Legal
Privacy Policy
Effective date: July 1, 2026. Last updated: July 23, 2026.
Clean Skin is a mobile application that helps you understand the composition of your skincare products by analysing their ingredients. This Privacy Policy describes how we collect, use, store, and share your personal data. By using the app you acknowledge that you have read this Policy and understand the data-processing practices described in it.
The controller of your personal data is the Clean Skin team (the "Service", "we", "us", "our"). For any privacy-related request contact us at sc.assistant.dev@icloud.com.
1. Personal data we collect
We collect only what the Service needs to work.
You provide to us:
- Email address, display name, and authentication identifiers from Google Sign-In or Sign in with Apple when you create an account;
- Skin profile data you choose to enter (skin type, concerns, preferences);
- Products and ingredients you mark as favourites, search for, or view;
- Messages you send to the in-app assistant;
- Photos you capture for skin analysis or ingredient recognition. A photo is processed transiently (on your device or on our server) and is not stored after the result is produced.
Please do not include third parties' personal data, or unnecessary sensitive information about yourself, in search queries or assistant messages.
Health-related data. Your skin profile, skin-analysis results, and the content of your assistant messages may qualify as health-related data. We process such data solely to provide the Service's features and only on the basis of your explicit consent, which you give by filling in your profile, sending a message, or starting an analysis. You may withdraw consent at any time by deleting the relevant data or your account.
Collected automatically by the Service:
- Authentication session data (JWT tokens, device fingerprints used to blacklist revoked sessions);
- Subscription status obtained from Apple (whether your Clean Skin Pro subscription is active).
Collected automatically by third-party SDKs used by the Service:
- Crash reports (device model, OS version, anonymous installation identifier, stack traces) via Firebase Crashlytics (provided by Google LLC);
- Push notification tokens issued by Apple Push Notification Service when you allow notifications.
We do not use facial images for identity or biometric recognition. A photo is used only for a one-off skin assessment (or ingredient recognition), processed transiently, and not retained by us after the result is produced.
We do not sell your personal data and do not disclose it to third parties in exchange for money or other consideration, or for their own marketing or advertising purposes.
2. Why we process your data
We process your data for the following purposes:
- Creating and operating your account — legal basis: contract and consent;
- Personalising scoring and recommendations — contract; for skin-condition data — explicit consent;
- Processing your Clean Skin Pro subscription — contract;
- Sending service-related push notifications — consent (revocable in iOS settings);
- Photo-based skin analysis and AI features (ingredient recognition, assistant) — explicit consent (you initiate the capture or request); processing is transient;
- Keeping the service stable (crash diagnostics) — legitimate interest;
- Preventing fraud and protecting the Service and our legal rights — legitimate interest;
- Complying with legal obligations — legal obligation.
Legal bases are determined under applicable data protection law and, where applicable, Articles 6 and 9(2)(a) of the EU GDPR — for health-related data we rely on your explicit consent.
If a new purpose for processing arises, we will inform you by updating this Policy before we start processing data for that purpose.
3. Who we share data with
We share only what is necessary, and only with the following providers:
- Apple Inc. — authentication (Sign in with Apple), subscription billing, push notifications;
- Google LLC — authentication (Google Sign-In), crash reporting (Firebase Crashlytics), and image processing via the Gemini API (photo-based ingredient recognition and, for Pro subscribers, photo-based skin analysis): the image is processed to produce a result, is not used to train models, and is not stored by us;
- DeepSeek — processing of messages you send to the in-app assistant in order to generate a reply;
- Competent authorities — only where we are legally required to respond to a lawful request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud.
We work only with providers that have assured us they apply appropriate technical and organisational data-protection measures. Where a provider acts as an independent controller (for example, Apple and Google for authentication, Apple for billing), its processing is governed by its own privacy policy, and we are not responsible for processing such providers carry out for their own purposes outside our instructions.
If we are involved in a merger, acquisition, or sale of assets, your data may be transferred to the successor; we will notify you of the change of controller and of any choices you may have.
4. International transfers
We provide the Service to users in different countries. Data processed by Google and Apple, and by the Service's infrastructure, may be transferred to and stored on servers outside your country, including the United States and the European Union, where data-protection laws may differ from those of your country. Such transfers rely on legally recognised safeguards, including the policies and contractual commitments of those providers. By using the Service, you consent to such transfers.
5. Retention and deletion
- Account data is kept for as long as your account is active;
- When you delete your account, we block access immediately and erase your personal data irreversibly within 30 days, except where retention is required by law or necessary to resolve disputes, prevent fraud, or protect our legal rights;
- Photos submitted for analysis are not stored — they are deleted right after processing; only the analysis result is kept (locally on your device);
- Crash reports are retained according to Firebase's default retention (currently 90 days);
- Backups are rotated within 30 days.
To delete your account use the in-app option or email sc.assistant.dev@icloud.com.
6. Your rights
Subject to applicable law (including, where applicable, the EU GDPR), you have the right to:
- Access the personal data we hold about you and obtain confirmation of whether it is being processed;
- Correct inaccurate or incomplete data;
- Withdraw your consent at any time (this does not affect the lawfulness of processing before withdrawal);
- Request erasure of your data (subject to legal exceptions — for example, where retention is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims);
- Obtain a copy of your data in a portable, structured, machine-readable format;
- Object to or restrict certain processing activities;
- Lodge a complaint with the data-protection authority in your country of residence.
To exercise any right, email sc.assistant.dev@icloud.com. For security, we may first ask you to verify your identity (for example, by writing from the email address linked to your account) — this protects against fraudulent requests to disclose someone else's data. We may decline manifestly unfounded or excessively repetitive requests to the extent permitted by law, and will explain why.
We will respond within a reasonable time, typically within 30 days. For complex requests this period may be extended; we will inform you of the extension and its reason. Before lodging a complaint with a supervisory authority, we encourage you to contact us first — most issues can be resolved directly and faster.
7. Security
- All traffic between the app and our servers is encrypted (TLS 1.2+);
- Passwords are stored as hashes (bcrypt);
- Access to production data is restricted and logged;
- Authentication sessions can be revoked at any time by signing out.
We take reasonable technical and organisational measures appropriate to the risks involved; however, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. If a breach affects you, we will notify you and, where required, the competent authority within the time frames prescribed by applicable law.
8. Children
Clean Skin is not directed at children under 13 (or the minimum age of digital consent in your country — 16 in most EU jurisdictions). We do not knowingly collect personal data from children. Holders of parental responsibility are responsible for preventing children from providing personal data without the required consent. If you believe a child has provided us with data without such consent, contact us and we will delete it as quickly as possible.
9. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date reflects the latest change. Material changes will be announced inside the app at least 14 days before taking effect. We encourage you to review the current version periodically. Your continued use of the app after changes take effect constitutes acceptance of the updated Policy.
10. Contact
Clean Skin
Email: sc.assistant.dev@icloud.com