1. Who we are
Dermara ("Dermara," "we," "us") provides the Dermara iOS app and this website, which is served at looksmith-legal.vercel.app. Dermara is currently operated under that trade name and is not, at present, incorporated as a separate legal entity; it is the controller of the personal information described in this policy. You can reach us at rfurdui@gmail.com, which is also the address for legal and privacy notices. If Dermara is later operated by an incorporated entity, we will update this section with its name and registered address.
2. Your account is anonymous
Dermara does not ask you to sign up. The app creates an anonymous account on your device, and everything we store is tied to that anonymous id and nothing else. We collect no email address, no name, no phone number, no username and no other contact details. There is no profile, no login, and no way for us to look you up as a person.
That has a practical consequence worth stating plainly: because we hold no identifier that points at you as a human being, we generally cannot find your data from an email you send us. The deletion control lives in the app because the app is the only thing that holds the key. See Section 8.
3. Face data: what we collect, how we use it, who receives it, and how to delete it
Face data is the most sensitive thing Dermara handles, so it gets its own section rather than being scattered through the policy. By face data we mean the photographs of your face that you take for a scan, and the scores and written findings we derive from them. This section states our collection, uses and disclosures, our sharing and retention, our deletion and consent revocation, and the protection given by the one third party that receives face data. The fuller detail on each point is cross-referenced rather than repeated.
3.1 What face data we collect, and every intended use and disclosure of it
What we collect. To produce a scan you take a front selfie, and optionally a side profile. Those photographs, and the scores and findings we derive from them, are the whole of the face data Dermara collects. You take each one deliberately: Dermara never captures your face in the background, never opens the camera on its own, and never reads a photo you did not choose. It is for your own face only.
Every intended use. We use face data for these purposes and no others:
- to produce your scores for each scored feature, your overall score, your modeled projected score, the confidence bands, and the written findings that go with them;
- to build and update the daily plan and tasks that follow from those findings; and
- to answer your questions in the coach chat, which uses the findings from your scan and never the photograph itself.
Uses we do not make, at all. We do not use face data to identify or recognize you, to search for you, to match your face against any other photograph, database or watchlist, to build a face template or faceprint, for advertising, or to train any AI model, ours or anyone else's. We do not sell face data and we do not share it for cross-context behavioural advertising.
Every intended disclosure. There is exactly one. Anthropic, PBC receives your photograph so that its Claude model can read it and return your scores and findings. It is named on the consent screen you must agree to before your first scan, and in Section 4. No one else receives your photograph: no advertiser, no data broker, no other user, and no other AI provider. See Section 3.4 for the protection Anthropic is bound to give it, and Section 10 for the providers that receive the non-face data that makes the app work.
3.2 How we share face data, and how long we keep it
Sharing. Your photograph is shared with one recipient, Anthropic, and only to produce your result. The scores and findings derived from it are stored by our database provider, and are not shared with anyone else for any other purpose.
Retention. Here is exactly what happens to a scan photograph:
- Metadata is stripped on your device. Location and device information embedded in the image (EXIF data) is removed on your phone, before anything is uploaded. It never reaches us.
- The photo is sent over an encrypted connection. It travels over TLS to our server function, and from there, over TLS again, to Anthropic. Those two are the only places it goes.
- It is analyzed in memory and immediately discarded. The model reads the image to produce your scores and findings, and the image is thrown away as soon as that finishes. Our retention period for the photograph is zero.
- It is never stored on our servers. No copy is written to our database, our file storage, any disk, or any log. We keep no photo archive, and there is nothing for us to hand over, lose, or be breached out of.
- No biometric identifier is ever created or kept. We do not create or store a face template, faceprint, embedding, landmark vector or any other persistent biometric identifier, and we do not ask anyone else to create one for us. See also Section 5.
- On your phone. A photo you take or pick stays in your own photo library, where you control it. The app holds the image in memory for the length of the scan and does not write its own copy to disk.
What is retained is the result, not the image: your scores, findings and the plan built from them, tied to your anonymous id, kept until you delete them. Nothing expires on a clock, so retention is entirely in your hands. See Section 8.
Anthropic's retention. Under the terms our access is governed by, Anthropic keeps what we send only for the limited period its API policies allow for safety and abuse monitoring, then deletes it, and it may not use it to train its models. See Section 4.
3.3 How you delete your face data, and how you revoke your consent
Consent comes first, and it blocks. Before your first scan the app shows a consent screen that lists what happens to your photos and names Anthropic as the provider that reads them. Nothing on it is pre-ticked: you must tick "I understand and agree to these terms," and the continue button stays disabled until you do. If you do not agree, you do not scan, no photograph ever leaves your device, and no face data is ever collected. If we republish this policy or the consent wording, the app asks you to agree again before your next scan.
How you revoke your consent. Dermara collects face data only in the moment you run a scan, and never between scans. So you revoke your consent by stopping: stop scanning and no further face data is collected, because every scan requires you to take the photo and send it yourself. There is no background collection to switch off, which is why the app has no separate "withdraw consent" switch. To undo what earlier scans produced, use "Delete my data" below, and to end it completely, delete the app.
How you delete your face data. "Delete my data" in the app's Settings erases from our servers, at any time and without asking us: your scans and the scores, findings and confidence bands derived from your photographs, your plans, tasks and completions, your streak and XP, your coach chat, and your quiz answers. Your anonymous account itself stays valid so the app keeps working, but it holds nothing derived from your face.
Be clear about what that means here. Because the photograph itself was never stored (see Section 3.2), there is no stored image for us to erase. What deletion removes is everything we derived from your photographs, which is the entirety of the face data we hold. Deleting the app, or resetting its data on your device, breaks the link to those records permanently and we cannot restore it. See Section 8, which also covers the two things deletion does not do: it does not cancel your subscription, and it does not remove billing records.
3.4 The third party that receives face data gives it the same protection
Anthropic, PBC is the only third party with which Dermara shares face data, and it provides the same or equal protection of that face data as is stated in this privacy policy. It acts as our processor. Under the Anthropic Commercial Terms of Service that our access is governed by, it is bound to security and confidentiality obligations equivalent to the ones we take on here, it may use what we send only to return our result, it may not use it to train its models, and it retains it only for the limited period its API policies allow for safety and abuse monitoring before deleting it. It never receives your name, your email or any account identifier, because we hold none to give it. Section 4 sets this out in full.
We will not share face data with any other provider unless it offers the same or equal protection. If we ever change AI provider, we will update Section 4 and the in-app consent screen, and ask you to agree again before the new provider receives anything.
4. How the AI analysis works
The scoring is not done on your phone. Our server passes your photo to Anthropic, PBC (San Francisco, California, USA), whose Claude model reads the image and returns the scores and findings. Anthropic is the only third party that ever receives your photo. We name it here, and on the consent screen you agree to before your first scan, because you should know who is looking at your face before you send it.
Anthropic acts as our processor. Under the Anthropic Commercial Terms of Service that our access is governed by, it may use what we send only to return our result and may not use it to train its models, and it is bound to security and confidentiality obligations equivalent to the ones we take on in this policy. It retains inputs and outputs only for the limited period its API policies allow for safety and abuse monitoring, and then deletes them. It does not receive your name, your email or any account identifier, because we do not have one to give it.
The coach chat works the same way. Your questions and the parts of your scan needed to answer them go to Anthropic to generate a reply, under the same terms. Your chat messages are stored on our servers so the conversation persists between sessions.
If we ever change AI provider, we will update this section and the in-app consent screen, and ask you to agree again before the new provider receives anything.
5. What we store
All of the following is tied to your anonymous account id:
- your scores for each scored feature, your overall score and your modeled projected score;
- the written findings and confidence bands produced with them;
- your daily plan and the tasks in it;
- task completions, streaks and XP;
- your coach chat messages;
- your answers to the onboarding quiz, which covers your goals, skin type, current routine, makeup habits, sleep and how much effort you want to put in;
- your subscription status, so the app knows what to unlock; and
- basic technical and product-analytics events, described in Section 6.
Feedback you choose to write and send us from the app is handled differently: it is emailed to us rather than stored with your account. See Section 6.1.
What we do not collect
- No name, email address, phone number or password.
- No stored copy of any photo you scan.
- No face template, faceprint or other persistent biometric identifier.
- No location. EXIF location data is stripped on your device before upload.
- No contacts, and no scanning of your photo library beyond the image you choose.
- No payment card details. Those stay with Apple.
6. Analytics
We use PostHog for product analytics: which screens are opened, which features are used, where people get stuck. It exists so we can fix what is broken and improve what is not. We keep it deliberately narrow and we do not enable broad automatic capture of your screen activity.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, we run no advertising in the app, and we do not track you across other apps or websites.
6.1 Feedback and support messages
The app sometimes asks how it is going. If you give it a star rating and then write us a note in the box that follows, we receive what you typed (up to 1,000 characters), the star rating you gave, the app version you were running, and whether you are on iPhone or Android. Nothing else is attached: no name, no email address, and nothing from your scans. If you put your own contact details inside the note, we will have those too, because you sent them to us.
The note is emailed to us. It is not sent to our analytics provider. We use FormSubmit (formsubmit.co), a form-to-email service, to deliver it to the support address in Section 16. FormSubmit passes the message on and receives nothing else about you. PostHog, described just above, is told only that a note was sent, with the star rating and how many characters long it was — never the words themselves.
Writing to us is always your choice. The box starts empty, nothing leaves your phone until you press Send, and closing the sheet sends nothing at all. You can leave an App Store review instead if you prefer; that one is public and goes to Apple rather than to us, and the app offers it whatever rating you gave.
How long we keep it. A feedback message sits in our support inbox like any other email. We keep it while we are acting on it and delete it once we no longer need it. Because it arrives as an email rather than as part of your account, "Delete my data" in the app does not remove it — write to rfurdui@gmail.com and we will delete it for you.
7. Purchases and subscriptions
Dermara Pro is sold and billed by Apple through the App Store. We use RevenueCat to tell the app whether your subscription is active. We receive a subscription status, the product you bought, an app-store subscriber identifier and renewal or expiry information. We never see your card number or any other payment detail; those go to Apple and stay with Apple.
8. Keeping and deleting your data
Photos: not retained at all, as described in Section 3.2. There is nothing to delete because nothing was kept. What deleting your face data does mean, and how you revoke your consent, is in Section 3.3.
Everything else: kept, tied to your anonymous id, until you delete it. "Delete my data" in the app's Settings erases your scores, findings, plans, task history, streaks and coach chat from our servers. It works at any time and you do not need to ask us to do it.
Two things deletion does not do. It does not cancel your subscription, which you cancel in your App Store settings; and it does not remove billing records, which we keep for as long as accounting, tax, restore-purchase and fraud-prevention purposes require, so that deleting your scores cannot silently end a subscription you are paying for.
Because Dermara is anonymous, the account on your device is the only key to your data. If you delete the app's data on your device, or reset the app, the link to your stored results is broken and we cannot restore it for you.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete or obtain a copy of your personal information, and to object to or restrict certain processing. Because we hold no name, email or account for you, the practical controls live in the app:
- Delete everything: "Delete my data" in Settings.
- Manage or cancel your subscription: in your App Store settings. See the Support page for the steps.
- Notifications: turn them off in your device settings at any time.
- Stop entirely: delete the app. Then use "Delete my data" first if you want the server-side records gone as well.
We will not discriminate against you for exercising any of these rights.
10. When we share information
We share information only with the service providers that make Dermara work, and only for that purpose:
- Anthropic, PBC (the AI provider) receives your photo to produce scores, and your coach questions to produce replies. It may not use either to train its models, and it provides the same or equal protection of your face data as this policy states. It is the only third party that receives face data. See Section 4 and Section 3.4.
- Cloud and database provider (Supabase) stores your scores, plan, chat and anonymous account.
- Apple and RevenueCat handle billing and tell the app your subscription status.
- Analytics (PostHog) receives limited product and technical usage events. It does not receive the text of any feedback you write.
- FormSubmit (formsubmit.co) delivers a feedback message you write in the app to our support inbox by email. It receives that message and nothing else. See Section 6.1.
- Legal and safety, where we are required by law to disclose information, or need to in order to protect our rights, our users or the public.
We may also share information in connection with a merger, acquisition or sale of assets, subject to this policy.
11. Security
We use industry-standard measures to protect information, including encryption in transit, access controls, and row-level security so an account can only reach its own data. Keys and provider credentials are held server-side and are not present in the app. The strongest protection here is structural rather than technical: the most sensitive thing you give us, your photo, is never kept, so it cannot be exposed later. No method of transmission or storage is perfectly secure, but we work to protect what we hold and to hold as little as possible.
12. Where Dermara is offered
Dermara is offered in the United States. If you use the app, your information may be processed in the United States and other countries where we or our providers operate; where required, we rely on appropriate safeguards for those transfers.
13. Children
Dermara is for adults aged 18 and over. It is not directed to children, we do not knowingly collect information from anyone under 18, and it must not be used to scan a minor's face. If we learn that we have collected information from someone under 18, we will delete it. If you believe a child has used Dermara, contact rfurdui@gmail.com and we will act on it.
14. Scores are not medical advice
Worth repeating here because it shapes what the data is: Dermara scores cosmetic appearance from a photograph and suggests everyday habits. It does not diagnose skin, hair or health conditions, it is not dermatological or medical advice, and no health information you may consider it to reflect is treated by us as a clinical record. See a qualified professional for anything medical.
15. Changes to this policy
We may update this policy as the product changes or the law requires. We will revise the "last updated" date and version above and, for material changes, provide a more prominent notice in the app. Continuing to use Dermara after an update means you accept the revised policy.
16. Contact us
Questions about privacy, or about anything in this policy, go to rfurdui@gmail.com. A person reads that inbox.
Dermara is operated under that trade name and has no separate incorporated entity at this time, so that address is also the contact point for legal and privacy notices. See Section 1.