Privacy Policy
1. Introduction
K-Beauty Care ("we," "our," or "the App") is an AI-powered skin analysis and virtual K-Beauty makeover app that helps users discover personalized Korean skincare routines and try on makeup looks. We respect your privacy and are committed to protecting it. This Privacy Policy explains what information we collect, how we use it, and your rights.
By using K-Beauty Care, you agree to the practices described below.
2. Information We Collect
a. Photos you submit (treated as "face data")
Skin analysis and makeover photos in this App typically include the user's face. For transparency we therefore refer to such photos as "face data" throughout this Privacy Policy.
- When you take or upload a photo, the image is sent over HTTPS to Google's Gemini API so the AI can (1) assess your skin condition and (2) generate a virtual makeover preview of the selected look on your photo. The Gemini models currently used are "gemini-3.1-flash-lite" for skin analysis and "gemini-3.1-flash-image" for the makeover image. These may be updated to newer Google models over time.
- Your photo, the generated makeover image, and the AI analysis text are stored locally on your device (SQLite) as part of your scan history.
- OPTIONAL photo sharing for quality review: if you leave the "Share my photo to help improve K-Beauty Care" option enabled on the photo screen, a copy of your submitted photo and its generated makeover result is uploaded to our Firebase Storage, together with a Firestore record containing your anonymous account ID, the selected look, your assessed skin type and skin score, the file paths, and a timestamp. These uploaded photos are reviewed manually by our operator to check and improve AI quality. This upload happens only when the option is enabled; if you turn it off, no photo leaves your device except the temporary Gemini API call described above. See Section 5 for retention.
- We do NOT perform face recognition, face matching, or identity verification.
- We do NOT generate, derive, or store any biometric template, faceprint, face geometry, face embedding, or other identifier from your face.
- We do NOT use the iOS Vision/ARKit face APIs or any equivalent biometric API on Android.
- We do NOT use your photo to train our own AI models.
b. Anonymous usage analytics (no photo)
- We use Firebase Analytics to collect anonymous usage events such as app opens, scans started/completed/failed, intro completion, image source selection, and review prompts.
- We also write anonymous onboarding statistics to Cloud Firestore for every user (not tied to the optional photo sharing above). Each record contains your anonymous account ID, the selected look, your assessed skin type and skin score, whether the photo was detected as a face, and whether the makeover succeeded. These records do NOT contain your photo or any image derived from your face.
- This analytics data does not include your name or other directly identifying information.
c. Anonymous account
- We use Firebase Anonymous Authentication to create a temporary account. It lets the app read remote configuration from Cloud Firestore and, when you enable optional photo sharing, associate the uploaded files with an anonymous ID. This account contains no personal data and is not linked to your real-world identity.
d. Purchase information
- Subscription purchases are handled directly by the Apple App Store or Google Play. We do not process or store any payment details.
e. Device-only data
- Your scan history (photos, generated makeover images where saved, AI analysis text, titles, timestamps) is stored on your device using SQLite.
- Local preferences (subscription status, intro seen flag, review-prompt flag, and similar) are stored only on your device.
f. Approximate location (optional, for daily weather tips)
- The App asks for location only if you tap to turn on the daily UV and humidity skincare tip. It is never requested at launch, and the tip works only while you allow it.
- When allowed, the App reads your approximate location (low accuracy) and rounds the coordinates to one decimal place (roughly an 11 km area) on your device before sending them, together with your device time zone, over HTTPS to our server function on Firebase (Cloud Functions). Our server uses the rounded coordinates to request the forecast from Apple WeatherKit.
- We do not store your location with your account. Our server keeps a cached forecast for each rounded area and time zone (with no account ID) so repeat requests do not need a new WeatherKit call, and keeps a per-account count of weather requests for the current hour (your anonymous account ID, the hour, and a number) to prevent abuse.
- The forecast is cached on your device for up to one hour.
g. Routine reminders
- If you turn on morning and evening routine reminders, they are scheduled as local notifications on your device. No push server is used, and reminder times are not sent to us. The morning reminder may mention the day's weather when the weather tip is on.
We do not collect your name, email, address, phone number, contacts, or precise location.
3. How Your Data Is Used
- Face data (photos): sent to Google Gemini to generate your skin condition analysis and your virtual makeover preview. If you enable optional photo sharing, a copy is also stored in our Firebase Storage and reviewed by our operator solely to check and improve AI quality. Face data is never used for advertising, profiling, identification, or training of our own models. Google processes the image according to its own privacy policy (https://policies.google.com/privacy) and the Gemini API Terms (https://ai.google.dev/terms).
- Anonymous analytics: aggregated, anonymous data used to understand feature usage, skincare and look preferences, and success rates so we can improve the app.
- Anonymous account: only to authenticate calls to Firebase services and to label optional photo-sharing uploads.
- Approximate location (only if you allow it): only to fetch the weather forecast for your area so the App can show a skincare tip. It is not used for advertising or profiling.
We do NOT sell or rent your personal data. We do NOT share your personal data with advertisers or third parties for marketing purposes. We do NOT show third-party advertisements inside the App.
4. Third-Party Services
K-Beauty Care relies on the following third-party services:
- Google Gemini API (skin analysis and makeover generation — receives the submitted photo)
https://policies.google.com/privacy
- Firebase by Google (Analytics, Anonymous Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Remote Config — Cloud Storage and Firestore receive your photo and its makeover result ONLY when you enable optional photo sharing; Cloud Functions receives your rounded location ONLY when you turn on the weather tip)
https://firebase.google.com/support/privacy
- Apple WeatherKit (weather forecast — our server sends it the rounded coordinates when you turn on the weather tip; your device does not contact Apple WeatherKit directly)
https://developer.apple.com/weatherkit/data-source-attribution/
https://www.apple.com/legal/privacy/
- Apple App Store / Google Play (in-app purchases)
https://www.apple.com/legal/privacy/
https://policies.google.com/privacy
- Olive Young Global (product purchase links open in your default browser; we do not share your photo or any face data with them)
5. Data Retention and Deletion
- Face data on your device: photos, makeover images, and analysis text remain in local SQLite scan history until you delete the entry from within the App or uninstall the App. Uninstalling removes all locally stored photos.
- Face data you optionally shared for quality review: retained in our Firebase Storage and Firestore for as long as needed to review and improve AI quality. You can request deletion of these copies at any time by contacting us at the email below, and we will remove them.
- Face data on Google's side: photos sent to the Gemini API are processed and retained by Google according to Google's Gemini API policies, which we do not control or extend.
- Anonymous analytics: retained in aggregated form to monitor and improve the App.
- Local preferences: removed when the App is uninstalled.
- Weather: cached forecasts on our server are refreshed over time and are not linked to any account; the hourly request count is overwritten each hour. The on-device forecast cache expires after one hour and is removed when the App is uninstalled.
6. Children's Privacy
K-Beauty Care is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has used the App and provided data, please contact us so we can remove any associated information.
7. Your Rights
You may at any time:
- Delete individual scan history entries (including the stored photo) within the App.
- Turn off optional photo sharing so no new photo is uploaded for review.
- Turn off location access for the App in your device settings, which stops the weather tip and any further location use.
- Turn off routine reminders in the App or notifications in your device settings.
- Uninstall the App to remove all local data.
- Contact us to request deletion of any photo you previously shared for review, or information about any data we may hold.
Depending on your location (for example EU/UK GDPR, California CCPA/CPRA), you may have additional rights including access, rectification, deletion, restriction of processing, objection, and data portability. Contact us to exercise these rights.
8. Security
We use industry-standard practices, including HTTPS for all network communication and Firebase's built-in protections and access controls (uploaded review photos are restricted to our operator). However, no system is completely secure, and we cannot guarantee absolute security of data transmitted over the internet.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date above will reflect the most recent change. Continued use of the App after changes are posted means you accept the updated policy.
10. Contact
If you have any questions about this Privacy Policy or our data practices, or to request deletion of shared data, please contact us:
Email: kimloydmail@gmail.com