MogTier

Privacy Policy

Version 2.1.0

Before this goes live: This document is a structurally complete draft written to reflect how the application actually works as of this version, not verified or reviewed by a lawyer. Replace every [bracketed placeholder] below with your actual legal entity details, and have this reviewed by qualified legal counsel — including for compliance in every jurisdiction you operate in — before relying on it for a real launch. See also docs/legal/CHANGELOG.md. Two items are flagged inline as still needing work before commercial launch: the transfer mechanism for the two US providers (Section 8.1) and a defined retention period for analysis results (Section 3). Section 7 describes the guardian-consent method actually implemented and states exactly what it does and does not establish; whether it is sufficient for special category data in each market is a question for counsel.

1. Who this policy covers

This Privacy Policy explains how MogTier (“the App,” “we,” “us”) collects, uses, stores, and deletes your information when you use the App. “MogTier” is operated by [Company/Operator Legal Name] (“the Operator”). If you have questions about this policy, contact us at mindurrmail@gmail.com.

The App is an educational and informational tool that analyzes user-submitted facial photos using computer vision and machine learning. It is not a medical device, not a diagnostic tool, and does not provide medical advice. See the Terms of Service for the full description of what the App does and does not do.

2. What we collect

2.1 Photos you upload

When you use the facial analysis feature, you upload:

  • One front-facing photo of your face.
  • One side-profile photo of your face.

These photos are processed to detect and align your face, assess image quality, and generate the analysis results described in the Terms of Service (attractiveness estimate, category scores, recommendations, and an AI-generated visualization).

Photos that fail our automated quality check (too blurry, too dark, too bright, appears heavily filtered/edited, or no face clearly detected) are never stored — they exist only in memory for the duration of that one upload request and are discarded immediately if rejected.

2.2 Derived biometric data — what this consent specifically covers

To perform the analysis, the App scans your face: it computes facial landmark positions (the approximate pixel location of features like your eyes, brows, nose, and jaw line) from your photos, then measures that geometry against the App’s reference dataset to generate an AI-estimated attractiveness score (on a 1–10 scale), category-level breakdowns, and recommendations. Depending on your jurisdiction, this kind of derived facial-geometry data may be legally classified as biometric data or special-category personal data, which can carry additional legal protections beyond ordinary personal data — for example, some laws require a specific disclosure of what is collected, the specific purpose, and the retention period, before collection, separate from general contract terms.

A separate checkbox, before you ever open the camera, is what grants this consent. It is not bundled into the Terms of Service, and it is not a “Get started” button. On the screen shown during sign-up you are told, in plain text above the box and not behind a link:

  • that your photos are used to measure facial geometry, which counts as biometric data;
  • that each scan sends your front-facing photo to a third-party AI service;
  • that the App does not diagnose medical conditions.

You then tick “I consent to my photos being analyzed as described above.” Registration is refused without it — the server checks, not just the app. What you are agreeing to is that your face is scanned to compute the geometry described above, that an AI model uses it to produce an attractiveness estimate and related feedback, that this estimate is informational and for self-improvement purposes only — not a medical, professional, or objective judgment (see the Terms of Service, Section 2), and that the photo itself is deleted within the short window described in Section 3.

You can withdraw this consent at any time without deleting your account. Settings has a “Stop analyzing my photos” option. It deletes every photo, every crop sent to the AI provider, every generated image and every analysis result derived from them, and stops scanning — while leaving your account, your purchase history and any unspent tokens untouched. You can turn analysis back on afterwards. Withdrawal does not affect the lawfulness of processing carried out before it.

The AI visualization is generated as part of every scan. This feature reuses your front-facing photo to produce an AI-illustrated depiction of possible changes to modifiable characteristics only (skin, grooming, lighting), never your underlying facial structure. Producing it requires sending your front-facing photo to a third-party AI provider (see Section 8). This runs automatically as part of the scan you start, so the consent you give when you begin a scan covers this use as well; there is no separate opt-in step for it. If you do not want your photo sent to that provider, do not start a scan.

This is a change from an earlier version of the App, in which the visualization was an optional extra step that you triggered yourself and consented to separately at that moment. Because it now always runs, the disclosure has been moved up-front rather than presented at the point of generation. Bundling this into the general scan consent is a simplification of the same kind flagged above, and is on the list to revisit before a broader or commercial launch.

Landmark data computed during analysis is used only in-memory to produce your results; it is not separately stored as a standalone dataset outside of the score/analysis records described in Section 2.3.

2.3 Analysis results and account data

We also store:

  • Account information: your email address, a securely hashed password (we never store your password in plain text), and your selected age band (13–17 or 18+).
  • Consent records: what you agreed to and when, which version of each document you accepted, and whether you later withdrew it (Terms of Service, Privacy Policy, biometric-data processing).
  • Technical data: your IP address, used to rate-limit sign-in and registration attempts so the App cannot be brute-forced or mass- registered. It is held in the server’s memory for the length of the rate-limiting window and is not written to our database. Our hosting provider also keeps ordinary access logs, which contain IP addresses, for its own operational purposes.
  • Parental/guardian consent record (13–17 accounts only): the guardian’s own email address, the exact wording they agreed to, and the times at which the request was sent, confirmed from their inbox, and withdrawn (if it was) — see Section 7. Kept separately from your own account and scan data, not mixed into your regular consent records.
  • Analysis results: your computed scores (overall and per-category), the internal feature values that fed into them, and any generated recommendations. These are not the photos themselves — see Section 3 for how long the photos are kept.
  • AI visualization results, including the generated image and a record of what modifications were requested of the visualization provider.
  • 90-day program data (only if you start the subscriber program): the improvement-priority roadmap derived from your scan results, which program quests you mark as done and on which dates, the achievements you earn, and score snapshots from the rescans you log for month-to-month comparison. This is habit-tracking data only: it contains no photos and no free text, it stays on our servers with your account so your streak survives reinstalling the App, and it is deleted along with everything else when you delete your data (Section 5). Optional “progress photo” quests never upload anything; any photo you take for one stays on your device.

2.4 What we do not collect

Your photos and derived biometric data are processed only for the requested analysis — we do not use them for any other purpose. We do not sell your photos or analysis results to third parties. We do not use your photos to train machine learning models without your separate, explicit consent (see Section 6).

2.5 Our legal basis for each of these

Under the GDPR every use of your data needs a legal basis. Ours:

What we do Legal basis
Create and run your account; take payment; provide the features you bought Contract (Art. 6(1)(b)) — we cannot give you an account without this
Scan your face, compute facial geometry, produce scores and recommendations, generate the AI visualization Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — the separate checkbox in Section 2.2, withdrawable at any time
Keep consent records showing what you agreed to and when Legal obligation (Art. 6(1)©) — we have to be able to demonstrate consent under Art. 7(1)
Rate-limit sign-in and registration using your IP address Legitimate interests (Art. 6(1)(f)) — keeping accounts from being brute-forced, which is in your interest too
Keep records of purchases Legal obligation (Art. 6(1)©) — accounting and tax law
Email a parent or guardian and record their answer, for a 13–17 account Legal obligation — we must be able to demonstrate that consent was given (Arts. 6(1)©, 7(1), 8)

The facial processing rests on consent and nothing else. If you withdraw it, that processing stops and its results are deleted — see Section 2.2.

3. How long we keep your photos

Every uploaded photo is deleted automatically within a short, fixed window of capture — currently 2 minutes (see photo_ttl_minutes in services/api/app/core/config.py) — regardless of any preference you select. This is not user-configurable: there is no option to keep photos longer. In that window you can view your result and optionally download the photo alongside your score; after it elapses, the photo is permanently deleted. This is enforced three ways, not just one: the link used to view/download a photo stops working after the window; the photo is deleted the next time anything happens to touch it past that point; and an independent, regularly-run cleanup process deletes anything left over as a backstop, so a photo isn’t relying on you (or us) remembering to come back and look at it.

Your analysis results (scores, category breakdowns, the facial measurements behind them, and recommendations) are retained separately from the photos themselves and are not deleted on this same short schedule. They are kept for as long as your account exists, so that you can compare scans over time, and are deleted when you delete your account, or immediately if you withdraw consent to the facial analysis (Section 2.2).

[Before launch: agree and implement a maximum retention period for analysis results — an inactivity-based rule is the usual approach — and state it here. “Until you delete it” is a description of a mechanism, not a retention period, and GDPR Art. 5(1)(e) and Art. 13(2)(a) expect a period or the criteria used to set one.]

4. Where your data is stored and how it’s protected

  • Your data is stored in the European Union. Our database and our photo storage are both hosted on Supabase, in the AWS eu-west-1 region (Ireland). The application server itself runs on Fly.io in London.
  • Data in transit between your device and our servers is encrypted (HTTPS/TLS), and the connection between our server and the database is encrypted as well.
  • Photos are encrypted by us before they are stored, using a key held only by our application and not by the storage provider. What sits in storage is unreadable ciphertext; the provider cannot see your face. This is deliberate: the provider encrypts data at rest with keys it holds itself, and for photographs of people’s faces we did not think that was enough on its own.
  • The storage bucket is private. It is not publicly browsable, and the link used to view or download a photo is a short-expiry signed link, not a permanent public URL.
  • Access to stored photos and analysis data is restricted to what our systems need to perform the requested analysis; we do not have a customer-support workflow that involves staff viewing your uploaded photos as a matter of course.
  • Photos are captured with the device’s camera only — there is no option to upload an existing photo from your device’s gallery for this feature.
  • The visualization feature is the one exception to our 2-minute window, and we state it plainly rather than bury it. Generating your “potential” image requires sending your front-facing photo to a third-party AI provider (see Section 8), which is outside the EU. That provider keeps a copy of the photo, the generated image and the request log for up to one hour after the request, then deletes them automatically. We cannot shorten that hour: the provider offers no account setting to disable retention and no way for us to delete a request early. Our own copies are still deleted on the 2-minute schedule described above.

5. Your rights and choices

You can, at any time, from inside the App:

  • View your account information and past analysis results.
  • Download everything we hold about you. Settings offers a data export that returns your account details, your consent history, every scan and its results (including the facial measurements behind the scores), and your purchase history, as a machine-readable JSON file. Your password and session credentials are deliberately excluded — they are not information about you in any useful sense, and putting them in a file you are invited to forward would be a way to leak them.
  • Stop the facial analysis without deleting your account, using “Stop analyzing my photos” in Settings. See Section 2.2.
  • Delete your data. “Delete my data” in Settings permanently deletes your account, any remaining stored photos, your analysis results, your recommendations and your program data. This cannot be undone, and it forfeits any unspent tokens.

You can also contact us at mindurrmail@gmail.com with any request about your data, including correcting information that is wrong.

5.1 Your rights under the GDPR

If you are in the European Economic Area or the UK you have the rights below. We answer requests within one month.

Right How to use it
Access (Art. 15) The data export in Settings, or ask us.
Rectification (Art. 16) Contact us — some fields cannot yet be edited in the App.
Erasure (Art. 17) “Delete my data” in Settings, or ask us.
Restriction (Art. 18) Contact us. “Stop analyzing my photos” achieves this for the facial processing.
Portability (Art. 20) The data export, which is JSON.
Object (Art. 21) Contact us, for anything we do on the basis of legitimate interests.
Withdraw consent (Art. 7(3)) “Stop analyzing my photos” in Settings, at any time.

You also have the right to complain to a supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, imy.se. If you live in another EEA country you may complain to your own national authority instead.

We do not make decisions about you that produce legal effects or similarly significantly affect you within the meaning of Article 22. The App profiles your facial geometry to produce a score and recommendations, and that profiling is explained in Section 2.2 and in the Terms of Service, Section 2 — but nothing in the App decides anything about your access to services, employment, credit, or any comparable matter.

If you are a California resident, you may have additional rights under the CCPA/CPRA. [This section requires legal review before the App is offered in the United States.]

6. AI model training

We do not use your photos to train or fine-tune our machine learning models without asking for your separate, explicit, opt-in consent first. If we ever want to use anonymized or de-identified data for model improvement, we will ask for that consent specifically — it is not implied by your use of the analysis feature itself.

7. Age requirements and minors

The App requires users to be at least 13 years old, with no exception — there is no parental-consent path for accounts under 13.

Users between 13 and 17 can create an account, but scanning stays locked until a parent or legal guardian confirms it from their own email inbox. The account holder cannot complete this step themselves, on their own device or any other. In outline:

  1. The account holder enters a parent’s or guardian’s email address in the App. This address must be different from the account’s own. Nothing is unlocked at this point.
  2. We email that address a one-time link, valid for 7 days. The email says which account it concerns, states that face analysis involves special category data, and says plainly that ignoring it refuses permission.
  3. The link opens a web page — no app, no account and no sign-in needed — that sets out what the App collects, what happens to it, who else receives it, how long it is kept, and how to undo the decision, before asking for a decision. Consent is recorded only when the guardian submits that page. Simply opening the link records nothing, so that automated mail scanners cannot consent on a guardian’s behalf.
  4. We then email the guardian a confirmation stating that a permission now exists in their name, containing a link that withdraws it at any time, again with no app and no sign-in. Withdrawal takes effect immediately: it re-locks scanning and deletes the photographs, measurements and results the analysis produced.

We store, for each such account: the guardian’s email address, the exact wording they agreed to, the time the request was made, the time they confirmed, and the time of any withdrawal. This record is kept separately from the account holder’s own data — see Section 2.3 — and is included in the account holder’s data export. Our lawful basis for holding the guardian’s address is Article 6(1)©: we are required to be able to demonstrate that consent was given (Article 7(1)).

We limit how often we will email a guardian’s address, so that repeated requests from the App cannot be used to send unwanted mail to somebody who is not our user.

What this does and does not establish — stated plainly. Requiring an answer from a separate mailbox means the account holder cannot grant this by themselves, and it puts the disclosures above in front of an adult who can refuse and who can later revoke. It does not verify anybody’s identity or age. A determined account holder with access to a second email address can defeat it. Verifying that the person answering is genuinely an adult and genuinely the account holder’s guardian would require something like an identity document check or a payment-card verification, which the App does not do.

LAWYER REVIEW REQUIRED. Whether this method meets the “reasonable efforts” standard in Article 8(2) GDPR for special category biometric data, and whether it meets the separate United States requirements for verifiable parental consent under COPPA, are questions for qualified counsel in each jurisdiction where the App is offered. Note also that the age at which a young person can consent for themselves varies across the EEA — Sweden sets it at 13, other member states set it as high as 16 — and that Article 8 governs information society services generally, while the consent required for biometric data under Article 9(2)(a) is a separate requirement that Article 8 does not displace. If a stronger verification method is required in a market, it must be implemented before the App is offered there.

8. Who else processes your data

We use the following providers. Each of them processes data only on our instructions, under a written data processing agreement.

Provider What it does What it receives Where
Supabase Database and photo storage Everything in Section 2.3, plus your encrypted photos (which it cannot read — see Section 4) EU (AWS eu-west-1, Ireland)
Fly.io Runs the application server All data in transit through the App, plus access logs containing IP addresses UK (London)
Replicate Generates the AI visualization Your front-facing photo and a text instruction — nothing else United States
RevenueCat Verifies purchases and tracks subscription status Your account identifier and your purchase history United States
Apple / Google Take the payment Your payment details, which go to them and never to us Their own global infrastructure

Notes on two of these:

Replicate. The AI visualization is the only feature that sends your photograph outside our own systems. Replicate hosts and runs the image model; the model’s original developer is a separate party from Replicate. Replicate deletes the photo, the generated image and the request log automatically one hour after the request — its published default for requests made the way we make them, and the shortest retention it offers. We do not send your name, email, account identifier or scores with it. You should review Replicate’s own privacy policy at replicate.com/privacy.

Apple and Google are not our processors for payment data. They are independent controllers of it, they hold your card details, and we never see them.

8.1 Transfers outside the EEA

Replicate and RevenueCat are in the United States, so using the App involves transferring some personal data outside the EEA — your front-facing photo in the first case, and your account identifier and purchase history in the second.

[Before launch: record here the transfer mechanism relied on for each of these — EU–US Data Privacy Framework certification, or Standard Contractual Clauses — and complete a transfer impact assessment for the Replicate flow specifically, since a facial photograph is the most sensitive thing the App transfers. Include how a user can obtain a copy of the safeguards. This paragraph must be replaced with the actual mechanism before the App is offered to users in the EEA.]

All other processing happens in the EEA or the UK.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected in a new version number here and in docs/legal/CHANGELOG.md, and your continued use of the App after a material change constitutes acceptance of the updated policy. Your ConsentRecord stores the version you most recently accepted.

10. Contact

Questions about this policy or your data: mindurrmail@gmail.com.