Home Privacy

Privacy

Last updated 15 August 2026 · written to be read, not to be survived

The short version

This website's free tools upload nothing — they have no server, and they work offline. In the iPhone app, a photo is sent for analysis, the result comes back, and the photo is deleted; five numbers and a timestamp are stored. Photos are never used to train anything. One tap deletes everything.

This website

What happens on skinlately.com
ThingWhat we collect
The two free tools (lighting check, before/after maker)Nothing. Your images are read into the browser tab, drawn on a canvas, and discarded when you close it. No upload, no account, no usage limit. Open the network panel and check: you will see our host's analytics beacon fire once when the page loads (see the Analytics row above) and then nothing — using the tool adds no requests at all, and the tool keeps working with the Wi-Fi off. Your images are never part of any request, because the tools have no server to send them to.
Your saved lighting spotTwo numbers and a date, in this browser's local storage on this device. Never transmitted. "Forget it" removes it.
The "email me the link" formThe email address you type, and which page you typed it on. Used once, to tell you the app has shipped. Not a newsletter, not sold, not shared. Reply to that email to be removed, or ask us at any time.
The interactive demoIt runs on sample data in your browser and stores its state locally so the flow works. No photo taken in the demo is uploaded — it is the same prototype code, which has no network calls at all.
AnalyticsOne, and we did not choose it. Our host (Cloudflare) injects its Web Analytics beacon into every page automatically — static.cloudflareinsights.com/beacon.min.js. It is cookie-free and does not follow you between sites; it records that a page was loaded, from roughly where, how fast, and what linked to it. We are trying to turn it off. Until we do, this row says it is there, because a privacy page that omits the one script on the page is worth nothing. We have added no analytics of our own.
CookiesNone — not by us, and the injected beacon does not set any either. No advertising, no tracking pixels. Apart from that one host-injected script, the site loads nothing from anywhere else: the fonts, the styles and the tool code are all served from this domain.

The reason the tools are built this way. "We do not look at your photos" is a promise. "There is no server to send them to" is a property of the software you can verify yourself in about thirty seconds. Those are different things and only one of them is worth anything from a stranger on the internet.

The iPhone app

The app does something the website does not: it sends a photo for analysis. That is worth being exact about.

What happens in the app
DataWhat happens to it
Your photoAnalysed and deleted. It is sent for the reading, the result comes back, and the image is discarded. It is not stored on our side, not kept in a queue, not backed up, and not used to train any model.
The original photoStays on your phone, in the app, so the before/after album works. It is yours; delete it whenever you like.
The five numbers and a timestampStored, because they are the trend. This is the only thing that persists off your device.
Your onboarding answersStored, to pick which of the daily actions you see.
ConsentYou are asked to agree to the photo being sent and deleted, explicitly, with a tap, before the first scan. Not pre-ticked, not buried in terms, and not bundled with anything else.
Your email or nameNot collected. There is no account.
DeletionSettings → Delete my data removes the local photos, the stored numbers and the profile. No copies are kept.
PaymentsHandled entirely by Apple. We never see a card number, and there is no other payment path.

Things we do not do

  • We do not sell, rent or share personal data. There is no advertising business here to feed one.
  • We do not build a face dataset, and we do not train on your photos.
  • We do not describe ourselves as HIPAA compliant. We are not a covered entity and claiming it would be misleading, which is why you will not find that phrase anywhere on this site.
  • We do not claim to be unhackable or "100% secure". Nobody can. What we can do is hold as little as possible, which is what the design above is for.

Your choices

Delete everything from Settings in the app, at any time, without asking us. For the website there is nothing to delete except a waitlist email, and one email to us removes that. If you are somewhere with a statutory right of access or erasure, the same address is the way to use it, and we will not make you prove anything unreasonable first.

Written in plain language on purpose. It describes what the software actually does; it is not legal advice, and a lawyer will review it before the app ships.