Legal
Privacy Policy
What Louvo does with your photo, what we keep, and what we do not. Written to describe the app as it is actually built.
Effective 2026-09-06
The short version
Louvo takes a photograph of you and shows you what a haircut would look like on you. To do that, your photo is sent to us and passed once to the image model that generates the preview. It is deleted as soon as the preview is made — not at the end of the day, and not when a cleanup job next runs.
The finished preview is downloaded onto your phone and deleted from our servers. After that, the only copy in existence is the one on your device, and it stays there until you delete it.
Your photos and your previews are never public, never shown to anyone else, never used to advertise to you, and never used to train an image model. When you share a look, what your friends see is our own mannequin render of that haircut — never your face.
You do not need an account to use the app. You need one only to buy generations, so that generations you have paid for survive a change of phone.
Who we are
Roda Production. We will publish a contact address here before Louvo is released publicly. We are the controller of the personal data described in this policy.
This policy covers the Louvo mobile app, the Louvo API behind it, and the web page a shared Louvo link opens.
What we collect, and why
- Your photograph
- The image you choose or take, in order to generate a preview. It is uploaded directly to private storage, read once by the generator, and deleted the moment the job finishes — whether it succeeded, failed or was cancelled. We also record its pixel dimensions, because the preview is generated in the same shape as your photo. It is never stored in our database, never made public, and never kept after the job settles.
- Your preview
- The generated image. It is held in private storage only until your phone has collected it, then deleted. If your phone never collects it — because it was switched off, or the app was removed — it is deleted unread after seven days.
- A device identifier
- When you first open the app, your phone generates a random secret and keeps it in the platform keystore. We store only a one-way hash of it. It identifies a phone, not a person, and it is what lets us match a finished preview to the device that asked for it.
- An install anchor, on Android
- On Android we additionally read the system-provided ANDROID_ID and store a salted hash of it. Its only purpose is to make the two free generations belong to a device rather than to an installation, so that removing and reinstalling the app does not hand out two more. It is not combined with anything else and is not used to recognise you anywhere but here.
- Account details
- Only if you sign in: your email address, the stable identifier your sign-in provider gives us, and a display name where the provider supplies one. If you use Sign in with Apple and choose to hide your address, we receive and store the relay address Apple gives us and nothing else.
- Purchases
- Which pack you bought, the store transaction identifier, and the resulting movements of your generation balance. We never see or receive your card details — payment happens entirely inside the App Store or Google Play.
- A notification token
- Only if you allow notifications: the push token issued by Apple or Google, so we can tell you when a preview you are waiting for is ready. It is removed when the platform tells us it has stopped working.
- Share events
- When you share a look, and when somebody opens a shared link, we record the share code, the channel, the platform, and the device hash where there is one. A shared link names a haircut, so none of this includes your photo or your preview. For someone opening a link in a browser we also record a truncated browser user-agent string.
- Technical logs
- Ordinary server logs: request paths, status codes, timings and errors, kept briefly to keep the service running and to investigate faults.
What we do not collect
- No advertising identifiers, no advertising SDKs, and no tracking of you across other companies’ apps or websites.
- No location, no contacts, no calendar, no microphone, no health data.
- No face recognition and no biometric template. Your photo is used to generate a picture; it is not measured, matched, indexed or used to identify you.
- No device fingerprinting. We deliberately do not compose an identifier out of your IP address, screen metrics or configuration.
- No scanning of your photo library. The app only ever receives the single image you pick or take.
- Your saved looks and favourites are stored on your device and are never uploaded.
Your photo, in detail
This is the part of the app worth being precise about, so here is exactly what happens when you generate a preview.
- Your phone uploads the photo directly to private storage using a short-lived, single-purpose upload link. It does not pass through our API, and it is stored under a random key with no public address and no CDN in front of it.
- A worker reads it once, through a link that expires in minutes, and sends it together with the haircut you chose to our image generation provider.
- The moment the job reaches a final state — done, failed or cancelled — the stored photo is deleted and our record of where it was is erased in the same operation. There is no state in which a finished job still points at your photograph.
- The preview is downloaded by your phone, and then deleted from our storage.
We do not use your photo or your preview to train, fine-tune or evaluate any model, and we do not permit our generation provider to do so either.
If you are using a build of the app configured without our server, your photo goes from your phone straight to the image provider and never reaches us at all. The Settings screen always states which of these the app you are running actually does.
Who we share data with
We do not sell your personal data, we do not share it for advertising, and we do not disclose it to anyone except the service providers we need in order to run the app. Each of them acts on our instructions and receives only what its job requires.
- Image generation
- Our generation provider receives your photo and the haircut reference for the length of one generation, in order to produce your preview.
- Storage and delivery
- Cloudflare holds your photo and your preview in a private bucket for the minutes described above, and serves our public catalog imagery.
- Hosting and database
- Railway runs our API and the database holding accounts, balances and job records.
- Purchases
- RevenueCat validates your purchase with the store and tells us to add generations to your balance. Apple and Google handle the payment itself.
- Notifications
- Expo, Apple and Google deliver the push notification that says your preview is ready. The notification does not contain your image.
- Sign-in
- Apple and Google verify who you are when you choose to sign in with them. We receive an identifier and an email address, and nothing more.
- Resend sends the six-digit code when you sign in with an email address.
We may also disclose information where the law requires it, or to establish or defend legal claims. If we are ever party to a merger or acquisition, personal data may transfer as part of it, and this policy continues to apply until you are told otherwise.
Where your data is processed
Our providers operate in the United States and the European Union, so your data may be processed outside the country you live in. Where data leaves the UK or the European Economic Area, transfers are made under the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.
How long we keep things
- Your photograph
- Minutes. Deleted as soon as the generation settles.
- Your preview
- Until your phone collects it, and at most seven days.
- Device record and push token
- While you use the app; removed when you delete your account or the app’s data.
- Account and email address
- Until you delete your account, which you can do yourself in Settings.
- Purchase and balance records
- Kept after account deletion with your identity removed, because tax law and store refunds require a record of the transaction.
- Share and referral events
- Kept in aggregate to measure how the app grows. They do not identify you.
- Server logs
- A short rolling window, then discarded.
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, and ask for it in a portable form. You can withdraw consent — for notifications, or for a generation you have not yet started — at any time, without affecting what was done before.
The fastest route for most of it is the app itself. Settings has account deletion, which permanently deletes your account and everything attached to it, and clearing saved looks and favourites removes what is held on your device. For anything else, contact us and we will answer within one month.
We will publish a contact address here before Louvo is released publicly. If you are in the UK or the EEA and you think we have got this wrong, you also have the right to complain to your national data protection authority.
Legal bases for using your data
If you are in the UK or the European Economic Area, we rely on the following bases.
- Performance of a contract
- Generating the preview you asked for, keeping the generations you bought, and running your account.
- Legitimate interests
- Keeping the service secure and working, preventing abuse of the free allowance, and understanding how many people share the app and how many arrive from a shared link.
- Consent
- Push notifications, and access to your camera or photo library.
- Legal obligation
- Keeping records of purchases, and answering lawful requests.
If you are in California
We do not sell personal information and we do not share it for cross-context behavioural advertising. We collect the categories described above — identifiers, commercial information, photographs, and internet activity relating to this app — for the purposes stated and for no other purpose.
You have the right to know what we collect, to delete it, to correct it, and not to be treated differently for exercising those rights. Account deletion is in the app, under Settings, and a contact address for the rest will be published here before Louvo is released publicly.
Children
Louvo is not intended for children under 13, or under 16 in countries where that is the age of digital consent. We do not knowingly collect personal data from children. If you believe a child has used the app, contact us and we will delete the account and everything on it.
How we protect what we hold
- Everything travels over encrypted connections.
- Your photo and your preview live in a private bucket with no public address, reachable only through links we mint that expire in minutes.
- Your device secret and your email sign-in code are stored only as one-way hashes, so a stolen database row cannot be replayed as you.
- No image is ever stored in our database — not your photograph, and not your preview.
- The app asks the operating system to block screenshots and screen recordings of its own screens.
No system is perfect and we do not claim otherwise. If a breach ever affects your data, we will tell you and the relevant regulator as the law requires.
Changes to this policy
If we change what we do with your data, we will change this document and move the date at the top of it. For anything material we will tell you in the app before the change takes effect, rather than relying on you to re-read it.
Effective 2026-09-06.