Privacy Policy
Last updated: 31 August 2026
Preveal is a hairstyle preview tool. You give it a photo, it shows you what a different cut or colour could look like on you. This policy explains, in plain language, exactly what happens to that photo — and to everything else.
We wrote this policy from our own source code rather than from a template, so that every sentence below describes something the app actually does. If you find a gap between this document and how Preveal behaves, that is a bug and we want to hear about it: aaronjasonall@gmail.com.
The short version
- Photos uploaded for previews may be stored securely for up to 7 days. This lets you reuse the same photo without uploading it again. Reuse never extends the original expiry, and you can delete an upload in Settings.
- Your photo is sent to OpenAI to generate the preview. OpenAI does not use it to train models, and deletes its safety copy within 30 days.
- The previews you generate are stored on our servers so the app can load them. You can delete them at any time, from inside the app.
- Face shape and colour analysis never leaves your phone. That feature runs entirely on your device.
- There is no account. We never ask for your name, email address or phone number.
- Analytics and ad measurement are optional. We use Mixpanel to understand usage and AppsFlyer and Meta to measure our ad campaigns. If you allow tracking, an advertising identifier may be read for that measurement; if you decline, none is.
1. Who we are
Preveal is operated by Preveal Team ("we", "us"), the developer of the Preveal iOS app.
Contact: aaronjasonall@gmail.com
2. What we collect
2.1 Photos you choose to preview
When you pick or take a photo and ask for a preview, that photo is sent over an encrypted connection to our server, which forwards it to OpenAI's image API to produce the edited image.
To avoid asking you to upload the same photo for every preview, we store the encrypted upload in Cloudflare R2 for a fixed period of up to 7 days. We store a one-way hash of an installation-only ownership key and the photo hash in Cloudflare D1 so only the same app installation can reuse or delete it. Neither hash is used to identify your face or match you to another person.
Reusing the photo does not extend its original expiry. You can delete an uploaded source photo earlier from Settings → Photo storage. Deletion blocks reuse immediately; if object storage is temporarily unavailable, our server keeps retrying the physical deletion.
The original photo is also saved on your own device, so that a saved look can show you the before/after pair. That copy never leaves your phone except as described above, and it is deleted when you delete the look.
2.2 The previews we generate
The generated image is stored on our servers (Cloudflare R2) so the app can load it, together with a small database record: the image's file key, your device ID, and the time it was created.
These stored previews are kept until you delete them. They do not expire on their own. Deleting a look in the app — individually, or all at once from Privacy Center — removes it from your device and asks our servers to delete their copy too; if your device is offline at that moment, the app retries the server-side deletion the next time it launches.
2.3 A device identifier
The app generates a random identifier the first time it runs and stores it on your device. It is sent with each request so that our servers know which previews belong to you and how many free looks you have used.
It is not Apple's advertising identifier (IDFA), and not the vendor identifier (IDFV). It is a random value with no meaning outside Preveal, and it is not linked to your name, email, Apple ID, or any other identity. Deleting and reinstalling the app produces a new one. (Advertising measurement may read IDFA separately when you allow tracking — see §2.6.)
2.4 Free-look and subscription state
We store a count of how many free previews the device has used. If you subscribe, your subscription status is verified from a receipt issued by Apple; we do not receive your payment details at any point.
2.5 Technical logs
Our servers write a short log line per request containing the request path, HTTP status, duration, the style and quality tier requested, and a random request ID. Photos are never logged, and the device identifier is not written to our application logs.
Like any internet service, our infrastructure provider (Cloudflare) processes your IP address in order to route and protect the connection.
2.6 Analytics and advertising measurement
Preveal uses three SDKs to understand how the app is used and to measure the performance of our advertising. Each runs only after you see the app's privacy explainer during onboarding.
- Mixpanel receives a stream of app-usage events (app launches, screens viewed, previews generated, paywalls shown, purchases) together with the random device identifier from §2.3. We use this to improve the app.
- AppsFlyer measures which of our ad campaigns brought you to the app. When you grant tracking permission (below), it may read Apple's advertising identifier (IDFA) for attribution; otherwise it works without it, using Apple's SKAdNetwork report.
- Meta (Facebook) records app activations and purchase events so we can measure campaign results, and passes its identifiers to our server for reporting.
Tracking permission. On first launch the app asks, through Apple's tracking prompt, for permission to track you across other companies' apps and websites. If you decline, no advertising identifier is read; the app remains fully usable. You can change your choice any time in Settings. We do not re-ask unless the app is reinstalled.
3. What we do not collect
- No account, name, email address, phone number or date of birth.
- No contacts, location, health data, or microphone access.
- No crash-reporting SDK (no Sentry) is present in the app at this time. If we add one, we will update this policy before it ships.
- We do not read your photo library. The app can add the looks you save to your photos, but it is not permitted to browse what is already there.
- We do not sell or share your personal information, and we never have.
4. What happens on your device only
Preveal's face shape and colour analysis runs entirely on your iPhone, using Apple's on-device vision framework and local calculations. The photo you analyse for this feature is never uploaded to us or to anyone else, and the resulting analysis is stored only on your device.
5. Service providers
We use a small number of service providers to run Preveal:
- OpenAI generates the hairstyle preview from the photo and style instruction you choose.
- Cloudflare hosts the service, stores source-photo uploads for up to 7 days, and stores generated previews until you delete them.
- RevenueCat manages subscriptions and purchase restoration.
- Mixpanel provides product analytics (§2.6).
- AppsFlyer provides ad campaign attribution (§2.6).
- Meta provides ad measurement events (§2.6).
- Apple processes payments, billing and refunds.
These providers process data only to provide their services. We do not sell personal information. Advertising measurement (AppsFlyer / Meta) happens only when you allow tracking, as described in §2.6.
6. How long we keep things
| Data | Where | Retention |
|---|---|---|
| Your source photo uploaded for previews | Cloudflare R2 + ownership/hash metadata in D1 | Up to 7 days from first upload; reuse does not extend expiry; earlier deletion available in Settings |
| Your source photo | OpenAI | Up to 30 days (abuse monitoring), then deleted |
| Your source photo | Your device | Until you delete the look |
| Generated previews | Cloudflare R2 + index record | Until you delete them; no automatic expiry |
| Generation job metadata (style, tier, timing — no images) | Cloudflare D1 | Automatically deleted after 24 hours |
| Device identifier + free-look count | Cloudflare D1 | Kept while the app is in use — see below |
| Request logs (no photos, no device identifier) | Cloudflare | Per Cloudflare's standard log retention |
One honest caveat about "delete everything". Deleting all your data in the app removes every photo and look from your device and deletes your stored previews from our servers. It does not reset the counter that records how many of your three free looks you have used — otherwise the free tier could be reset endlessly by tapping delete. That leaves one row on our side: your random device identifier and a number from 0 to 3. If you want that removed as well, email aaronjasonall@gmail.com and we will delete it.
7. Why we are allowed to do this (UK / EU users)
We apply UK GDPR and EU GDPR standards to everyone who uses Preveal, wherever they are.
- Generating your previews, storing them, and running your subscription — necessary to perform the contract you enter into when you use the app (Art. 6(1)(b)).
- Analytics (Mixpanel) and advertising measurement (AppsFlyer / Meta) — where you have given your consent through Apple's tracking prompt when the app asks for it (Art. 6(1)(a)). If you decline, none of these run.
- Counting free looks, preventing abuse, and keeping the service running — our legitimate interests in offering a free tier without it being drained (Art. 6(1)(f)).
International transfers. Our processors operate globally; in particular, OpenAI processes data in the United States. Where personal data leaves the UK or EEA, our providers rely on their own transfer mechanisms, including Standard Contractual Clauses.
8. Your rights, and how to actually use them
Because Preveal has no account system, most of these you can exercise yourself, immediately, without asking us:
| Right | How |
|---|---|
| Delete your data | Settings → Privacy Center → Delete all my photos & looks. Deletes everything on the device and your stored previews on our servers. |
| Delete an uploaded source photo | Settings → Photo storage → Delete photo. Reuse is blocked immediately. |
| Delete a single look | Delete it from My Looks. |
| Access / export | Every preview you have generated is already on your device, and can be saved to your photo library. |
| Withdraw from processing | Delete the app. Nothing continues after that except the stored previews, which you should delete first. |
| Anything else | Email aaronjasonall@gmail.com. |
If you are in the UK or the EEA, you also have the right to object to processing, to request restriction, and to lodge a complaint with your data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk).
If you are a California resident, you have the right to know what we collect, to delete it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, so there is no opt-out to offer you.
We do not offer a "correct my data" mechanism, because we hold no field about you that could be incorrect — there is no profile, no name, and no preferences record.
9. Children
Preveal is rated 13+ and is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that a user is under 13, we will delete the data associated with that device.
If you are a parent or guardian and believe a child under 13 has used Preveal, email aaronjasonall@gmail.com and we will remove the data.
10. Security
- All traffic between the app and our servers uses HTTPS/TLS.
- The app contains no AI provider keys; every AI call is made server-side.
- Stored previews are readable only by the device that created them — a request carrying a different device identifier is rejected, and file names are random identifiers that cannot be guessed or enumerated.
- We hold no passwords, because there are no accounts.
11. Changes to this policy
If we change how Preveal handles your data, we will update this page and change the date at the top. For changes that materially affect you — for example, adding an analytics SDK, or changing how long we keep your previews — we will also tell you inside the app before the change takes effect.
12. Contact
aaronjasonall@gmail.com