Beauty Privilege
  • Pricing
  • Methodology
  • About us
  • Contact

Privacy Policy

Version 1.0 · effective 2026-09-01 · version history

This policy explains what we collect, why, who sees it, how long we keep it, and what you can do about it. It is written to be read. If anything here is unclear, email dpo@beautyprivilege.com and we will fix the wording.

The short version. You send us six photographs of your face. We measure them, a person reviews the result, and we send you a report. We destroy your photographs 90 days after your report is ready. We do not sell your data. We do not share it with advertisers. We do not send it to any outside AI service. The only outside company involved at all is Stripe, who takes your payment.


1. Who we are

Quentin Aoustin, entrepreneur individuel, 45 B rue de la Ganache, 44550 Saint-Malo-de-Guersac, France (SIREN 898 608 146). We are the controller of your personal data — a single French business, with no joint-controller arrangement and no second company.

  • Data Protection Officer: dpo@beautyprivilege.com
  • Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), France. You may lodge a complaint with the CNIL, or with the authority where you live or work
  • Where we operate: the European Union, Norway, Iceland and Liechtenstein — and nowhere else
  • Postal: as above

2. The most important part: your photographs and your face data

When you buy an analysis, you upload six photographs of your face. From those we create:

  • a scan of your face geometry — 521 landmark points and a three-dimensional model of your face;
  • 181 biometric tests derived from that geometry;
  • skin analysis results;
  • a short mathematical identity signature we use only to check that our visualizations still look like you.

In law, all of this is biometric data. It is special category data under Article 9 of the GDPR, processed for the purpose of uniquely identifying nothing at all — only of measuring your own face for you. We treat it as the most sensitive thing we hold, because it is.

What we use it for: producing your analysis, your report, your plan and your visualizations. That is the entire list.

How long we keep it — and this is a promise with a mechanism behind it:

WhatHow long
Your original photographs90 days after your report is published, then permanently destroyed
Resized copies and overlays we make from them90 days, same
Your face geometry, 3D model and identity signature30 days after your report is published, then permanently destroyed
Your measurements (numbers, not pictures)Until you delete your account

Destruction is automatic. It happens whether or not you ask, whether or not you are still a customer, and whether or not you remember this policy exists. A separate job checks every night that it actually happened, and we treat a failure as an incident.

Our full biometric data retention and destruction policy is published separately at /legal/biometric-data.

What we will never do with it:

  • We will never sell, lease, trade or otherwise profit from your biometric data.
  • We will never share it with advertisers, data brokers, insurers, employers, or anyone else.
  • We will never send it to an outside AI service. Every piece of analysis runs on computers we own. The machines that do it have no route to the internet.
  • We will never use it to identify you anywhere else, or to search for you, or to match you against any other database. We have no such capability and we have not built one.
  • We will never use it to train our models unless you separately, specifically opt in — and that choice is off unless you turn it on.

Who looks at your face. A trained human reviewer checks every report before you see it. They see a resized, watermarked copy — never your original files. They can only open your images through a system that requires them to state a reason, ties the access to a specific task, and expires after 60 minutes. Every single time anyone opens your images, it is recorded with their name, the reason and the time. We review those records every week.

3. Everything else we collect

WhatWhyHow long
Name, email, password, language, time zoneYour accountWhile you have an account, then 24 months
Payment detailsTaking payment. Card numbers go straight to Stripe — we never see themStripe holds these; we keep invoices 7 years for tax
Your answers about goals, routine, lifestyle and budgetMaking the plan fit your lifeWhile you have an account
Your answers about health, medication, allergies and pregnancyChecking that nothing we recommend is unsafe for youWhile you have an account
Your answers to the wellbeing questionsMaking sure this product is right for you, and stopping if it is not3 years, or until you delete your account
Your self-declared ancestry, sex and date of birthComparing you against a relevant reference group, and confirming you are 18 or overWhile you have an account
Messages you send our care teamAnswering you3 years after the conversation ends
IP address, browser, device, pages viewedSecurity, fraud prevention, and making the product betterLogs 30 days; analytics 25 months, with your identifier removed after 90 days

About the wellbeing questions. Before we analyze anything, we ask a short set of standard clinical screening questions. If your answers suggest that appearance concerns are taking up a lot of your time and causing you real distress, we stop, we refund you in full, and we point you toward people who can actually help. We do this because the evidence is clear that cosmetic assessment does not help in that situation and can make it worse. Those answers are the most restricted data in our system. They are never used for marketing, ever, and anyone who screens positive is permanently removed from every marketing list we have.

Things we deliberately do not collect: your precise location, your contacts, your advertising identifiers, video of you, or anything about you from any other company.

4. Why we are allowed to do this

What we doOur legal basisFor special category data
Run your account, take payment, deliver your analysisPerformance of our contract with you — Art. 6(1)(b)—
Process your photographs and face geometryContract — Art. 6(1)(b)Your explicit consent — Art. 9(2)(a)
Health and wellbeing screeningContract and our legal duty to sell safely — Art. 6(1)(b), 6(1)(c)Your explicit consent — Art. 9(2)(a), and in an emergency, protecting someone's vital interests — Art. 9(2)(c)
Keep tax recordsLegal obligation — Art. 6(1)(c)—
Security and fraud preventionOur legitimate interests — Art. 6(1)(f)—
Research and model evaluationYour consent — Art. 6(1)(a)Your separate explicit consent — Art. 9(2)(a)
Marketing emailYour consent — Art. 6(1)(a)—

You can withdraw any consent at any time in your privacy settings. It takes one click and it takes effect immediately. Withdrawing your biometric consent deletes your photographs and face geometry; we will tell you exactly what that means before you confirm.

5. Automated decisions

No computer decides your report. Every analysis is reviewed and signed by a named human who can change or remove anything in it.

There is one automatic decision: if your answers to the wellbeing questions meet all three of the standard screening criteria — you are preoccupied with a perceived appearance flaw, it causes you significant distress or gets in the way of your life, and you spend an hour or more a day thinking about it — the system stops your analysis and refunds you automatically. We tell you exactly why, we do not use the word diagnosis because a questionnaire cannot diagnose anything, and you can reply and reach a clinician who can review the decision. We publish the exact criteria and the exact scoring rule so you can check them.

6. Who we share data with

Almost nobody.

WhoWhat they getWhereProtection
StripeYour email, name, billing address and what you bought. No health data, no biometric data, no report contentIreland, and onward to the United StatesData Privacy Framework certification plus Standard Contractual Clauses
Our reviewers and cliniciansWatermarked copies of your images, your measurements, your intake answersEU, and named individuals elsewhereIndividual data protection contracts; no local storage; time-limited access; every view logged
Our lawyers and accountantsBusiness records, and personal data only when genuinely necessaryFranceProfessional obligations

That is the list. We use no analytics companies, no advertising networks, no session recording, no third-party chat, no third-party email provider, no cloud AI services and no data brokers. We host our own database, our own storage, our own email, our own error tracking and our own analytics. When we add a subprocessor we announce it at /legal/subprocessors 30 days before they start, and if you object you can cancel and get a pro-rata refund.

7. Where your data lives

In the European Union. Our servers are in Germany, with backups in Finland. We operate no infrastructure outside the EEA.

The only routine transfer out of the EEA is to Stripe for payment processing, which is covered by the EU-US Data Privacy Framework and by Standard Contractual Clauses. We have assessed that transfer and we review the assessment every year.

8. Your rights

RightHowHow fast
See everything we holdDownload your data7 days
Take it elsewhere, machine-readableSame page7 days
Fix something wrongYour privacy settings, or Care for measurement disputes5 days
Delete your photographs onlyYour privacy settings7 days
Delete all biometric dataSame7 days
Delete everythingSame7 days
Withdraw a consentSameImmediately
Restrict or object to processingprivacy@beautyprivilege.com3 days
Ask us to stop marketingUnsubscribe link, or the same pageImmediately
See the specific third parties we disclosed your data toYour disclosure list7 days
Ask a human to review the wellbeing decisionReply to the email, or Care2 days

These deadlines are ours, not the law's. The law generally gives us a month; we aim for a week and we publish how we actually do in our annual transparency report.

When you delete everything, some records survive, and you should know which:

  • Invoices, for 7 years, because tax law requires it. We remove your name and email and keep the numbers.
  • Consent records, for 7 years, because we have to be able to prove you consented and that you withdrew.
  • The record of your deletion, so we can prove it happened.
  • Our audit log, with the content removed but the fact of the action kept.
  • Adverse event reports, if you told us something we recommended harmed you, because product safety records have to survive.
  • A one-way scrambled version of your email, if you asked us never to market to you — otherwise we would email you again the moment you came back.

If you contributed to our research and we have already used your data to train a model, deleting your data removes it from our records and from all future training, but we cannot surgically remove your contribution from a model that has already been trained. We say so plainly in the research consent, before you agree, because promising otherwise would be untrue.

9. Where we sell, and who regulates us

We sell only in the European Union, Norway, Iceland and Liechtenstein. If your billing address is anywhere else, checkout will tell you so rather than take your money. This is not a legal formality: the laws that protect biometric data differ sharply between countries, and we would rather serve one region properly than several badly.

Your supervisory authority. You can complain to the data protection authority in the country where you live, where you work, or where you think the problem happened — your choice, under Article 77. Because we are established in France, our lead authority is the CNIL. We would rather you told us first, at dpo@beautyprivilege.com, but you do not have to, and you do not have to go through us to complain.

What this means if you move. These rights follow you within the EEA. If you move outside it, we will keep honouring them for the data we already hold, because your data does not stop being sensitive when you cross a border — but we will not be able to sell you a new analysis.

10. Security

Your photographs are encrypted with a key that belongs only to you, which is itself encrypted under a master key held separately. Your original photographs are never shown to anyone — not to you, not to our reviewers, not to our engineers, not to anyone. They exist only so the computer can make a better working copy. Every database table containing your data enforces access rules at the database level, so a bug in our application cannot become a data breach. Staff accounts require two-factor authentication. Access to your images requires a stated reason, expires in 60 minutes, and is logged and reviewed.

If something goes wrong, we will tell the relevant regulator within 72 hours and we will tell you — because for biometric data we assume a breach is high risk unless we have specific evidence otherwise.

11. Children

This service is for adults. You must be 18 or older. We check your date of birth, we require you to confirm your age, and our system estimates age from the photographs as a backstop. If we have any reason to believe a user is under 18, we stop the analysis, refund the payment in full, and delete everything within 7 days. We do not knowingly collect data from anyone under 18 and we do not advertise to anyone under 18.

12. Cookies

We use cookies that are strictly necessary to run the site — signing you in, keeping your basket, preventing fraud. Everything else asks first. We use no advertising cookies at all, because we do no advertising tracking. Our analytics are first-party, stay on our own servers, and never leave them. See our cookie policy.

13. Changes

When we change this policy we will post the new version, keep the old ones in the version history, and show you a diff. If a change affects how we use your biometric data, we will ask for your consent again — we will not treat silence as agreement. For any other material change we will email you at least 30 days before it takes effect.

14. Contact

  • Data Protection Officer: dpo@beautyprivilege.com
  • Privacy requests: privacy@beautyprivilege.com, or your privacy settings
  • Someone else uploaded a photo of me: report an image — we respond within 72 hours
  • Post: 45 B rue de la Ganache, 44550 Saint-Malo-de-Guersac, France

We answer privacy email ourselves. There is no ticketing bot.

How this page is maintained

Version
1.0 · effective 2026-09-01 · version history
Legal review
Not yet reviewed by a solicitor. This text is published from our own drafting. It has not been through external legal review, and we would rather say so than let the absence be assumed either way.
Change detection
The text above is fingerprinted. Editing a word of it fails our build until the change is recorded, which is how an edit made after a review cannot pass unnoticed.

Product

  • Pricing
  • Methodology
  • About us
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Biometric Data Policy
  • Subprocessors
  • Cookies and Local Storage

Who we are

Quentin Aoustin, entrepreneur individuel. 45 B rue de la Ganache, 44550 Saint-Malo-de-Guersac, France. SIREN 898 608 146.

We sell in the European Union, Norway, Iceland and Liechtenstein, and nowhere else.