Privacy Policy
Last updated 21 July 2026
Template — pending legal review. Not final legal text.
This document is placeholder content used during development. It does not constitute legal advice and has not been reviewed by counsel.
This Privacy Policy explains how Syva ("Syva", "we", "us") collects, uses, shares, and protects information when you use our facial-aesthetics analysis service. Because our service processes images of your face, it necessarily involves biometric data, which we treat as sensitive and handle with heightened care.
By using Syva you agree to the practices described here. If you do not agree, please do not use the service.
1.Information we collect
We collect the following categories of information:
- Account information — such as your email address and authentication details when you create an account.
- Facial images and biometric data — photos you upload, and the facial landmarks, measurements, and derived geometry computed from them. See our Biometric Consent for detail.
- Analysis data — the scores, metrics, reports, and progress history generated for you.
- Usage and device data — such as log data, device and browser type, and general interaction events used to operate and improve the service.
- Payment information — processed by our third-party payment provider. We do not store full card numbers.
2.How we use your information
We use your information to:
- Produce your analysis, reports, simulations, and progress tracking.
- Operate, secure, maintain, and improve the service.
- Communicate with you about your account, purchases, and support requests.
- Comply with legal obligations and enforce our terms.
We do not use your facial images or biometric data to train models by default. Any such use requires your separate, explicit opt-in, which you can withdraw at any time.
3.Biometric data
Facial geometry derived from your photos is biometric data. We collect it only with your explicit consent, store it encrypted, restrict access, and never sell it. You can delete it at any time. The specifics of collection, retention, and destruction are described in our Biometric Consent document, which forms part of this policy.
4.How we share information
We share information only as needed to run the service:
- Service providers (processors) — vendors who host, process payments, or provide infrastructure under contractual confidentiality and security obligations.
- Legal and safety — where required by law, or to protect rights, safety, and the integrity of the service.
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to this policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5.Data retention
We keep personal information for as long as your account is active or as needed to provide the service, and thereafter only as required for legitimate business or legal purposes. Biometric data follows the retention and destruction schedule set out in the Biometric Consent. When data is no longer needed, we delete or de-identify it.
6.Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to withdraw consent, and to opt out of certain processing. In particular:
- EEA / UK (GDPR) — rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority.
- California (CCPA / CPRA) — rights to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them.
- Illinois (BIPA) — protections regarding the collection, storage, and destruction of biometric identifiers.
To exercise any right, contact us using the details below. We will not deny you service for exercising your privacy rights.
7.Security
We use technical and organizational measures — including encryption in transit and at rest, access controls, and monitoring — to protect your information. No method of transmission or storage is perfectly secure, but we work to protect your data proportionate to its sensitivity.
8.International transfers
We may process and store information in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards, such as standard contractual clauses, where required by applicable law.
9.Children
Syva is intended only for individuals aged 18 and over. We do not knowingly collect information from anyone under 18. If we learn that we have collected such information, we will delete it.
10.Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the service or by other reasonable means, and the "last updated" date above will change accordingly.
11.Contact us
Questions or requests about this policy can be sent to privacy@syva.beauty.