Privacy Policy
Version 2.2.1
1. Who this policy covers
This Privacy Policy explains how MogTier (“the App,” “we,” “us”) collects, uses, stores, and deletes your information when you use the App. “MogTier” is operated by Christian Lee (“the Operator”). If you have questions about this policy, contact us at support@mogtier.app.
The App is an educational and informational tool that analyzes user-submitted facial photos using computer vision and machine learning. It is not a medical device, not a diagnostic tool, and does not provide medical advice. See the Terms of Service for the full description of what the App does and does not do.
2. What we collect
2.1 Photos you upload
When you use the facial analysis feature, you upload:
- One front-facing photo of your face.
- One side-profile photo of your face.
These photos are processed to detect and align your face, assess image quality, and generate the analysis results described in the Terms of Service (attractiveness estimate, category scores, recommendations, and an AI-generated visualization).
Photos that fail our automated quality check (too blurry, too dark, too bright, appears heavily filtered/edited, or no face clearly detected) are never stored — they exist only in memory for the duration of that one upload request and are discarded immediately if rejected.
2.2 Derived biometric data — what this consent specifically covers
To perform the analysis, the App scans your face: it computes facial landmark positions (the approximate pixel location of features like your eyes, brows, nose, and jaw line) from your photos, then measures that geometry against the App’s reference dataset to generate an AI-estimated attractiveness score (on a 1–10 scale), category-level breakdowns, and recommendations. Depending on your jurisdiction, this kind of derived facial-geometry data may be legally classified as biometric data or special-category personal data, which can carry additional legal protections beyond ordinary personal data — for example, some laws require a specific disclosure of what is collected, the specific purpose, and the retention period, before collection, separate from general contract terms.
A separate checkbox, before you ever open the camera, is what grants this consent. It is not bundled into the Terms of Service, and it is not a “Get started” button. On the screen shown during sign-up you are told, in plain text above the box and not behind a link:
- that your photos are used to measure facial geometry, which counts as biometric data;
- that each scan sends your front-facing photo to a third-party AI service;
- that the App does not diagnose medical conditions.
You then tick “I consent to my photos being analyzed as described above.” Registration is refused without it — the server checks, not just the app. What you are agreeing to is that your face is scanned to compute the geometry described above, that an AI model uses it to produce an attractiveness estimate and related feedback, that this estimate is informational and for self-improvement purposes only — not a medical, professional, or objective judgment (see the Terms of\ Service, Section 2), and that the photo itself is deleted within the short window described in Section 3.
You can withdraw this consent at any time without deleting your account. Settings has a “Stop analyzing my photos” option. Turning it on stops any future scan and deletes every analysis result derived from your past scans — the scores, the measurements, and the recommendations built from them.
Your photos, the crop sent to our AI provider, and the AI-generated image are almost always already gone by the time you do this. As Section 3 describes, those are deleted automatically within minutes of a scan, whether or not you ever touch this setting — this option is not what removes them under normal use. What it does for them is closer to a safety net: if any copy happened to still be inside its short automatic retention window at the moment you turn this on, that copy is deleted immediately rather than waiting out the rest of the window.
Turning analysis off leaves your account, your purchase history and any unspent tokens untouched, and you can turn it back on afterwards. Withdrawal does not affect the lawfulness of processing carried out before it.
The AI visualization is generated as part of every scan. This feature reuses your front-facing photo to produce an AI-illustrated depiction of possible changes to modifiable characteristics only (skin, grooming, lighting), never your underlying facial structure. Producing it requires sending your front-facing photo to a third-party AI provider (see Section 8). This runs automatically as part of the scan you start, so the consent you give when you begin a scan covers this use as well; there is no separate opt-in step for it. If you do not want your photo sent to that provider, do not start a scan.
This is a change from an earlier version of the App, in which the visualization was an optional extra step that you triggered yourself and consented to separately at that moment. Because it now always runs, the disclosure has been moved up-front rather than presented at the point of generation. Operator decision, made when finalizing this policy for launch: bundling this into the general scan consent is accepted as the final design, not a placeholder awaiting a separate opt-in step.
Landmark data computed during analysis is used only in-memory to produce your results; it is not separately stored as a standalone dataset outside of the score/analysis records described in Section 2.3.
2.3 Analysis results and account data
We also store:
- Account information: your email address, a securely hashed password (we never store your password in plain text), and your selected age band (13–17 or 18+).
- Consent records: what you agreed to and when, which version of each document you accepted, and whether you later withdrew it (Terms of Service, Privacy Policy, biometric-data processing).
- Technical data: your IP address, used to rate-limit sign-in and registration attempts so the App cannot be brute-forced or mass- registered. It is held in the server’s memory for the length of the rate-limiting window and is not written to our database. Our hosting provider also keeps ordinary access logs, which contain IP addresses, for its own operational purposes.
- Parental/guardian consent record (13–17 accounts only): the guardian’s own email address, the exact wording they agreed to, and the times at which the request was sent, confirmed from their inbox, and withdrawn (if it was) — see Section 7. Kept separately from your own account and scan data, not mixed into your regular consent records.
- Analysis results: your computed scores (overall and per-category), the internal feature values that fed into them, and any generated recommendations. These are not the photos themselves — see Section 3 for how long the photos are kept.
- AI visualization results, including the generated image and a record of what modifications were requested of the visualization provider.
- 90-day program data (only if you start the subscriber program): the improvement-priority roadmap derived from your scan results, which program quests you mark as done and on which dates, the achievements you earn, and score snapshots from the rescans you log for month-to-month comparison. This is habit-tracking data only: it contains no photos and no free text, it stays on our servers with your account so your streak survives reinstalling the App, and it is deleted along with everything else when you delete your data (Section 5). Optional “progress photo” quests never upload anything; any photo you take for one stays on your device.
2.4 What we do not collect
Your photos and derived biometric data are processed only for the requested analysis — we do not use them for any other purpose. We do not sell your photos or analysis results to third parties. We do not use your photos to train machine learning models without your separate, explicit consent (see Section 6).
2.5 Our legal basis for each of these
Under the GDPR every use of your data needs a legal basis. Ours:
| What we do | Legal basis |
|---|---|
| Create and run your account; take payment; provide the features you bought | Contract (Art. 6(1)(b)) — we cannot give you an account without this |
| Scan your face, compute facial geometry, produce scores and recommendations, generate the AI visualization | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — the separate checkbox in Section 2.2, withdrawable at any time |
| Keep consent records showing what you agreed to and when | Legal obligation (Art. 6(1)©) — we have to be able to demonstrate consent under Art. 7(1) |
| Rate-limit sign-in and registration using your IP address | Legitimate interests (Art. 6(1)(f)) — keeping accounts from being brute-forced, which is in your interest too |
| Keep records of purchases | Legal obligation (Art. 6(1)©) — accounting and tax law |
| Email a parent or guardian and record their answer, for a 13–17 account | Legal obligation — we must be able to demonstrate that consent was given (Arts. 6(1)©, 7(1), 8) |
The facial processing rests on consent and nothing else. If you withdraw it, that processing stops and its results are deleted — see Section 2.2.
3. How long we keep your photos
Every uploaded photo is deleted automatically within a short, fixed
window of capture — currently 2 minutes (see photo_ttl_minutes in
services/api/app/core/config.py) — regardless of any preference you
select. This is not user-configurable: there is no option to keep photos
longer. In that window you can view your result and optionally download
the photo alongside your score; after it elapses, the photo is
permanently deleted. This is enforced three ways, not just one: the link
used to view/download a photo stops working after the window; the photo is
deleted the next time anything happens to touch it past that point; and an
independent, regularly-run cleanup process deletes anything left over as a
backstop, so a photo isn’t relying on you (or us) remembering to come back
and look at it.
Your full analysis result (the score, category breakdowns, the facial measurements behind them, and recommendations) is kept for 7 days after the scan, then permanently deleted — a short support window, not an indefinite one: it exists so that if something looks wrong shortly after a scan, we can actually look at what happened, and so a scan you haven’t gotten around to downloading yet isn’t gone within minutes. While it exists, it is also encrypted at rest with a key separate from every other key this App uses. It is deleted immediately, before that window, if you withdraw consent to the facial analysis (Section 2.2) or delete your account.
If that scan becomes the start of a 90-day improvement program, or a
monthly rescan inside one, its score and category breakdown are copied
onto the program record itself at that moment — specifically so the
program’s before/after comparisons keep working after the 7-day window
above, without needing to keep the full result around indefinitely to
support them. That copy does not include the underlying facial
measurements (internal_features in the export described below) — only
the score and category numbers — and it is kept for as long as the program
(or your account) exists, on the same terms as the rest of your account
data described below.
One consequence worth stating plainly: a scan that was never part of a program, downloaded via the data export described in Section 5 more than 7 days after it was taken, will no longer include that scan’s full detail — only whatever program/rescan snapshot exists for it, if any.
"For as long as your account exists" is bounded, not indefinite. If an account is not used — no login, and no session silently renewing itself from a device you’re still signed in on — for 24 months, we delete the account and everything on it, the same as if you had deleted it yourself. This is an inactivity-based rule, not a fixed expiry from your last scan: opening the app at any point restarts the 24 months from that day.
4. Where your data is stored and how it’s protected
- Your data is stored in the European Union. Our database and our photo
storage are both hosted on Supabase, in the AWS
eu-west-1region (Ireland). The application server itself runs on Fly.io in London. - Data in transit between your device and our servers is encrypted (HTTPS/TLS), and the connection between our server and the database is encrypted as well.
- For the roughly two minutes a photo exists on our servers, it is encrypted at rest, using a key held only by our application and not by the storage provider. What sits in storage is unreadable ciphertext; the storage provider cannot see your face. This is deliberate: the provider encrypts data at rest with keys it holds itself, and for photographs of people’s faces we did not think that was enough on its own. This is storage encryption specifically — it describes Supabase, and it is not how the visualization feature’s photo is handled; see the next bullet but one for that case, which is different on purpose.
- The storage bucket is private. It is not publicly browsable, and the link used to view or download a photo is a short-expiry signed link, not a permanent public URL.
- Access to stored photos and analysis data is restricted to what our systems need to perform the requested analysis; we do not have a customer-support workflow that involves staff viewing your uploaded photos as a matter of course.
- Photos are captured with the device’s camera only — there is no option to upload an existing photo from your device’s gallery for this feature.
- The visualization feature is the one exception to our 2-minute window AND to the encryption described above, and we state both plainly rather than bury them. Generating your “potential” image requires sending your front-facing photo to a third-party AI provider (see Section 8), which is outside the EU. That photo cannot be sent to them encrypted the way it sits in our own storage: their model has to actually see the photograph to redraw it, the same way any image editor needs to read the picture it is asked to edit. What protects it in transit is standard HTTPS, the same as any request to any server — not the separate encryption key described above, which only ever applies to what sits in our own storage. Once it reaches the provider, that provider keeps a copy of the photo, the generated image and the request log for up to one hour after the request, then deletes them automatically. We cannot shorten that hour: the provider offers no account setting to disable retention and no way for us to delete a request early. Our own copy of the original photo is still deleted on the 2-minute schedule described above regardless.
5. Your rights and choices
You can, at any time, from inside the App:
- View your account information.
- Request everything we hold about you. Email support@mogtier.app from the address on your account and we will send you a machine-readable JSON file of your account details, your consent history, and your purchase history. For scans, it includes whatever we still hold at the time you ask: the full result (including the facial measurements behind the scores) for any scan from the last 7 days, per Section 3’s retention window, plus the score and category breakdown — but not the underlying measurements — for any scan that became a 90-day program’s baseline or a monthly rescan, for as long as that program exists. A scan outside both of those is genuinely no longer held, so there is nothing left to export for it. Your password and session credentials are deliberately excluded — they are not information about you in any useful sense, and putting them in a file you are invited to forward would be a way to leak them. We answer within one month, the same as any other request under Section 5.1.
- Stop the facial analysis without deleting your account, using “Stop analyzing my photos” in Settings. See Section 2.2.
- Delete your data. “Delete my data” in Settings permanently deletes your account, any remaining stored photos, your analysis results, your recommendations and your program data. This cannot be undone, and it forfeits any unspent tokens.
You do not need the App installed to delete your account. Go to mogtier.app/cancel-subscription and submit a request there — say plainly in the “why” field that you want your account and data deleted, not just the subscription cancelled. This is deliberately a request we review and act on, not an instant automated deletion: a link that deletes everything the moment it is clicked is also a link that deletes everything if it is clicked by mistake, or by someone else with access to that inbox. We process it and confirm back to the contact email you gave us. This does the same thing as “Delete my data” in Settings and cannot be undone either.
You can also contact us at support@mogtier.app with any request about your data, including correcting information that is wrong.
5.1 Your rights under the GDPR
If you are in the European Economic Area or the UK you have the rights below. We answer requests within one month.
| Right | How to use it |
|---|---|
| Access (Art. 15) | Email support@mogtier.app for the data export described in Section 5. |
| Rectification (Art. 16) | Contact us — some fields cannot yet be edited in the App. |
| Erasure (Art. 17) | “Delete my data” in Settings, or ask us. |
| Restriction (Art. 18) | Contact us. “Stop analyzing my photos” achieves this for the facial processing. |
| Portability (Art. 20) | Email support@mogtier.app for the same export, which is JSON. |
| Object (Art. 21) | Contact us, for anything we do on the basis of legitimate interests. |
| Withdraw consent (Art. 7(3)) | “Stop analyzing my photos” in Settings, at any time. |
You also have the right to complain to a supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, imy.se. If you live in another EEA country you may complain to your own national authority instead.
We do not make decisions about you that produce legal effects or similarly significantly affect you within the meaning of Article 22. The App profiles your facial geometry to produce a score and recommendations, and that profiling is explained in Section 2.2 and in the Terms of Service, Section 2 — but nothing in the App decides anything about your access to services, employment, credit, or any comparable matter.
If you are a California resident, you may have additional rights under the CCPA/CPRA.
6. AI model training
We do not use your photos to train or fine-tune our machine learning models without asking for your separate, explicit, opt-in consent first. If we ever want to use anonymized or de-identified data for model improvement, we will ask for that consent specifically — it is not implied by your use of the analysis feature itself.
7. Age requirements and minors
The App requires users to be at least 13 years old, with no exception — there is no parental-consent path for accounts under 13.
Users between 13 and 17 can create an account, but scanning stays locked until a parent or legal guardian confirms it from their own email inbox. The account holder cannot complete this step themselves, on their own device or any other. In outline:
- The account holder enters a parent’s or guardian’s email address in the App. This address must be different from the account’s own. Nothing is unlocked at this point.
- We email that address a one-time link, valid for 7 days. The email says which account it concerns, states that face analysis involves special category data, and says plainly that ignoring it refuses permission.
- The link opens a web page — no app, no account and no sign-in needed — that sets out what the App collects, what happens to it, who else receives it, how long it is kept, and how to undo the decision, before asking for a decision. Consent is recorded only when the guardian submits that page. Simply opening the link records nothing, so that automated mail scanners cannot consent on a guardian’s behalf.
- We then email the guardian a confirmation stating that a permission now exists in their name, containing a link that withdraws it at any time, again with no app and no sign-in. Withdrawal takes effect immediately: it re-locks scanning and deletes the photographs, measurements and results the analysis produced.
We store, for each such account: the guardian’s email address, the exact wording they agreed to, the time the request was made, the time they confirmed, and the time of any withdrawal. This record is kept separately from the account holder’s own data — see Section 2.3 — and is included in the account holder’s data export. Our lawful basis for holding the guardian’s address is Article 6(1)©: we are required to be able to demonstrate that consent was given (Article 7(1)).
We limit how often we will email a guardian’s address, so that repeated requests from the App cannot be used to send unwanted mail to somebody who is not our user.
If a guardian never responds, the request does not sit on file forever. A pending request — one nobody has confirmed or withdrawn — is automatically deleted 30 days after it was made, along with the guardian’s email address. This does not affect the account holder’s ability to try again, including with a different guardian’s address; it only stops us holding a stranger’s contact details indefinitely when they never consented to anything in the first place.
What this does and does not establish — stated plainly. Requiring an answer from a separate mailbox means the account holder cannot grant this by themselves, and it puts the disclosures above in front of an adult who can refuse and who can later revoke. It does not verify anybody’s identity or age. A determined account holder with access to a second email address can defeat it. Verifying that the person answering is genuinely an adult and genuinely the account holder’s guardian would require something like an identity document check or a payment-card verification, which the App does not do.
8. Who else processes your data
We use the following providers. Each of them processes data only on our instructions, under a written data processing agreement.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database and photo storage | Everything in Section 2.3, plus your encrypted photos (which it cannot read — see Section 4) | EU (AWS eu-west-1, Ireland) |
| Fly.io | Runs the application server | All data in transit through the App, plus access logs containing IP addresses | UK (London) |
| Replicate | Generates the AI visualization | Your front-facing photo and a text instruction — nothing else | United States |
| RevenueCat | Verifies purchases and tracks subscription status | Your account identifier and your purchase history | United States |
| Apple / Google | Take the payment | Your payment details, which go to them and never to us | Their own global infrastructure |
Notes on two of these:
Replicate. The AI visualization is the only feature that sends your photograph outside our own systems. Replicate hosts and runs the image model; the model’s original developer is a separate party from Replicate. The photo reaches Replicate readable, not encrypted with our own key — their model has to see it to redraw it — protected only by standard HTTPS in transit; see Section 4 for how that differs from how the same photo is protected while it briefly sits in our own storage. Replicate deletes the photo, the generated image and the request log automatically one hour after the request — its published default for requests made the way we make them, and the shortest retention it offers. We do not send your name, email, account identifier or scores with it. You should review Replicate’s own privacy policy at replicate.com/privacy.
Apple and Google are not our processors for payment data. They are independent controllers of it, they hold your card details, and we never see them.
8.1 Transfers outside the EEA
Replicate and RevenueCat are in the United States, so using the App involves transferring some personal data outside the EEA — your front-facing photo in the first case, and your account identifier and purchase history in the second.
RevenueCat relies on the EU Standard Contractual Clauses (plus the UK Addendum and Swiss restricted-transfer terms, where applicable) under its own Data Processing Addendum. RevenueCat is not certified under the EU–US Data Privacy Framework.
Replicate’s data processing relies on Cloudflare’s Data Processing Addendum (Cloudflare, Inc., version 6.4, effective April 3, 2026), which Replicate’s own support confirmed (case 02317590, September 2026) is the operative mechanism for Replicate’s GDPR obligations, including transfers of personal data outside the EEA. Cloudflare is certified under the EU–US Data Privacy Framework, the UK Extension to it, and the Swiss–US Data Privacy Framework, and its Data Processing Addendum separately incorporates the EU Standard Contractual Clauses (with the UK Addendum and Swiss-law adaptations) for any transfer to a jurisdiction not covered by that certification.
You can request a copy of the safeguards described above — RevenueCat’s Standard Contractual Clauses, or Cloudflare’s Data Processing Addendum covering Replicate’s processing — by emailing support@mogtier.app.
All other processing happens in the EEA or the UK.
9. The Creator Program
This section covers the separate Creator Program (creators.mogtier.app): creators who post TikTok or Instagram videos about MogTier and get paid based on the views those videos get. It is optional, has its own sign-up, and is unrelated to the facial-analysis feature described in Sections 1–8 — joining the Creator Program does not give us access to any face scans on your App account, and using the App does not enrol you in it. Creator Program data is held in a separate database from the App's own account data, though both are operated by the same person and you can reach us about either at support@mogtier.app.
9.1 Signing in
You sign in to the Creator Program with Discord, not with an email and password. We receive your Discord username, your avatar, and your email address, used only to identify your account — never for marketing. We do not read your Discord servers, messages, or friends list, and we never post to Discord on your behalf. You can also set a display name inside the dashboard, shown instead of your Discord username on the leaderboard.
9.2 Connecting the accounts you post from
To submit a video, you connect the TikTok or Instagram page you posted it from. You can connect as many pages as you post from.
TikTok. Connecting a page signs you in through TikTok's own Login Kit. We receive your TikTok display name, your avatar, a stable account ID, and an access token, which we use only to (a) read the view count, caption and cover image of a video you submit for review, and confirm it is really posted from the page you connected, and (b) nothing else — we never post, edit, delete, or read anything else on your TikTok account, and we never see your TikTok password. The token is encrypted before it is stored and cannot be read from your browser; only our server can use it. If you disconnect a page, or its connection expires and you don't renew it, we delete that page's stored token and ask TikTok to revoke it. Removing a page does not delete videos you already submitted, or what you were already paid for.
Instagram. Connecting a page signs you in through Meta's Instagram API with Instagram Login, which only works for a Professional (Business or Creator) Instagram account — a personal account cannot connect. We receive your Instagram username, your avatar, a stable account ID, and an access token, which we use only to (a) read the view count, caption and cover image of a video you submit for review, and confirm it is really posted from the page you connected, and (b) nothing else — we never post, comment, message, or read anything else on your Instagram account, and we never see your Instagram password. The token is encrypted before it is stored and cannot be read from your browser; only our server can use it. If you disconnect a page, or its connection expires and you don't renew it, we delete that page's stored token; you can also remove MogTier's access yourself at any time from Instagram Settings → Apps and Websites. Removing a page does not delete videos you already submitted, or what you were already paid for.
9.3 Videos you submit
When you submit a video, we store its link, and — for TikTok — the view count, caption and cover image at the moment you submitted it (we keep our own copy of the cover image, because TikTok's own link to it stops working after a few hours). This is what your payout is calculated from. It is kept as part of your earnings record for as long as your Creator Program account exists, and afterwards for as long as we need it for our own financial records.
9.4 Your audience-demographics recording
Once a month, to be paid, you record a short video of your own TikTok or Instagram analytics screen showing your audience's countries, filmed with a second device. This recording is stored privately — only you and we can see it, never other creators. We watch it to confirm your audience meets the program's eligibility requirement, then approve it, reject it, or ask you to resend it. We do not delete this recording on any fixed schedule. Once we approve a recording we keep the file until we choose to delete it by hand, and a rejected recording stays stored until you replace it. The approval itself — that you met the requirement for that month — is kept as part of your payout eligibility record even after the recording file is later deleted.
9.5 Getting paid
If you choose to be paid, you give us either a PayPal email or phone
number, or a USDC wallet address on the Solana network. This is encrypted
before it is stored; your dashboard only ever shows you a masked version of
it back (for example a***@gmail.com), never the full value. The full
value is only ever decrypted on the Operator's own computer, to actually
send your payment, and it is never shared with anyone else.
9.6 Where this is stored, and who else is involved
Creator Program data is stored on Supabase, in the same EU
(eu-west-1, Ireland) region as the App's own data, but in a separate
project from it. The Creator Program website itself runs on
Cloudflare's global network. Signing in and connecting accounts
involves Discord, TikTok and Meta (Instagram), under their own
developer terms — we have not entered into a separate, bespoke data
processing agreement with any of them beyond what those terms already
provide, and you should review their own privacy policies for what they
do, in turn, with the fact that you connected an account. If we email you about the Creator Program,
that email is sent through Brevo, which sees your email address and the
message content and nothing else about your account.
9.7 Your rights, and deleting your Creator Program data
The rights described in Section 5 apply here too. There is currently no in-app "delete my Creator Program account" option; email support@mogtier.app and we will delete your connected accounts, payout details, submissions, and audience recordings, except where we are required to keep payout records for our own accounting.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will
be reflected in a new version number here and in
docs/legal/CHANGELOG.md, and your continued use of the App after a
material change constitutes acceptance of the updated policy. Your
ConsentRecord stores the version you most recently accepted.
11. Contact
Questions about this policy or your data: support@mogtier.app.