This Privacy Policy explains how Aesthetic Photo Std collects, uses, and protects user data.
1. General Principles
Aesthetic Photo Std is designed as a medical photography standardization tool. User privacy is a core principle of the application.
- We do not perform facial recognition.
- We do not create biometric identifiers.
- We do not store, transmit, or share facial data.
- All image-related processing occurs locally on the user's device.
2. Face Data and Camera Usage (Important)
Face Data Processing
The application uses real-time, on-device face detection solely to guide standardized medical photography (e.g., alignment, framing, and positioning).
Key clarifications:
- Facial data is processed temporarily and locally on the user's device.
- No facial data, face geometry, biometric identifiers, or face templates are collected.
- No face data is stored, logged, transmitted, or shared with any server.
- Face-related data is discarded immediately after the camera session ends.
- The application does not identify, recognize, or authenticate users by their face.
- This processing is used only to assist the user visually and has no analytical, identification, or tracking purpose.
3. Standard Users (Non-Registered Users)
3.1 Data Collection
Standard users can access and use the application without registration.
- We do not collect, store, or process personally identifiable information (PII).
- We do not track usage history.
- We do not associate any session data with an individual.
3.2 Purpose of Processing
Since no personal data is collected, no personal data processing or profiling activities occur for standard users.
3.3 Data Sharing Responsibility
Any data voluntarily shared directly by users outside the app environment is entirely under the user's responsibility and is not collected or controlled by Aesthetic Photo Std.
4. Registered Users (Healthcare Professionals)
4.1 Data Collection
For registered healthcare professionals, we collect:
- Personal information: name, surname, email
- Contact information: phone number (e.g., WhatsApp), address, city, country
- Professional information: medical specialty, certification documents
- Account data: profile photo or logo, unique user ID
- Subscription data: trial periods, subscription status, payment history
- Application status and access permissions
4.2 Purpose of Processing
Data is processed for the following purposes:
- User authentication and account management
- Professional credential verification
- Communication related to accounts and subscriptions
- Providing access to professional features
- Subscription and billing management
- Legal and regulatory compliance
- Security, fraud prevention, and abuse detection
4.3 Data Storage and Security
Data is securely stored using Firebase services (Google Cloud Platform).
- All data is encrypted: In transit (HTTPS) and at rest
- Access is restricted to authorized administrators only.
- Regular security reviews are performed.
4.4 Data Sharing
- We do not sell user data.
- Data is not shared with advertisers or marketing platforms.
- Data is accessed only by authorized administrators for verification and support.
- Data may be disclosed only if legally required by authorities.
4.5 User Rights (GDPR & Global Privacy Compliance)
Users have the right to:
- Access their personal data
- Rectify or update their information
- Request account and data deletion
- Request data portability
- Object to certain processing activities
Requests can be submitted via the contact details below or through the account and data deletion options described in section 4.7.
4.6 Data Retention
We retain user data for as long as the user account remains active or as needed to provide the services described in this policy. Users may request deletion of their data at any time.
After an account is deleted or personal data is removed upon request, deleted account data may remain in backup systems for up to 90 days before permanent removal. We may retain certain information longer only where required by law (for example, tax or accounting records, or anonymized or aggregated data that does not identify you).
- Standard (non-registered) users: we do not retain personal data on our servers as described in section 3.
- Registered users: account-related data is kept for the duration of the active account unless you request deletion.
- Limited anonymized records may be retained where legally required (e.g., audit logs).
4.7 Account and Data Deletion
Users can request account and data deletion directly from the application settings or by contacting us at info@aestheticphotostd.com. Upon request, personal data will be permanently deleted within a reasonable timeframe, except where retention is legally required.
5. Contact Information
For privacy-related questions or requests, please contact us at: info@aestheticphotostd.com
www.aestheticphotostandards.com