FACECARD
How it worksInside the appFAQGet the app ↗
Legal

Privacy Policy

Last updated: September 8, 2026Effective date: September 8, 2026Version: 3.0

This privacy notice for FaceCard Technologies Inc. ("we," "us," or "our") describes how and why we might collect, store, use, and share ("process") your information when you use our services ("Services"), such as when you download and use our mobile application, FaceCard – AI Dermatologist (formerly published as "Glowmate"), visit our website, or contact us. FaceCard Technologies Inc. is a Delaware corporation with its principal office at 25634 Moore Lane, Stevenson Ranch, CA 91381. Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have questions, contact us at support@facecard.app.

On this page

  1. Summary of Key Points
  2. 1. What Information Do We Collect?
  3. 2. How Do We Handle Face Data?
  4. 3. How Do We Process Your Information?
  5. 4. What Legal Bases Do We Rely On to Process Your Personal Information?
  6. 5. When and With Whom Do We Share Your Personal Information?
  7. 6. What Is Our Stance on Third-Party Websites?
  8. 7. Is Your Information Transferred Internationally?
  9. 8. How Long Do We Keep Your Information?
  10. 9. How Do We Keep Your Information Safe?
  11. 10. Do We Collect Information From Minors?
  12. 11. What Are Your Privacy Rights?
  13. 12. Controls for Do-Not-Track Features
  14. 13. Do United States Residents Have Specific Privacy Rights?
  15. 14. Do We Make Updates to This Notice?
  16. 15. How Can You Contact Us About This Notice?
  17. 16. How Can You Review, Update, or Delete the Data We Collect From You?

Health data has its own notice. Read the Consumer Health Data Privacy Policy.

Summary of Key Points

This summary gives the key points of our privacy notice. You can find more detail on any topic by following the link after each point or by using the table of contents.

What personal information do we process? When you use our Services, we process the information you give us, such as your name, contact details, skin profile, and the selfies you take for a skin scan, together with the results our Services generate for you. Learn more about the information we collect.

Do we process sensitive personal information? Yes. With your consent, we process face photos, skin condition assessments, allergies and sensitivities, cycle tracking entries if you choose to record them, and ethnicity if you choose to provide it. Learn more about sensitive information.

How do we handle face data? Selfies you take in the app are analyzed to describe your visible skin. We do not identify you from your face, we do not create biometric templates, we do not train AI on your photos, and we do not keep your daily scan photos on our servers. Learn more about face data.

Do we receive information from third parties? Only what is needed to run the Services: your name and email from Apple if you use Sign in with Apple, your subscription status from Apple's payment systems, product details from public product databases when you scan a barcode, and the skin assessment returned by our AI analysis provider.

How do we process your information? To provide, improve, and administer our Services, communicate with you, keep the Services secure, and comply with law. Learn more about how we process your information.

When and with whom do we share personal information? Only with service providers that work on our behalf under written contracts, with Apple for payments and sign-in, and as required by law. We do not sell personal information and we do not share it for advertising. Learn more about when and with whom we share information.

How do we keep your information safe? Encryption in transit, encryption at rest by our hosting provider, and access rules that limit each account to its own records. No system is perfectly secure, so we also commit to notifying you if a breach affects you. Learn more about security.

What are your rights? Depending on where you live, you may have rights to access, correct, delete, and port your information, to withdraw consent, and to appeal our decisions. Learn more about your privacy rights.

How do you exercise your rights? The easiest way is inside the app: Settings, then Delete Account, or Settings, then My Profile. You can also email support@facecard.app. We act on every request in accordance with applicable data protection laws.

1. What Information Do We Collect?

Personal information you disclose to us

In short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide when you create an account, complete onboarding, use features of the app, or contact us. The personal information we collect depends on the features you use and may include:

  • Account and contact details. Name, email address, and phone number. If you use Sign in with Apple, Apple sends us an identity token, your email address (which may be an Apple private relay address), and your name on first sign-in. If you sign in with an email address and password, our hosting provider stores only a hashed version of the password. Phone-verified accounts receive a random credential that is never shown to anyone.
  • Skin profile. Skin type, recent skin changes, the area you want to improve, lifestyle, routine depth, active ingredients you use, and an environment choice such as "Sunny and dry." The environment choice is self-reported; the app does not use GPS or any location service.
  • Optional profile details. Age, gender, and a profile photo chosen from your photo library. Available in Settings, under My Profile, and may be left blank.
  • Selfies. Three photos of your face taken with the device camera during a skin scan. See section 2.
  • Skin Journal entries. Sleep, water intake, stress, diet, exercise, free-text notes, and, if you turn it on, cycle tracking.
  • Product shelf. Products you add, including name, brand, category, how much is left, when you used it, an image link, and your notes. If you scan a product barcode, the app decodes it on your device and sends only the barcode number to public product databases to look up the product.
  • Feedback and support messages. Anything you type in the in-app feedback prompt or send to us by email.

All personal information you provide must be true, complete, and accurate, and you should update it in the app if it changes.

Sensitive information

When necessary, with your consent, we process the following categories of sensitive information:

Sensitive informationHow you consentPurposeHow to withdraw
Face photos and the skin assessment derived from themThe Face Data notice before your first scanSkin assessment, routine, progressSection 2.3
Skin condition assessments, allergies, and sensitivitiesYou enter them in onboarding or My Profile after a short noticeCalibrate the assessment; warn you when a suggested product contains something you react toEdit or clear them in My Profile
EthnicityOptional field in My Profile with a "Prefer not to say" choice and a short noticeCalibrate the assessment, because skin presents differently across skin tonesChoose "Prefer not to say" or clear it
Cycle tracking (period and cycle day)You turn it on in the Skin Journal after a short noticeShow patterns between your cycle and your skin scoresTurn it off and clear past entries

We do not use sensitive information to infer anything beyond the stated purpose, for advertising, or for sale or sharing.

Payment data

Purchases are made through Apple In-App Purchase. Apple collects the data necessary to process your payment. We never receive or store card numbers. You can find Apple's privacy notice at https://www.apple.com/legal/privacy.

Application data

If you use our app, we may also collect the following information if you choose to give us access or permission:

  • Camera. Used only for skin scans and for reading product barcodes. Barcode scanning does not capture or send an image. The camera library used by the app may show a microphone permission string; the app does not record audio.
  • Photo library. Used only if you choose a profile photo. Scans never read your photo library.
  • Push notifications. If you allow notifications, we store the token that identifies your device, with your platform, to send routine reminders, an occasional message if you have not used the app for a while, and occasional announcements. You can turn notifications off in the app's Notification Settings or in your device settings.

You can change these permissions at any time in your device settings.

Information automatically collected

In short: Our own code does not collect device or usage analytics. Our service providers receive the standard technical information any internet connection produces.

The app contains no analytics, crash-reporting, or advertising software, and our code does not collect your device model, operating system version, advertising identifier, or usage analytics. When the app connects to our service providers, they receive standard technical data such as your internet address, and our subscription provider and Apple collect standard device information through their software. Our hosting provider keeps server request logs for a short period, no longer than 90 days.

On your device only. Your sign-in session, reminder times, your answer to the baseline prompt, and a daily and monthly scan counter stay in private storage on your phone and are not sent to us. We do not use cookies.

2. How Do We Handle Face Data?

In short: Selfies you take in the app are analyzed to describe your visible skin. We do not identify you from your face, we do not create biometric templates, we do not train AI on your photos, and we do not keep your daily scan photos on our servers.

This section answers, in order, the four questions Apple requires face-data apps to answer. "Face data" means the selfies you take in the app and the information derived from them.

2.1 Collection, all intended uses, and disclosures

What we collect. When you run a skin scan, the app uses the device camera to capture three photos of your face: front, left profile, and right profile. On your device, each photo is reduced to about 1024 pixels wide and compressed as a JPEG before it is sent anywhere.

Consent. Before your first scan, the app shows a Face Data notice that states what is captured, why, where the photos go, how long they are kept, and how to withdraw. The scan does not start until you tap "I agree." You can decline and still use the rest of the app.

All intended uses. We use face data for these purposes and no others:

  • To produce a written skin assessment: scores for hydration, texture, tone, radiance, clarity, spots, breakouts, and puffiness, plus text observations.
  • To build your routine and product suggestions from that assessment.
  • To show your progress over time, using the stored scores from each scan.
  • If you opt in, to keep your first three photos as a private baseline you can view later.

Disclosures. Each scan is sent over an encrypted connection to a server function run by our cloud hosting provider. That function forwards the three photos, with a written prompt, to our AI analysis provider, a third-party artificial intelligence service that returns the assessment. The prompt includes the profile details that calibrate the analysis: age, gender, ethnicity, skin type, recent skin changes, lifestyle, routine depth, active ingredients, and allergies or sensitivities. It does not include your name, email address, phone number, or account identifier. Our server function does not write the photos to a database, file storage, or logs. No other company receives your face data.

What we do not do. We do not identify you or anyone else from your face, create face templates or any biometric identifier, or match your face against other photos or databases. We do not use face data to train AI models, and our AI analysis provider does not use the data we send it to train its models. We do not use face data for advertising, sell it, or share it for anyone else's purposes.

2.2 Sharing and retention

Who receives face data. Only our cloud hosting provider, which runs the server function that relays the photos, and our AI analysis provider, which analyzes them. Both act as our service providers under written terms and only on our instructions. We will tell you the names of these providers if you ask, using the contact details in section 15.

Retention schedule and destruction guidelines. We keep face data only as long as needed for the purpose you requested, and never longer than the periods below.

Face data elementWhere it is heldHow longHow it is destroyed
Daily scan photos in transitOur server function at our hosting providerOnly for the seconds the analysis takes; never written to storageDiscarded from memory when the request finishes
Daily scan photos at our AI analysis providerThe provider's API systemsUp to 30 days for abuse and misuse monitoring, then deleted; not used for trainingDeleted by the provider under its published data controls
Daily scan photos on your deviceThe app's private cache folder on your phoneUntil your operating system clears the app cache or you delete the app; not saved to your Photos library; never uploaded againCleared by the operating system, or removed when you uninstall
Baseline photos (opt-in only)A private storage folder at our hosting provider that only your signed-in account can openUntil you remove them in Progress, you delete your account, or your account is inactive for 3 years, whichever comes firstPermanently deleted from storage
Assessment results (scores and text)Our database at our hosting providerUntil you delete your account, or your account is inactive for 3 years, whichever comes firstDeleted with your account
File path text for scan photosOur database, stored with each resultSame as assessment resultsDeleted with your account
Profile details sent with the photosThe AI analysis provider's API systemsUp to 30 days, as aboveDeleted by the provider

"Inactive" means no sign-in and no scan for 3 years. We delete face data sooner once its purpose has been satisfied. If a law requires us to keep a specific record longer, we keep only that record for the required period.

Our AI analysis provider's handling. The provider's published data controls state that data sent through its API is not used to train or improve its models and that abuse monitoring logs are kept for up to 30 days, unless a longer period is required by law or needed to protect its services or a third party from harm. We have not enabled the provider's zero-retention option.

2.3 Deletion and how to revoke consent

You can withdraw consent to face data collection or use at any time. Past results stay in your account unless you delete them.

  • Stop scanning. No new face data is collected unless you start a scan.
  • Remove baseline photos. Open Progress, tap Your Baseline, then Remove. The photos are permanently deleted from our storage right away.
  • Delete your account and all face data. Open Settings, tap Delete Account, type DELETE, and confirm. The app deletes your profile and baseline photos from storage, then deletes your account with everything in it, including assessment results, file paths, journal, profile, push tokens, and phone verification records. This takes effect immediately.
  • Email us. Write to support@facecard.app from the email address on your account, or include your account phone number. We verify you as described in section 13 and complete the deletion within 45 days, usually much sooner.
  • Photos at our AI analysis provider are deleted under the 30-day limit above. We cannot delete them earlier.
  • Photos on your device. Delete the app, or clear its storage in your device settings.

Copies in our hosting provider's routine backups are overwritten within 30 days.

2.4 Third-party protection

Our AI analysis provider is the only third party with whom we share face data, and our hosting provider is the only provider that relays it. Each is bound by written terms requiring it to provide the same or equal protection for face data described in this policy, to use it only to provide its service to us, and not to disclose it to anyone else except as needed for that service. Neither may use your face data for advertising, identification, or model training. If we ever add another recipient, we will update this policy first and require the same commitment.

3. How Do We Process Your Information?

In short: We process your information to provide, improve, and administer our Services, communicate with you, keep the Services secure, and comply with law. We may also process your information for other purposes with your consent.

We process your personal information for the following reasons:

  • To create and manage your account. Including signing you in, sending one-time sign-in codes, and answering your requests.
  • To deliver the skin assessment you request. Your selfies and skin profile are analyzed to produce scores, observations, a routine, and product suggestions.
  • To show your progress and baseline. Using stored assessment results and, if you opt in, baseline photos.
  • To show patterns between your habits and your skin. Using Skin Journal entries and assessment results. These comparisons are calculated on your device, and journal entries are never sent to our AI analysis provider.
  • To keep your product shelf and look up products you scan.
  • To warn you when a suggested product contains an ingredient you react to.
  • To manage your subscription and to test which of two paywall designs works better.
  • To send reminders and service messages by push notification, if you allow them.
  • To protect the Services, prevent abuse, and keep records the law requires.

AI processing. Your assessment is produced automatically by an AI model and is informational only. It is not medical advice, a diagnosis, or a treatment plan, and it does not replace a dermatologist or other qualified professional. The results have no legal or similarly significant effects, and no one at FaceCard reviews your photos. If you disagree with a result, you can rerun a scan, adjust your profile, or contact us.

Marketing. We do not send marketing email or SMS. Push notifications include routine reminders, an occasional message if you have not used the app for a while, and occasional announcements. You can turn them off at any time.

4. What Legal Bases Do We Rely On to Process Your Personal Information?

In short: We process your personal information only when we have a valid legal reason to do so, such as your consent, a contract with you, a legal obligation, or our legitimate interests.

FaceCard is offered in the European Economic Area (except France) and the United Kingdom. If you are located in the EEA or the UK, the General Data Protection Regulation and the UK GDPR require us to explain the legal bases we rely on:

PurposeInformation usedLegal basis
Create and secure your account, sign you in, send one-time codesAccount and contact details, phone verification recordsContract
Analyze your skin and produce your assessment, routine, and product suggestionsFace data, skin profile, allergies, ethnicity, assessment resultsExplicit consent for face data, health data, and ethnicity; contract for the rest
Show your progress and baselineAssessment results, baseline photosConsent
Show patterns between your habits and your skinSkin Journal, assessment resultsExplicit consent
Keep your product shelf and look up products you scanProduct shelf, barcode numbersContract
Warn you when a suggested product contains an ingredient you react toAllergies and sensitivities, product dataExplicit consent
Manage your subscription and test which paywall design works betterSubscription information, account identifierContract; legitimate interest in improving the Services
Send reminders and service messagesPush token, first name, scan datesConsent for notifications; legitimate interest in service messages
Answer your questions and requestsContact details, feedbackContract; legal obligation for rights requests
Protect the Services, prevent abuse, keep records the law requiresAccount information, server logs, subscription recordsLegitimate interest; legal obligation

Where we rely on consent, including explicit consent for face photos, health information, and ethnicity, you may withdraw it at any time as described in section 11.

5. When and With Whom Do We Share Your Personal Information?

In short: We share information only with service providers that work on our behalf, with Apple for payments and sign-in, and as required by law. We do not sell personal information and we do not share it for advertising.

Service providers. We share your data with third-party service providers that perform services for us and need access to the information to do that work. We have written contracts with each of them designed to safeguard your personal information. They may not use your personal information for anything other than the service they provide to us, they may not share it with any organization apart from us except as needed to provide that service, and they must protect it and retain it only for the period we instruct. The categories of service providers we share personal information with are:

Service provider categoryWhat it receivesWhyProtection commitment
AI analysis providerThree face photos per scan and the profile details listed in section 2.1Produce your skin assessmentWritten terms; no training on inputs; up to 30-day retention; same or equal protection for face data
Cloud hosting and database providerEverything stored in your account, including baseline photos; relays scan photosHost our database, storage, sign-in, and server functionsData processing agreement; encryption at rest and in transit; row-level access controls
SMS delivery providerYour phone number and the one-time codeDeliver SMS sign-in codesData processing agreement
Subscription management providerYour account identifier, Apple purchase receipt, paywall label, and standard device information collected by its softwareManage subscriptionsWritten terms; processor obligations
Push notification delivery providerYour push notification token and the text of each notificationDeliver push notificationsWritten terms; Data Privacy Framework participant
Public product databasesThe barcode you scan and your device's internet addressLook up product details for your shelfBarcode only; no personal information sent

We will provide the names of our service providers on request. Use the contact details in section 15.

Apple. Apple processes your payments, provides Sign in with Apple, distributes the app through the App Store, and shows the native review prompt. Apple acts as an independent controller for those services under its own privacy policy at https://www.apple.com/legal/privacy.

Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or part of our business. The successor is bound by this policy until it notifies you of changes.

Legal requirements. We may disclose your information if required to do so by law or in response to a valid legal demand. We review every demand and notify you where the law allows.

6. What Is Our Stance on Third-Party Websites?

In short: We are not responsible for information you share with third-party websites we link to.

Product suggestions in the app link to Amazon with an affiliate tag. We may earn a commission if you buy through such a link. We send Amazon no personal information and learn nothing about what you buy. The app also links to educational pages such as the American Academy of Dermatology. Once you leave the app, the other site's privacy policy governs. We do not guarantee the safety or privacy of data you provide to any third party, and the inclusion of a link does not imply endorsement. You should review the policies of those third parties and contact them directly with questions.

7. Is Your Information Transferred Internationally?

In short: Our servers and our service providers are located in the United States.

We are based in the United States. Your account data is stored on servers located in the United States, and our service providers process information there. If you use FaceCard from another country, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country. For users in the EEA and the UK, each of our service providers is covered by one of the following safeguards: certification to the EU-U.S. Data Privacy Framework and the UK Extension, or the European Commission's Standard Contractual Clauses with the UK Addendum under a data processing agreement. Our AI analysis provider, our hosting provider, and our subscription management provider rely on the Standard Contractual Clauses with the UK Addendum. Our SMS and push notification providers are certified to the Data Privacy Framework and its UK Extension. Details of the safeguard that applies to a particular provider can be provided on request.

8. How Long Do We Keep Your Information?

In short: We keep your information for as long as your account is active, unless you delete it sooner, and we delete accounts that have been inactive for 3 years.

CategoryKept untilDestroyed by
Account and contact detailsAccount deletion, or 3 years of inactivityDeleted with the account
Phone verification proofsExpire minutes after issue; removed on use and on account deletionAutomatic deletion
Skin profile, including ethnicity and allergiesAccount deletion, or when you clear the fieldDeleted with the account or on edit
Profile photoYou replace or remove it, or account deletionDeleted from storage
Daily scan photosSee section 2.2See section 2.2
Baseline photosYou remove them, account deletion, or 3 years of inactivityPermanently deleted from storage
Assessment results and photo file pathsAccount deletion, or 3 years of inactivityDeleted with the account
Skin JournalAccount deletion, or when you delete an entryDeleted with the account or on edit
Product shelfAccount deletion, or when you remove a productDeleted with the account or on edit
Subscription status and datesAccount deletion; transaction records are kept by Apple and our subscription provider under their policies and by us for as long as tax and accounting law requires, generally up to 7 yearsDeleted or archived
Push notification tokenYou turn notifications off, sign out, or account deletionDeleted
FeedbackThe text is kept for product improvement; your account identifier is removed when you delete your account, so the text becomes anonymousAnonymized
Server request logs held by our hosting providerNo longer than 90 daysAutomatic rollover
Copies at our AI analysis providerUp to 30 daysDeleted by the provider
Email correspondence with support2 years after the last message in the threadDeleted

When you delete your account, deletion happens immediately in our live systems. Copies in our hosting provider's routine backups are overwritten within 30 days.

9. How Do We Keep Your Information Safe?

In short: We protect your personal information through technical and organizational security measures, and we will notify you if a breach affects you.

  • Every connection between the app, our servers, and our service providers uses TLS encryption.
  • Our hosting provider states that all customer data is encrypted at rest with AES-256 and in transit with TLS, and that it holds SOC 2 Type 2 and ISO 27001 certifications. Those are the provider's statements, not certifications held by FaceCard.
  • Database rows and storage files are protected by row-level access rules, so your signed-in account can reach only your own records and files. Baseline photos are served through links that expire after one hour.
  • Keys for our AI analysis provider and our SMS provider are held only on our servers, never in the app.
  • Passwords are hashed by our hosting provider. Phone-verified accounts use a random credential no one can see. Sign-in codes expire within minutes.
  • We never receive or store card numbers, and our server function never writes scan photos to storage or logs.

No electronic transmission or storage technology is perfectly secure, so we cannot guarantee that unauthorized third parties will never defeat our security. If we learn of a breach of security affecting your unencrypted personal information, we will notify you without unreasonable delay and within the time required by the law that applies to you. Where the FTC's Health Breach Notification Rule applies, we will notify affected users and the FTC no later than 60 calendar days after discovery. The notice will describe what happened, what information was involved, what we are doing, and what you can do.

10. Do We Collect Information From Minors?

In short: We do not knowingly collect data from or market to children under 13 years of age.

FaceCard is not directed to children under 13, and we ask that you be at least 13 to use it. Apple's age rating for the app is 12+. We do not knowingly collect personal information from a child under 13, and if we learn that we have, we will delete it. If you become aware of any data we may have collected from a child under 13, email support@facecard.app. For users under 18, we do not sell personal information, share it for targeted advertising, or use it for profiling.

11. What Are Your Privacy Rights?

In short: You may review, change, or delete your information at any time in the app, and depending on where you live you have additional rights under applicable data protection laws.

Controls inside the app.

  • Delete your account. Settings, Delete Account, type DELETE, confirm. Immediate.
  • Edit or clear your profile, including age, gender, ethnicity, and allergies. Settings, My Profile.
  • Remove baseline photos. Progress, Your Baseline, Remove.
  • Decline baseline saving. Tap "Not now" after your first scan. We will not ask again on that device.
  • Skip scans. Scans run only when you start one.
  • Notifications. Turn them off in Notification Settings or your device settings.
  • Cycle tracking. Leave the cycle section of the journal off.

If you are in the EEA or the UK. You have the right to request access to and obtain a copy of your personal information, to request rectification or erasure, to restrict processing, to data portability, to object to processing based on our legitimate interests, and not to be subject to automated decision-making that produces legal or similarly significant effects. Your skin assessment is automated, as described in section 3, and has no such effects; you can ask us to explain a result. You may lodge a complaint with your local supervisory authority. In the UK, that is the Information Commissioner's Office at https://ico.org.uk.

Withdrawing your consent. Where we rely on your consent, you may withdraw it at any time using the controls above or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.

Opting out of notifications. Turn off push notifications in the app's Notification Settings or in your device settings. We do not send marketing email or SMS. Sign-in codes are sent only when you request them.

Other regions. If you live outside the United States, the EEA, and the UK, you may have similar rights under local law. Contact us and we will respond under the law that applies to you.

If you have questions or comments about your privacy rights, email support@facecard.app.

12. Controls for Do-Not-Track Features

In short: We do not track you, so there is nothing for a Do-Not-Track signal to turn off.

The app contains no advertising or analytics trackers and does not track you across other companies' apps or websites. Because no uniform standard for recognizing Do-Not-Track signals has been adopted for mobile apps, we do not respond to them. Global Privacy Control signals request an opt-out from the sale or sharing of personal information; we do not sell or share personal information, so there is nothing to opt out of. If that ever changes, we will honor those signals where the law requires and update this notice.

13. Do United States Residents Have Specific Privacy Rights?

In short: Residents of states with comprehensive privacy laws have rights to know, access, correct, delete, and port their personal information, to opt out of sale, sharing, targeted advertising, and profiling, and to appeal our decisions. We extend these rights to every user in the United States.

What categories of personal information do we collect?

We have collected the following categories of personal information in the past twelve (12) months:

CategoryExamplesCollected
A. IdentifiersName, email address, phone number, account identifier, internet address held by our service providersYES
B. Personal information as defined in the California Customer Records statuteName and contact informationYES
C. Protected classification characteristics under state or federal lawAge, gender, and ethnicity, if you provide themYES
D. Commercial informationSubscription and purchase historyYES
E. Biometric informationFingerprints, voiceprints, face templates used to identify a personNO. We do not create identifier templates from your face; face photos are listed under H and L
F. Internet or other similar network activityServer request logs held by our hosting providerYES
G. Geolocation dataDevice locationNO
H. Audio, electronic, visual, or similar informationFace photos taken for skin scans; optional profile photoYES
I. Professional or employment-related informationJob title, work historyNO
J. Education informationStudent recordsNO
K. Inferences drawn from collected personal informationSkin assessment scores and observations generated from your scans and profileYES
L. Sensitive personal informationFace photos, health information (skin assessments, allergies, cycle tracking), and ethnicityYES

We use and retain the collected personal information as described in sections 3 and 8. We collect it from you, your device, and the service providers in section 5, and we disclose it for business purposes only to those service providers. We have not sold or shared personal information for a business or commercial purpose in the preceding twelve (12) months, and we do not knowingly sell or share the personal information of anyone under 16. We offer no financial incentives in exchange for personal information.

Your rights

Depending on your state, you have some or all of the rights below. We honor them for every user in the United States, without first deciding whether a particular law applies to you.

  • Right to know and access. Confirm whether we process your personal information and obtain a copy of it, with the categories, sources, purposes, and categories of recipients.
  • Right to correct. Fix inaccurate information. Most of it can be edited in the app.
  • Right to delete. The fastest way is Delete Account in Settings.
  • Right to portability. Receive your information in a portable, readable format.
  • Right to opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do none of these, so there is nothing to opt out of. If that ever changes, we will add an opt-out first.
  • Right to limit the use of sensitive personal information. We use sensitive personal information only to provide the features you request, so we do not post a separate "Limit the Use of My Sensitive Personal Information" link. You may withdraw consent at any time as described in sections 2.3 and 11.
  • Right to non-discrimination. We will not deny you the app, change the price, or lower service quality because you exercised a right. Features that depend on deleted data stop working.

How to exercise your rights

  • Two ways to ask. Use the controls in section 11, or email support@facecard.app with the subject "Privacy request."
  • Verification. In-app requests are verified by your signed-in session. For email requests, we match your request to the email address or phone number on your account and, if needed, send a one-time code to it. We use the information in your request only to verify you and act on it.
  • Authorized agents. An agent may submit a request with your signed written permission, and we may ask you to confirm your identity directly.
  • Timing. We respond within 45 days. If we need up to 45 more days, we will tell you why before the first period ends. In-app deletion is immediate.
  • Appeal. If we decline a request, we will say why. To appeal, email support@facecard.app with the subject "Privacy appeal." Within 45 days of receiving your appeal, we will inform you in writing of any action taken or not taken, with our reasons. If your appeal is denied, you may contact your state attorney general.
  • Cost. Free. If a request is clearly unfounded or repetitive, we may charge a reasonable fee or decline and explain why.

California residents

California Civil Code Section 1798.83, the "Shine the Light" law, permits California residents to request, once a year and free of charge, information about the categories of personal information we disclosed to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes. If you are under 18, reside in California, and have an account, you may request removal of content you publicly posted; FaceCard has no public posting features. California residents may also exercise the rights in this section, and our verification, timing, and appeal commitments above apply.

Washington, Nevada, and Connecticut residents

Skin assessments, allergies and sensitivities, cycle tracking, and inferences drawn from your face photos are "consumer health data" under the laws of these states. Our separate Consumer Health Data Privacy Policy describes that data, the categories of third parties that receive it, and how to exercise your rights. It applies to every user, wherever you live.

14. Do We Make Updates to This Notice?

In short: Yes, we will update this notice as necessary to stay accurate and compliant with relevant laws.

We may update this privacy notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top. If a change materially reduces your rights or expands how we use face data or sensitive information, we will ask for your consent again in the app before it applies to you. For other material changes, we will post a notice in the app. We encourage you to review this notice frequently.

Revision history. Version 3.0 (September 8, 2026) names FaceCard Technologies Inc., the app's owner, with its address; adds the Skin Journal, barcode lookups, the push notification provider, the AI provider's retention period, the retention schedule, the sensitive information table, state and EU/UK rights, breach notification, and the consumer health data notice; and corrects earlier statements about device data, usage logs, and photo storage. Version 2.0 (August 14, 2026) added a face data section, SMS sign-in, and the baseline photo option. Version 1.0 (October 19, 2025) was the first policy, published for the app under the name Glowmate.

15. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, email us at support@facecard.app or contact us by post at:

FaceCard Technologies Inc., 25634 Moore Lane, Stevenson Ranch, CA 91381, United States.

Subject lines that speed things up: "Privacy request," "Privacy appeal," or "Face data." We aim to acknowledge every privacy email within 10 business days.

16. How Can You Review, Update, or Delete the Data We Collect From You?

You can review and update your information in the app under Settings, then My Profile, and delete your account and all of its data under Settings, then Delete Account. You may also email support@facecard.app to request access to, correction of, or deletion of your personal information, or to ask for the names of our service providers. We will respond within the periods described in section 13.

Related documents. Consumer Health Data Privacy Policy. Terms of Use: the app is licensed under Apple's Licensed Application End User License Agreement.

Back to top ↑

Health data has its own notice. Read the Consumer Health Data Privacy Policy.

FACECARD
Privacy policyConsumer health dataTerms of useApp Store
© 2026 FaceCard Technologies

FaceCard provides informational skincare insights and is not a substitute for professional medical advice, diagnosis, or treatment. Consult a qualified healthcare professional about medical concerns. The app is free to download. All features require an active subscription.