Effective date: 2026-06-01
This Privacy Policy explains what information the SlayUp mobile application ("SlayUp", "the app", "we", "us") collects, how we use it, and the choices you have. SlayUp is published by Myriadloop.
By using SlayUp you agree to the practices described below.
What information we collect
We try to collect as little as possible. In normal use, SlayUp collects:
An anonymous account identifier. When you first open the app we create an anonymous Firebase account so we can store your scan results and subscription state. This identifier is a random string. We do not ask for your name, email address, phone number, or profile photo to create this account.
Optional onboarding answers. During the first-run quiz you may tell us your gender, age range, primary focus area (skin / colour / hair / overall glow), and how committed you are to a routine. Every quiz step is optional and can be skipped. We use these answers only to tailor your recommendations.
Face photos for scanning. Each time you run a scan, SlayUp captures one photo from your camera or photo library. The photo is resized on your device and sent to our server over an encrypted (HTTPS) connection so we can produce your reading. The photo is then stored under your account until you delete it. How we handle this photo is described in Section 3.
Your scan results. The numeric scores, dimensions, and recommendations produced from each scan are saved to your reading history so you can revisit them. The raw response from our analysis provider may be stored alongside the result for quality and debugging purposes.
Subscription state. If you subscribe to SlayUp Pro, our subscription partner (RevenueCat) records that you have an active entitlement and the identifier of the product you purchased. We never see your card details Apple processes the payment.
Crash diagnostics. If the app crashes, Firebase Crashlytics sends us a technical report (stack trace, device model, OS version) so we can fix the bug. Crash reports do not contain your photos or quiz answers.
SlayUp includes Firebase Analytics for possible future use. No analytics events are recorded at the time this policy takes effect. If we begin collecting analytics in a future update, we will update this policy.
We do not collect: your name, your email address, your contacts, your precise location, your browsing history, your advertising identifier, or any data we use for cross-app tracking.
Where your information goes
SlayUp is built on services run by third parties. The list below names every external service the app talks to and the purpose of each.
Firebase Authentication (Google) the anonymous account that holds your data. Privacy policy: https://policies.google.com/privacy
Cloud Firestore (Google) storing your scan history and subscription status. Privacy policy: https://policies.google.com/privacy
Firebase Storage (Google)storing your scan photos under your account (see Section 3). Privacy policy: https://policies.google.com/privacy
Cloud Functions for Firebase (Google) the server endpoint that processes scans. Privacy policy: https://policies.google.com/privacy
Firebase Crashlytics (Google) crash diagnostics. Privacy policy: https://policies.google.com/privacy
Firebase Remote Config (Google) delivering configuration values to the app. Privacy policy: https://policies.google.com/privacy
Firebase Analytics SDK (Google) included in the app; no events are sent today. Privacy policy: https://policies.google.com/privacy
RevenueCat (RevenueCat, Inc.) managing your subscription state. Privacy policy: https://www.revenuecat.com/privacy
OpenRouter (OpenRouter, Inc.) routing your scan photo to the AI model. Privacy policy: https://openrouter.ai/privacy
OpenAI /GPT model (OpenAI, L.L.C.) the AI model that analyses your scan photo. Privacy policy: https://openai.com/policies/privacy-policy
Apple (Apple Inc.) processing your subscription payment. Privacy policy: https://www.apple.com/legal/privacy/
We do not sell your information to anyone. We do not share it with advertisers or data brokers.
How we use your scan photos
This is the most sensitive thing the app does, so it gets its own section.
You take a photo (or pick one from your library) inside the app.
2. The app resizes the photo on your device and sends it over an encrypted connection to our Cloud Function.
3. The Cloud Function forwards the photo and your quiz context to OpenRouter, which routes the request to OpenAI's GPT vision model.
4. The model returns a structured analysis (scores and recommendations).
5. We save the analysis result to your reading history, and we store the photo in Firebase Storage under your account so your reading can display it later. The photo stays until you delete your account (see Sections 4 and 5).
6. While the photo is in transit and being analysed, it is handled under OpenRouter's and OpenAI's privacy and retention policies (linked in Section 2). We do not control how long those providers retain inputs sent to their models please refer to their policies for current terms.
The photo is used solely to produce your reading. It is not used to train any AI model on our behalf, and we do not share it with anyone else.
4. How long we keep your data
Scan results and subscription state stay on our servers until you delete your account.
Crash diagnostics are retained according to Firebase Crashlytics' standard retention (currently 90 days).
The scan photo itself is stored in Firebase Storage under your account and retained until you delete your account; deleting your account removes it (see Section 5). Retention by OpenRouter and the model provider during processing is governed by their policies.
5. Your choices and rights
You can delete your SlayUp account from inside the app:
Settings Account Delete Account
Deleting your account removes your scan history, your quiz answers, any account-scoped files, and your anonymous account identifier from our servers. This action is permanent.
Depending on where you live, you may have additional rights under laws such as the EU / UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA) including the right to access, correct, port, or delete the personal information we hold about you, and the right to object to or restrict certain processing. The in-app Delete Account flow is the primary way to exercise these rights in SlayUp. Because SlayUp accounts are anonymous, we may be unable to identify any data belonging to you without information that links your device to a specific account.
If a regulator in your jurisdiction handles privacy complaints, you have the right to lodge a complaint with them.
6. Children
SlayUp is not intended for use by children under 13. We do not knowingly collect information from children under 13. If you believe a child has used SlayUp, please delete the account from the device using the flow in Section 5.
Security
We use industry-standard measures to protect your data, including TLS for data in transit and the access controls provided by Google Firebase. No system is perfectly secure, and we cannot guarantee absolute security.
International transfers
SlayUp is available worldwide. The services listed in Section 2 are operated from, and may process data in, the United States and other countries. By using SlayUp, you understand that your information may be transferred to and processed in countries other than your own.
Changes to this policy
If we make material changes to this policy we will update the effective date at the top and, where appropriate, surface a notice inside the app. Continued use of SlayUp after a change takes effect means you accept the updated policy.
About Myriadloop
SlayUp is published by Myriadloop. Myriadloop is the controller of the personal information described in this policy.