Legal
Privacy Policy
1. Who we are
Controller: The operator of the Aesthetix application (trade name “Aesthetix”). For privacy requests contact: privacy@aesthetix.online (general support: support@aesthetix.online).
2. What we collect
Depending on how you use the app, we may process:
- Account data: email address, display name, authentication identifiers (e.g. from Apple or Google sign-in), and profile fields you provide.
- Physique photos: images you upload or capture for AI-assisted analysis. Images are sent to our backend for processing and are not used for advertising profiles.
- Analysis results: scores, muscle-group breakdowns, coaching text, and related metadata derived from your photos.
- Usage & gamification: scan history, XP, streaks, and in-app progress you generate.
- Subscription data: if you purchase Premium, payment is handled by Apple App Store or Google Play via RevenueCat; we receive subscription status (active/inactive, product, renewal dates), not your full card number.
- Consent records: version of Terms/Privacy accepted, timestamp, and whether you opted in to analytics.
- Technical data: device type, app version, and logs needed for security and debugging (e.g. error reports if crash reporting is enabled).
We do not knowingly collect data from children under 16 (see Section 10).
3. How we use your data
- Provide physique analysis, coaching features, and account functionality.
- Enforce free-tier scan limits and Premium entitlements.
- Authenticate you and keep your session secure.
- Comply with law, respond to requests, and prevent abuse or fraud.
- Improve reliability and security (including optional crash diagnostics).
- Send service-related communications where permitted (we do not sell your personal data).
4. Legal bases (GDPR)
If you are in the EU/EEA/UK, we rely on:
- Contract — to deliver the service you request.
- Consent — for optional analytics and, where required, for processing photos for analysis after you accept this policy.
- Legitimate interests — security, fraud prevention, and improving the app (balanced against your rights).
- Legal obligation — where we must retain or disclose data by law.
5. AI processing & photos
Photos and derived measurements are processed on our servers using third-party AI providers (currently OpenAI via our Supabase Edge Functions) solely to generate your analysis and coaching content. We instruct processors to use data only to provide the service. Do not upload images of other people without their permission.
Marketing copy in the app may state that photos are analyzed securely; retention follows our backend configuration—scan data is stored in your account until you delete it or delete your account.
6. Processors & third parties
- Supabase — authentication, database, and serverless functions (EU region: West EU, Paris).
- OpenAI — vision/language models for analysis and chat (data processed per their API terms).
- RevenueCat — subscription status and receipt validation.
- Apple / Google — in-app purchases and account sign-in when you choose those options.
- Sentry (optional) — crash and error reporting if enabled in a given app build.
We require processors to protect data under contractual safeguards. Some providers may process data in the United States; see Section 9.
7. Analytics
Product analytics are off by default. If you opt in, we may log events such as scan completed or premium viewed. No third-party analytics SDK is required for core app function. You can withdraw analytics consent in app settings where available.
8. Retention
- Account and scan data: until you delete content, delete your account, or we no longer need it for the service.
- Consent logs: retained as proof of consent (GDPR Art. 7(1)) for a period consistent with legal requirements.
- Deletion audit: when you delete your account, we may retain a non-identifying record that an erasure occurred (user ID only, no email).
- Backups: residual copies may persist for a limited time in encrypted backups.
9. International transfers
If you are outside the country where a processor hosts data, transfers may occur under Standard Contractual Clauses, adequacy decisions, or other lawful mechanisms. Contact us for more detail on transfer safeguards.
10. Children
Aesthetix is not directed at children under 16. We do not knowingly collect personal data from them. Contact us to request deletion if you believe a child provided data.
11. Your rights
EEA/UK: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent; lodge a complaint with your supervisory authority.
California: know, delete, correct, and opt out of “sale”/“sharing” (we do not sell personal information). Limit use of sensitive personal information where applicable.
Use in-app Privacy & Data → Delete account for erasure, or email privacy@aesthetix.online. We will verify your request and respond within applicable deadlines.
12. Security
We use encryption in transit (TLS), access controls, row-level security on our database, and server-side-only API keys. No method is 100% secure; report concerns to support@aesthetix.online.
13. Changes
We may update this policy. Material changes will be reflected in a new version identifier in the app; continued use after notice may require renewed acceptance where required by law.