Privacy Policy
Last updated 18 June 2026 · Effective immediately
1. Who we are
UpNew is operated by Dr. Gotthilf LLC, a Wyoming limited liability company (30 N Gould St Ste R, Sheridan, WY 82801, USA). Dr. Gotthilf LLC is the data controller for the purposes of the GDPR. For privacy questions, contact [email protected].
This policy explains what data UpNew collects when you use the UpNew mobile app or visit upnew.app, why we collect it, who we share it with, and how to remove it. Our practices are designed to comply with the EU/UK GDPR, the California CCPA/CPRA, and Apple/Google app-store privacy requirements.
2. Information we collect
UpNew is designed to need as little personal information as possible. We deliberately do not require an account, an email address, or a phone number to use the app.
a) On-device anonymous identifier
When you first open the app, your device generates a random 128-bit identifier (the "anonUid"). It is stored locally and sent with every request so we can link your scan history to itself. It is not linked to any real-world identifier and never leaves your device with PII attached.
b) Selfie image data
When you take a scan, the photo is sent to our backend over HTTPS for analysis by our AI vision model. The unaltered selfie is not retained after the analysis call completes. The only image we retain is the AI-generated "New You" rendering, which is cached in our object storage so you can re-open it without regenerating. You can delete that rendering at any time from Settings.
c) Cosmetic scores and attributes
The model returns eight numeric sub-scores (skin clarity, skin texture, hydration, evenness, glow, eye area, symmetry, plus an overall composite) and four attributes (face shape, undertone, hair texture, beard density). Those scores plus the timestamp and your anonUid are stored on our servers so you can see your progress over time. The scores are not personally identifiable on their own.
d) Subscription data
If you purchase UpNew Pro, the transaction is processed by Apple App Store or Google Play. We do not see your card details. Our subscription manager (RevenueCat) gives us a non-personally-identifiable transaction ID, your country, the product purchased, and renewal status, so we can unlock Pro features.
e) Diagnostic and usage data
To detect crashes and broken flows, we collect anonymous usage events (scan completed, paywall viewed, error occurred) using PostHog, and crash reports via Sentry. These contain device model, OS version, anonUid, and the event itself — never your selfie, scores, or any free-text input.
f) Marketing attribution
If you installed UpNew through an ad, AppsFlyer may share your install attribution (which campaign brought you in) with us. This uses Apple's SKAdNetwork or Google's equivalent privacy-safe attribution — no IDFA without your consent.
3. Information we do not collect
- Your name, email, phone number, or address.
- Your contacts, social-media accounts, or photo library beyond the selfies you explicitly capture.
- Precise location. The IP address you connect from is logged for fraud and rate-limiting, then dropped within 30 days.
- Biometric templates for identification. Our model produces cosmetic scores, not a face-recognition embedding, and we do not maintain a database keyed by your face.
4. Why we collect what we collect
We process the data in §2 to (a) deliver the core scan / "New You" / weekly-focus features you opened the app to use; (b) verify your subscription; (c) detect crashes and improve the product; (d) prevent abuse, fraud, and excessive load on the inference backend. Our legal basis under the GDPR is contract performance (delivering the features you requested) and our legitimate interest in security and product improvement.
5. Who we share data with
UpNew uses the following sub-processors. Each one only receives the minimum data required for its role.
| Sub-processor | What we send | Where |
|---|---|---|
| Anthropic (Claude) | Your selfie + scan request | US |
| Google (Gemini) | Your selfie + restyle prompt | US |
| Cloudflare | All traffic, R2-stored renderings | Global edge |
| RevenueCat | Subscription transactions | US |
| PostHog | Anonymous product events | US |
| AppsFlyer | Anonymous install attribution | US/EU |
| Sentry | Crash reports | US/EU |
We do not sell your data and we do not share it with advertisers for cross-context behavioural advertising. We have not sold or shared personal information in the meaning of the CCPA in the prior 12 months.
When data leaves the EU/UK, we rely on Standard Contractual Clauses with our sub-processors and on the EU-US Data Privacy Framework where applicable.
6. How long we keep things
- Selfie images: not retained — dropped after the analysis call.
- "New You" renderings: until you delete them in Settings or 24 months after your last scan, whichever comes first.
- Cosmetic scores history: until you delete your data or 24 months after your last scan.
- Crash and analytics events: 90 days.
- Subscription transaction records: 7 years (US accounting requirement).
- IP address logs: 30 days.
7. Your rights
Regardless of where you live, you can:
- See your data. Settings → Data → Export.
- Delete your data. Settings → Data → Delete account. We honour this within 30 days; sub-processors are notified to delete on their side.
- Withdraw consent to optional analytics: Settings → Privacy → Analytics off.
- Lodge a complaint with your local supervisory authority. EU residents may contact their national DPA; UK residents can contact the ICO; California residents may contact the California Attorney General.
Under GDPR you additionally have rights to access, rectify, restrict, and port your data. Under CCPA/CPRA you have the right to know, delete, correct, and opt out of "sale" or "sharing" (we don't do either). Email [email protected] to exercise any of these — please tell us your anonUid (Settings → About).
8. Children
UpNew is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect data from children. If you believe a child has used UpNew, email [email protected] and we will delete their data within 14 days.
9. Security
All traffic uses HTTPS (TLS 1.2+). API secrets are stored in Cloudflare's Workers Secrets vault, never on user devices. The R2 bucket holding "New You" renderings is private; access is mediated by signed URLs scoped to your anonUid. We do not store selfies, payment cards, or government IDs at any point.
10. Changes to this policy
If we make material changes, we will update the "Last updated" date and, for material changes affecting how your data is processed, surface an in-app notice before the change takes effect. The current version always lives at https://upnew.app/privacy.
11. Contact
For privacy questions, requests, or general support: [email protected]
Postal: Dr. Gotthilf LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA