Privacy Policy
This policy explains what we collect, why, who sees it, how long we keep it, and what you can do about it. It is written to be read. If anything here is unclear, email dpo@beautyprivilege.com and we will fix the wording.
The short version. You send us six photographs of your face. We measure them, a person reviews the result, and we send you a report. We destroy your photographs 90 days after your report is ready. We do not sell your data. We do not share it with advertisers. We do not send it to any outside AI service. The only outside company involved at all is Stripe, who takes your payment.
1. Who we are
Quentin Aoustin, entrepreneur individuel, 45 B rue de la Ganache, 44550 Saint-Malo-de-Guersac, France (SIREN 898 608 146). We are the controller of your personal data — a single French business, with no joint-controller arrangement and no second company.
- Data Protection Officer: dpo@beautyprivilege.com
- Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), France. You may lodge a complaint with the CNIL, or with the authority where you live or work
- Where we operate: the European Union, Norway, Iceland and Liechtenstein — and nowhere else
- Postal: as above
2. The most important part: your photographs and your face data
When you buy an analysis, you upload six photographs of your face. From those we create:
- a scan of your face geometry — 521 landmark points and a three-dimensional model of your face;
- 181 biometric tests derived from that geometry;
- skin analysis results;
- a short mathematical identity signature we use only to check that our visualizations still look like you.
In law, all of this is biometric data. It is special category data under Article 9 of the GDPR, processed for the purpose of uniquely identifying nothing at all — only of measuring your own face for you. We treat it as the most sensitive thing we hold, because it is.
What we use it for: producing your analysis, your report, your plan and your visualizations. That is the entire list.
How long we keep it — and this is a promise with a mechanism behind it:
| What | How long |
|---|---|
| Your original photographs | 90 days after your report is published, then permanently destroyed |
| Resized copies and overlays we make from them | 90 days, same |
| Your face geometry, 3D model and identity signature | 30 days after your report is published, then permanently destroyed |
| Your measurements (numbers, not pictures) | Until you delete your account |
Destruction is automatic. It happens whether or not you ask, whether or not you are still a customer, and whether or not you remember this policy exists. A separate job checks every night that it actually happened, and we treat a failure as an incident.
Our full biometric data retention and destruction policy is published separately at /legal/biometric-data.
What we will never do with it:
- We will never sell, lease, trade or otherwise profit from your biometric data.
- We will never share it with advertisers, data brokers, insurers, employers, or anyone else.
- We will never send it to an outside AI service. Every piece of analysis runs on computers we own. The machines that do it have no route to the internet.
- We will never use it to identify you anywhere else, or to search for you, or to match you against any other database. We have no such capability and we have not built one.
- We will never use it to train our models unless you separately, specifically opt in — and that choice is off unless you turn it on.
Who looks at your face. A trained human reviewer checks every report before you see it. They see a resized, watermarked copy — never your original files. They can only open your images through a system that requires them to state a reason, ties the access to a specific task, and expires after 60 minutes. Every single time anyone opens your images, it is recorded with their name, the reason and the time. We review those records every week.
3. Everything else we collect
| What | Why | How long |
|---|---|---|
| Name, email, password, language, time zone | Your account | While you have an account, then 24 months |
| Payment details | Taking payment. Card numbers go straight to Stripe — we never see them | Stripe holds these; we keep invoices 7 years for tax |
| Your answers about goals, routine, lifestyle and budget | Making the plan fit your life | While you have an account |
| Your answers about health, medication, allergies and pregnancy | Checking that nothing we recommend is unsafe for you | While you have an account |
| Your answers to the wellbeing questions | Making sure this product is right for you, and stopping if it is not | 3 years, or until you delete your account |
| Your self-declared ancestry, sex and date of birth | Comparing you against a relevant reference group, and confirming you are 18 or over | While you have an account |
| Messages you send our care team | Answering you | 3 years after the conversation ends |
| IP address, browser, device, pages viewed | Security, fraud prevention, and making the product better | Logs 30 days; analytics 25 months, with your identifier removed after 90 days |
About the wellbeing questions. Before we analyze anything, we ask a short set of standard clinical screening questions. If your answers suggest that appearance concerns are taking up a lot of your time and causing you real distress, we stop, we refund you in full, and we point you toward people who can actually help. We do this because the evidence is clear that cosmetic assessment does not help in that situation and can make it worse. Those answers are the most restricted data in our system. They are never used for marketing, ever, and anyone who screens positive is permanently removed from every marketing list we have.
Things we deliberately do not collect: your precise location, your contacts, your advertising identifiers, video of you, or anything about you from any other company.
4. Why we are allowed to do this
| What we do | Our legal basis | For special category data |
|---|---|---|
| Run your account, take payment, deliver your analysis | Performance of our contract with you — Art. 6(1)(b) | — |
| Process your photographs and face geometry | Contract — Art. 6(1)(b) | Your explicit consent — Art. 9(2)(a) |
| Health and wellbeing screening | Contract and our legal duty to sell safely — Art. 6(1)(b), 6(1)(c) | Your explicit consent — Art. 9(2)(a), and in an emergency, protecting someone's vital interests — Art. 9(2)(c) |
| Keep tax records | Legal obligation — Art. 6(1)(c) | — |
| Security and fraud prevention | Our legitimate interests — Art. 6(1)(f) | — |
| Research and model evaluation | Your consent — Art. 6(1)(a) | Your separate explicit consent — Art. 9(2)(a) |
| Marketing email | Your consent — Art. 6(1)(a) | — |
You can withdraw any consent at any time in your privacy settings. It takes one click and it takes effect immediately. Withdrawing your biometric consent deletes your photographs and face geometry; we will tell you exactly what that means before you confirm.
5. Automated decisions
No computer decides your report. Every analysis is reviewed and signed by a named human who can change or remove anything in it.
There is one automatic decision: if your answers to the wellbeing questions meet all three of the standard screening criteria — you are preoccupied with a perceived appearance flaw, it causes you significant distress or gets in the way of your life, and you spend an hour or more a day thinking about it — the system stops your analysis and refunds you automatically. We tell you exactly why, we do not use the word diagnosis because a questionnaire cannot diagnose anything, and you can reply and reach a clinician who can review the decision. We publish the exact criteria and the exact scoring rule so you can check them.
6. Who we share data with
Almost nobody.
| Who | What they get | Where | Protection |
|---|---|---|---|
| Stripe | Your email, name, billing address and what you bought. No health data, no biometric data, no report content | Ireland, and onward to the United States | Data Privacy Framework certification plus Standard Contractual Clauses |
| Our reviewers and clinicians | Watermarked copies of your images, your measurements, your intake answers | EU, and named individuals elsewhere | Individual data protection contracts; no local storage; time-limited access; every view logged |
| Our lawyers and accountants | Business records, and personal data only when genuinely necessary | France | Professional obligations |
That is the list. We use no analytics companies, no advertising networks, no session recording, no third-party chat, no third-party email provider, no cloud AI services and no data brokers. We host our own database, our own storage, our own email, our own error tracking and our own analytics. When we add a subprocessor we announce it at /legal/subprocessors 30 days before they start, and if you object you can cancel and get a pro-rata refund.
7. Where your data lives
In the European Union. Our servers are in Germany, with backups in Finland. We operate no infrastructure outside the EEA.
The only routine transfer out of the EEA is to Stripe for payment processing, which is covered by the EU-US Data Privacy Framework and by Standard Contractual Clauses. We have assessed that transfer and we review the assessment every year.
8. Your rights
| Right | How | How fast |
|---|---|---|
| See everything we hold | Download your data | 7 days |
| Take it elsewhere, machine-readable | Same page | 7 days |
| Fix something wrong | Your privacy settings, or Care for measurement disputes | 5 days |
| Delete your photographs only | Your privacy settings | 7 days |
| Delete all biometric data | Same | 7 days |
| Delete everything | Same | 7 days |
| Withdraw a consent | Same | Immediately |
| Restrict or object to processing | privacy@beautyprivilege.com | 3 days |
| Ask us to stop marketing | Unsubscribe link, or the same page | Immediately |
| See the specific third parties we disclosed your data to | Your disclosure list | 7 days |
| Ask a human to review the wellbeing decision | Reply to the email, or Care | 2 days |
These deadlines are ours, not the law's. The law generally gives us a month; we aim for a week and we publish how we actually do in our annual transparency report.
When you delete everything, some records survive, and you should know which:
- Invoices, for 7 years, because tax law requires it. We remove your name and email and keep the numbers.
- Consent records, for 7 years, because we have to be able to prove you consented and that you withdrew.
- The record of your deletion, so we can prove it happened.
- Our audit log, with the content removed but the fact of the action kept.
- Adverse event reports, if you told us something we recommended harmed you, because product safety records have to survive.
- A one-way scrambled version of your email, if you asked us never to market to you — otherwise we would email you again the moment you came back.
If you contributed to our research and we have already used your data to train a model, deleting your data removes it from our records and from all future training, but we cannot surgically remove your contribution from a model that has already been trained. We say so plainly in the research consent, before you agree, because promising otherwise would be untrue.
9. Where we sell, and who regulates us
We sell only in the European Union, Norway, Iceland and Liechtenstein. If your billing address is anywhere else, checkout will tell you so rather than take your money. This is not a legal formality: the laws that protect biometric data differ sharply between countries, and we would rather serve one region properly than several badly.
Your supervisory authority. You can complain to the data protection authority in the country where you live, where you work, or where you think the problem happened — your choice, under Article 77. Because we are established in France, our lead authority is the CNIL. We would rather you told us first, at dpo@beautyprivilege.com, but you do not have to, and you do not have to go through us to complain.
What this means if you move. These rights follow you within the EEA. If you move outside it, we will keep honouring them for the data we already hold, because your data does not stop being sensitive when you cross a border — but we will not be able to sell you a new analysis.
10. Security
Your photographs are encrypted with a key that belongs only to you, which is itself encrypted under a master key held separately. Your original photographs are never shown to anyone — not to you, not to our reviewers, not to our engineers, not to anyone. They exist only so the computer can make a better working copy. Every database table containing your data enforces access rules at the database level, so a bug in our application cannot become a data breach. Staff accounts require two-factor authentication. Access to your images requires a stated reason, expires in 60 minutes, and is logged and reviewed.
If something goes wrong, we will tell the relevant regulator within 72 hours and we will tell you — because for biometric data we assume a breach is high risk unless we have specific evidence otherwise.
11. Children
This service is for adults. You must be 18 or older. We check your date of birth, we require you to confirm your age, and our system estimates age from the photographs as a backstop. If we have any reason to believe a user is under 18, we stop the analysis, refund the payment in full, and delete everything within 7 days. We do not knowingly collect data from anyone under 18 and we do not advertise to anyone under 18.
12. Cookies
We use cookies that are strictly necessary to run the site — signing you in, keeping your basket, preventing fraud. Everything else asks first. We use no advertising cookies at all, because we do no advertising tracking. Our analytics are first-party, stay on our own servers, and never leave them. See our cookie policy.
13. Changes
When we change this policy we will post the new version, keep the old ones in the version history, and show you a diff. If a change affects how we use your biometric data, we will ask for your consent again — we will not treat silence as agreement. For any other material change we will email you at least 30 days before it takes effect.
14. Contact
- Data Protection Officer: dpo@beautyprivilege.com
- Privacy requests: privacy@beautyprivilege.com, or your privacy settings
- Someone else uploaded a photo of me: report an image — we respond within 72 hours
- Post: 45 B rue de la Ganache, 44550 Saint-Malo-de-Guersac, France
We answer privacy email ourselves. There is no ticketing bot.