Legal
Last updated 27 July 2026
Who is responsible for your data: Hairloom is run by one
independent developer in the European Union, who is the data controller for
everything described on this page.
Contact: favamvv@gmail.com
— this reaches us directly and is the only channel we use for privacy
requests. There is no separate data protection officer; that address is the
whole of it.
Hairloom analyses photographs of your hair and scalp to describe how they look, and builds a routine from that. This page explains exactly what we collect, where it goes, how long we keep it, and how to get rid of it.
The short version. Your photos are stored in the European Union and analysed by Google's Gemini model. They are never shown to another user, never sold, and never used for advertising. You can delete everything from inside the app, permanently, without asking us.
Hairloom is for adults. You must be 18 or over, and the very first question the app asks is your age range. Choosing "under 18" ends the flow there: nothing is saved and there is no way past that screen. We take your answer at face value — we do not and cannot verify it — and we do not knowingly collect data from anyone under 18. If you believe a minor has used the app, email us and we will delete the account.
| What | Why | Legal basis |
|---|---|---|
| Photographs — up to four hair and scalp photos per scan (three required, the fourth optional), and a photo of a product label if you use that instead of scanning a barcode, and a photo you attach to a journal entry | To produce the cosmetic appearance analysis that is the entire product, to show you a before/after over time, and to read the ingredients off a label you photograph | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), which you can withdraw at any time |
| Quiz answers — age range, hair type, texture, length, concerns, how long you have had them, washing and heat-styling routine, chemical treatments, products in use, how your scalp feels, shedding level, four lifestyle sliders, time and budget, goal | To tailor the routine, and to give the model context when it reads your photos | Performance of a contract (Art. 6(1)(b)); for the few answers that touch on health, your explicit consent (Art. 9(2)(a)) |
| Account identifier — a random ID issued the first time you open the app. That is the whole of it. There is no sign-in, no password and no email address | To connect your data to you without needing anything you would recognise as your identity | Performance of a contract |
| Subscription status — whether you are on Hairloom Pro, which product, and when it expires | To unlock what you paid for, and to stop unlocking it when you stop paying | Performance of a contract |
| Reminder settings — a push token from your device, which reminders you want, the hour you want them, and your timezone | To send the reminders you asked for, at a sensible local hour | Your consent, withdrawn by turning reminders off |
| App usage, performance and crash data — screens opened, features used, how long an analysis took, crashes and their stack traces, device model, OS version, app version, language, an app-install identifier, your IP address (from which Google derives an approximate country or region), and on Android the device's advertising identifier | To find bugs, to see which parts of the app work, to see where people get stuck, and to keep it fast. These events are tagged with your account identifier, so we can follow one person's path through the app across sessions — for example, which step of the setup questions people stop at. They are never tagged with your name or email, because we hold neither. One of these events carries your overall hair score | Legitimate interests (Art. 6(1)(f)) in maintaining a working product |
We use your photos to describe cosmetic appearance, and nothing we produce is a diagnosis. But a photograph of a scalp can carry more than we ask of it, and a few of the quiz questions — how much you shed, how your scalp feels, how you sleep — sit near the same line. European law treats data concerning health as a special category with a higher bar. Rather than argue about which side of the line this falls on, we hold your photographs and those answers to the higher bar: we ask for your explicit consent before the first photo, we use them only to produce your own report, and you can withdraw that consent whenever you like by deleting your photos or your account. Withdrawing it does not unwind reports we have already generated for you, but it stops any further use immediately.
The first time you open Hairloom it creates an anonymous account for you. That account is a random string issued by Firebase Authentication. It is not derived from your device, your phone number, or anything about you, and on its own it tells nobody who you are. Everything in the app hangs off it.
There is no way to sign in, and no way to tell us who you are. We would rather say that plainly than leave it implied: we do not know your name, we have no email address for you, and if you wrote to us we could not connect your message to your data unless you told us the identifier yourself.
That has one consequence worth understanding before you rely on the app. The account exists only on that install. It cannot follow you to a new phone, and if you delete the app without deleting your account first, the data becomes unreachable to you as well as to everyone else — the only key to it is gone. There is no recovery, because there is nothing to recover it with.
A photographed product label takes the same route — to storage, then to the Gemini API, which reads the brand, the product name and the ingredient list off it. The app never shows that photo back to you; it is an input to a lookup, not content, and nothing in the app can read it once it is uploaded.
A photo you attach to a journal entry is uploaded and stored alongside your scans, under the same account and the same access rules. It is not sent to the model: nothing reads it, and it exists so the entry can show it back to you later. Deleting the entry removes the entry; the photograph itself is removed when you delete your account, which purges everything.
The photos are sent to Gemini for exactly one purpose: producing your report. Under the terms that apply to our paid use of the Gemini API, Google does not use them to train or improve its models. Google does hold a short-lived copy for its own abuse monitoring before deleting it — that copy is Google's, we cannot reach it, and it is used for nothing else. Beyond that, photos are not shared with any third party, are not published anywhere, and are not visible to other users of the app.
In the European Union. Your account, your scans and your
results are held in Google's eur3 multi-region database (Belgium and
the Netherlands); your photographs are in Google Cloud Storage in
europe-west1 (Belgium); and the server code that reads both runs in
europe-west1 too.
The analysis step is the exception, and we would rather say so than round it off. When a scan is analysed, the resized photos are sent to Google's Gemini API. That is a global Google service; we do not choose and are not told which Google data centre answers a given request, so a photo may be processed outside the EEA for the few seconds the analysis takes. The copy we store never leaves the EU.
Three of the companies below are American: Google LLC, RevenueCat, Inc. and PostHog, Inc. Where your data reaches them, the transfer relies on the European Commission's Standard Contractual Clauses, which form part of those companies' standard data processing terms, together with the EU–US Data Privacy Framework where the recipient is certified under it.
Analytics is the second exception, and it is a standing one rather than a few seconds. Our product analytics is hosted in PostHog's United States region. Everything else about this app is European — the database, the photographs, the server functions — and the analytics is not. That is a choice we made, and the data it involves is the account identifier, which screens you opened, and your overall hair score. Your photographs, your quiz answers and your routine never reach it.
We do not sell your data, and we do not share it with advertisers or data brokers. There is no advertising SDK and no attribution SDK in the app. Google's analytics library does read the device's advertising identifier on Android as part of its ordinary behaviour; we do not use it for advertising, we do not build a profile from it, and we pass it to nobody.
| Processor | What they handle |
|---|---|
| Google Firebase (Google Ireland Limited, with Google LLC as sub-processor) | Authentication, the database, photo storage, the server functions, push notifications, remote configuration, analytics, performance monitoring and crash reporting |
| Google Cloud Logging (same companies) | Server logs. These record that an analysis ran, for which account identifier, and what it scored. They contain no photographs. |
| Google Gemini API (Google LLC) — a separate Google service, not part of Firebase | Reading your photos to produce the cosmetic analysis, reading a photographed product label, and generating your routine and weekly insights. It receives the photos and your quiz answers; it does not receive your account identifier — and we have no name or email address to withhold. |
| RevenueCat, Inc. (United States) | Subscription status. Receives your account identifier and your purchase state — never your photos, never your quiz answers |
| PostHog, Inc. (United States) | Product analytics — which screens you opened, which features you used, and your overall hair score, each tagged with your account identifier. Never your photographs, never your quiz answers, never your routine. No session recordings: PostHog is capable of replaying what a person did on screen, and we have that switched off deliberately, because the app photographs your scalp |
| Apple / Google Play | Payment processing. We never see your card details |
| Open Beauty Facts | Public product database, queried when you scan a product barcode. Only the barcode is sent — nothing about you |
One thing that is not in that table, because it is not us sending anything. Some product suggestions link out to Amazon, and a few of those links earn us a commission. If you tap one, your own browser opens Amazon and Amazon sees that visit the way it would see any other — your IP address, and whatever cookies you already have with them. We do not send them anything about you, we cannot see what you do there, and nothing happens at all unless you tap. The link carries a search term and our affiliate tag, and no identifier of yours.
If you turn on reminders, your device gives us a push token, and we store it against your account along with which reminders you want and what time of day suits you. Your timezone is stored with it — otherwise "nine in the morning" would mean nine different moments and we would wake half of you at three. A job on our server checks hourly who is due one and asks Google's messaging service to deliver it. The message text is generated from your own routine and streak; it never contains a photo or a score.
Turn reminders off in the app's notification settings, or in your phone's, and the sending stops. Deleting your account removes the token.
Just the photographs. In the app: Me → Account & data → Delete my scan photos. Every scan image is erased and every score, observation and chart survives. Twelve weeks of progress does not get punished for exercising a privacy right.
Everything. In the app: Me → Account & data → Delete account & everything in it. This removes your profile, your quiz answers, every photograph, every scan and its results, the raw model output behind each one, your routine, task history, journal, saved products and the anonymous account itself. It runs on our server, not on your phone, so it reaches things the app itself cannot see. When it finishes it re-reads both the database and file storage to check nothing survived, and retries if anything did. It usually completes within a minute; in every case within 24 hours. It cannot be undone, and it does not require you to contact us.
If you cannot get into the app, email favamvv@gmail.com and we will delete the account for you within one month.
Deleting your account does not cancel a subscription bought through Apple or Google — they hold it, not us. Cancel it in the App Store or Play Store, or you will keep being charged.
If you are in the UK, EEA or Switzerland you have the right to access, correct, erase, restrict and object to our use of your data, to receive it in a portable form, and to withdraw consent at any time.
Export is in the app, at Me → Account & data → Export my data. It produces a JSON file containing your profile, your quiz answers, every scan and its scores, the full text the model returned for each one, your routine, your task history, your journal entries, your saved products and your insights, and hands it to your phone's share sheet. It does not contain the image files themselves — the photographs are listed by their storage location. If you want copies of the images, ask us at the address below.
Erasure is in the app too — see the section above.
For anything else, email favamvv@gmail.com. We answer within one month, and will tell you if a request needs longer than that. You may also complain to your national data protection authority; ours is the Polish President of the Personal Data Protection Office (UODO), and you can equally complain to the authority where you live.
If you are in California, you have the right to know what is collected, to delete it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as the CCPA defines those terms, and we do not use sensitive personal information for any purpose other than delivering the app.
Every path to your data is scoped to your own account. The security rules on our database and on file storage are written so that a signed-in user can reach their own subtree and nothing else, and the fields that decide what you have paid for and what you scored are writable only by our server — never by an app on a phone.
Your photographs are readable only by your own account, and by our server functions when they run an analysis for you.
Hairloom provides cosmetic appearance analysis, not medical advice. For hair loss concerns, see a dermatologist. It does not diagnose, treat or cure any condition, and it is not a medical device. We do not knowingly process your data for any health purpose, and nothing here should be read as us doing so.
If we change how we handle your data we will update this page and change the date at the top, and tell you in the app if the change matters. The date at the top always reflects the current version.