← BaldAI
Privacy Policy
Effective: July 10, 2026
BaldAI ("we", "the app") is a visual hair-tracking application. This policy explains
what data we collect, why, and what control you have over it. The short version:
your photos stay in a private vault, are used only to generate
your own results, and everything is permanently deleted when you delete your account.
What we collect
- Account: an anonymous account identifier created on first launch. No email,
name or phone number is required to use BaldAI.
- Onboarding answers: your hair concerns, tracked zones, and goals — used to
personalize your tracking plan.
- Photos: hair scan photos and shed-count photos you choose to take. Location
metadata is never attached (the app does not request location access).
- Logs: the daily hair log entries you submit (predefined options only).
- Subscription status: processed by Apple and RevenueCat; we never see your
payment details.
- Usage & crash data: anonymous product analytics (PostHog) and crash reports
(Sentry) to keep the app working.
How your photos are handled
- Stored encrypted in transit and at rest, in a private storage bucket
(hosted on Supabase, EU — Frankfurt). Photos are accessible only to your account via
short-lived signed links.
- To compute your metrics, photos are processed by Google's Gemini API on our behalf.
They are used solely to generate your results and are not used to train
AI models.
- We never sell, share, or publish your photos. No human reviews them.
Face Data
The hair-scan photos you take may show your face. Because of that, we want to be
unambiguous about how this imagery is handled:
- What we collect: photographs of your head and hairline that you choose
to take for hair tracking. Your face may be visible in these photos. We do
not perform face recognition, face mapping, or
biometric identification of any kind, and we do not extract, generate, or store
faceprints, facial geometry, or any other biometric data.
- What it is used for: solely to analyze your hair (hairline, density and
related hair metrics) and to show your own progress over time — never for identification,
advertising, or training AI models.
- Where it is stored: in a private, access-controlled storage bucket on
Supabase (AWS eu-central-1, Frankfurt, EU), encrypted in transit and at rest. Photos are
linked only to your account; no other user can access them.
- Who it is shared with: only Google's Gemini API, which processes each
photo one time to compute your hair metrics (see
Third-Party AI Processing below). No other third party
receives your photos, and they are never sold or shared for advertising.
- How long it is kept: until you delete the scan it belongs to, or delete
your account — whichever happens first.
- How to delete it: delete individual scans in the app at any time, or use
Settings → Delete account to permanently erase all photos and
associated data. Deletion is irreversible.
Third-Party AI Processing (Google Gemini)
BaldAI uses Google's Gemini API to analyze your hair-scan photos on our behalf.
- What is sent: the hair-scan photo you submit for analysis, which may
include your face. We do not send your name, email address, or any other identifying
profile information with it.
- To whom and why: to Google (Gemini API), for a one-time automated
analysis that returns your hair metrics. The photo is not used by us or by Google to
train AI models, and no human reviews it.
- Your consent: the app asks for your consent before your photos are
submitted for analysis; no photo is sent to Google without it.
- Protection at Google: Google processes this data as a service provider
under the Gemini API Terms of
Service and Google Cloud's data processing terms, which impose confidentiality and
data-protection obligations at least equal to those in this policy.
What we don't do
- We don't sell your data. To anyone. Ever.
- We don't run third-party advertising or cross-app tracking.
- We don't diagnose: BaldAI is a visual tracking tool, not a medical device.
Data retention & deletion
Everything is kept only while your account exists. Delete it any time in
Settings → Delete account & data — this permanently removes your photos,
scans, counts, logs, reports and account. It cannot be undone. You can also request deletion
by email: keanexl1@gmail.com — see
account deletion.
Service providers
Supabase (data hosting, EU), Google Gemini API (photo analysis), Apple & RevenueCat
(subscriptions), PostHog (analytics), Sentry (crash reporting). Each receives only what it
needs to perform its function.
Children
BaldAI is not directed at children under 13 and we do not knowingly collect their data.
Changes & contact
We'll update this page if our practices change. Questions:
keanexl1@gmail.com