Hairstyle Swap
  • Results
  • How it works
  • Features
  • Pricing
Download the app

Legal

Privacy Policy

Your face is yours. This page explains, without euphemism, what happens to the photos you put into the app and the little we keep about you.

Effective the app's public release · TODO — registered legal name, Romania

Draft — not yet in force. This text is awaiting the operator's registered details and a review by a qualified lawyer. It does not bind anyone in its current form.

The short version.

Your selfie is sent to us only to make the picture you asked for, and is gone the moment it is made. We never store your photos and they are never used to train an AI model. Your looks and your photo library live on your phone, not on our servers. What we do keep is small and dull: who you are according to Google, and how many tokens you have left. You can delete all of it, permanently, from inside the app.

One honest clarification: to generate a try-on your photo does leave your phone — it has to, because the AI model runs on a server. It is held in memory, passed to the model, and never written to our database or our disks.

1. Who is responsible for your data

Hairstyle Swap is operated by TODO — registered legal name (TODO — trade register no.), TODO — registered address, Romania, Romania. Under the GDPR we are the data controller for everything described here.

For any question or request about your data, write to [email protected]. A person reads it.

2. What we collect, and why

Your account, from Google

Signing in is Google and only Google — we never see or store a password. When you sign in, Google tells us your account identifier, your email address, your display name and the URL of your profile picture. We need these to have an account to attach your tokens to. Legal basis: performance of a contract.

Your sessions

So you are not signed out every fifteen minutes, we keep one record per device: a one-way hash of your sign-in token (never the token itself, so a stolen copy of our database hands out nothing), the device's browser or app identifier, and the relevant dates. Legal basis: contract, and our legitimate interest in detecting stolen sessions.

Your tokens

We hold your token balance and an append-only list of the movements in and out of it — bought, spent, refunded. Each entry records an amount, a reason and an idempotency reference. It records nothing about the image: no prompt, no photo, no result, no description. Nothing in that ledger can be traced back to a picture you made. Legal basis: contract.

We never receive your card or payment details. Apple and Google take the payment; we are told only that a purchase was validated.

The photos you submit for a try-on

When you generate a look, your selfie and your reference photo are uploaded to our server, held in memory only, passed straight to the AI model that draws the result, and discarded. They are never written to our disks and never inserted into our database. The finished image comes back as a short-lived link that your phone downloads into your camera roll — which, along with the app's own storage on your device, is the only lasting copy that exists. Legal basis: performance of a contract, because this is the service you asked for.

We do not use your photo to identify or recognise you. No face template, faceprint or biometric signature is created, stored or compared against anything. The image is edited, not matched. Because of that, this is not biometric data under Article 9 of the GDPR, and we do not process special-category data.

This website

This site sets no cookies and has no tracking pixels. Visits are counted by Simple Analytics, which is EU-hosted, collects no personal data, builds no profile across sites and honours your browser's Do Not Track setting. Legal basis: our legitimate interest in knowing roughly how many people visit.

3. What we deliberately do not do

This list is as much a part of the design as the features are.

  • We never use your photos to train AI models, ours or anyone else's.
  • We keep no history of what you generated. There is no table for it. We could not show you a list of your past try-ons even if you asked, because we do not have one.
  • We do not sell or share your personal information, in any sense — including the specific meanings those words carry under California law. There is no advertising in the app, and no data goes to brokers.
  • No advertising identifiers, no cross-app tracking, no profiling. The app contains no advertising or attribution SDK.
  • No automated decision-making that produces legal or similarly significant effects for you.

4. Who else sees your data

We use a small number of companies to run the service. They act on our instructions, under contract, and may not use your data for their own purposes.

Who What they do Where
Google (Sign-In) Verifies who you are when you sign in, and tells us your email, name and profile picture. EU / United States
Replicate, Inc. Runs the AI image model that creates your try-on. Your photos pass through it for as long as the generation takes. United States
RevenueCat, Inc. Checks with Apple or Google that a token purchase really happened, then tells us to credit your balance. United States
Apple / Google Play Take the payment. They are the seller of record — we never see your card details. United States / global
Simple Analytics Counts visits to this website, with no cookies and no personal data. Not used in the app. European Union
TODO — hosting provider Runs our servers and the database holding your account and token balance. TODO — region

We will also disclose data if the law genuinely requires it — a valid court order, for instance. We have never received such a request; if we do, and we are allowed to tell you, we will.

5. Sending data outside Europe

Some of the companies above are in the United States, so your data reaches servers outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses, together with the EU–US Data Protection Framework where the provider is certified under it. For a try-on, the only thing crossing the border is the photo itself, for the seconds the generation takes.

6. How long we keep things

What How long
The photos you submit Seconds — the length of one generation. Never written to storage.
Generated results Never stored by us. A short-lived link at the model provider, and whatever your phone saved.
Account and token balance Until you delete your account.
Sign-in sessions 60 days from last use, or immediately when you sign out.
Your looks, inspiration board and saved selfie On your device, until you delete them or uninstall the app. We never have a copy.

7. Deleting everything

There are two separate controls, and they do different things.

  • Delete all my photos, in the app's privacy settings, erases the photos, looks and inspiration board held on your device.
  • Delete my account removes your account from our servers outright — the account record, every session and your token wallet, in one irreversible operation. It is a real deletion, not a flag on a row we keep.

Any unspent tokens are forfeited when you delete your account, and cannot be restored or refunded afterwards. Records of the purchases themselves stay with Apple, Google and our payment processor, who keep them for their own accounting and tax obligations — that is outside our control.

8. Your rights

If you are in the EEA or the UK, the GDPR gives you the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable format. Exercising any of them costs nothing and we will answer within one month.

Most of it is immediate and needs no request: your account data is visible in the app, and deletion is a control you operate yourself.

If you are unhappy with how we have handled your data, please tell us first — but you also have the right to complain to a supervisory authority:

  • Romania / EU: ANSPDCP — the Romanian National Supervisory Authority for Personal Data Processing — https://www.dataprotection.ro
  • United Kingdom: ICO — the Information Commissioner's Office — https://ico.org.uk

If you are in California

You have the right to know what we collect and why, to delete it, to correct it, and to opt out of sale or sharing. As set out in section 3, we do not sell or share personal information and never have, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights. To make a request, email [email protected].

9. Security

Everything travels over encrypted connections. Sign-in tokens are stored only as one-way hashes, so our database cannot hand out a working session. A sign-in token reused after it has been rotated revokes every session on that account, because that pattern means a copy was stolen. Your token balance is authoritative on the server, so a modified app cannot credit itself. And the strongest measure is the architectural one: the photos simply are not there to be breached.

No system is perfect. If a breach ever affects your rights, we will notify the supervisory authority within 72 hours and tell you directly when the law requires it.

10. Children

Hairstyle Swap is not for people under 16. We do not knowingly collect data from them. If you believe a child has created an account, write to [email protected] and we will delete it.

11. Changes to this policy

If we change how we handle your data, we will update this page and move the effective date at the top. For anything that materially affects you — a new category of data, a new recipient — we will tell you in the app before it takes effect, not after.

12. Contact

TODO — registered legal name, TODO — registered address, Romania, Romania.
[email protected]

Hairstyle Swap

Virtual hair try-on for every texture, for women and men. Photos stay on your device and never train a model.

Product

Results How it works Features Pricing

Company

Privacy Terms Contact

© 2026 Hairstyle Swap

AI previews are a guide — your stylist confirms what's feasible.