Legal

Privacy Policy

Last updated: August 11, 2026

HairGenie ("we", "us", and "our") respects your privacy. This Privacy Policy explains what data we collect, how we use it, where it is processed, and the choices available to you when using the HairGenie iOS app.

1. Data we collect

We may collect the following data:

  • Account information: your Apple sign-in account identifier and, where Apple provides it, your email address.
  • Face data and photos: selfies or photos you choose or capture that visibly contain a face, plus a limited result indicating whether the image contains one clear face suitable for hairstyle editing. If you separately allow Stylist Matching, this also includes your face shape, current hair length, hair density, and whether you have a beard.
  • Generated results: the AI-generated hairstyle, hair color, beard, bald, or makeup preview returned to your device.
  • Purchase and credit information: subscriptions, credit packs, entitlement status, credit balance, transactions, and renewal information.
  • App activity and diagnostics: style selections, generation events, saved or shared result events, paywall views, screen views, device type, app version, operating system, crash, and performance information.
  • Push notification tokens: if you allow notifications, we store a push token for that app installation against your account. It identifies the app installation, not you personally.

2. Face data and photos

"Face data" means a selfie or photo that visibly contains a person's face, as well as the limited result of our automated check that confirms whether the image contains one clear face suitable for hairstyle editing. If you separately allow Stylist Matching, it also includes the face shape, current hair length, hair density, and beard presence read from the photo.

We use face data only to:

  • Confirm that the submitted image contains one clear face suitable for editing.
  • With your separate permission, read your face shape, current hair length, hair density, and whether you have a beard so HairGenie can rank hairstyles for you.
  • Create the hairstyle, hair color, beard, bald, or makeup preview you specifically request.
  • Return the requested preview to your device.

HairGenie does not use face data to identify you, perform facial recognition, create biometric templates, or determine identity. We do not use your photos or face data to train our own AI models.

Stylist Matching (face analysis)

With your separate permission, HairGenie sends your photo to OpenAI to read four attributes: your face shape, current hair length, hair density, and whether you have a beard. The photo is used only to read those four things. HairGenie does not keep the photo, add it to your history, or use it to train anything.

The four results are kept only on your device, not on our servers, and are deleted when you sign out or withdraw permission. We never show you a conclusion about your face. The results only change which styles are listed first.

This permission is separate from permission to create style previews. If you decline it, everything else in the app continues to work normally. You can withdraw permission at any time in Settings.

3. How face data is shared and stored

Your selected photo is transmitted securely to our Supabase backend, which processes the request, and to OpenAI, which performs the clear-face suitability check, reads face shape, current hair length, hair density, and beard presence for Stylist Matching with your separate permission, and performs the requested AI image edit. Face data is shared only with these providers as needed to provide these features.

Face data is not shared with Apple for payments, RevenueCat for subscription management, or PostHog for analytics. We do not sell, rent, or use face data for advertising or cross-app tracking.

When you request a preview, your selfie is uploaded to HairGenie's private, Supabase-hosted storage so that generation can continue in the background even if you close the app. The generated result is written to that same private storage, and your device fetches it through a short-lived signed link rather than receiving the image directly in the generation response.

Storage is private and access-controlled: an account can read only its own images. If you choose to save a result, it is saved to your device's photo library and remains there until you delete it.

4. Face data retention

For Stylist Matching, HairGenie does not store the photo. The four analysis results remain only on your device and are deleted when you sign out or withdraw permission. When you create a style preview, the original selfie and generated result are stored privately and automatically deleted by a scheduled job no later than roughly 24 hours after the generation was created. Deleting your account immediately removes these stored preview images before the account itself is deleted.

HairGenie retains the non-image generation audit record indefinitely — the style, credit cost, time, and success status — because it supports the credit balance audit trail. That record contains no image or face data.

OpenAI may retain submitted content from the photo-processing purposes described above, including Stylist Matching image inputs and style-preview image inputs and outputs, in abuse monitoring logs for up to 30 days under its API data-retention controls. OpenAI API content is not used to train OpenAI models unless the customer explicitly opts in. You can read more in OpenAI's API data controls documentation.

Generated previews saved to your photo library are controlled by you and remain on your device until you delete them.

5. How we use other data

We use account, purchase, credit, activity, and diagnostic data to:

  • Create and manage your account.
  • Provide AI hairstyle generation and maintain your credit balance.
  • Process, validate, and restore purchases.
  • Provide customer support and respond to deletion requests.
  • Detect fraud, abuse, errors, crashes, and failed generation attempts.
  • Understand feature usage and improve app reliability.

6. Analytics

We use PostHog for product analytics and performance insights. Analytics may include events such as style selection, generation started or completed, generation errors, image saved or shared, paywall views, purchases, and screen views.

Analytics events do not include uploaded photos, generated images, or face data. HairGenie uses PostHog session replay to record how people move through the app — taps, screens, and navigation — so we can find where the app is confusing or broken. Replays are deliberately masked so they never capture your face data: your selfie while a preview is being generated, the generated result, and the saved images in your profile album are all blanked out in the recording, as is your account ID. We do not capture network request contents or console logs in replays.

We do not use analytics for third-party advertising or cross-app tracking.

7. Push notifications

If you allow notifications, HairGenie stores a push token for that installation against your account. The token identifies the app installation, not you personally.

We use it only to tell you that a hairstyle preview you requested finished while the app was closed or in the background. We never use it for marketing. Delivery goes through Expo's push service and then Apple Push Notification service (APNs). Notification text includes the style name and whether generation succeeded, but never an image.

One account may have tokens for several installs — an iPhone and an iPad, or a reinstall. We keep at most the five most recent tokens and automatically drop older ones. Turning notifications off in iOS Settings stops delivery, and deleting your account deletes the tokens.

8. Purchases and subscriptions

Purchases are processed by Apple through the App Store. We use RevenueCat to manage subscriptions, credit packs, purchase validation, entitlement status, and renewal information. RevenueCat may receive purchase-related information and your app user identifier so purchases can be restored and credits can be granted correctly.

9. Service providers

We use the following providers to operate HairGenie:

  • Apple: Sign in with Apple, App Store payments, and Apple Push Notification service (APNs).
  • Supabase: authentication, account records, credit balances, purchase metadata, and backend request processing.
  • OpenAI: clear-face suitability checks, Stylist Matching analysis of face shape, current hair length, hair density, and beard presence, and AI image editing.
  • RevenueCat: subscriptions and in-app purchase management. See its privacy policy.
  • PostHog: product analytics and performance insights. See its privacy policy.
  • Expo: push notification delivery.

10. Data retention

We retain account, purchase, credit, and transaction records only as long as necessary to provide the app, restore purchases, comply with legal obligations, prevent fraud, and resolve disputes.

If you delete your account, we delete your HairGenie account and associated account data, subject to records we must retain for legal, security, fraud-prevention, or accounting purposes. We may retain an email address solely to prevent repeated signup-credit abuse.

11. Your choices and rights

You can:

  • Delete your account and request deletion of associated personal data.
  • Request access to the personal data we hold about you.
  • Manage or cancel subscriptions through your Apple App Store account settings.
  • Manage camera and photo-library permissions in iOS Settings.
  • Delete photos and generated results saved in your device photo library.

You can delete your account in the app or contact us at waadrarii@gmail.com.

12. Camera and photo-library permissions

HairGenie requests camera access only when you choose to capture a selfie. It requests photo-library access only when you choose to upload a photo or save a generated result to your device.

13. Children

HairGenie is not directed to children under 13, and we do not knowingly collect personal data from children under 13.

14. Security and international processing

We use reasonable technical and organizational safeguards to protect data in transit and at rest. Your data may be processed in countries other than your own, depending on where our service providers operate.

15. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the date above and may provide notice in the app.

16. Contact

Questions or privacy requests? Contact waadrarii@gmail.com.