SensiSkin
  • Face scan
  • Ingredient scan
  • Routine
  • Plus
Get the app

https://sensiskin.app/privacy · Updated 1 September 2026

Privacy Policy

Data controller: SensiSkin. Contact: support@sensiskin.app. The service is operated for users in the EU.

1. Who we are

SensiSkin is a mobile app for facial skin analysis and cosmetic ingredient scanning. The data controller is SensiSkin. Contact support@sensiskin.app. The service is operated for users in the EU. We do not publish a registered office address here.

2. Scope

This policy covers signed-in accounts. Guest mode stays on the device and does not sync photos or results to our servers.

3. Data we process

Account email and user id, display name, plan tier, reminder hours, face photos you capture for a scan, skin scores and advice (including the raw score payload we store with a scan), routine products you add, products you save in Scan Vault (name, brand, barcode / Open Beauty Facts code, ingredient text), ingredient scans from on-device OCR, in-app notification copies, scan-quota counters, kit recommendations, session tokens, and optional consents (training opt-in and anonymous score sharing are each off by default). If you turn on anonymous score sharing we also store a session id, numeric scores, lighting-quality numbers, device model, OS version, and app version. Never photos, never your account id. We do not run advertising profiles.

4. Face photos (face data)

What we collect: the face photos you capture for a scan, and the numeric skin scores derived from them (hydration, oiliness, redness, texture and similar cosmetic measures). We do not collect face prints for identification, and we do not read the device Face ID / TrueDepth data.

Use: face photos and scores derived from how skin looks are treated as biometric / special category data under GDPR Art. 9. We process them only to run the scan you start, on consent (and contract for the account itself). We do not use photos for identity login, surveillance, advertising, or third-party marketing.

Sharing: face photos are shared with exactly one third party, and only when a Plus report runs: Perfect Corp / YouCam, which returns cosmetic scores (see §6). Free and guest scans are computed on the device and are not sent anywhere.

Storage: guest photos never leave the phone. Signed-in photos sync to a private Supabase Storage folder scoped to your account (§5).

Retention and deletion: photos stay until you delete them or delete the account from Profile (§8). Deleting a photo removes the file and its stored score payload; deleting the account removes all photos, scores and related rows. Perfect Corp does not retain scan photos beyond returning the report and does not use them to train its models.

5. Where data lives

The service is operated for users in the EU. Signed-in photos and scores sync to a private folder on Supabase Storage (selfies) so history can follow you to a new phone.

6. On-device vs Plus

Free scans after onboarding are limited to 1 on-device face scan per day. Framing the face and reading product labels uses Google ML Kit on the phone. The on-device skin model is our SkinNet TFLite network; those photos stay on the device for the analysis itself. Plus reports send the scan photo off the device to Perfect Corp / YouCam (via our server) so they can return cosmetic scores, limited to 2 reports per week after your first scan. Photos and scores processed for a Plus report are not used to train Perfect Corp’s neural networks. Their API terms forbid that use. The Perfect Corp API key stays in backend secrets. If credits fail, the app must not silently invent a clinic report. A Google Gemini fallback exists in our server code but is off unless we explicitly enable it; if we do, a copy of the photo would leave the device to Google to produce an estimate, and we will treat Gemini as a processor.

7. Training consent

“Help improve the analysis” is a separate toggle, off by default. It is never implied by signing up or running a scan. When it is on, your scan photo and on-device scores may be used to train our own skin model. Only scans computed on your device (SkinNet) qualify: Plus reports produced by Perfect Corp are never used as our training material, and they are not used to train Perfect Corp’s nets. Turning the toggle off also excludes past scans from our training.

8. Retention and deletion

Account, photos, and history stay while the account exists, unless you delete photos or the whole account from Profile. Photo-only delete keeps scores. Account delete is irreversible and removes auth, storage photos, and related rows.

9. Your rights

Where GDPR applies: access, rectification, erasure, restriction, objection, portability, withdraw consent, and a complaint to a supervisory authority (in Italy, the Garante). Email support@sensiskin.app.

10. Children

The app is not directed at children under 16, or the higher age required in your country.

11. Transfers

The service is operated for users in the EU. If Perfect Corp, Google, or other infrastructure processes data outside the EEA, transfers rely on that vendor’s contractual safeguards (including standard contractual clauses where they use them).

12. Processors and other recipients

Signed-in accounts use Supabase for authentication, the database, private photo storage, and Edge Functions (whyrwkzllhwscamzpeao.supabase.co). Plus reports go to Perfect Corp / YouCam (yce-api-01.makeupar.com). Transactional email (sign-in, confirm, reset) is sent with Resend (api.resend.com). Product look-ups query Open Beauty Facts (world.openbeautyfacts.org). Face framing and label OCR use Google ML Kit on the device. The public website is hosted on IONOS. Typefaces are served from this site. Apple In-App Purchase processes Plus subscriptions. Manage or cancel in your Apple ID subscription settings. We do not use Facebook, Google Analytics, Mixpanel, or Sentry.

13. Changes

The date at the top is the latest revision. Material changes will be flagged in the app where required.

1. Chi siamo

SensiSkin è un’app per l’analisi della pelle del viso e la lettura degli ingredienti cosmetici. Titolare del trattamento: SensiSkin, email support@sensiskin.app. Il servizio è operato per utenti in UE. Non indichiamo qui una sede legale registrata.

2. Ambito

Questa informativa vale per chi ha un account. La modalità ospite resta sul telefono e non sincronizza foto né risultati.

3. Dati

Email e id account, nome visualizzato, piano, orari dei reminder, selfie di scan, punteggi e payload dello scan, prodotti della routine, prodotti salvati in Scan Vault (nome, marca, codice a barre / Open Beauty Facts, testo ingredienti), letture ingredienti (OCR sul dispositivo), copie delle notifiche in-app, contatori di quota scan, raccomandazioni kit, token di sessione, consensi opzionali (training e condivisione anonima dei punteggi, entrambi spenti di default). Se attivi la condivisione anonima conserviamo un id di sessione, i punteggi numerici, dati di qualità dell’inquadratura, modello del dispositivo, versione OS e versione app. Mai foto, mai l’id account. Niente profilazione pubblicitaria.

4. Foto del viso (dati del volto)

Cosa raccogliamo: i selfie che scatti per uno scan e i punteggi numerici derivati (idratazione, oleosità, rossore, texture e misure cosmetiche simili). Non raccogliamo impronte del volto per l’identificazione e non leggiamo i dati Face ID / TrueDepth del dispositivo.

Uso: le foto e i punteggi derivati dall’aspetto della pelle sono dati biometrici / categorie particolari (GDPR art. 9). Le usiamo solo per lo scan che avvii, con consenso. Non per login biometrico, sorveglianza, pubblicità o marketing di terzi.

Condivisione: le foto del viso vanno a un solo terzo, e solo quando parte un report Plus: Perfect Corp / YouCam, che restituisce punteggi cosmetici (§6). Gli scan free e quelli in modalità ospite sono calcolati sul dispositivo e non escono dal telefono.

Conservazione: le foto degli ospiti restano solo sul telefono. Se hai un account, sincronizziamo in una cartella privata Supabase legata al tuo account (§5).

Cancellazione: le foto restano finché non le elimini o elimini l’account da Profilo (§8). Cancellare una foto rimuove file e punteggi salvati; cancellare l’account rimuove foto, punteggi e righe collegate. Perfect Corp non conserva le foto oltre la generazione del report e non le usa per addestrare i suoi modelli.

5. Dove stanno i dati

Il servizio è operato per utenti in UE. Se sei connesso, foto e punteggi vanno in una cartella privata su Supabase Storage (selfies) così la cronologia segue un telefono nuovo.

6. On-device e Plus

Dopo il primo scan, il piano free è 1 analisi on-device al giorno. L’inquadratura e la lettura delle etichette usano Google ML Kit sul telefono. Il modello on-device è la nostra rete SkinNet TFLite; per quell’analisi le foto restano sul dispositivo. I report Plus inviano la foto fuori dal telefono a Perfect Corp / YouCam (via i nostri server) per i punteggi cosmetici, 2 report a settimana. Foto e punteggi di un report Plus non sono usati per addestrare le reti di Perfect Corp: i loro termini API lo vietano. La chiave API non è nell’app. Un fallback Google Gemini esiste nel codice server ma è spento finché non lo abilitiamo; se lo facessimo, una copia della foto andrebbe a Google.

7. Training

“Help improve the analysis” è un consenso separato, spento di default. Non è implicito con la registrazione o con uno scan. Se attivo, la foto dello scan e i punteggi on-device (solo SkinNet) possono essere usati per allenare il nostro modello. I report Plus di Perfect Corp non vengono mai usati per il nostro training e non addestrano le loro reti. Disattivandolo escludi anche gli scan passati.

8. Conservazione e cancellazione

Da Profilo puoi cancellare solo le foto o l’intero account (irreversibile).

9. Diritti

Accesso, rettifica, cancellazione, limitazione, opposizione, portabilità, revoca del consenso, reclamo al Garante. Email support@sensiskin.app.

10. Minori

L’app non è per minori di 16 anni, o l’età più alta nel tuo Paese.

11. Trasferimenti

Il servizio è operato per utenti in UE. Se Perfect Corp, Google o altra infrastruttura elabora fuori dallo SEE, valgono le garanzie contrattuali del fornitore.

12. Responsabili e altri destinatari

Account connessi: Supabase (autenticazione, database, storage privato, Edge Functions). Report Plus: Perfect Corp / YouCam. Email transazionali: Resend. Catalogo prodotti: Open Beauty Facts. Inquadratura e OCR etichette: Google ML Kit sul dispositivo. Sito: hosting IONOS, i font sono serviti da questo sito. Pagamenti: Apple In-App Purchase. Gestisci o disdici dalle impostazioni abbonamenti del tuo Apple ID. Non usiamo Facebook, Google Analytics, Mixpanel o Sentry.

13. Modifiche

La data in testa è l’ultima revisione.

© 2026 SensiSkin
Privacy Terms Support