The short version. Your photos stay on your phone. Your notes — the areas you mark and what you call them, the small daily measurements, and your applied / skipped log — sync to our server in the EU. Never your photos. If you ask for a report, the app asks you again first: two cropped, normalized patches from each area you're watching are uploaded once for the write-up, and never stored. Withdrawing consent, exporting everything, and deleting everything are each one action away in settings. We show no ads and never sell your data. Usage analytics stays off unless you switch it on, and never includes your photos or your skin data.
1. Who we are
The data controller for Pentimento is:
Umut Aktaş (natural person, sole controller)
Utrecht, the Netherlands
Contact: privacy@usepentimento.com
The app is distributed via the Apple App Store and Google Play under developer accounts registered in Türkiye; the data controller is Umut Aktaş personally, and the store accounts are distribution channels that do not create a separate legal controller.
2. What Pentimento is — and isn't
Pentimento helps you see whether a product or routine is producing a change visible to your own eye, on your own face. It is cosmetic self-tracking, nothing more: it is not a medical device, it makes no diagnosis, gives no treatment or product advice, and assigns no absolute scores — only relative trends in your own photos, over time.
3. What stays on your phone
Your photos, with their capture details, are taken, stored, and measured on your device. In daily use, no photo ever leaves your phone. Your cycle record (the cycle phase you mark on a check-in) also stays on this phone only: it never syncs and never enters any AI prompt — reports that mention your cycle render that line on the device, from fixed wording. Saved reports are stored on your phone too. Deleting a photo removes the image for good; the day keeps its place in your record, and measurements already made stay — until you choose Delete everything.
4. What syncs to our server in the EU
Measurement happens on your phone; some of the results sync so your notes survive a lost or new phone. What syncs: the areas you mark and what you call them; the small daily measurements (numbers, never images); your applied / skipped log; your products and routine periods; your account identifier; and your consent record (which version you agreed to, and when). This data says something about your skin, which is why the law treats it as special-category data and why we only process it with your explicit consent (GDPR Art. 9(2)(a)). It is stored in the Netherlands (Google Cloud region europe-west4) — fixed from day one, never moved.
5. Reports ask again, every time
If you generate a report, two cropped, normalized patches from each area you're watching are needed for the write-up. The app tells you the exact count and asks you separately, before every report. The patches upload once, are used to ground the written text, and are never stored — regenerated only if you ask again. The written part of every report is AI-generated and labeled as such in the app (EU AI Act Art. 50): "the words in this report are ai-generated. the measurements and photos are yours." The trends themselves come from measurements made on your phone — not from the AI. We make no automated decisions about you with legal or similarly significant effects.
6. Usage analytics — only if you say yes
Separately from everything above, you can let the app count how you use it, so we can see what helps and fix what doesn't. It stays off unless you switch it on — with its own tick on the consent screen, in an occasional question in the app, or in settings — and the app works exactly the same without it. If you leave it off, the app may ask again now and then: never more than once every six months, never more than three times, and never after you switch it off in settings.
What is counted: that you opened the app (and whether from a reminder) and which screens you view; which setup, capture and review steps you finish or leave; which days you take a photo, and your streak; whether you set a reminder (never its time); that you answered a check-in, compared or deleted photos, exported your data, or gave or withdrew consent; that you saw the plans, and whether a purchase or sign-in went through (annual or monthly, never a price); once reports exist, whether you open or ask for one. Where a number helps, it is a count — how many concerns, products or photos, never which. Each event carries its time, the app version, and your phone's system (iOS or Android, and its major version).
What is never counted: your photos or your face; what your concerns, products or notes are; your cycle record; your measurements, trends or report text; your reminder time; your account, name or email; your location, country, time zone or IP address; your device model; advertising or push-notification identifiers.
Where it goes: to PostHog, stored in its EU region in Frankfurt, Germany (§8), under a random ID created on your phone — not your account, your email or your photos.
How long, and how to stop: each event is kept 12 months (§11). Switch analytics off in settings at any time: counting stops at once, and we ask PostHog to erase everything counted under your ID.
7. Why we're allowed (legal bases)
Everything in §§3–5 rests on your explicit consent (Arts. 6(1)(a) and 9(2)(a)) — the consent screen you accepted, versioned and re-readable in settings. Account and subscription mechanics rest on contract (Art. 6(1)(b)). We do no legitimate-interest processing of your content. Usage analytics (§6) rests on a separate consent of its own (Art. 6(1)(a)), asked apart from the one above; saying no, or switching it off later, costs you nothing.
8. Who processes data for us
Google (Firebase) — sign-in, database, and the AI service that writes report text; stored data in EU region europe-west4. Our AI features run on Google’s Gemini models through Firebase, pinned to Google’s Netherlands region (europe-west4), so the text we send is processed inside the EU. We never send your photos or your face to the AI. Google does not use this data to train its models; it may keep a short-lived copy for up to 90 days, in the same EU region, only to check for abuse of the service.
Apple App Store / Google Play — payment; we never see your card or bank details. RevenueCat — subscription status only (entitlement and transaction identifiers, no payment details). Subscription and purchase records are handled by RevenueCat, Inc. in the United States. That transfer is covered by the EU Standard Contractual Clauses (Module 2, controller to processor) in our data processing agreement with them. RevenueCat never receives your photos or your skin data.
When the app crashes or hits an error, we send a diagnostic report to Sentry so we can fix it. The report contains the technical error and stack trace, your device model, your operating system version and the app version. It never contains your photos, your face, your skin data, your email address or your IP address — we have turned off the setting that would attach personal identifiers. These reports are stored in Sentry’s EU region in Frankfurt, Germany (de.sentry.io), and are deleted after no longer than 90 days. We do this on the basis of our legitimate interest in keeping the app stable and secure (Article 6(1)(f) GDPR). You can object to this at any time — write to us and we’ll disable crash reporting for your account.
PostHog — usage analytics, only if you switch it on (§6). The events are stored in PostHog's EU region in Frankfurt, Germany, and we have set PostHog not to keep your IP address. PostHog, Inc. is a US company; where its staff or service providers outside the EU can reach the data, that transfer is covered by the EU Standard Contractual Clauses in our data processing agreement with PostHog, and PostHog participates in the EU–U.S. Data Privacy Framework. PostHog never receives your photos, your skin data, your account identifier or any payment details.
No advertising networks, no data brokers, no sale of data, ever. Your photos, your name and your email never appear in logs, analytics, or crash reports.
9. Your rights, and where each one lives
See it (Art. 15): everything the app holds is visible in the app; the export gives you a copy. Usage analytics is the exception: it sits with PostHog, not in the app. Your export's consent record carries the random ID it is stored under — write to us with it and we'll send you a copy.
Fix it (Art. 16): rename areas, edit products and notes directly in the app.
Take it with you (Art. 20): Export your data in settings assembles one bundle on your phone — nothing uploads: photos, measurements, concerns, products and periods, your applied / skipped record, your cycle record (the one thing that otherwise never leaves this phone), saved reports, and your consent record — machine-readable.
Delete it (Art. 17): Delete everything in settings wipes server first, then this phone, then the account itself. If the server can't be reached, nothing is deleted and the app says so plainly — it never pretends. If usage analytics is on, it also asks PostHog to erase it (up to a month).
Restrict it (Art. 18): withdrawing consent stops all new processing it covers (§10), and switching usage analytics off stops that too (§6); for anything narrower, contact us. If you correct or delete something, the change reaches our processors too (Art. 19).
Complain (Art. 77): Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl — though we'd welcome the chance to fix it first.
10. Withdrawing consent (Art. 7(3))
Withdrawing is as easy as consenting: one sheet in settings. One sentence is the whole rule: whatever creates or syncs new data stops; whatever lets you see, export, or delete what exists stays. Capture, measurement, check-ins, reminders, new reports: stop. Your archive, saved reports, export, delete: stay yours. Nothing is deleted unless you choose it. You can consent again anytime — same terms, no penalty. Your subscription is separate — manage it in the store. Usage analytics has its own switch (§6): withdrawing this consent doesn't change it.
11. How long we keep things
As long as you choose — your archive is the product, so nothing expires on a schedule. When you delete your account we remove your data from our live systems straight away. Copies can still sit in our encrypted backups and recovery snapshots for up to 30 days, all held in the Netherlands; we don’t use them for anything except restoring the service after a failure, and they’re overwritten on schedule. Report patches: never stored at all. Your consent record: kept while your account exists, as proof of what you agreed to. Deleting the app is not deleting your data — data on the phone goes with it, but synced data waits on the server until you delete it in-app first, or write to us. Usage analytics (§6): each event is kept 12 months, then deleted automatically. Switching analytics off, or Delete everything, asks PostHog to erase what was counted, and erasing finishes within a month; if your phone is offline at that moment, the request goes out as soon as it is back online. One catch: the events sit under a random ID that only your phone knows, so if you delete the app without switching analytics off first, we can't find them to erase early, and they expire on the 12-month schedule.
12. Subscriptions
Payment runs entirely through the App Store or Google Play. Withdrawing consent or deleting your data does not cancel a subscription — manage that in the store.
13. Age
Pentimento is not for anyone under 18. We don't knowingly process children's data; if you believe a child is using it, contact us.
14. Security
Data in transit is encrypted; server data is guarded by access rules tied to your account and app-integrity checks; on-device data sits behind your device's own protections. Above all we minimize what exists to protect: the most sensitive thing — your face — never leaves your phone in daily use.
15. Changes to this policy
This policy is versioned, like the consent text it mirrors. Material changes are announced in the app before they apply, and where the law requires it we ask for your consent again. Current version: v1.3 · september 2026.