Privacy Policy
Lervé is committed to privacy by design. This policy explains what we do and, critically, what we do not do with the information you provide.
Face images are never stored
Your captured photograph is processed transiently in memory for the duration of the analysis call only. It is never written to a database, object store, log, backup, or analytics pipeline. On completion — success or failure — the image and every temporary buffer are destroyed. Any temporary encrypted store used during analysis auto-deletes within 60 seconds, with a sweeper job as a backstop. We do not perform, enable or store facial recognition, facial templates or any faceprint.
What we retain
The derived cosmetic metrics (numeric scores and text descriptors), your report, the timestamp, your country and your user account link. Account details (email, hashed password or social sign-in identifier), plan status and payment records held by our payment provider.
Lawful bases (UK GDPR)
Consent for transient image processing; contract for your account and payment; legitimate interest for fraud prevention and aggregate analytics.
Sub-processors
We use a vision analysis provider (configured for zero data retention), a PCI-compliant payment provider, and a transactional email provider. A current list is available on request.
Your rights
Access, rectification, erasure, portability and objection. Self-service export and account deletion are available in your account settings. Erasure requests are propagated to backups per our retention policy.
Contact
For any privacy request, write to privacy@lerve.io. You also have the right to complain to the UK Information Commissioner’s Office (ICO).