This Privacy Policy explains what data Atelier collects, why we collect it, how we use it, and the rights you have over it. The app is operated by Aylan Apps (“we”, “us”, “our”). By creating an account or using the app you accept this policy.
If anything here is unclear, email contact@aylantech.com.
1. What Atelier is
Atelier is an AI makeup virtual try-on studio. You design a makeup “look” (blush, lips, eyes, brows, and more) in the studio, then you can “try it on your photo”: you take or upload a face selfie, and our backend forwards that selfie to Google Gemini to render the look applied to your face, returning a before / after image. Your try-on renders are saved to your account so you can revisit them. It is a beauty visualization and entertainment tool — not professional beauty, dermatological, or medical advice. See the Cosmetic Disclaimer for details.
2. Data we collect
2.1 Account data
- Email address (mandatory for full accounts; anonymous / device accounts use a device-derived synthetic ID).
- Hashed password (or the sign-in token from Sign in with Apple).
- Username.
2.2 Try-on submissions and face data
- The face selfie photos you capture or upload for a try-on.
- The look designs and specs you create in the studio (the makeup zones, shades, and settings you pick).
- The AI-generated before / after look images we hand back to you, stored against your account so you can revisit them.
The only face data Atelier collects is that ordinary 2D photograph. We do not collect or derive biometric data from it: no face geometry, landmarks, mesh, depth map, face embedding, or recognition template is created or stored, and the app does not use face detection, face recognition, Face ID, ARKit face tracking, or the TrueDepth camera. Your face is never used to identify, verify, or profile you, and never for advertising.
2.3 Device + abuse-prevention signals
- A per-install random identifier (
install_id). - A hashed device fingerprint (brand / model / OS, hashed locally before upload).
- Platform-stable identifiers used only for fraud prevention so a reinstall cannot reset the free try-on limit:
- iOS: DCDevice attestation token (Apple).
- Android: AppSetId (Google Play Services).
- A SHA-256 hash of submitted photos, used for de-duplication and a short render cache (cost discipline).
- IP address of register / login requests, retained for 30 days for abuse investigation.
2.4 Usage analytics
- Screen views, button taps, try-ons, subscription events.
- Crash reports (anonymised stack traces via Firebase Crashlytics).
2.5 Push tokens
Your FCM device token, registered when you allow notifications. We use it only to send the notifications you've enabled (e.g. “your try-on is ready”).
3. How we use the data
We use the data to:
- Run the AI makeup try-on render you requested (contract basis).
- Save and show back your looks and try-on history (contract).
- Track free-tier usage (1 free try-on, then Premium) and your Premium entitlement (contract).
- Send the notifications you enabled (consent).
- Detect duplicate-account / refund abuse (legitimate interest).
- Fix crashes and performance issues (legitimate interest).
- Improve the product via aggregated, de-identified usage trends (legitimate interest).
We never:
- Sell your data.
- Share your selfies or try-on images with advertisers.
- Use your photos or try-on images to train external models.
- Make your selfies, looks, or try-on images public.
4. Third parties we share data with
We share the minimum necessary data with vetted infrastructure providers:
- Google Cloud / Gemini API — your face selfie, for rendering the makeup look onto your photo.
- Firebase (Google) — authentication, crash + analytics, FCM push tokens, encrypted media storage (selfies and generated try-on images).
- RevenueCat — subscription receipts and entitlement state.
- Apple / Google App Stores — purchase + restore receipts.
We do not transfer your data to other third parties for their own use.
5. Where data is stored and for how long
- Servers and storage are hosted in the United States via Google Cloud / Firebase, with a backend on Render.
- Selfies and generated try-on images are encrypted at rest in Firebase Storage, scoped to your account.
- Database is encrypted at rest; passwords stored as salted hashes.
- We retain your data while your account is active so your looks and try-on history stay intact.
- Deleting a try-on in the app removes its stored images — both the selfie you submitted and the generated result — from our storage immediately.
- Anonymous accounts that are never converted are deleted after 180 days of inactivity.
- If you delete your account, all personal data — including selfies and try-on images — is removed within 30 days, except where law requires us to keep records.
6. Age requirement
Atelier is intended for users 13 and older and is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, email us — we will delete the account and associated data.
7. A note on your photos
Try-on images are AI-generated cosmetic simulations of your own face and can be imperfect. They are private to your account. Only upload photos of your own face, or of someone who has consented — never a minor's. See the Cosmetic Disclaimer.
8. Your rights
You can, at any time:
- Access: email support for an export.
- Correct: Settings / Account → edit profile (or contact support).
- Delete: Settings / Account → Delete account.
- Restrict / object: contact support.
- Withdraw consent for analytics: turn off analytics in your device settings.
- Portability: contact support for a JSON export.
EU / UK users may also lodge a complaint with their local data protection authority. California residents (CCPA / CPRA) have the right to know, delete, correct, and to opt out of any “sale” or “sharing” of personal information — we do neither.
9. Cookies and similar
The mobile app does not use cookies. The companion website (aylanapps.com) uses only essential cookies.
10. Security
- All API calls go over HTTPS / TLS 1.2+.
- Access tokens are short-lived; refresh tokens stored in the device keychain.
- Apple DCDevice and Google AppSetId gate registration against abuse.
- Backend has IP-based and device-based rate limiting.
Report security issues to contact@aylantech.com — we acknowledge within 72 hours.
11. Changes to this policy
We update this policy when our practices change. Material changes trigger an in-app notice. Continued use after the change means you accept the updated policy.
12. Contact
Email: contact@aylantech.com
For deletion-only requests: Settings / Account → Delete account, or email with subject “Delete my Atelier account”.