Skin Journal Privacy Policy
Version: 1.0.0
Last updated: August 18, 2026
1. Scope
This Privacy Policy applies to:
- the Skin Journal mobile app (iOS and Android);
- the skinjournal.net website and its pre-registration forms.
2. What Skin Journal Is
Skin Journal is a skin journaling app that lets you log daily face photos, skincare products, habits, and receive AI-generated analyses and insights. It is not a medical device and does not replace professional healthcare advice.
3. Data We Process
3.1. Account and authentication data
- Firebase user identifier (including initial anonymous access).
- If you sign in or link your account with Google: name, email address, and profile photo associated with your Google account.
- If you sign in or link your account with Apple: name and/or email address, when Apple provides them (Apple may hide your email behind a private relay address).
- If you create an account with email and password: your email address (verification required).
3.2. Profile data
- Display name or nickname (if you provide one).
- Gender identity (and custom description if provided).
- Date of birth (to verify minimum age and personalize the service).
- Preferred language.
3.3. Face data and appearance data (special category)
Skin Journal processes face data when you take a photo of your face in the app.
- What we collect: face photographs (images of your face) that you capture for cosmetic skin-appearance analysis; derived appearance metrics (for example blemish control, hydration, and redness control); and AI-generated comments.
- How we collect it: you take a photo in the app. We do not collect face data from your camera roll unless you choose a photo yourself.
- Use: only to provide the skin-appearance analysis, scores, comments, and insights you request in the app. We do not use face data for advertising, facial recognition, identity verification, or to identify you to other people.
- Sharing: we send face photographs to Google Gemini only after you give permission in the app. Gemini processes the image to return appearance scores and a short comment. We do not send face photographs to Groq. We do not sell face data.
- Storage: face photographs are not persistently stored on our servers. We only keep the resulting metrics and comments.
- Retention and deletion: metrics and comments are kept while your account is active. When you delete your account (Profile → Delete account), we delete this data. See section 8.
3.4. Service usage data
- Skincare products you log (name, ingredients, usage dates).
- Product photographs you take to identify a product. With the same in-app permission, these photos are sent to the AI providers listed in section 5; they are not persistently stored on our servers.
- Daily habits (sleep, stress, etc., as you record them).
- Insights and hypotheses generated from your history.
- Dates and frequency of use (scan streaks, completed logs).
3.5. Technical data
- Device and session identifiers required for operation.
- Technical and security logs (IP address, device type, app version) when needed to keep the service secure.
3.6. Website data
- Email address if you pre-register on skinjournal.net.
- Cookies and similar technologies (see section 10).
3.7. Analytics and measurement (only with your consent)
If you enable the optional setting in the app or on the website, we may process:
- Usage analytics to improve Skin Journal (Google Analytics / Firebase Analytics on the web and in the app).
- Campaign and install measurement (e.g. Singular, Meta) to understand where users come from and how advertising performs.
This analytics data is pseudonymous (e.g. app instance identifiers), not anonymous. You can use the service without enabling this option and withdraw consent at any time from Settings in the app (or the cookie banner on the website).
4. Purposes and Legal Bases
- Create and manage your account (Firebase ID; Google, Apple, and/or email credentials): contract performance (Art. 6(1)(b) GDPR).
- Provide journaling and analysis (profile, processed photos, metrics, products, habits): contract performance; explicit consent for health/appearance data (Art. 9(2)(a) GDPR). We ask for your permission in the app before sending face or product photos to third-party AI providers.
- Generate AI insights (metrics history, products, habits): contract performance; consent (Art. 9(2)(a)).
- Identify and research products you log (product photos and/or search queries): contract performance; in-app permission before sending product photos to AI providers.
- Operational communications (email, if applicable): contract / legitimate interest.
- Web pre-registration (email): consent (Art. 6(1)(a)).
- Product analytics and campaign measurement (aggregated or pseudonymized usage, install attribution): consent (Art. 6(1)(a)), via the optional setting in the app or website.
- Security and fraud prevention (technical logs): legitimate interest (Art. 6(1)(f)).
- Legal compliance (necessary data): legal obligation (Art. 6(1)(c)).
5. Processors and Third Parties
We share data with the following types of providers, only as necessary:
- Google (Firebase Authentication): user authentication, including email/password accounts (US / EU).
- Google (Google Sign-In): Google sign-in (US / EU).
- Apple (Sign in with Apple): Apple sign-in (US / EU).
- Google Gemini: with your in-app permission, we send face photographs (and product photographs, if you scan packaging) so Gemini can return appearance scores, a short comment, and product identification. Face photographs are not sent to Groq. Processing takes place primarily in the United States.
- Groq: we send journal context (logged products, habits, and previous appearance scores — not face photographs) so Groq can generate insights, product notes, and hypotheses. Processing takes place primarily in the United States.
- MongoDB (hosting infrastructure): app data storage (per hosting provider).
- Google Analytics / Firebase Analytics: usage analytics on the web and in the app, consent only (US).
- Meta (Facebook Pixel): web campaign measurement, consent only (US).
- Singular: app install attribution and campaign measurement, consent only (US).
All providers are subject to data processing agreements or standard contractual clauses where applicable.
6. International Transfers
Some providers are located outside the European Economic Area (primarily the United States). Transfers are made with GDPR safeguards (EU Standard Contractual Clauses, adequacy decisions, or other applicable mechanisms).
7. Data Controller
Óscar Ares Bascón
Tax ID (NIF): 54131325C
Address: Simón Bolívar 15, 1ºA, Spain
Privacy email: [email protected]
Skin Journal is a service operated by an individual (self-employed) based in Spain.
8. Data Retention
- Active account: we keep your data while you maintain your account.
- Photographs: not persistently stored; only derived metrics and comments are kept.
- After account deletion: we delete all associated personal data (analyses, products, habits, insights, profile) within a reasonable timeframe. You can delete your account from the app (Profile → Delete account).
- Web pre-registration: until you request removal or data is no longer needed.
- Security logs: minimum necessary period (typically up to 12 months).
9. Minors
Skin Journal is intended for people aged 16 or older. We do not knowingly collect data from anyone under 16. If we discover an account created by someone under 16, we will delete it.
10. Cookies and Similar Technologies (Website)
On skinjournal.net we use:
- Strictly necessary cookies: for basic site operation (e.g. language preference).
- Analytics cookies (Google Analytics): only if you accept in the cookie banner.
- Marketing/measurement cookies (Meta Pixel): only if you accept in the cookie banner.
You can manage your preferences at any time via the cookie banner or your browser settings.
11. Your Rights
You have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erasure ("right to be forgotten").
- Restrict processing.
- Data portability.
- Object to processing based on legitimate interest.
- Withdraw consent at any time (without affecting prior lawful processing), e.g. by turning off analytics in the app Settings or rejecting analytics cookies on the website.
To exercise your rights, email [email protected] with your request and identity verification if needed.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es.
12. Security
We apply appropriate technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), secure authentication via Firebase, and access controls on servers.
13. Changes to This Policy
We may update this Privacy Policy. We will notify you of significant changes in the app or on the website. The current version is always available at skinjournal.net/en/privacy and via the app API.
14. Contact
Óscar Ares Bascón
Simón Bolívar 15, 1ºA, Spain