← H28 Legal

Privacy Policy

Last updated: September 25, 2026 · Effective: September 25, 2026

This Privacy Policy explains how H28 (“we,” “us,” or “our”), the developer of the H28 mobile application (the “App”), collects, uses, stores, shares, and protects your information when you use the App. By using H28, you agree to the practices described here. If you do not agree, please do not use the App.

H28 is a self-improvement and entertainment app that analyzes a photo of your face to provide aesthetic ("looksmax") scores and improvement suggestions. The App does not perform facial recognition or identity verification, and we do not use your photos to identify you.

1. Information We Collect

H28 does not require you to create an account, and we do not ask for your name, email address, phone number, or social media identity to use the App. We collect the following:

a) Photos you submit ("Scan Photos")

When you take or upload a photo of your face for analysis, that image is processed as described in Section 2. You provide these photos voluntarily. We do not retain your photos — your image is used only transiently to generate your result and is then deleted from our servers (see Section 7). We keep the resulting scores, not the image.

b) Profile inputs you provide

During onboarding you may provide non-identifying attributes such as age range, height, weight, and country. These improve the relevance of your analysis.

c) Anonymous device account

We create an anonymous, opaque account identifier that is generated and stored on your device (in your device’s secure storage) so we can associate your scans and purchases with you. Because it lives on the device, it may persist if you reinstall the App, so your results and purchases stay linked to your device. It is a random value that is not linked to your name or real-world identity.

d) Scan results

The scores, ratings, regional breakdowns, and suggestions generated from your photo are stored so you can view them again later.

We also store a one-way cryptographic checksum (a hash) of the uploaded image file alongside your result, so that submitting the very same file again returns the result you already have. This checksum is not a faceprint: it cannot be reversed into an image, it cannot be used to recognize or identify you, and two different photos of the same person produce completely different values.

e) Purchase & entitlement data

When you make a purchase, our payment partners (Apple and RevenueCat) tell us whether your purchase or subscription is active. We do not receive or store your credit card or payment details.

f) Usage & diagnostic analytics

We use privacy-focused analytics (PostHog, hosted in the United States) to understand how the App is used, and an error-monitoring service (Sentry) to detect, diagnose, and fix crashes and technical faults. If you choose to send us feedback from inside the App, your message reaches us through that same error-monitoring service. We do not use third-party advertising SDKs and we do not track you across other companies' apps or websites.

Our website (h28.ai) measures visits with Google Analytics so we know which pages help people find the App. In the EEA, UK and Switzerland it only runs after you accept it. The website does not receive your photos or scan results.

g) Device information

We collect basic technical details about your device — such as device model, operating-system version, App version, and your region/locale setting — to display your results correctly and to diagnose issues. This information does not identify you personally.

2. How We Use Your Photos & Data

We use the information above to provide and improve the App, specifically to:

We do not retain your photos. After your photo is analyzed it is deleted from our servers; only the resulting scores and suggestions are stored. We also do not use your photos for facial recognition or identity verification, sell your photos or personal data, use your data for third-party advertising, or use your photos to train third-party AI models for their own purposes.

3. Automated Processing & AI

Your analysis is produced by automated systems, including a third-party large-language / vision AI model. To generate your scores and feedback, your Scan Photo and profile inputs are transmitted to our servers and to a third-party vision AI provider for the sole purpose of producing your result. That provider processes the image to return the analysis and does not receive your identity. We operate this AI processing under a strict zero data retention requirement: your image is not stored by the AI provider and is not used to train its models. It is transmitted solely to produce your result, and nothing is kept afterward. The current list of sub-processors, including the AI provider we use, is in Section 5. Results are estimates for entertainment and self-improvement and are not guaranteed to be accurate (see our Terms of Use).

4. Facial Images — No Recognition or Identification

H28 analyzes a facial image solely to produce the aesthetic scores and suggestions you request. H28 does not perform facial recognition or identity verification. We do not create, store, or use a faceprint, face-geometry template, or any other biometric identifier to recognize you; we do not match your face across users, sessions, or any external database; and we do not use your face to identify you. The checks that tell you whether your face is framed and turned correctly while capturing run entirely on your device: they are never transmitted to us and never stored. Your image is deleted after the analysis runs (see Section 7) — we keep only the resulting scores, not the photo. You provide your photo voluntarily, and you may withdraw and delete your data at any time (see Section 8).

5. Service Providers & Sharing

We share data only with service providers (“sub-processors”) who help us run the App, and only as needed to deliver the service:

ProviderPurposeData involved
SupabaseTransient photo upload, database, anonymous authScan photo (deleted after processing), results, account id
Vision AI provider (currently Google Gemini)AI analysis of the photo (zero data retention: image not stored or used for training)Scan photo, profile inputs
PostHog (US)Product analyticsUsage events, device information (model, OS, region)
Google AnalyticsWebsite visit measurement (h28.ai only)Pages viewed, browser, approximate location
SentryCrash and error monitoring, in-app feedbackDiagnostic event data, device information, feedback you choose to send
Apple & RevenueCatIn-app purchases & entitlementsPurchase/subscription status
Cloud hosting (EU and US regions)Server infrastructureEncrypted data in transit and at rest

We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, or property of our users or us. We do not sell your personal information.

6. International Data Transfers

We operate globally. Your data may be processed and stored on servers located in the United States, the European Union, or other countries where our providers operate. Where required, we rely on appropriate safeguards for such transfers.

7. Data Retention

Photos, on our servers: we do not retain them. Your photo exists in our storage only for the brief moment between upload and processing, and is deleted immediately after the analysis runs. We never keep the image afterward.

Photos, on your device: because we delete our copy, the App keeps your captured photos in its own private storage on your device so you can reopen your past scans and see the poses you submitted. The App keeps only a limited number of your most recent captures and deletes older ones automatically. These files never leave your device except as the transient upload described above, and they are removed when you use “Delete my data” or delete the App.

Results & account: we retain your scan results (the scores and suggestions, plus the image checksum described in Section 1(d) — not the image itself) and your anonymous account so you can view past results, until you delete them. You can erase everything at any time using “Delete my data” in the App’s Profile screen, which removes your scans and unlock status and signs you out. We may retain limited aggregated or anonymized analytics that no longer identify you.

8. Your Rights & Choices

Depending on where you live (e.g., under the GDPR, Türkiye’s KVKK, CCPA/CPRA, or BIPA), you may have the right to access, correct, delete, or restrict processing of your data, to withdraw consent, and to not be discriminated against for exercising these rights. You can:

Because accounts are anonymous, we may be unable to locate your data without the App-based deletion tool; deleting in-app is the most reliable way to exercise your deletion right.

9. Data Security

We protect data using encryption in transit (TLS/HTTPS), access controls, and per-user isolation so that you can only access your own data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children’s Privacy

H28 is intended for users 18 years of age or older. We do not knowingly collect personal information or photos from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new “Last updated” date. Material changes will be reflected in the App or by other reasonable means.

12. Contact Us

Questions or requests? Contact H28 at [email protected].


H28 · Privacy Policy · September 15, 2026