LogoBeardStyles
  • Beard Styles
  • Face Shape Guide
  • Find Your Style
  • Pricing
  • Blog
LogoBeardStyles

Preview and compare beard styles with AI before you grow or trim

Email
Powered byLogoAI
Product
  • Beard Styles
  • FAQ
Resources
  • Blog
  • About
  • Contact
Beard Guides
  • Short Beard Styles
  • Medium Beard Styles
  • Long Beard Styles
  • Face Shape Guide
Popular Categories
  • Beard Styles for Bald Men
  • Black Men Beard Styles
  • Beard Styles for Older Men
  • Gray Beard Styles
  • Patchy Beard Styles
By Face Shape
  • Round Face Beard Styles
  • Oval Face Beard Styles
  • Square Face Beard Styles
  • Oblong Face Beard Styles
  • Heart Face Beard Styles
  • Diamond Face Beard Styles
Legal
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
© 2026 BeardStyles All Rights Reserved.

Privacy Policy

How BeardStyles handles personal data and privacy choices

2026/08/17

1. Who Is Responsible and How to Reach Us

This Privacy Policy explains how BeardStyles handles personal data when you use our website, accounts, beard-preview tools, payments, newsletters, and support. The public identity and contact for this service are BeardStyles and support@beardstyles.org.

We currently publish the brand and support contact rather than a personal name or street address. Some laws may require a controller or operator to provide more complete identity details. This is a known limitation of our present disclosure, so we do not claim that this policy satisfies every privacy law in every location. We will reassess the disclosure before intentionally offering the service in a market that requires more information.

2. Data We Collect

Depending on what you choose to use, we process:

  • Account and authentication data: name, email address, avatar, account and session identifiers, credential-verification records, and Google or GitHub account details returned during sign-in. Password credentials are handled through our authentication system rather than stored as readable passwords.
  • Photos and preview data: photos you select, browser-derived face landmarks and face-shape estimates, chosen beard style and settings, generation requests, generated images, saved-image history, and related technical status. Face-shape analysis is not identity recognition.
  • Payment and entitlement data: Stripe customer, Checkout, subscription, payment, refund, and dispute identifiers; amount, currency, status, dates, and credits or access attached to a purchase. BeardStyles does not receive full payment-card numbers from Stripe-hosted payment pages.
  • Communications: messages sent through Contact, support, refund, complaint, privacy, Newsletter, or waitlist channels, plus delivery and subscription status.
  • Technical and security data: IP address, request headers, browser/device category, requested path, timestamps, security and rate-limit signals, and restricted operational diagnostics needed to deliver and protect the service.
  • Optional Analytics data: only after you explicitly consent to optional Analytics, Google Analytics may receive a client identifier, browser/device category, an origin-and-path page location with query and hash removed, a similarly reduced referrer, and approved product events. The four commerce events have narrow meanings: sign_up means a successful registration, login means a successful sign-in, begin_checkout means a Stripe Checkout Session was created successfully, and purchase means BeardStyles' internal payment record was confirmed as paid.
  • Local preferences: authentication/session state, security state, language, theme, payment continuity, and your Analytics choice. The Analytics choice is stored in first-party localStorage.

We receive data from you, your browser or device, the sign-in provider you select, payment and email providers, and the service systems involved in your request.

Depending on the event, the custom commerce-event properties BeardStyles adds are limited to the authentication method, stable product category and key, currency and value, one item, and—for purchase only—a random receipt transaction ID. BeardStyles does not add email, name, any BeardStyles internal user, session, or payment ID, any Stripe ID, image URL, callback URL, query, or hash as custom commerce properties. Refusal or consent-read failure means the event is omitted and not replayed after a later consent change. Stripe and internal payment records remain the revenue truth; Google Analytics is an incomplete sample limited to consenting users.

3. Browser Analysis and Photo Flow

MediaPipe estimates facial landmarks and face shape in your browser. Its WebAssembly files are downloaded from jsDelivr and its model is downloaded from Google Storage. Those hosts receive ordinary network information such as IP address and request metadata, but these resource requests are not BeardStyles Analytics.

When you choose to upload a photo and request a beard preview, the photo is sent to storage on Cloudflare R2 and made available to Replicate for the requested generation. Generated results are returned to BeardStyles and stored in R2 so they can be displayed, downloaded, or saved as requested. Processing may occur outside your location. If you do not want this processing, do not upload a photo.

AI output is an appearance preview. It can vary with the photo, lighting, face shape, selected style, and model output, and it does not guarantee an actual grooming result. Face-shape estimates are not medical or professional grooming advice.

4. Why We Process Data and the Basis We Rely On

To the extent allowed by applicable law, we use data for these purposes and bases:

  • To create and secure accounts, authenticate users, provide requested browser analysis, generate or save previews, deliver purchases, and maintain payment access: processing needed to take steps you request or perform our contract with you.
  • To load Google Analytics and use non-essential browser storage: your explicit Analytics consent. Refusing or withdrawing it does not block core service features.
  • To send Newsletter, waitlist, or other marketing communications: your explicit request or consent. You may unsubscribe at any time.
  • To prevent abuse, apply rate limits, protect accounts, diagnose failures, and maintain service integrity: what is necessary to provide a secure service or our legitimate interests in doing so, without extending that purpose to marketing.
  • To keep the minimum payment ledger, handle refunds and disputes, respond to lawful requests, and establish, exercise, or defend legal claims: legal obligations and legal-claims needs.

Where a different basis is required by the law that applies to you, we will use that basis or stop the affected processing. Whether photos or face-shape data require separate consent under a particular jurisdiction needs professional review before we claim compliance with that jurisdiction.

5. Service Providers and Other Recipients

We disclose data only as needed for the purposes above:

  • Cloudflare: application delivery, CDN and security processing, necessary request logs, R2 photo/image storage, and Email Routing for the support address.
  • Neon: hosted PostgreSQL data for accounts, sessions, linked sign-in accounts, credits, generation history, payment status, and account-deletion coordination.
  • Replicate: photo inputs, prompts, prediction outputs, files, and technical logs needed to generate a requested preview.
  • Upstash: short-lived rate-limit data and generation-request status or result references.
  • Stripe: customer, Checkout, subscription, payment, refund, dispute, fraud-prevention, and billing-portal processing. Stripe independently handles payment details on its hosted pages.
  • Resend: Newsletter and waitlist contacts, and delivery of account, transactional, contact, and support-related email.
  • Cloudflare Email Routing and a Google mailbox: routing and handling messages sent to support@beardstyles.org. We do not publish the private destination mailbox.
  • Google and GitHub OAuth: identity and profile data needed when you actively choose that sign-in method.
  • jsDelivr and Google Storage: delivery of MediaPipe browser code and its face-landmark model when you use the relevant feature.
  • Google Analytics: optional measurement after consent, subject to the route and field restrictions described above. Ads consent, Google Signals, ad personalization, and User-ID are disabled.

We may also disclose the minimum necessary information to comply with law, protect users or the service, investigate abuse, or establish, exercise, or defend legal claims. We do not sell personal data or user photos.

6. International Processing

The providers above may process data in countries or regions outside your location. The data, purpose, and transfer method depend on the feature: Cloudflare, Neon, Replicate, Upstash, Stripe, Resend, Google, GitHub, and jsDelivr receive data through encrypted network requests or provider integrations for delivery, storage, generation, authentication, payment, email, support, or optional Analytics.

Photo generation and other user-requested core functions use the providers needed to fulfill that request. Google Analytics is optional and remains off without consent. Google or GitHub sign-in and Stripe-hosted payment pages are contacted only when you initiate those features. Contact support@beardstyles.org to ask about an applicable transfer or privacy right. We do not promise that all data stays in one country.

7. Retention

We aim to keep data only for the following periods or for a shorter period when it is no longer needed:

DataRetention approach
Account profile, credits, and historyWhile the account is active, or until you delete the related item or account, subject to the exceptions below.
Temporary R2 uploadsAbout 1 day before Cloudflare R2 lifecycle deletion begins. Cloudflare commonly removes expired objects within about another 24 hours, but removal can take longer.
Saved images and avatarsUntil you delete the image or account.
Replicate prediction inputs, outputs, files, and logsAbout 1 hour under Replicate's API default; BeardStyles cannot guarantee the exact physical removal time.
Upstash generation-request cacheUp to about 30 days; other rate-limit data uses shorter expiry periods.
Newsletter and waitlist contactsUntil you unsubscribe, withdraw, or complete account deletion; Resend may retain provider records under its own policy.
Ordinary support, refund, complaint, and privacy mailNo more than 2 years after the last contact.
Sensitive attachments in support mailRemoved when the issue is resolved as soon as practicable, and no more than 30 days afterward, unless a reviewed legal hold applies.
BeardStyles minimum payment ledgerAt least 10 years, measured from the later of the relevant payment record's latest update (including any later subscription-status or cancellation update) and the latest refund, dispute, or other payment adjustment. On account deletion it is disconnected from the user and limited to amount, currency, dates, status, and Stripe transaction/refund/dispute identifiers. It is not used for marketing or to rebuild a profile.
Stripe's independent recordsAs Stripe needs for legal, anti-fraud, tax, and dispute purposes; this may be longer than BeardStyles account retention.
Google Analytics user- and event-level data2 months. This setting does not control Google's standard aggregated reports.
Google Analytics browser identifier cookiesUp to 60 days from creation, configured not to renew on later visits; accessible copies are expired when you withdraw where practicable.
Analytics consent preference180 days for either allow or reject, unless a policy version change makes it expire earlier.
Local commerce Analytics receiptsA minimal local one-shot receipt prevents duplicate events. Every receipt is user-linked, so account deletion removes it. A purchase receipt can also be payment-linked; if that internal payment row is removed, its linked receipt is removed. A pending auth receipt can be claimed only within 30 minutes after the successful session starts. For resolved auth and purchase receipts, sensitive event-payload fields used to build the event are cleared. A session identifier can help match an auth receipt, but this does not mean deleting an individual session removes the dedupe row. These records are separate from Google Analytics retention.
Necessary operational logs and backupsThe shortest actual period needed for service delivery, security, and recovery, subject to provider settings, contracts, and legal obligations.

Expiry, deletion requests, and account deletion start the relevant removal process. Backups, provider systems, and lifecycle queues may require additional time, so we do not promise immediate physical deletion everywhere.

8. Your Choices and Requests

Depending on the law that applies to you, you may ask to access, correct, or delete personal data; receive information about processing; withdraw consent; object to or restrict some processing; obtain a portable copy where applicable; or complain to a competent privacy authority. These rights can have legal exceptions, including payment, fraud, security, dispute, and legal-hold records.

You can change Analytics through Cookie Settings in the footer. Withdrawal stops future optional measurement after the choice is applied; it does not affect earlier lawful processing. You can unsubscribe from marketing through the message link or by contacting support. Browser controls can clear cookies and local storage, but blocking necessary authentication or security storage may prevent some functions from working.

Send a request to support@beardstyles.org. Describe the account or data involved without sending unnecessary photos, payment-card details, passwords, or authentication tokens.

9. Account Deletion and Identity Verification

Self-service account deletion is currently unavailable while its production safety switch remains off. Support can receive and assess deletion requests at support@beardstyles.org, but the protected deletion operation cannot run while that switch remains off.

An incoming message's From address alone is insufficient to authorize deletion. The current application contains an authenticated email-token path for the signed-in account and an administrator path requiring the exact account email and an explicit DELETE. Both paths are unavailable while the production safety switch is off. We do not promise that support can execute deletion or that a particular future verification workflow will be available; if deletion becomes available, the authorization and safety gates then in effect must be satisfied.

When the operation is enabled and authorized, deletion removes or de-identifies account data, owned R2 images, user-level Upstash data, and the Resend contact through the coordinated process, provided no active subscription or open Checkout blocks the operation. The minimum payment ledger is disconnected from the account and retained as described above. Replicate, Stripe, email providers, backups, and lifecycle systems may retain limited data under their own technical or legal timelines.

10. Age Requirement

Accounts and paid features are intended for people who are at least 18 years old and have reached the legal age to enter a contract where they live. General public content may still be viewed without an account. We do not ask for a birth date or use face analysis to estimate age.

If we learn that a minor submitted personal data contrary to this rule, we will stop the affected processing where practicable. The person or their parent or guardian may contact support@beardstyles.org to request deletion, subject to identity and authority verification.

11. Security and Its Limits

We use access controls, scoped service credentials, encrypted network connections, ownership checks, rate limits, deletion locks, and restricted operational logging designed to reduce risk. No online service, transmission, or storage system can guarantee complete security. Please use a strong unique password, protect sign-in links and devices, and contact us if you suspect unauthorized access.

12. Changes to This Policy

We may update this policy when the service, providers, practices, or legal requirements change. The date above shows the current version. We will post material changes prominently on the website and will email existing account holders only when a change materially affects their rights or when law requires it.

13. Contact

For privacy questions or requests, email support@beardstyles.org or use the Contact page. Please do not include unnecessary sensitive attachments.