How BeardStyles handles personal data and privacy choices
2026/08/17
This Privacy Policy explains how BeardStyles handles personal data when you use our website, accounts, beard-preview tools, payments, newsletters, and support. The public identity and contact for this service are BeardStyles and support@beardstyles.org.
We currently publish the brand and support contact rather than a personal name or street address. Some laws may require a controller or operator to provide more complete identity details. This is a known limitation of our present disclosure, so we do not claim that this policy satisfies every privacy law in every location. We will reassess the disclosure before intentionally offering the service in a market that requires more information.
Depending on what you choose to use, we process:
sign_up means a successful registration, login means a successful sign-in, begin_checkout means a Stripe Checkout Session was created successfully, and purchase means BeardStyles' internal payment record was confirmed as paid.localStorage.We receive data from you, your browser or device, the sign-in provider you select, payment and email providers, and the service systems involved in your request.
Depending on the event, the custom commerce-event properties BeardStyles adds are limited to the authentication method, stable product category and key, currency and value, one item, and—for purchase only—a random receipt transaction ID. BeardStyles does not add email, name, any BeardStyles internal user, session, or payment ID, any Stripe ID, image URL, callback URL, query, or hash as custom commerce properties. Refusal or consent-read failure means the event is omitted and not replayed after a later consent change. Stripe and internal payment records remain the revenue truth; Google Analytics is an incomplete sample limited to consenting users.
MediaPipe estimates facial landmarks and face shape in your browser. Its WebAssembly files are downloaded from jsDelivr and its model is downloaded from Google Storage. Those hosts receive ordinary network information such as IP address and request metadata, but these resource requests are not BeardStyles Analytics.
When you choose to upload a photo and request a beard preview, the photo is sent to storage on Cloudflare R2 and made available to Replicate for the requested generation. Generated results are returned to BeardStyles and stored in R2 so they can be displayed, downloaded, or saved as requested. Processing may occur outside your location. If you do not want this processing, do not upload a photo.
AI output is an appearance preview. It can vary with the photo, lighting, face shape, selected style, and model output, and it does not guarantee an actual grooming result. Face-shape estimates are not medical or professional grooming advice.
To the extent allowed by applicable law, we use data for these purposes and bases:
Where a different basis is required by the law that applies to you, we will use that basis or stop the affected processing. Whether photos or face-shape data require separate consent under a particular jurisdiction needs professional review before we claim compliance with that jurisdiction.
We disclose data only as needed for the purposes above:
support@beardstyles.org. We do not publish the private destination mailbox.We may also disclose the minimum necessary information to comply with law, protect users or the service, investigate abuse, or establish, exercise, or defend legal claims. We do not sell personal data or user photos.
The providers above may process data in countries or regions outside your location. The data, purpose, and transfer method depend on the feature: Cloudflare, Neon, Replicate, Upstash, Stripe, Resend, Google, GitHub, and jsDelivr receive data through encrypted network requests or provider integrations for delivery, storage, generation, authentication, payment, email, support, or optional Analytics.
Photo generation and other user-requested core functions use the providers needed to fulfill that request. Google Analytics is optional and remains off without consent. Google or GitHub sign-in and Stripe-hosted payment pages are contacted only when you initiate those features. Contact support@beardstyles.org to ask about an applicable transfer or privacy right. We do not promise that all data stays in one country.
We aim to keep data only for the following periods or for a shorter period when it is no longer needed:
| Data | Retention approach |
|---|---|
| Account profile, credits, and history | While the account is active, or until you delete the related item or account, subject to the exceptions below. |
| Temporary R2 uploads | About 1 day before Cloudflare R2 lifecycle deletion begins. Cloudflare commonly removes expired objects within about another 24 hours, but removal can take longer. |
| Saved images and avatars | Until you delete the image or account. |
| Replicate prediction inputs, outputs, files, and logs | About 1 hour under Replicate's API default; BeardStyles cannot guarantee the exact physical removal time. |
| Upstash generation-request cache | Up to about 30 days; other rate-limit data uses shorter expiry periods. |
| Newsletter and waitlist contacts | Until you unsubscribe, withdraw, or complete account deletion; Resend may retain provider records under its own policy. |
| Ordinary support, refund, complaint, and privacy mail | No more than 2 years after the last contact. |
| Sensitive attachments in support mail | Removed when the issue is resolved as soon as practicable, and no more than 30 days afterward, unless a reviewed legal hold applies. |
| BeardStyles minimum payment ledger | At least 10 years, measured from the later of the relevant payment record's latest update (including any later subscription-status or cancellation update) and the latest refund, dispute, or other payment adjustment. On account deletion it is disconnected from the user and limited to amount, currency, dates, status, and Stripe transaction/refund/dispute identifiers. It is not used for marketing or to rebuild a profile. |
| Stripe's independent records | As Stripe needs for legal, anti-fraud, tax, and dispute purposes; this may be longer than BeardStyles account retention. |
| Google Analytics user- and event-level data | 2 months. This setting does not control Google's standard aggregated reports. |
| Google Analytics browser identifier cookies | Up to 60 days from creation, configured not to renew on later visits; accessible copies are expired when you withdraw where practicable. |
| Analytics consent preference | 180 days for either allow or reject, unless a policy version change makes it expire earlier. |
| Local commerce Analytics receipts | A minimal local one-shot receipt prevents duplicate events. Every receipt is user-linked, so account deletion removes it. A purchase receipt can also be payment-linked; if that internal payment row is removed, its linked receipt is removed. A pending auth receipt can be claimed only within 30 minutes after the successful session starts. For resolved auth and purchase receipts, sensitive event-payload fields used to build the event are cleared. A session identifier can help match an auth receipt, but this does not mean deleting an individual session removes the dedupe row. These records are separate from Google Analytics retention. |
| Necessary operational logs and backups | The shortest actual period needed for service delivery, security, and recovery, subject to provider settings, contracts, and legal obligations. |
Expiry, deletion requests, and account deletion start the relevant removal process. Backups, provider systems, and lifecycle queues may require additional time, so we do not promise immediate physical deletion everywhere.
Depending on the law that applies to you, you may ask to access, correct, or delete personal data; receive information about processing; withdraw consent; object to or restrict some processing; obtain a portable copy where applicable; or complain to a competent privacy authority. These rights can have legal exceptions, including payment, fraud, security, dispute, and legal-hold records.
You can change Analytics through Cookie Settings in the footer. Withdrawal stops future optional measurement after the choice is applied; it does not affect earlier lawful processing. You can unsubscribe from marketing through the message link or by contacting support. Browser controls can clear cookies and local storage, but blocking necessary authentication or security storage may prevent some functions from working.
Send a request to support@beardstyles.org. Describe the account or data involved without sending unnecessary photos, payment-card details, passwords, or authentication tokens.
Self-service account deletion is currently unavailable while its production safety switch remains off. Support can receive and assess deletion requests at support@beardstyles.org, but the protected deletion operation cannot run while that switch remains off.
An incoming message's From address alone is insufficient to authorize deletion. The current application contains an authenticated email-token path for the signed-in account and an administrator path requiring the exact account email and an explicit DELETE. Both paths are unavailable while the production safety switch is off. We do not promise that support can execute deletion or that a particular future verification workflow will be available; if deletion becomes available, the authorization and safety gates then in effect must be satisfied.
When the operation is enabled and authorized, deletion removes or de-identifies account data, owned R2 images, user-level Upstash data, and the Resend contact through the coordinated process, provided no active subscription or open Checkout blocks the operation. The minimum payment ledger is disconnected from the account and retained as described above. Replicate, Stripe, email providers, backups, and lifecycle systems may retain limited data under their own technical or legal timelines.
Accounts and paid features are intended for people who are at least 18 years old and have reached the legal age to enter a contract where they live. General public content may still be viewed without an account. We do not ask for a birth date or use face analysis to estimate age.
If we learn that a minor submitted personal data contrary to this rule, we will stop the affected processing where practicable. The person or their parent or guardian may contact support@beardstyles.org to request deletion, subject to identity and authority verification.
We use access controls, scoped service credentials, encrypted network connections, ownership checks, rate limits, deletion locks, and restricted operational logging designed to reduce risk. No online service, transmission, or storage system can guarantee complete security. Please use a strong unique password, protect sign-in links and devices, and contact us if you suspect unauthorized access.
We may update this policy when the service, providers, practices, or legal requirements change. The date above shows the current version. We will post material changes prominently on the website and will email existing account holders only when a change materially affects their rights or when law requires it.
For privacy questions or requests, email support@beardstyles.org or use the Contact page. Please do not include unnecessary sensitive attachments.