PRIVACY POLICY
- Download and use
our mobile application ( Beauty Ally) , or any other application of ours that links to this Privacy Notice
- Use
Beauty Ally .Beauty Ally helps you evaluate whether a cosmetic product may suit your skin preferences. Sign in via Apple/Google (OAuth through Clerk) and optionally provide a basic skin profile (skin type, sensitivities, skin concerns, skincare actives currently used, a user-selected climate category, and whether you use SPF). When you upload front/back photos of a product, we use OCR and an AI service to extract the product name and ingredients and generate an informational suitability summary and tips. We store photos in private cloud storage and your profile/results in our database, protected by row-level access controls so only you can access your data. Not a medical device; no medical advice.
- Engage with us in other related ways, including any sales, marketing, or events
SUMMARY OF KEY POINTS
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
How we’ll notify you of changes. We will post any updates on this page and update the “Last updated” date. If we make material changes — for example, collecting new types of data, using data for new purposes, sharing with new third parties, changing retention, or making new cross‑border transfers — we will provide a prominent in‑app notice and, where available, send an email before the changes take effect. If a change requires consent, we will request it again.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.- To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
- To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
- To send administrative information to you. We may process your information to send you details about our products and services, changes to our terms and policies, and other similar information.
- To
fulfill and manage your orders. We may process your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.
- To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
Account authentication & access control .Create and manage your account via Clerk and Apple/Google OAuth (name, email, OAuth identifier) to keep your session secure and allow access to the service.
Subscription activation & entitlements .We receive purchase receipts/tokens or subscription status from Apple App Store or Google Play to activate/renew your plan and manage your scan allowances. Payments are processed by Apple/Google; we do not receive your full card details or billing address.
Security & abuse prevention .Use limited IP/service logs and abuse signals to detect, prevent, and respond to fraud, spam, and misuse; protect accounts; and ensure availability. Data is minimized and retained up to 30 days.
Service quality & diagnostics .Aggregate crash and performance metrics to debug issues and improve stability. No advertising, cross-site tracking, or behavioral profiling.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e.- Consent. We may process your information if you have given us permission (i.e.
, consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal information when we believe it is necessary to
fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
Analyze how our Services are used so we can improve them to engage and retain users
- Diagnose problems and/or prevent fraudulent activities
Keep Beauty Ally secure and reliable for all users.
Improve and maintain core functionality.
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
- For identifying injured, ill, or deceased persons and communicating with next of kin
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
- If the collection is solely for journalistic, artistic, or literary purposes
- If the information is publicly available and is specified by the regulations
- We may disclose de-identified information for approved research or statistics projects, subject to ethics oversight and confidentiality commitments
- AI Service Providers
- Cloud Computing Services
- Invoice and Billing
- User Account Registration and Authentication
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
5. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.AI predictive analytics
Log in to your account settings and update your user account
Contact us using the contact information provided
Profile → Privacy: toggle off “Skin-data processing.” This withdraws consent for OCR/AI analysis of your photos and skin profile; we stop future processing and delete queued/processed images and results from active systems, with backups purged within ~30 days. Product scanning won’t work without this consent. You can also delete your account anytime in Profile → Delete Account & Data.
7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own.8. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to9. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of10. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 13 years of age (or the minimum age of digital consent in your country). Individuals under the age of majority may use the Services only with a parent or guardian’s permission11. WHAT ARE YOUR PRIVACY RIGHTS?
In Short:Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:Log in to your account settings and update your user account.
Contact us using the contact information provided.
Profile → Delete Account & Data. This permanently deletes your profile, scan history, uploaded photos, OCR text, and results from our active systems. Deletion is immediate in active systems; encrypted disaster-recovery backups are overwritten on a rolling schedule and typically purge within 30 days.
Note: Deleting your Beauty Ally account (Clerk) doesn’t delete your Apple/Google accounts. Manage those with Apple/Google. Active subscriptions must be canceled in App Store or Google Play settings.
12. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident ofCategories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you. For a comprehensive inventory of all personal information we process, please refer to the sectionCategory | Examples | Collected |
---|---|---|
A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name |
B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information |
Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | ||
Transaction information, purchase history, financial details, and payment information | ||
Fingerprints and voiceprints | ||
Browsing history, search history, online | ||
Device location | ||
Images and audio, video or call recordings created in connection with our business activities | ||
Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us | ||
Student records and directory information | ||
Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics | ||
- Receiving help through our customer support channels;
- Participation in customer surveys or contests; and
- Facilitation in the delivery of our Services and to respond to your inquiries.
- Category A -
As long as the user has an account with us
- Category B -
As long as the user has an account with us
- Category
C - As long as the user has an account with us
- Category
D - As long as the user has an account with us
- Category
H - Scan photos and profile images are stored in private S3 buckets. Users can delete them anytime; deletion is immediate in active systems and backup copies purge within 30 days.
- Category
K - Used to generate skincare suitability insights and personalized matches. Not sold or shared with third parties; only processed by contracted service providers (e.g., OCR/AI) on our behalf. Users can disable future AI processing in Settings and may delete their account/data at any time. When deleted, related inferences are removed from active systems; encrypted backups purge on a rolling schedule (typically within 30 days).
- Category
L - As long as the user has an account with us
Sources of Personal Information
Learn more about the sources of personal information we collect inHow We Use and Share Personal Information
- Category A. Identifiers
- Category B. Personal information as defined in the California Customer Records law
- Category
C . Characteristics of protected classifications under state or federal law
- Category
D . Commercial information
- Category
H . Audio, electronic, visual, and similar information
- Category
L . Sensitive personal information
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data if it is used for targeted advertising
(or sharing as defined under California’s privacy law) , the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ( "profiling" )
- Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota)
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in
California, Delaware, and Maryland )
- Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in
Minnesota and Oregon )
- Right to review, understand, question, and correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Minnesota)
- Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California)
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida)
How to Exercise Your Rights
To exercise these rights, you can contact usRequest Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us atCalifornia "Shine The Light" Law
California Civil Code Section 1798.83, also known as the 14. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Representative
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/17485494389
GDPR-Rep certificate of representation
powered by Prighter
6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
In Short: We offer sign‑in with Apple and Google only.
If you choose to register or log in using Apple or Google (through our identity provider, Clerk), we receive certain limited profile information from that provider—typically your name, email address, and, if you allow it, a profile picture. We use this information to create and manage your account and to facilitate sign‑in.
We do not receive your contact lists, friends, or other data from these providers, and we do not post to your social accounts on your behalf. What information we receive depends on the settings you choose with Apple or Google. You can learn more and control what you share in your Apple ID or Google Account settings.