Introduction
Aerys ("we," "us," or "our") is a comprehensive facial analysis platform that provides scientific anthropometric measurements and attractiveness scoring. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website, services, and facial analysis tools (collectively, the "Services").
Important Notice: Aerys is provided for informational, educational, and entertainment purposes only. Our facial analysis tools are not medical devices and do not provide medical advice. Results should not be used for medical, diagnostic, or clinical decisions.
1. Information We Collect
1.1 Personal Information You Provide
Account Information:
- Email address
- Account credentials (username and password)
- Profile information you choose to provide
- Gender and ethnicity selections (optional, for analysis accuracy)
Payment Information:
- Payment details processed securely through Stripe
- Subscription tier and billing history
- Usage quota and feature access records
Communication Information:
- Messages sent through our support channels
- Feedback, suggestions, and feature requests
- Support ticket contents and correspondence
1.2 Facial Images and Analysis Data
Uploaded Content:
- Front-facing and side profile photographs you upload
- Any additional images you provide for analysis
- Facial landmark data extracted from your images
- Interactive measurement inputs you provide through our tools
Analysis Results:
- Over 90 anthropometric measurements including:
- Canthal tilt measurements
- Gonial angle calculations
- Facial width-to-height ratios
- Jaw metrics and facial thirds proportions
- Symmetry assessments
- And all other metrics calculated by our system
- Attractiveness scores and harmony ratings
- Category-specific assessments (harmony, dimorphism, angularity, features)
- Generated insights and recommendations
- Progress tracking data and comparison analyses
- Morphing simulation results (when applicable)
1.3 Technical Information
We collect minimal technical data necessary to operate and secure the Services:
Session Data:
- Authentication tokens and login session information
- Account activity timestamps
Usage Data:
- Analysis history and request timestamps
- Feature usage patterns (which tools you use)
- Error logs and diagnostic information
We DO NOT collect:
- IP addresses for tracking purposes
- Device fingerprinting data
- Third-party cookies for advertising
- Behavioral tracking across websites
- Location data
2. How We Use Your Information
2.1 Service Delivery
Facial Analysis Processing:
- Calculate facial measurements, ratios, and anthropometric data
- Generate attractiveness scores and harmony assessments
- Provide category-specific analysis (harmony, dimorphism, angularity, features)
- Create interactive visualizations of your facial metrics
- Generate morphing simulations showing potential improvements
Platform Functionality:
- Maintain your account and authenticate your identity
- Store your analysis history for progress tracking
- Manage your subscription tier and usage quotas
- Enable comparison between multiple analyses over time
- Provide access to your personalized dashboard
2.2 Communication
- Send service updates and feature announcements
- Provide technical support and respond to inquiries
- Send critical security and account notifications
- Deliver subscription and billing information
2.3 Legal and Security
- Comply with legal obligations and valid legal requests
- Enforce our Terms of Service and Usage Policy
- Detect and prevent fraud, abuse, and unauthorized access
- Protect our rights, property, and safety of our users
- Investigate and resolve disputes or security incidents
3. Data Storage and Security
3.1 Storage Infrastructure
Image Storage:
- All uploaded facial images are stored on secure cloud infrastructure
- Images are encrypted at rest using AES-256 encryption
- Access to stored images is restricted to authenticated users only
Database Storage:
- Analysis results and measurements are stored securely
- All database connections use SSL/TLS encryption
- Access controls limit data retrieval to account owners only
Processing:
- Analysis tasks are processed through secure job queues
- Processing data is temporary and purged upon completion
- Failed jobs retain minimal diagnostic data for debugging
3.2 Security Measures
We implement industry-standard security practices:
- End-to-end encryption for data in transit (HTTPS/TLS)
- Encryption at rest for stored images and sensitive data
- Secure authentication using industry-standard protocols
- Regular security audits and vulnerability assessments
- Access controls and principle of least privilege
- Secure API endpoints with authentication requirements
- Automated monitoring for suspicious activity
3.3 Data Retention
Active Accounts:
- We retain your images, analysis history, and account data for as long as your account remains active
- You control your data and can delete specific analyses or your entire account at any time
Account Deletion:
Upon account deletion request, we remove:
- All uploaded facial images
- Analysis results and measurement history
- Personal information
Some data may be retained as required by law or for legitimate business purposes.
4. Data Sharing and Disclosure
4.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information or facial images to third parties for their marketing purposes.
4.2 Service Providers
We share data with trusted third-party service providers who help us operate the Services, including:
- Cloud hosting and storage providers
- Payment processing services
- Authentication and security services
All service providers are carefully selected and contractually obligated to protect your data.
5. Your Rights and Choices
5.1 Access and Control
Account Dashboard:
- View all your uploaded images and analyses
- Download copies of your analysis results
- Delete individual analyses from your history
- Export your data in structured formats
5.2 Data Subject Rights
Depending on your location, you may have the following rights:
Right to Know:
- Request information about what personal data we process
- Understand the categories of data we collect
- Learn about our data sharing practices
Right to Access:
- Request a copy of your personal information
- Receive your data in a portable, machine-readable format
- Access your complete analysis history
Right to Correction:
- Request correction of inaccurate personal information
- Update your account details and profile information
- Note: We cannot guarantee factual accuracy of analysis results, as they are computational outputs
Right to Deletion:
- Request deletion of your account and all associated data
- Remove specific analyses from your history
- Deletion requests are completed promptly
Right to Data Portability:
- Receive your data in a structured, commonly used format
- Transfer your data to another service (where technically feasible)
5.3 Exercising Your Rights
To exercise any of these rights:
- Email us at privacy@aerys.co
- Use the data controls in your account settings
- Contact our support team
We will respond to your request promptly and may need to verify your identity before processing requests.
6. Cookies and Tracking
6.1 Essential Cookies Only
We use cookies solely for essential functionality:
Authentication Cookies:
- Keep you logged in to your account
- Maintain your session security
- Remember your preferences
Session Management:
- Ensure proper functioning of interactive tools
- Maintain state during analysis processes
6.2 What We Don't Use
We do NOT use:
- Third-party advertising cookies
- Analytics cookies for behavioral tracking
- Cross-site tracking technologies
- Social media tracking pixels
- Remarketing or retargeting cookies
Disabling cookies will prevent you from logging in and using the Services.
7. Third-Party Services and Links
7.1 Integrated Services
Our Services integrate with third-party platforms for payment processing, cloud infrastructure, and essential functionality. These providers have their own privacy policies governing their data practices.
7.2 External Links
Our Services may contain links to external websites or resources. We are not responsible for the privacy practices of third-party sites. We encourage you to review their privacy policies before providing any information.
7.3 Content Creator Partnerships
If you access Aerys through an affiliate or content creator partnership:
- We may share anonymized conversion data with partners
- Your personal information and images remain private
- Partners receive commission tracking data only
- You can contact us to learn which partner referred you
8. International Data Transfers
8.1 Global Operations
Aerys operates globally, and your data may be transferred to, stored, and processed in:
- United States (primary infrastructure)
- European Union (for EU users, where applicable)
- Other countries where our service providers operate
8.2 Transfer Safeguards
When transferring data internationally, we ensure protection through:
Standard Contractual Clauses (SCCs):
- EU-approved contractual protections for data transfers
- Legally binding data protection obligations
Adequacy Decisions:
- Reliance on jurisdictions with adequate data protection frameworks
- Compliance with regional data protection requirements
Additional Safeguards:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and audits
9. Children's Privacy
9.1 Age Restrictions
Our Services are NOT intended for individuals under 18 years of age.
Strict Policy:
- Users must be 18 years or older to create an account
- Users may not upload images of minors (under 18)
- We do not knowingly collect data from minors
9.2 Parental Notice
If we discover that we have collected information from a minor without proper consent:
- We will immediately delete the account and all associated data
- All uploaded images will be permanently removed
- Parents/guardians should contact us immediately if they believe a minor has used our Services
If you believe a minor has created an account or uploaded images, please contact us immediately at privacy@aerys.co.
10. Limitation of Liability
10.1 Security Disclaimer
While we implement robust security measures, no system is completely secure:
No Absolute Guarantee:
- We cannot guarantee 100% security against all threats
- Internet transmission carries inherent risks
- Unauthorized access, though unlikely, is theoretically possible
Your Responsibility:
- Maintain the confidentiality of your account credentials
- Use strong, unique passwords
- Report suspicious activity immediately
- Do not share your account with others
10.2 Limitation of Liability
To the maximum extent permitted by law:
Data Security:
- Not liable for data breaches caused by user's failure to secure their credentials
Service Interruption:
- Not liable for temporary unavailability or service interruptions
- Not liable for data loss due to technical failures or force majeure events
Analysis Accuracy:
- Facial analysis results are computational outputs, not professional assessments
- We make no warranties about the accuracy or reliability of measurements
- Results should not be used for medical, legal, or professional decisions
This limitation applies even if we have been advised of the possibility of such damages.
11. Regional Privacy Rights
11.1 European Economic Area (EEA), UK, and Switzerland
Data Controller:
For users in the European Region, the data controller is:
- Aerys International Limited (if established)
- Otherwise: Aerys, Inc.
Legal Bases for Processing:
We process your data based on:
- Contract Performance: To provide the Services you've subscribed to
- Legitimate Interests: To improve our Services and ensure security
- Consent: For optional features and communications
- Legal Obligations: To comply with applicable laws
GDPR Rights:
- Right to lodge a complaint with your supervisory authority
- Right to withdraw consent at any time
- Right to object to automated decision-making
- All rights listed in Section 5 above
11.2 California Residents (CCPA/CPRA)
California Privacy Rights:
Right to Know:
- Categories of personal information collected
- Sources of personal information
- Business purposes for collection
- Categories of third parties we share with
Right to Delete:
- Request deletion of personal information
- Exceptions for legal obligations and fraud prevention
Right to Opt-Out:
- We do not "sell" personal information as defined by CCPA
- We do not share personal information for cross-context behavioral advertising
Right to Non-Discrimination:
- We will not discriminate against you for exercising your rights
- Same service quality regardless of privacy choices
Shine the Light:
- We do not share personal information with third parties for their direct marketing
Contact for California Requests:
Email: privacy@aerys.co
11.3 Brazil (LGPD)
Legal Bases:
- Contract performance
- Legitimate interests
- Consent
- Legal obligations
- Exercise of legal rights
LGPD Rights:
- Confirmation of processing
- Access to your data
- Correction of incomplete or inaccurate data
- Anonymization, blocking, or deletion
- Data portability
- Information about data sharing
- Right to withdraw consent
- Right to review automated decisions
Brazilian Data Protection Officer:
Contact via: privacy@aerys.co
International Transfers:
- Standard Contractual Clauses approved by ANPD
- Compliance with Brazilian data protection requirements
Supervisory Authority:
Right to lodge a complaint with ANPD (Brazilian Data Protection Authority)
11.4 Canada
Consent:
By using our Services, you consent to the collection, use, and disclosure of your personal information as described in this Policy.
Cross-Border Transfers:
Your data may be processed in the United States and other jurisdictions where privacy laws may differ from Canadian law.
Withdrawal of Consent:
You may withdraw consent at any time, subject to legal and contractual restrictions.
11.5 Australia
Australian Privacy Principles (APP):
We comply with the APP where applicable to Australian users.
Supervisory Authority:
Right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
12. Data Processing Details
12.1 Automated Processing
Facial Analysis:
Our Services use automated algorithms to:
- Detect facial landmarks
- Calculate anthropometric measurements
- Generate attractiveness scores
- Create harmony assessments
No Legal Effect:
- Our automated processing does not produce legal effects
- Results do not affect your legal rights or status
- Analysis is for informational purposes only
- You are not subject to decisions based solely on automated processing
12.2 Flagged Content
If analysis is flagged for review:
- Content is initially reviewed in anonymized form
- Re-identification occurs only if policy violations are confirmed
- Used to enforce Terms of Service and Usage Policy
13. Changes to This Privacy Policy
13.1 Updates and Notifications
We may update this Privacy Policy to reflect:
- Changes in our Services or features
- Legal or regulatory requirements
- Improvements to our privacy practices
How We Notify You:
- Update the "Effective Date" at the top of this Policy
- Post notice on our website for material changes
- Email notification for significant changes affecting your rights
- In-app notification for active users
13.2 Continued Use
Your continued use of the Services after changes take effect constitutes acceptance of the updated Privacy Policy. If you disagree with changes, please discontinue use and contact us to delete your account.
13.3 Version History
Previous versions of this Privacy Policy are available upon request at privacy@aerys.co.
14. Contact Information
14.1 Privacy Questions and Requests
General Inquiries:
Email: privacy@aerys.co
Support:
Email: support@aerys.co
14.2 Response Time
We strive to respond to all privacy inquiries promptly:
- General requests: As soon as reasonably possible
- Urgent security concerns: Within 72 hours
- Data subject requests: As required by applicable law
14.3 Verification
For security purposes, we may request verification of your identity before processing data requests. This helps protect your information from unauthorized access.
15. Miscellaneous
15.1 Entire Agreement
This Privacy Policy, together with our Terms of Service, constitutes the entire agreement regarding privacy practices.
15.2 Severability
If any provision is found unenforceable, the remaining provisions continue in full effect.
15.3 No Waiver
Our failure to enforce any provision does not constitute a waiver of that provision.
15.4 Language
This Privacy Policy is provided in English. Translations may be available, but the English version governs in case of conflicts.