Privacy Policy
This Privacy Policy describes how Soulution Holdings LLC, a Wyoming limited liability company ("Morphe," "we," "us," or "our"), collects, uses, stores, and protects your information when you use the Morphe mobile application and related services (the "App"). Morphe is an appearance and longevity app: it uses a guided face scan to estimate your Appearance Age and skin metrics, pairs those with a short daily check-in, and surfaces personalized insights and a skincare-style protocol. Because the scan involves face images — which are a biometric identifier — and other personal information, we have written this policy to be as clear and transparent as possible. Please read it carefully.
By using the App, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the App.
1. Important Notice
Morphe is a cosmetic, informational, and self-development tool. It is NOT a medical device, and it does not diagnose, treat, cure, or prevent any disease or medical condition — including any skin condition. The Appearance Age estimate, skin metrics, and on-device vitals estimates (such as heart rate) provided by the App are approximations intended for general cosmetic and informational purposes only. They are not a substitute for professional medical, dermatological, or other advice, diagnosis, or treatment. Always consult a qualified professional about any health or skin concern, and never disregard professional advice because of something you saw or measured in the App.
2. Information We Collect
2.1 Face Images (Biometric Data)
The core feature of the App is a guided face scan. With your permission, the App uses your device's front-facing camera to capture still images of your face from up to three angles (front, and where available, left and right). These face images are a biometric identifier, and we treat them as sensitive biometric data. We use them to estimate your Appearance Age and skin metrics as described below. Handling of these images, including transmission to our skin-analysis processor and consent, is described in Sections 4 and 5.
By default we do not keep your scan photos on our servers: each photo is used to produce your reading and is not stored by us afterwards. There is one optional setting, "Keep my scan photos," which changes that — if you switch it on, the front photo from each scan is stored on our servers alongside that scan's results so that we can see what the scanner saw when a reading looks wrong. It is off unless you turn it on. It is currently available only on internal test builds used by our own team and does not appear in the App Store version of the App, so unless you can see that setting in Settings and have switched it on, no scan photo of yours is stored on our servers. Sections 4, 5, 7 and 8 describe what it stores, how long, and how to remove it.
2.2 On-Device Vitals (rPPG)
During the scan, the App also analyzes subtle frame-to-frame color changes on your skin — a technique called remote photoplethysmography (rPPG) — to estimate vitals such as heart rate, heart rate variability, and respiration rate. This computation runs entirely on your device. No video is recorded, stored, or transmitted for this purpose. The resulting numerical estimates are stored on your device, and (only where it improves your scan) we may attach a short numerical heart-rate/variability series to the skin-analysis request described in Section 4. If you turn on contributing results, those numbers are also included in the copy of your results that we keep on our servers — see Section 4.
2.3 Appearance Age and Skin Metrics
From the scan we derive your estimated Appearance Age, skin metrics (for example clarity, redness, smoothness, and evenness), and related insights and "age drivers." These derived results, along with the captured scan images, are stored on your device, which holds the full record of your scans and history. We also keep a copy of the derived results — the numbers, not your images — on our servers. Section 4 sets out exactly what that copy contains, and Sections 7 and 8 cover how long we keep it and how to have it deleted.
2.4 Daily Check-In and Journal
You may voluntarily record self-reported information through the daily check-in and journal — for example sleep, hydration, nutrition, workouts, sun exposure and SPF, skincare products and active ingredients, supplements, alcohol, and similar lifestyle factors. This information is optional, is provided by you, and is stored on your device, and the App computes correlations between these factors and your scan results on your device. If you turn on contributing results, your check-in answers are also stored on our servers alongside your scan results (Section 4).
2.5 Profile and Onboarding Information
During onboarding you may provide optional profile information such as a name, birth year (used to compute your age for the Appearance Age comparison), gender, skin type, skin goals, and preferences. This information is optional and is stored on your device. Your name, birth year and coach-voice preference stay there and are never sent to our servers. The appearance goals and motivations you select are also kept on your device, and are sent to our servers only if you switch on the optional onboarding-answer contribution described in Section 4. The App does not require you to create an account or provide an email address to use its core features.
2.6 AI Coach Conversations
If you use the in-app AI coach (including its voice mode), the questions you ask, relevant conversation history, and a short summary of your recent scan results and goals are sent to our backend and to third-party large language model (LLM) providers to generate a response. In voice mode, your speech is converted to text before it reaches us. Your device does that conversion itself wherever it can; where your device does not support it, the conversion is done by Apple's speech recognition service instead. Either way, what reaches our servers is the text, not audio from your side of the conversation: we do not receive, and do not store, a recording of your voice. We do not send your face images to the coach.
The coach also keeps a memory between sessions, stored on your device: short facts you have told it, the observations it made about your scans, and a summary of each session. It reads that memory from your device every time, and it is yours to read and delete in the App (You → What the coach remembers). Short extracts from it are included in the request described above so the coach can pick up where you left off. There is one optional setting, "Let us see what your coach remembers," which additionally sends a copy of that memory to our servers so our team can look at it when the coach gets something wrong. It is off unless you turn it on, your device remains the source of truth either way, and Sections 4, 7 and 8 describe what the copy contains, how long it is kept, and how to remove it.
A separate setting, "Share coaching sessions," decides whether we keep the conversation itself. As described above, what you say has to reach our servers as text for the coach to answer at all; this setting does not change that, and it is the only setting on this screen that is on unless you turn it off. With it on, we store the turns of each coaching session under your anonymous device identifier: what you said, what the coach said back, when each turn happened, and the result of the automated safety check for that turn. We use it to review and improve the coach, including reviewing sessions where a safety check fired. We do not sell it and we do not give it to advertisers. With it off, your sessions are used to answer you and are then discarded rather than stored, which is the same behavior as before this setting existed. You can change it during onboarding or at any time in Settings → Privacy, turning it off stops anything further being stored immediately, and Sections 4, 7 and 8 describe how long a stored session is kept and how to remove it.
2.7 Subscription and Device Data
Subscriptions are processed by Apple through the App Store; we do not collect or store your payment card details, and we receive only your subscription status and related identifiers from Apple to manage access. The App also uses an anonymous device identifier for backend requests. It registers that identifier with our servers once and receives an access credential specific to your device, which it stores in your device's secure keychain and uses for its own requests; this replaces a single credential shared by every installation, so requests from your device can be told apart from other people's and limited to your own data. The identifier is generated at random on your device, is not derived from any hardware identifier, and is not linked to your name or contact details. The App may also collect limited technical information such as app version and crash or stability diagnostics to keep the App working. We do not use this information to identify you personally.
3. How We Use Your Information
We use the information we collect to provide and improve the App, specifically to do the following:
- Run your face scan and estimate your Appearance Age, skin metrics, and age drivers.
- Compute on-device vitals estimates and keep your scan history and progress on your device, with a copy of the derived results on our servers as described in Section 4.
- Generate insights and correlations between your self-reported daily factors and your scan results.
- Produce personalized recommendations and, when you use it, AI coach responses.
- Operate, maintain, secure, and improve the App, and manage your subscription and access.
- Comply with legal obligations and enforce our terms.
We do not sell your personal information. We do not sell, rent, or share your biometric data or face images with advertisers or data brokers, and we do not use your biometric data for advertising.
4. What Leaves Your Device
Morphe is local-first: your device holds the full record of your scans, images, vitals, check-ins, and derived results, it remains the source of truth, and the App works offline. That does not mean nothing is stored elsewhere. We also keep a copy of some of your data on our servers, and this section says exactly what. Information leaves your device in these cases:
- Skin analysis: to estimate your skin metrics and perceived age, your captured face images are securely transmitted (encrypted in transit) to our skin-analysis service, along with an optional short numerical vitals series. Images are downscaled and compressed before upload, and are sent with a consent attestation as described in Section 5. If you have given a birth year, the App also includes your age in that request; our analysis service does not use it in the estimate and does not keep it.
- A retained copy of your scan results: the result the analysis returns for each scan — the derived numbers and text, such as your perceived-age estimate and skin metric scores — is stored on our servers as part of running the analysis, and we keep it. This copy contains derived results only; it does not contain your face images. It is kept whether or not you switch on any of the optional choices below, so that your results can be returned, supported, and improved on. We keep this copy for 24 months after your last interaction with the App, and then destroy it — see Section 7.
- AI coach: when you use the coach, the text described in Section 2.6 is sent to our backend and LLM providers. Our systems also keep security and safety logs of these requests, described in Section 7.
- Contributing results and habits (optional): if you turn this on in Settings, your scan measurements (including the vitals numbers in Section 2.2) and the habit and check-in answers you give the coach are stored on our servers under your anonymous device identifier, so that longer-term correlations can be computed and our analysis improved. This is off unless you turn it on. Turning it off stops anything further being stored; to remove what is already there, delete your data as described in Section 8.
- Contributing your onboarding answers (optional): if you turn this on in Settings, the appearance goals and motivations you selected during onboarding are stored on our servers under the same anonymous device identifier, so that we can improve the guidance the App gives. Your name, your birth year, and your chosen coach voice are never included. This is a separate choice from contributing results, and each is off unless you turn it on. Turning it off stops anything further being stored; to remove what is already there, delete your data as described in Section 8.
- Keeping your scan photos (optional, off by default): if you turn on "Keep my scan photos," the front photo from each scan is stored on our servers under your anonymous device identifier, in the same place as that scan's stored results. We use these photos for one purpose: to look at what the scanner saw when a reading appears wrong, and to improve the scan. We do not use them for advertising, we do not sell them, and we do not share them outside the people working on the App and the processors named in Section 6. They are kept for 24 months after your last interaction with the App and then destroyed, and "Delete all my data" removes them (Section 8). This setting is currently available only on internal test builds used by our own team; it does not appear in the App Store version, and no photo of yours is stored unless the setting is visible to you and you have switched it on. Turning it off asks our servers to delete what they hold for your device.
- Sharing your coaching sessions (optional, ON unless you turn it off): if you leave this on, the turns of each coaching session described in Section 2.6 — what you said, what the coach said back, the time of each turn, and the outcome of the automated safety check for that turn — are stored on our servers under the same anonymous device identifier. They are sent once, at the end of a session, from your device's memory. If that send does not get through we try once more straight away and then discard the session: nothing is written to your device's storage and nothing is held back for a later attempt. We use them to review and improve the coach, and in particular to review sessions where a safety check fired, which we otherwise have no record of at all. They are kept for 6 months after your last interaction with the App and then destroyed, "Delete all my data" removes them (Section 8), and turning the setting off stops anything further being stored straight away. This is the conversation in your own words, which is why it is a separate choice from contributing results and from the coach-memory copy below, and it is not connected to your scan photos, which have their own separate setting above.
- Letting us see what your coach remembers (optional, off by default): if you turn this on in Settings, a copy of the coach's memory described in Section 2.6 — the short facts you told it, the observations it recorded about your scans, and its summary of each session — is stored on our servers under the same anonymous device identifier. It is sent at the end of a coaching session, and each send replaces the previous copy, so what we hold is a snapshot of what is on your device rather than a growing history. Your device stays the source of truth: the coach always reads its memory from your phone, we never send any of this copy back to the App, and turning the setting off changes nothing about how the coach works. We use the copy for one purpose: to see what the coach remembered when it says something wrong. This is written in your own words rather than as numbers, which is why it is a separate choice from contributing results. It is kept for 24 months after your last interaction with the App and then destroyed, "Delete all my data" removes it (Section 8), and turning the setting off both stops anything further being sent and asks our servers to delete what they already hold for your device.
- Face video is never captured or transmitted. The App does not record video at any time, and there is no setting that causes it to. The scan captures still images (Section 2.1), and the vitals computation in Section 2.2 reads camera frames in memory and discards them. An earlier version of this App offered an optional "contribute face video" setting for a planned feature; that setting has been removed, and no video was ever captured or sent under it. We will update this Policy before any such feature is introduced.
We instruct our processors to use your data only to provide these features on our behalf and not to sell it or use it to train their own general-purpose models except as needed to provide the service.
5. Biometric Data (BIPA and Similar Laws)
Your face images are biometric identifiers, and certain jurisdictions — including Illinois under the Biometric Information Privacy Act (BIPA), and Texas and Washington under their respective laws — provide specific protections for biometric data. Where these laws apply, the following commitments govern our handling of your face images and any biometric information derived from them:
- We obtain your consent before capturing or processing your face images for the scan, and processing is attested at the time of each analysis request.
- We use your face images and derived biometric information solely to provide the App's scan and analysis features described in this Policy.
- We do not sell, lease, trade, or otherwise profit from your biometric data.
- We retain biometric data, and the results derived from it, only as long as needed to provide the service, and destroy it on the following written retention-and-destruction schedule. Face images sent to our skin-analysis processor are kept by the processor for no more than 30 days and are then deleted. The retained copy of your scan results and scan measurements — the numbers derived from your face — is kept for 24 months after your last interaction with the App and is then destroyed. Where you have switched on the optional "Keep my scan photos" setting described in Sections 2.1 and 4, the scan photos stored under that setting are kept on the same schedule: 24 months after your last interaction with the App, and then destroyed. We do not store your scan photos on our servers at all unless you switch that setting on. We destroy biometric data sooner when the purpose for collecting it has been satisfied, and when you ask us to delete your data we honor the request within 30 days (see Section 8). This schedule is our standing commitment for all biometric data we hold, wherever these laws apply.
By enabling and using the face scan, you provide your informed consent to the capture and processing of your face images and derived biometric information as described in this Policy. You may withdraw consent at any time by disabling camera access and deleting your data (see Section 8).
6. How We Share Information
We share information only in the limited circumstances below:
- Skin-analysis processor: our third-party (or in-house) skin-analysis service, which processes your face images to return skin metrics and a perceived-age estimate on our behalf under confidentiality and data-protection obligations.
- AI and infrastructure providers: LLM providers that generate coach responses, plus cloud hosting, storage, and diagnostics providers that process data on our behalf.
- Apple: for authentication of your subscription and processing of purchases through the App Store.
- Legal and safety: when required by law, subpoena, or to protect the rights, property, or safety of our users or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the protections of this Policy.
We never share your biometric data or face images for any third party's independent marketing or advertising purposes.
7. Data Storage, Security, and Retention
Your device holds the full record of your data and is the source of truth for it. We also hold the server-side copy described in Section 4. For information that leaves your device, we use industry-standard safeguards including encryption in transit (TLS), access controls, and secure infrastructure. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your on-device data remains until you delete it or uninstall the App. Deleting the App removes the copy on your device, but on its own it does not remove the server-side copy — use "Delete all my data" in the App for that (see Section 8). If you delete the App and install it again, the new installation generates a NEW anonymous device identifier; we do not restore the previous one, and the App cannot afterwards ask us to delete anything stored under it. If you want the server-side copy removed, use "Delete all my data" before you uninstall, or contact us using the details in Section 12. We keep the server-side copy of your derived results, any check-in and habit data you have contributed, any scan photos stored under the optional setting in Section 4, and any copy of your coach's memory stored under the optional setting there, for 24 months after your last interaction with the App, and then destroy them. Coaching sessions stored under the sharing setting in Section 4 are kept for a shorter period: 6 months after your last interaction with the App, and then destroyed. We set that period deliberately, because a stored session is a record of a conversation in your own words and we do not think we should hold one for as long as we hold a set of numbers. It applies to every stored session, including any session where an automated safety check fired. You do not have to wait for any of these periods: Section 8 sets out what the App's delete control removes by itself, what it does not, and how to ask us to remove the rest. Face images are sent to the service provider that performs the skin analysis for us. That provider does not store the image: it holds it in memory only for the length of the analysis, and passes it to the AI provider that produces the reading. Under that AI provider's published policy, material sent through its interface is kept for up to 30 days for abuse monitoring only and is then deleted, except where longer retention is required by law. We have not separately arranged a shorter retention period.
There are things we cannot delete on request, and we would rather say so here than let Section 8 imply otherwise:
- Security and safety records. Our systems keep an audit trail of sensitive events, including deletions themselves. Where the AI coach's automated safety checks flag a reply, that record includes your anonymous device identifier and a short excerpt of the coach's own reply — a bounded snippet, not your conversation and not your messages. These records are the evidence of what happened and of what was deleted, so they deliberately survive deletion; a trail that could itself be erased would prove nothing. They are not used to build a profile of you, and never for advertising. We keep security and safety records for 24 months. Records of deletion events themselves are the one exception: we keep those for 3 years, because the proof that data was destroyed has to outlive the data it covers.
- Records with no identifier attached. Some server-side records are written without a device identifier on them. Nothing links them to you, which also means we cannot find yours in order to delete them individually; we remove such records in bulk instead. They hold derived scan results, never your name or contact details. We purge unattributed records in bulk at least once every quarter — the purges are never more than 90 days apart.
8. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Within the App you can do the following:
- Access and review your scan history, results, and profile information in the App.
- Delete your data. "Delete all my data" (You → Delete all my data) erases the data the App holds about you on your device, and asks our servers to delete the scan measurements, check-in answers and contributed onboarding answers stored under your device identifier, together with the retained copies of your scan results described in Section 4, any scan photos stored under the optional setting there, any copy of your coach's memory stored under the optional setting there, and any coaching sessions stored under the sharing setting there. Everything any of the optional settings sends is stored under that identifier, so this one control reaches all of it. It also revokes your device's registration and the access credential described in Section 2.7, so that identifier can no longer be used. The App does the server step first and tells you the result: if it did not succeed, or if our servers could only remove part of what they held, it says so plainly and does not report a deletion that did not happen.
- Know what that does not reach. It does not delete records with no identifier attached, or the security and safety records described in Section 7. Records with no identifier attached cannot be found on an individual request at all — Section 7 explains how those are removed instead. The security and safety records are not removed on request. If the App tells you the server-side deletion did not finish, you can run it again, or contact us using the details in Section 12 and we will complete it. Deletion requests we handle by hand are honored within 30 days.
- Disable camera access at any time through your device settings, which turns off the scan feature.
- Choose not to switch on the optional contributions in Section 4, or switch them off at any time. Coaching-session sharing is the one that starts on, and you can turn it off during onboarding or at any time afterwards in Settings → Privacy. Switching any of them off stops anything further being stored; it does not by itself remove what is already stored.
California residents (under the CCPA/CPRA) and residents of the EU/UK (under the GDPR) have additional rights and may be entitled to lodge a complaint with a supervisory authority. We do not discriminate against you for exercising your privacy rights. To exercise any right, contact us using the details in Section 12.
9. Children's Privacy
The App is not intended for, and may not be used by, anyone under the age of 18. We do not knowingly collect personal or biometric information from minors. If we learn that we have collected such information from a person under 18, we will delete it promptly. If you believe a minor has provided us information, please contact us.
10. International Users
We are based in the United States, and information that leaves your device may be processed and stored in the United States or other countries where our service providers operate. These jurisdictions may have data-protection laws that differ from those in your country. Where required, we implement appropriate safeguards for international transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy in the App and updating the "Last updated" date, and, where required by law, by obtaining your consent. Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.
12. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your data, contact us at:
Soulution Holdings LLC
A Wyoming limited liability company
Email: info@morpheai.app