Home Privacy
Privacy
The short version
This website's free tools upload nothing — they have no server, and they work offline. In the iPhone app, a photo is sent for analysis, the result comes back, and the photo is deleted; five numbers and a timestamp are stored. Photos are never used to train anything. One tap deletes everything.
This website
| Thing | What we collect |
|---|---|
| The two photo tools (lighting check, before/after maker) | Nothing. Your images are read into the browser tab, drawn on a canvas, and discarded when you close it. No upload, no account, no usage limit. Open the network panel and check: the page load itself is not empty — this page, its stylesheet, two fonts, the tool's script, and our host's analytics beacon (see the Analytics row above) — but once it has loaded, using the tool adds nothing to that list, and the tool keeps working with the Wi-Fi off. Your images are never part of any request, because the tools have no server to send them to. |
| The routine test planner | Nothing, and this one does not even use local storage. It never asks for a photo. The boxes you tick live in the page while it is open and are gone the moment you reload it — the tool adds nothing to the network panel and works with the Wi-Fi off, the same as the two above. |
| Your saved lighting spot | Two numbers and a date, in this browser's local storage on this device. Never transmitted. "Forget it" removes it. |
| Any form on this site | There isn't one. There used to be an "email me the link" box on every page; it was removed on 15 August 2026 because the thing that received it was never built, so it always failed and then asked you to email us instead. Now the page just gives you the address. If you email hello@skinlately.com we have your address because you sent it to us — used once, to say the app shipped; not a newsletter, not sold, not shared; one reply removes you. |
| The interactive demo | It runs on sample data in your browser and stores its state locally so the flow works. No photo taken in the demo is uploaded — it is the same prototype code, which has no network calls at all. |
| Analytics | One, and we did not choose it. Our host (Cloudflare) injects its Web Analytics beacon into every page automatically — static.cloudflareinsights.com/beacon.min.js — and that script then sends what it measured to a second Cloudflare address, cloudflareinsights.com/cdn-cgi/rum. It is cookie-free and does not follow you between sites; it records that a page was loaded, from roughly where, how fast, and what linked to it. We are trying to turn it off. Until we do, this row names both addresses, because we only found the second one on 15 August 2026 by opening the site in a browser and reading the performance timeline — it is not in the page source, so a check that only reads the HTML will never see it. We have added no analytics of our own. |
| Cookies | None — not by us, and the injected beacon does not set any either. No advertising, no tracking pixels. Apart from that one host-injected script, the site loads nothing from anywhere else: the fonts, the styles and the tool code are all served from this domain. |
The reason the tools are built this way. "We do not look at your photos" is a promise. "There is no server to send them to" is a property of the software you can verify yourself in about thirty seconds. Those are different things and only one of them is worth anything from a stranger on the internet.
The iPhone app
The app does something the website does not: it sends a photo for analysis. That is worth being exact about.
| Data | What happens to it |
|---|---|
| Your photo | Analysed and deleted. It is sent for the reading, the result comes back, and the image is discarded. It is not stored on our side, not kept in a queue, not backed up, and not used to train any model. |
| The original photo | Stays on your phone, in the app, so the before/after album works. It is yours; delete it whenever you like. |
| The five numbers and a timestamp | Stored, because they are the trend. This is the only thing that persists off your device. |
| Your onboarding answers | Stored, to pick which of the daily actions you see. |
| Consent | You are asked to agree to the photo being sent and deleted, explicitly, with a tap, before the first scan. Not pre-ticked, not buried in terms, and not bundled with anything else. |
| Your email or name | Not collected. There is no account. |
| Deletion | Settings → Delete my data removes the local photos, the stored numbers and the profile. No copies are kept. |
| Payments | Handled entirely by Apple. We never see a card number, and there is no other payment path. |
Things we do not do
- We do not sell, rent or share personal data. There is no advertising business here to feed one.
- We do not build a face dataset, and we do not train on your photos.
- We do not describe ourselves as HIPAA compliant. We are not a covered entity and claiming it would be misleading, which is why you will not find that phrase anywhere on this site.
- We do not claim to be unhackable or "100% secure". Nobody can. What we can do is hold as little as possible, which is what the design above is for.
Your choices
Delete everything from Settings in the app, at any time, without asking us. The website collects nothing at all — there is no form on it, so there is nothing of yours for us to delete unless you have emailed us, and one email back removes that. If you are somewhere with a statutory right of access or erasure, the same address is the way to use it, and we will not make you prove anything unreasonable first.
Written in plain language on purpose. It describes what the software actually does; it is not legal advice, and a lawyer will review it before the app ships.