Privacy

Privacy Policy

This Policy explains how Looksmax processes information when an adult uses a front and side photo to request a private grooming and presentation report and 30-day plan.

Effective date: 15.08.2026

1. Controller and Section 11 notice

Kovacs Software Solutions is the controller for information processed by the App. Privacy inquiries: info@kovacssoftware.com. Support: support@kovacssoftware.com.

Providing information is voluntary. Without the required age/self-photo attestations, upload consent, selected photos, device identifier, and active entitlement, we cannot perform an analysis. We use the information only for the purposes and recipients described below. Subject to applicable law, you may request access to or correction or deletion of information by contacting us or using the App’s data controls.

2. Adults and your own photos only

The App is for people aged 18 or older. Analyze only photos of yourself. We record an eligibility confirmation timestamp, consent/policy version, and per-upload attestations; we do not request your birth date. If we learn that a minor or another person’s photo was submitted contrary to these rules, we may restrict the account and delete or isolate the information as permitted or required by law.

3. Information processed

  • The front and right-profile photos you capture or select for a requested analysis, and a front photo you separately choose to upload for an AI hairstyle preview.
  • Your chosen goals, 5/10/15-minute routine, grooming and skincare experience, and facial-hair preference. The AI is instructed not to infer these preferences.
  • The resulting report, applicable metric scores, confidence, observations, recommendation IDs, 30-day plan, task completions, check-ins, and progress comparisons.
  • A random installation identifier, guest or Apple-linked account identifier, authentication tokens, request/idempotency identifiers, entitlement status, purchase status, request timing, IP address, and limited security/diagnostic information.
  • Messages or attachments you voluntarily send to support, including any sensitive information you choose to include. Do not send health, mental-health, or other sensitive information that is not necessary for us to answer a product-support request.

We do not create facial-recognition templates or persistent identity embeddings. We do not infer or request ethnicity, religion, nationality, sexuality, disability, medical conditions, personality, exact age, or identity.

4. Why we process information

We process information to provide the analysis, plan, and hairstyle preview you request; assess photo quality and safety; save your report and progress on your device; authenticate sessions; verify subscriptions; enforce the 14-day rescan interval; prevent duplicate, fraudulent, or abusive requests; provide support; maintain security and reliability; and comply with applicable law.

We do not use photos or reports for advertising, public rankings, social comparison, marketing profiles, or sale to data brokers.

5. Photo and AI processing

During setup, you confirm that you are 18 or older and will use only your own photos. Before a scan upload, one confirmation states that the photos show you and explicitly permits sharing them with the disclosed AI processors to create your report. In the hairstyle studio, selecting Create My Preview provides the same confirmation and permission for the front photo already stored in the App.

The App re-encodes selected images as JPEG, limits their dimensions, and strips source metadata such as EXIF and location before upload. Our Laravel API validates the files and sends them to OpenAI or Google Gemini. Report analysis currently uses OpenAI with Gemini failover; hairstyle generation currently uses Gemini with OpenAI failover.

Raw photos are handled transiently in request memory and are not written to our permanent server storage or application logs. The structured report is encrypted temporarily for idempotent retry and is deleted when the App acknowledges safe local storage, or automatically within 24 hours. An AI hairstyle result is encrypted for exact retry for no more than 10 minutes, returned to the App, and stored only in the App’s private purgeable cache. Failed and stale requests are cleaned up on a schedule.

We do not train our own models on uploads and do not authorize providers to use uploads for model training. Release is conditional on verifying the applicable provider API terms and contractual safeguards.

AI processing is automated and probabilistic. We do not use the report to identify you, diagnose or infer a medical or mental-health condition, determine attractiveness or personal worth, or make a decision that produces legal or similarly significant effects. Looksmax does not monitor photos, reports, support channels, or device activity to identify distress or imminent harm.

6. On-device storage and optional iCloud

Accepted progress photos, reports, plans, and completion history are stored in private App storage on your iPhone by default. Rejected or abandoned captures are deleted. If you explicitly enable iCloud backup, a versioned copy of the selected App data and photos is stored in your private iCloud container under Apple’s terms. Disabling backup does not by itself delete an existing iCloud copy; use the in-App delete control.

Face ID protection and notifications are optional device features. Permission can be changed in iOS Settings.

Anyone who can unlock your device, access your Apple account or iCloud container, view a notification, or receive content you export or share may be able to see the information. You are responsible for device and account access controls. Device loss, operating-system behavior, backup configuration, screenshots, exports, and sharing outside the App are not controlled by Looksmax.

7. Processors and international transfers

  • Laravel application hosting/infrastructure for the authenticated API, encrypted temporary results, queues, and security controls.
  • OpenAI and Google Gemini for a user-requested analysis or hairstyle image edit.
  • RevenueCat for subscription entitlement and restoration.
  • Apple for the App Store, StoreKit billing, Sign in with Apple, device permissions, and optional iCloud backup.
  • Diagnostics or support providers only if identified in the current App privacy disclosures and used in the deployed build.

Some recipients may process information outside Israel. We use contractual, organizational, and technical safeguards required by applicable Israeli law. Each provider also publishes its own terms and privacy information and is responsible for processing it performs independently. External services may change their systems or terms; we update this Policy and our processor review when required.

8. Legal disclosures and business changes

We may preserve, access, or disclose the minimum information reasonably necessary when required by applicable law, valid legal process, or a competent authority, or where permitted by law to investigate fraud or security, enforce our terms, defend legal claims, protect rights, or address a credible and imminent threat to life or safety. We do not promise that support is monitored continuously or that we can identify or respond to an emergency.

If the App or its operator is involved in a financing, reorganization, merger, acquisition, insolvency proceeding, or transfer of assets, information may be reviewed or transferred subject to applicable confidentiality, purpose-limitation, notice, and other legal requirements. A transaction does not authorize a materially incompatible new use without any notice or consent required by law.

9. Retention and deletion

Server records retain only the minimum identifiers, consent/prompt/model versions, status, timing, keyed input digest, cooldown metadata, and security information needed to operate and protect the service. Raw photos are not retained server-side after request processing. The encrypted structured report is retained for no more than 24 hours unless acknowledged sooner; an encrypted hairstyle retry result expires within 10 minutes.

You may delete an individual scan locally or delete the account and local content from Settings. Account deletion also requests backend identity deletion and removes pending notifications. If iCloud backup is enabled, the App attempts to delete its iCloud copy. Deletion may not be instantaneous in encrypted backups, provider queues, or records that must be retained. Limited records may remain for the period reasonably necessary or legally required for security, accounting, dispute preservation, legal claims, and fraud prevention, after which they will be deleted or de-identified as applicable.

10. Security and incidents

We use encrypted transport, authenticated access, private device storage, encrypted temporary server fields, rate limits, idempotency controls, and access restrictions. No technical or organizational measure, device, transmission, provider, or storage system is completely secure or error-free, and we cannot guarantee that unauthorized access, loss, alteration, or disclosure will never occur. This statement does not reduce our legal security obligations. We maintain an incident-response process and will notify the Privacy Protection Authority or affected people when applicable law requires it.

11. Support and emergencies

Support is not continuously monitored and is not a medical, mental-health, emergency, or crisis service. Do not use support to report imminent danger. If you voluntarily send sensitive information, we will process it to handle the request, protect the service or people, comply with law, and establish or defend legal claims as applicable. If you or someone else may be in immediate danger, contact local emergency services rather than Looksmax.

12. Your choices and rights

You may decline an upload, revoke future consent, disable notifications, Face ID, or iCloud, restore or manage subscriptions, delete a scan, or delete your account. Existing locally saved reports remain readable after a subscription expires; new analyses and regenerated plans require an active entitlement.

To exercise applicable access, review, correction, objection, or deletion rights, email info@kovacssoftware.com. We may need to verify the request without requesting unnecessary identity data. Revoking consent applies to future consent-based processing and does not invalidate processing already completed lawfully or processing retained under another applicable legal requirement.

13. External resources and user sharing

The App may open Apple, ERAN, or other independent websites or services. Their operators determine their own processing, availability, and privacy practices. Review their notices before providing information. When you export, screenshot, or share a report or hairstyle image, the recipient and selected service may retain or redistribute it outside our control.

14. Changes and contact

We may update this Policy as the service or law changes. Material changes will be presented through an appropriate notice and, where required, renewed consent. Questions can be sent to info@kovacssoftware.com. See also our Terms of Use.