Privacy Policy

Ageflip — Last updated July 30, 2026

Section 1

1. Introduction

1.1. Ageflip ("we," "our," or "the app") is a skin analysis and skincare routine application that uses artificial intelligence to analyze selfie photographs and provide personalized skincare recommendations.

1.2. This Privacy Policy describes how we collect, use, and protect your information when you use the Ageflip mobile application. We are committed to safeguarding your privacy and being transparent about our data practices.

1.3. By downloading, installing, or using Ageflip, you acknowledge that you have read and understood this Privacy Policy.

Section 2

2. Information We Collect

2.1. Selfie Photographs

When you use the scan feature, your device's front-facing camera captures a photograph of your face. This image is:

  • Transmitted via encrypted HTTPS connection to Google's Gemini API for AI-powered skin analysis.
  • Stored locally on your device for display within the app.
  • Never uploaded to or stored on any servers owned or operated by Ageflip.

2.2. Personalization Data

During onboarding, we collect your responses to a personalization questionnaire including:

  • Your age (not your date of birth)
  • Skin concerns and goals
  • Lifestyle factors (sleep, stress, sun exposure, skincare habits)

Your answers are used to personalize your analysis. Ageflip also sends onboarding responses—including age, questionnaire answers, a randomly generated member identifier, and derived risk-factor categories—to PostHog under a pseudonymous installation identifier so we can understand onboarding completion and improve the app. Selfie photographs are not sent to PostHog.

2.3. Routine Tracking Data

The app tracks your daily skincare routine completion (which steps you have marked as done). This data is stored locally on your device and is not transmitted to any external service.

2.4. Subscription Information

Payment processing is handled by Apple through the App Store. Ageflip does not receive your payment-card number or billing credentials. RevenueCat manages subscription status and receives a pseudonymous App User ID, purchase and subscription records, the PostHog distinct identifier used by the app, and Apple Ads attribution information when available.

2.5. Product Analytics

We use PostHog to understand app performance and improve Ageflip. Depending on how you use the app, analytics may include a pseudonymous installation identifier, app version and build, device and operating-system context, lifecycle and interaction events, onboarding answers, the randomly generated member identifier, derived scan metrics such as skin age and aggregate concern counts, scan source, error categories and latency, paywall interactions, and purchase events. We do not send selfie photographs to PostHog.

2.6. Advertising and Attribution

Ageflip uses Apple AdServices, RevenueCat, and the TikTok for Business SDK to measure which ads lead to installs and subscriptions. This may include Apple Ads attribution tokens and campaign metadata; app install, launch, registration, and subscription events; product identifier, value, and currency; and device or advertising information made available by iOS. The TikTok SDK may access the Apple advertising identifier (IDFA) only if you grant tracking permission through Apple's App Tracking Transparency prompt. Apple Ads attribution does not require that permission.

2.7. Feedback and Support

If you choose “Send feedback,” Ageflip prepares an email that you can review and edit. Nothing is sent until you affirmatively send it from your email app. A sent message may include your sender email address and display name, your message and any attachment you add, plus removable technical details: app version and build, iOS version, generic device class, and language/region. We use this information only to respond, investigate bugs, evaluate requests, and improve Ageflip.

Section 3

3. Limits on Collection and Use

3.1. Ageflip does not require account registration.

3.2. Ageflip does not receive your payment-card number or App Store billing credentials.

3.3. Ageflip does not request precise GPS location. Service providers may process a general region derived from network or storefront information, and Apple Ads may provide country or region attribution.

3.4. We receive contact information only if you voluntarily send us an email, and we do not use support messages for unrelated marketing.

3.5. We do not provide selfie photographs to advertising or analytics providers. We disclose limited information to the service providers named below for AI processing, subscriptions, analytics, support, and advertising measurement as described in this policy.

Section 4

4. Third-Party Services

4.1. Ageflip uses the following third-party services:

4.1.1. Google Gemini API

Selfie images are transmitted to Google's Gemini AI service for skin analysis processing. Images are sent via encrypted HTTPS connection. Google's processing of this data is subject to Google's Privacy Policy.

4.1.2. RevenueCat

RevenueCat manages subscription status and entitlements. It processes pseudonymous identifiers, Apple purchase and subscription records, the PostHog distinct identifier, Apple Ads attribution, and subscription events used for configured integrations. Its practices are governed by RevenueCat's Privacy Policy.

4.1.3. PostHog

PostHog provides product analytics and processes the information described in Section 2.5 under a pseudonymous distinct identifier. Its practices are governed by PostHog's Privacy Policy.

4.1.4. TikTok for Business

The TikTok for Business SDK provides advertising measurement and processes the events and device information described in Section 2.6. Access to IDFA is controlled by your iOS tracking-permission choice. Its practices are governed by TikTok's Privacy Policy.

4.1.5. Apple App Store and AdServices

Apple processes App Store payments and provides Apple Ads attribution through AdServices. Apple's handling of payment and attribution data is subject to Apple's Privacy Policy.

Section 5

5. Data Storage and Security

5.1. Your profile, full scan results, routine tracking history, and photographs are stored locally using iOS app storage. The limited data described in Sections 2.2 and 2.4–2.7 is processed remotely by the named service providers.

5.2. Ageflip does not operate its own server database for selfie photographs or full scan histories. Third-party providers retain data under their own terms and retention practices.

5.3. Data sent to third-party services is transmitted using TLS/HTTPS encryption.

5.4. We use reasonable safeguards, including iOS sandboxed storage and device encryption, but no storage or transmission method can be guaranteed completely secure.

5.5. Our providers may process information in countries other than your own, subject to the safeguards and legal mechanisms described in their policies.

Section 6

6. Data Retention and Deletion

6.1. Local data remains on your device until you delete it or uninstall Ageflip.

6.2. “Delete app data” in the Account tab removes the Ageflip profile, scan history, routine data, preferences, and cached photograph stored by the app on that device, and resets the app's local PostHog identifier.

6.3. Deleting local app data does not cancel a subscription, erase Apple's transaction history, or automatically delete analytics, attribution, subscription, or support records previously received by our service providers.

6.4. Support emails are retained only as reasonably necessary to respond, investigate the issue, maintain appropriate business records, and meet legal obligations. Other providers retain information under their published policies and our configured retention settings.

6.5. To request deletion of remotely processed information, contact us at the address in Section 10. We will act on requests where we can reasonably identify the applicable pseudonymous records and where deletion is not limited by legal, security, fraud-prevention, or transaction-record obligations.

Section 7

7. Children's Privacy

7.1. Ageflip is not intended for use by individuals under the age of 13 (or the applicable minimum age in your jurisdiction).

7.2. We do not knowingly collect personal information from children. If we become aware that we have inadvertently received data from a user under the applicable minimum age, we will take steps to delete such information.

Section 8

8. Your Rights

8.1. You can view core local app data in Ageflip and delete it using “Delete app data.” You can manage or cancel subscriptions in your Apple ID settings.

8.2. You can change iOS tracking permission at any time in Settings > Privacy & Security > Tracking. Withdrawing permission prevents future IDFA access but does not delete data already processed.

8.3. Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; obtain a portable copy; withdraw consent; and complain to a data-protection authority.

8.4. Contact us to exercise a privacy right. Because Ageflip does not require an account and most remote records are pseudonymous, we may need information such as the relevant app identifier or message details to locate a record, and some requests may be limited where identity cannot reasonably be verified.

Section 9

9. Changes to This Policy

9.1. We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

9.2. The "Last updated" date at the top of this policy indicates when it was most recently revised.

9.3. Continued use of the app after any modifications constitutes your acceptance of the updated Privacy Policy.

Section 10

10. Contact Us

10.1. If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: milomitm@gmail.com