Biometric Data Policy
This page is about one thing: the data we derive from photographs of your face, how long each piece of it survives, and what destroys it. It is separate from our Privacy Policy on purpose. A retention promise buried in a long document is not a promise anyone can find.
What counts as biometric data here
When you buy an analysis you upload six photographs. From them we produce:
| What | What it is |
|---|---|
| Your photographs | The six original files, exactly as your phone took them |
| Working copies | Resized, colour-corrected and overlay versions we make in order to measure |
| Face geometry | 521 landmark points and a three-dimensional model fitted to them |
| Measurements | 181 biometric tests computed from that geometry, plus skin analysis |
| Identity signature | A short mathematical summary used only to check that a visualization still looks like you |
The first four are biometric data in the ordinary sense. The identity signature is the one people miss, so we name it: it is a template, we hold exactly one per analysis, and it is destroyed on the same clock as the geometry.
How long we keep each one
| # | What | How long | Counted from |
|---|---|---|---|
| 1 | Original photographs | 90 days | Publication of your report |
| 2 | Working copies and overlays | 90 days | Publication of your report |
| 3 | Face geometry, 3D model, stage checkpoints, identity signature | 30 days | Publication of your report |
| 4 | Uploads still being virus-scanned | 24 hours | Upload |
| 5 | Measurements — numbers, not pictures | Until you delete your account | — |
There is one more clock that people do not expect, and it is in your favour: if you do not log in for 24 months and have no active subscription, we write to you, wait 30 days, and then erase the account entirely. We would rather delete a dormant account than hold biometric data nobody is using.
What actually destroys it
A retention period without a mechanism is a wish. Ours has four parts, and each one is separately checkable:
- A lifecycle rule on the object store. The storage system itself expires the objects, on its own schedule, without anything in our application asking it to.
- A sweeper job. It runs nightly, looks for anything older than its period, and destroys it. This is the belt to the lifecycle rule's braces: if the rule were misconfigured, the sweeper still catches it.
- A nightly assertion. A separate job counts objects older than their retention period and expects zero. A non-zero count is treated as an incident, not as a log line.
- Key destruction for backups. We cannot rewrite an encrypted backup archive to remove one person's files, and anyone who says they can is either lying or destroying the integrity of their backups. What we can do is destroy the encryption key that belongs only to you, after which every copy of your media in every backup is unrecoverable noise. We record the key identifier and the moment it was destroyed, and that record is the evidence — for you, for a supervisory authority, and for us.
Deleting it yourself, before the clock runs out
You do not have to wait. In your privacy settings you can ask for three different things, and they are genuinely different:
- My photographs — the images and their working copies go, the measurements stay, your report stays readable.
- All biometric data — the images, the geometry and the identity signature go. This also withdraws your Article 9(2)(a) consent, so we cannot analyse anything further without asking you again.
- Everything — the account and all of it.
Deletion is a tracked job, not a button that hides a row. Every system that could hold a copy — the database, each storage bucket, the search index, the logs, the error tracker, the backups — is a separate target that must report completion, and the request cannot be marked complete while any target is outstanding. When it finishes we email you a receipt with a checksum you can keep.
What we never do with it
- We never sell, lease, trade or otherwise profit from it.
- We never disclose it to advertisers, data brokers, insurers or employers.
- We never send it to an outside AI service. Every stage of analysis runs on machines we own, and those machines have no route to the internet — that is a network configuration, tested on every build, not a policy.
- We never run face recognition against any external database. We hold no such database, we have integrated no such service, and we could not do it if we were asked to.
- We never use it to train a model unless you separately opt in, which is off by default, unbundled from your purchase, and revocable.
Who can open your images
Only a reviewer assigned to your analysis, and only through a viewer that requires them to state a reason, ties the grant to one task, and expires after 60 minutes. They see watermarked working copies, never your originals. Every access is recorded with the person, the reason and the time, and those records are reviewed weekly.
Changes to this policy
Every version of this page is kept, dated, and listed in the version history. If a change would extend how long we keep anything, we will ask for your consent again rather than treat silence as agreement.
Questions: dpo@beautyprivilege.com.