Privacy Policy
This policy explains how Veylo ("Veylo", "we") collects, uses, and protects personal data. Pending legal review before full public launch.
1. What we collect
- Photo: a single selfie you upload for analysis. Auto-deleted within 24 hours.
- Profile answers: age range, top skin concerns, current routine, sensitivities, and goal.
- Email address: to deliver your report and (with your consent) marketing communications.
- Order data: processed by Polar.sh (our Merchant of Record). We never see your full card number.
- Usage data: page views and funnel events, only if you've accepted analytics cookies.
- Attribution data: Meta click/browser ids and UTM parameters, used to measure ad performance.
2. How we use it
To generate your personalized analysis, deliver your report, process refunds, prevent fraud, improve the product, and measure marketing performance.
We do not sell your data. We do not use your photo to train AI models.
3. Who we share with
- Supabase — database, storage, edge functions (EU-based infrastructure)
- Polar.sh — payments (Merchant of Record handles tax/VAT)
- Anthropic — Claude Sonnet Vision analyzes your photo (image only, no other personal data)
- Resend — transactional email delivery
- PostHog — product analytics (only with your consent)
- Meta — conversion attribution (hashed email only)
4. Retention
- Photos: 24 hours from upload, then permanently deleted.
- Report data + email: until you request deletion.
- Order records: 7 years (tax obligation).
5. Your rights
You can request data export or deletion at veylo.beauty/account/data. We respond within 30 days, as required by GDPR (EU) and CCPA (California).
6. Cookies
See our Cookie Policy.
7. Contact
Questions? Email privacy@veylo.beauty.