Privacy Policy

We take your privacy seriously. This policy explains what data we collect,
how we use it, and the choices you have.

Effective Date: [Add Date]
Note: This document is an application privacy policy provided for informational purposes. It does not constitute legal advice. If you have legal questions about data privacy, please consult a qualified attorney.
01

Introduction

Lumiskin ("we," "our," or "us") is a skincare guidance application that uses face photo analysis to provide visible cosmetic observations, adaptive skincare routines, and progress tracking. This Privacy Policy describes how we collect, use, store, and protect information when you use the Lumiskin mobile application.

By using Lumiskin, you agree to the practices described in this policy. If you do not agree, please discontinue use of the app.

Lumiskin provides cosmetic observations only — we do not diagnose skin conditions, medical disorders, or health issues. All analysis is for personal skincare guidance purposes.

02

Information We Collect

We collect different types of information depending on how you use the app.

Account Information

When you create an account, we collect your email address, display name, and optionally your skincare goals, skin sensitivity level, and routine preferences. This information is stored securely in our database to personalise your experience.

Face Scan Photos

When you perform a skin scan, the app captures a selfie photo of your face. This photo is processed locally on your device (cropped, masked, and compressed) before being uploaded to our image hosting service for AI analysis. Photos are used solely for skin analysis.

Skin Analysis Results

After each scan, AI-generated skin observations (such as visible acne, redness, texture, and tone) are stored alongside your scan record. These results are used to generate routines and track your progress over time.

App Usage Analytics

We collect anonymised usage data (such as which features you use and how often) to improve the app. This data does not include your photos or analysis results.

Subscription and Payment Status

We collect your subscription tier (Free, Plus, or Pro) and subscription status via our payment provider. We do not store your payment card details — these are handled entirely by the payment processor.

  • Email address and display name
  • Skincare preferences and goals (optional)
  • Face photos (for analysis only)
  • Scan results and skin metrics
  • Anonymised app usage analytics
  • Subscription plan and status
03

How We Use Your Information

  • Skin analysis: To generate AI-powered visible skin observations from your face photos.
  • Routine generation: To create personalised AM/PM skincare routines based on your scan results and preferences.
  • Progress tracking: To compare scan results over time and show your skin's progress.
  • Account management: To authenticate you, manage your subscription, and restore your data across devices.
  • App improvement: To understand how features are used and improve the product via anonymised analytics.
  • Notifications: To send optional daily scan and routine reminders (only if you grant permission).

We do not sell, rent, or trade your personal information or face photos to any third party for marketing, advertising, or commercial purposes.

04

Image and Face Data Handling

Because Lumiskin captures face photos, we want to be especially transparent about how this sensitive data is handled.

Photos Are Used Only for Skincare Analysis

Your face photos are used exclusively to generate skin condition observations. They are not used for identity recognition, facial authentication, advertising targeting, or any purpose unrelated to the analysis you requested.

Processing on Your Device

Before any photo leaves your device, it is cropped to your face area, an oval mask is applied, and it is compressed to reduce file size. This pre-processing happens locally and is designed to minimise unnecessary data transfer.

Upload to Cloudinary

Processed face photos may be uploaded to Cloudinary, a cloud media management service, to generate a secure URL. This URL is used to pass the image to our AI analysis service. Cloudinary is subject to its own privacy and security policies.

AI Analysis via Claude API

The image URL is sent to Anthropic's Claude API for visible skin analysis. Claude generates observations about cosmetic skin indicators based solely on the image provided. We do not instruct the AI to identify, authenticate, or re-identify any individual.

No Sale or Identity Use

Your face photos are never sold to third parties and are never used for identity recognition, biometric profiling, or surveillance purposes.

05

Local Storage for Guest Users

Lumiskin offers a one-time free guest scan that does not require creating an account. The following applies to guest users:

  • Stored locally only: Guest scan results, captured image URI, date/time, skin metrics, and the next-allowed scan date are stored exclusively on your device using local app storage.
  • No account sync: Guest data is never uploaded to our database or synced to any server.
  • Deleted on login: When you create an account or log in, all guest local data is immediately deleted from your device. Guest scan results are not automatically imported into your account.
  • 21-day scan restriction: After completing a guest scan, a new guest scan is blocked for 21 days. The restriction date is stored locally. After 21 days, a new guest scan replaces all previous guest data.
  • You can view your result: During the 21-day period, you can still open and view your saved guest scan result at any time without logging in.
06

Third-Party Services

Lumiskin uses the following third-party services to deliver its features. Each service operates under its own privacy policy, which we encourage you to review.

Supabase

Account authentication, database, and secure backend infrastructure.

Privacy Policy ↗
Cloudinary

Secure cloud hosting for processed face photos used in AI analysis.

Privacy Policy ↗
Claude AI (Anthropic)

AI model used to generate visible skin condition observations from photos.

Privacy Policy ↗
RevenueCat

Subscription management and in-app purchase processing.

Privacy Policy ↗
PostHog

Anonymised product analytics to help us understand feature usage and improve the app.

Privacy Policy ↗

We do not share personally identifiable information with these providers beyond what is necessary to deliver the service. We do not allow any of these providers to use your data for their own advertising or marketing purposes.

07

Data Retention

  • Account data: Retained for as long as your account is active. You may request deletion at any time.
  • Scan results and metrics: Retained to support your progress history. Deleted when your account is deleted.
  • Cloud-hosted images: Face photos hosted on Cloudinary may be automatically deleted after 90 days to minimise long-term image storage. Scan metrics and analysis results are retained separately.
  • Guest data: Stored only on your device and never sent to our servers. Deleted when you log in or when a new guest scan replaces it.
  • Analytics data: Anonymised usage data may be retained for product analysis. It cannot be linked back to you personally.

When you delete your account through the app, we delete your profile, scan records, and associated data from our database. Some residual anonymised data may remain in aggregated analytics but cannot be used to identify you.

08

Your Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, please contact us at sathsara2000@gmail.com.

👁
Access
Request a copy of the personal data we hold about you.
✏️
Correction
Ask us to correct inaccurate or incomplete information.
🗑
Deletion
Request deletion of your account and associated personal data.
📤
Portability
Request your data in a portable, machine-readable format.
Object / Opt-out
Opt out of analytics data collection at any time in app settings.
🔒
Restriction
Ask us to restrict processing of your data in certain circumstances.

You can delete your account directly within the Lumiskin app (Settings → Account → Delete Account). Account deletion is permanent and cannot be undone.

09

Children's Privacy

Lumiskin is not intended for use by children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at sathsara2000@gmail.com and we will take steps to remove that information.

10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:

Your continued use of Lumiskin after any changes become effective constitutes your acceptance of the updated policy. We encourage you to review this page periodically.


11

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please reach out to us.

Get in touch

We aim to respond to all privacy-related enquiries within 5 business days.

sathsara2000@gmail.com

Lumiskin · [Company Address]