LooksGauge Privacy Policy

Last updated: August 30, 2026

Android platform details

LooksGauge is available on Google Play for Android 8.0 and later. The iPhone version is coming soon. References below to Apple, SwiftData, App Attest, or the iOS Keychain describe the iPhone version only.

On Android, photos use private app files, records use a local Room database, and preferences and usage counters use app-local storage. The app disables Android backup and requests exclusion from device transfers; device manufacturers may handle transfers differently. Delete scan history removes saved photos and results but keeps usage counters and preferences. Unlike the iOS Keychain marker, Android local counters are removed when Android app data is cleared or the app is uninstalled. This does not delete provider records or cancel a subscription.

Android uses Google Play Integrity through Firebase App Check to help verify requests. The same optional Google AI analysis, text-only follow-up chat, and result-report processing described on these pages apply. RevenueCat manages subscription entitlements, while Google Play handles Android purchases and refunds under its policies. Restore purchases using the Google account you used to subscribe. To manage or cancel a subscription, open Google Play → Payments & subscriptions → Subscriptions. Local prices, trial eligibility, and renewal terms appear on the store purchase sheet; uninstalling does not cancel Pro.

Our Privacy Commitment

LooksGauge is a private-by-design glow-up coach for iPhone and Android. Your selfies and your scan results (scores, tips, and trend history) are stored locally on your device. There is no account to create, no sign-in, no first-party product-event analytics about you or your scans, and no advertising tracking. LightPath keeps no routine cloud database of your photos or scan history. The exception is an optional result report that you choose to submit, which is scheduled to expire after 180 days as described below.

Only one flow sends a photo off your device, and it never happens without you: when you run a scan, your selfie or selfies, any optional note you wrote, and a brief summary of your most recent scored result are sent to Google's Gemini model for analysis — but only after you give explicit consent. That consent is asked for before the first scan, remembered so the app doesn't nag you on every run, and revocable at any time in Settings → Allow AI photo analysis; revoking it blocks all further analysis uploads. A separate, optional result-report flow can send the text and metadata shown in its preview, but never your selfie. Before a selfie is sent, location (GPS/EXIF) and camera metadata are stripped from the photo. The scan inputs are not used to train AI models. Google says published Gemini models may keep an in-memory, project-isolated cache for up to 24 hours, and prompts flagged for abuse monitoring may be logged for up to 90 days. The details are below.

Follow-up chat is text-only. When you tap Send, the saved scan summary, recent chat turns, and your question are sent to the same Gemini service; your selfie is not sent again.

What we store on your device

Selfie image files are saved in LooksGauge's private on-device media storage. Scan records, results, and references to those files use SwiftData (Apple's on-device framework). Preferences and the remembered AI-consent choice use app-scoped local preferences. The free-scan usage count is kept redundantly in those preferences, a SwiftData usage ledger, and a high-water marker in the iOS Keychain, so neither deleting scan history nor reinstalling the app restores used runs. This local data includes:

  • Selfies: photos you take in the app or import from your library for scanning
  • Scan results: your Looks Score, Potential Score, per-area breakdown, tips, and trend history
  • Follow-up chat: local threads tied to each saved scan
  • Preferences and settings: including AI consent and the number of free AI analysis attempts used

LooksGauge marks its local selfie files and SwiftData store files for exclusion from Apple device backups. This uses Apple's backup-exclusion marker; it is a platform request, not a promise about systems outside the app's control.

Deleting scan history is self-service: use Settings → Delete scan history to remove locally saved selfies, scores, tips, and trend history. Preferences and the remembered AI-consent choice remain until you change them or uninstall the app. The free-scan usage count is different: it is reconciled against a marker stored in the iOS Keychain, so it survives an ordinary uninstall and reinstall on the same device. It enforces the three-free-scan allowance, so neither deleting history nor reinstalling restores used free scans. Apple and RevenueCat retain purchase records as described below so subscriptions and restores continue to work.

Face Data: collection, use, sharing, retention, and control

Apple uses the term Face Data broadly to include an uploaded photo used for facial analysis. In LooksGauge, Face Data is limited to the selfie image or images you deliberately take or select and include in a scan, and the scores and tips returned about visible, changeable presentation in those images.

  • How it is collected: you choose to take or select the required front selfie and may add an optional three-quarter-angle selfie. Only images you mark as included are used. LooksGauge performs no background, continuous, or automatic face capture.
  • How it is used: to generate the Looks Score, Potential Score, presentation-area feedback, and tips you request, and to save that result in your local progress history. The scores and tips from a saved result are also sent when you start one of the two follow-on flows yourself: a follow-up chat, which sends the saved scan summary, and an optional result report, which sends the result text shown in its preview. Face Data is never used for advertising, marketing, user profiling, or eligibility decisions.
  • What LooksGauge does not create: the app does not create, receive, or store a face mesh, facial map or model, facial coordinates or landmarks, depth data, face embedding or vector, biometric template, or facial-recognition identifier. It does not identify, authenticate, verify, or match a person.
  • Who receives the included images: only Google receives the metadata-stripped selfie image or images included in that scan, through Gemini via Firebase AI Logic with a Vertex AI backend, after you grant explicit consent and tap Scan. Google processes them to return the requested scores and feedback, and may retain a copy flagged for abuse monitoring for the window described below; it does not use them to train its models. LooksGauge receives no face geometry or biometric template from Google. LightPath keeps no cloud copy of the images.
  • Who does not receive it: RevenueCat, Firebase Remote Config, Firebase App Check, advertisers, analytics providers, data brokers, and information resellers receive no selfie or face-geometry/biometric data. If you separately submit an optional result report, the LightPath-operated reporting endpoint receives the result text and metadata shown in the preview, but never the selfie, face geometry, or a biometric identifier.

Google processes Face Data as our service provider. We require Google to use it only to the limited extent needed for the analysis you consented to and to provide the same or equal protection described in this policy and required by Apple. Face Data is not sold, licensed, or disclosed for advertising, marketing, analytics, data brokerage, identity matching, or AI model training.

Your on-device selfies and their results remain until you delete them. Google's processing copy follows the published retention windows described below: a project-isolated in-memory cache for up to 24 hours, and up to 90 days if a prompt, including its image and accompanying text, is flagged for abuse monitoring. An optional result report contains no selfie and is scheduled to expire after 180 days as described below.

You can withdraw permission for future Face Data processing in Settings → Allow AI photo analysis; this blocks further scan and chat submissions. Use Settings → Delete scan history to remove locally saved selfies and results, or uninstall the app to remove its local app-container data. Withdrawing permission or deleting local history cannot recall a processing copy already sent to Google; that copy ages out under the retention windows above. LightPath has no cloud selfie copy to retrieve or delete. See the privacy requests page for help with optional reports, subscription records, or other privacy questions.

What leaves your device, and when

AI scan analysis (only with your consent)

LooksGauge's scores and tips are generated by Google's Gemini model, reached through Firebase AI Logic with a Vertex AI backend. When — and only after — you have granted AI-analysis consent and tap Scan:

  • The app first strips EXIF/GPS location data and camera metadata from each selfie you included.
  • The stripped selfie or selfies, any optional note you wrote for this scan, and a brief summary of your most recent scored result are sent to Google (Gemini via Firebase, Vertex AI backend) solely to generate your scores and feedback.
  • These scan inputs are not used to train AI models. Google says published Gemini models may keep an in-memory, project-isolated cache for up to 24 hours, and prompts (including the image and accompanying text) flagged for abuse monitoring may be logged for up to 90 days.
  • The scores and tips come back to your device and are saved in your local scan history. They are sent to LightPath only if you later choose to report that result.

If you never run a scan, no photo ever leaves your device.

Follow-up chat (text only, sent on demand)

For a scored scan, you may ask questions about its changeable presentation tips. When you tap Send, LooksGauge sends a compact saved-result summary, a bounded set of recent text turns, and your question to Google Gemini. It does not resend the selfie. Declined or unscored scans cannot enter chat.

Chat includes 10 successful replies per day on the free tier; Pro follow-up chat is unlimited. Separate abuse-prevention ceilings allow up to 30 actual provider attempts per day on the free tier and up to 100 on Pro, including fallback attempts. Daily usage counts are stored locally and in the iOS Keychain so uninstalling and reinstalling does not reset the same-day allowance.

Model configuration (Firebase Remote Config)

When the app launches it checks Firebase Remote Config for which Gemini model version to use. This exists so that if Google retires a model, already-installed copies of LooksGauge keep working without waiting for an app update. Firebase may receive technical metadata needed to provide this service, including a Firebase installation identifier, app version and build, device language, fetch time, and country inferred from the request's IP address. The request contains no photo or scan result; it is one of the service calls the app makes before AI consent, and LightPath does not use it for advertising or behavioral profiling. RevenueCat also checks subscription status and available products at launch. It may receive an anonymous app-user identifier, device and operating-system information, app version, product and transaction information, entitlement status, related service timestamps, and a coarse country inferred from the request's IP address. That traffic contains no photo or scan result.

Reporting an AI result (only if you choose to)

If a result is unkind, wrong, or crosses a line, you can report it from the result screen. This is entirely optional and never automatic. Before sending, the app shows you exactly what will be sent: the reason you picked, any comment you type, the AI's own output you are reporting, the result ID and the times the result and report were created, app name and version, platform, model used, whether a fallback model was used, whether output was truncated, and an anonymous per-install identifier that exists only so we can rate-limit abuse — it is not tied to an account and resets if you uninstall the app or clear its storage. Your selfie is never included. Reports go to a LightPath-operated endpoint (a Google Cloud Function in our Firebase project), and may be reviewed by LightPath to investigate the reported result. Each report receives an expiration time 180 days after submission. Firestore's TTL process usually deletes expired records within 24 hours after that time. You can also request earlier deletion through the privacy-requests page; because there is no account, include the anonymous install ID and result ID shown in the report preview if you still have them.

The endpoint also writes limited operational events to Google Cloud Logging: app, platform, report reason, model, whether processing failed, and a non-content error type on failures. A rate-limit event also contains the quota ceiling and a stable, truncated 12-character one-way SHA-256 derivative of the anonymous install ID, solely to diagnose repeated rate-limit abuse. Those logs deliberately exclude the selfie, report and result IDs, raw anonymous install ID, your comment, the AI output, and raw error messages. The truncated hash may link rate-limit events from the same installation while retained, but cannot identify an account or a specific report after its document is deleted. Operational logs follow the project's log-retention settings and are not automatically deleted when a report document expires or is deleted. You may request their deletion through the privacy-requests page; include the anonymous install ID so we can locate matching rate-limit events where reasonably possible, subject to security and legal retention needs.

App integrity check (Firebase App Check)

To confirm that scan and result-report requests come from a genuine, unmodified copy of LooksGauge, the app uses Firebase App Check with Apple's App Attest. This attestation contains no photos and no personal content — it exists to prevent abuse of the scanning service.

Subscriptions (RevenueCat)

LooksGauge Pro subscriptions are purchased through Apple's StoreKit and managed with RevenueCat, which processes your subscription and entitlement state (whether your device has an active Pro subscription) so the app can unlock Pro features and restore purchases. RevenueCat receives the anonymous identifier and technical, product, transaction, and entitlement details described above. It does not receive your photos, scores, or an account identity — there are no LooksGauge accounts. RevenueCat uses purchase history for Customer History, Charts, and Experiments analytics, and for app functionality such as receipt validation, entitlement checks, and purchase restores. RevenueCat may infer a coarse country from the request's IP address. Payment itself is handled by Apple under Apple's own privacy policy.

In Settings, LooksGauge shows the anonymous RevenueCat subscription support ID used by this installation. Include that ID if you ask LightPath to locate or delete RevenueCat records. RevenueCat may retain transaction or entitlement records as needed to provide purchase restoration, prevent fraud, and meet legal obligations; deleting them may limit our ability to help restore a purchase.

Third-party processors

LooksGauge uses four third-party services, each named above:

  • Google — Gemini via Firebase AI Logic (Vertex AI backend), to analyze a stripped selfie, optional scan note, and brief prior-result summary only after your consent
  • Firebase App Check (App Attest) — app-integrity verification for scan and result-report requests
  • Firebase Remote Config — which Gemini model version the app should use
  • RevenueCat — subscription and entitlement management for LooksGauge Pro, including purchase-history analytics for Customer History, Charts, and Experiments

We select processors whose published terms and contractual commitments provide privacy and security protections appropriate to the service they perform. Their own policies govern their processing as described here.

The only LightPath-operated endpoint is the reporting endpoint described above, and it is reached only when you choose to report a result. No LightPath server is involved in scanning, in storing your photos or results, or in anything the app does on its own.

What LooksGauge does NOT collect

  • No accounts and no sign-in
  • No first-party product-event analytics or behavioral profiling about your scans or how you use the app; Firebase and RevenueCat receive only the technical and service data described above
  • No tracking and no advertising identifiers
  • No precise or GPS location; location metadata is stripped from selfies before analysis, although Firebase and RevenueCat may infer a coarse country from an IP address when providing their services
  • No routine in-app collection of your name, email address, or other contact information

If you voluntarily email support or submit the privacy-request form, your own mail app sends LightPath the name, email address, and details you provide. We use that correspondence to answer your request, troubleshoot, protect the service, and meet legal obligations. We retain it only as long as reasonably needed for those purposes, and you may ask us to delete it unless we must keep it for security or legal reasons.

Data retention and deletion

  • On your device: selfies and scan results stay until you delete them. Use Settings → Delete scan history to remove that local history. The app retains its local free-scan usage count so deletion does not restore used free scans. Uninstalling LooksGauge removes local preferences, the remembered AI-consent choice, and the anonymous report identifier, but not the Keychain high-water marker: the free-scan usage count survives an ordinary uninstall and reinstall on the same device.
  • At Google: scan inputs (the stripped selfie, optional note, and brief prior-result summary) are never used to train models. Google says published Gemini models may keep an in-memory, project-isolated cache for up to 24 hours, and prompts flagged for abuse monitoring may be logged for up to 90 days.
  • At RevenueCat: subscription/entitlement records exist to keep your Pro purchase working (including restores). They contain no photos or scan content. Contact us with the subscription support ID shown in Settings to request record deletion; some records may be retained as needed for restores, fraud prevention, or legal obligations.
  • Reports you choose to send: a report may be reviewed to investigate the result. It is scheduled to expire 180 days after submission, and Firestore's TTL process usually deletes expired records within 24 hours after that time. It contains no photo. You may request earlier deletion using the identifiers shown before sending.
  • Support and privacy correspondence: retained only as long as reasonably needed to answer the request, troubleshoot, protect the service, or meet legal obligations.

LightPath keeps no routine first-party cloud history of your photos or scan results. An optional report you submit can include the reported result content and is scheduled to expire after 180 days. Google processing and RevenueCat subscription records are the other separate cases described above. If you have questions or want help, see our privacy requests page or email us.

Permissions LooksGauge requests

LooksGauge requests one permission, which is optional and shown with this exact explanation in iOS:

  • Camera: "LooksGauge uses the camera so you can take a selfie for your glow-up scan. Photos stay on your device unless you tap Scan."

Importing an existing selfie uses Apple's system photo picker, which does not give LooksGauge broad access to your photo library and does not require a Photos permission. That's the entire list: the app does not request location, microphone, contacts, or any other permission. You can change camera access at any time in iOS Settings → Privacy & Security.

Children's privacy

LooksGauge is not directed at children under 13 and we do not knowingly collect data from them. The app keeps routine photos and scan history in private app storage, requires explicit consent before any scan is analyzed, and maintains no accounts. A result is stored by LightPath only when a user deliberately submits the optional report described above.

Changes to this policy

We may update this privacy policy from time to time. Changes will be reflected on this page with an updated revision date at the top. Because LooksGauge has no account or in-app contact list, we cannot notify all users directly — please check this page if you want to confirm the current version.

Contact

If you have questions about this privacy policy or about LooksGauge's privacy practices, please contact us at:

Privacy by design

LooksGauge is private by default — no account, no behavioral analytics about your scans or app usage, no tracking. Stripped copies of the selfies you included, an optional scan note, and brief prior-result summary leave your device only after you grant AI-analysis consent and tap Scan, with metadata stripped first. Google says published Gemini models may cache the request in memory for up to 24 hours and may log prompts flagged for abuse monitoring for up to 90 days; they are never used for training. Follow-up chat sends bounded text context only when you tap Send and never resends your selfie. Your face is yours.