1. Types of Information We Collect

1.1 Collected Facial Data (Core Data)

For the core function of virtual hair clip try-on, we collect the following specific facial data from the portrait images you upload:

  • Key facial feature coordinates: 2D/3D coordinates of facial landmarks including forehead, temples, hairline, cheeks, jawline, bridge of the nose, eyes, and ears (used to position hair clips accurately).
  • Facial contour data: Outline shape of the face (oval, round, square, heart-shaped, etc.) to adapt hair clip display effects to different face shapes.
  • Hair area data: Position and range of hair coverage on the head (forehead hair, sideburns, top hair) to determine optimal hair clip placement areas.
  • Basic facial attribute data: Skin tone (non-identifiable, only for matching hair clip color harmony), face orientation/angle (front, side, tilted) to adjust 3D rendering of hair clips.
  • Original/uploaded portrait images: Portrait photos you upload are transmitted to OpenRouter for AI processing (the portrait may include face data). Yumi does not store your uploaded portrait images on its servers after processing.

1.2 Other Collected Data

In addition to facial data, we collect the following information to support service operation:

  • User-Provided Information: Account registration information (email address, username), feedback content, customer service communication records, and voluntarily shared try-on results.
  • Automatically Collected Information:
    • Device information: Device model, operating system version, screen resolution, camera parameters, unique device identifier (UDID, anonymized), network type (Wi-Fi/5G).
    • Usage data: Try-on history (hair clip styles selected, adjustment operations performed, number of adjustments, try-on duration), feature usage frequency, App interaction logs (button clicks, page visits).
    • Log data: IP address (anonymized by masking the last 8 bits), access timestamp, network provider, App version number, error logs (if any).
  • AI Processing Derived Data: Processed facial feature vectors, hair clip placement parameter sets, and rendered try-on result images (generated based on your uploaded portraits and AI algorithms).

1.3 Data Collection Methods

All data is collected through the following explicit methods with your active participation:

  • Facial data: Collected only when you voluntarily upload a portrait image (from device album or camera capture) and initiate the "AI Try-On" function; no facial data is collected in the background without your operation.
  • Account information: Collected when you voluntarily complete account registration (optional; basic try-on features are available without registration).
  • Device/usage data: Automatically collected in real-time only during your active use of the App (stops when you close the App).
  • Derived data: Generated automatically during AI processing of your uploaded portraits (tied to your try-on operation and not collected independently).

We do not collect sensitive personal information such as your race, religion, political views, or health status unless you voluntarily provide it. We do not use continuous background collection, covert tracking, or other non-explicit methods to collect any data.

2. Purpose of Information Use

2.1 Full Usage Scenarios for Facial Data

All collected facial data is used exclusively for the following scenarios related to virtual hair clip try-on, with no other secondary uses:

  • Core try-on effect generation:
    • Analyze facial landmarks to position different types of hair clips (bangs clips, side clips, top clips) accurately on the corresponding areas of the face/hair.
    • Adapt hair clip size, angle, and transparency based on facial contour and orientation to ensure natural and realistic try-on effects.
    • Match hair clip color/brightness with skin tone to optimize visual presentation of try-on results.
  • User-adjustable try-on features:
    • Support real-time adjustment of hair clip position (horizontal/vertical movement) based on facial feature coordinates.
    • Support adjustment of hair clip quantity (adding/removing multiple clips) by mapping additional clips to unused facial landmark areas.
    • Save adjustment parameters to retain your customized try-on settings for subsequent preview.
  • Try-on result rendering and display:
    • Generate final try-on result images/videos by overlaying hair clip assets on your portrait based on processed facial data.
    • Display try-on results in the App interface and allow you to save/share them (only with your explicit permission).
  • Service optimization (non-identifiable):
    • Anonymize facial data (remove all personally identifiable information) to analyze common face shape types of users, optimize hair clip adaptability for different face shapes, and improve AI algorithm accuracy.
    • Use aggregated (non-user-specific) facial data to debug and fix rendering bugs (e.g., hair clip misalignment on specific face shapes).
  • Technical troubleshooting:
    • Use facial data (temporarily) to diagnose and resolve user-reported issues (e.g., try-on effects not displaying correctly) with your explicit consent; delete the data immediately after troubleshooting is completed.

2.2 Usage Scenarios for Other Data

Other collected data is used for the following limited purposes:

  • Account management: Verify user identity, reset passwords, and ensure account security (only for registered users).
  • Service stability: Monitor App performance, fix technical bugs, and optimize loading speed based on device/usage data.
  • User experience improvement: Personalize hair clip style recommendations (based on your try-on history) without involving identifiable facial data.
  • Communication: Respond to your feedback/inquiries, send service updates (e.g., new hair clip styles) and important notices (e.g., policy changes).
  • Legal compliance: Comply with legal obligations (e.g., anti-fraud checks) using anonymized log data.

We will not use your personal information (including facial data) for any purpose not stated in this Privacy Policy without your explicit, written consent.

3. Third-Party Data Processing

We integrate the following specific third-party services to enhance functionality, and all data processing by these parties complies with strict privacy standards:

  • AI Service Provider: OpenRouter:
    • Data Processed: The uploaded portrait photo (resized/compressed JPEG image) together with the text prompt for the selected hair clip type. The photo may include face data.
    • Processing Purpose: Provide AI algorithm support for facial landmark recognition, hair clip position mapping, and 3D adaptive rendering of hair clips to generate accurate try-on effects.
    • Data Transmission: The portrait photo and prompt are transmitted to OpenRouter only after the user explicitly consents in-app (e.g., by tapping "Confirm & Generate" and selecting "Agree" in the consent prompt). Transmission is encrypted in transit using TLS 1.3 and occurs in real time for the requested try-on generation.
    • Data Protection Capability: OpenRouter maintains data protection capabilities equivalent to or higher than Yumi's standards, including compliance with GDPR, CCPA, and ISO 27001 certification. OpenRouter is prohibited from using Yumi user data for any purpose other than providing the agreed AI services, and is bound by a strict data processing agreement (DPA) with Yumi.
  • Cloud Storage Services:
    • Providers: Not applicable for Yumi portrait/result storage; portrait/result processing is handled by OpenRouter.
    • Data Stored: Yumi does not store user-uploaded portrait photos or generated try-on result images in external cloud storage for its own purposes. Any temporary handling needed to complete the AI request is performed by OpenRouter and its infrastructure according to its privacy and data processing policies.
    • Storage Location: AWS servers in US East (Virginia) or Google Cloud servers in EU (Frankfurt) (you may select the region during first use).
    • Protection Measures: AES-256 encryption for stored data, access control lists (ACLs) limiting access to authorized personnel only, and regular security audits.
  • Analytics Services:
    • Provider: Google Analytics 4 (GA4).
    • Data Processed: Anonymized usage data (no facial data, no personally identifiable information) including feature usage frequency, App interaction logs, and device type (anonymized).
    • Processing Purpose: Analyze App performance, optimize user interface, and identify usage trends (no user-specific analysis).
  • Payment Services:
    • Providers: Apple Pay, Google Pay, Stripe.
    • Data Processed: Only payment transaction information (no facial data or personal information); we do not store any payment card details (card number, CVV, expiration date).
    • Processing Purpose: Process payments for premium hair clip styles or ad-free experience.

We conduct annual audits of all third-party service providers (including OpenRouter) to verify their compliance with our data protection requirements. We terminate cooperation immediately if any provider fails to meet our standards.

4. Scenarios of Information Sharing

4.1 Facial Data Sharing (Strictly Limited)

Your facial data is shared only in the following scenarios, with strict safeguards:

  • With OpenRouter (AI Service Provider):
    • Shared Data: The uploaded portrait photo (resized/compressed JPEG) and the text prompt for the selected hair clip; the photo may include face data.
    • Sharing Trigger: Only when the user taps "Confirm & Generate" and selects "Agree" in the in-app consent prompt. Without this consent, we do not send the portrait to OpenRouter.
    • Storage Location of Shared Data: OpenRouter processes the data on its servers located in the EU (Ireland) and US (California); all data is deleted from OpenRouter's servers within 24 hours of processing completion.
    • Protection Measures: OpenRouter is contractually prohibited from storing, sharing, or using the data for any purpose other than providing AI try-on processing; all data is encrypted during transmission and processing.
  • With Your Explicit Consent:
    • Shared Data: Try-on result images (including facial data) that you choose to share to social media (e.g., Instagram, TikTok) or send to others via messaging apps.
    • Sharing Trigger: Only when you click the "Share" button and confirm the sharing action; we do not share any data on your behalf without confirmation.
    • Control: You may edit/delete the try-on result images before sharing to remove any unwanted facial features.
  • For Legal Compliance:
    • Shared Data: Facial data (if required) in response to valid legal requests (court orders, government subpoenas) from competent authorities; we will only share the minimum necessary data and notify you of the disclosure (unless prohibited by law).

4.2 Sharing of Other Data

Other data is shared only in the following limited circumstances:

  • With cloud storage/analytics/payment providers (as listed in Section 3) for service provision (only anonymized/non-identifiable data).
  • In case of business transfer (merger, acquisition, asset sale): All user data (including facial data) may be transferred as part of the transaction; we will notify you via email/App notice at least 30 days before the transfer and allow you to request deletion of your data.
  • With service providers (technical support, customer service): Only non-identifiable data to facilitate service provision (e.g., anonymized error logs for troubleshooting).

We will never sell, rent, or lease your facial data or personal information to third parties for commercial purposes under any circumstances. We take reasonable and industry-leading measures to ensure that any shared information is used only for the stated purpose and protected by appropriate security measures (encryption, access control, audit trails).

5. Security Measures

5.1 Retention Period for Facial Data

We retain your facial data only for the minimum period necessary to fulfill the stated purposes:

  • Raw portrait images: Yumi does not retain uploaded portrait images on its own servers. Uploaded photos are sent to OpenRouter only for the time required to process the request; any further retention, if any, is handled by OpenRouter and its infrastructure according to their policies.
  • Facial feature data/derived data: Retained only for the duration of the AI processing request needed to generate the try-on result. Yumi does not retain facial feature or derived facial data for a fixed number of days.
  • Try-on result images: Stored only in the App’s local “My Works” history on the user’s device (up to a maximum of 30 works). Try-on result images remain until the user deletes them or removes the account/app; they are not subject to a fixed time-based deletion period.
  • Anonymized facial data (for optimization): Retained indefinitely in aggregated form (no user identification possible) to improve AI algorithm accuracy and hair clip adaptability.
  • Legal retention exceptions: Retain data for a longer period if required by law (e.g., tax/regulatory obligations); we will delete the data immediately after the legal retention period expires.

5.2 Security Measures for Facial Data Protection

We implement the following technical and organizational measures to protect your facial data:

  • Encryption:
    • Transmission: All facial data is transmitted using TLS 1.3 (for external transmission to OpenRouter/cloud storage) and AES-256 (for internal transmission).
    • Storage: Raw portraits and facial feature data are stored with AES-256 encryption; encryption keys are managed via a secure key vault (AWS KMS/Google Cloud KMS) with multi-factor authentication (MFA) for access.
  • Access Control:
    • Only authorized Yumi personnel (e.g., AI engineers, technical support) with a legitimate business need can access facial data; access is granted on a "need-to-know" basis.
    • All personnel accessing facial data are bound by non-disclosure agreements (NDAs) and receive annual privacy/security training.
    • Access logs are maintained for all facial data access (including time, user, action) and reviewed monthly for unauthorized access attempts.
  • Technical Safeguards:
    • Regular security audits (quarterly) by third-party cybersecurity firms to identify vulnerabilities in facial data processing/storage systems.
    • Data loss prevention (DLP) tools to prevent unauthorized exfiltration of facial data.
    • Regular backups (encrypted) of facial data with a 30-day retention period for backup files; backups are tested monthly for recoverability.
  • Deletion Protocols:
    • Secure deletion (overwriting) of facial data from storage media (servers, backup tapes) to prevent recovery.
    • Confirmation of deletion from OpenRouter's servers (via API verification) within 24 hours of processing completion.

While we implement industry-leading security measures, no data transmission or storage system is completely secure. You acknowledge that there is no absolute guarantee of security, and we will notify you promptly (within 72 hours) of any unauthorized access to your facial data in accordance with applicable data breach notification laws.

6. User Rights Regarding Personal Data

In accordance with applicable data protection laws (e.g., GDPR, CCPA, California Privacy Rights Act), you have the following specific rights regarding your facial data and other personal information:

  • Right to access: You may request a complete copy of all facial data (raw portraits, feature coordinates, derived data) and other personal information we hold about you, in a structured, machine-readable format (e.g., JSON for feature data, JPG for images).
  • Right to correction: You may request to correct any inaccurate facial data (e.g., mislabeled face shape) or update your account information linked to facial data.
  • Right to deletion (Right to be Forgotten): You may request immediate and permanent deletion of all your facial data (raw portraits, feature data, try-on results) at any time; we will complete the deletion within 7 business days and confirm deletion via email. Exceptions apply only if required by law (e.g., legal hold).
  • Right to data portability: You may request to receive your facial data (feature coordinates, try-on results) in a structured, machine-readable format (e.g., CSV/JSON) for transfer to another service provider.
  • Right to withdraw consent: You may withdraw your consent to our processing of your facial data at any time (via the App's "Privacy Settings" or by contacting us); this will stop all further processing of your facial data (except for processing required by law) and trigger immediate deletion of existing facial data (per above).
  • Right to opt-out: You may opt out of anonymized facial data usage for service optimization (via App settings); this will not affect the core try-on function but may reduce the accuracy of hair clip adaptability to your face shape.

To exercise these rights, please contact us at Yumi@gmail.com with the subject line "Data Rights Request - [Your Username/Email]". We will verify your identity (via email/phone verification) and respond to your request within 30 days (or 7 days for deletion requests) in accordance with applicable laws. We do not charge any fees for processing your request unless it is excessive/repetitive, in which case we will notify you of reasonable fees in advance.

7. Children's Privacy Protection

Yumi is not intended for use by children under the age of 13. We do not knowingly collect, process, or share facial data or other personal information from children under 13.

  • If we become aware that we have collected facial data from a child under 13 without verifiable parental consent, we will take immediate steps (within 24 hours) to permanently delete all such facial data (including from OpenRouter's servers and our cloud storage) and any associated personal information.
  • Parents or legal guardians who believe their child (under 13) has provided facial data to us may contact us at Yumi@gmail.com (subject line: "Children's Data Deletion Request") to request deletion. We will verify parental identity and complete deletion within 72 hours.
  • For users aged 13-18, we require verifiable parental/guardian consent before collecting/processing any facial data. Parents/guardians may exercise the data rights listed in Section 6 on behalf of their minor children, including requesting deletion of facial data at any time.

We are committed to protecting the privacy of minors and have implemented technical measures to detect and block uploads of portraits that appear to belong to children under 13 (via AI age estimation); such uploads are rejected, and no data is collected or stored.

8. Policy Update Mechanism

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technological developments (e.g., new third-party AI services, changes to facial data retention periods):

  • We will notify you of material changes to this Policy (e.g., changes to facial data collection/sharing) by:
    • Posting the updated version on the App's "Privacy Policy" page with a prominent "Updated" banner.
    • Sending an email notification to registered users (at least 30 days before the changes take effect).
    • Displaying a full-screen notice within the App (requiring explicit acknowledgment) for non-registered users.
  • The updated Policy will take effect on the date indicated at the bottom of this document. Your continued use of the App after the effective date constitutes your acceptance of the updated Policy. If you do not accept the updated Policy, you must stop using the App and request deletion of your facial data and other personal information in accordance with Section 6.
  • We archive all previous versions of this Policy (available upon request) and maintain a "Privacy Policy Change Log" (on our website) detailing the nature of changes and effective dates.
  • We encourage you to review this Privacy Policy periodically (at least once a year) to stay informed about how we protect your facial data and other personal information.

If you have questions about any updates to this Policy, please contact us at Yumi@gmail.com for clarification before the effective date.