Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains how Vraie ("Vraie", "we", "us") collects, uses, and protects your information when you use the Vraie app and website (collectively, the "Service"). By using the Service, you agree to the practices described here.
Cosmetic, not medical. Vraie is a cosmetic skincare tool for general skin-wellness goals. It does not diagnose, treat, cure, or prevent any disease or medical condition, and is not a substitute for professional medical advice. For any skin concern, consult a licensed dermatologist or physician.
Information we collect
- Scan photos and face data. The selfies you capture to run a VraieScan and the cosmetic skin observations derived from them. The complete details are in Face data and scan photos below.
- Scan consultation fields. For an OpenAI-assisted VraieScan, Vraie sends only your selected skin type, selected tone range, and selected skincare goals with the selfie. Other onboarding answers — including your name, age range, discovery source, journey choice, cycle information, water intake, and shelf size — are not sent to OpenAI.
- Shelf Scan photos. Photos of skincare products you capture when you ask Vraie to identify products on your shelf. These are product photos, not face data. The complete details are in Shelf Scan photos below.
- Analysis results. The cosmetic metrics and insights Vraie derives from your scans, such as hydration, clarity, tone, texture, skin score, and visible focus areas.
- Daily Check-in data. Optional cosmetic and wellness signals you record, including cycle/on-period status, sleep quality, stress level, water intake, flare-ups, whether you tried a new product, and any product name or note you choose to enter.
- Account & usage data. Basic account details, app settings, and usage analytics. Firebase Analytics assigns an app-instance identifier and records app lifecycle, product-interaction, custom funnel, and purchase or subscription events, together with device information and approximate location derived from a masked IP address. Vraie uses this information to measure and improve the Service, not for advertising or tracking.
- Purchase data. Subscription and purchase records, processed by the relevant app store or payment provider. We do not store your full card details.
Your choice before OpenAI processing
Vraie asks for your express, feature-specific permission immediately before it first sends information to OpenAI. The notice names OpenAI, identifies the information the particular feature will send, explains its purpose, and offers both Allow & continue and Continue without AI. If you decline, Vraie does not send that feature's photo, text, profile context, or consultation fields to OpenAI. You can continue using the non-AI parts of Vraie.
- VraieScan: your selfie plus your selected skin type, selected tone range, and selected skincare goals, to return visible cosmetic skin observations.
- Cosmetic projection: your selfie, selected visible concern labels, and the selected projection timeframe, to return an AI-generated cosmetic simulation.
- Shelf Scan: the product photo you choose to capture, to identify visible skincare packaging.
- AI Coach: the optional product name or skin note you choose to enter plus your selected skincare concern labels, to return one tailored cosmetic tip. Your archetype, skin score, and other check-in answers remain on your device.
Permission is recorded on your device with the disclosure version, feature, decision, and decision time. Permission for one feature does not grant permission for another. You can review or withdraw OpenAI permission at any time in Vraie's Data & AI settings. Withdrawal blocks future OpenAI requests; it cannot recall information already processed before withdrawal. If Vraie materially changes a disclosure, the app requires permission again. This OpenAI-processing permission is separate from the optional training contribution described below.
How we use your information
- To generate your skin analysis, personalized routine, coaching responses, and progress journey.
- To save your Daily Check-ins, show patterns in your cosmetic skin journey, and provide a tailored AI Coach tip when you enter optional product or flare-up context.
- To identify skincare products in a Shelf Scan photo and show the requested product guidance.
- To provide, maintain, secure, and improve the Service.
- To process purchases and manage your subscription.
- To communicate important account, security, or service updates.
- Only if you opt in: to add your scan to a pseudonymised dataset used to evaluate, train, and improve Vraie's analysis for melanin-rich skin. This is off by default — see "Helping build a fairer model" below.
Face data and scan photos
For this Policy, "face data" means the selfie you capture or select for a VraieScan and the cosmetic skin observations derived from it. Derived observations can include apparent skin tone colours, hydration, clarity, texture, skin score, visible concern areas, and an optional AI-generated cosmetic projection.
Vraie does not collect Face ID data, create a faceprint or biometric identity template, perform facial recognition, verify identity from a face, or use face data for advertising. Vraie analyses visible cosmetic skin characteristics only.
How face data is used
- To provide the VraieScan requested by you, generate cosmetic skin observations, and build your personalised AM and PM skincare routine.
- To display your scan, skin profile, progress journey, and optional cosmetic projection in the app.
- To restore and sync your current scan and analysis across your devices when you choose to create or sign in to an account.
- Only with separate, explicit opt-in consent: to add a pseudonymised copy to Vraie's private training dataset so we can evaluate and improve performance across skin tones. This consent is off by default and can be withdrawn at any time.
These are the complete planned uses of face data. We do not sell face data, use it for advertising, or share it with data brokers.
Where face data is processed, stored, and shared
- Your device. Your current scan photo, analysis, and generated projections are stored in the app on your device so the features remain available between sessions.
- Google Cloud/Firebase. With your feature-specific permission, an AI request passes through Vraie's access-controlled Google Cloud Function in the United States (
us-central1) before it reaches OpenAI. If you sign in, your current scan photo and analysis are separately backed up in Vraie's access-controlled Firebase/Google Cloud account resources in the European Union (includingeurope-west1resources where applicable). The EU account backup and the US AI-processing gateway are different processing paths. Generated projection images remain on your device and are not included in the account backup. - OpenAI. After the in-app disclosure and your permission, the scan photo and the limited fields listed above are sent through Vraie's backend to the OpenAI API to generate the cosmetic analysis or projection you requested. OpenAI acts only as a service provider for Vraie. OpenAI states that API data is not used to train its models by default. Its standard abuse-monitoring logs may retain API inputs and outputs for up to 30 days, unless a longer period is legally required.
- Optional training dataset. If you explicitly opt in, a copy is stored in a private Firebase Storage dataset under a random token. Image metadata such as location and capture timestamp is stripped. A separate access-controlled mapping connects the random token to your account only to manage your contribution count and honour deletion requests. Authorised Vraie personnel and specialist reviewers may access these contributions to evaluate and improve the system. They are not public or sold.
Face-data retention and deletion
- On-device data: retained until you remove the app's data, restart the app experience, or delete your account.
- Signed-in account backup: retained while your account is active so your current scan and results can be restored. Choosing "Delete account" initiates deletion of the associated scan photo, analysis, and account data from Vraie's active Firebase storage and database.
- Optional training contributions: retained until you use "Delete my contributions" or delete your account. Either action initiates deletion of the contributed images and related records.
- OpenAI processing: subject to OpenAI's API retention described above, normally no more than 30 days for abuse monitoring.
Deletion may be delayed only where a service provider must retain limited information for security, fraud prevention, legal compliance, or disaster-recovery obligations.
Shelf Scan photos
When you choose Shelf Scan and grant its separate OpenAI permission, the product-shelf photo you capture is sent through Vraie's us-central1 backend to the OpenAI API solely to identify visible skincare products and provide product guidance. Shelf Scan is intended for product packaging, not faces, and its photos are not used for facial analysis.
Vraie does not save Shelf Scan photos to your account, Firebase Storage, or the optional training dataset. Vraie uses the photo only to return the requested result and discards its copy after the request completes. OpenAI acts as a service provider; its standard abuse-monitoring logs may retain API inputs and outputs for up to 30 days, unless a longer period is legally required. Shelf Scan photos are not used for advertising, tracking, or model training, and are not shared with data brokers.
Daily Check-ins and AI Coach
Daily Check-ins let you optionally record cycle/on-period status, sleep quality, stress level, water intake, flare-ups, whether you tried a new product, and an optional product name or note. Vraie uses these as cosmetic and general-wellness context only; they are not used to diagnose or treat a medical condition.
Your saved check-in signals — cycle/on-period status, sleep quality, stress level, water intake, flare-up status, and whether you tried a new product — are stored on your device. If you sign in, they are also synced with your other app data to your access-controlled Firebase/Google Cloud account record so they can be restored across your devices. An optional product name or note is used for the AI Coach request described below and is not added to your saved check-in history.
If you enter an optional product name or flare-up note, grant the AI Coach's separate OpenAI permission, and request a tip, Vraie sends that text through its us-central1 backend to the OpenAI API with only your selected skincare concern labels. Vraie does not send your archetype, skin score, other check-in answers, or full check-in history to OpenAI. OpenAI acts as a service provider; API data is not used to train its models by default, and standard abuse-monitoring logs may retain the input and output for up to 30 days unless a longer period is legally required. Daily Check-in data is not used for advertising or tracking.
Data minimisation and security records
Vraie limits each OpenAI request to the data listed for that feature. The backend enforces a maximum image payload size and removes embedded metadata from JPEG images before forwarding them. It also rejects an AI request unless it carries a current, feature-matching consent receipt. Vraie does not include your name, email address, advertising identifier, full onboarding questionnaire, or full check-in history in an OpenAI request.
Google Cloud necessarily receives network and technical information when a request reaches Vraie's backend. For Vraie's own abuse-prevention counter, the backend reduces an IPv4 address to a /24 network or an IPv6 address to a /64 network, converts that prefix to a keyed, date- and feature-specific hash, and stores only the resulting pseudonym, counter, date, and feature. Vraie does not persist or write the raw address to its application logs. These short-lived counter records carry an expiration time three days after the measured UTC day. Google Cloud may separately process operational and security logs under its service settings and legal obligations. Vraie's application logs do not intentionally include scan photos, Shelf Scan photos, consultation answers, AI Coach text, or OpenAI response content.
Your photos stay yours
Your VraieScan and Shelf Scan photos belong to you. We use them only for the purposes described in the "Face data and scan photos" and "Shelf Scan photos" sections above. We do not sell them or use them for advertising or tracking.
Helping build a fairer model (optional)
Most skin AI is trained mostly on lighter skin, so it under-reads redness and dark marks on deeper tones. You can choose to help fix that by contributing your scan to a private training dataset. This is strictly optional:
- Off by default, opt-in only. Nothing is contributed unless you turn it on. You can turn it off again anytime in the app.
- Pseudonymised. Contributed scans are stored under a random token rather than your name or email. A separate access-controlled mapping connects the random token to your account only to manage your contribution count and honour deletion requests. Image metadata such as location and capture timestamp is stripped before storage.
- Access-controlled & expertly reviewed. The dataset is private and may be accessed only by authorised Vraie personnel and specialist reviewers to evaluate and improve performance across skin tones. It is never made public or sold.
- Deletable. You can delete every scan you've contributed at any time from the app's "A fairer model" card, separately from your account.
Sharing
We do not sell your personal information. We share information only with the service providers needed to operate Vraie, including Google Cloud/Firebase for hosting, account storage, security, and the usage measurement described above; OpenAI for the feature you expressly permit and request; and Apple or Google for purchases. We use contractual, organisational, and technical safeguards designed to require OpenAI and Google Cloud/Firebase to process Vraie data only for the instructed service and to protect it to a standard equivalent to the commitments in this Policy. If a provider cannot provide that protection, Vraie will not send it the affected data. Face-data sharing is described completely in the Face data section above, Shelf Scan photo handling is described in the Shelf Scan section, and AI Coach processing is described in the Daily Check-ins section. We do not share information for advertising or tracking. We may also disclose information where required by law.
Data retention
We retain account information, results, and signed-in Daily Check-ins while your account is active so Vraie can provide the Service and preserve your progress. On-device check-ins remain until you restart the app experience, remove the app's data, or delete your account. The specific periods for VraieScan photos, derived face data, processor copies, and optional training contributions are listed in "Face-data retention and deletion" above. Shelf Scan photo retention and AI Coach processor retention are described in their respective sections.
Your choices & rights
- Access, correct, or request deletion of your data by using the available in-app controls or contacting us.
- Delete your account, which initiates deletion of your scan photo, analysis results, and other account data from Vraie's active systems.
- Review or withdraw any feature-specific OpenAI permission from the in-app Data & AI settings. Withdrawal blocks future requests for the affected feature.
- Withdraw optional training consent and permanently delete your training contributions from the "A fairer model" card.
- Opt out of non-essential analytics where supported by your device.
Children
Vraie is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, with in-app notice.
Contact
Questions about privacy? Email betacarryapp@gmail.com.