Privacy by design
We never keep your photograph.
Your photograph is not a data point we harvest. It is an image you loan us for a matter of seconds so we can measure observable cosmetic characteristics — and then it is gone.
Transient processing only
The captured image is held in volatile memory, or in a strictly time-boxed encrypted temporary store, only for the duration of the analysis call.
No persistence of the image
The raw photograph, and any full-resolution or croppable derivative from which a face could be reconstructed or recognised, is never written to a database, object store, log, backup, or analytics pipeline.
Immediate destruction
On completion of analysis — success or failure — the image and every temporary buffer are deleted. Any temporary encrypted store is enforced to auto-delete within 60 seconds, with a sweeper job as a backstop.
What we retain
Only the derived, non-identifying cosmetic metrics (numeric scores and text descriptors), your report, the timestamp, your country, and your user account link. None of these can reconstruct your photograph.
Zero data retention with our vision provider
Where analysis calls an external vision API, the request is configured for zero data retention on the provider side and transmitted over TLS only.
No biometric identification, ever
Lervé does not perform, enable or store facial recognition, facial templates or any faceprint. We assess surface cosmetic characteristics, not identity.
After every analysis you will see this confirmation: “Your photo has been analysed and permanently deleted. We keep your results, never your photograph.”
For the full detail — lawful bases under UK GDPR, sub-processors, retention windows and your data-subject rights — read our Privacy Policy.