This Privacy Policy explains what data ZyloScore collects, how we use it, who we share it with, and the choices you have. We built ZyloScore around one principle: only store what we need, and never store your photos unless you explicitly ask us to.
1. What we collect
Account & profile data
- Account data — your email address, authentication provider (email/password or Google), and account creation time.
- Profile data — name, date of birth, gender, and optionally the country you select during onboarding, for each profile you create. Your country selection determines which regional product catalog the AI coach draws from; it is not used for advertising.
- Goals — self-improvement goals you enter during onboarding, used to personalise AI coach responses.
Photos and voice recordings
- Face scan photos (Free & Lite plans) — uploaded photos are resized client-side, sent to our AI pipeline for analysis, and discarded immediately after your score is generated. We do not store the original photos.
- Face scan photos (Pro plan) — with your explicit consent, full-resolution weekly comparison photos are stored in Cloudinary so you can track visual progress over time. You can revoke this consent and delete all stored images at any time from Settings.
- Voice recordings — audio is sent to our self-hosted voice analysis service (not a third-party API) and not retained afterward. Only the computed metrics — pitch, pitch range, harmonic quality, jitter, shimmer, speaking rate, and a confidence score — are saved to your profile.
- Photo Picker & Couple Compatibility photos — analyzed instantly and discarded. Never stored on any plan.
- Face Scan (on-device) photos — analyzed instantly and discarded. Face Scan results (scores only, no photos) are stored for 3 days and then permanently deleted.
- Live transcription (onboarding only)— during the voice passage reading at onboarding, your audio is also streamed to Deepgram (Nova 3) for live transcription display only. This transcription is shown to you in real time and not stored.
Usage and analysis data
- Scan results— face scores (overall and per-dimension with the AI's explanation), voice metrics, and timestamps, stored in your profile to power progress tracking and the AI coach's shared memory.
- AI coach chat history— your messages and the coach's responses, stored so the coach can refer to earlier conversations. A rolling summary of important long-term context is also stored separately.
- Zylo Reports — generated weekly and monthly reports summarising your score trends, stored in your profile.
- Product tracking — products the AI coach has suggested, and whether you indicated you purchased or declined them, stored so the coach can follow up and attribute score changes.
- Quota counters— scan counts, chat message counts, and other usage metrics used to enforce your plan's limits.
Billing data
- Payment processing is handled entirely by Paddle.com Market Ltd. We never see or store your card details. We store only your Paddle customer ID, subscription ID, subscription status, and plan tier — the minimum needed to grant or revoke paid features.
- Purchased Zylo Credit balances are stored in your account.
Technical data
- Standard web server logs (IP address, browser type, pages visited) for security monitoring. These are not linked to your profile for analytics purposes.
- A regional preference stored in your browser's local storage to display the correct currency on pricing pages before Paddle loads.
2. How we use your data
- To run AI face and voice analysis on photos and recordings you submit.
- To power your AI coach, including giving it full context of your scan history, voice results, goals, and prior conversations before you type a word.
- To generate weekly and monthly Zylo Reports and progress comparisons.
- To recommend relevant grooming and skincare products via the coach, based on your results and regional catalog.
- To enforce your plan's quotas (scans, chat messages, premium features) and prevent abuse.
- To process payments and manage your subscription via Paddle.
- To operate, secure, and improve the Service. We do not use your photos, voice recordings, or scan results to train AI models.
3. Who we share data with
We use a small number of trusted service providers ("subprocessors") to run ZyloScore. We share only the data each provider needs to perform their function:
- Google Firebase — authentication (email/password and Google OAuth) and Cloud Firestore database storage for all user and profile data.
- Google Gemini API — processes your submitted photos and chat messages to generate AI face analysis, coaching responses, compatibility results, and report content. Audio is not sent to Gemini.
- Self-hosted voice analysis service — runs on our own infrastructure using the open-source Librosa library. Audio recordings are processed there and not forwarded to any third party.
- Deepgram — receives live audio during the onboarding voice recording step for real-time transcription display only. Audio is not retained by Deepgram beyond the live session.Deepgram's privacy policy applies to data they process.
- Cloudinary — stores Pro-plan comparison photos, only when you have explicitly granted consent. Your photos are stored under your account and accessible only to you.
- Paddle— processes subscription and credit payments as our merchant of record, and manages billing, invoices, and tax compliance. Paddle's privacy policy applies to data they collect.
- Vercel— hosts the web application. Standard request logs may be retained per Vercel's data practices.
We do not sell your personal data to advertisers, data brokers, or any other third party. We do not use your data for targeted advertising.
4. Biometric and sensitive data
Face photos and voice recordings may be considered biometric or sensitive personal data under certain laws. We minimise retention of this data by design: photos on Free and Lite plans are never stored; audio is never stored; Pro photo storage requires explicit opt-in. Photos are sent to Google Gemini API for analysis — please review Google's data processing terms if this is a concern for you. During onboarding, voice audio is also streamed to Deepgram for live transcription. This is limited to onboarding only; voice analysis for scoring uses our self-hosted service exclusively.
5. Your choices and rights
- Revoke image storage consent — go to Settings to revoke Pro photo storage consent and delete all stored comparison images immediately.
- Delete profiles — deleting a profile removes its scan history, chat history, reports, and all associated data.
- Delete your account — available in Settings. Deletes your account, all profiles, all scan and chat data, and all stored images. Your Paddle subscription will not be cancelled automatically — cancel it separately before deleting your account.
- Data access requests — contact us at the email below to request a copy of the data we hold about you.
- Correction or erasure — if you believe data we hold is incorrect or you have a right to erasure under applicable law (e.g. GDPR), contact us and we will respond within 30 days.
6. Children's privacy
ZyloScore accounts require the account holder to be 18 or older. We do not knowingly collect personal data from children under 18 directly. Additional profiles for minors may only be added by an adult account holder who accepts responsibility for that use of the Service. If you believe a child has provided data to us without appropriate consent, contact us and we will delete it.
7. Data retention
- Photos — Free/Lite: discarded immediately after analysis. Pro comparison photos: retained until you revoke consent or delete your account.
- Voice recordings — discarded immediately after analysis. Voice metrics are retained until you delete the profile.
- Face Scan results — stored for 3 days, then automatically deleted.
- Account and profile data — retained until you delete your account.
- Chat history — retained until you delete the profile or account.
8. Security
We use encrypted connections (HTTPS) for all data in transit, access-controlled databases with owner-only Firestore security rules, Firebase ID-token authentication on every protected API route, server-side quota enforcement, and restricted admin access. Sensitive credentials (API keys, service-account tokens, webhook secrets) are never exposed to the browser. No system is perfectly secure, but we take reasonable and industry-standard steps to safeguard your data.
9. Changes to this policy
We may update this Privacy Policy from time to time. We'll update the "Last updated" date above and, for material changes, notify you by email or in-app notice.