Privacy Policy
Last updated: August 28, 2026
1.About This Policy
Chromyne (“we,” “our,” or “us”) is a beauty and style recommendation app. This policy explains how we collect, use, and protect your information when you use Chromyne on iOS or Android.
2.Information We Collect
- Photos you provide (face data): You may upload or take a selfie to receive style recommendations. We use this photo only to generate your color analysis, makeup, and styling results — for example, estimating your undertone, contrast, and general face shape for styling purposes. We do not use selfies to identify you, verify your identity, run facial recognition, create a biometric template or faceprint, or make any biometric identity claims.
- App activity: We collect screen views, funnel actions, and paywall events to understand how the app is used and improve the experience.
- Purchase information: We collect your subscription status and purchase history to deliver premium features. Purchases are processed by Apple App Store, Google Play, and RevenueCat.
- Crash and diagnostic data: We collect crash logs and performance data to fix bugs and improve stability, processed by Sentry.
- Analytics: We use PostHog to collect anonymized usage analytics. No personal profiles are sold to advertisers.
- Referral and device identifiers: If you reach Chromyne through a creator's referral link, we collect a device identifier (your Android ID or iOS vendor identifier), and the IP address and time of your link click, in order to attribute your installation and any subscription to the correct creator. See Section 5.
- Advertising and measurement data: If you install the app after seeing a TikTok ad, or visit this website, we and TikTok may collect device and activity information — such as your device advertising identifier (on iOS, only if you allow tracking when asked), IP address, and the specific app or website actions listed in Section 5 — so we can measure whether our advertising works. We never send your selfie, your face data, or your generated images to any advertising platform.
- Account identifier: If you use premium features, we associate a RevenueCat app user ID with your purchases.
3.How We Use Your Information
We use your information to: generate your personalized style report; deliver and restore premium access; improve app quality and fix bugs; respond to support requests; and comply with legal obligations.
4.Data Sharing, Including Your Photo and Face Data
We share data only with the service providers that help us operate the app:
- OpenAI and Google (Gemini API) — your selfie photo is sent to these AI providers in real time so they can analyze it (undertone, contrast, face shape) and, for premium users, generate an AI makeup preview image. Before your first photo is analyzed, the app shows an in-app disclosure naming these providers and asks you to agree before any photo is sent. These providers process the photo only to fulfill that specific request; we do not permit them to use your photo to train their general-purpose AI models, and we do not send your name, email, or account identifier along with the image. OpenAI and Google are bound by their respective API terms of service to handle any face data we send them with confidentiality and security protections consistent with this Privacy Policy, and to use it only to provide the requested analysis — not for any other purpose.
- Supabase (for secure cloud storage of AI-generated report data and AI-generated preview images — see Data Retention below for what this does and does not include)
- RevenueCat (for subscription management)
- PostHog (for anonymized analytics)
- Sentry (for crash reporting)
- TikTok (for advertising measurement and attribution — see Section 5)
- Creators in our referral programme (a creator who referred you can see that a subscription happened, its date and amount, and a short reference code that cannot be traced back to you — never your name, email, photos, results, or any way to identify you; see Section 5)
We do not sell your personal data. We never share your selfie, your face data, or your generated images with advertisers or third-party marketing platforms. We do share a limited set of device identifiers and advertising events with TikTok so we can measure our advertising, as described in Section 5.
5.Advertising, Attribution, and Cookies
We advertise Chromyne on TikTok. To understand which ads actually lead to installs and subscriptions — rather than guessing — we share a limited amount of information with TikTok. This section explains exactly what.
In the app. The app includes the TikTok Business SDK. It reports that the app was installed and opened, and reports these specific milestones: completing onboarding, viewing a style report or preview, reaching the subscription screen, starting a purchase, and completing a purchase (including the amount and currency). On iOS, your device advertising identifier (IDFA) is included only if you allow tracking when the system asks you; if you decline, these events are still counted but are not linked to your advertising identifier. On Android, your Google Advertising ID may be included.
On this website. We use the TikTok pixel on chromyne.app. It records page views and clicks on our App Store and Google Play buttons, together with your IP address, browser and device information, and a cookie-based identifier set by TikTok.
Creator referral attribution. Chromyne runs a creator referral programme. When you open a creator's referral link (a chromyne.app/r/ address), we record that the link was opened, along with your IP address, your browser and device information, and which creator the link belongs to. If you then install the app, we use one of the following to connect that install back to the creator who referred you, so we can pay them correctly:
- On Android — the Google Play install referrer, which carries a reference to your original link click through the Play Store, together with your device's Android ID (an identifier specific to Chromyne on your device).
- On iOS — Apple provides no equivalent, so we compare the IP address and time of your app's first launch against recent link clicks, together with your device's vendor identifier (an identifier specific to Chromyne on your device). This is an inference, not a certainty, and we discard it when it is ambiguous.
We keep the IP address and browser information from a referral link click only for as long as they can serve that purpose — one hour — and erase them after that. The record that the link was opened is kept without them. The device identifiers above are stored for as long as the referral relationship needs to be accounted for, and are used only to attribute installs and subscriptions to the correct creator — never to build an advertising profile of you, and never shared with advertising platforms. If you subscribe, we record which creator referred you and the amount of their commission. In their dashboard a creator sees the date, the amount, and a short reference code derived from your internal record — never your name, your email, your photos, your results, or anything that could identify you.
What we never send. Your selfie, your face data, your generated images, and your report contents are never sent to TikTok or any other advertising platform.
How to opt out. On iOS, decline the tracking prompt, or go to Settings → Privacy & Security → Tracking and turn off tracking for Chromyne. On Android, go to Settings → Google → Ads to delete or reset your advertising ID. On this website, you can decline advertising cookies when asked and block cookies in your browser settings. You can also contact privacy@chromyne.app and we will action your request directly.
The creator referral attribution described above is separate from advertising tracking and is not covered by the iOS tracking prompt. To opt out of it, or to have a referral record connected to your device deleted, email privacy@chromyne.app.
TikTok processes this information as an independent controller for its own purposes as well. Its handling of that data is governed by TikTok’s own privacy policy.
6.Data Retention and Deletion — Photos and Face Data
Your original selfie is used only to generate your single analysis request. It is transmitted to our AI providers (OpenAI, Google) for that request and is not permanently stored on Chromyne's own servers. AI-generated preview images created for your report (such as a makeup preview) are stored securely in our cloud storage (Supabase) so we can display your report and let you revisit it. We are implementing a 12-month retention limit for these generated images, after which they will be deleted automatically. Until that automatic deletion is live, generated images are retained until you delete them or request account deletion. You can request deletion of your photos, generated images, reports, and account data at any time from the app's Settings screen or by contacting privacy@chromyne.app. We process deletion requests within 30 days.
7.Your Rights, Consent, and Data Deletion
Revoking consent for face data: Granting consent to analyze a selfie is never permanent. You can withdraw your consent for us to collect or use your face data at any time by opening the app and going to Settings → Face data consent → Withdraw. Once withdrawn, we will not analyze any new photo until you agree again — you'll see the same in-app disclosure and consent prompt the next time you start a report. Withdrawing consent does not automatically delete photos or reports we already processed; see below to delete those. You can also withdraw consent by uninstalling the app, which removes your on-device consent record.
Deleting your data: You may request deletion of your uploaded images, generated results, saved reports, and any account data at any time by using "Delete selfie data" in the app's Settings screen or by emailing privacy@chromyne.app. We will process your request within 30 days. You can also delete locally cached data by uninstalling the app.
8.GDPR — Your Rights If You Are in the EU, EEA, or UK
If you are located in the European Union, European Economic Area, or United Kingdom, the following applies to our processing of your personal data.
Lawful basis for processing. We rely on the following legal bases under Article 6 of the GDPR:
- Consent — for analyzing your selfie/face data to generate your color and style results. You can withdraw this consent at any time (see Section 7).
- Consent — for advertising measurement and attribution through TikTok (Section 5). On iOS we ask through Apple’s App Tracking Transparency prompt; on this website we ask before any advertising cookie or pixel is set. You can withdraw this consent at any time using the controls in Section 5.
- Legitimate interests — for app analytics (PostHog) and crash/diagnostic reporting (Sentry), which we use to keep the app working and improve it. You may object to this processing as described below.
- Performance of a contract — for processing purchase and subscription information needed to deliver premium features you have purchased.
Your rights. Subject to applicable law, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure of your data; request restriction of processing; receive your data in a portable format; and object to processing based on legitimate interests. To exercise any of these rights, contact privacy@chromyne.app. You also have the right to lodge a complaint with your local data protection supervisory authority.
EU representative. Chromyne is operated by Nazam LLC, a US company without an establishment in the EU. As of this policy’s last update, we have not yet appointed an EU representative under Article 27 of the GDPR. We are working to address this requirement; in the meantime, EU-related privacy inquiries can be directed to privacy@chromyne.app.
International data transfers. Some of our service providers — OpenAI, Google, Supabase, PostHog, Sentry, and TikTok — process data outside the EU/EEA/UK, including in the United States. Where we transfer personal data internationally, we rely on the European Commission’s Standard Contractual Clauses (SCCs) or an equivalent recognized transfer mechanism with those providers.
9.CCPA / CPRA — Your Rights If You Are a California Resident
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following rights over your personal information:
- Right to know what personal information we collect, use, and disclose about you.
- Right to delete personal information we have collected from you, subject to certain exceptions.
- Right to correct inaccurate personal information we hold about you.
- Right to opt out of the sale or sharing of your personal information.
- Right to limit use and disclosure of sensitive personal information (such as your selfie photo) to what is necessary to provide the app’s features.
- Right to non-discrimination for exercising any of these rights.
We do not sell your personal data. We do share a limited set of device identifiers and advertising events with TikTok for cross-context behavioral advertising, as described in Section 5. You can opt out at any time: on iOS by declining or revoking App Tracking Transparency permission, on Android by deleting or resetting your advertising ID, and on this website by declining advertising cookies. To opt out directly, or to exercise any other CCPA/CPRA right, contact privacy@chromyne.app. We will verify your request and respond within the timeframes required by law.
10.Children’s Privacy
Chromyne is not directed to children under 13. We do not knowingly collect information from children under 13.
11.Security
All data is encrypted in transit. We follow industry-standard practices to protect your information.
12.Changes to This Policy
We may update this policy from time to time. We will update the “Last updated” date at the top of this page. Continued use of the app after changes constitutes acceptance.
13.Contact
For privacy questions or data deletion requests:
Email: privacy@chromyne.app
Website: chromyne.app