← Back to home Legal

Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how Vraie ("Vraie", "we", "us") collects, uses, and protects your information when you use the Vraie app and website (collectively, the "Service"). By using the Service, you agree to the practices described here.

Information we collect

Your choice before OpenAI processing

Vraie asks for your express, feature-specific permission immediately before it first sends information to OpenAI. The notice names OpenAI, identifies the information the particular feature will send, explains its purpose, and offers both Allow & continue and Continue without AI. If you decline, Vraie does not send that feature's photo, text, profile context, or consultation fields to OpenAI. You can continue using the non-AI parts of Vraie.

Permission is recorded on your device with the disclosure version, feature, decision, and decision time. Permission for one feature does not grant permission for another. You can review or withdraw OpenAI permission at any time in Vraie's Data & AI settings. Withdrawal blocks future OpenAI requests; it cannot recall information already processed before withdrawal. If Vraie materially changes a disclosure, the app requires permission again. This OpenAI-processing permission is separate from the optional training contribution described below.

How we use your information

Face data and scan photos

For this Policy, "face data" means the selfie you capture or select for a VraieScan and the cosmetic skin observations derived from it. Derived observations can include apparent skin tone colours, hydration, clarity, texture, skin score, visible concern areas, and an optional AI-generated cosmetic projection.

Vraie does not collect Face ID data, create a faceprint or biometric identity template, perform facial recognition, verify identity from a face, or use face data for advertising. Vraie analyses visible cosmetic skin characteristics only.

How face data is used

These are the complete planned uses of face data. We do not sell face data, use it for advertising, or share it with data brokers.

Where face data is processed, stored, and shared

Face-data retention and deletion

Deletion may be delayed only where a service provider must retain limited information for security, fraud prevention, legal compliance, or disaster-recovery obligations.

Shelf Scan photos

When you choose Shelf Scan and grant its separate OpenAI permission, the product-shelf photo you capture is sent through Vraie's us-central1 backend to the OpenAI API solely to identify visible skincare products and provide product guidance. Shelf Scan is intended for product packaging, not faces, and its photos are not used for facial analysis.

Vraie does not save Shelf Scan photos to your account, Firebase Storage, or the optional training dataset. Vraie uses the photo only to return the requested result and discards its copy after the request completes. OpenAI acts as a service provider; its standard abuse-monitoring logs may retain API inputs and outputs for up to 30 days, unless a longer period is legally required. Shelf Scan photos are not used for advertising, tracking, or model training, and are not shared with data brokers.

Daily Check-ins and AI Coach

Daily Check-ins let you optionally record cycle/on-period status, sleep quality, stress level, water intake, flare-ups, whether you tried a new product, and an optional product name or note. Vraie uses these as cosmetic and general-wellness context only; they are not used to diagnose or treat a medical condition.

Your saved check-in signals — cycle/on-period status, sleep quality, stress level, water intake, flare-up status, and whether you tried a new product — are stored on your device. If you sign in, they are also synced with your other app data to your access-controlled Firebase/Google Cloud account record so they can be restored across your devices. An optional product name or note is used for the AI Coach request described below and is not added to your saved check-in history.

If you enter an optional product name or flare-up note, grant the AI Coach's separate OpenAI permission, and request a tip, Vraie sends that text through its us-central1 backend to the OpenAI API with only your selected skincare concern labels. Vraie does not send your archetype, skin score, other check-in answers, or full check-in history to OpenAI. OpenAI acts as a service provider; API data is not used to train its models by default, and standard abuse-monitoring logs may retain the input and output for up to 30 days unless a longer period is legally required. Daily Check-in data is not used for advertising or tracking.

Data minimisation and security records

Vraie limits each OpenAI request to the data listed for that feature. The backend enforces a maximum image payload size and removes embedded metadata from JPEG images before forwarding them. It also rejects an AI request unless it carries a current, feature-matching consent receipt. Vraie does not include your name, email address, advertising identifier, full onboarding questionnaire, or full check-in history in an OpenAI request.

Google Cloud necessarily receives network and technical information when a request reaches Vraie's backend. For Vraie's own abuse-prevention counter, the backend reduces an IPv4 address to a /24 network or an IPv6 address to a /64 network, converts that prefix to a keyed, date- and feature-specific hash, and stores only the resulting pseudonym, counter, date, and feature. Vraie does not persist or write the raw address to its application logs. These short-lived counter records carry an expiration time three days after the measured UTC day. Google Cloud may separately process operational and security logs under its service settings and legal obligations. Vraie's application logs do not intentionally include scan photos, Shelf Scan photos, consultation answers, AI Coach text, or OpenAI response content.

Your photos stay yours

Your VraieScan and Shelf Scan photos belong to you. We use them only for the purposes described in the "Face data and scan photos" and "Shelf Scan photos" sections above. We do not sell them or use them for advertising or tracking.

Helping build a fairer model (optional)

Most skin AI is trained mostly on lighter skin, so it under-reads redness and dark marks on deeper tones. You can choose to help fix that by contributing your scan to a private training dataset. This is strictly optional:

Sharing

We do not sell your personal information. We share information only with the service providers needed to operate Vraie, including Google Cloud/Firebase for hosting, account storage, security, and the usage measurement described above; OpenAI for the feature you expressly permit and request; and Apple or Google for purchases. We use contractual, organisational, and technical safeguards designed to require OpenAI and Google Cloud/Firebase to process Vraie data only for the instructed service and to protect it to a standard equivalent to the commitments in this Policy. If a provider cannot provide that protection, Vraie will not send it the affected data. Face-data sharing is described completely in the Face data section above, Shelf Scan photo handling is described in the Shelf Scan section, and AI Coach processing is described in the Daily Check-ins section. We do not share information for advertising or tracking. We may also disclose information where required by law.

Data retention

We retain account information, results, and signed-in Daily Check-ins while your account is active so Vraie can provide the Service and preserve your progress. On-device check-ins remain until you restart the app experience, remove the app's data, or delete your account. The specific periods for VraieScan photos, derived face data, processor copies, and optional training contributions are listed in "Face-data retention and deletion" above. Shelf Scan photo retention and AI Coach processor retention are described in their respective sections.

Your choices & rights

Children

Vraie is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, with in-app notice.

Contact

Questions about privacy? Email betacarryapp@gmail.com.