Privacy Policy

Updated: March 18, 2026

Introduction

This Privacy Policy explains how SKINFIELD Ltd. (“SKINFIELD”, “Company”, “we”, “our”, or “us”) collects, stores, processes, and protects information in connection with the SKINFIELD PRO platform (the “Platform”). The Platform provides cosmetic tools intended for use by skincare professionals. The Platform enables Professionals to generate cosmetic indicators relating to skin oiliness and related cosmetic characteristics. The Platform is not a medical device and is intended for cosmetic and informational purposes only. This Privacy Policy should be read together with the Platform’s Terms of Service.

Definitions

Platform

The SKINFIELD PRO software platform, including related software tools, applications, and services.

Professional

A cosmetologist, aesthetician, skincare practitioner, beauty clinic, or similar professional user of the Platform.

Client

An individual receiving cosmetic services from a Professional.

Client Data

Information relating to a Client that is entered, uploaded, or generated within the Platform by a Professional.

Categories of Data Processed

The Platform may process the following categories of information. The categories of information described below may include personal information, depending on how the Platform is used.

Professional Data

Information relating to Professionals using the Platform may include:

name

business details

contact information

billing information

login credentials

subscription information

platform usage information

Client-Related Data (Processed on Behalf of Professionals)

Professionals may enter or upload information relating to their Clients while using the Platform. Such information may include:

Client name or identifier (if entered)

images of used facial patches

facial skin images (if uploaded)

AI-generated informational outputs

skin-related visual indicators

treatment history notes (if recorded)

session-related metadata

Client Data is processed solely to provide cosmetic functionality within the Platform. In relation to Client Data, the Professional acts as the data controller, and SKINFIELD acts as a service provider or data processor solely for the purpose of operating the Platform. Professionals remain responsible for determining the lawful basis and retention policies applicable to Client Data.

Image Processing

The Platform may allow Professionals to capture, upload, store, or process images in connection with the services provided through the Platform. Such images may include facial skin images and images of facial patches used to generate cosmetic indicators. These images may be processed using automated software tools and artificial intelligence technologies in order to generate cosmetic indicators relating to skin oiliness and related cosmetic characteristics. Images are processed solely to support the functionality of the Platform and are not used for medical diagnosis or clinical decision-making. Professionals are responsible for obtaining any required consent from Clients before capturing or uploading images.

The Platform captures 3 facial skin images (front, left, right angles) through the iPhone camera for the purpose of cosmetic skin analysis.

Collection: Images are captured by the Professional through the Platform's camera functionality. End clients do not have Platform accounts — all data is managed by the Professional.

Use: Images are processed using SKINFIELD's proprietary algorithms running in a secured server environment.

Storage: Images are stored securely on AWS S3 using private buckets with presigned URLs, ensuring images are never publicly accessible.

Retention: Images are retained until the Professional deletes them or deletes their account, at which point all associated data is permanently removed.

No Facial Recognition: The Platform does not perform facial recognition, biometric identification, or identity verification. Images are used solely for cosmetic skin evaluation.

Professional Responsibility: Professionals are responsible for obtaining informed consent from their Clients before capturing any facial images.

AI Processing Transparency

The Platform may use automated processing technologies, including artificial intelligence, to generate cosmetic indicators from images uploaded to the Platform. Such processing is performed solely to enable the cosmetic functionality of the Platform. The Platform does not perform medical analysis or clinical decision-making.

No Training Use of Client Images

SKINFIELD does not use Client images uploaded or processed through the Platform for the purpose of training, developing, or improving artificial intelligence or machine learning models, unless such use is explicitly disclosed and authorized. Images are processed solely to provide cosmetic indicators and support the operation of the Platform. SKINFIELD does not sell, license, or otherwise commercialize Client images. Professionals remain responsible for obtaining any required consent from their Clients.

Biometric Data Disclaimer

The Platform is not intended to collect, derive, or process biometric identifiers or biometric information for the purpose of uniquely identifying any individual. Any facial images processed through the Platform are used solely for cosmetic image evaluation and related Platform functionality. The Platform does not perform facial recognition, identity verification, or biometric identification. Professionals remain responsible for ensuring that their use of the Platform complies with all applicable privacy and data protection laws.

Technical and Usage Data

When the Platform is used, certain technical information may automatically be collected, including:

IP address

device information

browser type

log files

usage metrics

system performance data

This information helps operate, maintain, secure, and improve the Platform.

Cookies and Similar Technologies

The Platform may use cookies or similar technologies to support authentication, platform functionality, and usage analytics. Users may control cookie settings through their browser or device settings.

User Content Responsibility

Professionals are solely responsible for any information, images, or other content uploaded to the Platform. Professionals represent and warrant that they have obtained all necessary rights, permissions, and consents required to upload and process such content through the Platform. Professionals must not upload:

medical records or protected health information where not permitted by law

content belonging to third parties without proper authorization

unlawful, harmful, or inappropriate content

SKINFIELD does not review all content uploaded to the Platform and assumes no responsibility for such content.

Data Sharing

SKINFIELD does not sell personal data. Information may be shared only in limited circumstances, including:

service providers supporting hosting, cloud infrastructure, payment processing, or analytics

compliance with legal obligations or lawful requests from authorities

protection of the Platform, its users, or SKINFIELD’s rights

corporate transactions such as mergers, acquisitions, or asset transfers

Data Security

SKINFIELD implements appropriate administrative, technical, and organizational safeguards designed to protect information against unauthorized access, misuse, or disclosure. However, no system can guarantee absolute security.

Data Retention

Information is retained only as long as necessary to:

provide the Platform services

maintain user accounts

comply with legal obligations

resolve disputes

Retention periods may vary depending on the nature of the information, unless a longer retention period is required or permitted by law. Professionals remain responsible for determining retention policies applicable to Client Data.

International Data Transfers

Information processed through the Platform may be stored or processed in different jurisdictions, including Israel or other locations where SKINFIELD or its service providers operate. SKINFIELD takes reasonable steps to ensure appropriate protection of such information.

Children’s Privacy

The Platform is intended for use by professionals and is not directed to children. SKINFIELD does not knowingly collect personal information directly from children. Professionals are responsible for ensuring that their use of the Platform complies with applicable laws relating to minors and the processing of children’s information.

Changes to This Policy

SKINFIELD may update this Privacy Policy periodically. The Last Updated date will reflect the most recent revision.

The best way to get in touch with us is by emailing procare@skinfield.com

SKINFIELD Ltd.