Privacy Policy

Last updated 17 August 2026

How SkinPassport handles personal data in the app and on this website, and how to exercise your rights.

This policy explains how personal data is handled in the SkinPassport app and on skinpassportapp.com. The two are described separately where they differ, and are referred to together as the Service.

The controller is [LEGAL ENTITY], [REGISTERED ADDRESS]. Contact: privacy@skinpassportapp.com.

Contents

  1. Personal data we collect
  2. Purposes of processing
  3. Legal bases
  4. Photographs of labels
  5. Recipients
  6. Cookies and local storage
  7. Retention
  8. Security
  9. Transfers outside the EEA and the UK
  10. Your rights
  11. Deleting your account
  12. Children
  13. Third-party sources
  14. Changes
  15. Contact

1. Personal data we collect

1.1 Data you enter in the app

Your skin profile: your name if you enter one, skin type, sensitivity, acne level, the concerns and goals you select, ingredients you ask the app to flag, skin conditions, and allergies.

Skin conditions, allergies, sensitivity and acne level are data concerning health, and therefore a special category of personal data under Article 9 GDPR and UK GDPR. The conditions and allergies steps in onboarding are optional, state what the answer is used for, and can be skipped. All of these fields can be changed or cleared afterwards in the Profile tab.

We also store your scans, meaning the ingredient text that was read or entered, the resulting score, the product name where one was identified, and the date, as well as the product groupings (“kits”) you create.

1.2 Data generated by the app

An anonymous account identifier, created on first launch. It is not derived from your device, an advertising identifier or any other personal data.

A count of label reads, used to apply free usage limits.

If you choose to add sign-in details so that your data is available on another device, we store the email address or the Apple ID identifier you use. Where you sign in with Apple and choose to hide your email address, we receive only the relay address.

1.3 Data you enter on the website

If you join the launch list, we store the email address, the form it came from, whether you agreed to be contacted about the launch, and the date.

If you send us a product, an ingredient or a suggestion, we store what you submitted, together with your email address where you provide one so that we can reply.

1.4 Data collected automatically

Our hosting providers record standard server log data, including IP address, user agent, the resource requested and the time of the request.

Submissions from the website are rate limited using a one-way hash of the caller’s IP address combined with a server-side secret. The IP address itself is not stored in that record.

1.5 Data we do not collect

We do not collect precise location data, use advertising identifiers, or apply device fingerprinting. The app contains no third-party analytics or attribution software. If analytics are introduced, this policy will be updated first.

2. Purposes of processing

Your skin profile is used to produce the scores, cautions and explanations shown in the app, and to make them available on another device where you have added sign-in details.

Scans and kits are stored so that your history is available to you, including offline.

Email addresses are used to sign you in where you have chosen that, to send the launch announcement where you asked for it, and to reply to submissions.

Photographs are used only to extract ingredient text, as described in section 4.

Ingredient lists and searches that returned no result are used to decide which products and ingredients to add to the catalogue. This is information about products rather than about identifiable users.

Server logs are used to operate and secure the Service.

Personal data is not used to train machine learning models, and our agreements with providers do not permit them to use it for that purpose. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

2.1 Automated analysis

Scores are produced automatically by comparing the ingredients identified on a label against the profile you entered. The result is informational and does not produce legal effects concerning you or similarly significantly affect you, so it is not a decision within the meaning of Article 22 GDPR. The app shows the reasoning behind each score, and you can amend your profile and repeat the analysis.

Performance of a contract (Article 6(1)(b)): providing the app, holding your account, profile, scans and kits, and carrying out the analysis you request.

Consent (Article 6(1)(a), and Article 9(2)(a) for data concerning health): the health-related fields in your profile, sending a photograph to the recognition provider where the on-device read fails, and launch list emails.

Consent for each of these is sought separately and is not a condition of using the app. In the app, the health-related fields are optional steps that state their purpose, and the photograph question is asked for each photograph. You may withdraw consent at any time by clearing the relevant fields, by declining the photograph question, or by contacting us. Withdrawal does not affect processing carried out before it.

Legitimate interests (Article 6(1)(f)): operating and securing the Service, preventing misuse, and improving the ingredient catalogue.

Legal obligation (Article 6(1)(c)): where retention or disclosure is required by law.

4. Photographs of labels

When you photograph an ingredient label, the app first attempts to read it on your device using the text recognition provided by the operating system. On that path the photograph does not leave your device.

If the on-device read does not succeed, the app asks whether you want the photograph read remotely. Only if you agree is it transmitted over an encrypted connection to our server and passed to the recognition provider named in section 5.

We do not retain the photograph. It is held in memory for the duration of the request and is not written to our database, to disk or to our logs. The ingredient text returned is saved to your scan history.

Neither we nor the provider uses the photograph to train models. The provider may retain the request briefly under its own terms for security and abuse monitoring.

5. Recipients

Personal data is disclosed to the following processors, which act on our instructions and may not use it for their own purposes:

Processor Data Purpose
Supabase Account, profile, scans, kits, launch list, submissions Database, authentication, server functions
Anthropic PBC Label photographs, in transit Text recognition on the fallback path
Vercel Server log data Website hosting

Where you purchase a subscription, it is sold by Apple or Google, which inform us whether a subscription is active. We do not receive your payment details.

We disclose personal data otherwise only where required by law, where necessary to establish or defend legal claims or to protect the vital interests of a person, or in connection with a merger or acquisition, in which case this policy continues to apply until you are notified otherwise.

6. Cookies and local storage

The website uses local storage for one purpose: to record that you have dismissed the cookie notice. It sets no advertising or analytics cookies and contains no third-party trackers, pixels or embedded content. Fonts, images and video are served from our own domain.

The app stores your session token in the operating system’s secure storage, and caches your profile and scan history on the device so that it works offline.

If non-essential cookies are introduced, consent will be requested before they are set, and it will be possible to decline and to change that choice later.

We do not respond to browser Do Not Track signals, for which there is no agreed standard.

7. Retention

Your account, profile, scans and kits are retained until you delete your account.

Photographs are retained only for the duration of a request (section 4).

Launch list records are retained until the launch announcement has been sent and you have had a reasonable opportunity to respond to it, or until you ask to be removed.

Submissions are retained while we process them. Personal data contained in a submission is deleted on request, and in any event once the submission has been dealt with. Where the product or ingredient information in a submission is incorporated into the catalogue, it remains there without any identifier and is no longer personal data.

Server log data is retained for a short operational period, ordinarily not more than 30 days.

8. Security

Data is encrypted in transit. Data at rest is held in a managed PostgreSQL database with row level security, so that records belonging to an account are accessible only to that account.

Server functions that operate on user data require a signed token identifying the user. The website form endpoint, which does not require a token, accepts requests only from our own domain, is rate limited, and returns the same response whether or not the address submitted is already held.

No system can be guaranteed secure. Where a personal data breach affects you and notification is required, we will notify you.

9. Transfers outside the EEA and the UK

We are established in [JURISDICTION]. Our processors operate internationally, and personal data may therefore be processed outside the EEA and the UK, including in the United States.

Where that occurs, we rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, entered into as part of each processor’s data processing agreement, or on an adequacy decision covering the destination. You can request details of the mechanism applying to a particular processor at privacy@skinpassportapp.com.

10. Your rights

If the GDPR or UK GDPR applies to you, you have the right to access your personal data, to have it rectified or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time. You may lodge a complaint with your national supervisory authority, and in the United Kingdom with the Information Commissioner’s Office.

If you are a California resident, you have the right to know what personal information is collected and for what purpose, to access, correct and delete it, and not to be treated differently for exercising those rights. As stated in section 2, we do not sell or share personal information. Residents of other US states with comparable legislation have equivalent rights of access, correction, deletion, portability and appeal.

Requests should be sent to privacy@skinpassportapp.com. We respond within one month, or explain why we need longer. Because app accounts are anonymous by default, we may need the request to be made from the device holding the account or from the email address associated with it in order to verify it.

11. Deleting your account

The Profile tab contains a “Delete my account” function. It removes your profile, scans, kits and the account itself from our servers, and clears the data held on the device. Deletion is immediate and cannot be reversed.

The launch list is held separately and is not linked to app accounts. To be removed from it, reply to the email or write to privacy@skinpassportapp.com.

12. Children

SkinPassport is intended for users aged 16 and over. We do not knowingly provide the Service to, or collect personal data from, anyone under that age. If you believe we hold data relating to a person under 16, contact privacy@skinpassportapp.com.

13. Third-party sources

Ingredient names are taken in part from CosIng, the European Commission’s cosmetic ingredient database, and product information in part from Open Beauty Facts, which is published under the Open Database License. These sources provide information about products. No personal data is sent to either.

14. Changes

This policy is updated when our processing changes. The date at the top is the date of the current version. Where a change materially affects how personal data is used, we will notify users in the app.

15. Contact

Data protection enquiries and requests: privacy@skinpassportapp.com

General enquiries: hello@skinpassportapp.com

[LEGAL ENTITY], [REGISTERED ADDRESS]