iBeauti Privacy Policy
Effective date: September 19, 2026
IBEAUTI TECHNOLOGY LLC (“we”, “us”, “our”) operates iBeauti, a beauty routine application available on the web at ibeauti.com and as a mobile app for iOS and Android (“the Service”). This policy describes what information we collect, how we use it, and the choices you have.
What we collect
Account information
When you create an account we store your email address and, if you provide one, a display name.
You can sign in with an email address and a password, or through Google, Facebook or Apple. If you set a password, it is held only by our authentication provider and only as a hash — we never see it, and nothing else in the Service stores it. If you sign in through a provider, that provider shares your email address (and, for Apple, your name if you allow it) so we can create your account. We do not receive or store your password from those providers.
Your email address is never shown to other users. Our own staff can see it: see Who at iBeauti can see what below. Your display name and profile picture are shown on your profile, on routines you publish and beside comments you leave — including to people who are not signed in. Your bio is shown on your profile to anybody who can read it — anybody signed in if your profile is public, the followers you have accepted if it is private.
Profile information
You may optionally provide:
- A profile picture (avatar)
- A short bio
- A skin type — never shown to another user. It is used only to break a product’s or a routine’s star ratings into anonymous groups, and only when a group holds enough people to stay anonymous. Our administrators can see it: see Who at iBeauti can see what below
- Style preferences (the looks you like) — never shown to anybody else
- A handle (a public username, e.g. ibeauti.com/mina)
- Whether your profile is public or private, and how you have arranged the public version of it — the routines and products you pin to it, and the note you write beside each
We also keep a shareable profile code, so you can hand somebody a link to your profile, and you can revoke it. A routine you publish can have a code of the same kind.
Routines and products
The core of iBeauti is beauty routines — ordered lists of products with notes and face-chart placements. We store the routines you create, the products you add to them, the notes you write, and where on the face chart you place each step. A routine keeps two separate pieces of writing: a private note, which is yours, and a public note, written to be read by whoever you publish it to. We also store your folders, the order you arrange your routines in, and unfinished work you have kept as a draft.
You may also keep a product shelf — a personal inventory of products you own or want, organised into folders and into an order you arrange, with favourites, the date you opened something, when you would like to replace it, a private note and private star rating on a product, and tags of your own invention. All of that is visible only to you.
Separately, you may keep a public shelf on your profile: the products you choose to show there, a note beside each, and the retailer links you add. That one is meant to be read by other people, and is.
Photographs
You may upload photographs for your avatar, for products, and for how a look turned out. The apps remove location data and other metadata from a photograph before it is uploaded — both apps re-encode a picture on your device before it leaves it.
Avatars and product images are public. A routine photograph is private by default: only you can see it, even after you publish the routine it belongs to. You can mark an individual photograph to travel with the routine, and then anybody signed in who can read that published routine can see it — for a public profile that is any signed-in person, and for a private profile it is the followers you have accepted. Routine photographs are served through links that expire rather than from a public address.
Messages
You can send direct messages to people who follow you back, and a consultant and the person they handed a routine to can message each other. You can send a single message request to somebody you follow, which they accept or decline; declining deletes it. Messages are visible only to the two participants in a conversation, with two exceptions:
- If somebody reports one of your messages, a moderator is shown the text of the reported message. They are shown that message alone — never the conversation around it.
- A conversation belongs to both people. If either participant deletes their account, the conversation and every message in it is deleted for both, so the other person loses the history too.
Ratings, comments and reports
You may rate products and published routines from 1 to 5 stars. Ratings are shown only as totals and averages — they are never displayed beside your name. Comments you leave on products are public, carry your display name and profile picture, and can be read by anybody, signed in or not.
If you report a comment, a routine, a profile or a message, we store what you reported, the reason you chose and any note you wrote. Only you and our moderators and admins can see it.
Support requests
If you send us a bug report or a suggestion from the support page, we store what you wrote, the contact address you gave us so we can answer, which app you sent it from and which version of it, and the page or screen you were on when you pressed the question mark. If you were signed in we also store which account sent it; if you were not, we store no account at all. You are shown a ticket number, which is how you refer to the request if you write to us again.
The forms work whether or not you are signed in, deliberately: “I cannot sign in” is a report worth being able to send. Your request is readable by our moderators and administrators, and is also emailed to our support address — see Third-party services below.
Following, blocking and activity
We store who you follow, who follows you, pending follow requests, and the accounts you have blocked — your blocks are visible only to you. We also store when you last opened What’s new, so the app can mark what has happened since.
Consultant handovers
If a consultant builds a routine for you in a store, we store the code they hand over, when it was first opened, how many times it has been opened, and — once you claim it — that your account claimed it and when. We also count scans and claims against the routine itself. That count records nothing about the person scanning: no IP address, no device details, no account.
If you are a consultant, we store your consultant record and the store it belongs to.
Device information
If you enable push notifications, we store a device token — an identifier issued by Apple’s or Google’s push service via Expo — and which of the two platforms the phone runs. We do not collect device identifiers for any other purpose. The token is deleted when you sign out, and when the push service tells us it no longer names a device.
Push notifications are sent for direct messages, including the first message of a message request. One carries the sender’s display name, the beginning of the message — or “sent a routine”, “sent a product”, “sent a person” where there was no text — and the identifier of the conversation to open. Everything else the app tells you about, including new followers and announcements, appears inside the app and is not pushed.
Camera and photo library
The mobile app requests access to your camera (to scan QR codes and barcodes, and to photograph products) and your photo library (to select an existing picture). The web app may request camera access for barcode scanning. We do not access your camera or photo library in the background.
When you scan a product barcode, the barcode is sent to our barcode lookup provider (see Third-party services) and the result is cached, along with which account asked for it, so the same barcode is not looked up twice.
Usage
While you are signed in, we record a short list of actions so we can see whether the app is being used and whether it is working: opening the app, opening the builder, opening one of your routines, opening somebody else’s published routine, opening a product, running a search, scanning a barcode or an iBeauti code, opening your shelf, and sharing a link. That is the whole list.
Each record holds which of those actions it was, whether it happened in the web app or the phone app, and when. It does not hold what you searched for, which routine or product it was, your IP address, your device, your screen size, or how long you stayed. We use these only for counts on our own internal admin screen — how many accounts were active, how many came back, how often each action happens. They are never used to build a profile of you, and they are never shared.
Nothing is recorded while you are signed out, and repeated openings of the app or of your shelf are collapsed into at most one record every thirty minutes each. These records are kept for as long as your account exists and are deleted with it.
Information we do not collect
We do not collect your location, contacts, browsing history, or any information from other apps on your device. We do not serve advertising. Neither app contains an analytics or tracking SDK. The web app’s security headers explicitly refuse access to microphone, geolocation and payment APIs.
Stored on your device
Some things stay on your device rather than being sent to us:
- Your sign-in session, so you stay signed in. In the browser this is ordinary local storage; on the phone it is the app’s own storage, which is not encrypted and not in the device keychain — on a jailbroken or rooted phone the stored sign-in token can be read by other software.
- Recent searches, unfinished routine work you have not saved, and rows you have dismissed from What’s new.
- On the phone, the products you recently viewed, added or put on a routine — the name, the brand and the picture, so the list draws without asking us for them again. It is not sent to us, and Clear on that screen removes it.
- On the phone, a cached copy of lists the app has already shown — your routines, your drafts, which features are switched on — so it can draw them again without waiting.
- The confirmation code for an account deletion you have requested, so you can check on it.
Signing out clears the stored session and removes that phone’s push token. Deleting the app, or clearing the site’s data in your browser, removes the rest. Deleting your account clears both.
How we use your information
We use the information above to:
- Provide the Service — creating and storing your routines, showing your profile, delivering messages and notifications
- Look up products by barcode when you scan one (see Third-party services below)
- Moderate content — see Who at iBeauti can see what below
- Understand how the Service is used — aggregate statistics such as how many accounts there are, how many people signed in recently, how many routines have been published and how handovers are going. These are worked out from the records described above at the moment an administrator opens the admin screens. There is no separate record of what you open or view, and the statistics are visible only to administrators
We do not sell your information. We do not share it with advertisers.
Who at iBeauti can see what
Access is by role, and it is narrower than the whole database.
Moderators can open the report queue — for each report, the reported comment, published routine name, profile name or message text, who it belongs to, and whether that account is suspended. They can also open the catalog review queue, which shows a submitted product, its barcode and picture, the email address of whoever submitted it, and what our barcode lookup provider returned for it — including which account scanned it. They can open the support queue, which holds what somebody wrote on a bug or feature form and the contact address they left. Moderators and administrators can both read the log of what staff have done.
Administrators can do everything a moderator can, and can also open the accounts list — every account’s email address, display name, role, whether it is on early access, when it was created, how many routines it holds, and its consultant and store record — plus the aggregate statistics described above, the stores, the feature flags and the announcements. An administrator can also read the rest of your profile record: your bio, your skin type, and whether your account is suspended.
Nobody on staff can read your routines, your shelf, your private notes, your drafts, your photographs or your messages, other than a single message that has been reported.
Third-party services
- Supabase (supabase.com)
- What we share: all data described above, plus the ordinary record of a web request (IP address, browser) that any host keeps.
- Why: our database, authentication and file storage provider. Data is stored in the United States (AWS us-west-2).
- What we share: your email (during sign-in).
- Why: authentication, if you choose Google sign-in.
- Facebook / Meta
- What we share: your email (during sign-in).
- Why: authentication, if you choose Facebook sign-in.
- Apple
- What we share: your email and name (during sign-in).
- Why: authentication, if you choose Apple sign-in.
- Expo (expo.dev)
- What we share: device push tokens, and the notification itself — the sender’s display name and the beginning of the message.
- Why: delivering push notifications to your device.
- UPCItemDB (upcitemdb.com)
- What we share: product barcodes (GTINs).
- Why: looking up product information when you scan a barcode.
- Catalog picture hosts (Open Beauty Facts, retailers and manufacturers’ own sites)
- What they receive: your IP address and browser or device details, and which catalog picture was loaded.
- Why: many catalog product pictures are loaded directly from whichever site supplied them rather than copied to ours, so your device fetches them from that site. We do not send them your account, your name, which page you were on or what you searched for.
- Resend (resend.com)
- What we share: a support request you send us — what you wrote, the contact address you gave, the ticket number, and which app, version and page it came from.
- Why: delivering that request to our support address as an email, so somebody reads it. Sign-in and password-recovery mail does not go through them.
- Vercel (vercel.com)
- What we share: standard web request data (IP address, browser).
- Why: hosting the web application.
Data retention
We keep your data for as long as your account is active.
When you ask us to delete your account, the account is closed immediately: you are signed out everywhere and nothing can be written to it again. The erasure itself then runs in the background on a schedule, and normally finishes within a few days. What we remove:
- Your profile, routines, folders, drafts, shelf, private notes, tags, follows, blocks, ratings, comments, reports and messages, and the barcode lookups your scans triggered
- Your conversations, which are removed for both participants
- Your photographs (avatar, product images, routine media)
- Your device push tokens
- Your usage records
- Your authentication record
Some things are deliberately left behind, in a form that is no longer yours:
- A product or shade you submitted to the catalog that was approved stays in the shared catalog, because other people’s routines point at it. Your name is removed from it and so is any description you wrote. A submission still awaiting review is deleted, and a step in somebody else’s routine that pointed at it is left saying “Removed product”.
- A routine of yours that somebody else copied or saved stays in their account. It is renamed, and your attribution, the photographs and the notes carried over from your copy are removed.
- Where a consultant built a routine for you in a store, their own record of it is theirs and stays. The fact that you claimed it is removed.
- A support request you sent stays, with your account taken off it. Its ticket and the contact address you gave us stay, because that is how the request is answered and found again.
A support request is kept for as long as it is open, and for twelve months after it is closed. If you delete your account, the account behind a request you sent is removed from it — what you wrote, the contact address you gave and the ticket stay for the rest of that period, because a support thread we are in the middle of is a conversation with two people in it.
We do not keep anonymous statistics from a deleted account. If that ever changes we will say so here first.
Copies of the data may survive in restricted backups until those backups age out, after the retention period configured for the Service. Nothing is restored from a backup into active use.
A deletion receipt is kept for 30 days after completion so you can verify the deletion was carried out, then it too is removed.
Your choices
Delete your account
You can delete your account from the app at any time. On the web, go to Account → Delete account; on the phone, go to Account → Delete account. You can also do it at ibeauti.com/delete-account without installing the app. You confirm in a dialog, and if you have not signed in recently you are asked to sign in again first — with whatever sign-in method you normally use.
Facebook data deletion
If you signed in with Facebook, you may also request deletion through Facebook’s interface. We provide a data deletion callback that Facebook calls on your behalf, which triggers the same deletion process. Deleting your iBeauti account does not delete your Google, Facebook or Apple account.
Control your visibility
Your profile is private by default: only the people you have accepted as followers can read the routines you publish and the profile page you arrange. If you make your profile public, your display name, picture, handle and published routines can be read by anybody, including people who are not signed in. You can remove a follower, and you can block individual users.
Manage notifications
You can disable push notifications at any time through your device’s settings.
Children
iBeauti is not directed at children under the age of 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
Security
All data is transmitted over HTTPS. The apps remove location and other metadata from a photograph before uploading it. Access to the database is controlled by row-level security policies — each user can only read and modify their own data, with specific exceptions for public content (published routines, public profiles, product comments). Routine photographs are held in private storage and served through links that expire. Staff access is restricted to accounts with the appropriate role and is limited to what Who at iBeauti can see what describes above; every action staff take on somebody’s content is logged.
Changes to this policy
We may update this policy from time to time. We will post the updated policy at this page and update the effective date. For material changes, we will notify you through the app.
Contact
If you have questions about this policy or your data, contact us at support@ibeauti.com, or through the support page, which reaches the same address.