Privacy

Last updated: July 2026

Summary in one paragraph

Your photo is used only to generate your care report. It is not retained on our servers unless you're signed in and explicitly save a report. We never sell your data. We never train AI models on your face. You can delete your account and saved reports at any time.

Who we are

CareLens ("we", "us") operates the CareLens website and installable app and is the data controller for the personal data described here. You can reach us at any time at hello@carelensai.app or through our Contact page. Your use of the service is also governed by our Terms of Service.

What we collect, why, and on what legal basis

  • Your photo and the features derived from it — used solely to generate your care suggestions. Legal basis: your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)), collected through the consent screen before any photo is analysed.
  • Account data (email, display name, saved reports) — used to sign you in and show your history. Legal basis: performance of a contract with you.
  • Chat messages you send the assistant — used to answer your question in that session. Legal basis: performance of a contract.
  • Basic technical data (IP address, browser type, pages viewed) — used to keep the service secure and working. Legal basis: our legitimate interest in operating a safe, reliable service.
  • Advertising cookies on content pages — legal basis: your consent where required by law; otherwise you can opt out through Google Ad Settings or your device controls.

We do not sell personal data, we do not share it for cross-context behavioural advertising beyond the ad cookies described below, and we do not use your photo to train AI models.

Who processes your data for us

We keep the list short on purpose. Our processors are: our hosting and application platform (Lovable), our database, authentication and storage provider (Supabase), and the AI model provider that generates your report. Google AdSense serves advertising on our public content pages. Each processor is bound by contract to use the data only to provide their service to us, and personal data may be processed in the United States and the European Union under Standard Contractual Clauses or an equivalent transfer mechanism.

How long we keep things

  • Photo and derived facial features: only for the seconds needed to produce your report, then discarded.
  • Saved reports (signed-in users only): until you delete them or delete your account.
  • Account record: until you delete your account; removed within 30 days of the request.
  • Chat messages: not stored on our servers by default.
  • Security and error logs: up to 90 days.

How we protect it

All traffic runs over TLS. Account data sits in a managed database with row-level security so one account cannot read another's reports. Access to production systems is limited to the people who maintain the service. No system is perfectly secure, so if a breach affects your data we will notify you and the relevant regulator as required by law.

Photos

When you analyze a photo, it is sent over an encrypted connection to our AI provider so the model can read visible cues and generate your personalized report. Photos are not retained on our servers unless you have created an account and explicitly saved a report. If you save a report, you can delete it — and the associated photo — at any time from your profile.

Our AI provider processes the image only to produce the response for your session and does not use your photo to train their models. We never sell photos to third parties or use them for advertising.

Biometric data

What we analyse. When you submit a photo, our AI provider examines visible features of your face and hair — including facial geometry and proportions, skin tone, texture, redness, pores, under-eye shadowing, and hair density — in order to generate general care suggestions.

Why this matters legally. In some jurisdictions this analysis qualifies as processing of biometric data — for example under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington's biometric privacy law (RCW 19.375), and Article 9 of the EU/UK GDPR. Because of this, we ask for your explicit, opt-in consent before any photo is analysed. We do not use facial analysis to identify you, and we do not sell, lease, trade, or otherwise profit from biometric information.

How long it is kept. Your photo and any derived facial measurements exist only for the duration of the request needed to produce your report — typically a few seconds — and are then discarded. They are not written to our databases. The only exception is when you are signed in and explicitly choose to save a report: in that case the report and its thumbnail are stored in your account until you delete them. Any saved biometric-derived data is permanently destroyed when you delete the report or your account, and in all cases no later than three years after your last interaction with us.

Withdrawing consent. You can withdraw your consent at any time. Simply stop submitting photos, clear your browser storage for this site, delete any saved reports from your profile, or email us at hello@carelensai.app and we will remove your data. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Account data

If you sign in, we store your email address, basic profile information (such as a display name), and any reports you choose to save. We use this data only to let you sign in, access your saved reports, and track scores over time inside the app.

Chat conversations

If you chat with the AI to refine your routine, the conversation is sent to the AI provider in the same way as your photo analysis. We do not store transcripts on our servers by default. Please do not include personal identifiers, medical record numbers, or other sensitive information in chat messages.

Cookies & analytics

We use a minimal set of cookies, primarily to keep you signed in. On content pages, Google AdSense may set advertising cookies as described in Google's privacy and cookie policies; these are only loaded on our public, content-rich pages (home, about, how-it-works, and the skin, hair, diet, wellness, and FAQ articles) and are not loaded on app screens like the calendar, profile, goals, or authentication pages.

Age requirement (16+)

CareLens is intended for people aged 16 and over, and we ask you to confirm you are 16 or older before any photo is analysed. We do not knowingly collect data from children under 16. If you believe a child has provided personal information, please contact us and we will remove it.

Your rights

You can access, export, correct, or delete your account and data at any time by using the delete-account option in your profile or by contacting us. Depending on where you live, you may also have the right to withdraw consent, to object to or restrict processing, to data portability, and to not be discriminated against for exercising these rights (GDPR / UK GDPR / CCPA-CPRA). We answer requests within 30 days and never charge for them.

If you are unhappy with how we handled a request, you can complain to your local data protection authority — for example the ICO in the UK, or your national supervisory authority in the EU.

Contact

For any privacy question or request, email us at hello@carelensai.app or use the Contact page. If we make a material change to this policy we will update the date at the top of this page and, for significant changes, tell you in the app before the change takes effect.