5. How your skin photos are processed
Skin analysis never runs without your permission. Before the first analysis, the app shows a consent screen naming what data is sent, who receives it and in which country, and what it is used for. You are free to decline, and the rest of the app keeps working — only skin analysis is unavailable.
You can withdraw that consent at any time from Profile inside the app. Once withdrawn, the next analysis request is refused outright and no data is sent until you grant consent again. Analyses already produced remain stored; to remove those, use account deletion under section 10. If we change the consent text materially, we ask for consent again before the next analysis runs.
The analysis is performed by Anthropic (the Claude model) in the United States as our service provider. Anthropic does not use API inputs to train its models.
The result is skincare guidance, not a medical diagnosis, and it produces no automated decision with legal effects for you. You are free to disregard it.
Each analysis you consent to sends the following data, and only the following:
- Your skin or face photo — before it is sent, the photo is resized and all of its metadata, including EXIF and any camera location data, is stripped.
- The skin concern you wrote yourself.
- Your Skin Loop check-in context, when you fill it in — the reason for scanning early, severity, symptoms, how long you have had them, and any recent treatment.
- The My Shelf products you flagged as suspects — the name, category, and ingredients you entered yourself. Other My Shelf products are not sent.
For anything serious, persistent, or worsening, see a doctor or dermatologist.
6. How your appearance attributes are processed
Alongside skin analysis, Levora can read the same face photo a second time for a different purpose: working out the attributes behind everyday appearance suggestions, such as which shade or style suits you. This is a separate purpose with its own consent screen and its own consent record — it is not an extension of skin analysis, and agreeing to one never agrees to the other.
Deriving these attributes takes no new photo, no new sensor, and no new access to your photo library. It reads the photo you already submitted for skin analysis, in the same request that analyses your skin.
From that photo we derive three attributes, and nothing else: skin tone depth, undertone, and face shape. Each one is a single label chosen from a fixed list — for example, face shape is one of seven possible values. We keep one such profile per account, updated by your most recent scan. We also store an internal measure of how certain the analysis was about each attribute; it is never shown to you as a score. When a photo is too dark or too obscured for an attribute to be read, that attribute is left out rather than guessed, and whatever value we already held for it stays as it was.
Anthropic (the Claude model) in the United States performs this analysis as our service provider, in the same request that carries out the skin analysis. Anthropic does not use API inputs to train its models. These attributes are specific personal data under UU PDP and a special category under Article 9 of the GDPR, and consent is our legal basis for processing them.
It matters just as much what this analysis does not do:
- It does not rate or score your appearance and does not judge attractiveness. There is no beauty score anywhere in Levora.
- It does not infer your age, weight, ethnicity, or race, and it makes no health or medical claim from these attributes.
- It is not facial recognition. The attributes cannot pick you out, are never used to identify or authenticate you, and are never matched against another person.
You can refuse appearance analysis and keep using skin analysis exactly as before, and you can withdraw appearance consent at any time from Profile inside the app. From the next scan on, these attributes are no longer derived; deleting the attributes already stored is account deletion, under section 10.