Privacy Policy
Last updated: 2026-08-08 Effective date: 2026-08-08
At a glance
| Topic | Summary |
|---|---|
| Who we are | Olga Leletko, a private entrepreneur registered in Ukraine, operating as SkinSpace |
| What we collect | Account info (email, optional name/avatar), an onboarding quiz about skin/health preferences, the products you check and save, subscription status, standard device/usage data, and app-install and campaign-interaction data used to measure our advertising |
| The headline privacy feature | Product-label photos are read on your device. We do not receive the photo — only the extracted product name and brand text — except for the optional missing-product-request flow described in Section 3.5 |
| Why we collect it | To run the app (scoring, your shelf, your scan history), to run your subscription, and to improve the product |
| Who we share it with | Specific categories of service providers — our backend platform provider, our subscription-management provider, our product-analytics provider, our email delivery provider, our website-hosting provider, and our attribution and marketing-measurement provider — plus Apple as an independent party for payment. We do not sell your personal information. To measure our ad campaigns, we share limited device and event data with the advertising platforms we advertise on; you can opt out — see Section 19.6 and Section 26 |
| Your choices | Access, correct, delete, or export your data; delete your account in-app. See Section 13 |
| Contact | support@skinspace.app |
This summary is for convenience only. The full policy below controls.
1. About this policy
This Privacy Policy explains how Olga Leletko, a private entrepreneur registered in Ukraine ("we," "us," or "SkinSpace") collects, uses, shares, and protects information about you when you use SkinSpace (the "App" or "Service"), our iOS app, and our website at skinspace.app.
SkinSpace helps you check cosmetic products before you buy them. You photograph a product's front label; your iPhone reads the text on the device; we look up the product and show you an ingredient safety score built from published safety data. SkinSpace does not scan faces or skin, and it never asks you to photograph or type an ingredient list.
This policy uses some defined terms in bold. Where we use a legal term of art (like "controller" or "sale"), we explain what it means in context.
This policy is a description of our practices, not a contract you accept by using the Service. Where the law requires your consent for a specific kind of processing (for example, GDPR consent under Article 6(1)(a) or 9(2)(a), or a marketing opt-in), we ask for that consent separately and you can withdraw it at any time. Where a feature is offered on the basis of a contract with you (for example, your Premium subscription), the relevant terms govern that feature.
2. Who we are
The controller of your personal information (or, for our California users, the "business") is:
Olga Leletko Private entrepreneur registered in Ukraine
You can reach our privacy team at support@skinspace.app. This is also our contact address for support requests and legal notices.
We do not have a Data Protection Officer — SkinSpace's data processing does not currently require one under GDPR Article 37 (we are not a public authority and do not carry out large-scale monitoring or large-scale special-category processing).
We are established in Ukraine. You can reach us on any privacy matter — including any question relating to EU or UK data protection — at support@skinspace.app.
3. The information we collect
We collect the categories below. Where a category is something you provide directly, we mark it "You give us." Where it's collected automatically, we mark it "Collected automatically."
3.1 Account and contact information (You give us)
When you create an account, we collect your email address, and optionally a display name and a profile avatar photo you choose to upload (stored in our file storage under a path scoped to your account). If you sign in with Apple and choose to hide your email, we store the private-relay address Apple assigns you and treat it the same as any other email address.
3.2 Authentication identifiers (You give us / From third parties)
You can create an account with Sign in with Apple, Sign in with Google, or email and password. Email/password accounts require you to verify your email before you can use most features.
- Sign in with Apple gives us a stable per-app identifier, your name (if you choose to share it), and an email address (which may be Apple's private-relay address).
- Sign in with Google gives us your Google account's identifier, name, email address, and profile photo.
We never receive your Apple ID or Google account password.
Onboarding itself does not require an account. You can complete the onboarding quiz and get a feel for the app before you sign up. An account is required either before your first product check or after your first purchase, depending on how we've configured the app at the time.
3.3 Onboarding quiz — skin and health-related preferences (You give us)
Before you create an account, SkinSpace asks a short quiz to personalize your scores and flags. This is the most sensitive information we collect, so we explain it in full here.
What we ask:
- Your age bracket (Under 18 / 18–24 / 25–29 / 30–34 / 35–44 / 45–49 / 50+ / Prefer not to say)
- A single primary goal: sensitive skin reactions, pregnancy caution, fragrance allergens, acne-prone products, cleaning up your routine, or comparing products before you buy
- Pain points and a watchlist you can select from a list: fragrance allergens, pregnancy caution, acne-prone skin, irritation risk, preservatives, sunscreen filters, retinoids, and environmental concerns
What this is, and what it is not. These are self-reported preferences, not a diagnosis, a medical record, or advice we act on clinically. We use your selections only as a signal to prioritize or flag ingredients in the products you check — for example, highlighting fragrance allergens if you've told us that's a concern. Selecting "pregnancy caution" does not tell us, and we do not infer, that you are pregnant; it only tells us you want that category of ingredient flagged.
Why we treat it carefully anyway. Some of these selections — particularly pregnancy caution, allergens, and acne-prone skin — touch on health-adjacent topics. Depending on your state of residence, this can qualify as "consumer health data" under laws like Washington's My Health My Data Act, even though it isn't a medical record. We explain the heightened handling we apply, and your specific rights, in Section 20.2 below. In short: we don't sell this information, we don't share it with anyone outside the service providers who run the app for us, and you can ask us to delete it at any time.
Where it's stored. Before you create an account, your quiz answers live only on your device (in local app storage). When you sign up, they are copied to your account record in our database so your preferences follow you across devices. Your quiz selections are also sent to our product-analytics provider — a service provider bound by contract to process data only on our instructions — as part of the usage information described in Section 3.10, so we can understand and improve the product. They are never sent to our attribution and marketing-measurement provider and are never used for advertising.
Changing or deleting it. You can update your preferences at any time in the app, and deleting your account deletes this data along with the rest of your profile (see Section 18).
3.4 Disclaimer acknowledgment (You give us)
Before you use scoring features, we ask you to confirm you've read a short disclaimer: that SkinSpace's scores and flags are based on published ingredient safety data and research — not on you or your skin specifically — and that SkinSpace is not medical advice. We record that you accepted this (and which version, and when), bundled with your acceptance of this Privacy Policy and our Terms of Use.
3.5 Label photos (processed on your device)
This is the core of how SkinSpace protects your privacy, so we want to be plain about it.
When you check a product, you photograph its front label. That photo is processed entirely on your device. SkinSpace does not upload the photo to our servers, and we do not receive it, as part of an ordinary product check. Only the text we extract from the label on your device — typically the product name and brand — is sent to our backend so we can look up (or add) the product.
SkinSpace does not scan faces or skin. It has no selfie feature, does not collect biometric data, and never asks you to photograph or type an ingredient list — ingredient data comes from our own research, not from you.
Planned feature — missing-product requests. If SkinSpace can't find a product you've scanned, we plan to let you submit a "missing product" request so our team can add it. When you do, we will receive the extracted product text as usual, and we may also receive the label photo itself, along with your account identifier. This feature is not live at the time of this policy's effective date; we're disclosing it now so the policy stays accurate the moment it ships. Label photos submitted this way depict a product's packaging, not a person, and we do not use them for anything other than adding the product to our catalog.
3.6 Scan activity and your shelf (You give us / Collected automatically)
Once you have an account, we store:
- The products you've checked, and when (needed to enforce the monthly allowance described in Section 3.7)
- Your shelf — the products you've chosen to save
- Any missing-product requests you submit (see 3.5), including your account identifier
3.7 Subscription and purchase information (You give us / From third parties)
SkinSpace Premium is sold through Apple's in-app purchase system. Apple is the merchant of record and processes your payment — we never receive your card number or bank details.
We use our subscription-management provider (a specialized service provider bound by contract to process data only on our instructions) to manage entitlements. It assigns your device an anonymous app-user ID before you sign up, and links it to your account's user ID after you sign in or create an account. Our subscription-management provider and our own backend receive your purchase and subscription status (e.g., which tier, renewal date, whether a payment failed) — not your payment details.
On allowances: the free tier includes a limited monthly allowance of product checks; SkinSpace Premium includes an increased monthly allowance. We don't print exact numbers here because they can change — the current allowances are always shown in the app and on the purchase screen. If we ever reduce a paying subscriber's allowance mid-term, we will give notice and the right to cancel before the reduction applies to that subscriber.
There is no free trial — a Premium purchase is billed immediately upon confirmation through Apple.
3.8 Communications and email (You give us / Collected automatically)
We use our email delivery provider (a specialized service provider bound by contract to process data only on our instructions) to send:
- Transactional emails — email verification, and lifecycle messages tied to your subscription status (e.g., purchase confirmation, cancellation, expiration, a billing problem, or renewal), triggered by events from our subscription-management provider and the app itself (such as your email being verified or a product check completed).
- Marketing/seasonal emails — roughly six times a year, sent to segments (free, Premium, or churned) that our email delivery provider maintains for us. You can unsubscribe at any time; we maintain a single suppression list so an unsubscribe applies going forward.
3.9 Device and technical information (Collected automatically)
When you use the Service we collect:
- Device and OS information — device model, operating system and version, app version, locale, time zone
- Network information — IP address (captured in ordinary backend and website server logs)
- App diagnostics — SkinSpace does not currently use a dedicated crash-reporting SDK; if we add one before launch, we will update this policy and the associated App Privacy Details before shipping it.
3.10 Usage information (Collected automatically)
We use our product-analytics provider (a specialized service provider bound by contract to process data only on our instructions; a dedicated SkinSpace analytics project, separate from any other product we operate) to understand how the app and website are used. Our product-analytics provider receives a pseudonymous device/person identifier, the screen and action events we instrument in the app (for example, "completed onboarding," "checked a product"), your onboarding quiz selections (see Section 3.3), and pageview/page-leave events on the website. On the website, our analytics are configured so that visitors remain anonymous unless and until they take an identifying action, at which point a profile is created.
3.11 Cookies and similar technologies (Collected automatically — website only)
Our website uses our product-analytics provider, which sets cookies/local storage to distinguish visitors. See Section 16 for details and a known gap we're closing before launch.
3.12 What we do NOT collect
We think it's just as important to tell you what we don't do:
- No face, skin, or selfie photos, and no biometric data of any kind
- No precise location, no access to your contacts, no microphone access
- No third-party ads shown inside the app, and no advertising profiles built from your quiz answers, scan history, or shelf
- No push notifications at launch (we may add these later; if we do, we'll update this policy first)
- We do not use your data to train any AI model
- We do not sell your personal information. We do use an attribution and marketing-measurement provider to measure our own ad campaigns (see Section 3.14); to the extent that involves "sharing" limited device and event data with advertising platforms, you can opt out (Section 19.6)
3.13 A note on ingredient scores and AI
SkinSpace's ingredient safety scores are generated from published ingredient safety data and research — no AI model ever computes or influences a score. We use automated tools, including AI, only to research public product information and to write plain-English summaries of already-computed scores; these tools work on public data and never receive your personal information.
3.14 Advertising attribution and campaign measurement (Collected automatically)
We use an attribution and marketing-measurement provider (a specialized service provider bound by contract to process data only on our instructions) to measure the performance of our advertising campaigns — for example, to understand which ads lead to app installs and subscriptions.
This provider receives device and app-install information, subscription and purchase events, and campaign interaction data. It never receives your onboarding quiz answers, your scan history, your shelf, or any health-adjacent preference data.
Where required by Apple's App Tracking Transparency framework, we ask your permission before any tracking as Apple defines it. If you decline, attribution is limited to aggregate, privacy-preserving measurement. Some of this measurement involves exchanging limited device and event data with the advertising platforms we advertise on; depending on where you live, this can qualify as "sharing" for cross-context behavioral advertising, and you can opt out — see Section 19.5, Section 19.6, and Section 26.
4. How we collect information
We collect information:
- Directly from you — when you complete onboarding, register, upload an avatar, submit a missing-product request, or contact support.
- Automatically — through on-device label reading (the photo never leaves your device), our product-analytics provider, our subscription-management provider, and our attribution and marketing-measurement provider.
- From third parties — when you sign in with Apple or Google, or when Apple delivers a purchase/subscription event to our subscription-management provider.
5. How we use information (purposes of processing)
| Purpose | What this means | Categories of data used |
|---|---|---|
| Provide the Service | Create your account, run product checks, maintain your shelf and scan history | Account info, quiz preferences, scan activity, device info |
| Process transactions | Manage your subscription and entitlement via Apple and our subscription-management provider | Subscription status, account ID |
| Customer support | Respond to questions and troubleshoot | Support correspondence, account info |
| Improve and develop the Service | Understand feature usage, fix bugs, plan improvements | Usage data collected via our product-analytics provider, device info |
| Personalize scoring | Prioritize or flag ingredients relevant to your stated preferences | Onboarding quiz data |
| Security and fraud prevention | Detect and prevent abuse of the free/Premium allowance system | Account info, scan activity, device info |
| Communicate with you | Send verification, lifecycle, and (with opt-out available) seasonal marketing emails | Email address, subscription status, engagement data |
| Measure our advertising | Understand which ad campaigns lead to installs and subscriptions | Device and app-install information, subscription/purchase events, campaign interaction data |
| Comply with law | Respond to lawful requests, enforce our Terms, defend legal claims | Any category as required |
Beyond the advertising-measurement purpose described above, we do not use your information for advertising, and we never use your onboarding quiz answers, scan history, or shelf for any advertising purpose.
6. Legal bases for processing (EEA, UK, Switzerland)
If you are in the EEA, UK, or Switzerland, we rely on the following lawful bases under GDPR Article 6 (and the equivalent UK GDPR / Swiss revFADP provisions):
| Purpose | Lawful basis |
|---|---|
| Providing the core Service (account, scans, shelf) | Contract (Art. 6(1)(b)) |
| Processing your subscription | Contract (Art. 6(1)(b)) |
| Onboarding quiz personalization | Consent (Art. 6(1)(a)) — completing the quiz is optional context you choose to give us, and you can change or delete it at any time |
| Customer support | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Analytics and product improvement | Legitimate interests (Art. 6(1)(f)) in operating and improving SkinSpace, balanced against your privacy |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Seasonal marketing email | Consent (Art. 6(1)(a)) where required, or legitimate interests for service-adjacent messages with an opt-out |
| Advertising campaign measurement | Legitimate interests (Art. 6(1)(f)) in measuring and improving our advertising, and consent where required (for example, tracking permission under Apple's App Tracking Transparency framework) |
| Compliance with law | Legal obligation (Art. 6(1)(c)) |
You have the right to object to processing based on legitimate interests, and to withdraw consent at any time — see Section 13.
7. How we share information
We share information only in the ways described below. We do not sell your personal information. To measure our advertising campaigns, we share limited device and event data with our attribution and marketing-measurement provider and with the advertising platforms we advertise on; where applicable law treats this as "sharing" for cross-context behavioral advertising, you have the right to opt out — see Section 19.5 and Section 19.6.
7.1 With our service providers (processors)
We use the categories of service providers described in Section 8 to run the app. They are bound by contract to use your data only to provide services to us, not for their own purposes.
7.2 With Apple, as an independent party
Apple processes your subscription payment as the App Store merchant of record, and operates Sign in with Apple. Apple acts independently, under its own privacy policy, for these functions — see Section 8.
7.3 In connection with corporate transactions
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you (via email or in-app notice) before your information becomes subject to a different privacy policy.
7.4 For legal reasons
We may disclose information if we believe in good faith it's necessary to comply with law or legal process, enforce our Terms, detect or prevent fraud or security issues, or protect the rights, property, or safety of us, our users, or the public. Where lawful and reasonable, we will notify you before disclosing your information in response to a legal request.
7.5 With your consent
We may share information with third parties when you direct us to or otherwise consent.
7.6 With advertising platforms, for ad measurement
Our attribution and marketing-measurement provider processes device and app-install information, subscription/purchase events, and campaign interaction data on our behalf, and limited device and event data is exchanged with the advertising platforms we advertise on so we can measure which campaigns work. Advertising platforms act as independent parties for this measurement. Your onboarding quiz answers, scan history, shelf, and any health-adjacent preference data are never included. You can opt out — see Section 19.6 and Section 26.
8. Third-party services and SDKs we use
We disclose every category of service provider we use — this is a deliberate choice so you know exactly what kind of party touches your data and why. We describe these providers by function rather than by brand name; each is a specialized service provider bound by contract to process data only on our instructions.
| Category | Role | Data shared | Classification |
|---|---|---|---|
| Our backend platform provider | Backend database, authentication, and file storage | Account/profile data, onboarding quiz answers, scan history, shelf, avatar photos | Service provider / processor |
| Our subscription-management provider | Subscription and entitlement management | Anonymous/authenticated app-user ID, purchase and subscription status | Service provider / processor |
| Our product-analytics provider | Product analytics (app and website) | Pseudonymous device/person identifier, usage events, onboarding quiz answers, website pageviews | Service provider / processor |
| Our email delivery provider | Transactional and marketing email delivery | Email address, subscriber segment, message engagement | Service provider / processor |
| Our attribution and marketing-measurement provider | Measurement and attribution of our advertising campaigns | Device and app-install information, subscription/purchase events, campaign interaction data | Service provider / processor (limited device/event data also exchanged with advertising platforms — see Section 7.6) |
| Apple | App Store payment processing, Sign in with Apple, and the platform itself | Payment/App Store account details, Sign in with Apple identifiers | Independent party (not our processor) — see https://www.apple.com/legal/privacy/ |
| Our website-hosting provider | Hosting for our website (and, where used, backend infrastructure) | IP addresses and standard server logs | Sub-processor |
We maintain a current list of our named service providers and will provide it on request at support@skinspace.app. We update this policy before adding any new category of provider.
We do not currently use Google Play services (SkinSpace is iOS-only).
Our ingredient research (public data sources and AI infrastructure used only for that research) processes public product and web information, never your personal data — we mention it for transparency, but it is not a recipient of information about you.
9. Analytics
We use our product-analytics provider, described in Section 8, to understand how the app and website are used so we can improve them. We have not enabled advertising features with our product-analytics provider, and our product-analytics provider does not use SkinSpace data for its own advertising purposes.
SkinSpace shows no third-party ads inside the app. We do use an attribution and marketing-measurement provider to measure the performance of our own advertising campaigns, as described in Section 3.14. Where required by Apple's App Tracking Transparency framework, we ask your permission before any tracking as Apple defines it; if you decline, attribution is limited to aggregate, privacy-preserving measurement.
10. International data transfers
We are based in Ukraine. Your information may be stored and processed outside your country of residence — including in the United States — in any country where we or our service providers listed in Section 8 maintain facilities.
When we transfer personal information from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on:
- Standard Contractual Clauses approved by the European Commission (and, for UK transfers, the UK International Data Transfer Addendum)
- The EU-US Data Privacy Framework (and its UK and Swiss extensions), for participating US-based providers
- Derogations under GDPR Article 49 where applicable (for example, transfer necessary for performance of our contract with you)
You can request a copy of the safeguards we use for a particular transfer by contacting us at support@skinspace.app.
11. How long we keep information (retention)
| Category | Retention period |
|---|---|
| Account information | While your account is active, then deleted within 30 days of account deletion |
| Onboarding quiz preferences | Same as account information; deleted with your account, or sooner if you clear your preferences in-app |
| Scan history and shelf | Same as account information |
| Missing-product request photos/text | Retained until the product has been added to our catalog or the request is closed, then deleted or anonymized |
| Subscription and transaction records | At least 7 years, to meet tax, accounting, and consumer-protection requirements |
| Support correspondence | Up to 3 years for service quality and dispute resolution |
| Backend and website server logs | Up to 90 days |
| Backups | Rotated and overwritten within 90 days |
When we no longer need information, we delete or anonymize it. Anonymized information that can no longer be linked to you may be kept indefinitely for analytical purposes.
12. Information security
We use industry-standard administrative, technical, and physical safeguards, including:
- Encryption in transit (TLS 1.2 or higher) and at rest
- Access controls and authentication on our internal systems
- Logging and monitoring of access to user data
No system is perfectly secure. If we become aware that your personal information has been compromised in a way that creates a risk to you, we will notify you and the relevant regulators as required by law (within 72 hours of becoming aware, under GDPR).
13. Your rights and choices
At a minimum, we offer everyone:
- Access — a copy of the information we hold about you
- Correction — fix inaccurate information
- Deletion — delete your information, including via in-app account deletion (Profile → Delete Account)
- Opt out of marketing — unsubscribe using the link in any marketing email
- Withdraw consent — where we rely on your consent (for example, the onboarding quiz), withdraw it at any time without affecting processing that already happened
13.1 How to exercise your rights
Email us at support@skinspace.app. We may need to verify your identity before responding — we will ask only for the minimum information necessary (typically, the email address on your account).
We will respond within the timeframes required by applicable law (generally within 30 days under GDPR, within 45 days under CCPA, each with one allowable extension).
Region-specific rights are described in Sections 19–25.
13.2 Right to lodge a complaint
You can complain to your local data-protection authority if you believe we have violated your privacy rights. We'd appreciate the chance to address your concern first at support@skinspace.app.
14. Children's privacy
This is a decision the SkinSpace team should confirm before launch, not treat as settled. We currently set the minimum age at 13, for one specific reason: onboarding includes an "Under 18" age bracket, meaning the product is designed to be usable by teenagers researching acne-prone skincare — an 18+ gate would directly contradict that use case. If that product decision changes, this section must change with it.
SkinSpace is not directed to children under 13, and we do not knowingly collect personal information from anyone under that age. If you are under 13, please do not use SkinSpace. If you are a parent or guardian and believe we've collected personal information from your child under 13, contact us at support@skinspace.app and we will delete it promptly.
For users between 13 and 18: where we rely on consent (for example, the onboarding quiz), the age of digital consent for that consent to be valid without parental involvement varies by law — 13 in the US and UK, 13–16 depending on the EU member state, 14 in South Korea, 16 in Brazil for sensitive data, and 18 in India. We do not knowingly process the personal information of users below the digital age of consent in their jurisdiction without appropriate parental consent, and we rely on the age bracket you self-report during onboarding as our signal.
California residents under 16: We do not sell personal information, and we do not knowingly "share" the personal information of consumers under 16 for cross-context behavioral advertising without the opt-in consent California law requires. See Section 19.5.
15. Automated decision-making and profiling
SkinSpace's ingredient safety scores are computed from published ingredient safety data and hazard classifications — not by a machine-learning model, and not personalized to any inference we've drawn about you beyond the preferences you told us in onboarding. We do not use scores or flags to make any decision that has a legal or similarly significant effect on you, and we do not build advertising profiles from your quiz answers, scan history, or shelf.
Because there is no automated decision-making with legal or significant effects, this section is intentionally short. If that changes, we will update this policy and describe the logic, its consequences, and how to contest it.
16. Cookies and similar technologies
Our website at skinspace.app uses our product-analytics provider, which sets cookies/local storage to distinguish visitors and record pageviews and page-leaves.
| Cookie / technology | Type | Purpose | Provider | Duration |
|---|---|---|---|---|
| Analytics distinct-ID cookie/local storage | Analytics | Distinguish visitors, measure pageviews | Our product-analytics provider | Per provider's default retention |
Known gap, being closed before launch: our website currently runs our product-analytics provider without a cookie-consent banner. Under the EU ePrivacy Directive, prior consent is required before setting analytics cookies for EU/EEA/UK visitors. We are treating this as a pre-launch blocker — see the companion checklist. Until a consent mechanism is live, EU/EEA/UK visitors should assume analytics cookies are set on first visit.
You can also manage cookies in your browser settings; disabling them may affect site functionality.
17. Push notifications and in-app messages
SkinSpace does not currently send push notifications — there is no push SDK integrated (no APNs registration) at this policy's effective date. If we add push notifications later, we will update this policy first and describe the provider, the data it receives, and how to opt out.
18. Account creation and deletion
You can create an account via Sign in with Apple, Sign in with Google, or email and password. You can delete your account at any time from within the app: Profile → Delete Account.
When you delete your account:
- Your account is deactivated immediately
- Your account record, avatar, shelf, quiz preferences, and profile row held by our backend platform provider are deleted
- Your customer record held by our subscription-management provider is deleted
- Your personal information is removed from our production systems within 30 days, and backups are overwritten within 90 days
- Some information may be retained longer where required by law (for example, transaction records for tax purposes) or in fully anonymized form for analytics
19. Notice to California residents (CCPA/CPRA, CalOPPA, Shine the Light)
This section supplements the rest of the policy and applies if you are a California resident.
19.1 Categories of personal information collected (12-month look-back)
| Category | Examples | Collected? |
|---|---|---|
| A — Identifiers | Email, account ID, IP address | Yes |
| B — Cal. Civ. Code § 1798.80(e) categories | Name (optional), email | Yes |
| C — Protected classification characteristics | Age bracket (self-reported, broad ranges only) | Yes |
| D — Commercial information | Subscription tier, purchase/renewal status | Yes |
| E — Biometric information | — | No |
| F — Internet or electronic network activity | In-app usage events, website pageviews, ad campaign interaction data | Yes |
| G — Geolocation data | — | No (we do not collect precise or coarse location) |
| H — Sensory data | Optional profile avatar photo you upload; product label photo processed on-device (not received by us in the ordinary flow) | Yes (avatar); Conditional (label photo, only via the missing-product-request flow described in Section 3.5) |
| I — Professional or employment-related information | — | No |
| J — Education information (non-public) | — | No |
| K — Inferences from any of the above | Ingredient-relevance flags derived from your stated onboarding preferences | Yes |
| L — Sensitive personal information | See § 19.2 below | Yes |
19.2 Sensitive personal information
We collect the following categories of sensitive personal information, as defined in Cal. Civ. Code § 1798.140(ae):
- Personal information concerning health — specifically, your self-reported onboarding preferences relating to pregnancy caution, allergens, and acne-prone skin (see Section 3.3 for the full, honest description — these are preference signals, not medical records)
- Account log-in credentials (a hashed password, if you use email/password sign-in)
We use sensitive personal information only for purposes permitted by Cal. Code Regs. tit. 11 § 7027(m) — namely, to perform the personalization service you asked for, to verify and improve the quality of the Service, to prevent security incidents, and to comply with law. We do not use it for any other purpose, so we do not need to offer the "Limit the Use of My Sensitive Personal Information" right beyond what's already true: we don't use it more broadly than described here.
19.3 Sources of personal information
We collect personal information from:
- You directly (onboarding, registration, uploads, support requests)
- Automatically (our product-analytics provider, backend logs)
- Third parties (Apple and Google, when you sign in with them; Apple, when it reports a purchase to our subscription-management provider)
19.4 Business and commercial purposes for collection
See Section 5.
19.5 Sale and sharing of personal information
We do not sell your personal information, as "sell" is defined in Cal. Civ. Code § 1798.140(ad). We may "share" limited personal information for cross-context behavioral advertising as defined in § 1798.140(ah): to measure our advertising campaigns, device and event data is disclosed to our attribution and marketing-measurement provider and to the advertising platforms we advertise on. You have the right to opt out of this sharing — see Section 19.6. We walk each recipient individually, not by asserting boilerplate:
| Category | Recipient | Purpose | "Sale" / "Share"? |
|---|---|---|---|
| Account, quiz, scan, avatar data | Our backend platform provider | Backend/database/storage under service-provider contract | Not a sale/share |
| Purchase/subscription status | Our subscription-management provider | Entitlement management under service-provider contract | Not a sale/share |
| Usage events, pageviews, onboarding quiz answers | Our product-analytics provider | Product analytics under service-provider contract, no advertising features enabled | Not a sale/share |
| Email address, engagement | Our email delivery provider | Transactional and marketing email under service-provider contract | Not a sale/share |
| Device/app-install information, subscription/purchase events, campaign interactions | Our attribution and marketing-measurement provider and the advertising platforms we advertise on | Measurement of our ad campaigns | Not a sale; may be a "share" — you can opt out (Section 19.6) |
| Payment/App Store account data | Apple | Payment processing, independent controller — but not for Apple's own advertising use of your SkinSpace data | Not a sale/share |
| Server logs | Our website-hosting provider | Hosting infrastructure, sub-processor | Not a sale/share |
We do not sell the personal information of any consumer, and we do not knowingly share the personal information of consumers under 16 without the opt-in consent required by Cal. Civ. Code § 1798.120(c).
19.6 Your California rights
You have the right to know, delete, correct, opt out of the sale or sharing of your personal information, limit use of sensitive personal information, non-discrimination for exercising these rights, and data portability. We do not sell personal information; to opt out of the "sharing" described in Section 19.5, email support@skinspace.app with the subject "Do Not Sell or Share My Personal Information", or use the in-app privacy control where available. On our website, we also honor the Global Privacy Control signal as an opt-out — see Section 26. To exercise any of these rights, contact us as described in Section 13. We will respond within 45 days, with one allowable 45-day extension (opt-out requests are honored within 15 business days).
19.7 CalOPPA — Do Not Track
See Section 26.
19.8 California "Shine the Light" (Cal. Civ. Code § 1798.83)
We do not share your personal information with third parties for those third parties' own direct-marketing purposes. If you'd still like to make a Shine the Light request, email support@skinspace.app with the subject "California Shine the Light Request."
20. Notice to other US state residents
If you live in a state with a comprehensive privacy law, you have additional rights under that law. Your state's law controls the exact procedures.
If you live in Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Hampshire, Nebraska, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, or Florida, you have the right to know/access, delete, correct, and obtain a portable copy of your personal data, and to opt out of the sale of personal data, targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects.
If you live in Utah or Iowa, you have the right to know/access, delete, and obtain a portable copy of your personal data, and to opt out of the sale of personal data (and, in Utah, targeted advertising). These states do not provide a statutory right to correction.
We honor universal opt-out mechanisms (such as Global Privacy Control) in the states whose laws require it — see Section 26.
As with California, we do not sell personal data in any of these states. Our use of an attribution and marketing-measurement provider to measure our own ad campaigns (Section 3.14) may qualify as processing for targeted advertising under some of these laws; you can opt out by emailing support@skinspace.app with the subject "Targeted Advertising Opt-Out", by using the in-app privacy control where available, or (on our website) via a Global Privacy Control signal.
To exercise any of these rights, contact us as described in Section 13. We will respond within 45 days, with one 45-day extension if reasonably necessary. Where your state's law provides an appeal right, you may appeal a denial and we will include appeal instructions in our response.
20.1 Texas-specific notice (TDPSA § 541.102(b))
We do not sell sensitive or biometric personal data, so the Texas point-of-collection notice requirement does not apply.
20.2 Washington My Health My Data Act
This sub-section is also our Consumer Health Data Privacy Policy for purposes of the Washington My Health My Data Act (Wash. Rev. Code § 19.373.030).
Whether MHMDA applies, honestly stated. SkinSpace's onboarding quiz asks about pregnancy caution, allergens, and acne-prone skin as preference signals, not diagnoses or symptoms. We are not certain these selections meet the statutory definition of "consumer health data," and we are not a clinical or fertility app of the kind Washington's Attorney General has targeted so far. We are treating this section as applicable anyway, out of caution, because the statutory definition is broad and includes inferences derived from non-health information used to identify consumer health data.
- Categories of consumer health data we collect: your self-reported goal and pain-point/watchlist selections from onboarding (pregnancy caution, allergens, acne-prone skin, and related categories described in Section 3.3)
- Sources: directly from you, during onboarding
- Categories of consumer health data shared: none sold, none shared with advertising or attribution providers, and none used for advertising; shared only with our processors under contract — our backend platform provider (database, to run the app) and our product-analytics provider (product-improvement analytics only)
- Categories of third parties with whom we share consumer health data: our backend platform provider and our product-analytics provider (processors only) — no independent third parties, and never our attribution and marketing-measurement provider
- How to exercise your rights: as described in Section 13, plus the right to withdraw consent and the right to have your consumer health data deleted from our records and those of our processors (our backend platform provider and our product-analytics provider)
We do not collect, use, or store geofencing data within 2,000 feet of any in-person healthcare service location, for any purpose — SkinSpace does not collect location data at all.
20.3 Nevada (Nev. Rev. Stat. § 603A)
We do not sell covered information. If you'd like to submit an opt-out request anyway, email support@skinspace.app with the subject "Nevada Opt-Out."
21. Notice to EEA, UK, and Swiss residents (GDPR / UK GDPR / revFADP)
If you are in the European Economic Area, the United Kingdom, or Switzerland, this section explains your rights.
21.1 Controller
The controller of your personal information is Olga Leletko, a private entrepreneur registered in Ukraine. See Section 2.
21.2 Your rights
Subject to certain limitations, you have the right to:
- Access your personal information (Art. 15)
- Rectify inaccurate or incomplete information (Art. 16)
- Erasure (Art. 17) — the "right to be forgotten"
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on our legitimate interests (Art. 21)
- Withdraw consent at any time (Art. 7(3))
- Lodge a complaint with your local supervisory authority (Art. 77) — a list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en
21.3 Lawful bases
See Section 6.
21.4 International transfers
See Section 10.
21.5 UK-specific notes
UK residents can lodge complaints with the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.
21.6 Swiss-specific notes
Swiss residents can lodge complaints with the Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch/.
22. Notice to Brazilian residents (LGPD)
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018) applies. You have the right to confirm the existence of processing, access your data, correct it, anonymize/block/delete unnecessary data, request portability, revoke consent, and get information about who we've shared your data with. To exercise these rights, contact support@skinspace.app. You can lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at https://www.gov.br/anpd/.
23. Notice to Canadian residents (PIPEDA + Quebec Law 25)
If you are in Canada, PIPEDA and, if you are in Quebec, Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25) apply. You have the right to access your personal information, request correction, and withdraw consent. You may lodge a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/ or, in Quebec, the Commission d'accès à l'information du Québec at https://www.cai.gouv.qc.ca/.
Quebec residents also have the right to data portability and to be informed of automated decisions affecting them (see Section 15 — SkinSpace's scoring is not automated decision-making with legal effects, but we describe it there anyway for transparency).
24. Notice to Australian residents (Privacy Act 1988)
If you are in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply. You can request access to and correction of your personal information by contacting support@skinspace.app. Complaints can be lodged with the Office of the Australian Information Commissioner at https://www.oaic.gov.au/.
25. Notice to other jurisdictions
The rights and procedures in Section 13 are available globally. In particular:
- New Zealand — Privacy Act 2020 — Office of the Privacy Commissioner (https://www.privacy.org.nz/)
- Japan — APPI — Personal Information Protection Commission (https://www.ppc.go.jp/en/)
- South Korea — PIPA — Personal Information Protection Commission (https://www.pipc.go.kr/eng/)
- China — PIPL — separate consent required for cross-border transfers; complaints to the Cyberspace Administration of China
- India — DPDPA — complaints to the Data Protection Board of India
- South Africa — POPIA — complaints to the Information Regulator (https://inforegulator.org.za/)
- UAE — PDPL — complaints to the UAE Data Office
- Saudi Arabia — PDPL — complaints to the Saudi Data and AI Authority (SDAIA)
26. Do Not Track and Global Privacy Control
Do Not Track (DNT): Because there is no industry consensus on how to respond to DNT signals, we do not respond to them at this time.
Global Privacy Control (GPC): Our website honors the Global Privacy Control signal as a valid opt-out of the sale or sharing of personal information under California, Colorado, Connecticut, and other state laws. Because we do not sell personal information, a GPC signal operates as an opt-out of the "sharing" for ad measurement described in Section 19.5.
27. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. For material changes, we will give you notice through the Service (an in-app notice or email) before the change takes effect. Your continued use of the Service after the change becomes effective constitutes acceptance of the updated policy.
A history of prior versions is available on request.
28. How to contact us
For any privacy question, request, or complaint, please contact us:
- Email: support@skinspace.app
29. Legal disclaimer
This privacy policy was prepared with reference to the requirements of the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act (as amended by the California Privacy Rights Act), the comprehensive privacy laws of every other US state in effect as of 2026-07-06, the Washington My Health My Data Act, the Children's Online Privacy Protection Act, the Brazilian Lei Geral de Proteção de Dados, Canadian PIPEDA and Quebec Law 25, the Australian Privacy Act and Australian Privacy Principles, the Swiss revFADP, and other applicable laws.
