Privacy Policy
Last updated: August 31, 2026
Your privacy matters
Hair Fairy is built to create hairstyle previews while minimizing the personal data retained by the application. This policy explains how photos, account information, purchases, technical data, and optional analytics are handled.
What we do not do
- We do not intentionally save uploaded or generated photos in Hair Fairy’s application database, object storage, or long-term file storage.
- We do not share photos with third parties for advertising or marketing.
- We do not use photos to train a Hair Fairy-owned AI model.
- We do not sell personal data.
How photos are processed
- You select a source photo in your browser, where a session copy is kept for the current tab.
- The browser normalizes the photo and sends it over an encrypted connection to Hair Fairy’s server.
- Hair Fairy sends the photo, hairstyle instructions, and any custom reference photo to Google’s Gemini image-generation API.
- The generated result returns through Hair Fairy’s server to your browser.
- Hair Fairy processes these images in memory and does not intentionally write them to its application database, object storage, or long-term file storage.
- The browser session copy is normally cleared when the tab closes. Google may temporarily retain API inputs, outputs, and related metadata under its applicable service terms and configuration.
Third-party processing
- Google Gemini processes photos and hairstyle instructions to create results.
- Supabase provides email/password authentication and stores account entitlements and generation-request records.
- Resend delivers transactional authentication emails and processes recipient addresses and email-delivery metadata.
- Polar processes checkout, payment, customer, and order information.
- Upstash Redis temporarily processes rate-limit counters and generation locks for abuse prevention.
- Netlify hosts the production application and may process ordinary request, network, and deployment logs.
Payments
Premium subscription payments and billing management are handled by Polar. Hair Fairy sends Polar the signed-in account identifier and email address so subscriptions, renewals, cancellations, and completed orders can be linked to the correct account. Card details are entered with Polar and are not received or stored by Hair Fairy.
Data we collect
- Uploaded images and hairstyle instructions, processed temporarily to create a result.
- Email address, authentication session, account identifier, subscription and legacy remaining-image balances, and free-generation status.
- Purchase, subscription, billing-period, and entitlement metadata needed to manage access, reset paid allowances, and prevent duplicate additions.
- Generation-request identifiers, processing status, entitlement type, and timestamps used to prevent duplicate or concurrent image use. Photos and custom hairstyle descriptions are not stored in this ledger.
- Technical request metadata and short-lived, HMAC-protected account/network rate-limit identifiers used for security and abuse prevention.
- Sanitized analytics page views where enabled by regional policy or visitor choice.
Analytics
For visitors located in the European Economic Area, United Kingdom, or Switzerland, Google Analytics 4 loads only after “Allow analytics” is selected in Privacy settings. Where prior opt-in is not required under Hair Fairy’s regional policy, analytics is enabled by default. If location cannot be determined, Hair Fairy requires consent. All visitors can change their choice at any time through the footer’s Privacy settings control, and a previous “Essential only” choice remains respected.
When allowed, Hair Fairy sends sanitized page-view information. URL query strings, account IDs, email addresses, photos, hairstyle descriptions, balances, and checkout identifiers are excluded. Advertising storage, Google signals, ad personalization, granular location/device collection, and Google Ads linking are disabled. Event data is configured for two-month retention.
Account deletion and retention
You can delete your Hair Fairy account from the account page. Hair Fairy first requests deletion or anonymization of the linked Polar customer, which cancels any active subscription, then deletes the Supabase account and its subscription, balance, claim, generation-request, and processed-order records. Some providers may retain limited transaction, security, or compliance records when required by law or their applicable terms.
Analytics is not assigned your Hair Fairy account ID or email address. Account deletion therefore cannot identify historical anonymous analytics events; analytics consent and cookies can be withdrawn separately through Privacy settings.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of personal data. Contact us to make a privacy request. You may also have the right to complain to your local data-protection authority.
Changes to this policy
We may update this policy as Hair Fairy evolves. Changes will be posted on this page with a revised “Last updated” date.
Questions?
Contact us at hello@hairfairy.app.