Skip to content

Privacy Policy

Your data, and what we do with it.

Effective 6 August 2026

Levora processes data that is genuinely sensitive: photos of your skin. That photo is used for two separate purposes, each with its own consent — analysing your skin, and deriving the appearance attributes behind daily styling suggestions. This page explains exactly what we collect, where it goes, how long we keep it, and what rights you have over it. This policy follows Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP) and the European Union’s General Data Protection Regulation (GDPR).

1. Who controls your data

Levora (“we”) is the personal data controller under UU PDP and the data controller under the GDPR for all data processed through the Levora Skincare iOS app and the levora.id website.

For any question, request, or objection about your personal data, contact admin@levora.id.

2. What we collect

We collect only what the service needs to work.

  • Account data — email, name, phone number, and profile photo. Passwords are stored as Argon2id hashes; we never store and cannot read your password in its original form.
  • Third-party sign-in identity — the unique identifier and email address from Google or Apple when you sign in with either. If you use Apple’s Hide My Email, we only ever receive the relay address, not your real one.
  • Skin data — the skin or face photos you upload, the concerns you write, the conditions the AI detects, the analysis narrative, the recommended routine, your skin score history, daily routine adherence, and the products you save to My Shelf. This is specific personal data under UU PDP and a special category under Article 9 of the GDPR.
  • Appearance attributes — if you consent to appearance analysis separately, three attributes derived from the face photo you have already uploaded: skin tone depth, undertone, and face shape. Each is a single label chosen from a fixed list, kept as one profile per account. Deriving them takes no new photo, no new sensor, and no new access to your photo library — it reads the same photo the skin analysis already uses. These are specific personal data under UU PDP and a special category under Article 9 of the GDPR, exactly like your skin data. Section 6 explains this purpose in full.
  • Transaction data — delivery address (recipient name, phone, street, city, province, postal code), order contents, and payment status. Card numbers and bank details never reach our servers; the payment provider handles them.
  • Device and security data — platform, device name, device identifier, notification token, whether the biometric lock is enabled, plus the IP address and user agent recorded on sign-in attempts and consultation requests. This data is used to prevent account abuse and to rate-limit requests.

3. What we do not collect

Some things look like personal data but never reach us.

  • Biometric identifiers. Face ID and Touch ID are verified entirely by iOS on your device. Levora only receives a success or failure answer — your face map and fingerprints are never sent to our servers and are never stored by us. The face shape attribute in section 6 is a different thing and should not be confused with this: it is one category label out of seven possible values, not a face map or biometric template, and it cannot be used to recognise, identify, or authenticate anyone.
  • Location coordinates. The location permission is used on-device only, to work out your time zone and city name so routine reminders appear at the right time. Coordinates are never sent to our servers and are not stored.
  • Tracking data. The app contains no third-party advertising or analytics SDKs, does not track you across apps or websites, and does not share data for advertising purposes.

4. Legal bases for processing

Every processing activity rests on one of the following.

  • Performance of a contract — creating your account, fulfilling orders, and shipping products.
  • Explicit consent — processing your skin photos and analysis results. Because this is health data, we ask for separate consent and you may withdraw it at any time without affecting processing already carried out.
  • Explicit consent, asked separately again — deriving appearance attributes from that same photo. This is a second processing purpose, not an extension of the first: it has its own consent screen, its own record, and its own withdrawal. Granting one does not grant the other.
  • Legitimate interests — keeping accounts secure, preventing abuse, and rate-limiting requests.
  • Legal obligation — retaining transaction records for as long as tax and bookkeeping rules require.

5. How your skin photos are processed

Skin analysis never runs without your permission. Before the first analysis, the app shows a consent screen naming what data is sent, who receives it and in which country, and what it is used for. You are free to decline, and the rest of the app keeps working — only skin analysis is unavailable.

You can withdraw that consent at any time from Profile inside the app. Once withdrawn, the next analysis request is refused outright and no data is sent until you grant consent again. Analyses already produced remain stored; to remove those, use account deletion under section 10. If we change the consent text materially, we ask for consent again before the next analysis runs.

The analysis is performed by Anthropic (the Claude model) in the United States as our service provider. Anthropic does not use API inputs to train its models.

The result is skincare guidance, not a medical diagnosis, and it produces no automated decision with legal effects for you. You are free to disregard it.

Each analysis you consent to sends the following data, and only the following:

  • Your skin or face photo — before it is sent, the photo is resized and all of its metadata, including EXIF and any camera location data, is stripped.
  • The skin concern you wrote yourself.
  • Your Skin Loop check-in context, when you fill it in — the reason for scanning early, severity, symptoms, how long you have had them, and any recent treatment.
  • The My Shelf products you flagged as suspects — the name, category, and ingredients you entered yourself. Other My Shelf products are not sent.

For anything serious, persistent, or worsening, see a doctor or dermatologist.

6. How your appearance attributes are processed

Alongside skin analysis, Levora can read the same face photo a second time for a different purpose: working out the attributes behind everyday appearance suggestions, such as which shade or style suits you. This is a separate purpose with its own consent screen and its own consent record — it is not an extension of skin analysis, and agreeing to one never agrees to the other.

Deriving these attributes takes no new photo, no new sensor, and no new access to your photo library. It reads the photo you already submitted for skin analysis, in the same request that analyses your skin.

From that photo we derive three attributes, and nothing else: skin tone depth, undertone, and face shape. Each one is a single label chosen from a fixed list — for example, face shape is one of seven possible values. We keep one such profile per account, updated by your most recent scan. We also store an internal measure of how certain the analysis was about each attribute; it is never shown to you as a score. When a photo is too dark or too obscured for an attribute to be read, that attribute is left out rather than guessed, and whatever value we already held for it stays as it was.

Anthropic (the Claude model) in the United States performs this analysis as our service provider, in the same request that carries out the skin analysis. Anthropic does not use API inputs to train its models. These attributes are specific personal data under UU PDP and a special category under Article 9 of the GDPR, and consent is our legal basis for processing them.

It matters just as much what this analysis does not do:

  • It does not rate or score your appearance and does not judge attractiveness. There is no beauty score anywhere in Levora.
  • It does not infer your age, weight, ethnicity, or race, and it makes no health or medical claim from these attributes.
  • It is not facial recognition. The attributes cannot pick you out, are never used to identify or authenticate you, and are never matched against another person.

You can refuse appearance analysis and keep using skin analysis exactly as before, and you can withdraw appearance consent at any time from Profile inside the app. From the next scan on, these attributes are no longer derived; deleting the attributes already stored is account deletion, under section 10.

7. Third parties that receive data

We never sell personal data. We share it only with the service providers we need in order to run Levora, and only as far as necessary.

  • Anthropic (United States) — analyses your skin photo, written concern, and check-in context, only after you have consented. Where you have also consented to appearance analysis, the same request derives your skin tone depth, undertone, and face shape.
  • Supabase (Singapore) — database and file storage.
  • Google Cloud (Singapore) — runs our API servers.
  • Google and Apple — verify your identity when you sign in with their accounts.
  • Xendit (Indonesia) — processes order payments.
  • Logistics partners — deliver orders to your address.
  • Hostinger — delivers transactional email such as account confirmation and password reset.

8. International data transfers

Our servers are in Singapore and the AI analysis runs in the United States. For transfers outside Indonesia and outside the European Economic Area, we ensure the recipient applies an equivalent level of protection through data processing agreements and standard contractual clauses, in line with Article 56 of UU PDP and Chapter V of the GDPR.

9. How long we keep data

We do not keep data longer than necessary.

  • Skin and face photos — we keep only the 10 most recent photos per account. Older photos are deleted from file storage automatically as you run new analyses.
  • Account data and the rest of your skin data (analysis results, routines, skin score history) — for as long as your account is active.
  • Appearance attributes — skin tone depth, undertone, and face shape are kept as one profile per account for as long as your account is active. A new consented scan updates that profile instead of adding another record, so we hold the current values rather than a history of them. Deleting your account removes the profile with everything else.
  • Sign-in sessions — refresh tokens expire 30 days after they are issued.
  • File links — signed URLs for photos are valid for at most 24 hours.
  • Sign-in attempt records — kept only as long as security requires, then deleted.
  • AI analysis consent records — for each purpose you were asked about, the version of the text you accepted, along with when you accepted and withdrew it, is kept for as long as your account is active, as evidence of the legal basis for processing. Withdrawing consent marks that record rather than deleting it.
  • After account deletion — all data belonging to you is permanently removed from the database and file storage. Transaction records we are legally required to retain are kept separately in a limited form.

10. Your rights

UU PDP and the GDPR give you the following rights, and we honour them regardless of where you live.

  • Access your data and obtain a copy of it.
  • Correct data that is wrong or incomplete.
  • Delete your data. You can do this yourself at any time via Profile → Delete Account inside the app, without contacting us first.
  • Restrict or object to particular processing.
  • Receive your data in a machine-readable format and move it to another provider.
  • Withdraw your consent at any time, directly from Profile inside the app. Skin analysis and appearance analysis are consented to separately and withdrawn separately: refusing or withdrawing appearance consent leaves skin analysis working exactly as it did before, and affects nothing else in the app. Withdrawing skin analysis consent stops the scan itself, and the appearance analysis stops with it, because there is no longer a scan to read.
  • Lodge a complaint with the personal data protection authority in Indonesia, or with the supervisory authority in your country if you are in the European Economic Area.

Send requests to admin@levora.id. Requests are free, and we respond within 30 days at the latest — sooner where the applicable law requires it.

11. How we secure data

Passwords are hashed with Argon2id and all traffic runs over HTTPS. Photos live in private storage reachable only through short-lived signed URLs, and the database is protected by row level security so one account cannot read another’s data. Accounts lock temporarily after five failed sign-in attempts, and API requests are rate-limited.

12. If there is a data breach

If personal data protection fails, we notify you and the competent authority within 3×24 hours of becoming aware, as UU PDP requires, and within 72 hours to the supervisory authority for users in the European Economic Area. The notice explains what data was affected and the steps we are taking.

13. Children

Levora is not directed at children under 17. If you are below that age, using this service requires the consent of a parent or guardian. If we learn we have collected a child’s data without valid consent, we delete it.

14. Changes to this policy

If this policy changes materially, we will tell you in the app or by email before the change takes effect. The effective date at the top of this page always reflects the current version.

15. Contact us

Questions, rights requests, or objections about your personal data can be sent to admin@levora.id.