baselit. ← back

Privacy Policy

Version 1.4 · July 1, 2026

This policy explains what data Baselit processes, on what legal basis, and what rights you have. Baselit is operated from Germany, so this policy follows the EU General Data Protection Regulation (GDPR / DSGVO) and German law. We keep it plain on purpose.

1. Who is responsible

Marco Mori
Birkachstraße 3
88131 Lindau (Bodensee)
Germany
Email: hello@baselit.app · Phone: +49 171 2931804

A Data Protection Officer is not yet legally required at our current size (single operator, no large-scale processing of special-category data, Art. 37 GDPR). We review this as we grow.

2. What we collect and why

2.1 Hosting & server logs

When you open this site, our hosting provider automatically stores standard technical data your browser sends: browser type/version, operating system, referrer URL, hostname, time of the request, and IP address (shortened where technically possible).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, stable website). Retention: max. 30 days, then automatic deletion. Provider: Vercel Inc., Covina, CA, USA, under an Art. 28 GDPR data processing agreement incl. EU Standard Contractual Clauses (see §5).

2.2 Waitlist signup (email address)

If you join the waitlist, we collect only your email address.

Purpose: to notify you about the app launch and relevant Baselit updates. Legal basis: Art. 6(1)(a) GDPR (your explicit, voluntary consent, given by entering your email and clicking the button; no pre-ticked boxes). Retention: until you withdraw, or at the latest 12 months after launch.

Withdrawal: you can withdraw consent any time with future effect, via email to hello@baselit.app (subject "unsubscribe") or the unsubscribe link in every email. Withdrawal does not affect the lawfulness of prior processing.

Processor: email delivery and support communication for the waitlist and transactional messages is handled via Zoho Mail (hello@baselit.app). The contracting entity is Zoho Corporation B.V., Amsterdam, Netherlands (EU); where data is processed in EU datacentres, no third-country transfer occurs. If routing through non-EU infrastructure applies, an Art. 28 GDPR data processing agreement incl. EU Standard Contractual Clauses is in place.

2.3 No cookies, no tracking (landing phase)

This landing page sets no tracking cookies and runs no web-analytics tool. We build no usage profiles. If we ever add privacy-friendly, cookie-free analytics, we will update this policy first.

3. The Baselit app

This section describes processing inside the Baselit app. If you only visit this website, it does not apply to you.

3.1 Skin analysis (selfie processing)

You can take a photo of your skin for AI-based skin scoring. Core design decision: the original photo is never stored on our servers. The flow is:

photo (in memory) → normalise → AI analysis → score numbers (0–100) → photo discarded

The selfie is transmitted transiently to the AI provider for analysis and discarded immediately after the score is computed. It is never written to our database or storage, and we keep no face embeddings or feature vectors. We store only the numeric score, the five axis values, the timestamp and your history. These pure numbers are not biometric data under Art. 9 GDPR, as no person can be identified from them (cf. EDPB Guidelines 05/2022).

Photo timeline: if you use the optional photo timeline, those photos are stored only locally on your device. They are never uploaded to our servers. Deleting the app deletes them. Alignment overlay: to help you line up a consistent before and after, an earlier scan photo of yours may be shown as a faint, semi-transparent overlay on your device while you take a new scan. This overlay is rendered locally and the photo never leaves your device.

Third-country transfer: the photo is sent to a US vision API (Anthropic Claude Vision) for analysis. An Art. 28 data processing agreement incl. EU Standard Contractual Clauses is in place; your photo data is not used to train AI models (contractually fixed); no personal identifiers (name, account ID) are sent in the API call (data minimisation, Art. 5(1)(c) GDPR). Legal basis: Art. 6(1)(b) GDPR (performance of the core service).

3.2 Account, history, sensitivity, payments

  • Account: email + hashed password (Art. 6(1)(b), kept until account deletion).
  • Score history: numeric scores + timestamps for progress tracking (Art. 6(1)(b)).
  • Onboarding sensitivity: optional inputs on skin sensitivities (e.g. allergies, pregnancy) may count as health data under Art. 9 GDPR. We ask for separate explicit consent (Art. 9(2)(a)); it is fully optional and the app works without it.
  • Subscription/payment: handled solely via the Apple App Store / Google Play. We never receive card data.

3.3 Skin Coach (chat)

The app includes an AI chat coach for skincare questions. When you send a message, the following is transmitted to generate the reply:

  • Chat content: your messages and the previous turns of the current conversation.
  • Score context: your current score numbers (overall score and the five axis values). Never your photo.
  • Onboarding profile (optional): skin type, skin concerns and your routine focus, plus the voluntary health-related inputs you may have given during onboarding (pregnancy/breastfeeding, skin sensitivity). These are sent so the coach can avoid unsafe recommendations, e.g. retinoids during pregnancy.

Recipient: the request is relayed through our backend to Anthropic PBC (USA), which runs the language model that generates the reply. An Art. 28 data processing agreement incl. EU Standard Contractual Clauses is in place, and Anthropic does not use API data to train its models (contractually fixed).

Storage: we do not store your chat content on our servers. Your chat history lives only locally on your device. Server-side we keep only a numeric usage counter (messages per day/month, no content) to enforce fair-use limits; error logs contain no conversation content.

Legal basis: Art. 6(1)(b) GDPR (performance of the service) for chat content and score context. For the voluntary health-related inputs (pregnancy/breastfeeding, sensitivity), which may constitute health data under Art. 9 GDPR: your explicit consent, Art. 9(2)(a) GDPR, given during onboarding. These inputs are optional; the coach works without them, and you can withdraw consent at any time by removing them from your profile or deleting your account.

3.4 Product analytics (PostHog)

To understand how the app is used and to improve it, we use PostHog, a product-analytics service. Only events we have explicitly defined are recorded: there is no automatic capture, no session recording, and no advertising or cross-app tracking. The events are: start of onboarding, completion of the first scan, opening the paywall, purchase or restoration of a subscription, completion of a re-scan, and sending a message to the Skin Coach.

Each event carries a random, installation-specific identifier generated on your device on first launch. It is not linked to your account, email, name, skin data or scores, and we do not use it to identify you as an individual. We send no names, email addresses, health data, skin photos or scores to PostHog. The app sends every event with GeoIP lookup disabled, so PostHog derives no location from your IP, and IP addresses are discarded server-side before storage (no IP is stored).

Recipient / third-country transfer: PostHog Inc. (USA). An Art. 28 GDPR data processing agreement incl. EU Standard Contractual Clauses is in place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the product); given the anonymous ID, the IP anonymisation, the absence of special-category data and the narrow event scope, our interest prevails. Retention: we set no custom period; the events remain in PostHog for the duration of its platform data-retention policy. As they carry no IP and only a random ID, they cannot be linked back to you, and you can stop collection at any time (see §7).

Object / opt-out: because the identifier is tied only to the app installation, not to your account or any directly identifying data, we do not profile you as an individual. You can object at any time by uninstalling the app, which removes the identifier on your device and stops all further collection; for any other data request, contact hello@baselit.app. More info: posthog.com/privacy.

3.5 Subscription management (RevenueCat)

To manage in-app subscriptions and entitlements, we use RevenueCat, a subscription infrastructure service. When you purchase or restore a subscription, the RevenueCat SDK processes an app-specific user identifier (a random ID generated on your device) together with your purchase and entitlement status as received from the Apple App Store.

We do not send your name, email address, skin data or scores to RevenueCat. RevenueCat receives only the purchase event data provided by the App Store and the app-specific identifier necessary to link the entitlement to your account.

Recipient / third-country transfer: RevenueCat, Inc., USA. An Art. 28 GDPR data processing agreement incl. EU Standard Contractual Clauses is in place. Legal basis: Art. 6(1)(b) GDPR (performance of the contract, i.e. provision of the paid service). More info: revenuecat.com/privacy.

3.6 Abuse prevention (device identifier)

Your first skin analysis is free. To enforce this single free scan per device and prevent abuse (e.g. repeatedly deleting and re-creating an account to obtain unlimited free AI analyses, each of which has a real processing cost), we process Apple's Identifier for Vendor (IDFV). This is a device-level identifier that Apple provides and that is shared only across our own apps — never across other developers' apps. It is not the advertising identifier (IDFA).

The IDFV is used solely to count the free scan against your device; it is stored with that claim in our backend (Supabase). We do not use it for advertising, cross-app tracking, or profiling, so it requires no App Tracking Transparency consent. If you delete your account, the link between this device marker and your account is removed — the identifier is then retained only as an anonymous "this device used its free scan" marker with no personal reference, so the free-scan limit cannot be bypassed by re-creating accounts. Recipient: Supabase (see §4). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing fraud and abuse of the free service).

3.7 Marketing attribution (AppsFlyer)

To understand which marketing campaigns lead to app installs and in-app purchases, we use AppsFlyer, a mobile attribution service. This helps us allocate our marketing budget effectively and improve campaign quality.

Method (SKAdNetwork-only, no IDFA): Baselit uses AppsFlyer exclusively via Apple's privacy-preserving attribution framework SKAdNetwork / AdAttributionKit. We do not request or process the Advertising Identifier (IDFA). Attribution data is aggregated and anonymised by Apple before it reaches us; no App Tracking Transparency (ATT) prompt is triggered. We receive no data that identifies you as an individual.

The following data categories are processed: pseudonymous device and usage events (e.g. app open, scan started, paywall viewed, subscription purchased), aggregated campaign attribution signals transmitted by Apple via SKAdNetwork, and subscription purchase events forwarded server-to-server from RevenueCat (anonymous purchase signal, no card data, no name, no email).

Recipient / third-country transfer: AppsFlyer Ltd., 8 Haarman Street, Tel Aviv 6473914, Israel. Israel benefits from a European Commission adequacy decision (Decision 2011/61/EU), meaning the level of data protection is considered equivalent to the EU standard. No Standard Contractual Clauses are required for the Israel transfer. An Art. 28 GDPR data processing agreement is in place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our marketing spend). Given that attribution is purely aggregated and SKAdNetwork-only (no individual identification, no IDFA, no cross-app tracking), your interest in not being tracked does not override ours.

Opt-out / further information: because we receive only aggregated, Apple-mediated signals and no individual identifiers, there is no individual profile to delete. You can stop any future device-level signals by disabling SKAdNetwork attribution in your iPhone settings (Settings → Privacy & Security → Apple Advertising → turn off Personalised Ads). More info and AppsFlyer's own privacy policy: appsflyer.com/legal/services-privacy-policy.

3.8 Face Data

This section states, in one place, exactly how Baselit handles face data — the selfies you take for a skin scan. It restates the skin-analysis flow in §3.1 as plainly as possible.

What face data we collect: when you run a scan, the app captures three front-facing selfies of your face (a centre, a left and a right angle) so the score stays steady across the frames. These photos are the only face data the app collects, and only while you are actively scanning. The app collects no other facial data.

What we use it for: the selfies are used for a single purpose — to compute your cosmetic Skin Score (one overall value plus five axis values: Clarity, Evenness, Texture, Hydration, Radiance). They are never used for identification, advertising, profiling, or any other purpose.

No biometric identification: Baselit does not create a face template, faceprint or face-recognition signature, and cannot identify or re-identify you from your face. We generate and keep no face embeddings or feature vectors. The face detection that helps you line up the shot runs on your device only, purely to guide framing — it never leaves your phone and is not transmitted anywhere. Because no biometric identifier is ever created or stored, this is not biometric data under Art. 9 GDPR (cf. EDPB Guidelines 05/2022).

Sharing and where it is processed: to compute the score, each selfie is transmitted transiently to our AI provider, Anthropic PBC (USA), which acts as our data processor under an Art. 28 GDPR data processing agreement incl. EU Standard Contractual Clauses. Anthropic processes the image only to return the score and does not use it to train AI models (contractually fixed). We do not sell face data, and we do not share it with any advertising, analytics or other third parties. The request carries no name, email or account identifier (data minimisation).

Storage and retention: the selfies are never stored — neither on our servers nor by our AI provider — and are discarded immediately after the score is computed; they exist only in memory for the moment of analysis. The only data we save are the resulting numbers (your Skin Score, the five axis values and the timestamp), kept in our backend database (Supabase; provider and region in §4). Those numbers are retained until you delete your account, which you can do at any time in the app via "Delete my data and account" (§7); deletion removes them from our servers. If you use the optional photo timeline, those photos stay only on your device and are never uploaded (see §3.1).

3.9 Crash and error reporting (Sentry)

To detect and fix crashes and technical errors, we use Sentry, an error-monitoring service. When the app encounters a technical error, a report is sent containing the error message and stack trace, your device model, operating-system version, app version and coarse technical context (e.g. which internal step failed). We send no names, email addresses, skin photos, scores or chat content to Sentry, and the reports are not used for advertising or profiling.

Recipient / third-country transfer: Functional Software, Inc. (dba Sentry), USA. An Art. 28 GDPR data processing agreement incl. EU Standard Contractual Clauses is in place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in keeping the app stable and secure). Retention: error events are deleted automatically after Sentry's standard retention period (90 days).

4. Processors & third parties

ProviderPurposeLocationTransfer basis
Vercel Inc.Hosting / CDN (landing)USASCCs, DPA
Zoho Corporation B.V.Email delivery & support (waitlist, transactional mail)EU (Amsterdam); see noteDPA; SCCs if non-EU routing
Supabase Inc. (app)Hosting, database, auth (backend)USA (EU region: Frankfurt, Germany)SCCs, DPA
Anthropic PBC (app)AI image analysis and Skin Coach chatUSASCCs, DPA
Functional Software, Inc. (Sentry) (app)Crash and error reportingUSASCCs, DPA
PostHog Inc. (app)Product analytics (anonymous usage events)USASCCs, DPA
RevenueCat, Inc. (app)Subscription & entitlement management (in-app purchases, restore)USASCCs, DPA
AppsFlyer Ltd. (app)Marketing attribution (SKAdNetwork-only, aggregated; no IDFA)IsraelAdequacy Decision (2011/61/EU), DPA

5. Third-country transfers (Art. 44 ff. GDPR)

Some providers are based in the USA. Transfers rely on EU Standard Contractual Clauses (Commission Decision 2021/914) and/or the EU–US Data Privacy Framework where the provider is certified. We have run a Transfer Impact Assessment and apply data minimisation. Details on the safeguards are available on request.

6. Retention at a glance

DataRetention
Server logsmax. 30 days
Waitlist emailuntil withdrawal, max. 12 months after launch
Account data (from app)until account deletion
Selfie raw datanot stored (discarded right after analysis)
Photo timeline (app)local on your device only, never uploaded
Coach chat content (app)not stored on our servers (history lives on your device)
Coach usage counter (app)numeric count per day/month, no content
Score history (from app)until account deletion
Sensitivity inputs (from app)until withdrawal or account deletion
Product analytics events (app)anonymous; kept for PostHog's platform retention period

7. Your rights (Art. 15–21 GDPR)

You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), and withdrawal of consent at any time with future effect (Art. 7(3)). To exercise any of these, contact hello@baselit.app. We usually respond within 30 days.

In-app deletion: you can delete your account and all server-side data directly in the app via "Delete my data and account" in the settings, without contacting us. This removes your account, score history and profile inputs.

8. Right to lodge a complaint

You may complain to a data protection authority if you believe your data is processed unlawfully. The authority responsible for Baselit (operator based in Baden-Württemberg) is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI)
Postfach 10 29 32, 70025 Stuttgart, Germany
Phone: +49 711 615541-0 · poststelle@lfdi.bwl.de
baden-wuerttemberg.datenschutz.de

9. No automated decision-making

We make no decisions based solely on automated processing (incl. profiling) that produce legal effects concerning you (Art. 22 GDPR). The skin score is an informational orientation value, not a binding decision.

10. Children

Baselit is not directed at anyone under 16. We do not knowingly collect personal data from minors under 16 and will delete such data promptly if discovered.

11. Changes to this policy

We may update this policy when our processing or the legal situation changes materially. The current version is always available on this page. For material changes, we notify registered users by email at least 30 days in advance.

Not legal advice. Before launch, the open items (active email inbox, processor DPAs, app-phase Art. 9 architecture, DPIA) must be confirmed by a qualified data-protection lawyer. See docs/legal-content.md for the full checklist.
baselit.app · Terms · Imprint · © 2026 Marco Mori