Privacy Policy
Effective: August 15, 2026
This policy explains how face navi handles your photo. Because a facial photograph can be treated as biometric information under laws such as the Illinois Biometric Information Privacy Act (BIPA), we describe our purpose, retention period and destruction schedule explicitly in Section 6.
1. Who we are
face navi (the “App”) is a mobile application provided by the facenavi operations team (“we”, “us”).
2. Information we handle
- Facial photographs — front and profile images you choose to upload. We handle the image itself only; metadata attached to the photo (location, capture time, device information) is not used. See Section 6 for full detail.
- Account information — your email address, and the account identifier returned by Google or Apple when you use social sign-in. Used for authentication only.
- Analysis results — scores and ratings calculated by the AI.
- Usage logs — crash reports and performance data, in a form that does not identify you.
3. Why we use it
- To provide the facial analysis service
- To generate procedure simulation images
- To manage and authenticate your account
- To improve app quality and fix defects
4. We do not sell or share your personal information
We do not sell, rent, trade or otherwise disclose your personal information — including your facial photographs, email address and analysis results — to any third party.
Specifically, we never:
- Sell or provide facial photographs or personal information to third parties
- Provide or share personal information with advertising companies
- Use personal information for marketing purposes
- Use facial photographs to train AI models
- Provide information to medical institutions, insurers or other organizations
We disclose information only in the following cases:
- Where disclosure is required by law
- Where you have given explicit consent
For the purposes of the California Consumer Privacy Act (CCPA/CPRA), we do not “sell” or “share” personal information as those terms are defined, and we have not done so in the preceding twelve months.
5. Third-party services we use
We use the following services to operate the App. Information sent to them is limited to what the service requires.
- OpenAI, L.L.C. (San Francisco, California, USA)— image processing for facial analysis and procedure simulation. Images sent through the API are processed under OpenAI’s API terms, which exclude API data from model training. See the OpenAI Privacy Policy.
- Supabase, Inc. (USA) — account authentication and management. See the Supabase Privacy Policy.
- Google Sign-In / Sign in with Apple— social sign-in. Each provider’s own privacy policy applies.
- Google AdMob — advertising shown to users on the free plan. Gold and Premium members see no ads. AdMob may process device identifiers for ad delivery. On iOS, personalized advertising is used only if you allow tracking when prompted.
We prohibit these providers from using your personal information for any purpose other than providing their service to us, and we send only the minimum information required.
6. Biometric information: facial photographs
This section is our written notice regarding biometric information, provided in accordance with the Illinois Biometric Information Privacy Act (740 ILCS 14) and comparable state laws.
(1) What we collect
- Only the still images of your face that you choose to upload
- We do not collect Face ID data, face geometry templates, or any device-level biometric identifier
- We do not collect image metadata (location, capture time, device information)
(2) Purpose of collection and use
- AI analysis of facial aesthetics (proportions, facial thirds and fifths, symmetry and related measurements)
- Face type classification (eight types)
- Generation of before-and-after simulation images for the procedures you select
- We use your photograph for no other purpose — not marketing, not advertising, not AI training, not medical records, and never for sale
(3) Disclosure to a processor
To perform the AI analysis, your photograph is transmitted to the processor named below. We obtain your explicit consent in the App before any transmission occurs.
- Recipient: OpenAI, L.L.C. (San Francisco, California, USA)
- What is sent: the image data only. Your email address, name, device identifier and other identifying information are not sent
- Handling by the processor: under the applicable API terms, data sent through the API is not used to train models. It is retained for up to 30 days for abuse monitoring and then deleted
- We do not transmit your photograph to any other third party, including advertising networks, other AI services or data brokers
(4) Retention schedule and destruction guidelines
- face navi servers: your photograph is never stored. It is held only in memory for the duration of the API request and discarded as soon as the response is returned (retention period: zero days)
- Processor: retained for up to 30 days for abuse monitoring, then automatically deleted
- Your device: images you upload remain on your own device. Saved history, where enabled, is stored on your device and is removed when you delete the entry or the App
- In all cases, biometric information is permanently destroyed no later than the earlier of (a) the date the purpose for collection has been satisfied, or (b) three years after your last interaction with us
(5) What we never do
- We do not use your photograph to train or improve AI models
- We do not sell, lease, trade or otherwise profit from your biometric information
- We do not use your photograph for advertising or marketing
- No third party — including our physicians and staff — views your photograph
- We do not send your photograph to any AI or analytics provider other than the processor named above
Your photograph is transmitted only after you agree to these terms on the consent screen shown before each analysis. If you do not consent, the analysis and simulation features cannot be used.
7. Security
We maintain appropriate technical and organizational safeguards against unauthorized access, loss, destruction, alteration and disclosure. All communication is protected with TLS encryption. We use the same or greater standard of care for biometric information as we do for other confidential information.
8. Children
The App is intended for users aged 18 and over. If you are under 18, please use the App only with the consent of a parent or guardian. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact us and we will delete it.
9. Your rights
You may:
- Request access to the personal information we hold about you
- Request correction or deletion of your personal information
- Delete your account, from within the App or by contacting us
- Withdraw your consent to biometric processing at any time by ceasing to use the analysis feature and deleting your account
California residents additionally have the right to know what personal information we collect, to request deletion or correction, and to opt out of the sale or sharing of personal information. As stated in Section 4, we do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
To exercise any right, contact us using the details in Section 10. We will respond within 45 days.
10. Contact
For any privacy question, including requests regarding biometric information:
Email: enavisupport@gmail.com
11. Changes to this policy
We may update this policy. If a change is material, we will notify you in the App or by email. Continued use after a change takes effect constitutes acceptance of the updated policy.
© 2026 face navi. All rights reserved.