Skinmetric
Privacy policy
Last updated July 29, 2026
Skinmetric ("we", "us") is a skin-tracking app from aqx.llc. This policy explains what we collect when you use the app or this website, why, how long we keep it, and how to control or delete it. It's written to match what the running code actually does — the retention windows below are the same ones enforced by our own database and are also published, table-form, on ourretention schedule.
Skinmetric is a cosmetic/wellness product for users 18 and older. It provides AI cosmetic analysis, not medical advice, diagnosis, or treatment — see "Not medical advice" below.
The short version
- Your original photos are never uploaded. They stay encrypted on your device.
- Only a normalized crop is sent for analysis, and only when you ask for one.
- That crop is deleted from our servers immediately after analysis.
- Cloud backup is off unless you turn it on, purpose by purpose.
- Every number we show is a change versus your own baseline — never a score, never compared to anyone else.
What we collect
Photos and scans
Original photos never leave your device — there is no server-side column or storage bucket for them anywhere in our systems. When you request an analysis, the app sends a normalized, cropped version of the relevant region over your authenticated session to our Analysis vendor (below). That crop is hard-deleted from our servers as soon as the analysis completes; a nightly automated sweep is a backstop that purges anything that should already be gone. We never claim data is "deleted immediately" without naming any window that still applies — see the vendor window below.
Appearance metrics
What comes back from analysis is a short list of appearance readings (for example, hydration index, texture uniformity, visible redness) — never the image itself. These are stored, versioned, against your account so we can show your own timeline. They are never converted into a single score, percentile, or comparison against anyone else.
Account and device identity
We use anonymous, device-first sessions by default; an account (Sign in with Apple, Google, or email) is only requested at the payment step, and attaches to your existing anonymous session rather than starting over. We store the identifiers needed to operate your account (user ID, sign-in identity, device session metadata) and your subscription/entitlement state.
Consent records
Camera and landmark capture, sending a crop for analysis, and cloud backup are each asked for separately, and each can be turned off separately. We keep a record of what you consented to and when, as evidence of that choice; if you revoke a consent, the revocation record is kept for a limited window (see the retention schedule) rather than deleted immediately, so we can demonstrate compliance if asked.
The analysis vendor
Cosmetic-analysis crops are processed by Anthropic, our AI vision-analysis provider. Your crop is never used to train Anthropic's models. We delete our own copy immediately after analysis, but Anthropic may retain the request for a limited period under its own API data-retention window (currently around seven days) that is outside our control — we disclose that window rather than implying the data is gone everywhere the moment our own copy is.
Cloud backup (opt-in)
Cloud backup is a separate, purpose-scoped consent you can turn on after purchase. When it's on, your photos and scan history are encrypted on your device before anything is sent — what we store is the encrypted copy, never the original. The encryption key stays on your device and is never sent to us: if every device that ever held that key is lost or erased before backup is turned off, the encrypted copy cannot be decrypted by anyone, including us. Turning backup off, or deleting your account, removes the encrypted copy from our servers; every removal is written to an internal, audited log.
Your controls
The in-app Privacy Center is where these mechanics live, not just this page:
- Manage consents — turn camera capture, analysis upload, or cloud backup on or off individually, any time.
- Export your data — download your photos and scan history from your device, plus your appearance readings from our servers.
- Delete everything — permanently deletes your account and every server-side record (scans, appearance readings, consents, any cloud backup), then erases the encrypted photo store on your device. This cannot be undone.
Not medical advice
Skinmetric provides AI cosmetic analysis, not medical advice, diagnosis, or treatment. It uses appearance language only (for example, visible redness, texture uniformity) and never diagnostic or treatment vocabulary. If you have a medical concern about your skin, talk to a licensed clinician.
Regional notices
Some regions require a standalone notice or written release for health or biometric data before capture. The in-app consent flow includes a region picker covering:
- Illinois — a BIPA written-release notice.
- Washington — a My Health My Data Act standalone notice (not bundled with other terms).
- Colorado — a Colorado Privacy Act biometric-identifier notice.
TODO(counsel): final notice text per region is pending legal review (src/features/consent/region-notices.ts) — the picker and its placeholder headings already exist so the real text is a drop-in, not a redesign.
Children's privacy
Skinmetric is not directed at, and may not be used by, anyone under 18. Age is confirmed at onboarding. We do not knowingly collect data from anyone under 18.
Changes to this policy
If we materially change what we collect or how long we keep it, we'll update this page and the "Last updated" date above, and update the retention schedule and in-app disclosures in the same change (rule 7 spirit: the doc and the code never disagree on purpose).
Contact
Questions, data requests, or deletion requests: [email protected], or use Delete Everything in the app's Privacy Center directly.