Last updated: 10 June 2026 · Governed by the Digital Personal Data Protection (DPDP) Act 2023 (India) and GDPR Article 9 (biometric data).
Skinest is an AI-powered skin analysis and personalised skincare recommendation platform designed for Indian users. We are the Data Fiduciary under the DPDP Act 2023 and the Data Controller under GDPR. Contact: privacy@yourdomain.com
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account creation, verification OTPs, notifications | 2 years after last login |
| Full name | Personalised recommendations | 2 years after last login |
| City / state | Climate-aware skincare recommendations | 2 years after last login |
| Date of birth | Age-appropriate recommendations | 2 years after last login |
| Skin tone classification | Bias-adjusted AI analysis | 2 years after last login |
| 512-dimension skin feature vector | AI skin analysis (no image stored) | 1 year |
| Lifestyle questionnaire answers | Personalised recommendations | 2 years after last login |
| IP address | Security — rate limiting, audit logs | 90 days |
| Device / browser (User-Agent) | Security audit logs | 90 days |
🔒 Raw face images are never stored. Your camera captures a frame, our on-device model extracts a 512-number mathematical vector, and the image is discarded immediately. The vector cannot be reverse-engineered into a face image.
View all data held about you from Settings → Privacy.
Download a ZIP of all your data in JSON format. Available in Settings → Privacy.
Permanently delete your account and all associated data. Settings → Delete Account.
Update your profile at any time in Settings → Profile.
To exercise any right, use the Settings page or email privacy@yourdomain.com. We will respond within 72 hours as required by the DPDP Act.
| Data | Purpose | Retention |
|---|---|---|
| Groq API | AI recommendation generation | No personal data sent — only anonymised skin profile |
| Pinecone | Product similarity search | Only product embeddings — no user data |
| AWS S3 (Mumbai region) | Temporary document storage | DPA in place; data never leaves ap-south-1 |
| SendGrid | Transactional emails | Email address only; DPA in place |
| Sentry | Error monitoring | Stack traces only; PII scrubbing enabled |
We never sell, rent, or share your personal data with advertisers or data brokers.
| Cookie | Type | Purpose | Expiry |
|---|---|---|---|
| next-auth.session-token | Essential | Authentication session — httpOnly, Secure, SameSite=Lax | 7 days |
| __csrf | Essential | CSRF protection — double-submit pattern | 1 hour |
| ph_* | Analytics (opt-in) | PostHog product analytics | 1 year |
| skinest_cookie_consent | Essential | Stores your cookie preference | 1 year |
You can change your cookie preference at any time via the consent banner or Settings → Privacy.
We will notify you by email at least 30 days before any material change. The "Last updated" date at the top of this page reflects the most recent revision. Continued use after changes constitutes acceptance.
For privacy requests, data subject access requests, or concerns:
privacy@yourdomain.com
We respond within 72 hours.