Morphe

Appearance Age, read from a scan.

A guided face scan estimates your Appearance Age and skin metrics, a daily check-in tracks what moves them, and a voice coach turns that into a protocol.

← Back to Morphe

Privacy Policy

Last updated: August 10, 2026  •  Effective: August 10, 2026

This Privacy Policy describes how Soulution Holdings LLC, a Wyoming limited liability company ("Morphe," "we," "us," or "our"), collects, uses, stores, and protects your information when you use the Morphe mobile application and related services (the "App"). Morphe is an appearance and longevity app: it uses a guided face scan to estimate your Appearance Age and skin metrics, pairs those with a short daily check-in, and surfaces personalized insights and a skincare-style protocol. Because the scan involves face images — which are a biometric identifier — and other personal information, we have written this policy to be as clear and transparent as possible. Please read it carefully.

By using the App, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the App.

1. Important Notice

Morphe is a cosmetic, informational, and self-development tool. It is NOT a medical device, and it does not diagnose, treat, cure, or prevent any disease or medical condition — including any skin condition. The Appearance Age estimate, skin metrics, and on-device vitals estimates (such as heart rate) provided by the App are approximations intended for general cosmetic and informational purposes only. They are not a substitute for professional medical, dermatological, or other advice, diagnosis, or treatment. Always consult a qualified professional about any health or skin concern, and never disregard professional advice because of something you saw or measured in the App.

2. Information We Collect

2.1 Face Images (Biometric Data)

The core feature of the App is a guided face scan. With your permission, the App uses your device's front-facing camera to capture still images of your face from up to three angles (front, and where available, left and right). These face images are a biometric identifier, and we treat them as sensitive biometric data. We use them to estimate your Appearance Age and skin metrics as described below. Handling of these images, including transmission to our skin-analysis processor and consent, is described in Sections 4 and 5.

By default we do not keep your scan photos on our servers: each photo is used to produce your reading and is not stored by us afterwards. There is one optional setting, "Keep my scan photos," which changes that — if you switch it on, the front photo from each scan is stored on our servers alongside that scan's results so that we can see what the scanner saw when a reading looks wrong. It is off unless you turn it on. It is currently available only on internal test builds used by our own team and does not appear in the App Store version of the App, so unless you can see that setting in Settings and have switched it on, no scan photo of yours is stored on our servers. Sections 4, 5, 7 and 8 describe what it stores, how long, and how to remove it.

2.2 On-Device Vitals (rPPG)

During the scan, the App also analyzes subtle frame-to-frame color changes on your skin — a technique called remote photoplethysmography (rPPG) — to estimate vitals such as heart rate, heart rate variability, and respiration rate. This computation runs entirely on your device. No video is recorded, stored, or transmitted for this purpose. The resulting numerical estimates are stored on your device, and (only where it improves your scan) we may attach a short numerical heart-rate/variability series to the skin-analysis request described in Section 4. If you turn on contributing results, those numbers are also included in the copy of your results that we keep on our servers — see Section 4.

2.3 Appearance Age and Skin Metrics

From the scan we derive your estimated Appearance Age, skin metrics (for example clarity, redness, smoothness, and evenness), and related insights and "age drivers." These derived results, along with the captured scan images, are stored on your device, which holds the full record of your scans and history. We also keep a copy of the derived results — the numbers, not your images — on our servers. Section 4 sets out exactly what that copy contains, and Sections 7 and 8 cover how long we keep it and how to have it deleted.

2.4 Daily Check-In and Journal

You may voluntarily record self-reported information through the daily check-in and journal — for example sleep, hydration, nutrition, workouts, sun exposure and SPF, skincare products and active ingredients, supplements, alcohol, and similar lifestyle factors. This information is optional, is provided by you, and is stored on your device, and the App computes correlations between these factors and your scan results on your device. If you turn on contributing results, your check-in answers are also stored on our servers alongside your scan results (Section 4).

2.5 Profile and Onboarding Information

During onboarding you may provide optional profile information such as a name, birth year (used to compute your age for the Appearance Age comparison), gender, skin type, skin goals, and preferences. This information is optional and is stored on your device. Your name, birth year and coach-voice preference stay there and are never sent to our servers. The appearance goals and motivations you select are also kept on your device, and are sent to our servers only if you switch on the optional onboarding-answer contribution described in Section 4. The App does not require you to create an account or provide an email address to use its core features.

2.6 AI Coach Conversations

If you use the in-app AI coach (including its voice mode), the questions you ask, relevant conversation history, and a short summary of your recent scan results and goals are sent to our backend and to third-party large language model (LLM) providers to generate a response. In voice mode, your speech is converted to text before it reaches us. Your device does that conversion itself wherever it can; where your device does not support it, the conversion is done by Apple's speech recognition service instead. Either way, what reaches our servers is the text, not audio from your side of the conversation: we do not receive, and do not store, a recording of your voice. We do not send your face images to the coach.

The coach also keeps a memory between sessions, stored on your device: short facts you have told it, the observations it made about your scans, and a summary of each session. It reads that memory from your device every time, and it is yours to read and delete in the App (You → What the coach remembers). Short extracts from it are included in the request described above so the coach can pick up where you left off. There is one optional setting, "Let us see what your coach remembers," which additionally sends a copy of that memory to our servers so our team can look at it when the coach gets something wrong. It is off unless you turn it on, your device remains the source of truth either way, and Sections 4, 7 and 8 describe what the copy contains, how long it is kept, and how to remove it.

A separate setting, "Share coaching sessions," decides whether we keep the conversation itself. As described above, what you say has to reach our servers as text for the coach to answer at all; this setting does not change that, and it is the only setting on this screen that is on unless you turn it off. With it on, we store the turns of each coaching session under your anonymous device identifier: what you said, what the coach said back, when each turn happened, and the result of the automated safety check for that turn. We use it to review and improve the coach, including reviewing sessions where a safety check fired. We do not sell it and we do not give it to advertisers. With it off, your sessions are used to answer you and are then discarded rather than stored, which is the same behavior as before this setting existed. You can change it during onboarding or at any time in Settings → Privacy, turning it off stops anything further being stored immediately, and Sections 4, 7 and 8 describe how long a stored session is kept and how to remove it.

2.7 Subscription and Device Data

Subscriptions are processed by Apple through the App Store; we do not collect or store your payment card details, and we receive only your subscription status and related identifiers from Apple to manage access. The App also uses an anonymous device identifier for backend requests. It registers that identifier with our servers once and receives an access credential specific to your device, which it stores in your device's secure keychain and uses for its own requests; this replaces a single credential shared by every installation, so requests from your device can be told apart from other people's and limited to your own data. The identifier is generated at random on your device, is not derived from any hardware identifier, and is not linked to your name or contact details. The App may also collect limited technical information such as app version and crash or stability diagnostics to keep the App working. We do not use this information to identify you personally.

3. How We Use Your Information

We use the information we collect to provide and improve the App, specifically to do the following:

We do not sell your personal information. We do not sell, rent, or share your biometric data or face images with advertisers or data brokers, and we do not use your biometric data for advertising.

4. What Leaves Your Device

Morphe is local-first: your device holds the full record of your scans, images, vitals, check-ins, and derived results, it remains the source of truth, and the App works offline. That does not mean nothing is stored elsewhere. We also keep a copy of some of your data on our servers, and this section says exactly what. Information leaves your device in these cases:

We instruct our processors to use your data only to provide these features on our behalf and not to sell it or use it to train their own general-purpose models except as needed to provide the service.

5. Biometric Data (BIPA and Similar Laws)

Your face images are biometric identifiers, and certain jurisdictions — including Illinois under the Biometric Information Privacy Act (BIPA), and Texas and Washington under their respective laws — provide specific protections for biometric data. Where these laws apply, the following commitments govern our handling of your face images and any biometric information derived from them:

By enabling and using the face scan, you provide your informed consent to the capture and processing of your face images and derived biometric information as described in this Policy. You may withdraw consent at any time by disabling camera access and deleting your data (see Section 8).

6. How We Share Information

We share information only in the limited circumstances below:

We never share your biometric data or face images for any third party's independent marketing or advertising purposes.

7. Data Storage, Security, and Retention

Your device holds the full record of your data and is the source of truth for it. We also hold the server-side copy described in Section 4. For information that leaves your device, we use industry-standard safeguards including encryption in transit (TLS), access controls, and secure infrastructure. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your on-device data remains until you delete it or uninstall the App. Deleting the App removes the copy on your device, but on its own it does not remove the server-side copy — use "Delete all my data" in the App for that (see Section 8). If you delete the App and install it again, the new installation generates a NEW anonymous device identifier; we do not restore the previous one, and the App cannot afterwards ask us to delete anything stored under it. If you want the server-side copy removed, use "Delete all my data" before you uninstall, or contact us using the details in Section 12. We keep the server-side copy of your derived results, any check-in and habit data you have contributed, any scan photos stored under the optional setting in Section 4, and any copy of your coach's memory stored under the optional setting there, for 24 months after your last interaction with the App, and then destroy them. Coaching sessions stored under the sharing setting in Section 4 are kept for a shorter period: 6 months after your last interaction with the App, and then destroyed. We set that period deliberately, because a stored session is a record of a conversation in your own words and we do not think we should hold one for as long as we hold a set of numbers. It applies to every stored session, including any session where an automated safety check fired. You do not have to wait for any of these periods: Section 8 sets out what the App's delete control removes by itself, what it does not, and how to ask us to remove the rest. Face images are sent to the service provider that performs the skin analysis for us. That provider does not store the image: it holds it in memory only for the length of the analysis, and passes it to the AI provider that produces the reading. Under that AI provider's published policy, material sent through its interface is kept for up to 30 days for abuse monitoring only and is then deleted, except where longer retention is required by law. We have not separately arranged a shorter retention period.

There are things we cannot delete on request, and we would rather say so here than let Section 8 imply otherwise:

8. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Within the App you can do the following:

California residents (under the CCPA/CPRA) and residents of the EU/UK (under the GDPR) have additional rights and may be entitled to lodge a complaint with a supervisory authority. We do not discriminate against you for exercising your privacy rights. To exercise any right, contact us using the details in Section 12.

9. Children's Privacy

The App is not intended for, and may not be used by, anyone under the age of 18. We do not knowingly collect personal or biometric information from minors. If we learn that we have collected such information from a person under 18, we will delete it promptly. If you believe a minor has provided us information, please contact us.

10. International Users

We are based in the United States, and information that leaves your device may be processed and stored in the United States or other countries where our service providers operate. These jurisdictions may have data-protection laws that differ from those in your country. Where required, we implement appropriate safeguards for international transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy in the App and updating the "Last updated" date, and, where required by law, by obtaining your consent. Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.

12. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or your data, contact us at:

Soulution Holdings LLC
A Wyoming limited liability company
Email: info@morpheai.app