Symmi Face Privacy Policy
Effective date: August 25, 2026
Published by TidalAurum, LLC ("we," "our," or "us")
Introduction
This Privacy Policy describes how Symmi Face (the "App") collects, uses, and protects your information. In short: everything about your face — photos, landmarks, measurements, scores, and history — stays on your device. What leaves your device is standard, non-facial operational data: pseudonymous usage events, device metadata, IP-derived approximate location, and purchase validation data. This policy explains both parts precisely.
1. Facial Data
What is processed
The App has two facial features, both of which run entirely on your device.
Photo analysis. The App detects facial landmarks (mathematical points for the eyes, nose, mouth, jaw, and face outline) from a photo taken with the camera or selected from your photo library, and calculates geometric measurements, proportions, and symmetry scores from them. Landmark detection uses a face-landmark model bundled inside the App (MediaPipe).
Live AR view (TrueDepth). On devices with a TrueDepth camera, the AR tab uses Apple's ARKit face tracking to draw live measurement lines and a mirrored-symmetry preview over your face in real time. During the session the App reads the 3D face-mesh vertex positions that ARKit provides and, for the symmetry preview, renders a temporary mirrored image of the camera view in memory. This data exists only in device memory while the AR view is open and is discarded when you leave it. Nothing from the AR view is saved to your device, added to your history, written to your photo library, or transmitted. ARKit face tracking is not Face ID and is not used for authentication or identification.
Where it is processed
Entirely on your device, for both features. Neither makes a network request; both work without an internet connection. No photo, video frame, landmark, face mesh, measurement, or score is ever transmitted to us or to any third party.
What is stored
Only photo analysis stores anything; the AR view stores nothing. When a photo analysis completes, the App saves the following to its private local database on your device: the scanned photo (compressed), the derived measurements (for example, eye-height difference or jaw shift in degrees), short descriptions of each measurement, an overall score, and the date. Progress photos you choose to save in the habit tracker are stored the same way, with a thumbnail. Landmark coordinates are used in memory during analysis and are not saved.
What is not done with facial data
We do not upload it, share it, sell it, or use it to train models. We do not use it for facial recognition, identification, or authentication. We do not build profiles from it. TrueDepth data from the AR view is never stored.
Retention and deletion
Analysis history and progress photos remain on your device until you delete them. "Clear All Data" in Settings deletes your entire analysis history (photos, measurements and scores). Progress photos in the habit tracker are deleted individually from the tracker. Questionnaire answers and preferences are removed when you uninstall the App. Deleting the App removes everything it stored on your device.
Backups
Your data is not synced to iCloud or to any server. As with any app, the App's local data is included in your iCloud backup or encrypted device backup if you have backups enabled; it stays inside that backup and is not accessible to us.
2. Non-Facial Information
Information you provide
Questionnaire answers during onboarding (for example, habits such as chewing side and sleep position), the facial areas you choose to focus on, app preferences, and any feedback or support messages you send us. Questionnaire answers and preferences are stored on your device. The focus areas you select (for example "jawline" or "eye area") are also sent to our analytics service as a pseudonymous event so we can see which features people want.
Information collected automatically through third-party services
The App uses the following third-party SDKs. None of them receive photos, facial landmarks, measurements, or scores.
PostHog (product analytics). Receives event names such as "scan completed" or "paywall viewed" (with non-facial properties such as the plan you tapped or the focus areas you selected), app-lifecycle events (open, background), the App version, device model, iOS version, screen size, language, time zone, network type (Wi-Fi or cellular), and your IP address, from which approximate city-level location is derived. Events are grouped under a random identifier generated on your device. Session recording and automatic interface capture are disabled. This data is pseudonymous: it is not linked to your name or identity.
AppsFlyer (advertising attribution). Receives a device vendor identifier (IDFV), IP address, and two funnel events (onboarding scan completed, onboarding finished). This is used only to determine whether an install came from one of our advertisements. For that purpose, limited non-facial event data may be shared with the advertising platform that served the ad. We do not request App Tracking Transparency permission and do not collect the advertising identifier (IDFA).
RevenueCat (subscription management). Receives an anonymous app user ID, App Store transaction data, Apple's first-party Search Ads attribution token (to know whether the install came from an Apple Search Ads campaign; this does not require tracking permission), and the AppsFlyer device identifier so that a purchase can be matched to its install source. RevenueCat forwards purchase events, including amount, to AppsFlyer for advertising measurement. We never receive your payment card details; payment is handled by Apple.
Crash diagnostics
Our analytics SDK includes crash-reporting capability, which we keep disabled; we do not receive crash reports through it. Crash diagnostics reach us only through Apple's own reporting, and only if you have opted in at the iOS level.
How we use non-facial information
To provide App functionality and personalized recommendations, to respond to support requests, to understand which features are used so we can improve the App, to measure whether our advertising works, and to meet legal obligations.
What we do not do
We do not sell your data. We do not share facial data with anyone. We do not use your data for facial recognition, for training external AI models, or for creating marketing profiles. The App does not collect data in the background when it is closed.
3. Your Choices
Deletion on your device. Delete individual analyses, or your entire analysis history, in Settings at any time; delete progress photos from the habit tracker. Uninstalling the App removes everything stored on the device.
Data held by third-party services. The analytics and attribution data described above is pseudonymous: it is identified only by a random device-generated ID, not by your name, email or any account, so it cannot be looked up or tied back to you. It is retained by those providers under their own retention policies and is not affected by clearing data in the App.
Permissions. Camera access can be granted or revoked in iOS Settings. Photos are selected through Apple's photo picker, which gives the App access only to the photos you choose and does not require library permission. Notifications can be managed in iOS Settings.
Analytics. The App does not currently offer an in-app switch to disable analytics. The analytics data described above never includes facial information.
4. Legal Rights
Biometric privacy laws. Facial landmarks and measurements are processed only on your device, only when you start an analysis, and are never disclosed to us or to any third party. We do not sell or profit from biometric data. Where state or national biometric laws apply, we rely on your action of starting an analysis as your consent to on-device processing.
California (CCPA). You have the right to know what we collect (described in this policy), the right to delete the data stored on your device (in the App), and the right to non-discrimination. We do not sell personal information, so no opt-out is required.
European Economic Area and United Kingdom (GDPR). Our legal bases are your consent (for on-device facial analysis, which you initiate) and our legitimate interests (for pseudonymous analytics, advertising measurement, and purchase validation). Because the data leaving your device is not linked to your identity, we hold no personal data that can be retrieved for an individual. You may lodge a complaint with your local data protection authority.
5. Children
The App is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child has used the App, delete the App from the device; all of its stored data is removed with it.
6. International Users
Facial data is processed on your device wherever you are. The third-party services listed above may process pseudonymous non-facial data on servers in the United States.
7. Changes to This Policy
We may update this policy when our practices or legal requirements change. The effective date at the top shows the current version. Material changes will be reflected in the App Store listing and in this document; continued use of the App after a change indicates acceptance.
8. Contact
Email: nathanlinshuo@gmail.com