Last updated: June 22, 2026
This Privacy Policy applies to SkinScan, an AI skin analysis app provided by MonoApps (the "Company"). We take your privacy seriously and comply with applicable laws (Korea PIPA, GDPR, Japan APPI, and others).
1. Purpose of Collection and Use
- Providing the AI skin analysis service (analyzing the skin condition in photos you take or select)
- Offering tailored information and product recommendations based on results
- Service stability analysis and daily usage-limit management
- Serving personalized ads (to operate the ad-supported free service)
- (With separate consent) Improving the AI model and analysis quality
2. Information We Collect
- Face photos: Images taken with the camera or chosen from the gallery for skin analysis. They are sent to the Company's server (api.monoapps.kr) for analysis.
- Analysis results: Outputs such as skin scores and skin type.
- Service identifier (device-id): An anonymous device identifier used for usage limits and service stability analysis. It is reset when the app is uninstalled and is not linked to information that directly identifies you (name, contact, etc.).
- Self-reported skin info: Skin type (e.g., sensitive skin) that you enter in Settings.
- Advertising identifier: IDFA on iOS or GAID on Android (for ad delivery).
- Purchase/billing info: Receipt data (transaction ID, product ID, purchase date) when you subscribe. Payment method details are handled by the App Store/Google Play billing systems; the Company does not access them.
3. How Face Photos Are Handled (Key Point)
Default principle — photos are not stored on our servers: Face photos sent for analysis are used only for processing and are discarded immediately after analysis completes. Unless you separately consent to AI training, photos are never written to any permanent server storage (database, file system, etc.). Only the analysis results are stored on your device.
- Transport protection: Photo uploads are protected with HTTPS (TLS) encryption.
- Local on-device storage: For your convenience, recent analyzed photos and results may be stored locally in the app's private sandbox. This data is not transmitted off the device, cannot be accessed by other apps, and is fully removed when you clear history in the app or uninstall it.
- No third-party sharing: Face photos are not provided to third parties; analysis takes place only on our own servers.
4. Data Use for AI Training (Optional · Opt-in)
To improve the skin-analysis AI model, the Company may use face photos for training only if you separately opt in within the app. You can fully use the analysis service without consenting.
- Scope: Only when you consent, your photo may be used to train and improve the AI model.
- De-identification: Training data is processed after removing identifiable information such as location (EXIF).
- Retention: Training data is retained for up to 730 days, then destroyed upon expiry or once the purpose is achieved.
- Withdrawal and deletion: You can withdraw consent and request deletion of server-side training data at any time via Settings > Delete Data (or by withdrawing training consent) in the app. After withdrawal, the data is no longer used for training. However, data already incorporated into a trained model may be technically difficult to separate and delete individually.
5. Advertising and Third-Party Services
The app serves ads through Google AdMob. For ad delivery, the advertising identifier (IDFA/GAID), device info (model, OS version), and ad impression/click data may be collected. See the Google Privacy Policy for details. You can limit ad tracking or reset your advertising identifier in device settings.
Subscriptions and in-app purchases are managed via RevenueCat, which may receive receipt data (transaction ID, product ID, purchase/expiry dates), an anonymous identifier for purchase restoration, and platform info (iOS/Android). RevenueCat does not process payment method details. See the RevenueCat Privacy Policy for details.
6. App Permissions
- Camera: Taking face photos for skin analysis
- Photos/Gallery: Loading an image to analyze
Permissions are active only when the relevant feature is used and can be revoked anytime in device settings. Revoking them may limit related features.
7. Data Security
- Encrypted communication: All communication with the server is protected with HTTPS (TLS).
- No-photo-retention principle: Unless you consent to training, photos are not stored on the server and are discarded right after analysis.
- Access restriction: On-device data is stored in the app's private sandbox and cannot be accessed by other apps.
8. Retention Periods
- Face photos for analysis (server): discarded right after analysis (not stored)
- Training data (if consented): up to 730 days
- Customer inquiry records: 1 year after resolution
- In-app stored data: stored only on the device and deleted when the app is uninstalled
9. Your Rights and How to Delete Data
You may request access, correction, deletion, and suspension of processing of your personal data. Data deletion is available as follows:
- In the app: Use Settings > Delete Data to directly request deletion of server-side data and withdraw training consent.
- By email: Contact [email protected] and we will act without delay.
10. Data Protection Contact
- Email: [email protected]
11. Changes to This Policy
This policy may be updated to reflect legal or service changes, and we will announce changes through the app or website.