Privacy Policy for Looksmax AI: Ganymede
**Effective date:** July 27, 2026
This Privacy Policy explains how Yusuf Ozmavi ("Ganymede," "we," "us," or
"our") collects, uses, shares, stores, and deletes information when you use the
Ganymede mobile application (the "App").
The App is available only to people who are at least 18 years old.
## 1. Contact and Data Controller
Yusuf Ozmavi is the data controller for information processed through the App.
Privacy contact: ozmaviyusuf@gmail.com
## 2. Information We Collect
### 2.1 Face Data
For this Policy, "Face Data" means information relating to a human face,
including information obtained from a photograph and information derived from
technical analysis of a photograph.
When you choose to run a scan, the App processes:
- A front photograph and side-profile photograph captured live with the App's
front-facing camera. The release App does not import scan images from the
photo library.
- Temporary on-device technical measurements used for face detection, capture
quality, alignment, framing, landmark availability, symmetry, and facial
proportions. These measurements support capture consistency and are not used
to identify or authenticate you.
- Results generated from the submitted photographs, including qualitative
presentation observations, controllable focus areas, grooming and routine
recommendations, a 28-day plan, qualitative progress states, and an optional
AI-generated Routine Preview. The App may retain internal continuity values
to keep signal ordering and personal check-ins consistent. These values are
not displayed as attractiveness scores, percentiles, tiers, or comparisons
with other people.
The App does not collect Face ID data, a TrueDepth face map, or a biometric
template. It does not identify you, authenticate you, match your face against
other people or images, determine your real-world identity, or create a public
face profile.
### 2.2 Profile Information
You may provide a grooming track, goal, and focus areas. The App also sends the
App's active language so the requested report can be returned in that language.
The App does not
require a name, email address, phone number, contacts, social-media account, or
date of birth. The App does not collect your birth date.
### 2.3 Anonymous Account and Purchases
Firebase Authentication creates a random anonymous user identifier. We use it
to associate your reports, progress, server-side usage controls, and
subscription entitlement with the same private account.
RevenueCat and Apple process purchase and subscription information. We do not
receive your full payment-card details.
### 2.4 App Usage and Technical Data
Firebase Analytics may collect a random app-instance identifier,
product-interaction and app-lifecycle events, session information, device and
app information, in-app purchase events, approximate location derived from a
masked IP address, and diagnostics. Events include actions such as viewing
onboarding or the paywall, starting or completing a scan, opening a report,
beginning a routine, restoring a purchase, or using a feature. We do not set
the Firebase anonymous account ID as the Analytics user ID. Our analytics
events do not include photographs, facial landmarks, facial measurements,
internal continuity values, report text, or generated images.
Firebase and related infrastructure may temporarily process IP addresses,
device information, security tokens, and request metadata to authenticate,
protect, operate, and troubleshoot the service.
## 3. How We Use Face Data
We use Face Data only to provide features you request:
1. Detect a usable face and guide front and side-profile capture.
2. Calculate temporary technical measurements for capture quality and
repeatable framing.
3. After explicit consent, send the front photograph, side-profile photograph,
relevant temporary measurements, selected grooming track, goal, focus areas,
and App language to the Google Gemini Developer API through an authenticated
Firebase Cloud Function.
4. Generate a private report about controllable presentation inputs, such as
grooming, skin-care consistency, recovery, posture, styling, lighting,
camera position, and repeatable framing.
5. Identify qualitative signal roles, including one controllable bottleneck,
one signal that is working well, and any capture-condition distortion.
6. Build a 28-day routine and compare later check-ins only with your own
baseline.
7. After separate explicit permission and only when you request it, send the
saved front photograph and selected goal to Google Gemini to generate an
optional Routine Preview that preserves your identity and illustrates
controllable grooming and presentation changes.
8. Display and locally save your report and, only when you choose, export or
share an image through the iOS share sheet.
We do not use Face Data for advertising, marketing, cross-app tracking,
surveillance, identity recognition, eligibility decisions, credit, employment,
insurance, healthcare decisions, law enforcement, public ranking, or comparison
with other people. We do not sell or rent Face Data. We do not use Face Data to
train our own machine-learning models.
Reports and generated images are subjective AI estimates for informational
self-improvement. They are not medical or psychological diagnoses and are not
professional advice.
## 4. Sharing and Third-Party Processing
### 4.1 Google
After you give explicit permission and initiate a scan, the front photograph,
side-profile photograph, relevant temporary measurements, selected grooming
track, goal, focus areas, and App language are transmitted over encrypted
connections to a protected Google Firebase Cloud Function and then to Google
LLC's Google Gemini Developer API. Google is the only third-party processor to
which we actively transmit Face Data.
Routine Preview has a separate permission prompt. If you choose to generate a
Routine Preview, the saved front photograph and selected goal are transmitted
through the same protected route. The side-profile photograph and technical
measurements are not sent for Routine Preview generation.
We use Gemini as a Paid Service through a Google Cloud project with billing.
Under Google's Paid Services terms, Google does not use submitted prompts,
images, or responses to improve its products. Google may temporarily process
limited logs for abuse prevention, security, and legal compliance and may use
isolated in-memory caching for up to 24 hours. We do not use Gemini Files,
Grounding, the Interactions API, explicit context caching, or optional prompt
sharing for scans.
We use third-party processors only when their applicable agreements require
them to process personal data for the services we request and to maintain
privacy and security protections. Google processes paid Gemini requests under
its applicable data-processing terms. We confirm that each third party with
whom we share personal data is required to provide the same or equal protection
of user data as stated in this Privacy Policy and required by the App Review
Guidelines. If a provider can no longer provide that protection, we will stop
sharing personal data with that provider.
Relevant policies:
- https://ai.google.dev/gemini-api/terms
- https://ai.google.dev/gemini-api/docs/zdr
- https://firebase.google.com/support/privacy
- https://policies.google.com/privacy
### 4.2 RevenueCat and Apple
RevenueCat receives the anonymous user identifier and purchase or subscription
status to provide entitlements, restore purchases, and process subscription
lifecycle events. Apple processes App Store purchases. We do not send scan
photographs, facial measurements, report data, or generated images to
RevenueCat or Apple as part of a scan.
- https://www.revenuecat.com/privacy
- https://www.apple.com/legal/privacy/
### 4.3 Legal and Security Disclosures
We may disclose information when required by applicable law or valid legal
process, or when reasonably necessary to protect users, our rights, or the
security of the App. We do not disclose Face Data to data brokers, advertisers,
or unrelated third parties.
## 5. Where Data Is Stored
- **On your device:** After a successful scan, the App stores a compressed copy
of the front photograph in protected Application Support storage so it can
display your report and Routine Preview. The folder is marked to be excluded
from iCloud and device backups. The side-profile photograph is held only for
the active capture and analysis session and is not intentionally persisted.
- **Firebase Cloud Functions:** Raw photographs pass through the function in
memory. Our code does not write raw photographs to Firebase Storage,
Firestore, or application logs. The request is released when processing ends;
the function has a maximum execution time of 120 seconds. Operational logs
may contain the anonymous user ID, request size, model name, usage count, and
generated error text, but not the submitted raw photograph.
- **Google Gemini:** Photographs and measurements are processed as inline
request content. Limited abuse-monitoring logs and isolated in-memory caching
may be handled as described in Section 4.1.
- **Cloud Firestore:** Generated reports and progress are stored under the
random anonymous user ID. This can include category observations,
recommendations, internal continuity values, routine activity, and check-in
trends. Firestore does not store the raw front or side photographs.
- **Routine Preview:** The generated image is returned to App memory for
display. Our code does not upload it to Firestore or Firebase Storage. It
leaves the App only if you choose an iOS share action.
Provider processing may occur in the United States and other countries where
Google, Firebase, RevenueCat, and Apple operate, subject to their contractual
and legal transfer safeguards.
## 6. Retention and Deletion
- Raw photographs exist in Cloud Function memory only while processing, for no
more than 120 seconds, and are then released.
- Google may use isolated in-memory caching for up to 24 hours and may retain
limited Paid Service logs for abuse prevention, security, or legal compliance.
Google does not publish a fixed duration for those limited logs.
- The compressed local front photograph and local report cache remain until you
delete the account and data in the App, delete the App and its data, or iOS
otherwise clears the App container.
- Firestore reports and progress remain until you use **Profile > Privacy &
data > Delete account and data**, or until the service is discontinued.
- Subscription and transaction records are retained as needed to provide the
subscription, resolve disputes, prevent fraud, and meet legal obligations.
They do not contain Face Data.
- Firebase Analytics data is retained for no longer than 14 months. Operational
Cloud logs are ordinarily retained for up to 30 days unless a security or
legal obligation requires longer retention.
The in-app deletion control permanently deletes the Firebase anonymous account,
Firestore profile, reports, routine data, subscription linkage held by us, and
locally stored scan photographs. Deletion is initiated and completed in the
App; an email is not required. A deletion request does not cancel an Apple
subscription. The App provides a Manage Subscription link, and Apple billing
continues until the subscription is canceled in Apple ID settings.
Deleting the account also resets the app's local Analytics identifier.
Previously processed Analytics events remain subject to the Analytics retention
period above because they are not associated with the Firebase anonymous
account ID.
For help with a privacy request, contact ozmaviyusuf@gmail.com and include the
anonymous Profile ID shown in the App.
## 7. Consent and Withdrawal
Before an AI scan, the App identifies Google LLC and the Google Gemini
Developer API, lists each category of data that will be sent, explains the
purpose, links to this Privacy Policy, and asks for explicit permission. The
App offers "Allow AI Processing" and "Not Now" choices. Choosing "Not Now"
sends nothing.
Consent is tied to the current disclosure version. After a material disclosure
change, an older consent record does not authorize processing and the App asks
again. Each Firebase Function request must contain a current consent receipt
before the function can forward data to Gemini.
Routine Preview uses a separate explicit permission because it sends a saved
front photograph for image generation. Face Data is sent only after the
applicable permission and only when you initiate the relevant feature.
You can withdraw consent for future AI processing at any time in **Profile >
Privacy & data > AI processing consent**. Withdrawal clears permission for
both report processing and Routine Preview generation. Those features remain
unavailable until you explicitly allow the applicable processing again.
Withdrawal does not affect processing already completed. You can delete stored
data through the in-app deletion control described in Section 6.
## 8. Security
We use reasonable administrative, technical, and organizational safeguards.
Data is encrypted in transit with HTTPS/TLS. Firebase rules restrict Firestore
records to the authenticated anonymous user. Server functions require
authentication and enforce subscription and usage controls. API and webhook
secrets are stored in server-side secret management rather than in the App.
No system is completely secure, and we cannot guarantee absolute security.
## 9. Your Privacy Rights
Depending on where you live, you may have rights to request access, correction,
deletion, restriction, portability, or objection; withdraw consent; and complain
to a data-protection authority. You will not receive discriminatory treatment
for exercising a privacy right.
For users in the EEA, United Kingdom, or Switzerland, we process Face Data and
profile answers based on consent and to provide the service you request. We
process security, fraud-prevention, and limited operational data based on our
legitimate interests in operating and protecting the App, subject to applicable
law.
For California residents, we do not sell personal information or share it for
cross-context behavioral advertising. We do not use or disclose sensitive
personal information, including Face Data, for purposes beyond providing and
securing the user-requested functions described in this Policy.
## 10. Age Requirement
The App and its AI features are not directed to, intended for, or permitted for
people under 18 and are distributed with an 18+ age rating. The App does not
collect a birth date or display a separate age-confirmation screen. We do not
knowingly collect Face Data from anyone under 18. If you believe a person under
18 submitted information, contact us so we can delete it.
## 11. Changes
We may update this Policy to reflect changes to the App, providers, or legal
requirements. We will publish the revised Policy with a new effective date and,
where required, request consent before materially changing how previously
collected Face Data is used.
## 12. Contact
Yusuf Ozmavi
Email: ozmaviyusuf@gmail.com