Privacy Policy

Last updated 18 June 2026 · Effective immediately

The 30-second version. UpNew analyses your selfie to give you a personalised cosmetic readout and an AI "New You" rendering. We do not store the selfie. We do not collect your name, email, or contacts. An anonymous ID lives on your device. You can delete everything at any time, with no account to recover.

1. Who we are

UpNew is operated by Dr. Gotthilf LLC, a Wyoming limited liability company (30 N Gould St Ste R, Sheridan, WY 82801, USA). Dr. Gotthilf LLC is the data controller for the purposes of the GDPR. For privacy questions, contact [email protected].

This policy explains what data UpNew collects when you use the UpNew mobile app or visit upnew.app, why we collect it, who we share it with, and how to remove it. Our practices are designed to comply with the EU/UK GDPR, the California CCPA/CPRA, and Apple/Google app-store privacy requirements.

2. Information we collect

UpNew is designed to need as little personal information as possible. We deliberately do not require an account, an email address, or a phone number to use the app.

a) On-device anonymous identifier

When you first open the app, your device generates a random 128-bit identifier (the "anonUid"). It is stored locally and sent with every request so we can link your scan history to itself. It is not linked to any real-world identifier and never leaves your device with PII attached.

b) Selfie image data

When you take a scan, the photo is sent to our backend over HTTPS for analysis by our AI vision model. The unaltered selfie is not retained after the analysis call completes. The only image we retain is the AI-generated "New You" rendering, which is cached in our object storage so you can re-open it without regenerating. You can delete that rendering at any time from Settings.

c) Cosmetic scores and attributes

The model returns eight numeric sub-scores (skin clarity, skin texture, hydration, evenness, glow, eye area, symmetry, plus an overall composite) and four attributes (face shape, undertone, hair texture, beard density). Those scores plus the timestamp and your anonUid are stored on our servers so you can see your progress over time. The scores are not personally identifiable on their own.

d) Subscription data

If you purchase UpNew Pro, the transaction is processed by Apple App Store or Google Play. We do not see your card details. Our subscription manager (RevenueCat) gives us a non-personally-identifiable transaction ID, your country, the product purchased, and renewal status, so we can unlock Pro features.

e) Diagnostic and usage data

To detect crashes and broken flows, we collect anonymous usage events (scan completed, paywall viewed, error occurred) using PostHog, and crash reports via Sentry. These contain device model, OS version, anonUid, and the event itself — never your selfie, scores, or any free-text input.

f) Marketing attribution

If you installed UpNew through an ad, AppsFlyer may share your install attribution (which campaign brought you in) with us. This uses Apple's SKAdNetwork or Google's equivalent privacy-safe attribution — no IDFA without your consent.

3. Information we do not collect

4. Why we collect what we collect

We process the data in §2 to (a) deliver the core scan / "New You" / weekly-focus features you opened the app to use; (b) verify your subscription; (c) detect crashes and improve the product; (d) prevent abuse, fraud, and excessive load on the inference backend. Our legal basis under the GDPR is contract performance (delivering the features you requested) and our legitimate interest in security and product improvement.

5. Who we share data with

UpNew uses the following sub-processors. Each one only receives the minimum data required for its role.

Sub-processorWhat we sendWhere
Anthropic (Claude)Your selfie + scan requestUS
Google (Gemini)Your selfie + restyle promptUS
CloudflareAll traffic, R2-stored renderingsGlobal edge
RevenueCatSubscription transactionsUS
PostHogAnonymous product eventsUS
AppsFlyerAnonymous install attributionUS/EU
SentryCrash reportsUS/EU

We do not sell your data and we do not share it with advertisers for cross-context behavioural advertising. We have not sold or shared personal information in the meaning of the CCPA in the prior 12 months.

When data leaves the EU/UK, we rely on Standard Contractual Clauses with our sub-processors and on the EU-US Data Privacy Framework where applicable.

6. How long we keep things

7. Your rights

Regardless of where you live, you can:

Under GDPR you additionally have rights to access, rectify, restrict, and port your data. Under CCPA/CPRA you have the right to know, delete, correct, and opt out of "sale" or "sharing" (we don't do either). Email [email protected] to exercise any of these — please tell us your anonUid (Settings → About).

8. Children

UpNew is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect data from children. If you believe a child has used UpNew, email [email protected] and we will delete their data within 14 days.

9. Security

All traffic uses HTTPS (TLS 1.2+). API secrets are stored in Cloudflare's Workers Secrets vault, never on user devices. The R2 bucket holding "New You" renderings is private; access is mediated by signed URLs scoped to your anonUid. We do not store selfies, payment cards, or government IDs at any point.

10. Changes to this policy

If we make material changes, we will update the "Last updated" date and, for material changes affecting how your data is processed, surface an in-app notice before the change takes effect. The current version always lives at https://upnew.app/privacy.

11. Contact

For privacy questions, requests, or general support: [email protected]
Postal: Dr. Gotthilf LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA