Last Updated: October 1, 2026
Background
This Privacy Policy explains how Hair Explained INC ("we", "our", "us") processes your personal data when you access our website, mobile applications, or related digital services (together, the "Service").
This Policy is intended to address applicable requirements under:
- EU General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA/CPRA)
- U.S. privacy protection laws and FTC transparency principles
- EU–US Data Privacy Framework (DPF) for cross-border transfers
- Other applicable international privacy regulations.
1. Who We Are (Data Controller)
The controller responsible for your personal data is:
Hair Explained INC Email: privacy@hairexplained.io
If you are located in the EU/EEA, you may additionally contact our EU Representative appointed pursuant to Articles 3(2) and 27 GDPR:
Hair Explained EU Representative Address: Rua Almirante Barroso 18, Apt 2, 1000-013 Lisbon, Portugal Email: privacy@hairexplained.io
2. What Data We Collect
We collect only the data necessary to operate and improve the Service. This includes:
2.1 Account Information
- Your name (or nickname)
- Email address
- Credentials you use to sign up to the services
2.2 Payment Information
Your payment details to process subscription payments.
2.3 Hair Care Data You Provide
- Hair photos you upload. We ask you not to upload your face or other identifiable details.
- Product photos you choose to analyze to identify or understand a product.
- Hair-care questionnaire data and derived profile: your answers about hair habits, hair and scalp concerns, hair-care practices, routines, and related hair-care information, plus the profile derived from those answers.
- Product and routine context: product names, barcodes, ingredients, product photos, and routine information you provide or choose to use when seeking a personalized assessment or recommendation.
We do not use your data for medical or health-related purposes and do not provide medical advice or health assessment. Please do not upload medical records, diagnostic information, or images that may reveal your health status. If you have a medical concern, please consult a qualified healthcare professional.
2.4 Technical and Usage Data
Automatically collected information:
- Device and browser information
- IP address (truncated or pseudonymized where possible)
- Cookies and usage analytics
- Interaction logs needed to maintain the Service, detect errors, and personalize content
In our mobile app, we do not request permission under Apple's App Tracking Transparency framework, access Apple's Identifier for Advertisers (IDFA), or use third-party advertising SDKs. On Android, our subscription-management SDK may access the Google Advertising ID assigned by your device. We do not use it for targeted advertising and do not disclose it to advertising platforms; you can reset or delete it in your Android settings.
On our website, we use advertising and conversion-measurement technologies, including the Meta Pixel and the TikTok Pixel, through browser-based tags and, where enabled, server-side integrations. We use these technologies to measure the effectiveness of our marketing, attribute conversions, optimise advertising campaigns, and reach or re-engage potential customers. Through these technologies, we and the advertising platforms identified in Section 6 may process online identifiers, cookie identifiers, IP addresses, device and browser information, and information about your interactions with our website for advertising and campaign-measurement purposes.
We enable these advertising technologies only for visitors located in the United States, and you can opt out of them at any time (see Section 10.3 and the Cookie Preferences control). If we cannot determine that a visitor is located in the United States, we do not load these advertising technologies. We do not deploy these advertising technologies on our hair questionnaire, photo-upload, or questionnaire-results screens, or on any other page that reveals or may reasonably reveal information about a hair or scalp concern, condition, treatment, health-related matter, uploaded photograph, or attribute derived from a photograph. We never include hair, scalp, health, treatment, or photo-derived attributes in advertising data, and we do not transmit such information to advertising platforms.
More details are contained in our Cookie Policy.
2.5 Hair and Scalp Information: Non-Medical Purpose and Limitations
The Service collects the hair and scalp information described in Section 2.3, including reported concerns and hair-care practices and related inferences in your derived profile. We use this information to provide personalized, non-medical hair-care assessments and recommendations, not to diagnose, treat, cure, or prevent a disease or to provide medical advice.
The Service is not intended to collect such sensitive personal data as biometric data used to identify a person, precise geolocation, medical records, diagnostic information, or other information about your health. However, depending on the information, context, and your place of residence, applicable law may treat some hair or scalp information, hair photographs, reported hair-care practices, or related inferences as sensitive personal information or consumer health data.
Sections 4, 5, 9, and 10 of this Policy describe the consent, withdrawal, retention, and privacy-rights controls available through the Service.
Please do not upload medical records, diagnostic information, or images that may reveal information beyond what is needed for the requested hair-care feature. We do not use photos for facial recognition or biometric identification, and we do not extract or retain face-geometry templates.
3. For What Purposes We Process Your Data
We use your data for the following purposes:
- Account registration and authentication (your name or nickname, credentials, and email)
- Providing AI-assisted, personalized, non-medical hair-care assessments and recommendations after the separate in-app AI-processing consent described in Sections 4 and 5
- Processing subscription payments (your payment details)
- Providing customer and technical support, and other service-related communications (your name or nickname, your email)
- Ensuring security, preventing fraud, and complying with legal obligations
- Service analytics, performance monitoring, and product development (usage data), subject to applicable legal requirements and your privacy rights
- Quality assurance and safety review of the Service, in which qualified personnel may review selected hair photos, questionnaire answers, and generated recommendations as described in Section 5
4. Legal Bases for Processing
We process your personal data only when we have a valid legal basis to do so. The basis for processing depends on the services you use and the jurisdiction you are in.
4.1 For Users in the European Union (EU) / European Economic Area (EEA), UK, and Switzerland
If you are located in the EEA, the United Kingdom, or Switzerland, we rely on the following legal bases under the General Data Protection Regulation (GDPR):
- Performance of a Contract (Article 6(1)(b) GDPR): We process personal data such as your account details, payment information, and questionnaire responses because it is necessary to deliver the Service you have requested and to fulfill our contractual obligations to you.
- Explicit Consent (Article 9(2)(a) GDPR): We process your uploaded hair photos, including for the quality assurance and safety review described in Section 5, only after you provide your explicit consent, because such photos may contain information that qualifies as special-category personal data under applicable law. We do not intentionally collect or use such information for medical, biometric-identification, or other sensitive purposes. You can withdraw your consent at any time; however, doing so will prevent us from providing the core recommendation feature of our Service.
- Separate Consent for AI Processing: Before Hair Explained sends your personal data to an AI provider for an AI-dependent feature, the mobile app presents a separate, in-context consent prompt. The prompt identifies the purpose of the processing, the categories of personal data involved, the AI providers, and provides a link to this Policy. The consent applies to the personal data required for the requested AI-dependent feature, which may include hair and product photos, questionnaire answers, your derived hair or scalp profile, and relevant product and hair-care routine information. If you decline or withdraw this consent, we will not send that personal data to an AI provider; Section 5.4 explains what happens if you decline or withdraw. Accepting the Terms of Service or this Privacy Policy does not constitute consent to such disclosure to AI providers.
- Legitimate Interests (Article 6(1)(f) GDPR): We process technical and usage data for our legitimate interests, which include ensuring the security and integrity of our platform, preventing fraud, troubleshooting technical issues, improving our Service, and reviewing selected questionnaire answers and generated recommendations for quality assurance and safety. We conduct a balancing test to ensure these interests do not override your rights and freedoms.
4.2 For Users in the United States
For users in the United States, we process your personal information for "business purposes" as defined by applicable U.S. privacy laws, including the California Privacy Rights Act (CPRA). These purposes include:
- Operating and maintaining the Service;
- Processing your payments and managing subscriptions;
- Protecting against security incidents and preventing fraudulent activity;
- Debugging to identify and repair errors that impair functionality;
- Conducting internal research to improve our Service;
- Complying with our legal and regulatory obligations.
As described in Sections 2.4 and 6, we may disclose personal information to advertising platforms and process it for targeted advertising. For California residents, if the CCPA applies to us, these disclosures may constitute "sharing" for cross-context behavioral advertising and may also constitute a "sale." Similar activities may be treated as targeted advertising or a sale under other U.S. state privacy laws. You may opt out at any time as described in Sections 10.3 and 12.
Before we share personal data with the AI providers identified in Section 6 for an AI-dependent feature, the mobile app presents a separate, in-context request for explicit permission. The request identifies the non-medical hair-care purpose, the categories of personal data that may be sent, and those AI providers as the potential recipients, as described in Section 5.1. Accepting the Terms of Service or this Policy does not provide that permission.
You may decline without authorizing the disclosure; Section 5.4 explains what happens if you decline or later withdraw. You may later withdraw through the mobile app's Data & Privacy settings or by contacting us as described in Section 12. Withdrawal stops later personal-data AI requests after it is recorded, subject to the limits in Section 5.4.
Federal and state consumer-health privacy protections may also apply to particular information or processing depending on the facts, including the FTC Act, the FTC Health Breach Notification Rule, and state consumer-health privacy laws. Depending on the applicable law, additional consent, access, deletion, or incident-notification requirements may apply; Section 10 describes how to exercise privacy rights. This description does not determine whether a particular law or statutory data category applies to every user or every data item.
4.3 Other Jurisdictions
For all users, accepting the Terms of Service or this Privacy Policy does not itself authorize personal-data AI processing. We request that authorization through the separate in-app consent prompt described in Sections 4.1 and 5. Other processing is carried out as permitted or required under applicable law, including on the basis of consent, performance of a contract, compliance with legal obligations, or other lawful grounds.
5. Use of AI & Machine Learning
Hair Explained uses automated processing, including artificial intelligence (AI), to provide personalized, non-medical hair-care assessments and recommendations. We do not use AI systems to make decisions that produce legal effects or similarly significantly affect you.
Recommendations provided through the Service are generated automatically. Qualified personnel may review selected inputs and outputs for quality assurance, safety, and improvement of the Service, but do not manually review every individual recommendation.
5.1 Explicit In-App Consent Before AI Processing of Personal Data
Before the Service sends your personal data to an AI provider for the purposes described below, the mobile app asks for your explicit consent in context through an in-app prompt and provides a link to this Policy.
The consent prompt identifies the purpose of the processing, the categories of personal data involved, and the relevant AI providers. The requested consent covers the disclosure to, and processing by, the AI providers identified in Section 6 of the following categories of personal data:
- hair or product photos,
- questionnaire answers,
- derived hair and scalp profiles, including reported concerns and hair-care routine details,
- product and routine context.
This AI-assisted processing is used to generate personalized, non-medical hair-care assessments and recommendations.
You may decline the consent request or withdraw your consent as described in Section 5.4. Accepting the Terms of Service or this Privacy Policy does not constitute consent to the disclosure or AI processing described in this Section.
5.2 AI Providers
AI-dependent features involve the processing of personal data by the AI providers identified in Section 6, subject to your separate, in-context consent in the mobile app as described in Section 5.1 above. Data sent to an AI provider may include the categories of personal data described in Section 5.1.
Requests sent to an AI provider do not include your name, email address, or internal account identifier, and we take measures intended to reduce the amount of directly identifying information in those requests. We cannot guarantee, however, that you could not be identified from the content of an uploaded image, its metadata, or other information you provide.
5.3 AI Provider Retention and Storage
We do not use your personal data to train or improve AI models of our own. Personal data sent to an AI provider may be retained or otherwise processed by that provider, including for model training or improvement, in accordance with the terms and settings applicable to that provider's service.
Where available, we use provider settings designed to limit retention and secondary use of personal data. However, limited retention may still occur for security, abuse prevention, legal compliance, or similar operational purposes. Provider retention and processing can also be governed by the provider's current terms and account configuration.
We do not represent that personal data sent to an AI provider is anonymous or that it is excluded from model training or improvement.
5.4 Declining, Withdrawal, and Limits
You may decline; in that case, we do not send those personal-data inputs to an AI provider, and features that require AI processing of your personal data are not provided.
You can withdraw AI-processing consent in the mobile app's Data & Privacy settings or by contacting us using Section 12. Withdrawal prevents future personal-data AI requests after it is recorded. Results of analysis completed before withdrawal remain available to you, but no new individualized analysis requiring AI processing is performed. Withdrawal cannot recall a request already sent to an AI provider or cancel processing already in progress, and it does not itself delete photos, questionnaire data, profile data, or other account data.
You may exercise the deletion rights described in Sections 9 and 10 with respect to data stored by Hair Explained. Deletion from our systems may not affect data retained by an AI provider in accordance with Section 5.3.
6. Data Sharing With Service Providers
We disclose personal data to the categories of recipients listed below for the stated Service purposes and, for United States visitors, to the advertising platforms separately described in the "Advertising Platforms" section below. Where a recipient acts as our service provider or processor, we require appropriate contractual commitments regarding confidentiality and the use of personal data. Other recipients may process personal data in accordance with their own applicable legal obligations and privacy terms.
Categories of Recipients:
- AI Providers: Google (Gemini API) and OpenAI (OpenAI API) provide AI processing used to generate the personalized, non-medical hair-care assessments and recommendations described in Section 5. Personal data disclosed to these providers is limited to the categories described in Section 5.1 and is sent only after you provide the in-app consent described there. Depending on the requested operation and technical availability, personal data may be processed by Google, OpenAI, or, where fallback processing is required, both providers. We do not represent personal data sent to AI providers as anonymous or pseudonymized.
- Cloud Hosting & Infrastructure Providers: Supabase (USA/EU) — authentication, database, and secure storage of hair photos and questionnaire data; Vercel (USA) — application hosting and edge runtime.
- Analytics Tools: PostHog (US cloud) — usage and performance analytics based on technical and interaction data generated when you use the Service. PostHog does not receive hair photos, questionnaire answers, or free-text content. For product analytics it receives coarse derived hair attributes — such as the hair type and thickness class a recommendation was built for — and diagnostics about how a hair-care routine was assembled; for the mobile app, these events are sent without a person profile and with IP-based geolocation disabled. For personal-data AI calls, PostHog also receives limited technical metadata about an authorized provider attempt, such as site, provider, model, token counts, outcome, attempt number, latency, environment, mode, normalized error category, and a random per-call identifier. These AI-call events do not contain user or domain identifiers, prompts, responses, raw errors, or image bytes. For these events, person-profile creation and IP-based geolocation are disabled. Where advertising is enabled for United States visitors, PostHog also forwards limited conversion events — including a hashed email address used as a match key — to the advertising platforms named below in this Section 6. We process the technical and usage analytics described above under the applicable legal bases set out in Section 4 and retain them for the technical-log period described in Section 9.
- Payment Processors: Stripe (USA) — secure payment and subscription management.
- Subscription Management: Adapty (USA) — processing and validation of in-app subscription purchases, entitlement status, and related device and transaction information.
- Email Delivery Providers: Resend (USA) — delivery of transactional emails (e.g., account, billing, and Service-related notifications).
- Error & Performance Monitoring: Sentry (USA) — diagnostic events, error reports, and stack traces used to detect and fix issues. We do not intentionally send hair photos or health-related data to this provider.
- Customer Support Tools: Intercom (USA) — to respond to your inquiries and resolve issues.
- Professional Consultants: Legal advisors, auditors, and privacy consultants who assist us with compliance, security assessments, and business operations.
- Affiliates: Corporate affiliates and subsidiaries that support our business operations.
Advertising Platforms. For visitors identified as being located in the United States, we may use advertising and conversion-measurement technologies provided by Meta Platforms, Inc. (USA) and TikTok Inc. (USA). We use these technologies to measure advertising performance, attribute visits, registrations, or subscriptions to advertising campaigns, optimise our campaigns, and create or reach advertising audiences. These advertising platforms may receive technical and usage information such as your IP address, device and browser information, cookie or similar identifiers, pages visited, interactions with the Service, and advertising or conversion events. Unlike the service providers listed above, these platforms do not act solely as our processors. We configure these technologies not to transmit uploaded photographs, questionnaire responses, photo-derived attributes, payment information, or any page, event, or parameter information that identifies or may reasonably reveal a specific hair or scalp concern, condition, symptom, treatment, or other health-related matter. We enable these advertising technologies for United States visitors only, on an opt-out basis, and do not load them for visitors identified as being outside the United States or whose location we cannot determine. You may opt out at any time through the Cookie Preferences control.
7. International Data Transfers
If you are a resident of the European Union (EU), the European Economic Area (EEA), or the United Kingdom (UK), please be advised that your Personal Data may be transferred to, stored in, and processed in the United States. Depending on the transfer and recipient, relevant transfer mechanisms and safeguards may include:
- EU Standard Contractual Clauses (SCCs)
- EU–US Data Privacy Framework (DPF) certifications (when applicable)
- Additional safeguards, including encryption and strict access controls
As described in Section 6, we enable the advertising technologies covered by this Policy for visitors identified as being in the United States only, who may opt out at any time; we do not load them for visitors outside the United States or whose location we cannot determine. Accordingly, the advertising data described in Sections 2.4 and 6 is not transferred from the EU/EEA or the UK to advertising platforms.
8. How We Protect Your Data
We use industry-standard technical and organizational security measures, including:
- Encryption in transit and at rest
- Access control restrictions
- Regular security audits
- Access controls, data minimization, and isolation measures for AI processing; personal data sent to an AI provider can still contain raw images, text, and structured context needed for the requested feature
- Logging and monitoring for abnormal behavior
9. Data Retention
We keep personal data only as long as necessary for the purposes described in this Policy:
- Account data — until your account is deleted or terminated
- Hair photos & questionnaire data — retained for as long as reasonably necessary to provide the Service. Your hair photos and the associated questionnaire data are permanently deleted from our storage when you delete the relevant photos or when your account is deleted, whichever happens first. For visitors who begin but do not complete a diagnosis without an account, the associated photos and questionnaire data are automatically deleted within 30 days (See Terms of Service for detailed information about account deletion)
- Payment identifiers — retained for the period required by applicable financial, tax, and anti-money laundering regulations
- Technical logs — retained for limited, reasonable periods for security and performance purposes
- Consent audit logs — retained as long as necessary to demonstrate valid consent under GDPR Article 7(1) and other applicable privacy laws, maintain consent and withdrawal history, resolve disputes, and verify that personal-data processing by AI providers was authorized.
- AI-provider processing records — limited records of provider attempts and associated consent status may be retained as necessary to provide and secure the Service, investigate errors or misuse, and demonstrate that a particular AI-provider request was authorized. These records are subject to the retention and deletion periods described in this Policy. Retention by an AI provider for operational, security, abuse-prevention, or legal-compliance purposes is governed by the applicable provider terms, settings, and contractual arrangements, as described in Section 5.3.
Following the expiration of the applicable retention period, or upon a valid request for erasure, we will securely erase or irreversibly anonymize your Personal Data, unless continued retention is required or permitted by applicable law (e.g., for the establishment, exercise, or defense of legal claims). Deletion or anonymization from our systems may not affect Personal Data retained by an AI provider in accordance with the provider-side retention practices described in Section 5.3.
Please note that if you request deletion of data that are necessary to provide personalized hair-care recommendations, we may no longer be able to provide some or all subscription features.
10. Your Rights
10.1 Rights of All Users
You may contact us at privacy@hairexplained.io to:
- Request access to your data
- Request deletion of your data
- Request correction of inaccurate data
- Ask questions about our privacy practices
- Withdraw consent to personal-data processing where that processing is based on your consent; and withdraw consent to AI processing and disclosure to AI providers through the mobile app's Data & Privacy settings or by contacting us. Withdrawal of AI-processing consent affects future personal-data AI processing as described in Section 5.4, but cannot recall requests already sent to an AI provider or cancel processing already in progress
10.2 Additional GDPR Rights (EU/EEA)
Under the GDPR, you also have the right to:
- Data portability
- Restrict processing
- Object to certain processing activities
- Lodge a complaint with your local Data Protection Authority
- Contact our EU Representative for inquiries
10.3 U.S. State Privacy Rights
Depending on your state of residence and subject to applicable requirements and exemptions, residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other U.S. states with applicable consumer privacy laws may have the right to:
- confirm whether we process their personal data;
- access their personal data;
- correct inaccuracies in their personal data;
- delete their personal data;
- obtain a portable copy of their personal data;
- opt out of the sale of personal data, sharing of personal data for targeted advertising, or certain profiling, where applicable;
- appeal a refusal to act on a request;
- exercise their rights without discrimination or retaliation.
As described in Sections 4.2 and 6, for visitors in the United States we disclose personal data to advertising platforms and process it for targeted advertising, which may constitute a "sale" or "sharing" under applicable U.S. state privacy laws. You may opt out at any time using the methods in Section 12 or the Cookie Preferences control, and we honour Global Privacy Control (GPC) signals. We do not use your personal data for profiling that produces legal or similarly significant effects.
To exercise your rights, please contact us at privacy@hairexplained.io. We may need to verify your identity before processing your request. We will respond within the timeframe required by applicable law.
11. Children and Minors
The Service is intended only for individuals 18 years or older. We do not knowingly collect personal data from individuals under 18. If you believe data was collected from a minor, contact us immediately at privacy@hairexplained.io.
12. How to Exercise Your Rights
12.1 Submitting a Request
You may submit any privacy request by emailing: privacy@hairexplained.io
We may need to verify your identity before fulfilling your request to protect your personal data from unauthorized access. Requests will be handled within the timeframe required by applicable law (typically up to 30 days, with possible extensions if your request is complex).
12.2 EU Representative (For EU/EEA Residents)
If you are located in the European Union or European Economic Area, you may also contact our designated EU Representative regarding any matters related to the processing of your personal data:
EU GDPR Representative: Hair Explained EU Representative Rua Almirante Barroso 18, Apt 2, 1000-013 Lisbon, Portugal Email: privacy@hairexplained.io
Our EU Representative acts on our behalf to address data protection inquiries.
12.3 Right to Lodge a Complaint
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the relevant data protection authority:
- For EU/EEA Residents: You may contact your local supervisory authority. A full list of EU data protection authorities is available at: European Data Protection Board
- For UK Residents: Information Commissioner's Office (ICO)
- For California Residents: California Privacy Protection Agency (CPPA)
Lodging a complaint with a supervisory authority does not affect any other legal remedies you may have.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If changes significantly affect your rights or the way we process data, we will notify you (e.g., via email or in-app notice). The "Last Updated" date at the top of this document indicates when it was last revised. When a change materially expands the personal-data AI processing described in Section 5, we require a new explicit in-app consent before using the changed processing.
14. Contact Us
If you have questions or requests regarding this Privacy Policy, please contact:
Hair Explained INC Email: privacy@hairexplained.io
If located in the EU/EEA, you may also reach our EU Representative: Hair Explained EU Representative, Rua Almirante Barroso 18, Apt 2, 1000-013 Lisbon, Portugal — privacy@hairexplained.io