Skip to content
Connie's Skin
Home Support Terms Privacy question

Privacy Policy

Clear choices for personal skincare data.

This policy explains what Connie's Skin collects, why it is used, which service providers process it, and how you can access, export, or delete it.

Effective September 20, 2026 · Last updated September 20, 2026

Connie's Skin onboarding explaining the optional cosmetic skin scan
⌾

The short version

  • We do not sell your personal information.
  • We do not run third-party advertising.
  • You choose which photos to share with the app.
  • The optional UV feature uses a place you type, not your device's precise-location permission.
  • You can export data or delete your account.

On this page

1. Scope 2. Information we collect 3. How we use information 4. Photos and AI scan 5. Service providers 6. Sharing and selling 7. Retention and deletion 8. Your choices and rights 9. Security 10. Age eligibility 11. International processing 12. Changes 13. Contact

Full Privacy Policy

1. Scope and who we are

Connie's Skin is a skincare routine companion operated by Charles Gao (“Connie's Skin,” “we,” “us,” or “our”). This policy applies to the Connie's Skin mobile application, this website, and related support and checkout services.

The app provides educational cosmetic routine organization and ingredient guidance. It does not provide medical diagnosis or treatment.

2. Information we collect

We collect information you provide, information created as you use app features, and limited technical information required to deliver the service.

Account and contact information

  • Email address and optional display name.
  • Email address if you join the beta waitlist on our website.
  • Authentication records. Passwords are handled by Supabase Auth and are not visible to us in plain text.
  • Messages and contact information you send when requesting support.

Skin profile, routine, and progress information

  • Skin type, concerns, sensitivity, budget, routine-size preference, onboarding selections, and product recommendations. Optional answers can include pregnancy, breastfeeding or trying to conceive, ingredient avoidance, and other skin-related information.
  • Products, brands, ingredient tags, purchase links, user-entered product-opened dates and period-after-opening (PAO) month values, routines, ordered steps, weekly schedules, reminder preferences, and completion history.
  • An account identifier, including an anonymous identifier when you choose a guest scan, and the scan eligibility and consent information needed to provide that feature.

Diary information

  • The calendar date for each diary entry and the entry's created and updated times.
  • A free-text note of up to 1,000 characters if you write one.
  • Any optional context tags you select: new product, travel, late night, period, stress, or weather.

Diary notes are synchronized to your account so they can appear on your supported devices. Because a free-text field can contain whatever you choose to write, please do not include information you do not want stored with your account.

Optional city and UV information

If the UV feature is enabled in your version of the app and you choose to use it, the app asks you to type a city or place. It does not request your device's precise-location permission for this feature. The text you enter is sent to Open-Meteo's geocoding service to return possible matches.

After you select a match, the place name and its latitude and longitude are saved under your account identifier on that device. Before requesting a UV forecast, the app rounds the coordinates to one decimal place (a roughly 11-kilometre north-to-south grid; east-to-west spacing varies by latitude) and sends those rounded coordinates to Open-Meteo. Open-Meteo also receives technical request information such as your IP address. Your selected place, coordinates, and UV cache are not synchronized to the Connie's Skin database.

Device-local PAO notice choices

If you dismiss a product-open-period notice, the app stores a device-local record containing the product identifier, the opened date, and the label's PAO month value. This record is kept under your account identifier on that device and is not synchronized to the Connie's Skin database.

Photos and scan results

  • Product photos you explicitly choose to upload.
  • If you use the optional AI skin scan, a face photo you capture or select for that scan request.
  • AI scan output such as overall and category scores, advice, model identifier, and scan date.

Purchase and order information

  • When checkout is available and you use it: selected products, quantities, totals, discounts, order status, shipping/contact details, and checkout and order identifiers. Shopify provides the checkout for new Shopify orders; earlier Stripe transaction identifiers may remain where needed for historical order support.
  • Shopify and the payment provider shown in checkout process payment information. If you choose a supported wallet, its provider processes the credentials needed to authorize payment. Connie's Skin does not receive or store your full card number. Checkout providers may also process cookies, device and network information for checkout operation, security and fraud prevention.

Technical information

Our hosting, authentication, database, Edge Function, and payment providers may process IP address, request timing, device/browser details, and security or diagnostic logs as needed to operate and protect their services. Connie's Skin does not currently include a third-party advertising or behavioral analytics SDK.

3. How we use information

  • Provide accounts, synchronize app data, and restore your routine across supported devices.
  • Build personalized product and routine suggestions from quiz answers.
  • Evaluate the routine rules you configure and show ingredient cautions.
  • Track completion, adherence, milestones, diary entries, and scan history.
  • Process product images and optional AI skin scans.
  • Create, fulfill, and support routine-kit orders.
  • Schedule reminders you enable on your device.
  • If the optional UV feature is enabled and you use it, find the city you type, retrieve that place's UV forecast, and decide whether an enabled SPF reminder qualifies for that day's forecast.
  • Use your product-opened dates, PAO month values, and local dismissal choices to show or suppress product-open-period notices.
  • Protect the service, prevent abuse, troubleshoot failures, and respond to support requests.
  • Comply with legal obligations and enforce our terms.

We do not use routine, scan, or account data to build an advertising profile.

4. Product photos and the optional AI skin scan

Your scan photo is sent for analysis; a prepared copy can remain on your device.

After your consent, the app sends a prepared face image, reduced in size when needed, for the requested analysis. We do not save that image in Connie's Skin cloud storage. After a successful scan, the app can keep that prepared image in its local cache for visual comparisons. This photo does not sync between devices and is excluded from the app's iCloud backup. It can disappear when you log out, delete or reset scan data, uninstall the app, or the operating system clears the cache. Scan results, including scores, controlled cosmetic explanations, model identifier and date, are stored with your account separately from the photo.

The app asks for your explicit permission for each scan before sending an image through Supabase to Google's Gemini API. You can decline and continue without a scan. Google's published abuse-monitoring policy provides for 55 days of retention of prompts, contextual information and outputs; authorized Google personnel may review flagged content. We do not represent this processing as zero retention. Deleting your Connie's Skin account does not immediately erase provider records retained under those separate policies. Read the Gemini API Terms and Google's abuse-monitoring policy before deciding whether to share a photo.

Product photos are different: when you choose to attach one to a product, it is stored in your account's Supabase Storage area so the app can display it later. You can replace or remove it in the app, and account deletion is designed to remove user-owned storage objects.

The scan is cosmetic and educational. Scores are estimates from a model and may be inaccurate. They are not a diagnosis, medical record, or treatment recommendation.

5. Service providers

We use service providers to operate specific parts of Connie's Skin:

Supabase

Authentication, database, file storage, and server-side Edge Functions.

Supabase Privacy Policy

Google Gemini API

Optional processing of face photos for the AI skin-scan request.

Gemini API Terms

Shopify

Checkout, payment and order processing, fulfillment information, and checkout security when Shopify purchasing is available and you use it.

Shopify Privacy Policy

Resend

Delivery of requested account confirmation, recovery and other authentication emails through our Supabase email configuration.

Resend Privacy Policy

Stripe

Processing and support of earlier Stripe payments, where applicable, including payment records and fraud prevention. New Shopify checkout uses the payment providers displayed there.

Stripe Privacy Policy

Apple Pay or Google Pay

If you select a supported device wallet, its provider processes the wallet credentials needed to authorize your payment.

Apple Pay & Privacy · Google Payments Privacy Notice

GitHub Pages

Hosting this public website and its legal/support pages.

GitHub Privacy Statement

Formspree

Processing beta-waitlist form submissions and delivering signup notifications.

Formspree Privacy Policy

Open-Meteo

City search and UV forecast data only if the optional UV feature is enabled and you use it. Your typed search or rounded coordinates are sent from your device.

Open-Meteo Terms & Privacy · Data Licence

These providers process information under their own terms and as needed to provide services to us. We expect service providers with access to personal information to protect it appropriately.

UV and location data are provided by Open-Meteo.com under the CC BY 4.0 data licence. Connie's Skin formats forecast values for display and adds UV exposure-category labels; Open-Meteo does not endorse Connie's Skin.

6. When we share information

We share information only as described in this policy:

  • With the service providers above to deliver the features you request.
  • When you direct us to share or export information.
  • To comply with law, legal process, or a valid government request.
  • To protect users, the public, our rights, or the security of the service.
  • As part of a business transaction, subject to appropriate notice and protection.

We do not sell personal information or share it for cross-context behavioral advertising.

7. Data retention and deletion

Account, routine, product, quiz, progress, diary, and scan-result data is generally kept while your account is active so the app can provide history and synchronization.

A diary entry remains until you clear that entry, choose Reset skin progress and confirm Reset current data, or delete your account. Product-opened dates and PAO month values remain with the related product until you clear the fields, delete the product, complete that reset flow, or delete your account.

Your selected UV place and coordinates, the most recently saved UV cache entry, and PAO-notice dismissal records stay on the device where they were created. A cached UV result is used only when its date and place match the current request and is replaced by a later successful forecast. The Reset current data and account-deletion flows are designed to clear these records for that account from the device. If device storage refuses that cleanup, the app warns you to retry the reset or clear Connie's Skin app data in device settings; after account deletion, it may instead direct you to clear app data or uninstall the app before another person uses the device.

Open-Meteo controls the API request logs it receives. Its current privacy terms state that individual API log files, which may include IP addresses or geographic coordinates, are removed after 90 days. See Open-Meteo Terms & Privacy for its current practices.

You can start account deletion from Settings → Account & data → Delete account. For a guest identity, the action may be labeled Delete guest data. When deletion completes successfully, this removes the authentication account, active user-owned skincare records and product-photo storage, and attempts to clear the account's local data and scan photos. If local cleanup fails, follow the app's retry or device-cleanup instructions. Contact us if you cannot access the app.

A guest scan creates an anonymous account. It does not have an email/password until you complete account setup. Logging out or losing the guest session does not itself delete cloud records and can make that identity impossible to recover. Save the account before leaving it if you want to keep access, or use the explicit deletion action while you still have the session.

Some information may remain for a limited period in encrypted backups, security logs, fraud-prevention records, or records we must retain for legal, tax, accounting, dispute, or payment obligations. Shopify, Stripe where applicable, and payment providers independently retain transaction information under their policies and legal obligations. Account deletion does not cancel an already placed order or automatically erase records required for refunds, fulfillment, tax or disputes. We may retain information that has been irreversibly de-identified.

Deleting the cloud account does not automatically erase a data export you previously saved or information remaining in your device's operating-system backups. You control those copies.

8. Your choices and privacy rights

  • Photos: choose whether to grant camera/photo access and which image to select. Revoke OS permissions in device Settings.
  • Notifications: enable or disable reminders in the app and in device Settings.
  • Optional UV feature: choose whether to search for and save a place. You can replace or remove the selected place in the app; Connie's Skin does not request precise-location permission for this feature.
  • Export: create a readable JSON copy from Settings and send or save it with your device's system share sheet. The export includes the locally cached app data used for your profile, quiz, products (including opened dates and PAO values), routines, schedule, completion history, recommendations, diary notes and tags, and appearance choice; legacy on-device reminder values may also appear in that cache. It does not include the separate current account-wide notification-preferences record, UV place/cache, PAO-notice dismissal records, original photos, scan history, or full payment-card number. The destination you choose controls the exported copy, so store and share it carefully.
  • Correction: edit products, routines, diary entries, profile choices, and other app information.
  • Reset: choose Reset skin progress and confirm Reset current data without closing your account. This clears resettable cloud data, including diary entries, and attempts to clear the account's local UV and PAO-notice state from that device. Changes that an older or offline signed-in device has not yet sent may be added again after a reset; use Delete Account when you want the account and its skincare data erased instead of reset. If device cleanup fails, the app tells you how to retry or clear its local data.
  • Deletion: delete individual diary entries, product photos/items, or start full account deletion.
  • Support requests: contact us to request access, correction, deletion, restriction, or portability where applicable.

Rights vary by location. We may need to verify your identity before fulfilling a request. You may also have the right to appeal or complain to a local data-protection authority.

9. Security

We use technical and organizational safeguards appropriate to the service, including authenticated access, database and storage access controls, encrypted network transport, per-user data scoping, and restricted server credentials. No internet service can guarantee absolute security.

Protect your device and account credentials, and contact us if you believe your account has been compromised.

10. Age eligibility

Connie's Skin is intended for adults aged 18 and older. People under 18 must not use the service or submit photos or other personal information. Each AI scan also requires an adult-age affirmation. If you believe a person under 18 has provided personal information, contact support so we can investigate and remove it as appropriate.

11. International processing

Our service providers may process information in the United States and other countries. Those locations may have privacy laws different from your home country. Where required, providers and we rely on recognized safeguards for international transfers.

12. Changes to this policy

We may update this policy as Connie's Skin changes. We will post the new date here and provide additional notice in the app when a change is material. Continued use after the effective date is subject to the updated policy.

13. Contact

Questions, requests, or concerns can be sent to:

Connie's Skin — Privacy support@connieskin.com We aim to respond to privacy requests within 30 days.
Legal review recommended.

This policy is intended to describe the current product implementation in plain language. Before a public store launch or expansion to additional jurisdictions, have qualified counsel review the policy, terms, consent flow, data-processing agreements, and App Store/Google Play disclosures.

© 2026 Connie's Skin.

HomeSupportTerms