LooksLab ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services. We take your privacy seriously and are committed to being transparent about our data practices.
We collect the following types of image data when you use our scan features:
Important: We do NOT collect biometric identifiers for identity verification, facial recognition, or authentication purposes. All image data is collected solely for appearance analysis, health insights, and progress tracking.
In-App Consent: Before your photos are sent to any third-party AI service for the first time, the app displays a clear disclosure screen explaining what data is sent, who processes it, and how it is retained. You must explicitly agree before any data is transmitted.
Third-Party Processing: Your photos are shared with a third-party AI analysis service (currently OpenRouter, which routes requests to AI models) to provide core app functionality including facial analysis, hair analysis, food analysis, personalized recommendations, and progress tracking. This sharing is essential for the app to function properly. The AI service processes your images in real-time and does not retain them after analysis completion.
We may collect personal information such as your name, email address, age, and other demographic information you choose to provide when creating an account or using our services.
We collect device and usage information to provide analytics, attribution, and improve our services:
We use Sentry, a third-party service, to monitor app performance and track crashes to improve app reliability. Sentry collects:
We use PostHog to understand how users interact with our app to improve the user experience. PostHog collects:
This data does not include your facial images, personal information, or any content you create in the app. Both services use randomly generated device IDs that cannot identify you personally across app installations.
We use your photos exclusively for the following purposes:
We do NOT use your photos for: Identity verification, facial recognition, advertising targeting, sharing with marketers, creating user profiles for non-app purposes, or any commercial use beyond the core app functionality.
Service Provider: We use OpenRouter, an AI routing service, to transmit your photos to AI models for analysis. OpenRouter may route requests to underlying AI model providers (such as Google or Anthropic) depending on availability and performance.
Data Shared: Your face, hair, or food photographs are transmitted for analysis processing. This includes the raw image data and basic metadata (timestamp, image dimensions).
Purpose: The AI service processes your images to generate analysis scores, identify features, and provide personalized recommendations. This processing is essential for our app's core functionality.
User Consent: The app displays a clear disclosure and requests your explicit consent before transmitting any photos to the AI service for the first time.
Data Handling: The AI service processes images in real-time and does not store or retain your images after analysis completion. Processing typically takes 2-10 seconds per image.
Storage Location: During processing, images are temporarily held on the AI provider's secure servers and are automatically deleted immediately after analysis.
Provider Responsibilities: OpenRouter and its underlying AI model providers are contractually prohibited from using your data for their own training or commercial purposes. Their handling of your data is governed by their respective privacy policies.
Data Shared: Device identifiers (IDFA, IDFV, GAID), app install events, in-app purchase events, and user engagement metrics for marketing attribution and campaign optimization.
Purpose: AppsFlyer helps us understand which marketing campaigns are most effective, track user acquisition costs, and optimize our advertising spend.
Privacy Policy: AppsFlyer Privacy Policy
Data Shared: Device identifiers, subscription status, purchase events, revenue data, and user IDs for managing in-app subscriptions and purchases.
Purpose: RevenueCat processes subscription management, handles payment processing, provides subscription analytics, and manages user entitlements.
Privacy Policy: RevenueCat Privacy Policy
We use PostHog for product analytics and Sentry for error monitoring. These services receive basic usage data and error logs but do not have access to your facial images or personal identification information.
We do not sell, trade, or otherwise transfer your personal information or facial data to any other third parties without your explicit consent, except as described in this policy or as required by law.
We implement industry-standard security measures to protect your data, including encryption, secure servers, and regular security audits. Your photos are encrypted during transmission to our AI analysis service and are processed securely. We regularly update our security practices to protect against unauthorized access, alteration, disclosure, or destruction of your personal information.
Face Photo Storage: Your original facial photos are stored securely on our servers (Supabase) with end-to-end encryption until you manually delete them or delete your account.
Analysis Data: Facial measurements, scores, and progress data are retained indefinitely for your progress tracking until account deletion.
Temporary Processing: During AI analysis, your images are temporarily held on the AI provider's servers for processing and are automatically deleted immediately after analysis completion.
Account Deletion: When you delete your account, we permanently delete ALL associated data within 30 days, including:
Individual Photo Deletion: You can delete individual photos at any time through the app, and they will be permanently removed from our servers within 24 hours.
Legal Retention: We do not retain any facial data for legal or compliance purposes beyond what is necessary for app functionality.
You have the right to access, update, or delete your personal information and facial data at any time. You can also request a copy of your data or opt out of certain data collection practices. Account deletion will result in the permanent removal of all your images and personal data. To exercise these rights, please contact us at hello@lookslab.app.
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Your data may be transferred to and processed in countries other than your own, including the United States where our AI analysis services are operated. We ensure that such transfers comply with applicable data protection laws and that appropriate safeguards are in place.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you through the app or by email.
If you have any questions about this Privacy Policy or our data practices, please contact us at:
LooksLab Privacy Team
Email: hello@lookslab.app
Response time: Within 48 hours