Privacy Policy

Last updated: January 30, 2026

At ADONIC, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our facial analysis service. By using ADONIC, you agree to the practices described in this policy.

Consent & Legal Bases

Before using our service, you must explicitly consent to this Privacy Policy and the Terms of Service . Your consent is required before payment or account creation.

Consent:You must provide explicit consent to this Privacy Policy and Terms of Service before making a payment or creating an account. By using our service, you consent to our data processing practices.
Performance of Contract:We process your data to fulfill our contractual obligations - providing you with facial analysis results and service delivery.
Legitimate Interests:We process data for security monitoring, fraud prevention, service improvements, and business operations, provided your rights and freedoms are not overridden.

Legal Compliance: We process personal data in accordance with GDPR, CCPA, and other applicable data protection laws. Our processing is based on your consent, performance of our contractual obligations to provide services, and our legitimate interests in security, fraud prevention, and service improvement.

Data Collection

We collect only the information necessary to provide our facial analysis service:

  • Photos:Front and side facial photos you upload for analysis.
  • Demographics:Age, ethnicity, and gender details you provide to improve analysis accuracy.
  • Email:Your email address (collected via Stripe) to deliver your analysis results.
  • Payment Information:Payment details are processed by Stripe. We never store your card information on our servers.
  • Device & IP Information:IP address, device type, browser information, and approximate location for security and analytics.
  • Usage Logs:Service interactions, timestamps, and session data for troubleshooting and improvement.
  • Cookies:Essential cookies for session management, authentication, and optional analytics cookies to improve our service.

Photo Storage

120-Day Retention Period

Your photos are securely stored for 120 days from the date of your analysis. This allows you to access your results and track progress over time.

Automatic Deletion

After the 120-day retention period, your photos and associated analysis data are automatically and permanently deleted from our servers. No manual action is required.

Early Deletion Requests

You may request early deletion of your data at any time by contacting us at support@adonic.app. We will process your request within 48 hours.

Data Usage

Your privacy is our priority. We have strict policies about how your data is used:

Never Shared:Your photos and personal data are never shared with third parties for marketing purposes.
Never Sold:We never sell your personal information to anyone, period.
No AI Training:Your photos are never used to train AI models or machine learning systems.

We use your data exclusively for:

  • Generating your personalized facial analysis report
  • Delivering your results via email
  • Processing your payment securely
  • Providing customer support when requested

Data Retention Periods

We retain your data only for as long as necessary. Here are our data retention periods:

Photos

120 days

Automatically deleted after 120 days from analysis date. Early deletion available on request.

Analysis Results

120 days

Your facial analysis scores, reports, and recommendations remain accessible for 120 days.

Personal Information

Until account deletion

Email, demographics, and account preferences retained until you delete your account or request erasure.

Payment Records

7 years

Transaction records retained per legal and tax requirements. Payment card data never stored.

Usage Logs

90 days (anonymized)

Retained for 90 days, then anonymized and used only for aggregate analytics.

Security Measures

We implement industry-standard security measures to protect your personal information:

Encryption in Transit

All data is transmitted using TLS 1.3 encryption protocols.

Encryption at Rest

Stored data is encrypted using AES-256 encryption standards.

Access Controls

Multi-factor authentication, role-based access, and least-privilege principles.

Security Audits

Regular security assessments and penetration testing.

Incident Response

Documented procedures for detecting and responding to security incidents.

PCI DSS Level 1 Certification: Our payment processing is conducted through Stripe, which is PCI DSS Level 1 certified, ensuring the highest standard of security for payment card data.

AI Processing & Decision-Making

How AI Analysis Works

ADONIC uses AI-powered algorithms to analyze facial features and generate personalized reports. This automated decision-making process provides informational assessments and recommendations.

Nature of Service

Non-medical and informational only - not a diagnostic or medical tool.

Data Used

Your uploaded photos and optional demographic information.

Human Review

Individual analyses are not reviewed by humans. However, you may request human review of your results.

Your Rights: You have the right to contest automated decisions and request alternative assessment methods.

To request human review or contest an automated decision, contact us at support@adonic.app with subject "AI Decision Contest".

Third-Party Services

We work with trusted third-party services to provide our facial analysis. Each service processes data according to its own privacy policy and terms of use. We encourage you to review these policies for more details.

Face++

Facial image analysis (face detection, landmark recognition)

Purpose:Primary facial feature detection and analysis
Provider:Facial image analysis (face detection, landmark recognition)
Data Retention:Face++ does not retain images for AI model training. Processed facial data is stored temporarily for analysis completion.

Anthropic Claude

AI text analysis and report generation

Purpose:Generates written analysis content and recommendations based on facial data
Provider:AI text analysis and report generation
Data Retention:Anthropic does not train models on user data submitted via API. Data is processed ephemerally and not retained for model improvement.

OpenAI

AI-powered analysis

Purpose:AI-powered analysis and scoring for legacy workflows
Provider:AI-powered analysis
Data Retention:OpenAI does not train models on customer API data by default. Data handling follows OpenAI privacy policy.

Google Gemini

AI image generation for visualizations

Purpose:Generates personalized visual guides and enhancement previews
Provider:AI image generation for visualizations
Data Retention:Google may retain processed data according to their privacy policy. Images are not used to train Gemini models.

Stripe

Secure payment processing

Purpose:Secure payment processing, fraud detection, and PCI compliance
Provider:Secure payment processing
Data Retention:Stripe retains transaction data for legal and compliance purposes per their privacy policy. Payment card data is tokenized and never stored by ADONIC.
We share your billing name, email, and payment token with Stripe. Stripe works with financial partners for processing and fraud prevention.

Supabase

Secure data storage

Purpose:Secure data storage for user accounts, analysis results, and temporary photo uploads
Provider:Secure data storage
Data Retention:Database records retained according to our 120-day retention policy. User account data retained until account deletion.

We carefully evaluate third-party services and only use those that meet our strict privacy and security standards.

Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights regarding your personal data:

Right to Access

Request a complete copy of all personal data we hold about you. Email support@adonic.app with subject "Data Access Request".

Right to Rectification

Request correction of inaccurate or incomplete data. Email support@adonic.app with details of the correction needed.

Right to Erasure

Request permanent deletion of your personal data, photos, and analysis results. Processed within 48 hours.

Right to Data Portability

Receive your data in a structured, commonly used format (JSON or CSV) for transfer to another service.

Right to Restriction

Request limitation on how we process your data, such as disabling certain features while retaining core service access.

Right to Object

Object to certain types of data processing, such as marketing communications or specific data uses.

Right to Non-Discrimination

Receive equal service regardless of your privacy choices. We will not discriminate for exercising your rights.

Right to Contest AI Decisions

Request human review of AI-generated analysis results or opt out of automated processing.

For EU residents (GDPR): You have additional rights including the right to data portability and the right to lodge a complaint with a supervisory authority.

For California residents (CCPA): You have the right to know what personal information we collect and to request deletion. We do not sell your personal information.

Contact Us

If you have any questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle your data, please contact us:

We aim to respond to all privacy-related inquiries within 48 hours.