Privacy Policy

Last updated: 10 June 2026 · Governed by the Digital Personal Data Protection (DPDP) Act 2023 (India) and GDPR Article 9 (biometric data).

1. Who We Are

Skinest is an AI-powered skin analysis and personalised skincare recommendation platform designed for Indian users. We are the Data Fiduciary under the DPDP Act 2023 and the Data Controller under GDPR. Contact: privacy@yourdomain.com

2. What We Collect

DataPurposeRetention
Email addressAccount creation, verification OTPs, notifications2 years after last login
Full namePersonalised recommendations2 years after last login
City / stateClimate-aware skincare recommendations2 years after last login
Date of birthAge-appropriate recommendations2 years after last login
Skin tone classificationBias-adjusted AI analysis2 years after last login
512-dimension skin feature vectorAI skin analysis (no image stored)1 year
Lifestyle questionnaire answersPersonalised recommendations2 years after last login
IP addressSecurity — rate limiting, audit logs90 days
Device / browser (User-Agent)Security audit logs90 days

🔒 Raw face images are never stored. Your camera captures a frame, our on-device model extracts a 512-number mathematical vector, and the image is discarded immediately. The vector cannot be reverse-engineered into a face image.

3. How We Use Your Data

  • Provide AI skin analysis and product recommendations — Legal basis: Contract performance
  • Send email verification OTPs and security alerts — Legal basis: Legitimate interest (security)
  • Improve recommendation accuracy (aggregated, anonymised) — Legal basis: Legitimate interest
  • Fraud prevention and abuse detection — Legal basis: Legitimate interest (security)
  • Analytics on platform usage (PostHog — opt-in only) — Legal basis: Consent
  • Dermatologist review of high-risk cases — Legal basis: Explicit consent at registration

4. Your Rights (DPDP Act 2023 & GDPR)

To exercise any right, use the Settings page or email privacy@yourdomain.com. We will respond within 72 hours as required by the DPDP Act.

5. Who We Share Data With

DataPurposeRetention
Groq APIAI recommendation generationNo personal data sent — only anonymised skin profile
PineconeProduct similarity searchOnly product embeddings — no user data
AWS S3 (Mumbai region)Temporary document storageDPA in place; data never leaves ap-south-1
SendGridTransactional emailsEmail address only; DPA in place
SentryError monitoringStack traces only; PII scrubbing enabled

We never sell, rent, or share your personal data with advertisers or data brokers.

6. Security Measures

  • Passwords hashed with bcrypt (cost 12) — plaintext never stored
  • JWTs signed with RS256 — private key never leaves the server
  • All data in transit encrypted with TLS 1.3
  • PostgreSQL data encrypted at rest (AES-256)
  • Admin access requires two-factor authentication (TOTP)
  • IP allowlist on admin routes
  • Audit log on every data-modifying action
  • Annual penetration testing

7. Cookies

CookieTypePurposeExpiry
next-auth.session-tokenEssentialAuthentication session — httpOnly, Secure, SameSite=Lax7 days
__csrfEssentialCSRF protection — double-submit pattern1 hour
ph_*Analytics (opt-in)PostHog product analytics1 year
skinest_cookie_consentEssentialStores your cookie preference1 year

You can change your cookie preference at any time via the consent banner or Settings → Privacy.

8. Changes to This Policy

We will notify you by email at least 30 days before any material change. The "Last updated" date at the top of this page reflects the most recent revision. Continued use after changes constitutes acceptance.

Contact Our Privacy Team

For privacy requests, data subject access requests, or concerns:
privacy@yourdomain.com
We respond within 72 hours.