This Privacy Policy explains how Aperia ("Aperia", "we", "us") collects, uses, and protects your information when you use the Aperia mobile application (the "App"). Aperia is a personal skin-and-cycle wellness tool. We take your privacy seriously, especially because some of the data you choose to share with us is sensitive.
Some information you can log in Aperia — such as photos of your skin, menstrual-cycle dates, symptoms, mood, and energy — is considered special-category (health) data under the EU General Data Protection Regulation (GDPR), Article 9. We only process this data with your explicit consent, which you give when you choose to use those features, and you can withdraw it at any time by deleting the data or your account.
| Category | Examples | Why |
|---|---|---|
| Account | Email address, birth year, biological sex, preferred language | Create and secure your account; tailor the experience |
| Skin photos & scan results | Selfies you capture for a skin scan, and the derived skin metrics | Provide the skin-analysis feature and track changes over time |
| Cycle & health logs | Period dates, symptoms, mood, energy, sleep, daily notes, products used, improvement goals | Show cycle-aware trends and pattern insights |
| Approximate location | A coarse, rounded location label (we do not store precise GPS) | Optional context for environmental factors |
| Device & notifications | Push notification token, device/OS info | Deliver reminders and notifications you opt into |
| Subscription | Subscription status and plan (via our payments provider) | Manage Aperia Plus access |
| Diagnostics | Crash reports and error logs (no health data, no raw photos) | Keep the App stable and fix bugs |
You are never required to log health data to use the App — those features are entirely opt-in.
To analyze your skin and produce insights, your skin photos and certain logged data are processed by our AI provider, Anthropic (the Claude API). Under our agreement with Anthropic:
We do not use your private personal data to train any public AI model. Separately, you may optionally consent to let fully anonymized data contribute to product research; this is off by default, and you can withdraw it anytime.
The selfies you capture for a skin scan are images of your face ("face data"). We use them for one purpose only: to analyze the visible condition of your skin (such as redness, texture, and clarity) and to let you track changes over time. We use AI-based face detection solely to confirm that a face is present in the frame so the scan is usable. We do not use face data for facial recognition or identity verification, we do not create or store a faceprint or any biometric identification template, and we do not attempt to identify who you are from your photos.
Sharing. Your face photos are shared only with our AI processor, Anthropic (the Claude API), strictly to return your skin-analysis result to you. Under our agreement they are not used to train public models and are deleted in accordance with the provider's data-handling commitments. We never sell face data or share it for advertising.
Storage and retention. Your face photos are stored encrypted (AES-GCM) by our storage provider, Cloudflare (R2). They are retained only while your account is active. You can delete individual scans at any time in the App, and when you request account deletion your face data is permanently erased after a 30-day grace period (GDPR Article 17).
We do not sell your data, and we do not share it for advertising. We use a small number of trusted service providers ("processors") strictly to run the App:
| Provider | Purpose |
|---|---|
| Anthropic | AI skin analysis and insight/chat generation |
| Cloudflare (R2) | Encrypted storage of your photos |
| RevenueCat | Subscription management |
| Apple | App distribution and in-app purchases |
| Sentry | Crash and error diagnostics (no health data, no photos) |
| OpenStreetMap (Nominatim) | Turning a coarse location into a place label |
| Hosting provider (Railway) | Running our backend servers and database |
Some providers are located outside the European Economic Area (for example, in the United States). Where data is transferred internationally, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an equivalent mechanism.
We keep your data for as long as your account is active. When you request deletion, your account enters a 30-day grace period (so you can change your mind), after which your personal data is permanently deleted, except where we must retain limited records to meet legal obligations.
Under the GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; receive a portable copy; and withdraw consent at any time. Many of these you can exercise directly in the App (export and delete are built in). For anything else, contact us at hello@aperiaskin.com.
You also have the right to lodge a complaint with your supervisory authority. In Slovakia this is the Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky).
We protect your data with measures including encryption of stored photos, encrypted connections, hashing of identifiers in logs, and access controls. No method of transmission or storage is 100% secure, but we work hard to safeguard your information.
Aperia is not intended for children. You must be at least 16 years old (or the age of digital consent in your country) to use the App. We do not knowingly collect data from children under this age; if you believe a child has provided us data, contact us and we will delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the App.
Questions or requests about your privacy? Email hello@aperiaskin.com.
Important: Aperia is a wellness and self-knowledge tool. It does not diagnose, treat, or prevent any medical condition and is not a substitute for professional medical advice. See our Terms of Use.