Lookmax Analyzer logo
Privacy by design

Privacy Policy

This policy explains what stays in your browser, what is processed by our service providers, and the choices you have when using Lookmax Analyzer.

Last updated: October 3, 2026
1

Who controls your data

Lookmax Analyzer is the controller of personal data processed through this website, except where a service provider acts as an independent controller under its own terms. You can contact us at [email protected].

2

Photo processing and browser storage

Facial analysis is performed locally in your browser. Your uploaded photo and facial landmarks are not sent to our servers as part of the analysis or paid-report flow.

To preserve your analysis while you move through checkout and open a paid report, your browser may store a compressed copy of the photo together with scores, measurements, report preferences, and unlock state in local storage. This data remains on your device until you use Clear my data, clear browser storage, or your browser removes it.

Paid access is also represented by a secure, signed browser cookie that normally expires after 30 days. The cookie contains a report reference and entitlement information, not your photo.

3

AI Appearance Coach

The coach is an optional feature included with eligible paid reports. When you use it, we send OpenAI your question, recent conversation messages, and bounded report context needed to personalize the answer. That context may include scores, measurements, displayed priorities and strengths, report actions, hairstyle direction, and the preferences selected in your report.

We do not send your original photo, raw facial landmarks, full payment details, or contact details to OpenAI through the coach. Requests use the OpenAI API with application-state storage disabled. OpenAI may nevertheless retain prompts and responses in abuse-monitoring logs for up to 30 days by default, unless an exception or different approved data control applies.

Up to 12 recent coach messages are stored in your browser's session storage so the conversation survives a reload in the same browser session. They are normally removed when that tab's browser session ends and can also be removed with Clear my data.

Do not include sensitive personal information. Coach responses may be inaccurate and are general appearance information, not medical, dental, dermatological, psychological, or surgical advice.

4

Optional AI styling and hairstyle previews

Eligible Full and Advanced reports may include one optional AI-generated styling preview. The feature remains off until you select its unchecked consent box and request generation. We then send OpenAI a compressed copy of your analysis photo and a bounded list of reversible styling directions, such as hair framing, grooming, or makeup direction. We do not send raw facial landmarks, payment details, contact details, or the full report.

For the single styling makeover, the source photo is relayed in memory and the generated JPEG is returned directly to your browser. We do not save either image to our application storage or Redis. Your browser may save the generated preview in local storage so it remains visible on the device where it was created; Clear my data removes that browser copy.

Full reports may also offer four hairstyle try-ons and Advanced reports six, generated together as one comparison sheet after separate consent. We send OpenAI the compressed photo and hairstyle directions selected from the verified report measurements, styling goal and hair profile. The source photo is relayed in memory. For hairstyle sets, we retain the generated sheet and its option descriptions privately in Upstash for up to 30 days so a refresh or lost response can recover the result without another generation charge. A copy may also be saved in your browser. Clear my data deletes the server copy before removing paid-access credentials and removes the browser copy. Counters remain to prevent resetting the allowance. Hairstyle previews do not change your face scores or predict real-world results.

OpenAI states that API data is not used to train its models by default. OpenAI may retain image inputs and outputs in abuse-monitoring logs for up to 30 days unless an approved alternative data-control setting applies. Image inputs are also scanned for child-safety enforcement. The preview is an AI visualization, not a prediction of structural, medical, skincare, or real-world results.

5

Optional photo-aware report analysis

Eligible Full and Advanced reports may offer an optional photo-aware analysis. It remains off until you select its separate unchecked consent box. If selected, we temporarily save an encrypted copy of the photo for delivery. The initial review starts automatically after verified payment, even if you close checkout. We then send OpenAI the exact compressed analysis photo, bounded report scores, the current candidate advice and its supporting evidence, available local appearance evidence, photo-quality limitations, and the styling preferences you choose. The review may validate, revise, remove, reorder, or add reversible advice and may estimate apparent age and visible skin presentation. We do not send raw facial landmarks, payment details, contact details, or the full rendered report.

For consented checkout delivery, the compressed photo and bounded context are encrypted in Upstash for up to seven days. We delete this temporary copy when the review finishes or checkout expires or fails. Clear my data also revokes pending delivery. Upstash QStash queues only a purchase identifier for background delivery; the photo and report context stay in encrypted storage until the review runs. Photos submitted directly for a later review are relayed in memory. We store the validated observation and recommendation JSON in Upstash for up to 30 days so the result can be recovered without resending the photo. A copy may also be stored in your browser for same-device continuity. Clear my data attempts to delete the server copy before removing browser data and paid-access credentials.

Your report review is generated automatically by AI; it does not include a manual photo assessment. Authorized provider personnel may review retained content for safety enforcement or legal obligations under its data controls. OpenAI API data is not used to train its models by default, but may be retained in abuse-monitoring logs under OpenAI's applicable data controls. The result is general appearance information and may be inaccurate. It is not medical, dermatological, dental, psychological, or surgical advice.

6

Server-side enforcement and retention

We use Upstash to enforce the plan-specific question allowance, prevent duplicate charges against that allowance, and rate-limit abuse. The stored records use hashed or pseudonymous identifiers rather than your photo or raw Stripe Checkout ID.

  • The used-question and provider-attempt counters are retained for the lifetime of the paid-report entitlement so refreshing the browser cannot reset the allowance.
  • Generated answers and retry markers are retained for up to 30 days so a retry does not consume another included question. The original question is not stored in this server-side retry record.
  • Hashed IP rate-limit counters are short-lived and normally expire after a few minutes.

Assistant questions and answers are not included in our analytics events.

7

Payments and paid reports

Payments are processed by Stripe. Stripe collects payment and billing details under its own privacy terms. We receive limited checkout information such as payment status, price, currency, country code, a report reference, and pseudonymous transaction metadata needed to unlock and support the purchase. We also attach the report score, selected appearance goal, and gender setting to the Stripe transaction so we can understand and support purchases. We do not send the report photo or facial measurements to Stripe, and we do not receive or store your complete card number.

We use a report-context hash to bind paid access to the report that was purchased. This prevents a paid token from being reused for different report data without sending the report photo to Stripe. New eligible purchases may also include a one-way hash that binds optional photo analysis to the exact locally retained image. Stripe receives the hash, not the image.

8

Cookies, analytics, and experiments

We use Google Analytics 4 only after you consent. Consented events may include pages visited, device type, score or score bucket, selected appearance goal or gender setting, plan and pricing variant, and a one-way purchase reference used to prevent duplicate counting.

Analytics events do not contain your photo, facial landmarks, complete payment details, contact details, coach questions or answers, or raw Stripe Checkout identifiers. You can change your analytics choice through Cookie Preferences in the footer.

Essential browser storage and cookies are used for report continuity, secure paid access, fraud prevention, and stable product-experiment assignment. These are separate from optional analytics consent.

9

Service providers and transfers

We use a limited group of providers to operate the service:

  • Vercel for website hosting and request processing;
  • Stripe for checkout and payment processing;
  • OpenAI for coach answers, safety moderation, consented photo-aware report analysis, and consented styling previews;
  • Upstash for pseudonymous counters, retry records, and rate limits; and
  • Google Analytics 4 when analytics consent is granted.

These providers may process data in countries other than your own under their applicable contractual and legal safeguards. Affiliate links may take you to independent third-party sites whose privacy practices we do not control.

10

Your choices and rights

You can remove browser-held analysis data with Clear my data, clear site data in your browser, decline or withdraw optional analytics consent, and choose not to use any optional AI feature.

Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing of personal data, and to complain to a data protection authority. To make a request, email [email protected] with enough information to locate the relevant purchase or report. We may need to verify the request before acting on it.

11

Security, changes, and contact

We use reasonable technical and organizational safeguards, including signed paid-access tokens, request-size limits, rate limits, pseudonymous identifiers, and restricted server credentials. No internet service can guarantee absolute security.

We may update this policy as the service or legal requirements change. Material changes will be reflected here with a revised date. Questions and privacy requests can be sent to [email protected].