Fingertip Facelift Fingertip Facelift Custom Routine Builder
Classroom Products Membership Sign In

Consumer Health Data Privacy Policy

Last updated August 27, 2026

This is a separate policy required by Washington State's My Health My Data Act. It sits alongside our main Privacy Policy, which still applies to everything we do. Where the two overlap, they say the same thing. This one goes into more detail about health-related data specifically.

A Wise Approach LLC, doing business as Fingertip Facelift ("we", "us"), operates the Fingertip Facelift Custom Routine Builder app. We are the company responsible for the data described here. You can reach us any time at help@fingertipfacelift.com.

Who this policy is for. It applies to you if you live in Washington State, or if your consumer health data is collected while you are in Washington. We have chosen to apply it to everyone, because running two different standards for the same data would be confusing and worse for you. Residents of Nevada and Connecticut have similar rights, described near the end.

A note on what our app is. Fingertip Facelift teaches facial massage and face yoga for cosmetic and wellness reasons. It is for adults 18 and older. It is not medical care, it does not diagnose anything, and nothing in it is medical advice. We do not want, ask for, or keep medical records. We are writing this policy anyway, because the Washington law defines health data broadly, and we would rather treat your information carefully than argue about definitions.

1. The consumer health data we collect, why we collect it, and where it comes from

Below is everything we treat as consumer health data, whether or not each item finally turns out to meet the legal definition. We would rather over-include than surprise you.

a. The concerns you choose in the routine builder

What it is: the cosmetic concerns you pick from a set list when you build a routine, for example fine lines, puffiness, or jaw definition. You choose from options we wrote. There is no free-text box here, which is deliberate.
Where it comes from: you, directly, in the app.
Why we collect it: to build your routine. Your stated concerns are what the routine is made from. We also use them, in aggregate, to see which routines people build and to improve the app.

b. Your progress photos, if you choose to upload them

What it is: photos of your own face that you upload to track your progress over time.
Where it comes from: you, directly. Uploading is optional, and the app works fully without it.
Why we collect it: so you can see your own progress. These photos are private to you. They are kept in private storage and shown only to you through short-lived signed links. Our staff cannot browse them, and they are never shown to other members. One thing is different, and it is your own choice: a photo you attach to an optional survey such as our beta outcomes study, which our team reads as part of that study. You can delete any photo, at any time, and it is removed from storage and from our database immediately.

c. Skincare concern results from photo analysis (not available yet)

What it is: short text descriptions of visible cosmetic concerns, for example "puffiness" or "fine lines", produced by an automated image-analysis service looking at a photo you chose to submit.
Where it comes from: derived by an AI service provider from a photo you provide.
Status: this feature is built but switched off, and it has never run on anyone's photo. No photo has ever been sent to an analysis provider. When and if we turn it on, it will be optional and it will ask for your separate, explicit consent first.
Why we would collect it: to add supporting emphasis to the routine you already chose. It would never override your own stated concerns, and it is not a diagnosis of anything.

d. Anything you type to us in your own words

What it is: questions you type into the Ask Allison AI chat (a feature we are building, not yet switched on), messages you send through the in-app feedback box, answers to in-lesson questions, and answers to our optional beta outcomes survey. These are free-text, so you could mention something health-related if you chose to.
Where it comes from: you, directly, when you decide to write to us.
Why we collect it: to answer you, to fix problems you report, and to understand whether the programme is working for people.
What we keep, and what we do not. Feedback, in-lesson answers and survey responses are stored. Chat is different: we keep no transcript of it at all, so there is nothing on our side to show you or delete. Your question does pass through our AI provider to be answered.
Please do not type health information into these boxes. We do not ask for it, we do not want it, and the chat is built to decline medical questions and point you to a professional instead. If you do share something health-related, we treat it as consumer health data under this policy, and we do not turn it into a health record about you.

e. Your activity in the app

What it is: which routines you built and saved, which ones you completed and when, your streak, which lessons you watched, and general usage and error data.
Where it comes from: your use of the app, on your device.
Why we collect it: to run the app, to show you your own history and streak, and to see what is working and what is broken. Some of this could be linked back to the concerns you chose, so we list it here rather than leave you to work that out.

f. Your account and contact details

What it is: your name, email address, optional phone number, your subscription status, and your consent record (what you agreed to, when, and which version of the wording you were shown).
Where it comes from: you, and our payment provider when you buy something.
Why we collect it: to give you an account, take payment, contact you, and prove what you consented to. On its own this is not health data. We list it because it is the thing that would connect everything above to you as a person.

What we do not collect

  • No faceprint. We do not create, measure, or store a scan of your face geometry or any other facial-recognition template, and we never use your photos to identify you.
  • No precise location. The app does not ask for or use your device's location, and it actively switches off the browser's location permission on every page. We do not know where you are.
  • No health records, no diagnoses, no medical conditions. We do not collect them, and the app is built so the AI cannot report them.
  • No buying health data about you. We do not purchase consumer health data from data brokers, and we do not obtain it about you from anyone other than you.

2. The consumer health data we share, and who we share it with

We do not publish your health data, and we do not hand it around. We share it in two situations: with the companies that run parts of the app for us, and where you have specifically asked us to.

The categories of third parties

a. Cloud hosting and database providers. They hold the app and its database, which includes your concern selections, your routines and activity, and your account details. Shared: everything in section 1 except your photos, which live separately.

b. Private file storage providers. They hold your progress photos privately. Shared: your photos.

c. Authentication providers. They hold your sign-in identity. Shared: your name and email address. No health data.

d. Payment processors. They take your payment. Shared: your contact and payment details, and what you bought. No concern data, no photos.

e. Email service providers. They send our emails. Shared: your name, email address, and general subscriber status. Concern-based tags would be shared here only if you opt in to tailored personalization, which is a separate, explicit choice. We are not sending concern tags to our email provider today.

f. Product analytics and error-monitoring providers. They help us see which features are used and catch errors. Shared: your activity data and an identifier for your account. These are non-essential, so you control them. In the EEA and UK they do not run at all until you accept. Everywhere else they run unless you decline, and you can decline at any time using the links in section 3c. We do not record your screen.

g. AI service providers. They will power the Ask Allison AI chat, which sends them your typed question so they can write an answer and find the right lesson for you. If photo analysis ever launches, an AI provider would also receive the photo you chose to submit. These providers work for us under data-processing agreements and are contractually barred from using your data to train AI models.

h. Advertising and measurement platforms. We measure how our ads perform. What we send is: that a page was viewed, and, when a purchase happens, the amount, the currency, the name of the product bought, hashed versions of your contact details (email, phone, name, city, postal code, country), a hashed account identifier, the platform's own click and browser identifiers, your IP address, and your browser type. We do not send your concern selections, your photos, or any analysis results to any advertising platform. We do note honestly that a product name can suggest what part of the face a course is about, so a purchase event can imply an interest. You can switch advertising measurement off at any time (see section 4), and in the EEA and UK nothing advertising-related runs until you say yes.

i. Legal authorities, where the law requires it.

We do not share health data with

  • Data brokers. We do not sell, rent, or trade your data to anyone who resells it.
  • Other members. Your photos and your concerns are never shown to other members.
  • Other companies in a group. Fingertip Facelift is a brand of A Wise Approach LLC. We do not pass your consumer health data to any other company that owns us or that we own.

Your photos, specifically

Your progress photos are private to you by default and are shared with nobody. Sharing a photo with us for marketing is not switched on yet. When it is, it will be a separate per-photo permission you can withdraw. That is described in our main Privacy Policy and in our Terms.

3. Your rights, and exactly how to use them

These rights are yours under the Washington My Health My Data Act. You do not need an account to make a request, and we will not charge you or treat you worse for making one.

How to make a request. Email help@fingertipfacelift.com and tell us which right you want to use. Put "Health data request" in the subject line if you like, though we will read it either way. Some of these you can also do yourself, in the app, without asking us. Those are noted below.

How long we take. We will respond within 45 days of receiving your request. If your request is genuinely complicated, we may take up to 45 days more, and we will tell you why before the first 45 days are up.

Proving it is you. Because this data is sensitive, we need to be reasonably sure the request comes from you before we hand over or delete anything. Usually that means replying from the email address on your account. If we cannot confirm who you are, we will tell you so rather than guess.

a. The right to know, and to see your data

You can ask us to confirm whether we collect, share, or sell your consumer health data. If we do, you can ask for a copy of it. When we answer, we will also give you a list of every third party and affiliate we have shared or sold your consumer health data to, with a working email address or other way to contact each of them.

b. The right to have it deleted

You can ask us to delete your consumer health data, and we will.

  • You can do this yourself, right now. Your account settings have a "Delete Your Account" control that wipes your profile, your routines and practice history, and your photos, cancels your membership, and takes you off our email list. You can also delete any individual photo at any time, which removes it from storage and from our database immediately.
  • We delete it from our own systems, both the live app and our file storage.
  • We pass the instruction on. When you ask us to delete your consumer health data, we tell every service provider and every affiliate that holds it on our behalf to delete it too, and we direct any third party we have shared it with to do the same and to pass that instruction to their own providers. Some of those deletions happen automatically as part of the same action, and some are done by hand by our team. Either way we keep a record that it was done.
  • Backups. Our backups exist so we can recover from a disaster, and they are on a rotating schedule, so a copy of deleted data can sit in a backup until that backup expires. A restore is never allowed to bring back data someone asked us to delete.
  • What we keep, and why. We keep the record that a sale happened, because tax law requires us to keep sales records for years. Those retained records no longer carry your email address: it is replaced with a placeholder and a one-way code. We also keep a short line in our deletion log saying that your request was made and honored on a particular date, because that log is how we prove to you, or to a regulator, that we actually did what you asked. Neither of those holds any of your health data: no concerns, no photos, no analysis results, no answers you wrote.

c. The right to withdraw your consent

You can withdraw your consent to us collecting or sharing your consumer health data at any time, and you do not have to give a reason. Withdrawing consent does not undo processing we already did before you withdrew, and it does not affect your ability to use the app.

  • Photo storage consent: withdraw it in your account settings, and delete your photos there.
  • Beta marketing release: if you gave one at the end of the follow-up, turn off "my before-and-after photos and my words may be used in marketing" in your account settings. We stop using them publicly from that moment.
  • Beta study results: turn off "my answers may be used in shared results" in your account settings. We stop using your answers in anything we publish and stop inviting you to the follow-up.
  • Personalization and tailored marketing: turn it off in your account settings. We stop using your concerns to tailor anything and we remove you from tailored audiences.
  • Photo analysis: you choose it per photo, so simply do not tick the box. Deleting a photo also deletes anything we derived from it.
  • Analytics and advertising measurement: use the Cookie Preferences link in the footer, or the Do Not Sell or Share My Personal Information link, also in the footer. We also honor the Global Privacy Control signal from your browser.
  • Marketing emails: unsubscribe from any email, or use the setting in your account.
  • Or just email us at help@fingertipfacelift.com and we will do it for you.

d. The right to appeal if we say no

If we refuse your request, we will tell you in writing, within the 45 days, why we refused and how to appeal. Appealing is free.

To appeal: reply to our refusal, or email help@fingertipfacelift.com with "Health data appeal" in the subject line. Tell us what you asked for and why you think our answer was wrong.

What happens next: a person who was not involved in the original decision reviews it, and we respond in writing within 45 days of receiving your appeal, explaining our reasoning.

If we still say no: we will give you a way to complain to the Washington State Attorney General's Office. You can file a complaint with that office at www.atg.wa.gov/file-complaint at any time, whether or not you have appealed to us first.

4. Consent, and what we would have to do before ever selling your health data

Collecting or sharing your health data needs its own, separate consent

Under Washington law, agreeing to our Privacy Policy or our Terms is not consent to collect or share your consumer health data. Consent has to be its own decision, and that is how we have built it.

  • We collect only what is needed to give you the thing you asked us for, unless you separately say yes to more.
  • Every one of our health-related permissions is a separate, unticked box. Nothing is bundled into a single "I agree", and nothing is pre-ticked for you.
  • None of the permissions above is required to use the app. You can build routines and use your membership without saying yes to any of them.
  • Our beta outcomes study is the one thing we do ask you to complete. It is running now. If you joined during the beta, we ask a short set of questions about how you feel about your face before you build your first routine, because measuring whether the method actually works is the point of the beta. Two of those questions, the ones you answer in your own words, are optional, and so is adding a photo. If you are in the EEA or the UK, the whole thing is optional and you can skip straight to your routine.
  • Letting us use your answers is separate, and always optional. Answering the questions is one thing; agreeing that your answers may appear in results we share, such as "most testers saw a change", is another. That box is never required, you can leave it unticked, and you can change your mind at any time in your account settings. If you turn it off we stop using your answers in anything we share, and we stop inviting you to the follow-up. Your answers are not deleted by this, and you can delete them along with everything else at any time.
  • We record each consent with the date, the time, and the exact version of the wording you were shown, so if we ever change the wording, your old consent is still traceable to what you actually read.
  • You can withdraw any of them at any time (see section 3c).
  • We do not use your consumer health data for a purpose we did not tell you about when we collected it. If we ever want to, we come back and ask.

Selling health data needs something stricter: a signed, valid authorization

Selling consumer health data is not something consent can cover. Washington law requires a separate document that you sign, called a valid authorization, which is different from and additional to any consent, and which has to contain all of the following:

  1. The specific consumer health data that would be sold.
  2. The name and contact details of the person collecting and selling the data (that would be us).
  3. The name and contact details of the person buying it.
  4. A description of the purpose of the sale, including how the buyer would gather and use the data.
  5. A statement that the product or service you asked for can be provided to you even if you do not sign.
  6. A statement that we may not condition the product or service on your signing.
  7. A statement that you have the right to revoke the authorization at any time, and a description of how to revoke it.
  8. A statement that the data being sold may be redisclosed by the buyer and may then no longer be protected by this law.
  9. An expiration date no more than one year from the date you sign.
  10. Your signature and the date.

The authorization also has to be written in plain language, we have to give you a copy of it, and both we and the buyer have to keep a copy for six years.

Where we stand today

We do not sell your consumer health data. We never have, and we have no plans to. Nobody has ever been asked to sign a valid authorization, because we have never sold anything that would need one, and we do not receive money or anything else of value in exchange for your concerns, your photos, or any analysis results.

The one thing worth naming plainly, because we would rather you heard it from us: we use advertising measurement (the Meta pixel and Conversions API) to see which of our ads lead to purchases. As described in section 2h, those events carry purchase and contact information, and never your concerns, your photos, or any analysis results. We treat that as advertising measurement about a purchase, not as a sale of health data. You can switch it off at any time using the Cookie Preferences or Do Not Sell or Share links in the footer, or by turning on Global Privacy Control in your browser, and if you are in the EEA or UK it does not run at all until you say yes.

5. We do not use geofencing

We do not use geofencing anywhere, at all.

We do not draw a virtual boundary around any health care facility, clinic, hospital, pharmacy, counselling service, or provider's office. We do not use anyone's location to work out that they went to one, to send them a message or an advertisement because they were near one, or to collect data about them from being near one.

We could not do it if we wanted to. The app never asks for your device's location, and it explicitly switches off the browser's location permission on every page, so your precise location is not something we hold.

6. Who can see your health data inside our company

Access is limited to the people who need it to do their job. Anyone working with us who can reach member data is required to keep it confidential, under written data-protection terms we are in the process of putting in place with everyone who has access.

There is no screen in our app that lets our team browse the photographs in your private progress tracker, and we do not open them. Not the founder, not our developer, not our assistant. They are stored privately and served only to you. One thing is different, and it is your own choice: a photo you attach to an optional survey such as our beta outcomes study, which our team reads as part of that study.

7. If you live in Nevada or Connecticut

Nevada and Connecticut have their own consumer health data rules that work much like Washington's.

Nevada. You have similar rights to know what consumer health data we collect and share, to have it deleted, and to withdraw your consent. We do not sell consumer health data, and we do not geofence health care facilities, in Nevada or anywhere else.

Connecticut. Consumer health data is treated as sensitive data under Connecticut law, which means we need your opt-in consent before processing it, and the same ban on geofencing health care facilities applies.

The rights in section 3 and the commitments in sections 4 and 5 are how we handle all of this, for everyone. To use any of them, email help@fingertipfacelift.com.

8. Changes to this policy

If we change how we handle consumer health data, we will update this policy and change the date at the top. If the change is significant, or if it means we want to use data we already hold for a new purpose, we will tell you in the app or by email, and where the law requires it we will ask for your consent again rather than assume it.

9. Contact us

A Wise Approach LLC, doing business as Fingertip Facelift
Email: help@fingertipfacelift.com

For anything not specific to health data, see our main Privacy Policy. For how long we keep photo related data and how we destroy it, see our Biometric Data Retention and Destruction Policy.

© 2026 Fingertip Facelift

Stop guessing. Start knowing what to do with your face.  ·  Questions? help@fingertipfacelift.com  ·  Privacy Policy  ·  Terms & Conditions  ·  Consumer Health Data Policy  ·  Biometric Data Policy  ·  Do Not Sell or Share My Personal Information  ·  Cookie Preferences

Your privacy choices

We use cookies and similar tools to run this site and, with your permission, to understand how it is used and to measure our ads. Essential cookies that keep you signed in are always on. You can change your choice anytime from the footer. See our Privacy Policy.