Privacy Policy — Lookmaxx AI

Effective date: 29 May 2026 Last updated: 29 May 2026


Privacy at a glance

Eight things to know in plain English:

  1. Your data lives on your iPhone. Almost everything Lookmaxx AI creates about you — your face scan results, your photos, your scores, your routines, your workouts — is stored only on your device. We do not run a server that holds your data.
  2. We do not run analytics, ad networks, or crash reporters. No SDK is silently watching how you use the app.
  3. Two things leave your phone: subscription receipts go to Apple, and (only when you ask) your selfie and the chosen reference style image go to Google's Gemini AI to generate a try-on preview or an AI Coach reply.
  4. Google Gemini is the only third-party AI we use. We name it openly and ask for your explicit, in-app consent the first time before any photo or message is sent.
  5. You can wipe everything in two taps. Settings → Reset Data — or just delete the app. There is nothing on a server of ours to delete.
  6. HealthKit data stays on your device. It is never sent to Google, never used for ads, never shared.
  7. We do not knowingly collect data from anyone under 18. This app is built for adults.
  8. You have full rights under GDPR and CCPA — access, deletion, opt-out, the lot. See section 11.

If you want the full detail, the table of contents is right below.


Table of contents

  1. Who we are
  2. Scope and acceptance
  3. The data we collect, why, and where it lives
  4. Google Gemini AI — what we send, why, and your consent
  5. EU AI Act transparency notice
  6. HealthKit-specific commitments
  7. Subscriptions and billing
  8. International data transfers
  9. Retention — how long we keep things
  10. Children
  11. Your rights
  12. California ADMT pre-use notice
  13. Security
  14. Data breach notification
  15. Changes to this policy
  16. Contact us

1. Who we are

Lookmaxx AI is operated by Maksym Televiak, an individual sole proprietor based in Ukraine.

We are not currently established in the European Union, the United Kingdom, or the United States. Under Article 27 of the GDPR, a data controller outside the EU that offers its services to people in the EU must, in most cases, designate a written representative inside the EU.

At our current scale, we are not yet required to appoint such a representative under the practical thresholds in Article 27(2)(a). If our monthly active users from the EU cross those thresholds, we will appoint an Article 27 representative and update this policy with their details. In the meantime, EU and UK users can reach us directly at the email above for any privacy-related request, and we will respond within 30 days.


2. Scope and acceptance

This policy explains how Lookmaxx AI handles your personal information. It applies to the iOS app distributed through the Apple App Store, and to any communication you send us at the email above.

It does not cover:

By installing or using Lookmaxx AI, you confirm that you have read this policy. We do not, however, treat your continued use as consent for activities that the law — in particular GDPR Article 9 for biometric and health data, and the CCPA for sensitive personal information — requires us to obtain through an explicit, separate in-app action. Those activities are gated by their own consent prompts.


3. The data we collect, why, and where it lives

Below is every category of personal data Lookmaxx AI may handle. For each one we tell you what it is, why we use it, the lawful basis under the GDPR, where the data physically sits, and how long we keep it.

We never sell your personal information, and we do not share it for cross-context behavioural advertising. We do not engage in "selling" or "sharing" as those terms are defined under the CCPA.

3.1 Face scan image and derived facial geometry

3.2 Selfies and reference images used for AI Try-On

3.3 AI Coach chat messages

3.4 Profile data you enter yourself

3.5 Workout logs, weight history, body measurements

3.6 HealthKit data (only if you enable it)

3.7 Bookmarks and saved content

3.8 Subscription and receipt data

3.9 Device permissions and on-device system data

We do not collect IP addresses, device fingerprints, advertising identifiers (IDFA), precise geolocation, contacts, microphone audio, or any other category not listed above.


This section exists because Apple's App Review Guideline 5.1.2(i) — updated in November 2025 — requires apps to name third-party AI providers explicitly, explain what is sent, and obtain user permission before any data is transmitted. Here is the whole picture, with no euphemisms.

4.1 Who Google is, in this context

Google is the only third-party AI provider Lookmaxx AI uses. Specifically, the app talks to Google Gemini through Google's Generative Language API, hosted at generativelanguage.googleapis.com. Two models are used:

4.2 What we send to Google

Nothing else — no contacts list, no other photos, no HealthKit data, no device identifiers, no IP-based location tags added by us. Google may, separately, log standard request metadata for its own service operation; that is Google's processing under its own terms.

4.3 Why we send it

To generate the AI Try-On image you asked to see, or to compose the AI Coach reply you are waiting for. We have no other reason to send any data to Google.

4.4 What Google does with it

Google's published terms for the paid Gemini API state that:

You should read Google's own documents for the authoritative version:

The first time you tap "Generate AI Try-On" or send a message to the AI Coach, Lookmaxx AI shows a full-screen consent dialog that:

Until you tap Agree and continue, no data leaves your phone. If you cancel, the AI features are disabled, and the rest of the app continues to work normally.

Open Settings → Privacy → Revoke AI Consent inside Lookmaxx AI. We immediately stop sending anything to Google. We also delete the cached AI Try-On images and the AI Coach chat history from your device. The next time you tap an AI feature, the consent dialog reappears.


5. EU AI Act transparency notice

Lookmaxx AI uses an AI system to do two things you should know about, in line with the transparency obligations of Article 50 of the EU AI Act.

You are interacting with an AI. The AI Coach is not a human. Its replies are generated by a large language model (Google Gemini). They are produced from patterns in training data, not from professional judgement. They can be wrong, out of date, or biased.

AI Try-On generates altered images of your likeness. The preview you see is a synthetic image. It is not a photograph. It is an approximation produced by an image-generation model. Your actual result with a real barber, a real beard, or a real skincare routine may differ.

Do not rely on Lookmaxx AI for medical advice. Skincare suggestions, fitness programmes, and nutrition macros in the app are personalisation, not medicine. If you have a medical condition — including any skin condition, hair loss, mental-health concern, or eating disorder — please consult a qualified physician. We will not be liable for any health decision made solely on the basis of an AI-generated suggestion.

We do not use the app for emotion recognition, social scoring, biometric categorisation by protected attributes, or any other practice prohibited under Article 5 of the EU AI Act.


6. HealthKit-specific commitments

Apple's HealthKit framework comes with privacy obligations baked in, and we want to spell out our specific commitments so there is no ambiguity:

  1. Your HealthKit data never leaves your device through Lookmaxx AI. We do not transmit any HealthKit-sourced workout, weight, or body-measurement record to Google, to ourselves, to any analytics service, or to any other recipient.
  2. HealthKit data is never used for advertising. Lookmaxx AI does not show ads, and even if we ever did, HealthKit data would not be involved.
  3. HealthKit data is never used for data-mining or research purposes beyond your direct, in-app use of the app.
  4. HealthKit data is never sold or shared.
  5. You stay in control. You grant access in Apple's HealthKit permission dialog, you can revoke any specific category at any time in iOS Settings → Privacy & Security → Health → Lookmaxx AI, and you can delete the app, which immediately cuts our access.

These commitments are binding under Apple's HealthKit terms and under this Privacy Policy.


7. Subscriptions and billing

If you choose a premium plan, the purchase is processed by Apple, not by us.


8. International data transfers

Almost everything Lookmaxx AI does happens on your device, so there is usually no international transfer of your data at all.

The single exception is the AI features, which call Google's Gemini API. Those calls are sent to Google's servers, which are predominantly located in the United States.

For users in the European Economic Area, the United Kingdom, or Switzerland, this means a cross-border transfer of personal data. The legal safeguard for the transfer is the Standard Contractual Clauses incorporated by reference into the Google API terms (as amended for the 2021 EU SCCs), supplemented by the Data Protection Framework certifications Google holds where applicable. The current text of Google's contractual safeguards is available at Google Cloud's data processing terms.

Because we — Maksym Televiak as sole proprietor — do not run servers, we do not perform any further transfer of your data ourselves.


9. Retention — how long we keep things

We keep on-device data for as long as the app is installed and you have not asked us to delete it. Concretely:

Apple may retain App Store transaction records under its own policies, regardless of what we do. Google may retain Gemini API request data briefly for abuse-monitoring under its own policies. We do not control either of those retention periods.


10. Children

Lookmaxx AI is intended for users aged 18 or older. The App Store age rating reflects this, and the onboarding flow asks the user to confirm their age.

We do not knowingly collect personal information from anyone under the age of 16 — or, where local law sets a higher digital-consent age, that higher age. If you are a parent or legal guardian and you believe your child has used Lookmaxx AI, please email us at maks.televyak@gmail.com. We will help you wipe all data from the device. Because we hold no copy on a server, deletion is immediate and complete.


11. Your rights

Whatever country you are in, you have a set of rights over your personal information. Below are the rights themselves and the practical way to use them in Lookmaxx AI.

11.1 Rights under the GDPR (EU, EEA, UK)

You have the right to:

In practice, because all your data is on your iPhone:

For any data Google may transiently hold, contact Google through the channels listed in Google's privacy policy. We will assist where reasonably possible.

11.2 Rights under the CCPA / CPRA (California)

If you are a California resident, you have the right to:

Use any of these rights by:

We do not require you to create an account to exercise these rights. If we need to verify that the request is genuinely yours, we will ask for the minimum information necessary (typically the email address you used to contact us and details of your last App Store transaction, if any).

11.3 Authorised agents

You may use an authorised agent (CCPA) or a third party (GDPR) to make a request on your behalf. We may ask the agent to provide written authorisation from you.


12. California ADMT pre-use notice

This section is required by the California Privacy Protection Agency's regulations on Automated Decision-Making Technology, which became effective on 1 January 2026.

What ADMT we use in Lookmaxx AI:

Purpose of the automated processing. To produce a personalised preview, score, or piece of advice you asked for.

Logic, in plain language. The face scan applies geometric heuristics to facial landmarks. Gemini is a large generative model trained on broad image and text data — Google is the best source on its underlying logic; see the Gemini documentation.

Your rights. You can:

Human alternative. The app does not gate access to anything material on ADMT output. If for any reason you want a non-automated alternative, please tell us and we will discuss what is possible.


13. Security

The practical measures we take:

No system is perfectly secure. We do not promise "end-to-end encryption" — your data is encrypted in transit, and at rest on a locked iPhone, but it is in plaintext in memory while the app is running, as is normal for an iOS app.


14. Data breach notification

If we become aware of a personal data breach affecting your data, we will:

Because we run no server, the most likely "breach" scenario is a compromise of a third-party processor (Apple or Google). In that case the primary notification obligation lies with that processor; we will pass along any information they share that affects you.


15. Changes to this policy

We may update this Privacy Policy from time to time.

The previous version remains available on request at the email below for at least 12 months after each change.


16. Contact us

For anything privacy-related — questions, rights requests, breach reports, or just feedback — write to us:

We aim to reply to every privacy email within 7 days and to fulfil any rights request within 30 days (GDPR) or 45 days (CCPA), as the law requires.


Effective date: 29 May 2026 — Last updated: 29 May 2026