Privacy Policy
Effective date: August 20, 2026
Works On Me provides cosmetic skin analysis from quiz answers and a selfie. Nothing is sent to OpenAI until you explicitly allow analysis. Permission applies only to that scan by default, with an optional device-only setting to remember your choice. We do not sell your personal data. Scan photos are used to generate your analysis and protect service integrity and are not stored on Works On Me servers. A separate optional choice can share a first-result usefulness answer to improve the Works On Me experience; the feedback never includes a scan photo or skin data.
Information We Collect
The app stores your name, quiz answers, scan records, product shelf items, daily logs, product tests, verdicts, saved scan photos, and saved product photos locally on your device. Optional product-label text and barcodes are read on-device with Apple Vision and are not sent to Works On Me, Vercel, or OpenAI. If you subscribe, scan history remains on your device so you can compare progress over time.
For an OpenAI analysis, the app sends a compressed selfie and quiz answers. Version 1.0.2 and later send skin type, selected skin concerns, sensitivity, and fragrance preference. Version 1.0.1 and earlier also send age, skincare spending range, sleep range, routine-safety preference, and shopping preference. Your name, location, random app-install identifier, scan operation identifier, RevenueCat anonymous app-user identifier, analytics cohort identifier, and the Apple Vision face rectangle are not sent to OpenAI.
The app sends a random app-install identifier, per-capture scan operation identifier, and RevenueCat anonymous app-user identifier only to the Works On Me analysis endpoint, hosted by Vercel, for server-side access checks, bounded lost-response recovery, and abuse limits. The endpoint uses the RevenueCat identifier to verify membership with RevenueCat or authorize one teaser analysis. For an active membership, it uses RevenueCat's canonical original app-user identifier so restored aliases for the same subscriber share one membership-week limit. It immediately converts access, operation, and ordinary network identifiers into one-way HMAC-derived keys. Upstash receives those keys, counters, and opaque retry state. It does not receive the raw identifiers or network address. The analysis endpoint does not send these values to OpenAI or Meta.
Vercel hosts the Works On Me website and API endpoints. It processes request contents and ordinary network metadata, such as IP address, device or browser information, and request timestamps, to operate and secure those endpoints.
If you allow location access, the app uses your approximate location at scan time to request local humidity, UV index, and weather context. Coordinates are used for that weather request and are not saved in your scan history.
Apple and RevenueCat process an anonymous app-user identifier, subscription product, purchase history, and entitlement status to complete purchases, unlock membership, restore access, and provide subscription-performance analytics. The Works On Me endpoint also sends that anonymous identifier to RevenueCat to verify the active membership before analysis.
The app automatically sends privacy-filtered product-interaction events, such as scan completion, report views, routine actions, paywall actions, and purchase conversion, to the Works On Me analytics endpoint. These events may include a separate random first-party analytics cohort identifier so Works On Me can understand whether a purchase cohort later reaches product value. They exclude names, contact information, the RevenueCat identifier, photos, location, quiz answers, advertising identifiers, and cross-app tracking data. These first-party product events are not sent to Meta.
On the first limited reveal, the app may ask whether the first result is useful. You can select Yes, Somewhat, or No without sending anything. If you then choose Share feedback, the app sends only that answer with the iOS source, app version and build, runtime environment, event time, and a random one-time delivery ID. It sends no analytics cohort identifier, photo, quiz answer, skin measurement, marker, product, routine, subscription data, RevenueCat identifier, install identifier, Meta identifier, advertising identifier, or location. The answer is used to evaluate whether the first result feels useful and improve the first-reveal and report experience. Don’t share and leaving the screen send no feedback, and your choice does not affect your report, trial, price, or membership features.
Supabase stores shared first-reveal feedback with Works On Me's first-party analytics. Although the feedback has no analytics cohort or persistent user or install identifier, its event time may permit correlation with nearby product activity. Works On Me therefore classifies it conservatively as linked Product Interaction in its App Store privacy answers and does not intentionally join it to a scan result, product, subscription, advertising identity, or real-world identity.
On a production first launch, the app may request an Apple AdServices attribution token and send it to a Works On Me proxy that forwards it only to Apple. The proxy does not log, store, echo, or place the raw token in analytics. Apple may return an attributed flag and campaign, ad group, keyword, ad, conversion, claim, placement, and country or region fields. Works On Me records only those fields with its random first-party analytics cohort identifier. Apple AdServices does not provide Works On Me with IDFA and is not used to track you across other companies' apps or websites.
The app includes the Meta SDK for install and subscription attribution. The Meta SDK is not initialized and does not send an app-activation event or identifier before permission. If you authorize tracking through Apple's App Tracking Transparency prompt, the app may send Meta its standard app-activation event and give RevenueCat the Meta anonymous identifier and permitted device identifiers needed for attribution. RevenueCat, not the app client, sends subscription trial, initial purchase, trial conversion, and renewal events to Meta so those events are not duplicated. If you deny or restrict tracking, the app sends no Meta identifier or app-activation event and does not enable RevenueCat-to-Meta attribution syncing. Works On Me never sends Meta scan photos, quiz answers, skin data, cosmetic marker results, product names, routine activity, custom product events, or first-party analytics events. Works On Me's constant-value Apple SKAdNetwork registration may still provide aggregate attribution without tracking permission; Meta's own SKAdNetwork reporting is off.
The website stores one first-party A/B variant cookie, containing only “a” or “b” for up to one year, so repeat visits receive the same landing-page treatment. The website also sends privacy-filtered first-party interaction events with the page path, assigned variant, and bounded campaign tags supplied in the URL. The cookie and website events exclude names, contact information, account or device identifiers, photos, location, and advertising identifiers, and are not used for cross-site tracking.
Before launch, the website email form collected email addresses only for waitlist and launch updates. That form is no longer active.
Works On Me is for adults 18 and older at launch.
How We Use Information
- To send a scan to OpenAI only after you grant analysis permission, then generate cosmetic estimates of visible skin marker bands and personalized routine guidance.
- To show your report, timeline, and scan comparisons inside the app.
- To verify membership server-side, authorize one teaser analysis, enforce access limits, and protect the Works On Me analysis endpoint from abuse.
- To provide optional scan-time weather context.
- To understand product performance using privacy-filtered interaction events.
- To evaluate whether the first result feels useful and improve the first-reveal and report experience using only an answer a user affirmatively chooses to share.
- To send launch updates to people who joined the prelaunch website email list.
- To process subscriptions, restore purchases, and understand subscription performance through RevenueCat and Apple.
- To measure which Apple Ads and Meta campaigns lead to app installs and subscriptions under the permission boundaries described in this policy.
Data Monetization
We may use aggregate, anonymized insights to understand product performance. We never sell individual user data. The only advertising-related sharing is the limited Apple attribution data and the permission-gated Meta attribution data described in this policy. Brand payments never influence Works On Me recommendations.
Face and Scan Data
Face data means the selfie you choose to submit for cosmetic analysis and the temporary face rectangle used to guide capture. Apple Vision calculates the face rectangle on your device only. The rectangle is not transmitted or stored, and Works On Me does not perform face recognition, identify people, or create faceprints or biometric identity templates.
After you take a selfie and answer the quiz, the app shows an Allow OpenAI analysis? screen before the selfie and quiz answers are first sent for analysis. Those items are not sent until you tap Allow & analyze. If you tap Not now, the app sends no selfie or quiz answers for that scan. A Don’t ask me again option is off by default; if you select it before allowing analysis, the app remembers that permission on this device for later scans under the same disclosure. A camera acknowledgement is not permission to transfer data to OpenAI.
After you grant analysis permission, the compressed selfie and the quiz fields listed above pass through the Works On Me analysis endpoint, hosted by Vercel, to OpenAI only to generate the requested cosmetic report and protect service integrity. The same occurs on a later scan while your optional remembered permission remains active. Works On Me does not persist the selfie or quiz answers on its servers after completing the request. OpenAI may keep API inputs and outputs, including the submitted selfie, quiz answers, and report, in abuse-monitoring logs for up to 30 days, unless longer retention is required by law or reasonably necessary to protect its services or third parties from harm. OpenAI does not use API data to train its models by default.
Paying users can save scan photos locally on their device for timeline and comparison features. Local photos remain until you use Delete all data in the app, delete them through an available app control, or remove the app. Scan photos are not sold, used for advertising, or used to train Works On Me models. First-reveal feedback never includes a scan photo or skin data.
Third-Party Services
Works On Me uses Vercel to host its website and API endpoints, Supabase to store privacy-filtered first-party analytics and shared first-reveal feedback, OpenAI as its third-party AI provider for report generation, Open-Meteo for optional weather context, RevenueCat for subscription entitlement management and permission-gated subscription attribution, Meta for permission-gated install and subscription attribution, Upstash Redis for access and abuse-limit state, and Apple for App Store purchases and Apple Ads attribution. Vercel processes analysis requests, access identifiers, privacy-filtered product-interaction events, shared first-reveal feedback, the transient Apple attribution token, and ordinary network metadata only to operate and secure the Works On Me endpoints. RevenueCat receives its own anonymous app-user identifier for entitlement verification. Upstash receives only one-way HMAC-derived access and network keys, reservations, and counters, not the raw identifier, raw network address, selfie, or quiz answers. Access and analytics identifiers are not forwarded to OpenAI.
Works On Me requires every service provider that receives personal data from the app to use it only for the purposes described in this policy and to provide the same or equal protection of user data as this policy and Apple's App Review Guidelines require.
Consent and Your Choices
OpenAI analysis is opt-in. By default, Allow & analyze authorizes only that scan and future scans require a new choice. If you select Don’t ask me again, the app stores a versioned permission only on this device so later scans can begin analysis without showing the permission screen again. You can revoke that choice from the next scan’s preflight or Profile by selecting Ask me before every scan, and Delete All Data also clears it. A changed disclosure requires permission again. A transfer that has already completed cannot be reversed; the retention terms below still apply to data already processed.
First-reveal feedback is a separate, one-time local choice shown on the first limited reveal. Selecting Yes, Somewhat, or No sends nothing. Only Share feedback sends the selected answer and limited delivery details listed above. Don’t share and leaving the screen send nothing. Delete All Data clears the local disposition so a later first-use flow may ask again, but it cannot retract feedback already delivered because the event has no persistent account, device, install, or cohort identifier.
You can turn off location access in iOS Settings. You can allow or deny Meta tracking in iOS Settings under Privacy & Security, then Tracking. Denying or restricting tracking prevents new Meta identifier sharing, Meta app-activation events, and RevenueCat-to-Meta attribution syncing.
You can use Delete All Data in the app to remove locally stored quiz answers, including their device-local Keychain copy, scan records and photos, shelf items and photos, daily logs, product tests, verdicts, the random app-install identifier, and analytics cohort identifier. The next first-party analytics event uses a new cohort identifier. Delete All Data turns off current Meta advertiser-identifier collection and clears Meta and RevenueCat attribution state that the app controls. It does not change Apple's system-level tracking permission, reset server-side anti-abuse records, or erase attribution and subscription records already received by Meta, RevenueCat, or Apple. If tracking remains authorized and you continue using the app, future use may create and share new attribution data. Turn off Works On Me under iOS Tracking settings to prevent future Meta sharing. Use Delete All Data before removing the app if you want to ensure the Keychain copy is deleted.
To request deletion of a prelaunch website email address or ask about data already processed by a service provider, email help@worksonme.com.
Retention and Deletion
- Works On Me does not retain submitted selfies or quiz answers on its servers after completing an analysis request.
- OpenAI may keep the submitted selfie, quiz answers, and generated report in abuse-monitoring logs for up to 30 days, unless longer retention is required by law or reasonably necessary to protect its services or third parties from harm.
- Vercel retains service-generated network and security data only as described in its service terms and privacy notice. Works On Me does not intentionally log submitted selfies or quiz answers.
- Local app data, the random app-install identifier, and analytics cohort identifier remain on your device until you delete them with an available app control or use Delete all data. The device-local Keychain copy of quiz answers may persist after the app is removed unless Delete all data is used first.
- Privacy-filtered product-interaction events and their random analytics cohort identifier are retained only as long as needed to understand product performance, then deleted or kept only in aggregate form.
- Shared first-reveal feedback contains no analytics cohort or persistent user or install identifier. Supabase retains each raw feedback event for no more than 90 days to evaluate the first-result experience, then a daily retention job deletes it. Aggregate response counts may be kept after the raw event is deleted. Delete All Data clears only the local prompt disposition and cannot retract a previously delivered event.
- The first-party website A/B variant cookie expires after one year unless you clear it sooner. Website interaction events are retained only as long as needed to measure product and campaign performance, then deleted or kept only in aggregate form.
- Upstash retains one-way HMAC-derived keys needed to remember teaser, membership-week, included quality-retake, and bounded same-operation recovery state. Membership and operation keys expire no later than seven days after the official scan; HMAC-derived network and global daily counter keys expire within 48 hours. Upstash does not receive the selfie, quiz answers, report, raw RevenueCat identifier, raw operation UUID, or raw network address. Delete all data removes local identifiers and product data but does not reset these server-side anti-abuse records.
- Apple and RevenueCat retain purchase and entitlement records as needed to provide subscriptions, restore purchases, measure subscription performance, meet legal obligations, and resolve transactions.
- Meta and RevenueCat may retain permission-gated attribution and subscription lifecycle records under their privacy policies. Delete All Data clears the locally controlled attribution state but cannot erase records already received by those services. Future use may create new attribution data while tracking remains authorized.
- Works On Me does not retain the raw Apple attribution token. Allowlisted Apple Ads attribution fields are retained with first-party analytics only as long as needed to measure campaign performance, then deleted or kept only in aggregate form.
- A prelaunch website email address remains on the launch list until you unsubscribe or request deletion.
Medical Disclaimer
Works On Me results are cosmetic estimates, not medical diagnoses. Consult a dermatologist for medical skin concerns.
Contact
Questions? Email help@worksonme.com.