Privacy Notice
Last updated May 2026
We don’t store your photos. Neither does Google.
Your photo lives in server memory only while we generate your visualization, then it’s discarded — never written to disk on our servers. We run Google’s Vertex AI in Zero Data Retention mode: caching is disabled at the project level, and Google’s abuse-monitoring logging exception has been approved for our project, so your photo isn’t stored, logged for human review, or used to train any model. This page explains what that looks like in practice.
1. What we collect
To run the Service, we collect:
- Your Google email, display name, and avatar URL, returned by Google when you sign in. We use these to identify your account and to show you in the navbar.
- Anonymous page visits for our public pages (landing page, sign-in page). Each visit records the page name, a timestamp, and an anonymous session identifier — no IP address, no name.
- Your hairstyle selections and 1–5 star ratings of generated visualizations, so we can improve recommendations.
- Observation text you provide during the edit step of the two-stage generation pipeline (e.g. “curlier than that, with shorter sides”). This text is sent to Google to refine the next visualization. We do not persist it server-side once the request is done.
2. What we do not collect
- Your uploaded photo is never stored on our servers. It exists in server memory only for the few seconds it takes to generate a visualization, then it’s discarded.
- The AI-generated visualizations are never stored on our servers either. They’re streamed back to your browser, where they can be saved to your personal gallery — encrypted in your browser only, on your device.
- We do not collect your IP address; it’s stripped from application logs.
- We do not collect phone numbers or any payment information.
3. Cookies and browser storage
We use the minimum needed to keep you signed in and to remember that you’ve seen our terms.
- A signed session cookie set by the Service. After sign-in it carries your
user_id; before sign-in it carries an anonymoussession_idused to deduplicate visit analytics. The cookie is signed so it cannot be tampered with, and contains no personal data on its face. - A
terms_accepted_v1flag in your browser’s localStorage. Set when you click “I agree, continue” on the first-visit terms modal, so you don’t see the modal again on the same device. Clearing your browser’s site data removes it.
4. Vertex AI / Gemini — our product promise
To generate a visualization, your photo is transmitted to Google’s Gemini models via the Vertex AI API. Zero Data Retention isn’t a footnote — it’s a property of the Service we deliberately committed to:
- No training on your data. Google’s paid-tier Vertex AI terms of service contractually prohibit using customer data to train Google’s models.
- No caching. Data caching is disabled at the GCP project level for our project.
- No human review. The abuse-monitoring logging exception has been approved for our project, which means Google does not log prompts or images for human review.
- No identity linkage. API calls to Google carry no participant identifier — no name, no email, no account ID. Google has no way to link a photo back to you as an individual.
The contractual basis is documented in Google’s Vertex AI data governance policy.
5. How long we keep things
- Photo and generated image bytes: never. Discarded as soon as the request is done.
- Account metadata (your Google email, display name, avatar URL): retained while your account exists. Deleted when you ask us to delete your account.
- Selection and rating metadata (which hairstyle you tried, your 1–5 rating): retained while your account exists.
- Gallery visualizations: stored only in your browser, encrypted on your device. Subject to whatever you do with your browser’s “Clear site data” control — we have no copy to keep or delete.
6. Your rights
You can ask us, at any time, to:
- Tell you exactly what account information we hold for you;
- Delete your account and all associated metadata;
- Correct your display name or other account details.
Email rfagya27@colby.edu from the address on your account and we’ll handle it.
7. Changes to this notice
We may update this Privacy Notice from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, prompt you to re-acknowledge on next sign-in.
8. Contact
Questions about this notice or how we handle your data? Reach the team at rfagya27@colby.edu.