Last updated: 2026-08-04
1. What we collect
Account data — email address, password (stored only as a scrypt hash, never in plain text), display name and avatar URL if you set them, and account timestamps.
Photographs — the selfie you take for diagnosis and the upper-body photo you take for virtual try-on. These are uploaded to PerfectCorp (YouCam API) for processing, and we keep our own copy of the photo you are currently styling with so that the studio can show it to you again after a reload.
Colour profile — the numeric result of analysis: skin/eye/hair/lip CIELAB coordinates, season classification, and the derived palette.
Renders — every hair-color, hairstyle and try-on image produced while you style. Each one is copied to our storage as soon as it is generated, because the provider's own link expires in two hours. These copies are deleted when you delete the styling session they belong to.
Security records — sign-in attempts (email, IP address, success or failure) and the IP address and browser user agent recorded at the moment you agree to terms. These exist to detect account attacks and to evidence consent.
2. How your photographs are handled
We keep a copy of the photo you are styling with. Without it the studio cannot show you your own photo after a page reload. That copy is stored outside the public web root and is served only to you, after an ownership check.
A session's photos cannot be swapped. Each styling session keeps the photos it started with. To style a different photo you start a new session — and you can delete the old session at any time from the studio home.
Deleting a session deletes its photographs and renders from our storage. At the processing API, the selfie is deleted too where a completed analysis or render lets us reference it. Other provider copies — including the upper-body photo, whose deletion call would destroy a shared cache other people are using — expire there automatically within 30 days.
One gap we have not closed. Closing your account does not automatically delete your styling sessions or your colour profile — it anonymises your account record. Delete your sessions yourself before closing, or ask us using the contact below and we will.
We do not publish your photographs and we do not use them to train anything.
3. Third parties
PerfectCorp (YouCam API) — receives your photographs to perform skin tone analysis and virtual try-on rendering.
Anthropic — receives the text of your conversations with the AI assistant, and also receives images in two places: a downscaled copy of your selfie is checked for framing before upload, and your photo is sent when hairstyle candidates are scored for fit. Anthropic does not train on data sent through its API.
4. How long we keep it
| Data | Retention |
|---|---|
| Photos of a styling session (our copies) | Until you delete that session, or until you ask us |
| Selfie at the processing API | Deleted with its session where possible, otherwise 30 days |
| Upper-body photo at the processing API | 30 days |
| Renders | Until you delete their session, or until you ask us |
| Account record | Anonymised when you close your account |
| Colour profile | Until you ask us to delete it |
| Sign-in records | 1 year |
| Consent records | 5 years after the account closes (legal evidence) |
5. Your rights
From account settings you can view your data, correct your profile, review your full consent history, and close your account.
Deleting a styling session — its photographs and renders — is self-service: delete the session from the studio home. Your measured colour profile numbers are kept (they contain no photograph); deleting those is not yet self-service — ask us using the contact below and we will do it. We would rather say that than describe a button that does not exist. Consent records are kept after closure because they are the evidence that consent was given; they contain no photographs.
6. Contact
Reach us at the address published on the repository for this project.