Privacy Policy

Version privacy-policy@2026-09-21 · Effective 21 September 2026

Draft pending legal review. This policy describes what ROUTN actually does, but it has not yet been reviewed by a qualified data-protection practitioner and contains placeholders for company details. It must not be relied on as the final published policy.

1. Who is responsible for your data

ROUTN is operated by [LEGAL_ENTITY_NAME] (company number [COMPANY_NUMBER]), registered at [REGISTERED_ADDRESS]. We are the data controller for the personal data described here.

Privacy contact: [PRIVACY_EMAIL] ([DPO_OR_PRIVACY_CONTACT]).

2. What we collect

Categories of personal data ROUTN processes.
CategoryWhat it includes
AccountEmail address, authentication session, display name if you give one, age band, timezone, locale.
Skin profileYour own answers about how your skin behaves and what you notice, including whether it reacts easily and whether you shave.
Hair and scalp profileYour goals, scalp concerns you selected, which regions you track, and how often you wash your hair.
ProductsBrand, product name, category, notes, dates, and ingredient lists where available.
RoutineYour generated routine, its steps and versions, and which steps you completed or skipped on which day.
PhotographsSkin and hair progress photos you choose to keep; temporary photos used for a single analysis; product photos.
Analysis resultsThe structured description produced from a photo, plus which model and prompt version produced it.
CoachYour messages, the Coach’s replies, and a short list of routine-relevant preferences it remembers.
SubscriptionWhether you have an active entitlement, the store product identifier and period end. We never receive or store your card details.
Feedback boardIdeas you post and votes you cast, shown to other users without your name; when you posted; and, if a post is refused, the refused text and any resulting posting pause. Before an idea appears, its text (and nothing else about you) is checked by a word filter and then by our AI provider, which answers with a single category and keeps nothing. Only we can see which account posted what.
TechnicalDevice platform and app version, request identifiers, and error diagnostics with personal content stripped out.
SupportWhat you send us through the contact form, and our replies.
Email updates (website)If you ask this website to email you the app link: your email address, the time you asked and the wording you agreed to, and whether the email was sent. No account is needed or created.

We deliberately do not collect your full date of birth, home address, phone number, precise location, contacts, or microphone audio. The app blocks location and contacts permissions outright.

3. Why we process it, and on what basis

Purpose and lawful basis. The Article 9 analysis is flagged for legal review.
PurposeDataLawful basis (draft)
Create and run your accountAccountContract (Art. 6(1)(b))
Build and maintain your routineSkin/hair profile, products, routineContract (Art. 6(1)(b))
Analyse a photo you submit for a check-inPhotographs, analysis resultsConsent (Art. 6(1)(a)), plus explicit consent under Art. 9(2)(a) where the information is treated as health data. Requires legal review.
Keep progress photos in your timelinePhotographsConsent — asked separately from analysis and withdrawable
Answer your Coach questionsRoutine, products, check-in metadata, messagesContract, and consent for optional long-term memory
Send routine remindersAccount, routine, notification tokenConsent (device permission), withdrawable at any time
Manage subscriptionsSubscriptionContract
Keep the service secure and reliableTechnical, audit eventsLegitimate interests (Art. 6(1)(f)) — security and abuse prevention
Email you the app link and occasional updates from the websiteEmail address given on the websiteConsent (Art. 6(1)(a) and PECR), given by asking for the email; withdrawable with the one-tap link in every email
Product analyticsPseudonymous event counts: which screens are used and which features are tapped, and when the app is opened and closedConsent, off by default; asked once in the app and changeable in Settings

For legal review: self-reported skin and scalp information, and photographs analysed for visible characteristics, may constitute special-category data concerning health. The company must determine and document both the Article 6 basis and the Article 9 condition before launch. ROUTN’s design assumption is explicit consent, collected separately and never bundled into acceptance of the Terms.

3a. Email updates from the website

The website can email you the App Store and Google Play link, and — because you asked for it there — the occasional update about ROUTN afterwards, never more than a few a month. This is separate from having an account: we keep only the address you typed, when you asked, the wording you agreed to and whether the email went. Every email carries a one-tap unsubscribe link, which removes you from the list immediately; the entry is then deleted within 30 days. To limit abuse of the form we also keep a salted hash of the requesting connection’s address for 24 hours, from which the address itself cannot be recovered.

4. Photographs

There are exactly two kinds of photo in ROUTN, and you are told which one you are taking before the camera opens.

Photos are stored in a private bucket. They are never given a public URL and are served to you through signed links that expire in about two minutes. Images are resized and re-encoded on your device before upload, which removes EXIF metadata including any GPS coordinates.

To run an analysis, the image is sent to our AI provider. We do not use your photographs to train AI models, and we configure our provider for the minimum retention available. The specific provider, its retention setting and its data-processing terms are recorded in our processor register and must be confirmed before launch.

5. Who processes your data

Processors. This list must match reality — no aspirational vendors.
ProcessorPurposeData
SupabaseDatabase, authentication, file storage, server functionsAll account data and photographs
[AI_PROVIDER]Photo analysis and Coach responsesThe specific image or context sent for one request
PostHog (EU, Frankfurt)Product analytics, only with your consentEvent names from a fixed list, screen names, app open and close, a random id generated on your device. Never your account id, email, photographs, answers or anything you type. Location from your IP address is switched off.
RevenueCatSubscription entitlementPseudonymous user id, store transaction reference
Apple / GooglePayment, app distribution, push deliveryHandled under their own policies; we never see payment details
[HOSTING_PROVIDER]Website hostingServer logs

6. International transfers

Where a processor is outside the UK, we rely on UK adequacy regulations or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. The specific locations and safeguards for each processor above must be documented before launch. [TRANSFER_SAFEGUARDS]

7. How long we keep it

DataRetention
Temporary analysis photosDeleted after processing; hard limit one hour
Progress photosUntil you delete them or delete your account
Account, routine, products, check-insUntil you delete your account
Coach messages and memoryUntil you clear them or delete your account
Feedback board ideas and votesUntil you delete them or delete your account
Refused feedback posts and posting pauses400 days, then removed automatically
Consent records6 years after the account closes, as evidence of consent
Website email listUntil you unsubscribe, then removed within 30 days
Security and audit events12 months
Support correspondence24 months
Encrypted backupsUp to 30 days, after which deleted data is gone from backups too

These periods are implemented as automated jobs, not just written here. The written policy and the code are checked against each other before every release.

8. Your rights

Under UK data protection law you have the right to:

Access, portability and erasure are built into the app: Settings → Privacy & Data → Export My Data, or Delete Account & Data. You can also request deletion from this website without the app. For anything else, contact [PRIVACY_EMAIL].

9. Automated processing

ROUTN generates your routine automatically from your answers and the products you own, and uses AI to describe what is visible in a photo. Neither produces a legal or similarly significant effect, and neither is treated as authoritative: every AI-suggested routine change is shown to you as a before-and-after that you approve or decline, and analysis results are descriptive rather than diagnostic.

10. Children

ROUTN is intended for people aged [MINIMUM_AGE] and over. We recognise that skincare and hair care appeal to teenagers, so we do not rely on a terms clause alone: ROUTN has no appearance scoring, no peer comparison and no public feed, analytics are off by default, and photo features are optional throughout. Our full age strategy and the corresponding assessment under the Children’s Code require professional review before launch.

11. Security

Data is encrypted in transit and at rest. Access to your records is enforced at the database level by row-level security, so one account cannot read another’s data even if application code were wrong. Photographs live in a private bucket behind ownership checks. Staff do not have routine access to user photographs. See our security overview.

12. Changes to this policy

Each version of this policy has a version identifier and an effective date, and your acceptance is recorded against the version you accepted. If we make a material change to how we use your data, we will ask again rather than quietly updating this page.

13. Contact

[PRIVACY_EMAIL] · [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]