Biometric Data Retention and Destruction Policy
A Wise Approach LLC, doing business as Fingertip Facelift®
Effective August 27, 2026 · Version 1.1
This policy explains how long we keep photographs of your face and anything we derive from them, and exactly how we destroy them. It sits alongside our Privacy Policy, which covers everything else we collect. If the two ever appear to disagree about photographs, this policy is the more specific one and it governs.
Questions: help@fingertipfacelift.com
1. Scope, and what publishing this policy does and does not mean
This policy covers:
- photographs of your own face that you upload to the Fingertip Facelift app: whether you save them to your private progress tracker, send one with an optional survey such as our beta outcomes study, or use one only for a single routine, and
- anything we derive from those photographs, which today means short text descriptions of visible cosmetic concerns (we call these "concern tags").
We publish this policy, and we hold ourselves to it, for all of that material.
We publish it because you are entitled to know how long a photograph of your face stays with us and how it is destroyed, and because publishing a written retention and destruction schedule is what Illinois law asks of a company that holds biometric identifiers or biometric information. We want to meet that standard whichever way the question is answered for us.
Publishing this policy is not an agreement that we hold biometric identifiers or biometric information. As section 2 explains, we do not create a faceprint, a facial-geometry template, or any other biometric measurement of you, and we never use a photograph to identify you or to match you against another person. We do not believe that what we hold is a biometric identifier or biometric information under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, Colorado's biometric provisions, or Washington's biometric law. We publish this policy and follow it anyway, so that your photograph is protected on the same schedule either way. Nothing here waives or gives up any position we may take about how these laws apply to us.
Where this applies. We apply this policy to every member, everywhere, not only to members in one state. Where a law that covers you sets a shorter limit than the one in section 3, we apply the shorter limit to you. In scope terms, this policy is written to answer:
- Illinois (Biometric Information Privacy Act), which asks for a publicly available written retention schedule and destruction guidelines;
- Texas (Capture or Use of Biometric Identifier Act), which asks for destruction within a reasonable time after the purpose for collection has ended;
- Washington (the state biometric law at RCW 19.375), which asks that we not keep this material longer than is reasonably necessary to provide the service you asked for, to comply with the law, or to protect against fraud and security problems.
- Colorado (the biometric provisions added to the Colorado Privacy Act by House Bill 24-1130), which asks for this same publicly available policy, with a retention schedule and destruction guidelines, and for your consent before we collect a biometric identifier at all. Colorado applies these rules to any business that collects biometric identifiers, whatever its size, so they reach us regardless of the thresholds that govern the rest of that Act.
Washington's My Health My Data Act is a separate law with its own requirements. It is answered in our Consumer Health Data Privacy Policy, not here.
2. What we collect, and what we do not create
What we collect.
- The photograph you upload. You choose to upload it. Nothing in the app takes a photograph on its own, and nothing scans you in the background.
- Concern tags, which are short pieces of plain text such as "puffiness under the eyes" or "fine lines". They describe what is visible, in the same words a person might use. They are cosmetic preferences, not medical findings, and we do not provide medical assessments.
What we do not create, hold, or receive.
- No faceprint.
- No scan or measurement of your facial geometry, and no template built from one.
- No biometric vector, embedding, or numeric representation of your face.
- No voiceprint, retina or iris scan, fingerprint, or hand or face geometry scan.
- No identification of you from a photograph, and no matching of one person's photograph against another person's, against a database of faces, or against a watchlist. We never use a photograph to work out who someone is. We already know who you are, because you are signed in.
About the providers who help us. When photo analysis is available and you tick the box to use it on a photo, that photograph is sent to our image-analysis provider, which returns text and nothing else. We do not receive, request, or store any faceprint, template, embedding, or numeric face representation from any provider. Our contract requires that provider not to use your photograph to train AI models, and to delete it within 30 days. If their safety systems flag a submission, they may keep it for up to two years for that purpose.
3. Retention schedule
3.1 The outer limit that always applies
Whatever else this schedule says, we destroy your photographs and the concern tags derived from them at the earlier of these two points:
- when the purpose we collected them for has been satisfied, or
- three years after your last interaction with us.
That outer limit binds us even if you never ask us to delete anything. If you stop using Fingertip Facelift and your account simply goes quiet, we destroy your photographs and concern tags once three years have passed since your last interaction with us, and we do it without waiting to hear from you. We run this as a routine housekeeping job rather than only on request. No account has reached three years yet, because the photo feature is newer than that, so nothing has yet fallen due. Where a law that applies to you sets a shorter limit, we use the shorter one.
"Your last interaction with us" means the most recent of: signing in, using the app, uploading or viewing a photograph, buying or renewing a subscription, or contacting us.
3.2 What we actually do, day to day
Inside that outer limit, your photographs are yours to control, and we do not delete them on a timer just because time has passed. We made that choice deliberately: members come back after months away and expect their progress history to still be there, and losing it would be worse for them than keeping it. So in practice:
| What | How long we keep it | What triggers destruction |
|---|---|---|
| A photograph you saved to your progress tracker | Until you delete it or close your account, and in any event no longer than the outer limit in 3.1 | You delete the photo, you delete your account, you ask us to delete it, or the outer limit is reached |
| A photograph used for one routine only (the "just use it for this routine" option, available when photo analysis launches) | Not kept at all. It is held in memory only, never written to disk or to our photo storage, and discarded when the request ends. It never appears in your tracker | Nothing to trigger. The photograph is gone when the request ends |
| Concern tags derived from a photograph you saved | With the photograph they came from. Deleting the photograph deletes the tags with it | Photo deletion, account deletion, or the outer limit |
| Concern tags from a "just use it for this routine" photo | Held in your own browser's session cookie, not in our database, until the routine is built. The short note they produce is then saved with that one routine, so you can still read it later | Building the routine, starting the quiz over, signing out, or closing your browser. Starting the quiz over also removes the note from your routines, and so does deleting the routine |
| Your consent record (that you ticked the box, when, and which version of the wording you saw) | For the life of your account, as proof that we asked you before we collected anything | Contains no photograph and no biometric data of any kind |
| Our erasure log entry (that a deletion was carried out, for whom, on what date) | A limited period, then purged | Contains no photograph, no concern tags, and no biometric data. It exists to prove your deletion happened |
3.3 Two things that do not delete your photos
- Cancelling your subscription does not delete your photographs. Cancelling ends your access to the courses and stops the billing. Your account and your progress photos stay, so that if you come back your history is still there. If you want the photographs gone, delete them or delete your account (section 8).
- Unsubscribing from our emails does not delete your photographs either. It only stops the email.
4. How we destroy it
Destruction is permanent. We do not move photographs to an archive, a "deleted items" area, or a staff-reviewable holding area. There is no copy kept for our records.
When you delete a single photograph. The image file is deleted from our private storage and the record naming it is deleted from our database, immediately, in the same request.
When you delete your account, or ask us to delete it for you. Both routes run the same process, so they wipe identically. We permanently delete every photograph of yours from private storage and every record that names one, including any stray file left behind by an interrupted upload, along with the concern tags derived from them, your routines and history, and your profile. Your sign-in account is deleted too, so there is no login left behind. We keep one line in a deletion record confirming your request was carried out; it holds nothing belonging to you.
If a step fails, we say so. If our storage or another provider is unreachable at that moment, the failure is recorded on that permanent log and raised to our team as an alert that stays open until a person finishes the job by hand. We would rather tell you a step is outstanding than quietly report success.
Backups. We keep short-lived backups of our database so we can recover from a disaster. Those backups hold records, not your photograph files: photographs live only in the private storage described above and are deleted from it straight away. Backup copies are kept only briefly and are replaced on a rolling cycle, so records of a deleted account age out of them. A restore is never allowed to bring back data someone asked us to delete. Backups exist to recover from failure, not to keep a second copy of something you deleted.
5. We do not sell, lease, trade, or profit from this data
We do not sell, lease, trade, or otherwise profit from your photographs, your concern tags, or any biometric identifier or biometric information. We do not sell your personal information for money, and we never have. Some US state laws treat the use of advertising cookies as "sharing" or "targeted advertising"; that never involves your photographs or concern tags, and you can switch it off at any time from the footer. Your photographs are not a product, not an advertising asset, and not something we would ever hand to a data broker.
Two related points, so that nothing here is a surprise:
- Personalization. If you separately choose it, we use your concern tags to tailor what we show and suggest to you inside our own service. That is us using what you told us to make your own experience better. It is not selling, leasing, or trading your data to anyone, and no third party receives your concern tags in order to advertise to you. You can turn personalization off at any time in your account, and we will stop.
- Sharing a photo with Allison. Progress photos are private to you by default. Photo sharing is not switched on yet. When it is, sharing one specific photo will give us permission to use that one photo in our marketing, and that permission will be written, separate, per-photo, and withdrawable. Nothing moves out of your private tracker without that deliberate choice.
6. When we disclose, and to whom
We do not show your photographs to other members, and our staff cannot browse the photographs in your private progress tracker. Beyond that, we disclose a photograph or a concern tag only:
- to you, the person it belongs to;
- to the service providers who store or process it for us, under a written contract that limits them to acting on our instructions. Today that means our storage provider, Cloudflare R2, which holds the encrypted file in a private location. When photo analysis launches, it will also mean Anthropic, which receives the image and returns text. Anthropic is contractually barred from using your photograph to train AI models, and deletes it within 30 days, or up to two years if their safety systems flag it. These providers do not get to use your photograph for their own purposes;
- to our own team, if you attach a photograph to an optional survey such as our beta outcomes study. That photograph is part of your answers, and our team reads it as part of the study. It is separate from your private progress tracker, it is optional, and it is only used publicly if you also tick the marketing box;
- when the law requires it, including under a valid warrant or subpoena. If we ever receive one of those, we check that it is valid before we respond.
That is the complete list. Advertising is not a category of its own: no photograph of yours reaches our marketing or an advertising platform at all.
7. How we protect it
We use at least the standard of care we would use for any confidential and sensitive information we hold, and in the same way for everyone. Specifically:
- Photographs are stored in a private location with no public web address. There is no link that someone could guess or share.
- When you view your own photos, the app mints a short-lived signed link that expires quickly and then stops working. Treat that link like the photo itself: anyone you forward it to can open it until it expires.
- Our staff cannot browse the photographs in your private progress tracker. There is no staff screen that lists them. One thing is different, and it is your own choice: a photo you choose to attach to an optional survey such as our beta outcomes study, which our team reads as part of that study. Everything else in your tracker stays closed to us.
- Data is encrypted in transit (HTTPS) and encrypted at rest in storage.
- Access to personal data inside the company is limited to people who need it for their job.
- Photo analysis never runs unless you tick the box beside a photo, and the feature as a whole is not switched on yet. While it is off, no photograph is sent to any third party at all.
- We have a written breach response plan and will notify you and the regulators where the law requires it.
8. Questions, and how to have your data deleted
You never need our permission or a reason, and we will not ask you why.
- Delete a single photograph: open your account, go to your progress photos, and delete it. It is removed from storage and from our database immediately.
- Delete your account and everything in it: account settings, "Delete Your Account". You will be asked to type DELETE to confirm. This wipes your photographs, your concern tags, your routines and history, and your profile, cancels your membership, and takes you off our email list.
- Prefer that we do it for you, or have a question about this policy: email help@fingertipfacelift.com and we will handle it, and we will confirm when it is done.
- Withdraw a consent at any time. For photo analysis, simply do not tick the box next time, and delete the photo to remove anything we derived from it. For storage or personalization use your account or email us.
Your other rights, including access, correction, and portability, are described in our Privacy Policy.
9. Changes to this policy
If we change this policy we will update the effective date and version above, and we will tell you about any significant change through the app or by email. Earlier versions are kept so that you can see what you agreed to at the time.