Privacy Policy
Last updated: April 18, 2026
1. Data controller
HairMaxxing — contact: contact@hairmaxxing.com.
2. Data collected
- Account: email, name, profile picture (if using Google/Apple sign-in).
- Profile: gender, age, hair goal, hair type and density, satisfaction level.
- Photos: 3 face photos (front, profile, top) submitted to generate visualizations.
- Subscription: status (free / premium), App Store or Google Play receipt.
3. Purposes
- Generate the requested hairstyle visualizations.
- Personalize recommendations based on your face shape.
- Manage your account and subscription.
- Improve service quality (aggregated, anonymized data).
4. Legal basis
Performance of the contract (Terms), consent for sensitive data (photos), legitimate interest for usage statistics.
5. Recipients
- Google Gemini and OpenAI — visualization generation and analysis. Photos are sent encrypted and are not retained by these providers beyond processing.
- Cloudflare R2 — secure storage of generated results (S3-compatible, EU/US hosting).
- Apple App Store / Google Play — in-app purchase validation.
6. Retention period
- Account: as long as the account is active.
- Submitted photos: deleted within 30 days.
- Generated visualizations: kept as long as the account is active.
- Billing data: 10 years (legal obligation).
7. Your rights (GDPR)
Under GDPR, you have the right to access, rectify, erase, port, and object. You can:
- Export your data directly from the App (Settings → Export my data).
- Delete your account directly from the App (Settings → Delete account). This action is irreversible.
- Contact us at contact@hairmaxxing.com for any other request.
8. Security
Data is encrypted in transit (TLS) and at rest. Passwords are hashed (bcrypt). JWT tokens have a short lifespan (15 minutes, secure refresh).
9. Cookies
The hairmaxxing.com website does not use advertising cookies or third-party trackers. Only essential technical cookies are used.
10. DPO contact / Complaints
For any question related to your data: contact@hairmaxxing.com. You may also file a complaint with the CNIL (cnil.fr).