※ privacy

The quiet of your
own record.

Last updated: 11 May 2026

Halia is a thirty-day skin-and-self ritual. This page explains, in plain language, what we collect, why, where it goes, and how to take it back.

If you read only one paragraph, read this one: your photos are sent to our AI partner only to create the reading, dossier, plan context, inspiration, outfit, wardrobe, and product analyses you request. We do not sell them, use them for ads, or opt them into model training. Your journal entries stay yours. You can delete everything from inside the app, no questions asked.

1. Who we are

Halia is published by the developer named in the App Store listing. Contact: hello@halia.app. For privacy questions: privacy@halia.app.

2. The data we collect

CategoryExamplesWhy
IdentifiersA Halia user id; your email if you sign up with oneSo we can tell whose readings are whose
Sign-in tokensApple or Google authentication subject handled through ClerkAuthentication only
Photos and uploadsThe three quiet portraits taken during a reading; inspiration, outfit, and wardrobe photos you choose to uploadThe AI reading, Beauty Dossier, wardrobe scan, inspiration reads, outfit checks, and product guidance (see §4)
Health dataLast night's sleep, read on-device onlyPre-fills your journal slider — never leaves your device
Journal textWhat you write in the evening reflectionStorage so you can read it later
Habit completionsThe toggles you tap on TodayStreak calculation
Subscription stateApple-issued transaction id, plan tierWhether the paywall should show
Device localeLanguage and timezone stringsEvening nudge timing
Crash diagnosticsStack traces, device model, OS versionBug fixes; opt-in only
First-party telemetryFunnel events such as "reading_revealed"Improving onboarding; never sold

We do not collect: contact lists, location, advertising id (IDFA), microphone, browsing history, third-party social profiles.

3. How we use it

To make Halia work — render readings, save your journal, schedule nudges. To honour your subscription — verify entitlements with Apple. To improve the app — anonymised funnel events tell us where people get stuck; crash data tells us what's broken.

We do not profile you, segment you for advertising, or build look-alike audiences. We do not run third-party analytics.

4. Face data

This section answers, in plain language, exactly what Halia does with photos of your face. Read it before you take your first reading.

What we collect. When you tap Begin reading, the app captures three still photographs of your face — a front pose, a slight-left pose, and a slight-right pose. You may also choose to upload further photos to optional surfaces (Inspiration, Outfit, Wardrobe, Product Match); these may also contain a face if you choose to point the camera at one. We collect images — we do not extract, store, or transmit any biometric template (face geometry, embeddings, eigenfaces, ArcFace-style descriptors). We do not perform face recognition or identity matching.

How we use it. The three reading photos are transmitted, over a TLS-encrypted connection, to our backend (Convex) and from there to Anthropic's Claude API. Claude returns qualitative, editorial guidance: a 0–10 composite score, six sub-scores (skin, symmetry, jawline, frame, eyes, posture), a tone signature, sub-tone, and — for paid users — a Beauty Dossier with hair, makeup, colour-season, and styling notes. The reading is qualitative and editorial; it is not a medical diagnosis, a biometric identity, a deepfake, or an objective attractiveness ranking.

Third parties. Photos pass through exactly two third parties, both for the analysis you requested:

· Convex — our backend host. Stores your photos at rest in encrypted US data centres until you delete your account.
· Anthropic (Claude API) — receives photos and prompts to produce the analysis. Anthropic's API does not train on your inputs or outputs by default, and Anthropic retains API content for up to thirty days before deletion (longer only for legal-hold or misuse investigations they document publicly).

Photos are not shared with advertisers, model training pipelines, data brokers, social platforms, or any other third party. We do not sell face data. We do not run face-recognition or face-matching services. We do not maintain a face database that could be queried by identity.

Where face data lives. Photos sit in Convex storage scoped to your user id. Each download URL is short-lived and signed; a leaked link expires automatically and cannot be browsed publicly. Convex runs in the United States.

Retention. Photos persist until one of three things happens:

1. You tap Delete account in Settings. We start a thirty- day soft-delete grace period (signing back in cancels it). After thirty days every photo, reading row, dossier, journal entry, and storage object tied to your account is hard-deleted.
2. You manually delete a specific reading from inside the app, which removes its photo storage objects immediately.
3. We prune readings that were started but never completed — see the "stale reading" cleanup cron — after twenty-four hours.

Anthropic's copy of the prompt content (which includes the photo bytes for the analysis call) is subject to Anthropic's API retention window, which is up to thirty days as of the date at the top of this policy.

5. Photos beyond face data (Wardrobe, Outfit, Inspiration, Product Match)

When you upload an outfit, wardrobe item, inspiration reference, or product photo, the same pipeline applies: the image travels over TLS to Convex, then to Anthropic for the analysis you requested. Anthropic returns structured guidance back to us. We do not opt these photos or prompts into model training. Anthropic states that API inputs and outputs are not used for model training by default and are deleted from its backend within thirty days except for misuse, legal, or contractual exceptions. These photos remain in your account on Convex storage until you delete your account or trigger a manual purge.

6. Children

Halia is rated 17+ and not intended for children under 13. We do not knowingly collect data from children under 13.

7. Your rights

You can at any time:

· Access — every screen of Halia is your data, surfaced.
· Export — write to privacy@halia.app; we'll send a machine-readable archive within thirty days.
· Correct — edit your journal or readings inside the app.
· Delete — Settings → Delete account. Thirty-day grace; signing back in cancels.
· Restrict / object — write to us; thirty-day response.

8. Where data lives

Convex (US) for account, readings, dossiers, journal, habits, photos, wardrobe audits, share cards, and utility results. Anthropic (US) for AI analysis and generation, with API content not opted into model training and subject to Anthropic's API retention policy. Apple, Google, and Clerk for authentication and StoreKit. Resend only for data exports or support messages. Sentry for opt-in crash reporting. We do not sell data.

9. Retention

Account + readings + dossiers + journal + photos + uploaded images until you delete; ninety days for crash diagnostics; thirty days for raw telemetry rows; seven years for subscription receipts (tax compliance). Deletion runs a thirty-day grace, then a hard purge.

10. Security

TLS 1.2+ in transit, encrypted at rest, Apple Sign-In tokens in the iOS keychain. Two engineers maximum have backend access; access is logged. Vulnerability reports: security@halia.app.

11. Cookies / trackers

None. Halia is not a web property.

12. Changes

We post a notice and email registered users at least seven days before any material change.

13. Contact

· hello@halia.app
· privacy@halia.app
· security@halia.app