Privacy by design

We never keep your photograph.


Your photograph is not a data point we harvest. It is an image you loan us for a matter of seconds so we can measure observable cosmetic characteristics — and then it is gone.

Transient processing only

The captured image is held in volatile memory, or in a strictly time-boxed encrypted temporary store, only for the duration of the analysis call.

No persistence of the image

The raw photograph, and any full-resolution or croppable derivative from which a face could be reconstructed or recognised, is never written to a database, object store, log, backup, or analytics pipeline.

Immediate destruction

On completion of analysis — success or failure — the image and every temporary buffer are deleted. Any temporary encrypted store is enforced to auto-delete within 60 seconds, with a sweeper job as a backstop.

What we retain

Only the derived, non-identifying cosmetic metrics (numeric scores and text descriptors), your report, the timestamp, your country, and your user account link. None of these can reconstruct your photograph.

Zero data retention with our vision provider

Where analysis calls an external vision API, the request is configured for zero data retention on the provider side and transmitted over TLS only.

No biometric identification, ever

Lervé does not perform, enable or store facial recognition, facial templates or any faceprint. We assess surface cosmetic characteristics, not identity.

After every analysis you will see this confirmation: “Your photo has been analysed and permanently deleted. We keep your results, never your photograph.”

For the full detail — lawful bases under UK GDPR, sub-processors, retention windows and your data-subject rights — read our Privacy Policy.

Lervé is a personal exploration and wellness curiosity tool — not a medical application.