Skip to content

Legal

Privacy Policy

Last updated: 31 July 2026

This policy explains what data SkinRead collects, who processes it, on what legal basis, and how long it is kept. SkinRead analyses the visible, cosmetic appearance of your skin. We have described the system as it actually works, including the parts that involve third parties outside the EU.

1. Controller

Controller
Speakwise GmbH
Address
Kollage 3, 49170 Hagen a.T.W., Niedersachsen, Germany
Managing director
Nicolas Hagedorn
Contact
nico@skinread.app

2. No account, no login

SkinRead has no user accounts. There is no registration and no login: we never ask for your name, email address or a password in order to use the app. That is also why there is no “delete your account” flow — there is no account to delete. Your scans live on your device, and deleting them (or removing the app) removes them.

3. What we collect, and why

  • Selfies / face images you capture for a scan — to generate your cosmetic analysis.
  • Scan results — cosmetic scores and observations (e.g. hydration, redness, texture, visible pores, cosmetic skin age, skin type, per-zone results).
  • AI coach messages — the text you send the in-app coach, to generate its replies.
  • Voice notes — to transcribe your speech into text.
  • Onboarding answers — e.g. skin type, goals, age range, to tailor your routine.
  • Product analytics — how the app is used in aggregate, to find bugs and improve it.
  • Service telemetry — token counts, latencies and status codes, for cost and reliability monitoring (Section 8).
  • Advertising attribution signals — limited install/subscription events, only if you allow tracking (Section 9).

4. Appearance analysis — not biometric identification

This distinction matters, so we state it plainly: SkinRead analyses how your skin looks. It does not perform facial recognition, does not build a face template, and never uses your face data to identify you or match you against any person or database. Because the purpose is cosmetic appearance assessment rather than the unique identification of a person, we do not process your images as biometric data for identification purposes under Article 9 GDPR.

5. Legal basis for each purpose

  • Delivering the scan, the coach and transcription — Art. 6(1)(b) GDPR (performance of the contract you enter into by using the app).
  • Product analytics and service telemetry — Art. 6(1)(f) GDPR (our legitimate interest in a working, affordable and secure service). No photos, results, voice notes or coach messages are used for this.
  • Advertising attribution — Art. 6(1)(a) GDPR (your consent), given through Apple's App Tracking Transparency prompt and withdrawable at any time in iOS Settings.

6. Processors we use

  • Google (Google Gemini) — two purposes: (a) your selfie is sent to Gemini to produce your cosmetic analysis; (b) your coach messages are sent to Gemini to generate replies. See Google's Privacy Policy and the Gemini API terms.
  • Deepgram, Inc. — your voice notes are sent to Deepgram for transcription. See Deepgram's Privacy Policy.
  • TelemetryDeck — privacy-focused product analytics. It receives usage signals only — never your photos, scan results, voice notes or coach messages.
  • Supabase — hosts our processing proxy in the EU (Section 7).
  • Vercel — hosts this website.
  • Meta and TikTok — advertising attribution only, and only with your ATT consent (Section 9).

7. International transfers — stated accurately

Our processing proxy runs in the EU (Supabase, eu-north-1). That alone does not make this EU-only processing, and we will not imply that it does: Google and Deepgram are US processors. When you run a scan, use the coach or send a voice note, that content is transferred to and processed in the United States.

For those transfers we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework adequacy decision. You can request information about the safeguards applied by writing to nico@skinread.app.

8. Where your data lives

On your device. Your scan results, coach history and onboarding answers are stored locally on your device, not in an account on our servers. Images are sent for analysis and are not stored on our servers afterwards.

Our server-side telemetry contains no identifier of any kind — no user ID, no IP address, no device ID, and no hash of any of those. It records only token counts, latencies and status codes so we can monitor cost and reliability. It is kept for 30 days and then reduced to aggregate figures.

9. Advertising attribution (Meta & TikTok)

If we run ad campaigns, the Meta and TikTok SDKs receive limited install and subscription events plus advertising identifiers, purely to measure whether an ad worked. They never receive your photos, scan results, voice notes or coach messages.

This is gated by Apple's App Tracking Transparency prompt: if you decline, the sharing is disabled. Attribution is not active until we begin advertising. See Meta's Privacy Policy and TikTok's Privacy Policy.

10. What we never do

  • We never sell your data.
  • Your photos, scan results, voice notes and coach messages are never used for advertising and are never shared with ad networks.
  • We never use your face data to identify you.

11. How long we keep things

  • Selfies — transmitted for analysis; not retained on our servers.
  • Scan results, coach history, onboarding answers — on your device until you delete them or remove the app.
  • Voice notes — transmitted for transcription; not retained on our servers.
  • Service telemetry — 30 days, then aggregated (and identifier-free throughout).
  • Product analytics — retained by TelemetryDeck under its own retention policy.
  • Attribution events — retained by Meta and TikTok under their own policies.

We cannot control, and do not guarantee, how long Google, Deepgram, Meta or TikTok retain data sent to them, and we cannot delete provider-held data on your behalf.

12. Your rights

Under the GDPR you have the right to:

  • access your personal data (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure (Art. 17) — see Data deletion;
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • objection to processing based on legitimate interests (Art. 21);
  • withdrawal of consent at any time, without affecting processing already carried out.

To exercise any of these, email nico@skinread.app. We respond within one month (Art. 12(3) GDPR). Because the app has no accounts, we often hold nothing that can be linked to you — where that is the case we will say so and explain what is technically possible.

You also have the right to complain to a supervisory authority. Ours is:

Supervisory authority
Die Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen), Prinzenstraße 5, 30159 Hannover, Germany

13. Consent in the app

Before your first scan the app tells you, in plain language, that your selfie is sent to Google Gemini and your voice notes to Deepgram, and asks you to agree. You can decline, and you can stop using a feature or delete your data at any time.

14. This website

This website sets no cookies and runs no tracking or analytics. Fonts are served from our own domain, so loading these pages makes no requests to third-party servers and sends your IP address to no one but our host. The site is hosted by Vercel, which processes server logs in order to deliver the pages.

15. Children

SkinRead is not directed to children. You must be at least 16 years old to use the app, and we do not knowingly collect data from anyone under that age.

16. Changes

We may update this policy. Material changes will be communicated in the app or by other appropriate means, and the “last updated” date above will change.

17. Contact

Questions about privacy? Email nico@skinread.app or write to Speakwise GmbH, Kollage 3, 49170 Hagen a.T.W., Germany.