Privacy Policy
Cosmetry ("we," "our," or "the App") is operated by Mustafa Batin Efe. This Privacy Policy explains how we collect, use, and protect your information when you use our iOS application.
Cosmetry helps you manage your skincare product inventory, track allergens and skin reactions, build skincare routines, and get AI-powered skincare tips. Your privacy is fundamental to how we build and operate the App.
1. Data We Collect
Account Information
We use Apple-signed App Store transaction data for account creation and restoration and Apple's App Attest framework for request integrity. We collect:
- App Transaction ID — An Apple-signed identifier associated with the App Store acquisition of Cosmetry. It is not your Apple ID, email address, hardware serial number, or advertising identifier
- App Attest data — Public keys, attestation receipts, assertion counters, and short-lived challenges used to verify genuine app requests and prevent replay and fraud. The corresponding private key remains under Apple's system management on your device
- Security rate-limit data — Short-lived HMAC-based rate keys and limited pseudonymous security events used to prevent automated abuse; raw network addresses and raw App Attest keys are not stored in the challenge table
- One-time Apple device-verification value — Used during registration to bind the signed App Store transaction to the request; it is not used for advertising or cross-app tracking
- Support ID — A generated identifier for customer support purposes
We do not collect your name, email address, or Apple ID credentials directly.
Profile Data
Display name (optional), skin type, skin concerns, and notification preferences.
Product Inventory
Product names, brands, categories, ingredient lists, purchase/open/expiration dates, PAO values, and product status.
Allergen Data
Your personal allergen avoid list and allergen source information.
Skin Reaction Logs
Reaction date, severity, symptoms, body location, notes, and reaction photos (stored locally on device only).
Routine Data
Routine names, time of day, product order, usage logs, streaks, and reminder preferences.
AI Chat Conversations
Chat messages, AI responses, conversation history, titles, and message feedback.
Photos
Product, reaction, and profile photo libraries are stored locally on your device. Selected product photos and an optional Skin Scan selfie pass through a Cosmetry serverless function to Google Gemini only after you grant the relevant permission. Cosmetry does not persist uploaded image files in its Supabase database or object storage, but Google's processing and limited retention remain governed by the applicable Gemini API terms.
Purchase, Subscription & Usage Data
Credit balance, transaction history, subscription/premium status, and daily counts of your AI feature usage (used to enforce fair-use limits). Subscriptions are managed by Adapty; purchase receipts are processed by Apple and Adapty.
- Active subscribers use eligible AI features without per-request credit deductions, subject to the fair-use controls disclosed in the App
- Credit pack credits do not expire as long as your account is active
- Welcome, trial, or subscription-included credit amounts are those disclosed in the App or Apple's purchase sheet for the applicable offer
- We record how many AI actions you make per day only to enforce fair-use limits — never for advertising
Skin Scan (optional)
If you choose to use the optional AI Skin Scan, we take one photo of your face and send it to Google's Gemini AI to estimate cosmetic skin attributes (skin type, visible concerns, tone) to help personalize your profile.
- The photo is processed in real time and is not stored on our servers
- We keep only the derived results that you review and choose to apply to your profile (for example, "combination skin"), not the image file
- The scan is optional — you can skip it and answer a few questions instead
- Results are a cosmetic estimate for personalization only — not a medical diagnosis, and should not be used to detect or treat any condition
- We record a per-day count of scans solely to prevent abuse (fair-use), never for advertising
Legacy iCloud Migration
Versions before 1.0.2 may have placed your custom allergen list, App Transaction ID, or an internal Supabase account UUID in Apple's iCloud Key-Value Store. Version 1.0.2 no longer uses iCloud as an account or identity source. It removes those legacy identity values and, where a legacy custom-allergen value is available, merges it into storage on the current device and deletes the iCloud copy. Custom allergens are device-local after that migration and do not receive Cosmetry cloud backup or cross-device synchronization.
2. How We Use Your Data
- Core Functionality — Managing your product inventory, tracking allergens, logging reactions, and building routines
- AI-Powered Analysis — Providing personalized skincare tips, ingredient analysis, and product extraction via Google Gemini API
- Allergen Detection — Automatically flagging products that contain ingredients on your avoid list
- Expiry Tracking — Sending push notifications when products are approaching or past expiration
- Credit & Subscription Management — Processing purchases and managing your credit balance
- Fair-Use Enforcement — Recording daily counts of your AI feature usage to enforce fair-use limits and prevent abuse (never used for advertising)
- Customer Support — Using your Support ID to assist with issues
3. Third-Party Services
Google Gemini API
After you grant the relevant in-app permission and invoke an AI feature, Cosmetry sends the data needed for that request to Google's Gemini API. Depending on the feature, this can include your product and ingredient data, allergen list, reaction history, routine and profile context, chat message and recent conversation context, selected product photos, or one optional Skin Scan selfie. Cosmetry does not persist submitted image files; Google processes and may retain API inputs, outputs, and limited logs under the Google Gemini API Terms.
Supabase
Backend infrastructure for database storage, authentication, and serverless functions. All data is secured with row-level security policies. See Supabase Privacy Policy.
Adapty
Manages subscriptions and in-app purchases. We identify the related Adapty customer profile using the App Transaction ID. Adapty processes that identifier, purchase receipts, subscription status, and purchase analytics; we do not send it your optional display name, inventory, photos, allergen list, reaction history, or AI chat content. See Adapty Privacy Policy.
Apple App Attest
Verifies that requests come from genuine iOS devices, preventing fraud and abuse.
4. Photo Storage & Processing
When you use AI Product Scan or optional AI Skin Scan, the selected image passes through a Cosmetry serverless function to Google Gemini. The function keeps it only in request memory long enough to obtain the result and does not write it to our database, logs, or object storage. Google's retention and data-use rules remain governed by the Gemini API terms and may include limited retention for abuse monitoring and service operation.
5. Analytics & Tracking
- Adapty processes the App Transaction ID and purchase/subscription events to operate purchases, restore entitlements, prevent duplicate customer profiles, and provide subscription analytics
- We do not integrate any third-party advertising SDKs
- We do not engage in cross-app tracking
- We do not request App Tracking Transparency permission because we do not perform any such tracking
6. Data Retention & Deletion
- Ordinary app data is retained as long as your account is active
- App Attest challenges expire after about five minutes and are removed by scheduled cleanup; pseudonymous security-event telemetry is retained for up to 14 days
- Delete your account anytime from Profile > Delete Account
- Deletion permanently removes your Supabase Auth account and ordinary app data, including products, allergens, reactions, routines, chat history, profile data, notification tokens, AI usage counters, and Cosmetry's credit ledger
- To prevent repeated welcome-credit and one-time free-scan abuse, Cosmetry retains an indefinite, service-only pseudonymous tombstone. It contains a keyed one-way HMAC derived from the App Transaction ID and App Store environment, claimed-benefit flags, deletion time, and key/schema version. It does not contain the raw identifier, profile, inventory, photos, chat, or purchase ledger
- Apple and Adapty may retain transaction or subscription records independently for purchase administration, fraud prevention, accounting, or legal compliance; deleting Cosmetry data does not cancel an Apple subscription
- Local photos are deleted from your device during account deletion
- Google's independently retained processing or abuse-monitoring logs remain subject to Google's retention schedule
- Deletion of ordinary app data is irreversible — we cannot recover it
7. Data Export
You can export your data using Export My Data in Profile. The portable JSON includes your account and profile, products, ingredients, allergens, reactions, routines, notifications, chat history, credit and usage records, available Adapty profile/purchase data, relevant device preferences, and locally stored product, reaction, and profile photos encoded in the export file.
8. Security
- App Attest — Device-level verification prevents unauthorized access
- Row-Level Security (RLS) — Database policies ensure users can only access their own data
- JWT Authentication — Secure token-based authentication for all API calls
- Keychain and App Attest — Session credentials are stored in the iOS Keychain; App Attest keys are created and managed through Apple's App Attest service
- TLS Encryption — All network communication is encrypted in transit
- Server-Side Credit Management — Credit deductions are processed server-side
9. Your Rights
- Access — Export your data anytime via Profile > Export My Data
- Deletion — Delete your account and ordinary app data via Profile > Delete Account, subject to the limited anti-abuse and third-party retention described in Section 6
- Notification Control — Manage push notification preferences in Profile settings
- AI Consent — AI features are optional. Chat/Product Scan and Skin Scan use separate Google data-sharing permissions that you can withdraw from Profile > AI Data Sharing Consent. Withdrawal prevents new sharing but does not itself delete existing chat or profile records
- Correction — Edit your profile, products, and data at any time within the App
10. GDPR (European Economic Area Residents)
If you are located in the EEA, the UK, or Switzerland, the following additional provisions apply under the GDPR.
Data Controller: Mustafa Batin Efe — help@mbefe.com
Legal Basis: Legitimate Interest (core functionality, service security, fraud prevention, and one-time-benefit enforcement), Consent (AI data sharing), and Contract Performance (purchases/subscriptions).
Your Additional Rights: Right to Data Portability, Right to Object, Right to Lodge a Complaint with a supervisory authority.
Automated Decision-Making: We do not engage in automated decision-making or profiling that produces legal effects.
Cross-Border Transfers: Data may be transferred to the US (Supabase, Google Gemini API), safeguarded by Standard Contractual Clauses (SCCs).
11. CCPA/CPRA (California Residents)
- We do NOT sell your personal information
- We do NOT share your personal information for cross-context behavioral advertising
- You have the Right to Know, Right to Delete, Right to Correct, Right to Limit qualifying sensitive-data use, and Right to Opt-Out, subject to applicable exceptions including the narrowly scoped anti-abuse record described in Section 6
- We will not discriminate against you for exercising your privacy rights
Contact: help@mbefe.com
12. Children's Privacy
Cosmetry is intended for users aged 13 and older. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us at help@mbefe.com.
13. Medical Disclaimer
14. Limitation of Liability & Indemnification
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, Cosmetry and its developer shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or related to your use of the App. The App is provided on an "as is" and "as available" basis without warranties of any kind.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top will reflect changes. Continued use of the App after changes constitutes acceptance of the updated policy.
16. Contact Us
Email: help@mbefe.com
Developer: Mustafa Batin Efe