MyShade API — Privacy Policy

Last updated: May 26, 2026

1. Overview

This Privacy Policy explains how our Beauty Advisor app (the "App") collects, uses, discloses, and otherwise processes personal information, including biometric data collected through camera-based features.

2. Information We Collect

2.1 Camera-Based Face Data

When you use the camera shade matching feature, we collect:

Important: The original face image is NOT retained on our servers. It is processed in real-time and immediately discarded after the skin color is extracted.

2.2 Device Information

When using the shade matching feature, we may also receive:

2.3 Product and Search Data

When you search for or view product recommendations, we collect:

3. How We Use Your Information

3.1 Primary Purposes

We use the face data and skin color information for the following purposes:

  1. Skin Tone Classification: To classify your skin tone into categories of depth (fair, light, medium, deep, rich) and undertone (warm, cool, neutral, olive)
  2. Foundation Shade Matching: To recommend foundation shades from our database that match your skin tone
  3. Cross-Brand Matching: To provide equivalent foundation shade recommendations across multiple beauty brands using Delta E color matching algorithms
  4. Service Improvement: To improve the accuracy of our shade matching algorithm and product recommendations

3.2 Secondary Purposes

4. How We Process Face Data

4.1 Real-Time Processing

Face data is processed in real-time for your immediate results:

  1. Image is transmitted to our secure servers
  2. Face detection is performed via a third-party API service
  3. Dominant skin color is extracted from the detected cheek area
  4. The extracted color is compared against our foundation database
  5. Foundation shade recommendations are returned to your device
  6. Original image and all temporary processing data are immediately deleted

No Long-Term Storage: The original face image is never stored on our servers or databases.

4.2 Image Quality Requirements

To protect your privacy and ensure efficient processing, we enforce reasonable image size and quality limits for processing. Images that do not meet our requirements will be rejected.

5. Third-Party Data Sharing

5.1 Google Cloud Vision API

Processor: Google LLC

What data is shared:

Purpose:

Data Retention:

Your Rights:

5.2 Supabase (Product Catalog Storage)

Processor: Supabase (Supabase Inc.)

What data is stored:

What is NOT stored:

Purpose:

6. Data Retention

6.1 Face Image Data

6.2 Extracted Skin Color (Hex Value)

6.3 Face Detection Metadata

6.4 Product Interaction Data

6.5 API Key Usage Data

7. Data Security

7.1 Transmission Security

7.2 Processing Security

7.3 Rate Limiting & Access Control

7.4 Limitations

While we employ industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

8. Your Privacy Rights

8.1 Access & Transparency

Since we do not retain your face data or skin tone information, there are no personal records to access. However, you have the right to:

8.2 Data Deletion

Because we do not store face data or extracted skin tones, there is no data to delete. However:

8.3 Opt-Out

8.4 Regional Privacy Rights

Depending on your location, you may have additional rights:

GDPR (European Union / EEA residents):

CCPA (California residents):

Contact us (see Section 10) to exercise these rights.

9. Children's Privacy

Our App is not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information and terminate that child's use of the App.

If you believe we have collected information from a child under 13, please contact us immediately (see Section 10).

10. Contact Us

If you have any questions about this Privacy Policy, our privacy practices, or your privacy rights, please contact us at:

Email: support@my-shade.com

Response Time: We will respond to privacy inquiries within 30 days.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  1. Posting the updated Privacy Policy in the App
  2. Updating the "Last Updated" date at the top of this policy
  3. Requesting your consent if required by applicable law

Your continued use of the App following the posting of revised Privacy Policy terms means you accept and agree to the changes.

12. Data Processing Addendum (for B2B / Enterprise Users)

If you are using this App on behalf of an organization or enterprise, additional data processing terms may apply. Contact us for a Data Processing Addendum (DPA) if your organization requires GDPR-compliant data processing documentation.

13. Compliance & Legal Basis

13.1 Lawful Basis for Processing (GDPR)

We process face data under the following lawful basis:

13.2 Data Processing Locations

13.3 International Data Transfers

If you are located in the European Union or other jurisdictions with strict data protection laws, your data may be transferred to the United States for processing. By using our App, you consent to such transfers.

14. Third-Party Links & Services

Our App may contain links to third-party websites and services (e.g., beauty brand websites, Sephora, Ulta). This Privacy Policy does not apply to third-party services. We encourage you to review their privacy policies before providing any personal information.

15. California Privacy Rights (CCPA / CPRA)

California Residents: Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the following rights:

15.1 Right to Know

You have the right to request what categories of personal information we collect, use, and disclose.

15.2 Right to Delete

You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.

15.3 Right to Opt-Out

You have the right to opt-out of the sale or sharing of your personal information for cross-context behavioral advertising.

15.4 Right to Correct

You have the right to request that we correct inaccurate personal information.

15.5 Right to Limit Use

You have the right to limit use of your personal information to the purposes necessary to provide the service.

Note: Because we do not retain face data or skin tone information, most CCPA requests will result in confirmation that no personal data is retained.

To exercise your rights, contact us at: support@my-shade.com

16. EU/EEA Residents — GDPR Rights

If you are a resident of the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

16.1 Right of Access

You have the right to obtain confirmation as to whether we are processing your personal data and to request access to that data.

16.2 Right to Rectification

You have the right to request that we correct inaccurate personal data.

16.3 Right to Erasure

You have the right to request that we delete your personal data, subject to certain legal exceptions.

16.4 Right to Restrict Processing

You have the right to request that we limit how we use your personal data.

16.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another organization.

16.6 Right to Object

You have the right to object to our processing of your personal data.

16.7 Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority.

EU Data Protection Authority Contact: If you believe we have violated your GDPR rights, you may file a complaint with your national data protection authority. A list of authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

17. Apple App Store Privacy Requirements

This section addresses Apple's specific privacy data disclosure requirements for App Store submission:

17.1 Category: Photos and Videos

Data CollectedFace image (via camera)
PurposeShade matching via face recognition
Linked to UserNo (images are not stored or linked to user accounts)
Used for TrackingNo
Data RetentionNot retained (processed and immediately deleted)

17.2 Category: User ID / Device ID

Data CollectedAPI key authentication headers
PurposeAPI authentication and rate limiting
Linked to UserYes (to validate API access)
Used for TrackingNo
Data Retentionlast_used timestamp retained

17.3 Category: Search History

Data CollectedProduct search queries
PurposeProduct recommendations and analytics
Linked to UserNo (not linked to personal identity)
Used for TrackingNo
Data RetentionApplication logs (typically 30 days)

17.4 Category: Product Interaction Data

Data CollectedViewed products, shade names, brands
PurposeImprove recommendations
Linked to UserNo
Used for TrackingNo
Data RetentionApplication logs (standard retention policy)

18. Frequently Asked Questions (FAQs)

Q: Is my face image stored on your servers?

A: No. Your face image is processed in real-time and immediately deleted after the skin color is extracted. We do not store, retain, or archive face images.

Q: Can you identify me from the face image?

A: No. We only extract the dominant skin color (a hex value) from your cheek area. We do not retain facial features, facial geometry, or any identifying characteristics.

Q: How is my data protected during transmission?

A: All data transmitted between your device and our servers is encrypted using HTTPS/TLS 1.2 or higher. API requests require authentication via API key.

Q: Do you sell my data?

A: No. We do not sell face data, skin tone data, or any personal information to third parties. We only share face images with Google Cloud Vision API for the purpose of face detection.

Q: Can I delete my data?

A: Because we do not retain your face data or skin tone information, there is no data to delete. You can disable camera permissions in your device settings or uninstall the app to prevent future data collection.

Q: How long do you keep my information?

A: Face images and extracted skin tones are not retained. Application logs may be retained for up to 30 days for service improvement and debugging.

Q: What is Delta E color matching?

A: Delta E (ΔE) is a color science metric that measures the perceptual difference between two colors in the LAB color space. We use it to find foundation shades that are most similar to your extracted skin tone.

Q: Why do you use Google Vision API?

A: Google Vision API provides reliable, accurate face detection technology. We use it to identify your face and locate the cheek region for color extraction, ensuring we sample the most appropriate skin tone area.

19. Definitions

20. Acknowledgment & Consent

By using our Beauty Advisor app, you acknowledge that:

  1. You have read and understand this Privacy Policy
  2. You consent to the collection and processing of face images as described herein
  3. You consent to the sharing of face images with Google Cloud Vision API for the purposes described
  4. You understand that your face image is not retained on our servers
  5. You consent to the extraction and use of skin color information for shade matching
  6. You understand your privacy rights and how to exercise them

If you do not consent to these terms, please do not use the face scanning feature of the App.

Appendix A: Summary for Apple App Store

App Name: Beauty Advisor

Data Collection Summary:

Privacy Certification: This app complies with GDPR, CCPA/CPRA, and Apple's privacy guidelines.