from your device settings. The app never asks for or uses your location.

Three anonymous counts

The app tells our own service when a scan fails, when the upgrade screen is shown, and when a purchase completes, so failures can be noticed. These carry no identifier at all, not even the installation identifier, so two counts from one phone cannot be told apart from two counts from two phones.

Product names and category names

When a suggested product is shown, the app asks Open Beauty Facts — a public, open database of cosmetics — for that product’s photograph. The query carries only the product’s name. To fill the product shelf, the app asks our service to search a public retailer catalogue; that query carries only category and skin-concern names from a fixed list, plus the same two-letter country region. Neither carries anything about you, your scan or your device.

What stays on your device

Your scores, your history, the tasks you have checked off and your intake answers stay on the phone. Of the intake answers, only your skin type and your goal are sent with a routine request so the plan matches them; the safety answers are not sent — a request carries only whether the routine must avoid certain ingredients, never the reason.

Your latest scan photograph stays on the phone, is replaced by the next scan, and is deleted after 30 days without one. It is deliberately excluded from your device backup, so it never reaches iCloud. Photo history is a separate feature and is off by default.

What is never collected

No name, email address or phone number. No contacts, calendar, location or health data. No advertising identifier. The app contains no third-party analytics or tracking SDK of any kind.

Who processes your data

WhoWhat they processWhere
Google Cloud (Cloud Run, Firestore) Hosts our analysis service. Handles the photograph in transit only; stores the installation identifier with a daily scan count. europe-west3 (Frankfurt, Germany)
OpenRouter, Inc. Routes the analysis request to the AI model named below. States that it does not use inputs or outputs for model training. United States
Google and, if Google is unavailable, OpenAI — the AI model providers reached through OpenRouter Reads the photograph and returns the analysis. The request goes to Google’s Gemini model first and falls through to OpenAI’s only when Google cannot answer; we name both because either may be the one that reads a given photograph. Every request we send carries a requirement that it be routed only to a provider that does not retain or train on what it receives; if none qualifies, the request fails rather than being routed to one that would. United States
Apple Handles the subscription. We never see your payment details — only whether a subscription is active. Per Apple’s own terms

The analysis service itself runs in Frankfurt, Germany. The AI providers reached through it — Google, and OpenAI as the fallback — operate in the United States, so a photograph is transferred outside the EEA for the seconds the request takes. OpenRouter’s privacy policy states that where information is transferred outside the EEA or UK it relies on adequacy decisions of the European Commission and on Standard Contractual Clauses approved by the Commission; that is the basis this transfer rests on.

Why we are allowed to process it

A facial photograph processed for cosmetic analysis is processed on the basis of your explicit consent (GDPR Article 6(1)(a)). The app asks for that consent before the first photograph leaves the device and tells you what will happen; you can withdraw it at any time in Settings, after which no further photograph is sent.

The installation identifier and the daily count are processed on the basis of our legitimate interest in preventing abuse of a paid service (Article 6(1)(f)).

Worth legal review, and left visible on purpose: whether this analysis is processing of biometric data under Article 9. The app performs cosmetic analysis and identifies nobody — it does not match, recognise or link a face to a person — which is the distinction Article 4(14) turns on. A regulator will still read that sentence first, and it should be checked by a lawyer rather than settled here.

How long it is kept

Photographs are not retained: they exist only for the duration of the request, and are never written to a log.

Our service keeps, per installation identifier, the current day, a count of requests made that day, and the time it was last seen. That record is not linked to a person. It is deleted automatically 90 days after the last request from that installation — the database removes it on its own, without anyone having to run anything.

Age, and children

The app is not intended for anyone under 16, and asks you to confirm you are 16 or older before the first photograph is sent.

We do not knowingly collect anything from a child. Sixteen is the default age in Art. 8 GDPR at which a person can consent to an information-society service on their own; we apply it everywhere rather than lowering it per country, because the app does not know where its user is and would rather ask too much than too little. The declaration is a statement you make, not a verification we perform — we have no way to check it and do not attempt one, which is itself a reason we keep so little.

If you believe a child under 16 has used the app and sent a photograph, write to support@skincareai.beauty. Photographs are not retained by the service, so there is usually nothing to delete beyond the installation record — and that we will delete on request.

Where to complain

The controller is established in Bavaria, so the competent supervisory authority is the Bavarian Data Protection Authority for the private sector: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany — lda.bayern.de.

Article 77 GDPR also lets you complain to the authority of the country you live or work in, whichever is easier for you. For the languages this app ships in, that is:

CountryAuthority
GermanyBayLDA (above), or your own Land's authority
SpainAgencia Española de Protección de Datos (AEPD) — aepd.es
FranceCommission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
ItalyGarante per la protezione dei dati personali — garanteprivacy.it
PortugalComissão Nacional de Proteção de Dados (CNPD) — cnpd.pt
NetherlandsAutoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl
Any other EEA countryYour national authority; the full list is at edpb.europa.eu

If you are in the United States, the state routes are in the US section below. Complaining costs you nothing and does not affect your use of the app.

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where we rely on your consent you may withdraw or revoke that consent at any time (Art. 7(3)), and doing so does not affect the lawfulness of what was processed before you did.

Because almost everything the app holds is on your own device, most of these you can exercise yourself and immediately: Settings → Data → Delete all removes every report, routine and photograph from the phone. In the same place you can revoke permission for photographs to leave the phone; after that no scan is sent, because there is nothing to send it to.

What that does not reach is the installation record on our service. To have that erased, or to exercise any of the rights above, write to support@skincareai.beauty. We answer within one month, as Art. 12(3) requires.

A scan that has already been answered cannot be recalled.

You also have the right to complain to a data protection supervisory authority in your country.

Whether you have to give us anything

You are under no statutory or contractual obligation to provide any of it. Giving a photograph is voluntary and it is the only way the analysis can work; if you decline, the consequence is simply that scanning does not run. Nothing else in the app is withheld for it.

Automated decisions

The reading is produced automatically, by a model, from one photograph. It scores cosmetic qualities and proposes a skincare routine. It makes no decision that produces legal effects for you or that similarly significantly affects you, in the sense of Art. 22 GDPR — it does not decide about credit, employment, insurance, health or access to any service, and nothing you are entitled to depends on what it says. You can ignore it, scan again, or delete it.

Data protection officer

We have not appointed one. The thresholds in Art. 37 GDPR and § 38 BDSG are not met: this is a one-person operation, and its core activity is not the large-scale monitoring of people. Data protection questions go to support@skincareai.beauty, which reaches the controller directly.

If you are in the United States

The sections above describe what happens to everyone. US state law adds rights on top of them, and a photograph of a face is treated as biometric and as sensitive under most of those laws — so this app sits inside the strictest part of each. Nothing here takes anything away from what is written above.

We do not sell, and we do not share for advertising

We have never sold personal information, and we do not share it for cross-context behavioural advertising. There is no advertising identifier in this app, no analytics SDK, no tracking SDK and no data broker anywhere in the path. That is true in every state, and it is why there is no “Do Not Sell or Share My Personal Information” link here — there is nothing for it to switch off.

California — CCPA and CPRA

In the last twelve months we collected these categories, for the purposes already described and for no others:

CategoryWhat it is hereKept for
Biometric information (sensitive personal information) One facial photograph per scan Not stored by us at all — the length of the request. Your own copy: replaced by the next scan, deleted after 30 days.
Identifiers A random installation identifier — not your name, device id or Apple Account 90 days after the last request, deleted automatically
Internet or network activity A daily scan counter kept against that identifier 90 days, with the identifier
Geolocation None. The two-letter region from your device settings is not location and is never resolved to a place. Not kept

You have the right to know what we collect and why, to delete it, to correct it, to opt out of sale or sharing (there is none), to limit the use of sensitive personal information, and to be free from discrimination for exercising any of them — we do not offer a worse price or a lesser app to anyone who does.

On limiting sensitive personal information: the only sensitive category here is the photograph, it is used solely to perform the service you asked for, and it is never used to infer characteristics about you. You can limit it completely and at any moment by withdrawing photo permission in the app, which stops scans being sent at all.

An authorised agent may make a request on your behalf; we will ask for proof of that authority. We answer within 45 days and will say so if we need the further 45 days the law allows.

Illinois — BIPA, and our retention and destruction schedule

Illinois requires a publicly available written retention schedule for biometric identifiers and biometric information, and a rule for destroying them. This is it, and it is deliberately shorter than the law's outer limit:

Washington and Nevada — consumer health data

Those states treat a facial photograph and a cosmetic skin score as consumer health data and require their own separate notice. It is here: Consumer Health Data Privacy Policy, and it is linked from our home page as the My Health My Data Act requires.

Texas, Virginia, Colorado, Connecticut, Oregon, Montana, Utah and the other comprehensive-law states

You have the right to confirm and access what we hold, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects — none of which we do. Where consent is required before processing sensitive data, including biometric data, we ask for it before the first photograph and not after.

Some of those states give you a right to appeal a refused request. Reply to our answer and we will reconsider it, tell you the outcome in writing, and give you your Attorney General's complaint address if we still say no.

Children

The app is not directed to children and we do not knowingly collect anything from anyone under 16, which is stricter than the 13 that US federal law sets. See the age section above.

How to exercise any of this

Write to support@skincareai.beauty. Most of it you can also do yourself in seconds: delete everything on the profile screen, and the photo-permission switch beside it.

Changes

This page changes when the app’s behaviour changes, and the date at the top records when. The app’s own “Where your data goes” screen is kept in step with it.