M
MAXAURA AI
Legal

Privacy Policy

Last Updated: August 16, 2026

Data Controller: MaxAura AI, operated by Shirish Kadam  · [email protected]
Scope: this policy covers both the MaxAura website (maxauralab.com) and the MaxAura iOS app. The analysis itself works identically on both; where the app differs — how you sign in, how photos are chosen, and who processes payment — it is called out below.

1. Information We Collect

When you sign in with Google, we receive your:

  • Name and email address
  • Google profile photo URL
  • Google account ID (used as your unique identifier)

In the iOS app you may instead Sign in with Apple, in which case we receive:

  • Your name, only if you choose to share it
  • Your email address — or, if you select Hide My Email, an anonymous Apple relay address instead. We never see your real address in that case
  • An Apple user identifier (used as your unique identifier)

This information is used only to create and maintain your account and saved reports.

What you tell us. When the app first sets up, it asks a short set of questions: a first name to address you by, what you would like help with, how you heard about us, what has frustrated you about style before, and whether you have an occasion coming up. Your answers are saved to your account and used to make the reading feel written for you. In Account you can also add your gender and age range. All of this is optional — you can skip any question, and you can change or clear these answers at any time.

If you provide a gender or age range, it is included with the hairstyle and eyewear requests sent to Google for analysis, so the suggestions suit you. It is deliberately never sent with the colour analysis, which is read from your photo alone.

Notifications (iOS only). If you allow notifications, reminders such as “your try-on is ready” are scheduled locally on your device. We do not collect a push token, we cannot send you anything from our servers, and you can turn notifications off at any time in Settings › MaxAura.

Device integrity (iOS only). The app asks Apple to confirm the request came from a genuine, unmodified copy of MaxAura, using Apple's DeviceCheck service via Firebase App Check. This returns a token that proves the device is legitimate. It does not identify you, is not linked to your account, and we cannot use it to track you across apps.

We do not track you across other companies' apps or websites. MaxAura does not use the iOS advertising identifier (IDFA), does not ask for App Tracking Transparency permission, and does not sell or share your personal data with data brokers or advertisers.

2. How We Handle Your Photos

When you upload or capture a photo for analysis, it is processed as follows:

  • The image is transmitted securely to Google LLC for real-time AI styling analysis. Google LLC is based in the United States. This transfer is covered by Google's Standard Contractual Clauses (SCCs)
  • Your input photos and AI-generated output images are stored in Firebase Cloud Storage (Google LLC, United States infrastructure governed by Google's SCCs). Storage is linked to your account, and is what your photo vault and your saved looks are made of
  • Stored images are never shared with third parties and never used for AI model training
  • You can stop this at any time. In the app, Account › Your photos has a switch that stops new photos being saved, and a button that deletes every photo already there. Saved looks can be removed one by one, and deleting your account removes everything. These happen immediately, not on a request queue
  • You can also email us to have anything deleted — we action it within 30 days
  • Please upload only photos needed for styling analysis and avoid sensitive personal content

On iOS. The app asks your permission before using the camera or your photo library, and iOS will not grant access unless you allow it. You can withdraw either permission at any time in Settings › MaxAura. We only receive the specific photo you choose or capture — never your wider photo library — and it is then handled exactly as described above.

Legal basis (GDPR Art. 6(1)(b)): We store your photos solely to deliver the analysis service you requested. The photos are not used for identification or profiling beyond the styling recommendations you asked for.

Google LLC may temporarily log inputs and outputs for safety, abuse prevention, and legal compliance under their own policies.

3. How We Use Your Information

  • To authenticate you and maintain your account
  • To perform AI styling analysis on your uploaded photos
  • To store your analysis history, photo vault and saved looks
  • To personalise your reading using the answers and profile details you give us
  • To track usage for free tier limits and Pro subscription management
  • To improve the service via usage analytics and crash reporting — on the website these run only with your consent; in the iOS app see Section 5

4. Third-Party Services

MaxAura AI uses the following third-party services:

  • Firebase (Google LLC) — authentication, account data storage, analysis history, and photo storage (Firebase Cloud Storage). Google LLC, United States. Covered by Google's Standard Contractual Clauses.
  • Google LLC — AI-powered styling analysis. Limited request/response data may be retained temporarily for trust and safety enforcement under Google's AI usage policies.
  • Google Tag Manager (Google LLC) — anonymized usage analytics to improve the service. Loaded only after you give explicit consent.
  • PostHog, Inc. — product analytics: which screens are opened and which features are used, linked to your account identifier. On the website it loads only after you consent; in the iOS app it runs from app launch (see Section 5). No advertising identifier is involved and your photos are never sent to it. PostHog, Inc. is based in the United States and transfers are covered by its Standard Contractual Clauses. Privacy policy
  • Sentry (Functional Software, Inc.) — crash and error reporting, so we can find and fix what breaks. It receives technical diagnostics such as the error, your device model and OS version, plus your account identifier — not your photos. Based in the United States, with transfers covered by its Standard Contractual Clauses. Privacy policy
  • Stripe, Inc. / Link (Merchant of Record) website purchases only. Checkout, payment processing, billing, tax calculation and remittance, fraud prevention, and dispute management for Pro subscriptions. Stripe, Inc. is based in the United States. Data transfers are safeguarded by Stripe's Standard Contractual Clauses. Privacy policy
  • Apple Inc.iOS app only. Apple processes all in-app purchases as merchant of record, provides Sign in with Apple, and operates the DeviceCheck service used to verify the app is genuine. We never receive your payment card details. Apple Inc. is based in the United States. Privacy policy
  • RevenueCat, Inc.iOS app only. Validates App Store purchase receipts and tells our servers which subscription you hold, so your Pro access works on the device. It receives your purchase history and your MaxAura account identifier — not your name, email, or photos. RevenueCat, Inc. is based in the United States and transfers are covered by its Standard Contractual Clauses. Privacy policy

Payment processing depends on where you subscribed: subscriptions bought on the website are handled by Stripe, and subscriptions bought in the iOS app are handled by Apple. A single MaxAura account can hold only one active subscription at a time, whichever way you bought it.

5. Lawful Basis for Processing (GDPR Article 6)

We process your personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b)): We process your name, email address, and account data to create and maintain your account and deliver the service you requested.
  • Legitimate interests (Art. 6(1)(f)): We use usage analytics and crash reporting to understand how the service is used, and to find and fix faults. The iOS app has no cookies and no cookie banner, so analytics and crash reporting there start with the app and rest on this basis. You can object at any time by emailing us, and the service remains fully functional either way.
  • Consent (Art. 6(1)(a)): On the website, analytics and Firebase Performance Monitoring are only activated after you give explicit consent via the cookie banner.
  • Contract performance (Art. 6(1)(b)): The onboarding answers and the gender and age range you optionally provide are used to produce the personalised reading you asked us for.

6. Your Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate data.
  • Right to Erasure (Art. 17): Request deletion of your personal data.
  • Right to Data Portability (Art. 20): Request your data in a machine-readable format.
  • Right to Restriction (Art. 18): Request that we limit how we process your data.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

7. International Data Transfers

MaxAura AI uses services operated by Google LLC (United States). These transfers are safeguarded by Google's Standard Contractual Clauses (SCCs) approved by the European Commission:

  • Firebase (Google LLC) — authentication and database
  • Google LLC — AI styling analysis
  • Google Tag Manager (Google LLC) — analytics (website, consent-gated)
  • PostHog, Inc. — product analytics
  • Sentry (Functional Software, Inc.) — crash and error reporting
  • Stripe, Inc. — payment processing and billing for Pro subscriptions bought on the website. Stripe is based in the United States. Transfers are covered by Stripe's Standard Contractual Clauses approved by the European Commission.
  • Apple Inc. — in-app purchases, Sign in with Apple, and DeviceCheck verification for the iOS app. Apple is based in the United States and relies on Standard Contractual Clauses for transfers out of the EEA.
  • RevenueCat, Inc. — App Store receipt validation and subscription status for the iOS app. RevenueCat is based in the United States and transfers are covered by its Standard Contractual Clauses.

8. Data Retention & Deletion

We retain your data for as long as your account is active. The fastest way to delete anything is in the app itself: Account › Your photos deletes your stored photos, saved looks can be removed individually, and Account › Delete account removes your account, your reports, your photos and your answers. Those take effect immediately. You can also email [email protected] and we will delete your account, saved analysis reports, stored photos (input and output images), onboarding answers, profile details and usage data within 30 days.

9. Age Requirement

You must be at least 16 to use MaxAura AI, and the iOS app is rated 16+. We chose 16 because it is the highest age at which the GDPR lets a person agree to a service like this on their own behalf, anywhere in the EU — so we never need a parent's consent to hold your data.

We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has given us their information, contact us and we will delete it.

10. Contact & Supervisory Authority

For privacy questions or data requests, contact us at [email protected].

You also have the right to lodge a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos — AEPD) at www.aepd.es if you believe your personal data is being processed in violation of GDPR.

M
MAXAURA AI
© 2026 MaxAura AI · AI-powered beauty intelligence