Hairoine

Privacy Policy

Effective July 18, 2026

Overview

Hairoine ("Hairoine", "we", "us", or "our") operates the Hairoine mobile application and the related web service at hairai.bondrift.com (together, the "Service").

The Service lets you upload a photo of yourself, optionally add a reference photo and a text prompt describing a hairstyle, and receive AI-generated hairstyle previews.

This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described here.

Information We Collect

Photos and prompts. When you request a hairstyle preview, we collect the photo you upload of yourself, any optional reference photo you add, and the text prompt or selected style you choose. This content is used to generate your requested preview.

Account and sign-in service data. If you continue with Apple or Google, Hairoine receives the provider's stable account identifier and the verified email address the provider makes available. The Google Sign-In software included in the iOS app declares that it may process linked name, email address, phone number, coarse location, user and device identifiers, and authentication or usage data for sign-in, service operation, security, and analytics. Hairoine's backend stores only the provider identifier and verified email from the identity token; it does not request or store your phone number or location for the Hairoine account. A device or session identifier is used to associate your generations, purchases, and saved looks with the same Hairoine account across the app and web service.

Purchase information. In the iOS app, credits and subscriptions are sold through Apple's In-App Purchase service. On the web service, checkout may be handled by Stripe. We receive the transaction identifier, product, offer or introductory-trial status, subscription status and expiration, and payment status needed to grant credits or membership. Your payment card details are handled by Apple or Stripe and are not shared with us.

Paywall and subscription service data. Superwall and RevenueCat may receive a pseudonymous Hairoine app user identifier, product identifiers, purchase history and subscription status, app and device details, and product-interaction events such as onboarding or paywall views, taps, selections, and purchase-flow results. Because the app user identifier is associated with your Hairoine session or account, these records may be linked to you for App Store privacy-disclosure purposes. Superwall and RevenueCat do not receive your uploaded photos, reference photos, generated images, prompts, or payment card number.

Advertising measurement data. Where enabled, Hairoine uses limited Meta attribution to measure its own advertising. On iOS, Hairoine asks for Apple's tracking permission before any Meta attribution starts; if you decline, the app works normally and sends no Meta activation, trial, or purchase events. If you allow it, Meta may receive manual app-activation, trial, and verified purchase events, purchase value and currency, and basic app or device details. On hairai.bondrift.com, Meta Pixel receives page views, checkout starts, completed purchases after Stripe verification, and basic browser or network details. Automatic event logging and advertiser-ID collection remain disabled in iOS. We do not send photos, prompts, generated media, email addresses, or payment card details to Meta.

Usage and technical data. We may collect basic analytics such as app events, approximate device type, paywall and onboarding interactions, and error logs to keep the Service stable and improve the product.

How We Use Information

To provide the Service: generate hairstyle previews from your photo, reference photo, and prompt, and to display your generation history inside your account.

To operate credits and subscriptions purchased through Apple's In-App Purchase service in the iOS app, and through Stripe where web checkout is offered.

To deliver remotely configured onboarding and paywall experiences, assign product experiments, and measure whether those experiences work correctly.

To respond to support requests and to investigate and prevent fraud, abuse, or violations of our terms.

To maintain and improve the performance, safety, and quality of the Service.

Face Data

Face data means the photos you upload that may show your face. We use those photos, optional reference photos, selected styles, and prompts only to create the hairstyle preview you request and, when live video is enabled, the hairstyle video you request.

We do not create or keep a facial template. We do not use face recognition, biometric identification, identity verification, or biometric inferences.

Third-party AI partners receive the source photo, optional reference photo, and prompt needed to generate an image preview. Temporary provider files used for multi-image edits are deleted by Hairoine after the edit attempt. These partners may retain limited abuse-monitoring logs under their data controls, currently up to 30 days by default unless stricter approved controls apply. When live video is enabled, a video-processing partner receives a short-lived Hairoine backend grant to the selected generated image needed to render that video. Vercel Blob stores face/source/reference/result/video files as private objects. Neon stores account, job, purchase-linkage, and media-reference metadata needed to operate your account.

Vercel Insights and Bondrift analytics receive website usage and technical data, such as page, browser, device, session, referral, and event information. We do not send uploaded photos, reference photos, generated images, or videos to those analytics services.

Saved Looks remain in Hairoine active systems until you delete the content or your account. Content deletion immediately removes the related private Blob objects, generation jobs, and saved history, while your account, session, and purchases stay available for new generations. Account deletion also removes account data, active sessions, and purchase linkage from active systems. For deletion help or questions, contact paddyganto12@gmail.com.

After account deletion, we retain only a non-personal HMAC record of a StoreKit transaction key and its deletion time. This small fraud and financial-control record stops a deleted purchase from being replayed. It does not contain your name, email, photos, prompts, payment card data, or the raw transaction key.

How Your Hairstyle Content Is Processed

Choosing or uploading a photo sends it to the Hairoine backend for private storage, but does not by itself send it to third-party AI partners. When you affirmatively start a hairstyle generation, the selected photo, optional reference photo, selected style or prompt, and generation settings are sent to third-party AI partners to produce the preview you requested. Hairoine keeps the selected source, reference, generated result, and job record in private Saved Looks so you can find them later and use a generated result for a future video. If live video is enabled and you request a video, the selected generated image is also made available to a video-processing partner through a short-lived Hairoine backend grant for that render.

Third-party AI partners process image requests and may retain limited abuse-monitoring logs under their data controls. When live video is enabled, a video-processing partner processes the selected generated image for that video render. We do not share face data with advertising or analytics services.

Uploaded photos, reference photos, prompts, generated previews, and generated videos are retained as Saved Looks until you delete the content or your account.

Third-Party Services

Third-party AI partners. Used to generate hairstyle previews from your source photo, optional reference photo, and prompt. Temporary provider files used for multi-image edits are deleted after the edit attempt; limited provider-side abuse-monitoring retention follows the partner's data controls.

Video-processing partners. Used only when live video is enabled and you request a video; the partner receives a short-lived backend grant to the generated image selected for that render.

Vercel hosting and Vercel Blob. Vercel hosts the Hairoine website and backend and may process network and technical request data needed to deliver and secure them. Vercel Blob is used for private storage of source photos, reference photos, generated previews, and generated videos.

Neon. Used for account, session, job, credit, purchase-linkage, and media-reference metadata needed to operate the Service.

Vercel Insights and Bondrift analytics. Used for website usage and technical analytics; uploaded or generated media is not sent to these analytics services.

Apple In-App Purchase. Used to sell credits and subscriptions inside the iOS app and to verify the product, transaction, offer or introductory-trial status, subscription status, and expiration used to grant access. Payment information is processed by Apple and is not shared with Hairoine.

Sign in with Apple and Google Sign-In. Used to authenticate you and keep one Hairoine account in sync across iOS and the web service. Hairoine receives a provider account identifier and verified email. Google's included sign-in software may also process the linked profile, contact, approximate-location, device, and usage categories declared in its Apple privacy manifest for authentication, service operation, security, and analytics. Hairoine does not send photos, prompts, generated media, or payment-card details through login.

Superwall. Used to deliver remote onboarding and paywall experiences and measure product interactions. Superwall may process a pseudonymous Hairoine app user identifier, purchase and subscription status, product identifiers, app and device details, and onboarding or paywall events. The Hairoine identifier can link those records to your Hairoine session or account. Hairoine photos, prompts, generated media, and payment card details are not sent to Superwall.

RevenueCat. Used in observer mode to synchronize Apple purchase and subscription status with a pseudonymous Hairoine app user identifier. The Hairoine identifier can link that purchase history to your Hairoine session or account. Apple StoreKit and the Hairoine backend remain the purchase and entitlement source of truth. Hairoine photos, prompts, generated media, and payment card details are not sent to RevenueCat.

Meta. Used for limited measurement of Hairoine advertising where enabled. On iOS, Hairoine requests Apple's tracking permission before Meta attribution starts; a denial sends no Meta activation, trial, or purchase event and does not limit app features. If allowed, the iOS app may send manual activation, trial, and verified purchase events. The web service sends page views, checkout starts, and Stripe-verified purchases through Meta Pixel. Automatic event logging and advertiser-ID collection remain disabled in iOS. Hairoine photos, prompts, generated media, email addresses, and payment card details are not sent to Meta.

Stripe. Used for web checkout where offered. Payment information is processed by Stripe and is not shared with Hairoine.

Service Provider Safeguards

We require service providers that process information for Hairoine to use it only to provide, secure, support, or measure the Service as described in this policy, and to protect it to the same or an equivalent standard required of Hairoine. We do not authorize these providers to use Hairoine photos, prompts, or generated media for their own advertising or to sell that content.

Access to personal information is limited to the providers and personnel that need it for the purposes described in this policy. Provider processing may occur in the United States or other countries where those providers operate, subject to their contractual and legal safeguards.

Advertising and Tracking

Hairoine does not show third-party advertising inside the app.

We do not sell or rent your personal information or your hairstyle content to third parties.

We do not share your photos or prompts with third parties for their own advertising or tracking purposes.

Where Meta attribution is enabled, Hairoine uses limited activation, trial, checkout, and verified purchase events to measure its own ads. The iOS app requests Apple's tracking permission first; declining keeps Meta attribution off and leaves the app fully usable. Automatic event logging and advertiser-ID collection remain disabled.

Data Retention and Deletion

Uploaded photos, reference photos, prompts, generated previews, and generated videos are retained as Saved Looks until you delete the content or your account. This Hairoine-owned retention supports Gallery and future video requests.

Temporary provider files used for a multi-image edit are deleted after the edit attempt. Third-party AI partners may retain limited abuse-monitoring logs under their data controls, currently up to 30 days by default unless stricter approved controls apply; Hairoine deletion cannot remove those provider-side logs.

Content deletion immediately removes the related private Vercel Blob objects, generation jobs, and saved history. It does not delete your account, session, credits, subscription, or purchase linkage, so you can create new generations afterward.

Account deletion also removes account data, active sessions, and purchase linkage from Hairoine active systems. After account deletion only, we retain a minimal non-personal HMAC record of StoreKit transaction keys to prevent purchase replay and maintain fraud and financial controls. This record cannot be used to recover your photos, prompts, account profile, email address, or raw transaction identifier. Deleting your Hairoine account does not cancel an Apple subscription; subscriptions are managed through your Apple account.

Security

We use reasonable administrative, technical, and physical safeguards to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children's Privacy

The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.

Your Privacy Rights

Depending on where you live, you may have the right to access, correct, or delete the personal information we hold about you, and to object to or restrict certain processing.

You control whether to submit a photo, reference image, or prompt for AI generation. Selecting or uploading content does not by itself start third-party AI processing; you start that transfer by affirmatively requesting a hairstyle generation. You may withdraw from future AI processing by not starting another generation, remove individual Saved Looks through the content-deletion controls, or use the in-app Delete Account control to remove your account and active Hairoine data as described above.

You can also stop optional camera or photo-library access in iOS Settings. Revoking device permission does not delete content already submitted; use Hairoine's content or account deletion controls for that.

To exercise any of these rights, contact us at the email below. We will respond in line with applicable law.

International Users

The Service is hosted in the United States and may be used from other countries. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, and by using the Service you consent to that transfer where applicable law requires consent.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. Continued use of the Service after a change means you accept the updated policy.

Contact Us

If you have any questions about this Privacy Policy or your personal information, please contact Hairoine support at paddyganto12@gmail.com.


Hairoine · hairai.bondrift.com · paddyganto12@gmail.com

About Hairoine · Support