← Home

Privacy Policy

Last updated: July 2026

This policy explains what personal data BeforeAndAfter.io ("we", "us") collects when you use our AI cosmetic preview service, why we collect it, who processes it on our behalf, and the rights you have over it. We are the data controller for the processing described here. Questions or requests: info_beforeandafter.io.

1. Data we collect

  • Account data. Your email address and authentication identifiers. If you sign in with Google, we receive your email address and basic profile information from Google — never your Google password.
  • Photos you upload. The facial photographs you submit for transformation. These are images of a person's face and are treated as sensitive by us regardless of legal classification.
  • Generated images. The AI previews produced from your uploads, including any refinement versions you create.
  • Generation metadata. The procedure and options you selected, intensity settings, adjustment parameters, timestamps, and success or failure status.
  • Payment data. Credit purchases, amounts, currency, and a payment processor customer identifier. We never receive or store your card number — card details are entered directly with Stripe.
  • Usage analytics. Pages viewed, features used, approximate location derived from IP, device and browser type.
  • Technical logs. IP address, request timestamps and error diagnostics generated automatically when you use the service.

2. Why we process it, and our legal basis

  • To deliver the service (contract, GDPR Art. 6(1)(b)). Creating your account, processing uploads, generating previews, storing your gallery, tracking your credit balance and handling purchases.
  • To process facial images (consent, GDPR Art. 6(1)(a) and, where applicable, Art. 9(2)(a)). Facial photographs are only processed because you actively upload them and ask us to generate a preview. You may withdraw consent at any time by deleting the images and your account.
  • To improve and secure the service (legitimate interests, GDPR Art. 6(1)(f)). Aggregate usage analytics, abuse prevention, debugging and fraud detection.
  • To meet legal obligations (GDPR Art. 6(1)(c)). Retaining transaction records for accounting and tax purposes.

We do not use your photographs or generated images to train AI models, and we do not sell or rent your personal data to anyone.

3. How your photos are handled

  • Uploads are transmitted over encrypted connections (HTTPS/TLS) and stored in access-controlled storage tied to your account.
  • Your photo is sent to our AI image provider solely to generate the preview you requested, and only for the duration of that request.
  • Only you can view your uploads and generated results while signed in to your account. Our staff do not routinely access them, and access is limited to what is necessary to investigate an abuse report, a support request or a technical fault.
  • You can delete any generated image from your Gallery at any time. Deleting your account removes your uploads and generated images.
  • Previews are illustrative AI simulations and are not medical records. See our Terms of Service for the full medical disclaimer.

4. Service providers (processors)

We rely on a small number of vendors who process data on our instructions:

  • Lovable Cloud — application hosting, database, authentication and file storage.
  • Google (Gemini image models, accessed through the Lovable AI Gateway) — generates the transformation previews from the photo you submit.
  • Stripe — payment processing for credit purchases. Stripe is an independent controller for card data and holds it under its own privacy policy.
  • PostHog — product analytics on how the site is used.

Each provider is bound by a data processing agreement and may only use the data to deliver its service to us.

5. International transfers

Some providers process data outside the European Economic Area, including in the United States. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent approved safeguard.

6. Retention

  • Uploads and generated images — retained while your account is active, or until you delete them.
  • Account and credit balance — retained while your account is active.
  • Purchase and invoice records — retained for the period required by applicable accounting and tax law, typically five years, even after account deletion.
  • Technical logs — typically retained for up to 90 days.

7. Your rights

If you are in the EEA or UK, you have the right to access your data, correct it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time. Withdrawing consent does not affect processing already carried out.

Exercise any of these by emailing info_beforeandafter.io. We respond within 30 days. You also have the right to lodge a complaint with your national data protection authority — in Norway, Datatilsynet.

8. Cookies and similar technologies

We use cookies and browser storage that are strictly necessary to keep you signed in and to remember that you have acknowledged our disclaimer. We also use analytics storage to understand aggregate product usage. We do not run advertising or cross-site tracking cookies.

9. Security

Data is encrypted in transit, access to stored images is scoped to the owning account through row-level access rules, and payment credentials never touch our servers. No online service can guarantee absolute security, so please use a strong, unique password and notify us immediately of any suspected unauthorised access.

10. Children

The service is intended for adults. You must be at least 18 years old to create an account, and you must not upload photographs of minors. If we learn that we hold data about a child, we will delete it.

11. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced in the app or by email, and the "last updated" date above will change.

12. Contact

BeforeAndAfter.io — info_beforeandafter.io

HomePrivacy PolicyTerms of ServiceRefund Policy