FutureSkin
Privacy Policy
FutureSkin asks for a photo of your face. That deserves a plain answer about what happens to it — so this document leads with the short version.
The short version
- Your selfie is shrunk and stripped of location and EXIF data on your device before it is uploaded.
- It is stored in a private bucket that no one else can browse, and is only ever reachable through links that expire after one hour.
- To make your portraits it is sent to two AI providers, on paid plans under which they do not train models on it.
- We do not sell your data, show ads, or embed advertising or analytics trackers.
- Deleting your account in Settings erases your photos, your answers, and your account — permanently, and without asking us.
1. Who is responsible
FutureSkin is operated by Deepfai (“we”, “us”). We are the controller of the personal data described here. You can reach us at privacy@deepfai.com.
2. What we collect
Information you give us
- Email address — the only account identifier. We sign you in with a one-time code, so we never ask for or store a password.
- Questionnaire answers — eighteen multiple-choice answers about your skincare routine and lifestyle: age range, sex, skin type and concerns, cleansing, moisturiser, sunscreen and reapplication, actives, makeup removal, sleep, water, smoking, alcohol, sugar, stress, exercise, sun exposure and tanning. Some of these touch on health and habits, so we treat the whole set as sensitive.
- A selfie — taken in the app or chosen from your library, only when you ask for future portraits. This is biometric-adjacent data and is handled as described in section 4.
Information created by using the app
- Your results — the routine score, category scores, risk flags and the written analysis generated for you, plus the two portraits.
- Subscription status — whether you are on a trial or an active plan, which product, and when the period ends. Payment card details never reach us; Apple and Google handle payment.
- Monthly usage counts — how many analyses and portrait scans you have run this month, to enforce fair-use limits.
We do not collect your name, address, phone number, contacts, precise location, or advertising identifiers. The app contains no analytics or advertising SDKs.
3. Why we use it, and on what basis
- To provide the service — scoring your routine, writing your plan and generating your portraits. This is performance of our contract with you.
- To process your photo — done only on your explicit consent, given on the consent screen before the camera opens. You can withdraw consent at any time by deleting your account or your scans.
- To keep the service working and affordable — usage limits, abuse prevention and troubleshooting. This is our legitimate interest.
- To manage subscriptions — verifying entitlement server-side so paid features unlock. Contract and legitimate interest.
We do not use your data for profiling, for advertising, or for any automated decision with legal or similarly significant effects. Your results are an illustrative simulation, not an assessment of you.
4. What happens to your selfie
- On your device. The image is downscaled to at most 1024 pixels and its EXIF metadata — including any GPS coordinates, camera details and timestamps — is removed before anything leaves your phone.
- In storage. It is uploaded to a private bucket, filed under your own account folder. The bucket is not public. Access rules permit only your account to read its own folder, and the app reaches images through signed links that expire after one hour.
- Quality check. The image is sent to Anthropic’s Claude to confirm it contains one clear, well-lit face before we spend anything generating from it.
- Generation. The image and a text prompt are sent to Google’s Gemini image model, twice, to produce your two portraits. The portraits are written back to the same private bucket.
- Afterwards. Nothing is posted anywhere. Portraits are shown only to you, and are labelled in the app as AI-generated simulations.
Both providers are used through their paid business APIs, under terms where submitted content is not used to train their models. We never use your photo to train anything ourselves, and we never publish it.
5. Who else processes your data
| Provider | What they receive | Why |
|---|---|---|
| Anthropic | Your questionnaire answers and score; your selfie for the quality check | Writing your analysis; confirming the photo is usable |
| Google (Gemini API) | Your selfie and the generation prompt | Creating the two future portraits |
| RevenueCat | Your account identifier and subscription events | Managing subscriptions and entitlement |
| Apple / Google | Your payment details, which we never see | Taking payment and handling refunds |
| Resend | Your email address | Delivering your sign-in codes |
| Hostinger | Hosts our server; data at rest sits on their infrastructure | Running the backend |
The app also loads its display fonts from Google Fonts at first run, which discloses your IP address to Google in the same way visiting any website using those fonts would.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We may disclose data if legally compelled, or to protect the rights and safety of our users.
6. Where your data is stored
Your account, answers, results and images are stored on our own server infrastructure in Boston, United States. Our AI and subscription providers may process data in the United States and other countries. If you are in the UK or the EEA, transfers outside your region rely on the providers’ standard contractual clauses.
7. How long we keep it
- Your scans, answers, portraits and selfies — kept until you delete them or delete your account, so that your history stays available to you.
- Your account and email — kept until you delete your account.
- Subscription records — kept while the subscription is live and for a limited period afterwards where needed for accounting and dispute handling.
- Monthly usage counters — reset each month and deleted with your account.
8. Deleting everything
Open Settings → Delete account. This permanently removes your stored images, your scans, your answers and your account. It cannot be undone and does not require you to contact us.
One thing deletion does not do: cancel a paid subscription. Subscriptions are billed by Apple or Google, so you must cancel through the App Store or Google Play — the app links you straight there from Settings.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or object to our use of your data, and to withdraw consent for photo processing. Deletion is built into the app; for anything else, write to privacy@deepfai.com and we will respond within the period the law allows. You may also complain to your local data protection authority.
10. Children
FutureSkin is not directed at children under 13, and we do not knowingly collect their data. If you tell us you are under 18, the app will give you a score and a plan but will not generate or offer future portraits, and will not ask for a photo. If you believe a child has given us data, contact us and we will delete it.
11. Security
Traffic is encrypted in transit. Images live in a private bucket reachable only through short-lived signed links. Database access is constrained by row-level security so an account can only ever read its own rows. AI provider keys are held server-side and never shipped inside the app. No system is perfectly secure, but we work to keep the amount of data we hold small and its blast radius smaller.
12. Changes
If we change this policy materially we will update the date above and, where the change is significant, tell you in the app before it takes effect.
Questions about this document? Write to privacy@deepfai.com.