Privacy Policy
Last updated: July 27, 2026 · Consent text version 2026-07-22.1
What we collect
- Your photo — the selfie you upload for color analysis, and any photo you upload for the try-on studio (plus the try-on images we generate from them, which we treat exactly like your photo).
- Your quiz answers — eye color, hair color, and style preferences.
- Your email — to deliver your report.
- Purchase records — handled by Stripe; we never see or store your card number.
- Technical & security data — your IP address and browser user-agent, recorded when you purchase or upload a photo. We use these only to run the service securely, prevent fraud, and defend against payment disputes (chargebacks) — never to identify you.
How your photo is handled (the important part)
- Your photo is analyzed on our servers to extract skin, hair and eye colors — the analysis output is a set of color values and scores, not an image.
- It is stored encrypted (AES-256-GCM), with location metadata (EXIF) removed on upload, and is accessible only to you.
- We never create or store a face template, never use your photo to identify you, never match faces across users, and never sell or share your photo.
Retention & destruction schedule
Retention & destruction schedule: uploaded photos (and try-on images created from them) are retained for a maximum of 30 days from upload, then permanently destroyed by an automated purge job. Derived results (your season and palette) contain no photo or biometric data and are kept with your report.
You can also delete your photo (and any try-on images) immediately, any time, with the “Delete my photo now” control on your report page. Deletion is permanent and removes both the encrypted files and their records.
What survives past 30 days: your derived result only — season name, palette color values, and the written report. None of that contains your photo or any biometric identifier.
The IP address recorded with a photo upload is deleted together with the photo. The IP recorded with a purchase stays with your order and receipt records, which we keep for fraud protection, payment-dispute defense, and accounting.
Biometric privacy notice (Illinois, Texas, Washington)
Some states regulate “biometric identifiers.” We design for the strictest reading: we collect your photo only with your explicit written consent (recorded with a version and timestamp), we publish this retention/destruction schedule, we destroy photos within 30 days or sooner at your request, and we never create face geometry templates or perform face matching. Consent is enforced on our servers at every endpoint that touches photo data — not just in the interface.
Service providers
Supabase (encrypted storage & database), Vercel (hosting and privacy-friendly page analytics), Stripe (payments), Meta and Google (advertising measurement on our marketing pages). Photo bytes live only in encrypted storage; payment, analytics and advertising providers never receive them.
Page analytics and advertising tags run on our public marketing pages only. They are switched off on your report pages, so the private link to your report is never shared with an analytics or advertising provider.
If you reach us from an ad and then buy, we tell Meta and Google that the purchase happened, so we can tell which ads are worth running. That message contains the amount, the currency, an order reference, and a scrambled (hashed) copy of your email address — scrambled in your browser before it is sent, so neither company receives your address in readable form. It is used only to match the purchase to the ad you clicked. We never send your photo, your color result, or anything derived from your photo to an advertising provider.
When you request a try-on render in the studio, your photo is sent to Google (Gemini API) solely to generate that render, then the result is stored encrypted under the same 30-day deletion schedule as your photo. We send renders one at a time, never your name or account details alongside them, and Google processes them under its API data-use terms. If you delete your photo, there is nothing left for us to send.
What this product is
Palettewell provides style and color guidance for fun and confidence. It is not a medical, dermatological, or diagnostic service.
If there is a breach
If a breach affects your personal information — including a photo or any biometric identifier derived from it — we will notify you as the law requires: within 30 days for New York residents under the New York SHIELD Act, and as otherwise required by state and federal breach-notification law.
Contact
Privacy questions or deletion requests: support@palettewell.com.
Lyra Ventures LLC
348 4th Avenue Ste 1031, Brooklyn, NY 11215, United States