Summary of Key Points
This summary gives the key points of our privacy notice. You can find more detail on any topic by following the link after each point or by using the table of contents.
What personal information do we process? When you use our Services, we process the information you give us, such as your name, contact details, skin profile, and the selfies you take for a skin scan, together with the results our Services generate for you. Learn more about the information we collect.
Do we process sensitive personal information? Yes. With your consent, we process face photos, skin condition assessments, allergies and sensitivities, cycle tracking entries if you choose to record them, and ethnicity if you choose to provide it. Learn more about sensitive information.
How do we handle face data? Selfies you take in the app are analyzed to describe your visible skin. We do not identify you from your face, we do not create biometric templates, we do not train AI on your photos, and we do not keep your daily scan photos on our servers. Learn more about face data.
Do we receive information from third parties? Only what is needed to run the Services: your name and email from Apple if you use Sign in with Apple, your subscription status from Apple's payment systems, product details from public product databases when you scan a barcode, and the skin assessment returned by our AI analysis provider.
How do we process your information? To provide, improve, and administer our Services, communicate with you, keep the Services secure, and comply with law. Learn more about how we process your information.
When and with whom do we share personal information? Only with service providers that work on our behalf under written contracts, with Apple for payments and sign-in, and as required by law. We do not sell personal information and we do not share it for advertising. Learn more about when and with whom we share information.
How do we keep your information safe? Encryption in transit, encryption at rest by our hosting provider, and access rules that limit each account to its own records. No system is perfectly secure, so we also commit to notifying you if a breach affects you. Learn more about security.
What are your rights? Depending on where you live, you may have rights to access, correct, delete, and port your information, to withdraw consent, and to appeal our decisions. Learn more about your privacy rights.
How do you exercise your rights? The easiest way is inside the app: Settings, then Delete Account, or Settings, then My Profile. You can also email support@facecard.app. We act on every request in accordance with applicable data protection laws.
1. What Information Do We Collect?
Personal information you disclose to us
In short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you create an account, complete onboarding, use features of the app, or contact us. The personal information we collect depends on the features you use and may include:
- Account and contact details. Name, email address, and phone number. If you use Sign in with Apple, Apple sends us an identity token, your email address (which may be an Apple private relay address), and your name on first sign-in. If you sign in with an email address and password, our hosting provider stores only a hashed version of the password. Phone-verified accounts receive a random credential that is never shown to anyone.
- Skin profile. Skin type, recent skin changes, the area you want to improve, lifestyle, routine depth, active ingredients you use, and an environment choice such as "Sunny and dry." The environment choice is self-reported; the app does not use GPS or any location service.
- Optional profile details. Age, gender, and a profile photo chosen from your photo library. Available in Settings, under My Profile, and may be left blank.
- Selfies. Three photos of your face taken with the device camera during a skin scan. See section 2.
- Skin Journal entries. Sleep, water intake, stress, diet, exercise, free-text notes, and, if you turn it on, cycle tracking.
- Product shelf. Products you add, including name, brand, category, how much is left, when you used it, an image link, and your notes. If you scan a product barcode, the app decodes it on your device and sends only the barcode number to public product databases to look up the product.
- Feedback and support messages. Anything you type in the in-app feedback prompt or send to us by email.
All personal information you provide must be true, complete, and accurate, and you should update it in the app if it changes.
Sensitive information
When necessary, with your consent, we process the following categories of sensitive information:
| Sensitive information | How you consent | Purpose | How to withdraw |
|---|---|---|---|
| Face photos and the skin assessment derived from them | The Face Data notice before your first scan | Skin assessment, routine, progress | Section 2.3 |
| Skin condition assessments, allergies, and sensitivities | You enter them in onboarding or My Profile after a short notice | Calibrate the assessment; warn you when a suggested product contains something you react to | Edit or clear them in My Profile |
| Ethnicity | Optional field in My Profile with a "Prefer not to say" choice and a short notice | Calibrate the assessment, because skin presents differently across skin tones | Choose "Prefer not to say" or clear it |
| Cycle tracking (period and cycle day) | You turn it on in the Skin Journal after a short notice | Show patterns between your cycle and your skin scores | Turn it off and clear past entries |
We do not use sensitive information to infer anything beyond the stated purpose, for advertising, or for sale or sharing.
Payment data
Purchases are made through Apple In-App Purchase. Apple collects the data necessary to process your payment. We never receive or store card numbers. You can find Apple's privacy notice at https://www.apple.com/legal/privacy.
Application data
If you use our app, we may also collect the following information if you choose to give us access or permission:
- Camera. Used only for skin scans and for reading product barcodes. Barcode scanning does not capture or send an image. The camera library used by the app may show a microphone permission string; the app does not record audio.
- Photo library. Used only if you choose a profile photo. Scans never read your photo library.
- Push notifications. If you allow notifications, we store the token that identifies your device, with your platform, to send routine reminders, an occasional message if you have not used the app for a while, and occasional announcements. You can turn notifications off in the app's Notification Settings or in your device settings.
You can change these permissions at any time in your device settings.
Information automatically collected
In short: Our own code does not collect device or usage analytics. Our service providers receive the standard technical information any internet connection produces.
The app contains no analytics, crash-reporting, or advertising software, and our code does not collect your device model, operating system version, advertising identifier, or usage analytics. When the app connects to our service providers, they receive standard technical data such as your internet address, and our subscription provider and Apple collect standard device information through their software. Our hosting provider keeps server request logs for a short period, no longer than 90 days.
On your device only. Your sign-in session, reminder times, your answer to the baseline prompt, and a daily and monthly scan counter stay in private storage on your phone and are not sent to us. We do not use cookies.
2. How Do We Handle Face Data?
In short: Selfies you take in the app are analyzed to describe your visible skin. We do not identify you from your face, we do not create biometric templates, we do not train AI on your photos, and we do not keep your daily scan photos on our servers.
This section answers, in order, the four questions Apple requires face-data apps to answer. "Face data" means the selfies you take in the app and the information derived from them.
2.1 Collection, all intended uses, and disclosures
What we collect. When you run a skin scan, the app uses the device camera to capture three photos of your face: front, left profile, and right profile. On your device, each photo is reduced to about 1024 pixels wide and compressed as a JPEG before it is sent anywhere.
Consent. Before your first scan, the app shows a Face Data notice that states what is captured, why, where the photos go, how long they are kept, and how to withdraw. The scan does not start until you tap "I agree." You can decline and still use the rest of the app.
All intended uses. We use face data for these purposes and no others:
- To produce a written skin assessment: scores for hydration, texture, tone, radiance, clarity, spots, breakouts, and puffiness, plus text observations.
- To build your routine and product suggestions from that assessment.
- To show your progress over time, using the stored scores from each scan.
- If you opt in, to keep your first three photos as a private baseline you can view later.
Disclosures. Each scan is sent over an encrypted connection to a server function run by our cloud hosting provider. That function forwards the three photos, with a written prompt, to our AI analysis provider, a third-party artificial intelligence service that returns the assessment. The prompt includes the profile details that calibrate the analysis: age, gender, ethnicity, skin type, recent skin changes, lifestyle, routine depth, active ingredients, and allergies or sensitivities. It does not include your name, email address, phone number, or account identifier. Our server function does not write the photos to a database, file storage, or logs. No other company receives your face data.
What we do not do. We do not identify you or anyone else from your face, create face templates or any biometric identifier, or match your face against other photos or databases. We do not use face data to train AI models, and our AI analysis provider does not use the data we send it to train its models. We do not use face data for advertising, sell it, or share it for anyone else's purposes.
2.2 Sharing and retention
Who receives face data. Only our cloud hosting provider, which runs the server function that relays the photos, and our AI analysis provider, which analyzes them. Both act as our service providers under written terms and only on our instructions. We will tell you the names of these providers if you ask, using the contact details in section 15.
Retention schedule and destruction guidelines. We keep face data only as long as needed for the purpose you requested, and never longer than the periods below.
| Face data element | Where it is held | How long | How it is destroyed |
|---|---|---|---|
| Daily scan photos in transit | Our server function at our hosting provider | Only for the seconds the analysis takes; never written to storage | Discarded from memory when the request finishes |
| Daily scan photos at our AI analysis provider | The provider's API systems | Up to 30 days for abuse and misuse monitoring, then deleted; not used for training | Deleted by the provider under its published data controls |
| Daily scan photos on your device | The app's private cache folder on your phone | Until your operating system clears the app cache or you delete the app; not saved to your Photos library; never uploaded again | Cleared by the operating system, or removed when you uninstall |
| Baseline photos (opt-in only) | A private storage folder at our hosting provider that only your signed-in account can open | Until you remove them in Progress, you delete your account, or your account is inactive for 3 years, whichever comes first | Permanently deleted from storage |
| Assessment results (scores and text) | Our database at our hosting provider | Until you delete your account, or your account is inactive for 3 years, whichever comes first | Deleted with your account |
| File path text for scan photos | Our database, stored with each result | Same as assessment results | Deleted with your account |
| Profile details sent with the photos | The AI analysis provider's API systems | Up to 30 days, as above | Deleted by the provider |
"Inactive" means no sign-in and no scan for 3 years. We delete face data sooner once its purpose has been satisfied. If a law requires us to keep a specific record longer, we keep only that record for the required period.
Our AI analysis provider's handling. The provider's published data controls state that data sent through its API is not used to train or improve its models and that abuse monitoring logs are kept for up to 30 days, unless a longer period is required by law or needed to protect its services or a third party from harm. We have not enabled the provider's zero-retention option.
2.3 Deletion and how to revoke consent
You can withdraw consent to face data collection or use at any time. Past results stay in your account unless you delete them.
- Stop scanning. No new face data is collected unless you start a scan.
- Remove baseline photos. Open Progress, tap Your Baseline, then Remove. The photos are permanently deleted from our storage right away.
- Delete your account and all face data. Open Settings, tap Delete Account, type DELETE, and confirm. The app deletes your profile and baseline photos from storage, then deletes your account with everything in it, including assessment results, file paths, journal, profile, push tokens, and phone verification records. This takes effect immediately.
- Email us. Write to support@facecard.app from the email address on your account, or include your account phone number. We verify you as described in section 13 and complete the deletion within 45 days, usually much sooner.
- Photos at our AI analysis provider are deleted under the 30-day limit above. We cannot delete them earlier.
- Photos on your device. Delete the app, or clear its storage in your device settings.
Copies in our hosting provider's routine backups are overwritten within 30 days.
2.4 Third-party protection
Our AI analysis provider is the only third party with whom we share face data, and our hosting provider is the only provider that relays it. Each is bound by written terms requiring it to provide the same or equal protection for face data described in this policy, to use it only to provide its service to us, and not to disclose it to anyone else except as needed for that service. Neither may use your face data for advertising, identification, or model training. If we ever add another recipient, we will update this policy first and require the same commitment.
3. How Do We Process Your Information?
In short: We process your information to provide, improve, and administer our Services, communicate with you, keep the Services secure, and comply with law. We may also process your information for other purposes with your consent.
We process your personal information for the following reasons:
- To create and manage your account. Including signing you in, sending one-time sign-in codes, and answering your requests.
- To deliver the skin assessment you request. Your selfies and skin profile are analyzed to produce scores, observations, a routine, and product suggestions.
- To show your progress and baseline. Using stored assessment results and, if you opt in, baseline photos.
- To show patterns between your habits and your skin. Using Skin Journal entries and assessment results. These comparisons are calculated on your device, and journal entries are never sent to our AI analysis provider.
- To keep your product shelf and look up products you scan.
- To warn you when a suggested product contains an ingredient you react to.
- To manage your subscription and to test which of two paywall designs works better.
- To send reminders and service messages by push notification, if you allow them.
- To protect the Services, prevent abuse, and keep records the law requires.
AI processing. Your assessment is produced automatically by an AI model and is informational only. It is not medical advice, a diagnosis, or a treatment plan, and it does not replace a dermatologist or other qualified professional. The results have no legal or similarly significant effects, and no one at FaceCard reviews your photos. If you disagree with a result, you can rerun a scan, adjust your profile, or contact us.
Marketing. We do not send marketing email or SMS. Push notifications include routine reminders, an occasional message if you have not used the app for a while, and occasional announcements. You can turn them off at any time.
4. What Legal Bases Do We Rely On to Process Your Personal Information?
In short: We process your personal information only when we have a valid legal reason to do so, such as your consent, a contract with you, a legal obligation, or our legitimate interests.
FaceCard is offered in the European Economic Area (except France) and the United Kingdom. If you are located in the EEA or the UK, the General Data Protection Regulation and the UK GDPR require us to explain the legal bases we rely on:
| Purpose | Information used | Legal basis |
|---|---|---|
| Create and secure your account, sign you in, send one-time codes | Account and contact details, phone verification records | Contract |
| Analyze your skin and produce your assessment, routine, and product suggestions | Face data, skin profile, allergies, ethnicity, assessment results | Explicit consent for face data, health data, and ethnicity; contract for the rest |
| Show your progress and baseline | Assessment results, baseline photos | Consent |
| Show patterns between your habits and your skin | Skin Journal, assessment results | Explicit consent |
| Keep your product shelf and look up products you scan | Product shelf, barcode numbers | Contract |
| Warn you when a suggested product contains an ingredient you react to | Allergies and sensitivities, product data | Explicit consent |
| Manage your subscription and test which paywall design works better | Subscription information, account identifier | Contract; legitimate interest in improving the Services |
| Send reminders and service messages | Push token, first name, scan dates | Consent for notifications; legitimate interest in service messages |
| Answer your questions and requests | Contact details, feedback | Contract; legal obligation for rights requests |
| Protect the Services, prevent abuse, keep records the law requires | Account information, server logs, subscription records | Legitimate interest; legal obligation |
Where we rely on consent, including explicit consent for face photos, health information, and ethnicity, you may withdraw it at any time as described in section 11.
5. When and With Whom Do We Share Your Personal Information?
In short: We share information only with service providers that work on our behalf, with Apple for payments and sign-in, and as required by law. We do not sell personal information and we do not share it for advertising.
Service providers. We share your data with third-party service providers that perform services for us and need access to the information to do that work. We have written contracts with each of them designed to safeguard your personal information. They may not use your personal information for anything other than the service they provide to us, they may not share it with any organization apart from us except as needed to provide that service, and they must protect it and retain it only for the period we instruct. The categories of service providers we share personal information with are:
| Service provider category | What it receives | Why | Protection commitment |
|---|---|---|---|
| AI analysis provider | Three face photos per scan and the profile details listed in section 2.1 | Produce your skin assessment | Written terms; no training on inputs; up to 30-day retention; same or equal protection for face data |
| Cloud hosting and database provider | Everything stored in your account, including baseline photos; relays scan photos | Host our database, storage, sign-in, and server functions | Data processing agreement; encryption at rest and in transit; row-level access controls |
| SMS delivery provider | Your phone number and the one-time code | Deliver SMS sign-in codes | Data processing agreement |
| Subscription management provider | Your account identifier, Apple purchase receipt, paywall label, and standard device information collected by its software | Manage subscriptions | Written terms; processor obligations |
| Push notification delivery provider | Your push notification token and the text of each notification | Deliver push notifications | Written terms; Data Privacy Framework participant |
| Public product databases | The barcode you scan and your device's internet address | Look up product details for your shelf | Barcode only; no personal information sent |
We will provide the names of our service providers on request. Use the contact details in section 15.
Apple. Apple processes your payments, provides Sign in with Apple, distributes the app through the App Store, and shows the native review prompt. Apple acts as an independent controller for those services under its own privacy policy at https://www.apple.com/legal/privacy.
Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or part of our business. The successor is bound by this policy until it notifies you of changes.
Legal requirements. We may disclose your information if required to do so by law or in response to a valid legal demand. We review every demand and notify you where the law allows.
6. What Is Our Stance on Third-Party Websites?
In short: We are not responsible for information you share with third-party websites we link to.
Product suggestions in the app link to Amazon with an affiliate tag. We may earn a commission if you buy through such a link. We send Amazon no personal information and learn nothing about what you buy. The app also links to educational pages such as the American Academy of Dermatology. Once you leave the app, the other site's privacy policy governs. We do not guarantee the safety or privacy of data you provide to any third party, and the inclusion of a link does not imply endorsement. You should review the policies of those third parties and contact them directly with questions.
7. Is Your Information Transferred Internationally?
In short: Our servers and our service providers are located in the United States.
We are based in the United States. Your account data is stored on servers located in the United States, and our service providers process information there. If you use FaceCard from another country, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country. For users in the EEA and the UK, each of our service providers is covered by one of the following safeguards: certification to the EU-U.S. Data Privacy Framework and the UK Extension, or the European Commission's Standard Contractual Clauses with the UK Addendum under a data processing agreement. Our AI analysis provider, our hosting provider, and our subscription management provider rely on the Standard Contractual Clauses with the UK Addendum. Our SMS and push notification providers are certified to the Data Privacy Framework and its UK Extension. Details of the safeguard that applies to a particular provider can be provided on request.
8. How Long Do We Keep Your Information?
In short: We keep your information for as long as your account is active, unless you delete it sooner, and we delete accounts that have been inactive for 3 years.
| Category | Kept until | Destroyed by |
|---|---|---|
| Account and contact details | Account deletion, or 3 years of inactivity | Deleted with the account |
| Phone verification proofs | Expire minutes after issue; removed on use and on account deletion | Automatic deletion |
| Skin profile, including ethnicity and allergies | Account deletion, or when you clear the field | Deleted with the account or on edit |
| Profile photo | You replace or remove it, or account deletion | Deleted from storage |
| Daily scan photos | See section 2.2 | See section 2.2 |
| Baseline photos | You remove them, account deletion, or 3 years of inactivity | Permanently deleted from storage |
| Assessment results and photo file paths | Account deletion, or 3 years of inactivity | Deleted with the account |
| Skin Journal | Account deletion, or when you delete an entry | Deleted with the account or on edit |
| Product shelf | Account deletion, or when you remove a product | Deleted with the account or on edit |
| Subscription status and dates | Account deletion; transaction records are kept by Apple and our subscription provider under their policies and by us for as long as tax and accounting law requires, generally up to 7 years | Deleted or archived |
| Push notification token | You turn notifications off, sign out, or account deletion | Deleted |
| Feedback | The text is kept for product improvement; your account identifier is removed when you delete your account, so the text becomes anonymous | Anonymized |
| Server request logs held by our hosting provider | No longer than 90 days | Automatic rollover |
| Copies at our AI analysis provider | Up to 30 days | Deleted by the provider |
| Email correspondence with support | 2 years after the last message in the thread | Deleted |
When you delete your account, deletion happens immediately in our live systems. Copies in our hosting provider's routine backups are overwritten within 30 days.
9. How Do We Keep Your Information Safe?
In short: We protect your personal information through technical and organizational security measures, and we will notify you if a breach affects you.
- Every connection between the app, our servers, and our service providers uses TLS encryption.
- Our hosting provider states that all customer data is encrypted at rest with AES-256 and in transit with TLS, and that it holds SOC 2 Type 2 and ISO 27001 certifications. Those are the provider's statements, not certifications held by FaceCard.
- Database rows and storage files are protected by row-level access rules, so your signed-in account can reach only your own records and files. Baseline photos are served through links that expire after one hour.
- Keys for our AI analysis provider and our SMS provider are held only on our servers, never in the app.
- Passwords are hashed by our hosting provider. Phone-verified accounts use a random credential no one can see. Sign-in codes expire within minutes.
- We never receive or store card numbers, and our server function never writes scan photos to storage or logs.
No electronic transmission or storage technology is perfectly secure, so we cannot guarantee that unauthorized third parties will never defeat our security. If we learn of a breach of security affecting your unencrypted personal information, we will notify you without unreasonable delay and within the time required by the law that applies to you. Where the FTC's Health Breach Notification Rule applies, we will notify affected users and the FTC no later than 60 calendar days after discovery. The notice will describe what happened, what information was involved, what we are doing, and what you can do.
10. Do We Collect Information From Minors?
In short: We do not knowingly collect data from or market to children under 13 years of age.
FaceCard is not directed to children under 13, and we ask that you be at least 13 to use it. Apple's age rating for the app is 12+. We do not knowingly collect personal information from a child under 13, and if we learn that we have, we will delete it. If you become aware of any data we may have collected from a child under 13, email support@facecard.app. For users under 18, we do not sell personal information, share it for targeted advertising, or use it for profiling.
11. What Are Your Privacy Rights?
In short: You may review, change, or delete your information at any time in the app, and depending on where you live you have additional rights under applicable data protection laws.
Controls inside the app.
- Delete your account. Settings, Delete Account, type DELETE, confirm. Immediate.
- Edit or clear your profile, including age, gender, ethnicity, and allergies. Settings, My Profile.
- Remove baseline photos. Progress, Your Baseline, Remove.
- Decline baseline saving. Tap "Not now" after your first scan. We will not ask again on that device.
- Skip scans. Scans run only when you start one.
- Notifications. Turn them off in Notification Settings or your device settings.
- Cycle tracking. Leave the cycle section of the journal off.
If you are in the EEA or the UK. You have the right to request access to and obtain a copy of your personal information, to request rectification or erasure, to restrict processing, to data portability, to object to processing based on our legitimate interests, and not to be subject to automated decision-making that produces legal or similarly significant effects. Your skin assessment is automated, as described in section 3, and has no such effects; you can ask us to explain a result. You may lodge a complaint with your local supervisory authority. In the UK, that is the Information Commissioner's Office at https://ico.org.uk.
Withdrawing your consent. Where we rely on your consent, you may withdraw it at any time using the controls above or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
Opting out of notifications. Turn off push notifications in the app's Notification Settings or in your device settings. We do not send marketing email or SMS. Sign-in codes are sent only when you request them.
Other regions. If you live outside the United States, the EEA, and the UK, you may have similar rights under local law. Contact us and we will respond under the law that applies to you.
If you have questions or comments about your privacy rights, email support@facecard.app.
12. Controls for Do-Not-Track Features
In short: We do not track you, so there is nothing for a Do-Not-Track signal to turn off.
The app contains no advertising or analytics trackers and does not track you across other companies' apps or websites. Because no uniform standard for recognizing Do-Not-Track signals has been adopted for mobile apps, we do not respond to them. Global Privacy Control signals request an opt-out from the sale or sharing of personal information; we do not sell or share personal information, so there is nothing to opt out of. If that ever changes, we will honor those signals where the law requires and update this notice.
13. Do United States Residents Have Specific Privacy Rights?
In short: Residents of states with comprehensive privacy laws have rights to know, access, correct, delete, and port their personal information, to opt out of sale, sharing, targeted advertising, and profiling, and to appeal our decisions. We extend these rights to every user in the United States.
What categories of personal information do we collect?
We have collected the following categories of personal information in the past twelve (12) months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, phone number, account identifier, internet address held by our service providers | YES |
| B. Personal information as defined in the California Customer Records statute | Name and contact information | YES |
| C. Protected classification characteristics under state or federal law | Age, gender, and ethnicity, if you provide them | YES |
| D. Commercial information | Subscription and purchase history | YES |
| E. Biometric information | Fingerprints, voiceprints, face templates used to identify a person | NO. We do not create identifier templates from your face; face photos are listed under H and L |
| F. Internet or other similar network activity | Server request logs held by our hosting provider | YES |
| G. Geolocation data | Device location | NO |
| H. Audio, electronic, visual, or similar information | Face photos taken for skin scans; optional profile photo | YES |
| I. Professional or employment-related information | Job title, work history | NO |
| J. Education information | Student records | NO |
| K. Inferences drawn from collected personal information | Skin assessment scores and observations generated from your scans and profile | YES |
| L. Sensitive personal information | Face photos, health information (skin assessments, allergies, cycle tracking), and ethnicity | YES |
We use and retain the collected personal information as described in sections 3 and 8. We collect it from you, your device, and the service providers in section 5, and we disclose it for business purposes only to those service providers. We have not sold or shared personal information for a business or commercial purpose in the preceding twelve (12) months, and we do not knowingly sell or share the personal information of anyone under 16. We offer no financial incentives in exchange for personal information.
Your rights
Depending on your state, you have some or all of the rights below. We honor them for every user in the United States, without first deciding whether a particular law applies to you.
- Right to know and access. Confirm whether we process your personal information and obtain a copy of it, with the categories, sources, purposes, and categories of recipients.
- Right to correct. Fix inaccurate information. Most of it can be edited in the app.
- Right to delete. The fastest way is Delete Account in Settings.
- Right to portability. Receive your information in a portable, readable format.
- Right to opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do none of these, so there is nothing to opt out of. If that ever changes, we will add an opt-out first.
- Right to limit the use of sensitive personal information. We use sensitive personal information only to provide the features you request, so we do not post a separate "Limit the Use of My Sensitive Personal Information" link. You may withdraw consent at any time as described in sections 2.3 and 11.
- Right to non-discrimination. We will not deny you the app, change the price, or lower service quality because you exercised a right. Features that depend on deleted data stop working.
How to exercise your rights
- Two ways to ask. Use the controls in section 11, or email support@facecard.app with the subject "Privacy request."
- Verification. In-app requests are verified by your signed-in session. For email requests, we match your request to the email address or phone number on your account and, if needed, send a one-time code to it. We use the information in your request only to verify you and act on it.
- Authorized agents. An agent may submit a request with your signed written permission, and we may ask you to confirm your identity directly.
- Timing. We respond within 45 days. If we need up to 45 more days, we will tell you why before the first period ends. In-app deletion is immediate.
- Appeal. If we decline a request, we will say why. To appeal, email support@facecard.app with the subject "Privacy appeal." Within 45 days of receiving your appeal, we will inform you in writing of any action taken or not taken, with our reasons. If your appeal is denied, you may contact your state attorney general.
- Cost. Free. If a request is clearly unfounded or repetitive, we may charge a reasonable fee or decline and explain why.
California residents
California Civil Code Section 1798.83, the "Shine the Light" law, permits California residents to request, once a year and free of charge, information about the categories of personal information we disclosed to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes. If you are under 18, reside in California, and have an account, you may request removal of content you publicly posted; FaceCard has no public posting features. California residents may also exercise the rights in this section, and our verification, timing, and appeal commitments above apply.
Washington, Nevada, and Connecticut residents
Skin assessments, allergies and sensitivities, cycle tracking, and inferences drawn from your face photos are "consumer health data" under the laws of these states. Our separate Consumer Health Data Privacy Policy describes that data, the categories of third parties that receive it, and how to exercise your rights. It applies to every user, wherever you live.
14. Do We Make Updates to This Notice?
In short: Yes, we will update this notice as necessary to stay accurate and compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top. If a change materially reduces your rights or expands how we use face data or sensitive information, we will ask for your consent again in the app before it applies to you. For other material changes, we will post a notice in the app. We encourage you to review this notice frequently.
Revision history. Version 3.0 (September 8, 2026) names FaceCard Technologies Inc., the app's owner, with its address; adds the Skin Journal, barcode lookups, the push notification provider, the AI provider's retention period, the retention schedule, the sensitive information table, state and EU/UK rights, breach notification, and the consumer health data notice; and corrects earlier statements about device data, usage logs, and photo storage. Version 2.0 (August 14, 2026) added a face data section, SMS sign-in, and the baseline photo option. Version 1.0 (October 19, 2025) was the first policy, published for the app under the name Glowmate.
15. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, email us at support@facecard.app or contact us by post at:
FaceCard Technologies Inc., 25634 Moore Lane, Stevenson Ranch, CA 91381, United States.
Subject lines that speed things up: "Privacy request," "Privacy appeal," or "Face data." We aim to acknowledge every privacy email within 10 business days.
16. How Can You Review, Update, or Delete the Data We Collect From You?
You can review and update your information in the app under Settings, then My Profile, and delete your account and all of its data under Settings, then Delete Account. You may also email support@facecard.app to request access to, correction of, or deletion of your personal information, or to ask for the names of our service providers. We will respond within the periods described in section 13.
Related documents. Consumer Health Data Privacy Policy. Terms of Use: the app is licensed under Apple's Licensed Application End User License Agreement.
Back to top ↑