سياسة الخصوصية
آخر تحديث: ٢٢ أغسطس ٢٠٢٦ · الإصدار v3
خصوصيتك مقدَّسة عند ONSTA. نلتزم بمعايير حماية البيانات وفق GDPR الأوروبي، وPDPL في السعودية والإمارات، وCCPA الأمريكي، بالإضافة لإرشادات Apple وGoogle.
GDPRCCPAPDPL
Apple 5.1.1Google Play
صورتك لا تُحفظتُحلَّل ثم تُحذف تلقائياً
تشفير كاملTLS أثناء النقل، وتشفير عند التخزين
الحق بالحذفمن داخل التطبيق
1. مقدمة ونطاق السياسة
من نحن وماذا تغطي هذه السياسة
- تطبيق ONSTA («التطبيق» أو «نحن») منصة رقمية للعناية بالبشرة والجمال تعتمد على الذكاء الاصطناعي لتحليل الوجه واليدين والجسم وتقديم توصيات جمالية شخصية.
- تشرح هذه السياسة كيف نجمع بياناتك الشخصية ونستخدمها ونحميها ونحذفها، عند استخدامك التطبيق عبر iOS وAndroid والويب.
- نلتزم بالأنظمة المعمول بها، وعلى وجه الخصوص: GDPR الأوروبي، وPDPL في السعودية والإمارات، وCCPA/CPRA في كاليفورنيا.
2. بيانات الوجه والصور البيومترية
الأهم — كيف نتعامل مع صور الفحص
الالتزام الأساسي: صور الوجه واليدين والجسم التي تلتقطها للفحص لا نحتفظ بها. تُرسل للتحليل الآمن ثم تُحذف من خوادمنا.
٢.١ ما بيانات الوجه التي نجمعها
يجمع ONSTA صورة ثابتة واحدة، تُلتقط داخل التطبيق من كاميرا جهازك عند ضغطك زرّ التصوير. وقد يلتقط التطبيق في الجلسة نفسها صورة قريبة إضافية لمنطقة العين. وهناك ميزات منفصلة وواضحة التسمية تلتقط صورة اليد أو الجسم.
نجمع هذه الصورة ولا شيء غيرها عن وجهك. وتحديداً، نحن لا:
- نُجري تعرّفاً على الوجه أو تحديداً لهوية صاحبه بأي شكل.
- نُنشئ قوالب بيومترية أو بصمات وجه أو تمثيلات رقمية للوجه.
- نستخرج معالم الوجه لأغراض تحديد الهوية.
- نستخدم بيانات الوجه للمصادقة أو تسجيل الدخول.
- نستعمل ARKit لتتبّع الوجه، ولا كاميرا TrueDepth، ولا Face ID. التطبيق يستعمل الكاميرا العادية وحدها.
لا توجد قاعدة بيانات وجوه نقارنك بها، ولا مسار في الشيفرة يقارن وجهاً بوجه.
٢.٢ كيف نستخدم بيانات الوجه
تُستخدم صورتك لغرض واحد فقط: إنتاج تحليل مظهرك التجميلي الخاص بك، ويُعرض عليك وحدك. ومنها نستخلص:
- تحليلاً للبشرة والشعر والجمال — نصوصاً وصفية ودرجات رقمية.
- تقديراً للعمر الظاهر ومؤشرات الحيوية الظاهرة.
- توصيات مخصّصة للعناية بالبشرة والمظهر.
- شخصية رمزية كرتونية (Memoji) — وهي رسم، لا صورتك.
- فحصاً إلزامياً لحماية القاصرين — انظر ٢.٦.
ولا تُستخدم بيانات الوجه أبداً للمصادقة، أو الإعلانات، أو التسويق، أو الاستهداف، أو التصنيف السلوكي، أو تدريب النماذج.
٢.٣ خدمات الذكاء الاصطناعي من أطراف ثالثة
لإجراء التحليل، تُرسَل الصورة مرة واحدة، عبر اتصال مشفَّر، إلى مزوّد ذكاء اصطناعي واحد:
- Google Gemini API (شركة Google LLC) — العنوان
generativelanguage.googleapis.com. يُجري تحليل البشرة والجمال ويُولّد الشخصية الرمزية. ونحن نستعمل الحصّة المدفوعة، وبموجب شروط Gemini API الإضافية فإنّ ذلك يعني أنّ Google «لا تستخدم مُدخلاتك (ومنها الملفّات كالصور والفيديو والمستندات) ولا مُخرجاتها لتحسين منتجاتها». وتعمل Google كمُعالِج لحسابنا بموجب شروط المعالجة الخاصة بها. وهي تُسجّل المُدخلات والمُخرجات لفترةٍ محدودة، لغرضٍ واحدٍ هو كشفُ إساءة استخدام الواجهة ومنعُها — لا لتدريب النماذج أبداً. ونقول ذلك بدل الادّعاء بأنّ لا شيء يُسجَّل، لأنّ شروطَهم المنشورة تقول خلافَه، ووعدٌ يناقضه مزوّدُنا نفسُه لا قيمةَ له.
وتُرسَل الصورة دون اسمك أو بريدك الإلكتروني أو معرّف حسابك. ولا يتلقّى صورتك أي مزوّد آخر — هذا هو الوحيد.
وللإفصاح الكامل: تستعمل منصّتنا أيضاً OpenAI, LLC في موضع واحد لا علاقة له بهذا — ترجمة نصوص قوائم الأعمال (أسماء المنشآت، التصنيفات، الإعلانات) لدليل الأنشطة الشريكة. وهي تتلقّى مقاطع نصية قصيرة عن الأنشطة فقط. ولا تُرسَل إليها أي صورة، ولا أي بيانات وجه، ولا أي بيانات شخصية خاصة بك، ولا دور لها في مسار تحليل الوجه إطلاقاً.
٢.٤ تخزين البيانات
- تعمل بنيتنا التحتية بالكامل على Amazon Web Services، في منطقة US East (us-east-1).
- تُكتب صورتك في Amazon S3 للدقائق التي تفصل بين الالتقاط والحذف. ونصف الآلية الحقيقية بدل الادّعاء بأنّ الصورة لا تلمس التخزين أصلاً، لأنّ هذا وعد يحقّ لك التحقق منه. وبدقّة: الوصول العام إلى الدلو محجوب، ومحتواه لا يقرؤه إلا شبكةُ التوزيع الخاصة بنا، ولا يُسرَد ولا يُفهرَس؛ والملف نفسه يُجلَب عبر HTTPS بمفتاح عشوائي طويل يُولَّد لكل فحص ولا يُنشَر في أي مكان. ونقول «غير قابل للسرد ولا للتخمين» بدل «خاص»، لأنّ الوصف الصادق لرابط توزيع ليس هو التحقّق من هويّة — وما يجعله آمناً أنّه يعيش دقائق، لا أنّه سرٌّ إلى الأبد.
- تُخزَّن نتائج التحليل والشخصية الرمزية في Amazon Aurora PostgreSQL، مشفَّرةً في حالة السكون.
- وكل ما ينتقل عبر الشبكة يمرّ عبر HTTPS/TLS وحده.
٢.٥ مدة الاحتفاظ
كيف يعمل الحذف بالضبط: بعد انتهاء التحليل، تُعلَّم الصورة للحذف وتزيلها مهمة تنظيف تعمل على خوادمنا كل خمس دقائق. فالمدة القصوى التي قد تبقى فيها صورة على خوادمنا هي دقائق معدودة، لا ثوانٍ. نذكر الرقم الحقيقي عمداً بدل عبارة أعمّ: هذا وعد يمكن التحقق منه، ونفضّل أن يكون دقيقاً.
نفس المهمة تحذف أيضاً الصور «اليتيمة» التي اختفى سجلّها من قاعدة البيانات، حتى لا يبقى ملف بلا صاحب.
- صورتك: خمس دقائق كحدّ أقصى على خوادمنا. فحدُّ الاحتفاظ وجدولُ التنظيف كلاهما خمس دقائق، وهذا يسري على كل فحص — الناجح والفاشل والمتروك في منتصفه والمرفوض بفحص حماية القاصرين على حدّ سواء.
- والحذف مضمون لا «قدر المستطاع»: إن فشل حذفٌ يوماً، يُكتَب سجلّ حذفٍ معلَّق ويُعاد المحاولة بفواصل متزايدة حتى يُتأكَّد من زوال الملف.
- نتائج التحليل (درجات الحيوية، المؤشرات، التوصيات): تُحفَظ ما دام حسابك نشطاً، أو حتى تحذف ذلك الفحص.
- الشخصية الرمزية (Memoji) — رسم كرتوني مُنتَج بالذكاء الاصطناعي وليست صورتك: تُحفَظ ما دام حسابك نشطاً.
- ولا نحتفظ بأيّ صورة لك إطلاقاً. الصورة المصغّرة التي كان يستعملها سجلّ فحوصاتك تُحذف في دورة الخمس دقائق نفسها التي تُحذف فيها الصورة الأصلية.
٢.٦ حماية القاصرين (دون ١٨)
ONSTA للراشدين في الثامنة عشرة أو أكثر، والحماية مُنفَّذة في المنتج لا موعودة هنا فقط:
- قبل تشغيل الكاميرا لأول مرة، يطلب التطبيق تأكيدك أنّك في الثامنة عشرة أو أكثر.
- إن حدّد التحليل أنّ الصورة لقاصر، يرفض الخادم الفحص رفضاً تاماً — فلا يُنتَج تقرير ولا تُولَّد شخصية رمزية.
- وطبقة تحقّق ثانية مستقلّة تضمن ألّا يظهر عمر دون ١٨ في أي تقرير، أيّاً كان ما يُعيده الذكاء الاصطناعي.
- وتُحذف الصورة المرفوضة في دورة الخمس دقائق نفسها، ولا يُعرَض ولا يُخزَّن شيء عن ذلك الفحص.
- وإن تبيّن لنا وجود حساب لمن هو دون ١٨ حذفناه فوراً. ويمكن لأحد الوالدين مراسلتنا على support@onsta.ai فنحذف الحساب خلال ٢٤ ساعة. انظر أيضاً القسم ١٠.
٢.٧ المشاركة مع أطراف ثالثة — وما لا نفعله أبداً
- لا نحتفظ بصورك على خوادمنا بعد التحليل، ولا نرفعها إلى iCloud.
- لا نشارك صورك مع المعلنين ولا وسطاء البيانات ولا أي طرف ثالث لأي غرض تسويقي.
- لا نبيع بياناتك البيومترية — أبداً.
- لا نستخدم صورك لتدريب نماذج ذكاء اصطناعي، ولا يحقّ لمزوّدنا ذلك.
٢.٨ حقوقك على بيانات وجهك
- موافقتك الصريحة أولاً. قبل تشغيل الكاميرا لأول مرة، يعرض التطبيق شاشة موافقة تصف كيف تُستخدم صورتك، وتخبرك أنّها تُحذف بعد التحليل، وتطلب تأكيدك أنّك في الثامنة عشرة أو أكثر. لا تُلتقط أي صورة قبل موافقتك، ونسجّل نوع الموافقة ونسختها وتاريخها كإثبات. والمزوّد الذي يتلقّى الصورة مذكورٌ بالاسم في ٢.٣ أعلاه.
- حذف فحص واحد من داخل التطبيق في أي وقت، فتُمحى نتائجه المخزَّنة.
- حذف حسابك بالكامل من داخل التطبيق: حسابي → الخصوصية والأمان → حذف الحساب. تؤكّد بكتابة بريدك الإلكتروني بنفسك. ويُحذَف كل ما يتعلق بالحساب فوراً، ولا نُبقي أي نسخة أرشيفية.
- وحقوقك في الوصول والتصحيح ونقل البيانات والاعتراض مبيَّنة كاملةً في القسم ٧.
3. البيانات التي نجمعها
قائمة تفصيلية وشفافة
أ) بيانات الحساب
- البريد الإلكتروني (لتسجيل الدخول والاسترداد).
- الاسم الكامل.
- رقم الهاتف (اختياري).
- كلمة المرور — تُخزَّن مُجزَّأة ولا يمكننا قراءتها.
- لغة الواجهة المفضّلة، وتاريخ الإنشاء وآخر نشاط.
ب) نتائج الفحوصات (لا الصور)
- درجة الحيوية والمؤشرات الجمالية.
- تقدير عمر البشرة الجمالي (استرشادي، ليس تشخيصاً طبياً).
- سجل التحسن والتوصيات المُقدَّمة.
- الجنس — يُستنتج من تحليل صورة الوجه، ولا نطلبه منك؛ يُستخدم لتخصيص التوصيات والمحتوى.
- الشخصيات الرمزية المُولَّدة للوجه واليد والجسم.
ج) بيانات تقنية
- نوع الجهاز ونظام التشغيل وإصدار التطبيق.
- عنوان IP — يُسجَّل كما هو في سجلّات الأمان والزيارات، ولا نُجهّله. يُستخدم لأمن الجلسة ومنع إساءة الاستخدام.
- الدولة والمنطقة — تُستنتج من عنوان IP بقاعدة بيانات محلية على خادمنا، دون إرسال عنوانك لطرف ثالث لهذا الغرض.
- رمز الجهاز للإشعارات، إن سمحت بها.
- أيام النشاط ونوع المنصّة، لإحصاءات مجمّعة.
د) بيانات أخرى تنتج عن استخدامك
- تتبّع شرب الماء — أهدافك اليومية والكميات المسجّلة.
- تذاكر الدعم — الرسائل التي ترسلها لفريق الدعم.
- سجلّ الموافقات — نوع الموافقة ونسختها وتاريخها.
- حالة الاشتراك — بدون أي بيانات بطاقة.
نطبّق مبدأ تقليل البيانات: نجمع أقل قدر ممكن يحقق الخدمة.
4. كيف نستخدم بياناتك
أغراض محددة وشرعية فقط
- تقديم الخدمة: تشغيل التحليلات وعرض النتائج والتوصيات.
- تحسين تجربتك: تخصيص الروتين بناءً على تاريخ فحوصاتك.
- الأمان: اكتشاف محاولات الدخول غير المصرَّح بها وحماية حسابك.
- الدعم الفني: الرد على استفساراتك وحل المشكلات.
- التزامات قانونية: فقط عند تلقي أمر قضائي صريح من جهة مختصة.
لن نستخدم بياناتك أبداً في: الإعلانات المستهدفة، أو بيعها لأطراف ثالثة، أو تدريب نماذج ذكاء اصطناعي عامة.
5. الأطراف الثالثة الموثوقة
من نتعامل معهم، وماذا يصلهم بالضبط
| الجهة | الغرض | ما يصلها |
| Google — Gemini | تحليل صور الفحص وتوليد الشخصية الرمزية | صورة الفحص وقت المعالجة فقط |
| Amazon Web Services | الاستضافة وقاعدة البيانات والتخزين والبريد والإشعارات | كل البيانات المخزَّنة، مشفَّرة |
| Stripe | معالجة الدفع والاشتراكات على الويب | بيانات الدفع وبريدك الإلكتروني |
| Apple (App Store) | بيع اشتراكات التطبيق على iPhone واستلام الدفع | تتم عملية الشراء عبر حساب Apple الخاص بك. لا تصلنا بيانات بطاقتك إطلاقاً — البائع هو Apple، ولا نراها في أي مرحلة |
| RevenueCat | إدارة اشتراكات التطبيق وتأكيد عمليات الشراء التي تتم على iPhone | معرّف حسابك لدينا وسجلّ اشتراكك — دون أي بيانات دفع |
| Sentry | تسجيل الأعطال والأخطاء التقنية | تفاصيل الخطأ التقني ومسار الطلب. نمرّر كل تقرير عبر مُنقٍّ يحذف الصور والرموز وكلمات المرور وعناوين IP قبل الإرسال |
| WeatherAPI.com | حالة الطقس ودرجة الحرارة لحساب هدف شرب الماء | عنوان IP الخاص بك، لتحديد المدينة |
| Apple / Google | إيصال الإشعارات لجهازك | رمز الجهاز ونص الإشعار |
حماية مكافئة — مع استثناءين نسمّيهما بدل أن نطمسهما: كل جهة في الجدول أعلاه، عدا WeatherAPI.com و Apple، تعالج بياناتك بصفتها معالِجاً يعمل بتعليماتنا، وبموجب شروط معالجة بيانات تُلزمها بمستوى حماية لا يقل عمّا تتعهد به هذه السياسة: تحديد الغرض، والسرية، وتدابير أمان مناسبة، وعدم استخدام بياناتك لأغراضها الخاصة. ولا يجوز لأيٍّ منها بيع بياناتك أو استخدامها لتدريب نماذج ذكاء اصطناعي عامة. وحيثما تعبر البيانات حدوداً دولية نعتمد الشروط التعاقدية القياسية (SCCs) — التفاصيل في البند 11.
أما WeatherAPI.com فهي الاستثناء. يصلها شيء واحد — عنوان IP الخاص بك — لغرض واحد: تحديد مدينتك كي يأخذ هدف شرب الماء درجة الحرارة عندك بالحسبان. وهي تعمل بموجب شروطها المنشورة، لا باتفاقية معالجة بيانات معنا. نذكر هذا صراحةً بدل ادعاءٍ شامل، لأن الادعاء الشامل هو الذي لا يصمد أمام من يتحقق.
و Apple هي الاستثناء الثاني، لسبب مختلف. عند الاشتراك من داخل تطبيق iPhone تكون Apple هي البائع: تستلم الدفع بموجب سياستها واتفاقها معك، لا بتعليماتنا — فهي متحكِّم مستقل في تلك المعاملة، لا معالِج يعمل لحسابنا. وما يعنيه ذلك لك ملموس: لا نرى بيانات بطاقتك ولا نخزّنها في أي مرحلة، ويمكن إلغاء الاشتراك أو استرداده من إعدادات Apple دون المرور بنا. أمّا RevenueCat، الذي يخبرنا فقط ما إذا كان اشتراكك فعّالاً، فهو معالِج يعمل بتعليماتنا وتشمله الفقرة الأولى أعلاه.
ملاحظة عن Sentry: نستخدمه لاكتشاف الأعطال التقنية. لأن طلبات هذا التطبيق قد تحمل صور فحص، بنينا مُنقّياً يفحص كل تقرير قبل مغادرته: يحذف الصور بالحجم والشكل، والرموز والمفاتيح وكلمات المرور بالاسم، وعناوين IP والإحداثيات بشكل القيمة نفسها — لا بالاسم فقط. ولا نُرفق هوية المستخدم بأي تقرير.
6. مدة الاحتفاظ بالبيانات
كم من الوقت نحتفظ بمعلوماتك
- صور الفحص: تُحذف بعد التحليل ضمن دورة تنظيف كل خمس دقائق (البند 2).
- نتائج الفحوصات: تبقى في حسابك حتى تحذفها أو تحذف حسابك — لأنها أساس مقارنة تطوّرك.
- بيانات الحساب: طوال فترة نشاط الحساب. عند حذف الحساب تُحذف فوراً وبشكل متسلسل، ولا نحتفظ بأرشيف بعدها.
- بيانات الاستخدام المجمّعة: تُقلَّم بعد نحو ١٥ شهراً.
- سجلّات التدقيق الإدارية: تُحفظ دون حدّ زمني، لأنها سجلّ لما فعله المسؤولون. عند حذف حسابك يُفصل السجلّ عن هويتك.
- بيانات الفواتير: يحتفظ بها Stripe — أو Apple إن تم الشراء من داخل تطبيق iPhone — وفق التزاماتهما الضريبية والقانونية.
7. حقوقك القانونية
أنت المتحكِّم دائماً
- حق الوصول: طلب نسخة من بياناتك، عبر مراسلتنا.
- حق التصحيح: تعديل بياناتك من داخل التطبيق.
- حق الحذف (النسيان): حذف حسابك وكل بياناته نهائياً من داخل التطبيق عبر «الإعدادات ← الخصوصية ← حذف الحساب».
- حق النقل: يتيح لك التطبيق تصدير البيانات المحفوظة على جهازك بصيغة JSON. أما نسخة كاملة من بيانات حسابك على خوادمنا فتُطلَب بمراسلتنا ونجهّزها لك.
- حق الاعتراض: إيقاف أي معالجة تعتقد أنها غير مبرَّرة.
- حق سحب الموافقة: إلغاء إذن الكاميرا أو الإشعارات في أي وقت من إعدادات جهازك.
لممارسة أي حق: راسلنا على support@onsta.ai أو استخدم قسم «الخصوصية والأمان» داخل التطبيق. نلتزم بالرد خلال ٣٠ يوماً.
8. الأمان والتشفير
كيف نحمي بياناتك تقنياً
- نقل البيانات عبر HTTPS/TLS حصراً.
- تخزين البيانات مشفَّراً على بنية Amazon Web Services، وملفات التخزين خاصة وغير متاحة للعامة.
- كلمات المرور مُجزَّأة بـ bcrypt — لا نراها أبداً ولا يمكن استرجاعها.
- مصادقة عبر رموز JWT قصيرة الصلاحية مع تجديد آمن.
- حدّ لمحاولات الدخول الفاشلة، وقفل مؤقت للحساب عند تجاوزه.
- تسجيل تدقيق لكل وصول إداري إلى بيانات المستخدمين.
- تنقية تقارير الأعطال قبل إرسالها لأي طرف خارجي (البند 5).
في حال اكتشاف خرق أمني يمسّ بياناتك الشخصية، سنُبلغك وسنُبلغ الجهة التنظيمية المختصة دون تأخير غير مبرَّر، وفق ما تفرضه GDPR وPDPL.
9. البيانات الصحية والحدود
التطبيق ليس بديلاً عن الطبيب
تنبيه مهم: جميع تحليلات ONSTA — بما فيها تقدير عمر البشرة ومؤشرات الحيوية وتوصيات الروتين — مؤشرات جمالية استرشادية عامة، وليست تشخيصاً طبياً ولا بديلاً عن استشارة طبيب جلدية.
نلتزم بإرشادات Apple 5.1.3 للبيانات الصحية:
- لا نستخدم أي بيانات صحية للإعلانات أو التسويق.
- لا نخزِّن معلومات صحية شخصية على iCloud.
- لا ندّعي أن التطبيق جهاز طبي معتمد من FDA أو أي جهة تنظيمية.
- في أي حالة تتطلب استشارة طبية، نُحيلك دائماً إلى مختص.
10. الأطفال والقاصرون
حماية خاصة للفئات الحساسة
ONSTA مخصص للبالغين ١٨ سنة فأكثر. لا نجمع بيانات من أي قاصر عن قصد.
- قبل فتح الكاميرا، يسألك التطبيق صراحةً إن كنت ١٨ سنة فأكثر.
- إذا رصد التحليل أن الصورة لقاصر، يرفض الخادم الفحص ولا يُنتج تقريراً ولا شخصية رمزية.
- نلتزم بقانون COPPA الأمريكي.
- إذا اكتشفنا حساباً لمستخدم دون ١٨، نحذفه فوراً.
إذا كنت وليَّ أمر واكتشفت أن طفلك يستخدم التطبيق، راسلنا على support@onsta.ai وسنحذف الحساب خلال ٢٤ ساعة.
11. النقل الدولي للبيانات
أين تُخزَّن بياناتك جغرافياً
تُخزَّن بياناتك على بنية Amazon Web Services في منطقة شرق الولايات المتحدة (us-east-1). نذكر ذلك صراحةً لأنه يعني أن بياناتك تُعالَج خارج بلدك على الأرجح، وهي معلومة يحق لك معرفتها.
عند نقل البيانات دولياً — وهو ما يحدث في الاستضافة نفسها وفي معالجة الذكاء الاصطناعي — نعتمد على:
- Standard Contractual Clauses (SCCs) المعتمدة من المفوضية الأوروبية.
- اتفاقيات معالجة بيانات (DPA) مع مزوّدي الخدمة.
12. التغييرات على هذه السياسة
كيف نُبلغك بالتحديثات
قد نُحدِّث هذه السياسة لتعكس تغييرات في القانون أو في التطبيق. في هذه الحالة:
- نُحدِّث تاريخ «آخر تحديث» ورقم الإصدار أعلى الصفحة.
- عند أي تغيير جوهري، نعرض عليك النسخة الجديدة داخل التطبيق ونطلب موافقتك عليها قبل المتابعة.
- لأي تغيير يتعلق بمشاركة البيانات، نطلب موافقتك الصريحة من جديد.
التواصل
البريد: support@onsta.ai
الموقع: https://onsta.ai
Privacy Policy
Last updated: 22 August 2026 · Version v3
Your privacy is sacred at ONSTA. We uphold data-protection standards under GDPR (EU), PDPL (KSA/UAE) and CCPA (US), and comply with Apple App Store and Google Play policies.
GDPRCCPAPDPL
Apple 5.1.1Google Play
Your photo isn't keptAnalyzed, then deleted automatically
Full encryptionTLS in transit, encrypted at rest
Right to deleteFrom within the app
1. Introduction & Scope
Who we are and what this policy covers
- ONSTA ("the App", "we", "us") is a digital beauty and wellness platform that uses artificial intelligence to analyze the face, hands and body and deliver personalized beauty recommendations.
- This policy explains how we collect, use, protect and delete your personal data when you use ONSTA across iOS, Android and web.
- We comply with applicable regulations, in particular the EU General Data Protection Regulation (GDPR), the KSA/UAE Personal Data Protection Law (PDPL), and the California Consumer Privacy Act (CCPA/CPRA).
2. Facial & Biometric Data
The most important section — how we handle your scan photos
Core commitment: the face, hand and body photos you capture for scanning are not retained. They are sent for secure analysis and then deleted from our servers.
2.1 What face data we collect
ONSTA collects a single still photograph, captured inside the app from your device camera when you tap the shutter. In the same session the app may capture one additional close-up still of the eye area. Separate, clearly-labelled features capture a hand photo or a body photo.
We collect this photograph and nothing else about your face. Specifically, we do not:
- Perform facial recognition or identification of any kind.
- Create biometric templates, faceprints, or facial embeddings.
- Extract facial landmarks for identity purposes.
- Use face data for authentication or sign-in.
- Use ARKit face tracking, the TrueDepth camera, or Face ID. The app uses the ordinary camera only.
There is no face database to match you against, and no code path that compares one face to another.
2.2 How we use face data
Your photograph is used for exactly one purpose: producing your own cosmetic-appearance analysis, shown only to you. From it we derive:
- A skin, hair and beauty analysis — descriptive text and numeric scores.
- A perceived-age estimate and apparent-vitality indicators.
- Personalised skincare and grooming recommendations.
- A stylized cartoon avatar (a "Memoji"-style illustration, not your photograph).
- A mandatory child-safety check — see 2.6.
Face data is never used for authentication, advertising, marketing, targeting, profiling, or model training.
2.3 Third-party AI services
To perform the analysis, the photograph is transmitted once, over an encrypted channel, to one third-party AI provider:
- Google Gemini API (Google LLC) — endpoint
generativelanguage.googleapis.com. It performs the skin and beauty analysis and generates the cartoon avatar. We use the paid quota, and under the Gemini API Additional Terms of Service that means Google "doesn't use your prompts (including … files such as images, videos, or documents) or responses to improve our products". Google acts as our processor under its data processing terms. It does log prompts and responses for a limited period, solely to detect and prevent abuse of the API — never to train models. We say so rather than claim nothing is logged at all, because their published terms say otherwise and a promise contradicted by our own provider is worth nothing.
The image is sent without your name, e-mail address or account identifier. No other provider receives your photograph — this is the only one.
For completeness: our platform also uses OpenAI, LLC in one unrelated place — translating business-listing text (venue names, categories, announcements) for the partner-business directory. It receives short pieces of business copy only. No photograph, no face data and no personal data of yours is ever sent to OpenAI, and it takes no part in the face-analysis pipeline.
2.4 Data storage
- All our infrastructure runs on Amazon Web Services, region US East (us-east-1).
- Your photograph is written to Amazon S3 for the minutes between capture and deletion. We describe the real mechanism rather than claiming the image never touches storage, because this is a promise you are entitled to check. Precisely: public access to the bucket is blocked and its contents are readable only by our own content-delivery distribution, never listable and never indexed; the object itself is reached over HTTPS at a long random key that is not published anywhere and is generated per scan. We say "not listable and unguessable" rather than "private", because the honest description of a delivery URL is not the same as a credential check — and the reason it is safe is that it exists for minutes, not that it is secret forever.
- Analysis results and the cartoon avatar are stored in Amazon Aurora PostgreSQL, encrypted at rest.
- Everything in transit travels over HTTPS/TLS only.
2.5 Data retention
Exactly how the deletion works: once analysis finishes, the image is marked for removal and a cleanup job running on our servers every five minutes deletes it. So the longest an image can sit on our servers is a matter of minutes, not seconds. We state the real number deliberately instead of a vaguer phrase: this is a verifiable promise, and it should be accurate.
The same job also removes orphaned images whose database record is already gone, so no file is left without an owner.
- Your photograph: at most five minutes on our servers. The retention limit and the cleanup schedule are both five minutes, and this applies to every scan — completed, failed, abandoned part-way, and refused by the child-safety check alike.
- Deletion is durable, not best-effort: if a delete ever fails, a pending-deletion record is written and retried with increasing delays until the file is confirmed gone.
- Analysis results (vitality scores, indicators, recommendations): kept while your account is active, or until you delete that scan.
- The generated Memoji — an AI-drawn cartoon character, not your photograph: kept while your account is active.
- No image of you is kept at all. The small thumbnail your scan history once used is deleted in the same five-minute cycle as the photo itself.
2.6 Minor protection (under 18)
ONSTA is for adults aged 18 or over, and the protection is enforced in the product, not only promised here:
- Before the camera opens for the first time, the app asks you to confirm you are 18 or older.
- If the analysis determines the image is of a minor, the server refuses the scan outright — no report is produced and no avatar is generated.
- A second, independent check guarantees that no age below 18 can ever appear in any report, whatever the AI returns.
- The refused image is deleted by the same five-minute cycle, and nothing about the scan is shown or stored as a result.
- If we discover an under-18 account, we delete it immediately. A parent can e-mail support@onsta.ai and we delete the account within 24 hours. See also section 10.
2.7 Sharing with third parties — what we never do
- We do not keep your photos on our servers after analysis, and we do not upload them to iCloud.
- We do not share your photos with advertisers, data brokers, or any third party for marketing.
- We do not sell biometric data — ever.
- We do not use your photos to train AI models, and neither may our provider.
2.8 Your rights over your face data
- Explicit consent first. Before the camera opens for the first time, the app presents a consent screen describing how your photo is used, telling you it is deleted after analysis, and asking you to confirm you are 18 or older. No image is captured before you agree, and we record the type, version and date of that consent as evidence. The provider that receives the photo is named in 2.3 above.
- Delete a single scan from inside the app at any time; its stored results are erased.
- Delete your whole account from inside the app: Profile → Privacy & Security → Delete Account. You confirm by typing your own e-mail address. Everything associated with the account is deleted immediately, and we keep no archive.
- Your access, correction, portability and objection rights are set out in full in section 7.
3. Data We Collect
A detailed, transparent inventory
a) Account data
- Email address (for sign-in and recovery).
- Full name.
- Phone number (optional).
- Password — stored hashed; we cannot read it.
- Preferred language, creation date and last activity.
b) Scan results (never photos)
- Vitality Score and cosmetic indicators.
- Cosmetic skin-age estimate (advisory only, not medical).
- Progress history and the recommendations delivered.
- Gender — inferred from the face-scan analysis, not asked of you; used to personalize recommendations and content.
- Generated Memoji avatars for face, hand and body.
c) Technical data
- Device model, OS and app version.
- IP address — recorded in full in our security and visit logs; we do not anonymize it. Used for session security and abuse prevention.
- Country and region — derived from your IP using a local database on our own server, without sending your address to a third party for this purpose.
- Push notification device token, if you allow notifications.
- Active days and platform, for aggregate statistics.
d) Other data your use produces
- Water tracking — your daily goals and logged intake.
- Support tickets — messages you send our support team.
- Consent records — the type, version and date of each acceptance.
- Subscription status — with no card data of any kind.
We apply the principle of data minimization: we collect the least possible to deliver the service.
4. How We Use Your Data
Specific, lawful purposes only
- Providing the service: running AI analyses and displaying results and recommendations.
- Improving your experience: personalizing your routine based on scan history.
- Security: detecting unauthorized access and protecting your account.
- Support: responding to your inquiries and resolving issues.
- Legal obligations: only on receiving a valid order from a competent authority.
We will never use your data for: targeted advertising, selling to third parties, or training public AI models.
5. Trusted Third Parties
Who we work with, and exactly what reaches them
| Provider | Purpose | What they receive |
| Google — Gemini | Analyzing scan images and generating avatars | The scan image, at processing time only |
| Amazon Web Services | Hosting, database, storage, email, push delivery | All stored data, encrypted |
| Stripe | Payment and subscription processing on the web | Payment details and your email address |
| Apple (App Store) | Selling app subscriptions on iPhone, and taking the payment | The purchase is made through your Apple ID. Your card details never reach us — Apple is the seller, and we are not shown them at any point |
| RevenueCat | Managing app subscriptions and confirming purchases made on iPhone | Your account identifier with us, and your subscription history — no payment details |
| Sentry | Crash and error reporting | Technical error details and the request path. Every report passes through a scrubber that strips images, tokens, passwords and IP addresses before it is sent |
| WeatherAPI.com | Weather and temperature, used to calculate your hydration goal | Your IP address, to resolve your city |
| Apple / Google | Delivering notifications to your device | Device token and notification text |
Equal protection — with two exceptions we would rather name than paper over: every provider in the table above except WeatherAPI.com and Apple processes your data as a processor acting on our instructions, under data processing terms binding it to a standard of protection no lower than this policy promises: purpose limitation, confidentiality, appropriate security measures, and no use of your data for its own purposes. None of them may sell your data or use it to train general-purpose AI models. Where data crosses an international border we rely on Standard Contractual Clauses — see section 11.
WeatherAPI.com is the exception. It receives one item — your IP address — for one purpose: resolving your city so your hydration goal can account for the local temperature. It operates under its own published terms rather than a data processing agreement with us. We state this rather than making a blanket claim, because a blanket claim is the kind that does not survive being checked.
Apple is the second exception, for a different reason. When you subscribe inside the iPhone app, Apple is the seller of record: it takes the payment under its own privacy policy and its own agreement with you, not on our instructions — so for that transaction it is an independent controller, not a processor acting for us. What that means for you is concrete: we never see or store your card details at any point, and the subscription can be cancelled or refunded from your Apple settings without going through us. RevenueCat, which only tells us whether your subscription is active, is a processor acting on our instructions and is covered by the first paragraph above.
A note on Sentry: we use it to detect technical faults. Because requests in this app can carry scan images, we built a scrubber that inspects every report before it leaves: it removes images by size and shape, tokens, keys and passwords by name, and IP addresses and coordinates by the shape of the value itself — not by field name alone. We also attach no user identity to any report.
6. Data Retention
How long we keep your information
- Scan photos: deleted after analysis by a cleanup cycle that runs every five minutes (section 2).
- Scan results: kept in your account until you delete them or delete your account — they are the basis for comparing your progress.
- Account data: for the lifetime of the account. On deletion it is cascade-deleted immediately, and we keep no archive afterwards.
- Aggregate usage data: trimmed after roughly 15 months.
- Administrative audit logs: kept without a time limit, because they are the record of what administrators did. When your account is deleted, the log entry is detached from your identity.
- Billing records: held by Stripe — or, for a purchase made inside the iPhone app, by Apple — under their own tax and legal obligations.
7. Your Legal Rights
You are always in control
- Right of access: request a copy of your data by contacting us.
- Right to rectify: correct your details from within the app.
- Right to erasure (be forgotten): permanently delete your account and all its data from within the app via "Settings → Privacy → Delete Account".
- Right to portability: the app lets you export the data held on your device as JSON. For a full copy of your server-side account data, contact us and we will prepare it for you.
- Right to object: stop any processing you consider unjustified.
- Right to withdraw consent: revoke camera or notification permissions at any time from your device settings.
To exercise any right: email support@onsta.ai or use the "Privacy & Security" section inside the app. We respond within 30 days.
8. Security & Encryption
How we protect your data technically
- Data in transit over HTTPS/TLS only.
- Data at rest encrypted on Amazon Web Services infrastructure, with private, non-public file storage.
- Passwords hashed with bcrypt — we never see them and they cannot be recovered.
- Authentication via short-lived JWT tokens with a secure refresh flow.
- Failed sign-in attempts are capped, with a temporary account lock beyond the threshold.
- An audit log of every administrative access to user data.
- Crash reports scrubbed before they reach any external provider (section 5).
If we discover a security breach affecting your personal data, we will notify you and the competent supervisory authority without undue delay, as GDPR and PDPL require.
9. Health Data & Boundaries
ONSTA is not a substitute for a doctor
Important notice: all ONSTA analyses — including the cosmetic skin-age estimate, vitality indicators and routine recommendations — are general cosmetic guidance, not a medical diagnosis and not a substitute for consulting a dermatologist.
We comply with Apple's Guideline 5.1.3 for health data:
- We do not use any health data for advertising or marketing.
- We do not store personal health information on iCloud.
- We do not claim to be an FDA-approved or otherwise regulated medical device.
- For any condition requiring medical consultation, we always refer you to a qualified professional.
10. Children & Minors
Special protection for vulnerable groups
ONSTA is intended for adults aged 18 or older. We do not knowingly collect data from any minor.
- Before the camera opens, the app explicitly asks whether you are 18 or older.
- If the analysis detects that the image is of a minor, the server refuses the scan and produces no report and no avatar.
- We comply with the US COPPA.
- If we discover an under-18 user has created an account, we delete it immediately.
If you are a parent and discover your child using the app, email us at support@onsta.ai and we will delete the account within 24 hours.
11. International Data Transfers
Where your data is stored geographically
Your data is stored on Amazon Web Services infrastructure in the US East (us-east-1) region. We state this plainly because it means your data is most likely processed outside your own country, and that is something you are entitled to know.
Where international transfer occurs — which it does in the hosting itself and in AI processing — we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Data Processing Agreements (DPAs) with our service providers.
12. Changes to This Policy
How we notify you of updates
We may update this policy to reflect changes in law or in the app. When we do:
- We update the "Last updated" date and version number at the top of this page.
- For any material change, we present the new version inside the app and ask you to accept it before continuing.
- For any change to data sharing, we ask for your explicit consent again.
Contact
Email: support@onsta.ai
Website: https://onsta.ai