Legal

Privacy Policy

Version 2.4 — Effective September 14, 2026.

The Short Version

A summary, for orientation only. The numbered sections below are the policy, and they govern.

Your photos are never stored on our servers. Each one is held in memory for the seconds our AI providers need to score it, then discarded. The photos and scores you keep live on your device, and in your own iCloud or Google Drive if you switch on backup. On our servers we hold your email address, your subscription and consent records, your marketing preference, your scan counts, and your sign-in records — Section 3 lists them in full. You can export everything, delete any scan, or delete your account, from inside the app.

We never sell or rent your data. We never use your photos to train AI models, and our providers may not either. We never run advertising, ad cookies, or cross-site tracking. We never use your face to identify you, and we build no face-recognition template. We never use your skin tone to infer your race or ethnicity.

1. About This Service

Skin Intelligence is a cosmetic skincare guidance app. It is not a medical device and does not diagnose, treat, cure, monitor, or prevent any skin disease or condition. Skin scores reflect appearance metrics, and routine suggestions are advisory cosmetic guidance, not medical advice. Always consult a qualified healthcare provider for medical concerns.

2. Data Controller

The data controller responsible for your personal information is Skin Intelligence Inc., 329 Howe St #2031, Vancouver, BC V6C 3N2, Canada.

Our Privacy Officer, who is also our designated Data Protection Officer, handles every privacy inquiry and data request. The published business contact information is: Data Protection Officer, Skin Intelligence Inc. · privacy@skinintelligence.ai · +1 604 600 0360.

3. Data We Collect

Anything described below as stored on your device is also copied to your own iCloud or Google Drive if you switch on optional backup (Section 7); we never receive or access that copy.

Account Data: Your email address, collected when you create your account. The account information stored on Skin Intelligence servers is: your email address; your subscription details (plan, subscription status, and payment platform); your consent record (a history of each consent action you take — acceptances and withdrawals — with the version and date of each); your marketing-email preference (whether you have opted in, and when); your scan usage counters (how many scans you have used in the current period, kept to apply your plan limit and prevent abuse); and records of your sign-ins (including the network (IP) address each sign-in came from), kept by our authentication system for account security.

Profile Data: Your name, age range, gender, skin type, skin tone, and experience level. Your name, age range, gender, and experience level are provided by you. Your skin type and skin tone are detected from your scan photos by our AI providers as part of each scan and returned together with your skin scores; you can review and change them in the app at any time. Skin tone is a cosmetic shade indicator used only to personalise your routine — we do not use it to determine, infer, or record your race or ethnicity. Some privacy laws may treat skin-tone information as sensitive personal information, and we handle it on that basis: it is never sold and is never used for profiling or advertising. None of this information is stored on Skin Intelligence servers; it stays on your device. Some of these fields are briefly transmitted to our servers to perform a request you initiate. Your age range and gender accompany each scan, to improve accuracy. Your skin type, skin tone, experience level, your selected or score-derived focus areas, your weekly routine pace, and any ingredient swaps you have chosen are sent when you generate a routine, so the engine can build it. In both cases the data is held only in memory for the duration of the request, processed, and immediately discarded. Your name is never sent to Skin Intelligence servers.

Routine Filter Selections: Your Routine Preferences selections (such as Maternity & Nursing, Fragile or Sensitive, Recent Facial or Laser) are stored on your device only, and are never transmitted to or stored on Skin Intelligence servers. When you generate a routine, only the resulting list of excluded ingredient identifiers is sent to our servers; your underlying filter choices remain private to your device. These excluded ingredient identifiers are used solely to build your routine. They do not name any preference or reason, are held only in memory for the duration of the request, and are never logged or stored on our servers. We do not attempt to infer why an ingredient was excluded.

Scan Data: Facial images that you voluntarily capture through the app for cosmetic skin appearance analysis, along with the numerical skin scores generated from each scan. Your photos are never stored, logged, or retained on our servers — Section 5 sets out exactly how they are processed. The photos and scores you keep are stored on your device only. Facial images may be treated as biometric or sensitive data under some privacy laws. We use them solely to generate your cosmetic skin analysis results; we do not use them to identify or recognise you, we do not create or store a facial-recognition template or face embedding, and we do not use them for identity verification. We do not sell, lease, or trade your facial images or any biometric data, and we receive no money or other value in exchange for them.

Shelf Data: If you use the optional My Shelf feature, you may photograph cosmetic products you own. Your product photos are sent to our servers and read by an AI model (Google, via Google Cloud Vertex AI) to extract the product's brand, name, category, size, and ingredient list. The photos are used only for that read and are never stored on our servers. Your shelf itself — the products and photos you save — is stored on your device only. We do not keep the product details read from your photos on our servers. If you use Pick while signed in, your product photos are read in exactly the same way, under exactly the same rules, and the verdict is worked out on your device.

Device & Usage Data: Basic device information (device model, device type, and operating system version) and usage patterns (features used, steps completed within a feature, session duration) to improve the platform experience and to detect faults affecting particular devices. On our website and in the app, our hosting provider works out an approximate country from your connection and passes us only that country. We use it so that what you see matches where you are: subscription prices and web checkout, the app-store buttons we show, approximate converted prices for the products we link to, the cosmetic ingredient strength limits that apply in your country, and the regional availability limits described in Section 12.

4. How We Use Your Data

  • Account Management — To create and maintain your user account, using the account information listed in Section 3.
  • Skin Analysis — To generate your skin analysis results from the scan you take, as described in Section 5.
  • Routine Suggestions — To generate personalized cosmetic skincare routine recommendations based on your scores and preferences.
  • Trend Tracking — To show you how your skin metrics change over time. Your scores and photos stay on your device, and you can delete any scan at any time from within the app.
  • Product Analytics — To improve platform features using anonymous usage data (such as page views and anonymous counts of certain in-app actions, for example when a free scan is used) collected via PostHog, as described in Section 10. We do not collect, use, or sell your photos, your skin scores, or any personal data to train or improve any AI system, and our agreements prohibit our AI providers from using your data to train theirs. If we ever decide to train our own models on user data, we will ask for separate, explicit, opt-in consent first.
  • Marketing Communications — If you opt in, we use your email address to send you skincare tips, product updates, and promotional offers. Marketing emails are optional and sent only with your consent; you can withdraw consent at any time in your profile settings or via the unsubscribe link in any marketing email. This is separate from essential service messages (such as subscription renewal reminders, security notices, and changes to these terms), which we may send regardless of your marketing preference. We do not sell your email address or share it for third-party advertising.

Our Legal Basis: Where the law of your country requires us to have a legal basis for using your personal data, we rely on the following.

  • Performance of our contract with you — creating and running your account, generating your skin analysis results, building your routine, reading your product labels in My Shelf, and managing your subscription. Without this data we cannot provide the service you asked for.
  • Your consent — capturing and processing your facial images (and any skin-tone information that may be treated as sensitive), transferring your images to our AI providers in the United States, backing up your data to your own cloud storage, and sending you marketing emails. Each of these is a separate choice, and you can withdraw any of them at any time (see Section 8).
  • Our legitimate interests — keeping the Service secure, preventing fraud and abuse of the free-scan allowance, and improving the app using anonymous product analytics. We weigh these against your rights and freedoms, and you may object at any time (see Section 8).
  • Compliance with a legal obligation — keeping the records the law requires us to keep, and responding to lawful requests from authorities.

Automated Processing: Your skin scores are produced by AI models, and your routine is built by a rule-based engine from those scores and your preferences. These are cosmetic, advisory outputs only, and you decide what to do with them. They do not produce any legal or similarly significant effect concerning you: they do not affect your finances, employment, housing, insurance, education, healthcare, or access to any essential service. You stay in control of every result: you can re-take a scan, change your inputs, or delete any scan and its scores at any time in the app.

5. AI Partners

To generate your skin analysis results, your facial images are sent from your device to Skin Intelligence servers, which then transmit them to our AI providers for analysis:

  • OpenAI OpCo, LLC (United States)
  • Google, contracted through Google Cloud Canada Corporation, via Google Cloud Vertex AI (processed in the United States)

Your photos are transmitted to Skin Intelligence servers for transient processing only. Photos are held in server memory during analysis and are immediately discarded — they are never stored, logged, or retained on our servers. To improve analysis accuracy, your age range and gender are also included in the scan request. Our providers return only your scores, your detected skin type and skin tone, and brief written skin-appearance observations that are discarded once your scores are generated; your image is never returned.

Under our agreements with these providers, your facial images are never used for model training or fine-tuning and — apart from the subprocessors that operate these providers' own infrastructure — are never shared with any third party or used for any unrelated purpose, except for the child-safety reporting described below. Neither provider retains your facial images once your skin analysis results have been generated. With OpenAI we have executed zero-retention terms, so your images and the analysis request are not logged or retained for abuse monitoring or human review. Google is contractually barred from storing your image outside our account for longer than producing your result requires. In both cases an image is kept only where an automated child-safety scan flags it, or where a longer period is required by law (see below).

Both OpenAI and Google operate automated safety systems under their own policies that check images submitted to their services for child sexual abuse material (CSAM); we cannot disable these checks. United States federal law (18 U.S.C. § 2258A) requires these providers to report any such material they become aware of. In the unlikely event that a safety system flags an image, the AI provider may retain the image for manual review and report it to the National Center for Missing and Exploited Children (NCMEC), regardless of the retention terms described above. Skin Intelligence does not control this process and cannot prevent it.

For more information about how each provider handles data, you may review their privacy policies:

OpenAI — Enterprise PrivacyGoogle — Cloud Privacy Notice

6. Service Providers & Cross-Border Data Transfers

Your account data is stored by our hosting provider (Supabase) in Canada, and encrypted daily backup copies of that account data are stored with Google Cloud (Google LLC) in Canada and deleted automatically within 30 days (see Section 7). Most personal data (photos, scores, profile preferences) is stored on your device only and is never stored or retained on our servers; photos and certain profile fields transit our servers for transient processing per request, as described in Sections 3 and 5. Image processing by our AI partners involves data transfers to the following locations:

  • OpenAI — United States
  • Google — United States

Subscription and payment processing relies on additional US-based service providers. None of them receives your scan photos, skin scores, profile preferences, or any health-related information:

  • Stripe, Inc. (United States) — payment processing for web subscriptions. Receives your email address, account identifier, subscription plan, and payment metadata, and collects your payment-card details and billing address directly from you at checkout in order to process your payment.
  • RevenueCat, Inc. (United States) — subscription management for iOS and Android. Receives your account identifier, the product purchased, and subscription status, together with basic device information (such as device model, operating system version, and locale) collected by its software on your device, and the app store's purchase record for your subscription, in order to process and validate purchases. RevenueCat never receives your email address.
  • Apple Inc. and Google LLC — billing for subscriptions purchased through the Apple App Store or Google Play. The store processes your payment under its own terms and privacy policy.

Analytics and error monitoring rely on additional US-based service providers:

  • PostHog, Inc. (United States) — product analytics, as described in Section 10.
  • Vercel, Inc. (United States) — website traffic analytics (aggregate, cookie-free), as described in Section 10.
  • Sentry / Functional Software, Inc. (United States) — error monitoring, as described in Section 10.

Transactional email — such as sign-in codes and essential service messages — is delivered by Resend, Inc. (United States), which receives your email address solely to deliver these messages.

Your photos transit Skin Intelligence servers (hosted by Vercel, Inc. in the United States) before being forwarded to AI providers for analysis.

Every third party with whom we share your data is named here, apart from the subprocessors that operate our AI providers' own infrastructure (Section 5): OpenAI, Google (Vertex AI and Cloud Storage), Stripe, RevenueCat, Supabase, Vercel, PostHog, Sentry, and Resend. Each is contractually required to provide a comparable level of protection for your data as described in this Privacy Policy and as required by applicable law, and to use it only to provide services to us. If we add or replace one, we update this list and record the change in the version history of this policy.

International Transfers — What Leaves Your Country, and Why. If you live outside Canada and the United States, your personal data is transferred out of your country every time you use the Service. Specifically: your facial image, together with your age range and gender, goes to the United States for the seconds it takes our AI providers to generate your skin analysis results; your email address, subscription details, and consent record are stored in Canada; and the payment, subscription-management, analytics, error-monitoring, and email providers listed above are in the United States. Nothing else leaves your device unless you choose to back it up to your own iCloud or Google Drive account.

What We Rely On to Make Those Transfers. Two things, independently. First, your consent: before your first scan you are asked, as a separate item, to consent to your images being transferred to our AI providers in the United States, and you may withdraw it at any time in Profile → Privacy & Data. Second, the written agreements summarised below.

The United States' Data-Protection System, in Plain Terms. The United States has no single, comprehensive federal data protection law of the kind found in Canada, Japan, South Korea, Brazil, Singapore, or the European Union. Protection there comes from sector-specific federal laws, a growing number of individual state privacy laws, and the contracts a company signs. The United States has not been recognised as offering an equivalent or adequate standard of protection by the authorities of Japan, Georgia, or most other countries whose law asks that question. While your data is in the United States it may be accessed by US courts, law enforcement, and government or national-security authorities under US law, and the routes available to you to challenge that access or obtain a remedy may be weaker than those in your own country. We cannot control or prevent such access. These are the possible threats that come with the transfer.

The Protection Your Data Still Has There — a Written Summary. Our agreements with OpenAI and Google require them to: use your facial image solely to generate the skin analysis results you requested; never use it for model training or fine-tuning; retain nothing once those results are generated (the zero-retention and no-storage terms are set out in Section 5); not disclose it to anyone other than the subprocessors operating their own infrastructure; apply security measures appropriate to the data; and support us in answering your requests. Stripe, RevenueCat, Supabase, Vercel, PostHog, Sentry, and Resend are bound by equivalent written commitments covering the limited data each receives, which never includes your scan photos or skin scores. Taken together, these obligations are intended to give your personal data a standard of protection comparable to the protection it has under the law of your own country, and we review them if that ceases to be so. The one exception we cannot contract away is the automated child-safety scanning described in Section 5.

7. Data Retention & Deletion

How long we keep things, at a glance:

  • Scan photos and scores — on your device until you delete them; never stored on our servers.
  • Account data (email, subscription, consent record) — for as long as your account is active, then deleted 30 days after you ask us to delete it.
  • Our encrypted daily backups of account data — 30 days.
  • Our hosting provider's backups — approximately 7 days.
  • Technical error reports — 90 days.
  • Incomplete signups, which hold only your email address — 30 days.
  • A scrambled (hashed) email address, kept only to prevent free-scan abuse — up to 24 months.

Device Data — You can delete individual scans or all scan data at any time from within the app. If you uninstall the app or clear app data, your scan photos and scores are permanently removed from your device, and Skin Intelligence cannot recover them on your behalf.

Server Data — For as long as your account is active, we store on our servers the account information listed in Section 3 (Account Data). We also keep an internal change log of those account fields, recording which field changed, its previous and new values, when, and who made the change, to maintain the accuracy and security of your account; it contains no email address and is deleted together with your account. Our encrypted daily backup copies of this server data are stored with Google Cloud in Canada, for disaster recovery only.

Analytics & Error-Report Data — The product-analytics events (PostHog) and technical error reports (Sentry) described in Section 10 are retained only for as long as needed for product analytics and error monitoring. Because these records are not linked to your name, email, or account, we cannot single out which are yours, so they are not affected by an account-deletion request and are not returned in response to a data-access request.

AI Provider Data — Our AI providers retain nothing once your skin analysis results are generated; their obligations, and the single child-safety exception, are set out in Section 5. We cannot retrieve or reproduce any photo after the analysis request completes.

Biometric Data — We retain no facial image or biometric identifier on our servers. Facial images you choose to keep are stored on your device until you delete them, and deleting your account also attempts to remove the cloud backup copy. On-device facial-landmark data used to frame your photo is never transmitted or stored.

Account Deletion — Upon receiving your account deletion request, your account will be immediately deactivated. You may log back in within 30 days to cancel the deletion. After 30 days, your account data (email, subscription information) will be permanently deleted from our active systems. Residual copies in encrypted backups are removed in the normal backup rotation, and are never used to restore a deleted account except as part of a disaster recovery. The one thing we keep is a one-way scrambled (hashed) version of your email address, retained for up to 24 months solely to recognise if the same email is used to claim free scans again. It cannot be reversed or used to contact you, and it is the only item not erased in response to a deletion request — an exception the law expressly allows for preventing fraud and abuse (for California residents, Cal. Civ. Code § 1798.105(d)). Third-party records held by our payment and subscription processors (Stripe, Apple, Google, and RevenueCat) are subject to those providers' own retention policies. When you delete your account, the scan photos and scores stored on this device are also deleted immediately, and we attempt to remove any cloud backup from your personal iCloud or Google Drive.

Cloud Backup — You may optionally back up your data to your personal iCloud or Google Drive account. Your backup includes your scan photos and scores, your profile details (name, age range, gender, skin type, and skin tone), your My Shelf products, your My Calendar history, and your routine and app settings, together with a copy of your account details (such as your email, plan, subscription status, your latest consent acceptance — its date and version — and marketing preference). When you enable this feature, your data transfers directly from your device to your own cloud storage. Skin Intelligence does not receive, access, or store your backup data. Your backup is governed by Apple's or Google's privacy policies and your own cloud storage settings. When you delete your Skin Intelligence account, we attempt to remove the backup from your personal iCloud or Google Drive; you should also verify it has been removed from your own cloud storage settings.

8. Your Rights

Depending on where you live, you may have the following rights.

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate or incomplete data.
  • Deletion — Request deletion of your personal data and account.
  • Portability — Request your data in a structured, commonly used, machine-readable format.
  • Withdraw Consent — Withdraw previously given consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Object — Object at any time to processing based on our legitimate interests, including our product analytics. Because our analytics events are not linked to your name, email, or account, we cannot identify or delete your past events, and an objection to analytics takes effect going forward.
  • Complain — Lodge a complaint with your local data protection authority.

Self-Serve Export: You can download a copy of your personal data directly from the app at any time. Open Profile → Backup & Restore → Export File to download a ZIP archive containing your account information (email, plan, subscription status, marketing preferences, and your consent record — the date you accepted and the version of the terms/consent you accepted), your profile details, your on-device preferences and routine selections, your My Shelf products and My Calendar history, your scan metadata and skin scores, and your scan photos. The archive uses standard JSON and image formats (JPEG, and on some Apple devices HEIC) and can be opened on most devices.

To exercise any other rights, or if you have questions, contact us at privacy@skinintelligence.ai. Response timelines depend on where you live — see Section 13 (U.S. state residents: within 45 days) and Section 14 (Canadian residents). You may also complain directly to us at the same address: we will acknowledge your complaint within 30 days and respond without undue delay.

9. Security

We protect your personal data with technical and organizational measures:

  • Encryption of data in transit (TLS) and at rest. Server-side account data is encrypted at rest by our hosting provider (Supabase). Device-stored data (photos, scores, profile preferences) is protected by operating system-level encryption (iOS Data Protection, Android file-based encryption).
  • Role-based access controls limiting data access to authorized personnel.

Reporting a Security Problem — If you believe you have found a vulnerability in our app, website, or API, email support@skinintelligence.ai with the subject "Security". We will acknowledge your report and investigate it. We will not bring a claim against you, or refer you for prosecution, for good-faith research that stays within our own app, website, and API, does not access, change, or delete anyone else's data, does not degrade the service, and gives us a reasonable chance to fix the problem before you make it public.

Government & Law-Enforcement Requests — If an authority asks us for your data, we require valid legal process, we push back on requests that are overbroad or improper, we disclose no more than the request compels, and we tell you where the law permits us to. Because your photos, scores, and preferences never rest on our servers, there is very little for us to produce.

Data Breaches — If a personal data breach is likely to result in a risk to your rights, we will act without undue delay. For Canadian users, where a breach creates a real risk of significant harm we will report it to the Office of the Privacy Commissioner of Canada — and, for Alberta residents, to the Office of the Information and Privacy Commissioner of Alberta — and notify affected individuals as soon as feasible. For US residents, we will notify you and the relevant state authorities of any breach of your personal information as required by your state's data-breach notification law. If you live elsewhere, we will notify you and your national data protection authority where your country's law requires it, within the time that law sets.

10. Cookies, Local Storage & Analytics

This platform uses local storage to maintain your session state and preferences (such as dark mode). On web, this is browser localStorage. On mobile apps, session data is stored in the app's internal storage.

Product Analytics: We use PostHog (PostHog, Inc., United States) for first-party product analytics that are not linked to your name, email, or account (such as page views and counts of certain in-app actions, for example when a free scan is used) so we can improve the app. We do not send your name, email, scan photos, or device-stored data to PostHog, and we do not create identified analytics profiles. PostHog may use your IP address to derive an approximate location — your country and region (state or province) only — after which the IP address itself is discarded and not stored; it is not used to identify you, and session recording is disabled.

Website Analytics: On our website only, we use Vercel Web Analytics (Vercel, Inc., United States) to measure aggregate traffic — such as page views, referring sites, and visitor country/region. It is cookie-free and uses no cross-site tracking or persistent identifiers; visitors are counted using a temporary daily hash of connection details that resets each day and cannot identify you or follow you across sites or over time. Your IP address is not stored.

Error Monitoring: We use Sentry (Functional Software, Inc., United States) to detect and investigate technical errors. When an error occurs, technical metadata such as the error type, stack trace, request method, and HTTP status code is transmitted to Sentry, along with limited technical detail about the failure (for example, a truncated error message returned by a processing step). We configure our error reports to exclude scan photos, scan scores, profile data, payment information, and email addresses; error messages are truncated and are not used to identify you. Session replay is disabled.

We do not use advertising cookies, cross-site tracking, or sell data.

11. Children's Privacy

This platform is intended for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18.

If we discover that we have collected data from a user under 18, we will promptly delete their account and associated data.

12. Service Availability — Illinois, Washington & Quebec Residents

Skin Intelligence is not available to residents of the State of Illinois, the State of Washington, or the province of Quebec. We restrict access from IP addresses in all three, and by agreeing to our Terms you represent that you are not a resident of any of them. These measures reduce but cannot entirely eliminate access — for example, where IP location is unavailable or circumvented. If you are a resident of one of these places, please do not create an account or attempt to use the platform. If we identify an account as belonging to a resident of one of them, we will deactivate it and delete the associated data in accordance with Section 7.

Illinois — We do not knowingly offer the service to, collect personal information from, or process biometric identifiers or biometric information of Illinois residents. Beyond the sign-in restriction, every scan is re-checked on our servers at the moment you take it and is refused before any image is read or analyzed if it comes from a blocked location, so a blocked-location scan is stopped before any analysis, not only at login.

Quebec — Skin Intelligence is offered in English only.

13. U.S. State Privacy Rights

Depending on your state of residence, you may have additional privacy rights under state law.

California (CCPA/CPRA)

If you are a California resident, then to the extent the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to us, you have the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected.
  • Right to Delete: Request deletion of your personal information, subject to the exceptions permitted by Cal. Civ. Code § 1798.105(d) (for example, the scrambled email value we keep for up to 24 months to prevent free-scan abuse, as described in Section 7).
  • Right to Correct: Request correction of inaccurate personal information.
  • No Sale of Data: We do not sell your personal information to third parties.
  • No Sharing for Cross-Context Behavioral Advertising: We do not share your personal information for cross-context behavioral advertising.

Sensitive Personal Information: Under CPRA, your facial images — and, to the extent it may be considered information relating to racial or ethnic origin, your skin-tone classification — may be treated as Sensitive Personal Information, and we handle them on that basis. Both are stored on your device only, and both transit our servers in memory only, for the single request you initiate, as described in Sections 5 and 7. We process them solely to provide the cosmetic skin-analysis and routine you request, and for no other purpose — never to infer characteristics about you, and never for profiling, advertising, enrichment, or AI-model training. We do not sell them. You can delete your photos at any time, individually or in bulk, from within the app.

California — Additional Disclosures: We do not discriminate against you for exercising your privacy rights. We do not track you across third-party websites and do not respond to Do Not Track signals because we do not perform such tracking.

Texas (TDPSA)

If you are a Texas resident, the Texas Data Privacy and Security Act provides you with rights to access, correct, delete, and obtain a copy of your personal data. You may also opt out of the processing of personal data for targeted advertising. Your facial images may be treated as sensitive data under the TDPSA; where they are, we obtain your consent before processing, and we handle them as described in Sections 5 and 7.

Texas also regulates biometric identifiers under the Capture or Use of Biometric Identifier Act (CUBI, Tex. Bus. & Com. Code § 503.001). As that law requires, we inform you and obtain your consent in the app before any facial image is captured, and we retain no biometric identifier after the analysis completes. We never sell or lease your facial images, and we do not disclose them to anyone other than the AI processing providers acting on our behalf to perform the analysis you request, under contracts that prohibit any other use. Our separate Biometric Data Policy sets this out in full.

Virginia (CDPA)

If you are a Virginia resident, the Virginia Consumer Data Protection Act provides you with rights to access, correct, delete, and obtain a copy of your personal data. You may appeal a denied request by contacting us at privacy@skinintelligence.ai.

Colorado (CPA)

If you are a Colorado resident, the Colorado Privacy Act provides you with rights to access, correct, delete, and opt out of targeted advertising or the sale of personal data. Biometric data is classified as sensitive data requiring your consent. You may appeal a denied request by contacting us at privacy@skinintelligence.ai.

Colorado Biometric Identifier Notice: Colorado law (HB 24-1130, codified at C.R.S. § 6-1-1314) requires that we tell you, before collection, the following — the facial images you capture may be treated as biometric identifiers; they are collected for the sole purpose of generating your cosmetic skin-appearance scores; they are disclosed only to our AI processing providers (OpenAI and Google), and only to perform the analysis you request; and they are not retained — photos are processed in server memory and immediately discarded, and the copies you keep stay on your device (and in your own cloud backup, if you enable it — see Section 7) until you delete them. We obtain your consent in the app before your first scan, and we never sell biometric identifiers or use them to identify you. Our separate Biometric Data Policy — available from the Privacy & Data screen (Profile → Privacy & Data) and the footer of our website — sets out our biometric retention schedule, deletion practices, and data-security-incident response in full.

Connecticut (CTDPA)

If you are a Connecticut resident, the Connecticut Data Privacy Act (as amended) gives you the right to confirm whether we are processing your personal data and to access it, to correct it, to delete it, and to obtain a portable copy of it. Because your facial images are treated as biometric data, Connecticut law does not allow us to release the images themselves in response to an access request — instead, we will confirm that we collected them and tell you how they were used. We process your facial images, and any skin-tone information that may be considered sensitive data, only with your opt-in consent and only where reasonably necessary to provide the cosmetic skin-analysis you request. We do not sell personal data, we do not process it for targeted advertising, and we do not profile you in a way that produces legal or similarly significant effects — so there is nothing for you to opt out of, and no list of third parties to which we have sold your data, because there are none. We will respond to a request within 45 days (extendable once by a further 45 days where reasonably necessary). If we decline your request, you may appeal by emailing privacy@skinintelligence.ai with the subject "Privacy Appeal"; we will respond within 60 days, after which you may contact the Connecticut Attorney General (portal.ct.gov/ag).

Nevada (Consumer Health Data)

If you are a Nevada resident, your facial images and skin-appearance scores may be "consumer health data" under the Nevada Consumer Health Data Privacy Law (SB 370). How we collect, use, share, store, and delete that data, and the rights you have over it, are described in our separate Consumer Health Data Privacy Policy, which you can open from the Privacy & Data screen (Profile → Privacy & Data) and from the footer of our website. Skin Intelligence is not available in Washington (see Section 12); should that change, that policy also gives effect to the Washington My Health My Data Act.

Other States

If you reside in any other US state with a comprehensive consumer privacy law, you have the rights described above to the extent that law applies to us. We do not sell your personal data or sensitive data, and we do not process it for targeted advertising, in any US state — so there is no sale, sharing, or targeted advertising for a Global Privacy Control (GPC) signal to opt you out of: you are treated as opted out by default, because there is nothing to opt out of. We process facial images, and any skin-tone information that may be considered sensitive data, only with your opt-in consent and only where strictly necessary to provide the service; we do not use skin tone to infer your race or ethnicity. Maryland residents: we collect facial images and skin-tone information only where strictly necessary and never sell sensitive data.

To exercise any of your U.S. state privacy rights, contact us at privacy@skinintelligence.ai. You do not need an account to make a request, and we will not charge you for it. We will respond within 45 days of receiving your request; where reasonably necessary we may extend this once by a further 45 days and will tell you if we do. You may also designate an authorized agent to submit a request on your behalf — we may ask the agent for proof of your written permission and may ask you to verify your identity. If we decline your request, you may appeal by emailing privacy@skinintelligence.ai with the subject "Privacy Appeal"; we will respond within 45 days, after which, if your appeal is denied, you may contact your state Attorney General. This appeal right applies in every US state whose law provides one, including Texas.

14. Canadian Residents (PIPEDA, BC PIPA, Alberta PIPA)

Skin Intelligence Inc. is a federal corporation incorporated under the Canada Business Corporations Act, with its registered office in British Columbia, and your account data is hosted in Canada. The person responsible for the protection of personal information is our Privacy Officer (privacy@skinintelligence.ai), who is the designated responsible person under the Canadian privacy regimes.

You may access, correct, and obtain a portable copy of your personal information (Profile → Backup & Restore → Export File), and you may withdraw your consent at any time.

Some of your personal information is processed by our service providers outside Canada, in the United States: your scan photos are processed there transiently by our AI providers (OpenAI and Google) to generate your skin analysis results, and your email, subscription, analytics, and error-monitoring data are handled by the US-based providers listed in Sections 5 and 6. These transfers are governed by written agreements requiring a comparable level of protection. While your information is outside Canada, it may be subject to access by the courts, law enforcement, and national-security authorities of that jurisdiction. Our policies and practices for using service providers outside Canada are described in this Privacy Policy (see Sections 5 and 6) and are available on request. If you have any questions about the collection, use, disclosure, or storage of your personal information by our service providers outside Canada, you may contact our Privacy Officer at privacy@skinintelligence.ai.

In line with our accountability obligations, we have conducted and maintain an internal Privacy Impact Assessment of the platform under PIPEDA. This assessment is reviewed whenever our processing changes materially and is available to privacy regulators on request.

You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). British Columbia residents may also complain to the Office of the Information and Privacy Commissioner for BC, and Alberta residents to the Office of the Information and Privacy Commissioner of Alberta.

15. Other Countries — Region-Specific Information

This section adds the information particular countries require. Everything in it supplements — and does not replace — the rest of this policy, and in particular Section 6, which describes every transfer we make and what protects your data during it.

Japan (APPI)

The country to which your personal data is transferred is the United States. The recipients are OpenAI OpCo, LLC, established in the United States, and Google, with whom we contract through Google Cloud Canada Corporation and which processes your image on Google infrastructure located in the United States. The personal information protection system of that country is described in Section 6 ("The United States' Data-Protection System, in Plain Terms") — in short, the United States has no comprehensive federal data protection law, and it is not designated by the Personal Information Protection Commission as a country with an equivalent standard of protection. The measures the recipients take to protect your personal data are described in Section 6 ("The Protection Your Data Still Has There"). We give you this information before you consent, and we obtain your consent to the transfer before your first scan.

South Korea (PIPA)

We entrust the processing of your personal data abroad in order to perform our contract with you, and disclose the prescribed matters here. (1) The personal data transferred: your facial image, together with your age range and gender. (2) The country, date, and method of transfer: the United States, at the moment you take each scan, transmitted over an encrypted internet connection. (3) The recipients and their contact details: OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, United States — Data Protection Officer, privacy@openai.com; and Google, contracted through Google Cloud Canada Corporation, which processes your image on Google infrastructure in the United States — privacy requests through the contact route published in Google's privacy policy at policies.google.com. (4) The recipients' purpose of use and retention period: generating your cosmetic skin scores, retained no longer than that single request takes — zero retention, as described in Section 5. (5) How to refuse, and what happens if you do: you may refuse by not accepting the image-transfer item on our consent screen, or by withdrawing that consent later in Profile → Privacy & Data. You keep your account and everything already on your device; skin scanning cannot be provided without the transfer.

Georgia

The United States, where your facial image is processed, does not provide the data-protection safeguards required by Georgian law, and no adequacy or equivalent recognition applies to it. The possible threats that follow are set out in Section 6: access by US courts, law enforcement, and government or national-security authorities, and routes to challenge that access or obtain a remedy that may be weaker than those available to you in Georgia. Your consent to the transfer is the basis on which we make it. You give that consent in written electronic form, by ticking the separate image-transfer item on our consent screen after this information has been shown to you, and we keep a written record of it — the wording you accepted, its version, and the date and time. You may withdraw it at any time in Profile → Privacy & Data.

Singapore and Brunei Darussalam

The two paragraphs in Section 6 headed "The United States' Data-Protection System, in Plain Terms" and "The Protection Your Data Still Has There — a Written Summary" together form the written summary, required by Singapore's Personal Data Protection Act and Brunei Darussalam's Personal Data Protection Order, of the extent to which your personal data transferred out of those countries will be protected to a standard comparable to the protection it has under those laws. The business contact information of the individual we have designated under both laws is published in Section 2.

India (DPDP Act)

This Privacy Policy and our consent notice are published in English. You have the option to receive their contents in any of the languages listed in the Eighth Schedule to the Constitution of India: email privacy@skinintelligence.ai naming the language you want, and we will send you that version free of charge, normally within seven days. Translations are prepared so that you can understand the notice, and we correct any error you report to us. You may withdraw your consent at any time in Profile → Privacy & Data, with the same ease as you gave it. If you have a grievance, write to our Privacy Officer at the same address and we will respond within the period the Act and its Rules require, after which you may complain to the Data Protection Board of India.

Brazil (LGPD)

Your facial image is sensitive personal data, and we process it and transfer it internationally on the basis of your consent, which is asked for specifically and separately from every other purpose, after you are told that the transfer is international and where it goes (see Section 6). We never use it for any purpose other than generating the skin scores you requested. You may withdraw that consent at any time in Profile → Privacy & Data. You may complain to the Autoridade Nacional de Proteção de Dados (gov.br/anpd).

Australia, Hong Kong SAR, Kenya, Kuwait, Namibia, Trinidad and Tobago, Ukraine, the United Arab Emirates, and Jordan

The rights set out in Section 8, the transfer information in Section 6, and the contact details in Section 2 apply to you in full. You may also complain to your national privacy authority — in Australia the Office of the Australian Information Commissioner, in Hong Kong the Privacy Commissioner for Personal Data, in Kenya the Office of the Data Protection Commissioner, in Ukraine the Ombudsperson, in the United Arab Emirates the UAE Data Office, and in Jordan the Personal Data Protection Unit.

16. Changes & Contact

We may update this Privacy Policy from time to time. If we make material changes, we will notify you within the app and request your re-acceptance before you continue using the scan feature. When we do, the version you previously accepted stays available to read in the app, so you can see exactly what changed.

Skin Intelligence Inc. 329 Howe St #2031, Vancouver, BC V6C 3N2, Canada Email: privacy@skinintelligence.ai