Privacy Policy
Blimae · Last updated 20 August 2026
Blimae analyses your skin from a selfie and builds a skincare routine around your answers. This policy explains exactly what happens to that data — including the part most apps leave vague: your photo.
The short version. Your selfie is never stored on our servers. It is sent to our analysis provider, scored, and the scores come back to your phone. Your answers, your routine, your check-ins and your history stay on your device. We keep no account and no name — only an anonymous identifier, used to meter the scans, simulations, coach messages and product lookups a device has run.
1. Who we are
Blimae ("we", "us") is operated by Steeven Noncent, 47 rue Littré, 44100 Nantes, France, who is the data controller for the processing described here.
For any privacy question or request, contact contact@blimae.com.
2. We do not ask you to create an account
Blimae has no sign-up, no login, no email address and no password. We never ask for your surname or any contact detail. The first name you can optionally enter stays on your device to greet you — the single exception is the skin coach, whose opening greeting is part of the conversation sent with your question (see section 3).
To count how many scans a device has used — our analysis provider charges per scan, so it is metered — the app generates an identifier the first time it opens, made of the moment of that first launch and a random string, for example dev-mfk3z1a0-q7x2m9b4kt. It is created by the app, it is not your device's advertising ID or any hardware serial number, and it is not linked to you. Deleting the app deletes it; reinstalling produces a new, unrelated one. Restoring a purchase asks Apple what your Apple ID already owns, so your subscription follows you to the new identifier — nothing else does.
3. What we process, and why
Your selfie
When you run a skin analysis, the photo is sent over an encrypted connection to our backend, which immediately forwards it to the analysis provider that scores it. Our backend keeps no copy: as soon as the scores come back, the photo is gone from it. The provider necessarily receives and holds the photo for the time it takes to run the analysis, and applies its own retention period to it — see its policy, linked in section 4.
We write your photo to no database, no storage bucket and no log of ours. It exists in our backend only for the seconds it takes to pass it to the provider and get a result. The visual overlays shown in your report are delivered to your phone through short-lived links and are not kept on our side either.
The copy of your photo saved with your report lives on your phone, in the app's private storage, so you can compare scans over time. It is removed when you delete the scan or the app.
Because that copy disappears with the app, Profile → Help & data offers Save my photos to Photos, which writes them into your own photo library. It runs only when you tap it, it asks iOS for permission to add photos and nothing more — Blimae never gains the right to read your library — and the copies then belong to you alone: they are outside the app, and deleting Blimae no longer touches them. Nothing is sent to us at any point.
Once per device, the same photo is also used for the skin simulation: the provider returns a version of your own face with your main concerns corrected, so you can see what your skin could look like. That image is generated from your selfie, sent straight back to your phone and stored there — we keep neither the source photo nor the result.
No face recognition. Blimae does not identify faces. We ask the analysis provider for skin-condition scores and the overlay images shown in your report, and that is all we receive: no faceprint, no face template, no identifier that could be used to recognise you in another photo. Your phototype is worked out on your phone from the answers you gave, and is never sent anywhere.
Your questionnaire answers, routine and history
Skin type, concerns, goal, sensitivity, sun responses, product preferences, age range, your daily check-ins and your saved products are stored only on your device. We do not receive a copy or hold them on our servers.
The one exception is the skin coach: when you ask it a question, your recent messages in that conversation and a short summary of your profile (skin type, goal, sensitivity, product preferences — never your concerns) are sent along with it so the answer is relevant to your skin. They are used to produce the reply and are not stored on our servers afterwards.
Products you look up
When you search for a product, photograph its packaging, or scan its barcode, what you typed or photographed is sent to our backend and on to the provider that identifies it. A barcode is looked up in the open Open Beauty Facts database, and the ingredient list printed on the pack is then read by OpenAI so the app can say who the formula suits; a search term or a packaging photo is read by OpenAI directly. Product photos are handled exactly like your selfie: passed through, never written to a database, a storage bucket or a log of ours. We keep no record of what you searched for — the products you save live on your phone.
Usage counters
We store, against your anonymous identifier, counters only: how many full analyses and weekly scans that device has run, how many analysis attempts it has made today, whether it has used its one skin simulation, how many coach messages and product searches it has sent today, and the time of the last of these. Some counters reset daily or weekly; the full-analysis and simulation counts are kept for the life of the identifier. This is what enforces the weekly scan limit and prevents abuse of a paid API. No content is stored — not your photo, not your question, not what you searched for.
| Data | Purpose | Legal basis (GDPR) | Where it lives |
|---|---|---|---|
| Selfie | Produce your skin analysis and, once, your skin simulation | Performance of our contract with you (Art. 6(1)(b)) | In transit only — not stored by us |
| Questionnaire, routine, check-ins, scan history | Build and track your routine | Performance of our contract with you | Your device only |
| Coach message + profile summary | Answer your question | Performance of our contract with you | In transit only — the thread is stored on your device, and its recent messages travel with each new question |
| Product search term, packaging photo or barcode | Identify the product and who its formula suits | Performance of our contract with you | In transit only — saved products stay on your device |
| Anonymous device identifier + usage counters (scans, simulation, coach messages, product searches, last-activity time) | Enforce scan limits, prevent abuse | Our legitimate interest in protecting a metered service (Art. 6(1)(f)) | Our database, EU (Paris region) |
4. Who else sees your data
We use the processors listed below, and only for the purposes above. We do not sell your data, we do not share it with advertisers, and none of it is used to train our own models.
- Perfect Corp. — performs the skin analysis and the skin simulation on your photo. See their privacy policy.
- OpenAI — powers the skin coach, identifies the products you search for or photograph, and scores your selfie when the primary provider is unavailable. API data is not used to train their models. See their privacy policy.
- RevenueCat — checks your App Store receipt on our behalf and tells the app whether a subscription is active. It receives your anonymous device identifier and the subscription information Apple returns; it never receives your photo, your answers or your coach messages. See their privacy policy.
All three are established outside the European Economic Area. Transfers rely on the European Commission's Standard Contractual Clauses. Each provider applies its own retention period to the data it receives, which we do not control beyond our contract with them; their policies above describe it.
One lookup does not go through us at all. When you scan a product barcode, your phone queries Open Beauty Facts — the open, non-profit cosmetics database — directly, so that service sees the barcode and your device's IP address. We send it nothing about you, and we receive back only the product record. See their site for how they handle it.
Our backend and database are hosted by Supabase in the European Union (Paris region).
Your subscription is billed by Apple through the App Store. We never see your payment details — through RevenueCat we receive only whether a subscription is active, which plan it is, and whether it is still in its trial.
5. How long we keep things
- Your selfie: not retained by us at all.
- Usage counters: kept for as long as that device identifier is in use, so a scan limit cannot be reset by closing the app. You can have them deleted at any time — see section 6.
- Error logs: our backend records technical failures — status codes, error messages, and a truncated excerpt of what the provider answered — to diagnose problems. Your photo is never written to them; an excerpt can occasionally carry part of one of the short-lived links to an overlay image from your scan, and those links stop working within hours. Logs are kept by our hosting provider under its own retention.
- Everything on your device: as long as you keep the app. Deleting the app deletes all of it.
6. Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interest. Write to contact@blimae.com.
One honest limit. Because we hold no account and no name, we usually cannot connect a request to a specific record — there is nothing to look you up by. If you want the data associated with your device removed, you can either delete the app, which removes everything held locally, or use Profile → Help & data → Delete the data we hold in the app, which opens a mail already carrying your device identifier. The same identifier is printed lower down in that Help & data card, if you prefer to send it yourself.
You also have the right to lodge a complaint with your national data protection authority.
7. Children
Blimae is not directed at children under 16 and we do not knowingly process their data.
8. Security
All traffic between the app, our backend and our providers is encrypted in transit (TLS). Provider credentials are held server-side as secrets and are never shipped in the app. Access to our database is restricted to the backend service.
9. Changes
If we change how we handle your data, we will update this page and its date. Material changes will be surfaced in the app.