Privacy Policy
Last updated: 12 July 2026
This Privacy Policy explains how samko labs, s. r. o., with registered seat at Trnková 451/12, 040 14 Košice – mestská časť Košická Nová Ves, Slovak Republic
(IČO: 53928881, DIČ: 2121532600) ("we", "us", "our"), processes
personal data when you use the Apex Face app. We are the data controller under the EU
General Data Protection Regulation (GDPR).
Your selfies are not stored.
Each photo you capture is sent over an encrypted
connection to Google's Gemini AI for analysis, held only in memory for the duration of
that single request, and then discarded. We do not save your photos on our servers, and
we do not log them.
1. What we process
- Face photos — processed transiently to generate metrics (see below).
They are never persisted by us.
- Face metrics & app data (scores, streaks, goals, reminder time)
— stored locally on your device. We do not receive a copy.
- Subscription data — when you purchase or change a subscription,
Apple sends us signed subscription lifecycle events (e.g. purchase, renewal,
cancellation, refund) containing transaction identifiers, product ID, and status. We
store these to operate the service, prevent fraud, provide support, and meet legal and
accounting obligations.
- Diagnostics & analytics — aggregated, non-photo usage and
performance data to improve the App.
2. How photos are analyzed
Your selfie is analyzed using Google Gemini AI. The image is
transmitted to Google solely to compute your face metrics and is not used by us to
identify you. Google processes the request as our processor; the photo is not stored by us.
We do not claim analysis happens on-device.
Cloud AI analysis only happens with your permission: before every analysis,
the App shows a consent screen explaining that your photo will be sent to Google Gemini
AI, and asks you to agree. If you decline, analysis runs on your device only and the
photo never leaves your phone. You can also withdraw or grant this consent at any time
in Settings → Privacy inside the App.
3. Face data: collection, use, sharing, and retention
- What face data we collect: the selfie photo you capture, and six
numeric cosmetic scores derived from it (puffiness, jawline definition, skin clarity,
symmetry, under-eye, and an overall face score). We do not create or store
biometric identifiers, faceprints, or facial-geometry templates, and we do not use
face data to identify you.
- How we use it: solely to compute your cosmetic face metrics and
show your progress inside the App. Face data is never used for advertising, marketing,
identification, or AI model training by us.
- Who it is shared with: with your consent, the photo is sent over
an encrypted connection to our server (hosted by Cloudflare), which forwards it to
Google Gemini AI acting as our processor to compute the metrics. It is
shared with no other third party.
- Where it is stored: the photo is held only in memory on our server
for the duration of the single analysis request and is never written to disk, database,
cache, or logs. Your photos and metrics are stored locally on your device only; we keep
no copy.
- How long it is retained: photos sent for analysis are retained for
zero time beyond the request — they are discarded immediately after the metrics are
computed. On-device photos and metrics remain on your phone until you delete them
(Settings → Delete All Data) or uninstall the App.
4. Legal bases (GDPR)
- Consent (Art. 6(1)(a), Art. 9(2)(a)) — cloud AI analysis of your
face photo, asked in-app before every analysis and revocable anytime in
Settings → Privacy.
- Performance of a contract (Art. 6(1)(b)) — to provide the analysis,
subscriptions, and core features you request.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, security,
and product improvement.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records for
purchases.
5. Who we share data with
- Apple — processes all payments and sends us subscription events.
- Google (Gemini AI) — performs the face analysis on the transient
image.
- Cloudflare — hosts our backend and processes subscription data on
our behalf.
- Meta / Facebook — the App may use the Facebook SDK for measurement
and analytics.
We do not sell your personal data. Some processors may transfer data outside the EEA
under appropriate safeguards such as the EU Standard Contractual Clauses.
6. Retention
Photos: not retained (in-memory only, discarded after each analysis request — see
section 3). On-device data: kept until you delete it or uninstall the App. Subscription
records: kept for the life of the account and for as long as required by tax and
accounting law.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, or object to the
processing of your personal data, and the right to data portability. To exercise these
rights, email samo@vrablik.eu. You also have the right to lodge a
complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov
Slovenskej republiky) or your local supervisory authority.
8. Children
Apex Face is not directed to children under 16. We do not knowingly process their data.
9. Changes
We may update this Policy; material changes will be reflected by the "last updated"
date above.
10. Contact
samko labs, s. r. o., Trnková 451/12, 040 14 Košice – mestská časť Košická Nová Ves, Slovak Republic. Email: samo@vrablik.eu.