Legal

Privacy Policy

Effective date: July 30, 2026

This policy describes the data handling of the Face Harmony mobile application, operated by Face Harmony App LLC (“we,” “us”). It is written to describe what the app actually does. Where a category of data is not collected, it is not mentioned.

Face Harmony is an appearance and grooming app that produces numeric estimates of facial proportion from a face scan. It is not a medical device and does not provide medical advice, diagnosis, or treatment.

1. Accounts and Identifiers

  • An anonymous account identifier (a Firebase “uid”) is created when you first open the app, before you sign in. All app data is keyed to this identifier.
  • If you create an account, you do so with Firebase Phone Authentication. Your phone number is held by Google Firebase Authentication. We do not copy it into our own database.
  • You may optionally provide a display name, and separately a marketing email address if you opt in to marketing.

2. What Stays on Your Device and Is Never Uploaded

The following never leaves your device. There is no server-side file or image storage provisioned for this app, so these have no cloud destination at all:

  • Your face photographs (front and side)
  • The 3D face mesh and its vertex data
  • Facial landmark coordinates
  • The full local scan result

These are deleted when you delete the app or clear its data, and when you delete a scan in the app if that option is available to you.

3. What We Store on Our Servers

We store the following in Google Firestore. See Section 6 for where it is located.

Account record

  • Display name, if you provided one
  • Your age range
  • Which versions of our policies you accepted
  • A summary of your most recent score
  • Created and updated timestamps

Onboarding profile

  • Gender
  • Primary goal; improvement goals and their priority
  • Photo confidence; concern intensity
  • Skin type and skin concerns
  • Workout frequency; skincare products used; diet type; sleep amount
  • Lifestyle habits; previous attempts; experience level; time commitment

Assessments — one record per face scan

  • Your overall score and per-category scores
  • Derived facial measurements. Up to 100 numeric records per scan (typically around 27), each consisting of an identifier, category, status, value, and unit. These are anthropometric facial measurements expressed in millimetres and degrees — for example interpupillary distance, bizygomatic (cheekbone) width, intercanthal distance, palpebral fissure length, chin projection, and canthal tilt. They are numbers derived from the on-device scan. The imagery, mesh, and landmark coordinates they were derived from are not uploaded.
  • The age-range and sex cohort applicable at the time of the scan
  • The scoring version used
We consider these measurements sensitive and treat them as such. Whether they constitute “biometric data” or a “biometric identifier” under laws such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington My Health My Data Act, or Article 9 of the GDPR is a question that depends on whether the measurements can be used to identify an individual. We do not use them to identify anyone, to authenticate anyone, or to match one person against another. If you are in a jurisdiction with a biometric statute and you do not want these measurements stored on our servers, do not complete a scan while signed in, or delete your account (Section 8).

Private account data

  • Account status
  • Deletion-requested timestamp, if you have requested deletion
  • Marketing consent flag and the time it was given
  • An optional marketing email address

Aggregate distributions

We maintain score histograms across all users — counts of how many users fall into each score bin, per cohort. These contain no user identifier and no measurements, and nothing in them is traceable to an individual. They are used to place a score in context.

4. What We Do Not Do With Scan Data

  • We do not use your scan data or measurements to identify you as a person.
  • We do not use them for authentication, Face ID, identity verification, or surveillance.
  • We do not sell them.
  • We do not share them with advertisers or data brokers.
  • We do not use them to track you across other apps or websites.

5. Third Parties That Receive Data

We do not sell personal information. The following providers process data in order for the app to function:

Google Firebase — Firestore, Authentication, Cloud Functions

Hosts everything described in Sections 1 and 3, including your phone number in Firebase Authentication.

Google Analytics for Firebase (GA4)

Receives, tied to your account identifier:

  • Sex
  • Your exact age — not an age range, unlike the account record described above
  • Primary goal; desired look; analysis depth
  • Referral source
  • Subscription tier
  • In-app events, such as screens viewed and features used

Analytics data is used to understand product usage. Because your account identifier is attached, this data is not anonymous.

Firebase Crashlytics

Receives crash and error reports, including device and diagnostic context.

Firebase Cloud Messaging

Receives a push notification token for your device installation.

RevenueCat

Manages subscriptions and purchases, identified by our user identifier. Payment card details are handled by the Apple App Store or Google Play and are never received by us.

Your face photographs, face mesh, and landmark coordinates are not sent to any of these providers, because they are not uploaded anywhere.

6. Where Your Data Is Stored, and International Transfers

Our Firestore database and server functions run in Google Cloud region us-central1, in the United States. Our analytics, crash reporting, messaging, and subscription providers are also US-based.

If you use Face Harmony from the European Economic Area, the United Kingdom, or Switzerland, your data is transferred to and processed in the United States. Those transfers rely on the standard contractual clauses and equivalent transfer mechanisms in our providers' terms, together with the EU–US Data Privacy Framework where the provider is certified under it. You may contact us for further detail on the transfer mechanism applicable to a specific provider.

7. Retention

Your account record, onboarding profile, assessments, and private account data are retained until you delete them or delete your account. We do not currently apply an automatic expiry to stored assessments — they persist so that you can see your history over time.

Data held by our analytics, crash reporting, and subscription providers is retained under those providers' own retention windows.

Aggregate score distributions are rebuilt nightly. Once your data is deleted, you drop out of the aggregates at the next rebuild.

8. Deleting Your Data

The app includes a delete-account option. When you use it, a server function recursively deletes your account record, your onboarding profile, your assessments — including all derived measurements — and your private account data, and deletes your Firebase Authentication user, which removes your stored phone number.

To be accurate about the limits of that: account deletion does not currently reach data already held by Google Analytics for Firebase, Firebase Crashlytics, or RevenueCat. If you want those records removed as well, email us at the address in Section 11 and we will process the request with those providers.

Anything held only on your device is removed when you delete the app or clear its data.

9. Your Rights

Depending on where you live, you may have the right to access, correct, or delete your data, to obtain a copy of it, to withdraw consent, to object to or restrict processing, and not to be discriminated against for exercising these rights.

  • Deletion: use the in-app delete-account option, or contact us.
  • Access or a copy: contact us and we will provide your stored records.
  • Marketing: you may withdraw marketing consent at any time.
  • Camera: you can revoke camera permission in your device settings. Scanning will not work without it.
  • Push notifications: you can disable them in your device settings.

10. Children

Face Harmony is not intended for children under 13, and we do not knowingly collect their information. If you believe a child has provided information to us, contact us and we will delete it.

11. Security, Changes, and Contact

Access to stored data is restricted by database security rules that limit each account to its own records, and data is encrypted in transit and at rest by our providers. No system is completely secure, and we do not claim otherwise.

We may update this policy. Material changes will be surfaced in the app or by other appropriate means, and the updated policy is effective when posted. The policy version you accepted is recorded on your account.

Questions or requests: dev@faceharmony.org

12. Medical Disclaimer

Face Harmony provides appearance and grooming information for general informational purposes only. It does not provide medical advice, dermatological or health diagnosis, treatment or surgical recommendations, or mental health advice. For any such concern, consult a qualified professional.