# Rhea Privacy Notice Version: `privacy-2026-08-25` Effective date: `25 August 2026` This Notice explains how **Rhea Skin Routine AI**, **Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom** (**Rhea**, **we**) processes personal data in the Rhea Skin App and related services. It is intended to satisfy transparent-notice requirements, including Türkiye's Personal Data Protection Law No. 6698 (**KVKK**) and, where applicable, the EU/EEA General Data Protection Regulation (**GDPR**). Territory-specific annexes may supplement it. ## 1. Controller and contacts Data controller: **Rhea Skin Routine AI**<br> Address: **Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom**<br> Privacy requests: `rhea@rheaskin.com`<br> EEA representative, if required: `Contact details will be published here if legally required` Data Protection Officer, if appointed: `For data-protection requests: rhea@rheaskin.com` ## 2. Scope and important product limits Rhea is for adults and provides cosmetic skincare and wellness organization and education, not diagnosis or medical treatment. Do not submit medical records or information that the feature does not request. Some profile answers or analysis results may nevertheless be treated as sensitive or special-category data in some territories depending on their content; where law requires it, we request a separate valid condition such as explicit consent rather than relying on this Notice as consent. Rhea does not perform face recognition, create biometric identity templates, infer ethnicity, emotion, attractiveness or health status from a face, or make solely automated decisions producing legal or similarly significant effects. ## 3. Data we process, purposes and legal grounds The final legal ground must be confirmed for every launch territory. The table describes the intended baseline; consent is never bundled with a purpose that can reasonably rely on another ground. | Data category | Examples | Specific purposes | Intended legal ground | | --- | --- | --- | --- | | Account and authentication | email, provider subject identifier, one-time-code/security evidence, session/device records | create and secure the account; authenticate; prevent takeover; re-authenticate sensitive actions | contract/service necessity; legitimate interests in security; legal obligation where applicable | | Registration and profile | name, full date of birth, age/age band, gender answer, unverified phone, language, timezone | enforce the 18+ gate; personalize requested features; maintain account settings and support | contract/service necessity; legal obligation for eligibility where applicable; consent where a field is legally sensitive | | Skin/wellness preferences | goals, concerns, sensitivities, allergies entered for cosmetic use, routine preferences | configure routines; provide compatibility warnings and requested cosmetic explanations | contract/service necessity; explicit consent where required for sensitive/special-category content | | Routines, inventory and activity | products, steps, schedules, completion/skip events, notes | sync and play routines; provide history, offline reconciliation and reminders | contract/service necessity | | Temporary images | selected face image for analysis; shelf/package/barcode image; technical validation metadata | perform the analysis/recognition requested; validate uploads; prevent abuse | contract/service necessity and explicit consent where required; legitimate security interests for validation | | Structured analysis | cosmetic appearance observations, confidence, version, correction/feedback | show and reopen a result; track user-requested cosmetic changes; validate quality and safety | contract/service necessity; explicit consent where required | | Device-only content | raw face/journal photos and local comparison history | provide an on-device journal and comparisons | stored by the app on your device; server processing occurs only when you deliberately select a temporary upload feature | | Product/catalog contributions | GTIN, proposed product facts, package evidence, source links, review/moderation state | identify products; review and enrich the catalog; prevent false or duplicate facts | contract/service necessity; legitimate interests in catalog quality and fraud prevention | | Subscription and entitlement | store transaction/event identifiers, plan/status, renewal/refund/revocation evidence, entitlement ledger | verify purchase; provide Premium; restore and reconcile access; accounting and disputes | contract/service necessity; legal obligation; legitimate interests in fraud prevention/records | | Notifications | device/push identifier, locale/timezone, category preference, delivery result | deliver requested routine reminders, security/service messages and separately opted-in marketing | contract/service necessity for requested/service messages; consent for marketing messages | | Support/community | ticket content, correspondence, review/comment/report, moderation and appeal records | answer requests; moderate content; enforce rules; protect users | contract/service necessity; legitimate interests; legal claims/obligations where applicable | | Security and operations | IP/network metadata, request ID, timestamp, coarse device/app version, allowlisted error and audit events | detect abuse; protect availability; troubleshoot; audit privileged actions; recover service | legitimate interests in security/reliability; legal obligation | | Product analytics | pseudonymous Rhea identifier and allowlisted feature events | understand aggregate feature reliability and adoption without advertising profiles | legitimate interests subject to balancing and opt-out/consent where required | | Marketing choices | channel choices, consent text/version/locale/time/source, withdrawal evidence | prove and respect your optional communication choice | consent; legal obligation to retain evidence | We do not intentionally send names, email, phone, birth date, gender/profile answers, images, user notes, review drafts, AI prompts or AI outputs to product analytics. V1 has no session replay and no cross-app advertising tracking. ## 4. How data is collected We collect data directly from you when you register, configure the profile, create routines, upload a selected image, contact support or choose communication settings; automatically from the app and systems when needed for security, synchronization, diagnostics or transactions; and from Apple, Google, RevenueCat or another provider when they verify authentication, purchases, refunds or subscription status. Catalog sources and sellers may provide public product data with recorded provenance. When KVKK requires notice for data obtained from another source, we provide it within the legally required period or at first communication/disclosure, subject to lawful exceptions. ## 5. Photos and AI processing Raw face-analysis and optional journal photos persist only on your device by design. When you explicitly request cloud analysis, a selected image is stripped of unnecessary metadata where feasible, validated, encrypted in transit and uploaded with opaque access. It is deleted immediately after terminal processing and a cleanup sweep must remove it no later than one hour after upload. Shelf/package evidence follows the same temporary principle unless a separate catalog contribution screen clearly asks you to retain/publish it. Structured cosmetic results may be stored in your account. Raw photos must not appear in CMS, analytics, logs or error monitoring. We do not use images or sensitive prompts for advertising, identity recognition or provider/model training. A future reuse purpose would require a new specific choice and legal review. AI requests pass through Rhea's server gateway. Providers receive only the minimum data needed for the selected operation, under contractual/security restrictions. Outputs are schema-validated; provenance, confidence and model/prompt version may be retained without logging sensitive prompt content. ## 6. Recipients and processors Access is limited by role and purpose. Data may be disclosed to: - cloud database/authentication/storage and European VPS/backup providers; - email, push-notification, authentication and customer-support providers; - Apple, Google and RevenueCat for purchases and entitlement reconciliation; - controlled AI providers for an operation you request; - pseudonymous analytics and scrubbed error-monitoring providers; - professional advisers, auditors and authorities where legally required; - a successor in a lawful corporate transaction, with appropriate notice and safeguards. The publication-ready notice must link to `public subprocessor register to be published before processing begins`, listing legal provider names, role, data categories, processing countries and safeguards. We do not sell personal data. We do not share it for third-party cross-context behavioral advertising. ## 7. International transfers The primary database and initial hosting are designed for Europe, but provider support, authentication, app stores, notifications, AI or corporate systems may involve processing outside Türkiye or the EEA. Before launch, each transfer must be documented and supported by the mechanism required in the relevant territory: an adequacy decision, KVKK-approved appropriate safeguard/standard contract, GDPR standard contractual clauses and supplementary measures, binding corporate rules, or a narrowly applicable statutory derogation. Where a KVKK standard contract is used, the responsible party must complete any required regulator notification within the legal deadline. Contact `rhea@rheaskin.com` for information or an available copy of safeguards, with confidential terms redacted. ## 8. Retention We keep data only as long as necessary for its stated purpose, security and legal obligations. Engineering defaults—subject to counsel approval and territorial law—are: | Record | Default maximum/trigger | | --- | --- | | temporary analysis/shelf upload | immediate terminal deletion; failsafe no later than 1 hour | | device-only photos | controlled by you and the device/OS lifecycle | | OTP/security abuse evidence | 30 days | | application logs | 30 days hot; restricted security evidence up to 90 days | | scrubbed error monitoring | 30 days | | pseudonymous product analytics | no more than 13 months | | raw webhook payload | 7 days; normalized transaction evidence as legally required | | idempotency result | 180 days | | generated export archive | 7 days | | deletion anti-resurrection tombstone | 180 days, pseudonymous | | encrypted database backups | daily copies for 35 days; deletion replayed after restore | | account/profile/routines | active account life, then deletion workflow and lawful exceptions | | consent/audit/subscription/financial evidence | minimum period required for proof, disputes, tax/accounting and fraud prevention | We delete, anonymize or restrict data when the period ends. Backup deletion may occur through bounded expiry rather than immediate rewriting; deletion tombstones prevent restored data from reopening an account. ## 9. Security Measures include encryption in transit, protected secret/session storage, least-privilege access, row/ownership checks, mandatory MFA for administrators, signed short-lived private-file access, upload validation, audit logs, rate limits, provider isolation, encrypted backups and recovery tests. No system is risk-free. We will assess incidents and notify users/regulators within applicable legal timeframes where required. ## 10. Your choices and rights Depending on applicable law, you may request to: - learn whether and how we process your data and obtain a copy; - correct incomplete or inaccurate data; - delete, destroy or anonymize data, and notify recipients where required; - restrict or object to processing, including direct marketing; - receive portable data where applicable; - withdraw consent at any time without affecting earlier lawful processing; - obtain information about automated processing and contest a qualifying decision; - claim compensation for unlawful processing where the law permits; - complain to the Turkish Personal Data Protection Authority, your EEA supervisory authority or another competent regulator. Use the in-app controls or contact `rhea@rheaskin.com`. We may verify identity and recent account control before fulfilling a request. We respond within the applicable deadline and explain any lawful refusal or fee. Marketing can be withdrawn independently; security, transaction and requested routine messages are managed separately. Account deletion has a seven-day cancellable safety window in the current engineering design and targets completion within 30 days after confirmation, subject to legal retention and bounded backup expiry. Deleting the account does not cancel an Apple/Google subscription. ## 11. Children Rhea V1 is limited to adults aged 18 or older. We do not knowingly provide accounts to children. If you believe a minor has submitted data, contact `rhea@rheaskin.com`; we will investigate and delete/restrict it as required. ## 12. Changes and language We may update this Notice when processing, providers or law changes. We show the effective date and immutable version and provide proportionate notice. Material new purposes or consent-dependent processing require the legally appropriate new notice/choice. `Mandatory local consumer and data-protection rules remain unaffected.`. Questions or complaints may be sent to `rhea@rheaskin.com` or **Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom** using the subject “Privacy Request.”