Privacy Policy — Lookmaxx AI
Effective date: 29 May 2026
Last updated: 29 May 2026
Privacy at a glance
Eight things to know in plain English:
- Your data lives on your iPhone. Almost everything Lookmaxx AI creates about you — your face scan results, your photos, your scores, your routines, your workouts — is stored only on your device. We do not run a server that holds your data.
- We do not run analytics, ad networks, or crash reporters. No SDK is silently watching how you use the app.
- Two things leave your phone: subscription receipts go to Apple, and (only when you ask) your selfie and the chosen reference style image go to Google's Gemini AI to generate a try-on preview or an AI Coach reply.
- Google Gemini is the only third-party AI we use. We name it openly and ask for your explicit, in-app consent the first time before any photo or message is sent.
- You can wipe everything in two taps. Settings → Reset Data — or just delete the app. There is nothing on a server of ours to delete.
- HealthKit data stays on your device. It is never sent to Google, never used for ads, never shared.
- We do not knowingly collect data from anyone under 18. This app is built for adults.
- You have full rights under GDPR and CCPA — access, deletion, opt-out, the lot. See section 11.
If you want the full detail, the table of contents is right below.
Table of contents
- Who we are
- Scope and acceptance
- The data we collect, why, and where it lives
- Google Gemini AI — what we send, why, and your consent
- EU AI Act transparency notice
- HealthKit-specific commitments
- Subscriptions and billing
- International data transfers
- Retention — how long we keep things
- Children
- Your rights
- California ADMT pre-use notice
- Security
- Data breach notification
- Changes to this policy
- Contact us
1. Who we are
Lookmaxx AI is operated by Maksym Televiak, an individual sole proprietor based in Ukraine.
- Data controller (GDPR): Maksym Televiak
- Email: maks.televyak@gmail.com
- Postal address: I. Franka St., 4, apt. 10, Smyha, Rivne Oblast 35680, Ukraine
We are not currently established in the European Union, the United Kingdom, or the United States. Under Article 27 of the GDPR, a data controller outside the EU that offers its services to people in the EU must, in most cases, designate a written representative inside the EU.
At our current scale, we are not yet required to appoint such a representative under the practical thresholds in Article 27(2)(a). If our monthly active users from the EU cross those thresholds, we will appoint an Article 27 representative and update this policy with their details. In the meantime, EU and UK users can reach us directly at the email above for any privacy-related request, and we will respond within 30 days.
2. Scope and acceptance
This policy explains how Lookmaxx AI handles your personal information. It applies to the iOS app distributed through the Apple App Store, and to any communication you send us at the email above.
It does not cover:
By installing or using Lookmaxx AI, you confirm that you have read this policy. We do not, however, treat your continued use as consent for activities that the law — in particular GDPR Article 9 for biometric and health data, and the CCPA for sensitive personal information — requires us to obtain through an explicit, separate in-app action. Those activities are gated by their own consent prompts.
3. The data we collect, why, and where it lives
Below is every category of personal data Lookmaxx AI may handle. For each one we tell you what it is, why we use it, the lawful basis under the GDPR, where the data physically sits, and how long we keep it.
We never sell your personal information, and we do not share it for cross-context behavioural advertising. We do not engage in "selling" or "sharing" as those terms are defined under the CCPA.
3.1 Face scan image and derived facial geometry
- What it is: A photo of your face captured through the iPhone front camera during the in-app face scan, and the numeric scores Lookmaxx AI computes from it on your device (jawline, symmetry, skin, hair density, overall aesthetic score).
- Why we use it: To show you those scores and to suggest hairstyles, beard styles, skincare routines, and exercises that suit your features.
- Special category: Yes. Biometric data used to uniquely identify a person is a special category under GDPR Article 9. Even though we do not use the data to identify you — only to compute aesthetic scores about you — we treat it under the strictest tier as a matter of caution.
- GDPR lawful basis: Article 9(2)(a) — your explicit consent, captured by the in-app prompt before the first scan. Article 6(1)(a) at the general level.
- Where it lives: On your device only, inside the app's Documents directory and a SwiftData database. Never uploaded to any server controlled by us.
- How long: Until you delete the scan from in-app history, tap Reset Data in Settings, or delete the app — whichever comes first.
3.2 Selfies and reference images used for AI Try-On
- What it is: When you tap "AI Try-On" on a hairstyle or beard, the app prepares two images — your most recent face-scan selfie (or a photo you pick from your Photo Library) and the reference style image — and sends them to Google's Gemini API.
- Why we use it: To generate a single photorealistic preview of you with the chosen style. The generated image is shown back to you in the app.
- Special category: Yes. A picture of your face is biometric data under GDPR Article 9 because Gemini is performing facial analysis to produce the new image.
- GDPR lawful basis: Article 9(2)(a) explicit consent, captured by the dedicated AI consent dialog shown before the first AI Try-On. You can revoke this consent at any time in Settings → Privacy → Revoke AI Consent.
- Where it lives:
- Outbound: each request is transmitted over TLS 1.2+ to
generativelanguage.googleapis.com. Google's published Generative AI Privacy Notice for the paid API tier states that prompts and outputs are not used to train Google's models, and that data is retained only briefly to detect abuse and meet legal obligations.
- Inbound: the returned image is cached on your device under
Documents/ai_tryon/ so we don't burn another API call if you reopen the same style.
- How long: The on-device cache is cleared when you tap Settings → Clear AI Cache, Reset Data, or delete the app. Google's retention is governed by Google's terms — see section 4 for the link.
3.3 AI Coach chat messages
- What it is: Text you type to the AI Coach, plus a system-prompt summary of your stored profile (age range, fitness level, dietary preferences, face scan scores).
- Why we use it: To send the chat to Google Gemini so it can produce a tailored reply.
- Special category: Potentially yes, because the profile summary may mention health and biometric attributes. Treated under Article 9 as a precaution.
- GDPR lawful basis: Article 9(2)(a) explicit consent (covered by the AI consent dialog).
- Where it lives: Locally on the device, so the chat persists between sessions. Each new message is transmitted to Google as in 3.2.
- How long: Until you clear the chat in-app, tap Reset Data, or delete the app.
3.4 Profile data you enter yourself
- What it is: Age, biological sex, height, weight, activity level, fitness goal, hair type, skin concerns, glow-up priority, optional name.
- Why we use it: To compute calorie targets, recommend programmes, and personalise content.
- Special category: Yes — weight, height, fitness/health data and some skin information qualify as health data under GDPR Article 9 in some jurisdictions.
- GDPR lawful basis: Article 6(1)(b) — performance of our service to you (a contract); Article 9(2)(a) — your explicit consent given through the onboarding flow for any special-category fields.
- Where it lives: On your device only, inside Apple's
UserDefaults and a SwiftData database. We do not have a copy.
- How long: Until you tap Reset Data or delete the app.
3.5 Workout logs, weight history, body measurements
- What it is: Reps, sets, weight lifted, bodyweight readings, waist/chest/arm/hip circumferences you log over time.
- Why we use it: To draw your progress charts and let you see trends.
- Special category: Yes — health data under GDPR Article 9.
- GDPR lawful basis: Article 6(1)(b) and Article 9(2)(a).
- Where it lives: On your device only.
- How long: Until you delete an entry, tap Reset Data, or delete the app.
3.6 HealthKit data (only if you enable it)
- What it is: Workouts you complete, bodyweight, and body measurements read from or written to Apple HealthKit if you grant the permission.
- Why we use it: To sync the progress charts you see in the app with the data Apple Health already holds, and to write your in-app workouts back to Health.
- Special category: Yes — health data.
- GDPR lawful basis: Article 9(2)(a) — explicit consent granted through Apple's HealthKit permission dialog.
- Where it lives: Entirely on your device, inside Apple's HealthKit store. Lookmaxx AI never transmits HealthKit data to Google or to anyone else. See section 6 for our binding HealthKit commitments.
- How long: HealthKit data remains in Apple Health regardless of whether Lookmaxx AI is installed. You can revoke our access in iOS Settings → Privacy & Security → Health → Lookmaxx AI.
3.7 Bookmarks and saved content
- What it is: The hairstyles, beards, meals, and exercises you tap the bookmark icon on.
- Why we use it: To keep your favourites in one place.
- GDPR lawful basis: Article 6(1)(b).
- Where it lives: On your device.
- How long: Until you unbookmark, Reset Data, or delete the app.
3.8 Subscription and receipt data
- What it is: Apple App Store identifiers (such as the transaction ID and original transaction ID) for any in-app purchase you make, the subscription product you bought (monthly or annual), expiry dates, and renewal status.
- Why we use it: To know whether you have premium access and to unlock the relevant features.
- GDPR lawful basis: Article 6(1)(b) — performance of the subscription contract you entered into with us through Apple.
- Where it lives: On your device, inside the secure StoreKit subsystem maintained by Apple. We do not receive your name, billing address, card number, or any other payment detail — Apple handles all of that, and we never see it.
- How long: As long as the StoreKit transaction remains active. Apple's own retention of payment data is governed by Apple's policies.
3.9 Device permissions and on-device system data
- Camera — needed for the face scan and to take a fresh photo for AI Try-On. We use the camera only while you are actively using those screens.
- Photo library — needed if you choose a saved photo instead of taking a new one. We only read the single image you pick; we do not scan your library.
- Notifications — needed if you opt into reminders for workouts, skincare routines, or hydration. You can turn this off in iOS Settings at any time.
- App-generated identifiers — a random UUID stored locally to label your own data on your own device. It is not a tracking identifier and is not shared.
We do not collect IP addresses, device fingerprints, advertising identifiers (IDFA), precise geolocation, contacts, microphone audio, or any other category not listed above.
4. Google Gemini AI — what we send, why, and your consent
This section exists because Apple's App Review Guideline 5.1.2(i) — updated in November 2025 — requires apps to name third-party AI providers explicitly, explain what is sent, and obtain user permission before any data is transmitted. Here is the whole picture, with no euphemisms.
4.1 Who Google is, in this context
Google is the only third-party AI provider Lookmaxx AI uses. Specifically, the app talks to Google Gemini through Google's Generative Language API, hosted at generativelanguage.googleapis.com. Two models are used:
- Gemini 2.5 Flash Image (also marketed as "Nano Banana Pro") — for AI Try-On, the photorealistic hair/beard preview;
- Gemini 2.5 Flash — for the AI Coach text chat.
4.2 What we send to Google
- For AI Try-On: the user-selected selfie (down-scaled to 1024 pixels on the long edge, JPEG-compressed) and the chosen reference style image, plus a text prompt that names the style and instructs the model to preserve your identity.
- For AI Coach: the current message you typed, the last twelve messages of your chat history with the Coach, and a one-paragraph summary of your stored profile (e.g. "user goal: hair growth; face shape: oval; activity: moderate").
Nothing else — no contacts list, no other photos, no HealthKit data, no device identifiers, no IP-based location tags added by us. Google may, separately, log standard request metadata for its own service operation; that is Google's processing under its own terms.
4.3 Why we send it
To generate the AI Try-On image you asked to see, or to compose the AI Coach reply you are waiting for. We have no other reason to send any data to Google.
4.4 What Google does with it
Google's published terms for the paid Gemini API state that:
- Your prompts and Google's responses are not used to train Google's models. They are not shown to a human reviewer for that purpose.
- Google may retain request data briefly to enforce its acceptable-use policy, detect abuse, and meet legal obligations.
- Google processes data primarily in the United States.
You should read Google's own documents for the authoritative version:
4.5 How we obtain your explicit consent
The first time you tap "Generate AI Try-On" or send a message to the AI Coach, Lookmaxx AI shows a full-screen consent dialog that:
- Names Google Gemini as the recipient;
- States what will be sent (your photo, or your chat plus a profile summary);
- Links to Google's policies above and to this Privacy Policy;
- Has two clear buttons: "Agree and continue" and "Cancel".
Until you tap Agree and continue, no data leaves your phone. If you cancel, the AI features are disabled, and the rest of the app continues to work normally.
4.6 How you revoke consent
Open Settings → Privacy → Revoke AI Consent inside Lookmaxx AI. We immediately stop sending anything to Google. We also delete the cached AI Try-On images and the AI Coach chat history from your device. The next time you tap an AI feature, the consent dialog reappears.
5. EU AI Act transparency notice
Lookmaxx AI uses an AI system to do two things you should know about, in line with the transparency obligations of Article 50 of the EU AI Act.
You are interacting with an AI. The AI Coach is not a human. Its replies are generated by a large language model (Google Gemini). They are produced from patterns in training data, not from professional judgement. They can be wrong, out of date, or biased.
AI Try-On generates altered images of your likeness. The preview you see is a synthetic image. It is not a photograph. It is an approximation produced by an image-generation model. Your actual result with a real barber, a real beard, or a real skincare routine may differ.
Do not rely on Lookmaxx AI for medical advice. Skincare suggestions, fitness programmes, and nutrition macros in the app are personalisation, not medicine. If you have a medical condition — including any skin condition, hair loss, mental-health concern, or eating disorder — please consult a qualified physician. We will not be liable for any health decision made solely on the basis of an AI-generated suggestion.
We do not use the app for emotion recognition, social scoring, biometric categorisation by protected attributes, or any other practice prohibited under Article 5 of the EU AI Act.
6. HealthKit-specific commitments
Apple's HealthKit framework comes with privacy obligations baked in, and we want to spell out our specific commitments so there is no ambiguity:
- Your HealthKit data never leaves your device through Lookmaxx AI. We do not transmit any HealthKit-sourced workout, weight, or body-measurement record to Google, to ourselves, to any analytics service, or to any other recipient.
- HealthKit data is never used for advertising. Lookmaxx AI does not show ads, and even if we ever did, HealthKit data would not be involved.
- HealthKit data is never used for data-mining or research purposes beyond your direct, in-app use of the app.
- HealthKit data is never sold or shared.
- You stay in control. You grant access in Apple's HealthKit permission dialog, you can revoke any specific category at any time in iOS Settings → Privacy & Security → Health → Lookmaxx AI, and you can delete the app, which immediately cuts our access.
These commitments are binding under Apple's HealthKit terms and under this Privacy Policy.
7. Subscriptions and billing
If you choose a premium plan, the purchase is processed by Apple, not by us.
- Plans: monthly (US$9.99, or the local equivalent Apple displays) and annual (US$59.99, or local equivalent). Prices may change with prior notice through the App Store.
- Free tier: unlimited use of the core app, plus a lifetime quota of three AI Try-On generations to let you experience the feature before deciding.
- Auto-renewal: subscriptions renew automatically at the end of each period unless you cancel at least 24 hours before the renewal date. Apple charges your saved payment method.
- Cancellation: open iOS Settings → [your name] → Subscriptions and pick Lookmaxx AI to cancel. Cancellation stops the next renewal; you keep access until the current period ends.
- Refunds: are handled by Apple under Apple's standard refund policy. We cannot process a refund directly.
- What we see: only the StoreKit transaction outcome — that you are or are not a premium subscriber. We do not see your name, billing address, card number, or any other payment detail.
8. International data transfers
Almost everything Lookmaxx AI does happens on your device, so there is usually no international transfer of your data at all.
The single exception is the AI features, which call Google's Gemini API. Those calls are sent to Google's servers, which are predominantly located in the United States.
For users in the European Economic Area, the United Kingdom, or Switzerland, this means a cross-border transfer of personal data. The legal safeguard for the transfer is the Standard Contractual Clauses incorporated by reference into the Google API terms (as amended for the 2021 EU SCCs), supplemented by the Data Protection Framework certifications Google holds where applicable. The current text of Google's contractual safeguards is available at Google Cloud's data processing terms.
Because we — Maksym Televiak as sole proprietor — do not run servers, we do not perform any further transfer of your data ourselves.
9. Retention — how long we keep things
We keep on-device data for as long as the app is installed and you have not asked us to delete it. Concretely:
- Anything you delete inside the app (a bookmark, a workout entry, a chat message) is gone from the device immediately.
- Tapping Settings → Reset Data wipes the entire on-device store, including your profile, scan history, AI cache, and bookmarks. There is no recovery — make sure you mean it.
- Deleting the app from iOS removes the on-device store automatically.
Apple may retain App Store transaction records under its own policies, regardless of what we do. Google may retain Gemini API request data briefly for abuse-monitoring under its own policies. We do not control either of those retention periods.
10. Children
Lookmaxx AI is intended for users aged 18 or older. The App Store age rating reflects this, and the onboarding flow asks the user to confirm their age.
We do not knowingly collect personal information from anyone under the age of 16 — or, where local law sets a higher digital-consent age, that higher age. If you are a parent or legal guardian and you believe your child has used Lookmaxx AI, please email us at maks.televyak@gmail.com. We will help you wipe all data from the device. Because we hold no copy on a server, deletion is immediate and complete.
11. Your rights
Whatever country you are in, you have a set of rights over your personal information. Below are the rights themselves and the practical way to use them in Lookmaxx AI.
11.1 Rights under the GDPR (EU, EEA, UK)
You have the right to:
- Be informed about how your data is used (that's what this policy is for).
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Restrict how we process your data.
- Portability — get a structured copy of your data and reuse it elsewhere.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, where processing relies on consent.
- Lodge a complaint with your national data protection authority.
In practice, because all your data is on your iPhone:
- Access, rectification, portability — your data lives in the app's Settings screens; you can view it, change it, or export your progress reports there. If you need a raw export of, say, your SwiftData store, email us and we'll walk you through Apple's "On My iPhone" backup option.
- Erasure — tap Settings → Reset Data, or delete the app.
- Restriction / Objection — turn off the AI features in Settings → Privacy → Revoke AI Consent, or revoke HealthKit access in iOS Settings.
- Withdraw consent — same path as above.
- Complain — your local supervisory authority can be found via the European Data Protection Board.
For any data Google may transiently hold, contact Google through the channels listed in Google's privacy policy. We will assist where reasonably possible.
11.2 Rights under the CCPA / CPRA (California)
If you are a California resident, you have the right to:
- Know what categories of personal information we collect, the purposes, and the categories of recipients.
- Access the specific pieces of personal information we hold about you.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information. (We do not sell or share your personal information as those terms are defined under the CCPA — there is nothing to opt out of, but you have the right.)
- Limit use of sensitive personal information (which includes biometric and health data under the CCPA).
- Non-discrimination — we will not charge you a different price or give you a lesser service for exercising any of these rights.
Use any of these rights by:
- Tapping Reset Data in app Settings (deletion), or
- Emailing maks.televyak@gmail.com with the subject "CCPA request — [your request type]". We respond within 45 days.
We do not require you to create an account to exercise these rights. If we need to verify that the request is genuinely yours, we will ask for the minimum information necessary (typically the email address you used to contact us and details of your last App Store transaction, if any).
11.3 Authorised agents
You may use an authorised agent (CCPA) or a third party (GDPR) to make a request on your behalf. We may ask the agent to provide written authorisation from you.
12. California ADMT pre-use notice
This section is required by the California Privacy Protection Agency's regulations on Automated Decision-Making Technology, which became effective on 1 January 2026.
What ADMT we use in Lookmaxx AI:
- Face scan scoring. The face scan computes scores on your device using on-device geometric analysis. It does not make a "significant decision" about you in the CCPA sense (no credit, employment, housing, healthcare, education, or essential goods/services decision). It is an aesthetic preview.
- AI Try-On and AI Coach (Google Gemini). Same — these are generative outputs offered to you. They do not deny you any essential service.
Purpose of the automated processing. To produce a personalised preview, score, or piece of advice you asked for.
Logic, in plain language. The face scan applies geometric heuristics to facial landmarks. Gemini is a large generative model trained on broad image and text data — Google is the best source on its underlying logic; see the Gemini documentation.
Your rights. You can:
- Opt out of any ADMT processing by not enabling the face scan or the AI features, and by revoking AI consent at any time in Settings. The non-AI portions of the app will still work.
- Ask us for further information about the ADMT logic, the type of personal information used, and the role of the output by emailing maks.televyak@gmail.com.
Human alternative. The app does not gate access to anything material on ADMT output. If for any reason you want a non-automated alternative, please tell us and we will discuss what is possible.
13. Security
The practical measures we take:
- On-device data lives in iOS's standard sandbox, which is protected by Apple's hardware-backed data protection. When your iPhone is locked, the operating system encrypts the contents at rest.
- In-flight network traffic (StoreKit calls to Apple, AI calls to Google) is sent over TLS 1.2 or higher. We do not allow cleartext HTTP connections.
- The Google Gemini API key is restricted server-side to requests originating from the Lookmaxx AI iOS application (Bundle ID
com.maksymteleviak.hairapp). A key extracted from the app binary cannot be used from a different application or from a script.
- No backend means a smaller attack surface. We do not run a server that holds your data, so there is no central database for an attacker to breach.
- Source-code controls. The repository's secrets file is gitignored, and a pre-commit hook blocks any commit that contains a Google API key pattern.
No system is perfectly secure. We do not promise "end-to-end encryption" — your data is encrypted in transit, and at rest on a locked iPhone, but it is in plaintext in memory while the app is running, as is normal for an iOS app.
14. Data breach notification
If we become aware of a personal data breach affecting your data, we will:
- Where required by GDPR Article 33, notify the competent supervisory authority within 72 hours of becoming aware.
- Where required by GDPR Article 34 (high risk to your rights and freedoms), notify you directly, in plain language, without undue delay.
- Comply with all applicable US state breach-notification laws, including California's SB 446 (30-day notification window for California residents).
Because we run no server, the most likely "breach" scenario is a compromise of a third-party processor (Apple or Google). In that case the primary notification obligation lies with that processor; we will pass along any information they share that affects you.
15. Changes to this policy
We may update this Privacy Policy from time to time.
- For minor changes (typos, clarifications, link updates), we update the "Last updated" date at the top.
- For material changes that broaden how we use your data — e.g. adding a new third-party processor or a new category of data — we will:
- show an in-app notice on your next launch, and
- give you at least 30 days' notice before the change takes effect, so you can decide whether to continue using the app.
The previous version remains available on request at the email below for at least 12 months after each change.
For anything privacy-related — questions, rights requests, breach reports, or just feedback — write to us:
- Email: maks.televyak@gmail.com
- Postal address: I. Franka St., 4, apt. 10, Smyha, Rivne Oblast 35680, Ukraine
- Subject lines we react to first: "GDPR request", "CCPA request", "Security report", "Child data".
We aim to reply to every privacy email within 7 days and to fulfil any rights request within 30 days (GDPR) or 45 days (CCPA), as the law requires.
Effective date: 29 May 2026 — Last updated: 29 May 2026