This Privacy Policy explains what data VShape collects, why we collect it, how we use it, and the rights you have over it. The app is operated by Aylan Apps (“we”, “us”, “our”). By creating an account or using the app you accept this policy.
If anything here is unclear, email support@aylanapps.com.
1. What VShape is
VShape is an AI physique / body-shape (“V-taper”) analysis and self-improvement app. You take or upload a body photo (typically a shirtless upper-body / torso photo); our backend forwards that photo to Google Gemini, which analyses your V-taper (shoulder-to-waist ratio) and returns an overall aesthetic V-taper score plus per-muscle-group sub-scores (e.g. shoulders, chest, lats, shoulder-to-waist), a goal / target ratio, progress tracking across scans, and personalized self-improvement tips (training and physique-oriented). It is for self-improvement and entertainment. It is not a medical, clinical, body-composition (e.g. DEXA / BIA), or professional fitness assessment, a diagnosis, or a measure of your health, fitness, or worth. See the Cosmetic Disclaimer for details.
2. Data we collect
2.1 Account data
- Email address (mandatory for full accounts; anonymous accounts use a device-derived synthetic ID).
- Hashed password, or a sign-in token from Apple when you use Sign in with Apple.
- Username.
2.2 Scan submissions and results
- The body photos you capture or upload for analysis.
- Derived results we compute and store against your account: your overall V-taper score, per-muscle-group sub-scores (e.g. shoulders, chest, lats, shoulder-to-waist ratio), your goal / target ratio, and personalized self-improvement tips.
- Your scan history, kept so you can track progress over time.
- Any AI-generated goal physique image produced from your scan.
VShape does not record or collect audio or video. The app has no microphone permission and no voice or video feature.
2.3 Processed entirely on your device
- Pose landmarks and body outline, computed locally by Google ML Kit to help you frame the shot. This runs on-device and is never uploaded.
- Body measurements and nutrition figures you enter yourself (weight, measurements, calorie and macro targets). These are stored only in your device's local app storage and are never sent to our servers.
2.4 Device + abuse-prevention signals
- A per-install random identifier (
install_id). - A hashed device fingerprint (brand / model / OS, hashed locally before upload).
- Platform-stable identifiers used only for fraud prevention so a reinstall cannot reset the free-scan limit:
- iOS: DCDevice attestation token (Apple).
- Android: AppSetId (Google Play Services).
- A SHA-256 hash of submitted photos, used for de-duplication and a short analysis cache (cost discipline).
- IP address of register / login requests, retained for 30 days for abuse investigation.
2.5 Usage analytics
- Screen views, button taps, scans, subscription events.
- Crash reports (anonymised stack traces via Firebase Crashlytics).
2.6 Push tokens
Your FCM device token, registered when you allow notifications. We use it only to send the notifications you've enabled (e.g. “your analysis is ready” or a check-in reminder).
3. How we use the data
We use the data to:
- Run the AI physique analysis you requested and return your V-taper score, sub-scores, and tips (contract basis).
- Build your history so you can track progress over time (contract).
- Track free-tier usage (1 free body scan, then Premium) and your Premium entitlement (contract).
- Send the notifications you enabled (consent).
- Detect duplicate-account / refund abuse (legitimate interest).
- Fix crashes and performance issues (legitimate interest).
- Improve the product via aggregated, de-identified usage trends (legitimate interest).
We never:
- Sell your data.
- Share your body photos or results with advertisers.
- Use your body photos or results to train external models.
- Make your scans, scores, or tips public.
4. Third parties we share data with
We share the minimum necessary data with vetted infrastructure providers:
- Google Cloud / Gemini API — your body photo, for physique analysis.
- Firebase (Google) — authentication, crash + analytics, FCM push tokens, encrypted media storage (your body photos and generated images).
- Render — hosting for our backend and its encrypted database (your account, profile, scores and scan metadata).
- RevenueCat — subscription receipts and entitlement state.
- Apple / Google App Stores — purchase + restore receipts.
We do not transfer your data to other third parties for their own use.
5. Where data is stored and for how long
- Servers and storage are hosted in the United States — media in Google Cloud / Firebase, and the backend database in Oregon via Render.
- Body photos are encrypted at rest in Firebase Storage, scoped to your account.
- Database is encrypted at rest; passwords stored as salted hashes.
- We retain your data while your account is active so your history stays intact.
- Anonymous accounts that are never converted are deleted after 180 days of inactivity.
- If you delete your account, all personal data — including your body photos and results — is removed within 30 days, except where law requires us to keep records.
6. Age requirement
VShape is intended for users 13 and older. It is not directed at children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, email us — we will delete the account and associated data.
7. A note on body-image and self-esteem sensitivity
V-taper scores and physique sub-scores are subjective AI estimates for self-improvement and entertainment, and they can be imperfect. They are not a measure of your health or fitness, nor a judgement of your worth. Physique goals can carry real pressure, and for some people constant scoring can feed muscle dysmorphia, compulsive checking, or unhealthy eating or exercise. If a score affects how you feel about yourself, please step back and, where helpful, speak with someone you trust or a qualified professional. See the Cosmetic Disclaimer.
8. Your rights
You can, at any time:
- Access: email support for an export.
- Correct: Settings / Account → edit profile (or contact support).
- Delete: Settings / Account → Delete account.
- Restrict / object: contact support.
- Withdraw consent for analytics: turn off analytics in your device settings.
- Portability: contact support for a JSON export.
EU / UK users may also lodge a complaint with their local data protection authority. California residents (CCPA / CPRA) have the right to know, delete, correct, and to opt out of any “sale” or “sharing” of personal information — we do neither.
9. Cookies and similar
The mobile app does not use cookies. The companion website (aylanapps.com) uses only essential cookies.
10. Security
- All API calls go over HTTPS / TLS 1.2+.
- Access tokens are short-lived; refresh tokens stored in the device keychain.
- Apple DCDevice and Google AppSetId gate registration against abuse.
- Backend has IP-based and device-based rate limiting.
Report security issues to support@aylanapps.com — we acknowledge within 72 hours.
11. Changes to this policy
We update this policy when our practices change. Material changes trigger an in-app notice. Continued use after the change means you accept the updated policy.
12. Contact
Email: support@aylanapps.com
For deletion-only requests: Settings / Account → Delete account, or email with subject “Delete my VShape account”.