Privacy Policy
Version privacy-policy@2026-09-21 · Effective 21 September 2026
Draft pending legal review. This policy describes what ROUTN actually does, but it has not yet been reviewed by a qualified data-protection practitioner and contains placeholders for company details. It must not be relied on as the final published policy.
1. Who is responsible for your data
ROUTN is operated by [LEGAL_ENTITY_NAME] (company number [COMPANY_NUMBER]), registered at [REGISTERED_ADDRESS]. We are the data controller for the personal data described here.
Privacy contact: [PRIVACY_EMAIL] ([DPO_OR_PRIVACY_CONTACT]).
2. What we collect
| Category | What it includes |
|---|---|
| Account | Email address, authentication session, display name if you give one, age band, timezone, locale. |
| Skin profile | Your own answers about how your skin behaves and what you notice, including whether it reacts easily and whether you shave. |
| Hair and scalp profile | Your goals, scalp concerns you selected, which regions you track, and how often you wash your hair. |
| Products | Brand, product name, category, notes, dates, and ingredient lists where available. |
| Routine | Your generated routine, its steps and versions, and which steps you completed or skipped on which day. |
| Photographs | Skin and hair progress photos you choose to keep; temporary photos used for a single analysis; product photos. |
| Analysis results | The structured description produced from a photo, plus which model and prompt version produced it. |
| Coach | Your messages, the Coach’s replies, and a short list of routine-relevant preferences it remembers. |
| Subscription | Whether you have an active entitlement, the store product identifier and period end. We never receive or store your card details. |
| Feedback board | Ideas you post and votes you cast, shown to other users without your name; when you posted; and, if a post is refused, the refused text and any resulting posting pause. Before an idea appears, its text (and nothing else about you) is checked by a word filter and then by our AI provider, which answers with a single category and keeps nothing. Only we can see which account posted what. |
| Technical | Device platform and app version, request identifiers, and error diagnostics with personal content stripped out. |
| Support | What you send us through the contact form, and our replies. |
| Email updates (website) | If you ask this website to email you the app link: your email address, the time you asked and the wording you agreed to, and whether the email was sent. No account is needed or created. |
We deliberately do not collect your full date of birth, home address, phone number, precise location, contacts, or microphone audio. The app blocks location and contacts permissions outright.
3. Why we process it, and on what basis
| Purpose | Data | Lawful basis (draft) |
|---|---|---|
| Create and run your account | Account | Contract (Art. 6(1)(b)) |
| Build and maintain your routine | Skin/hair profile, products, routine | Contract (Art. 6(1)(b)) |
| Analyse a photo you submit for a check-in | Photographs, analysis results | Consent (Art. 6(1)(a)), plus explicit consent under Art. 9(2)(a) where the information is treated as health data. Requires legal review. |
| Keep progress photos in your timeline | Photographs | Consent — asked separately from analysis and withdrawable |
| Answer your Coach questions | Routine, products, check-in metadata, messages | Contract, and consent for optional long-term memory |
| Send routine reminders | Account, routine, notification token | Consent (device permission), withdrawable at any time |
| Manage subscriptions | Subscription | Contract |
| Keep the service secure and reliable | Technical, audit events | Legitimate interests (Art. 6(1)(f)) — security and abuse prevention |
| Email you the app link and occasional updates from the website | Email address given on the website | Consent (Art. 6(1)(a) and PECR), given by asking for the email; withdrawable with the one-tap link in every email |
| Product analytics | Pseudonymous event counts: which screens are used and which features are tapped, and when the app is opened and closed | Consent, off by default; asked once in the app and changeable in Settings |
For legal review: self-reported skin and scalp information, and photographs analysed for visible characteristics, may constitute special-category data concerning health. The company must determine and document both the Article 6 basis and the Article 9 condition before launch. ROUTN’s design assumption is explicit consent, collected separately and never bundled into acceptance of the Terms.
3a. Email updates from the website
The website can email you the App Store and Google Play link, and — because you asked for it there — the occasional update about ROUTN afterwards, never more than a few a month. This is separate from having an account: we keep only the address you typed, when you asked, the wording you agreed to and whether the email went. Every email carries a one-tap unsubscribe link, which removes you from the list immediately; the entry is then deleted within 30 days. To limit abuse of the form we also keep a salted hash of the requesting connection’s address for 24 hours, from which the address itself cannot be recovered.
4. Photographs
There are exactly two kinds of photo in ROUTN, and you are told which one you are taking before the camera opens.
- Temporary analysis photos. Captured only to run one check-in or product scan. Deleted immediately after processing, and in any case within one hour by an automated retention job — including when the analysis fails.
- Progress photos. Kept in your timeline because you chose to keep them. Retained until you delete them or delete your account.
Photos are stored in a private bucket. They are never given a public URL and are served to you through signed links that expire in about two minutes. Images are resized and re-encoded on your device before upload, which removes EXIF metadata including any GPS coordinates.
To run an analysis, the image is sent to our AI provider. We do not use your photographs to train AI models, and we configure our provider for the minimum retention available. The specific provider, its retention setting and its data-processing terms are recorded in our processor register and must be confirmed before launch.
5. Who processes your data
| Processor | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All account data and photographs |
| [AI_PROVIDER] | Photo analysis and Coach responses | The specific image or context sent for one request |
| PostHog (EU, Frankfurt) | Product analytics, only with your consent | Event names from a fixed list, screen names, app open and close, a random id generated on your device. Never your account id, email, photographs, answers or anything you type. Location from your IP address is switched off. |
| RevenueCat | Subscription entitlement | Pseudonymous user id, store transaction reference |
| Apple / Google | Payment, app distribution, push delivery | Handled under their own policies; we never see payment details |
| [HOSTING_PROVIDER] | Website hosting | Server logs |
6. International transfers
Where a processor is outside the UK, we rely on UK adequacy regulations or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. The specific locations and safeguards for each processor above must be documented before launch. [TRANSFER_SAFEGUARDS]
7. How long we keep it
| Data | Retention |
|---|---|
| Temporary analysis photos | Deleted after processing; hard limit one hour |
| Progress photos | Until you delete them or delete your account |
| Account, routine, products, check-ins | Until you delete your account |
| Coach messages and memory | Until you clear them or delete your account |
| Feedback board ideas and votes | Until you delete them or delete your account |
| Refused feedback posts and posting pauses | 400 days, then removed automatically |
| Consent records | 6 years after the account closes, as evidence of consent |
| Website email list | Until you unsubscribe, then removed within 30 days |
| Security and audit events | 12 months |
| Support correspondence | 24 months |
| Encrypted backups | Up to 30 days, after which deleted data is gone from backups too |
These periods are implemented as automated jobs, not just written here. The written policy and the code are checked against each other before every release.
8. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, where we rely on consent;
- complain to the Information Commissioner’s Office.
Access, portability and erasure are built into the app: Settings → Privacy & Data → Export My Data, or Delete Account & Data. You can also request deletion from this website without the app. For anything else, contact [PRIVACY_EMAIL].
9. Automated processing
ROUTN generates your routine automatically from your answers and the products you own, and uses AI to describe what is visible in a photo. Neither produces a legal or similarly significant effect, and neither is treated as authoritative: every AI-suggested routine change is shown to you as a before-and-after that you approve or decline, and analysis results are descriptive rather than diagnostic.
10. Children
ROUTN is intended for people aged [MINIMUM_AGE] and over. We recognise that skincare and hair care appeal to teenagers, so we do not rely on a terms clause alone: ROUTN has no appearance scoring, no peer comparison and no public feed, analytics are off by default, and photo features are optional throughout. Our full age strategy and the corresponding assessment under the Children’s Code require professional review before launch.
11. Security
Data is encrypted in transit and at rest. Access to your records is enforced at the database level by row-level security, so one account cannot read another’s data even if application code were wrong. Photographs live in a private bucket behind ownership checks. Staff do not have routine access to user photographs. See our security overview.
12. Changes to this policy
Each version of this policy has a version identifier and an effective date, and your acceptance is recorded against the version you accepted. If we make a material change to how we use your data, we will ask again rather than quietly updating this page.
13. Contact
[PRIVACY_EMAIL] · [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]