The short version. Your photos stay on your phone. Your notes — the areas you mark and what you call them, the small daily measurements, and your applied / skipped log — sync to our server in the EU. Never your photos. If you ask for a report, the app asks you again first: two cropped, normalized patches from each area you're watching are uploaded once for the write-up, and never stored. Withdrawing consent, exporting everything, and deleting everything are each one action away in settings. We show no ads, use no trackers, and never sell your data.

1. Who we are

The data controller for Pentimento is:

Umut Aktaş (natural person, sole controller)
Utrecht, the Netherlands
Contact: privacy@usepentimento.com

The app is distributed via the Apple App Store and Google Play under developer accounts registered in Türkiye; the data controller is Umut Aktaş personally, and the store accounts are distribution channels that do not create a separate legal controller.


2. What Pentimento is — and isn't

Pentimento helps you see whether a product or routine is producing a change visible to your own eye, on your own face. It is cosmetic self-tracking, nothing more: it is not a medical device, it makes no diagnosis, gives no treatment or product advice, and assigns no absolute scores — only relative trends in your own photos, over time.


3. What stays on your phone

Your photos, with their capture details, are taken, stored, and measured on your device. In daily use, no photo ever leaves your phone. Your cycle-day tags also stay on this phone only: they never sync and never enter any AI prompt — reports that mention cycle days render that line on the device, from fixed wording. Saved reports are stored on your phone too. Deleting a photo removes the image for good; the day keeps its place in your record, and measurements already made stay — until you choose Delete everything.


4. What syncs to our server in the EU

Measurement happens on your phone; some of the results sync so your notes survive a lost or new phone. What syncs: the areas you mark and what you call them; the small daily measurements (numbers, never images); your applied / skipped log; your products and routine periods; your account identifier; and your consent record (which version you agreed to, and when). This data says something about your skin, which is why the law treats it as special-category data and why we only process it with your explicit consent (GDPR Art. 9(2)(a)). It is stored in the Netherlands (Google Cloud region europe-west4) — fixed from day one, never moved.


5. Reports ask again, every time

If you generate a report, two cropped, normalized patches from each area you're watching are needed for the write-up. The app tells you the exact count and asks you separately, before every report. The patches upload once, are used to ground the written text, and are never stored — regenerated only if you ask again. The written part of every report is AI-generated and labeled as such in the app (EU AI Act Art. 50): "the words in this report are ai-generated. the measurements and photos are yours." The trends themselves come from measurements made on your phone — not from the AI. We make no automated decisions about you with legal or similarly significant effects.


6. Why we're allowed (legal bases)

Everything in §§3–5 rests on your explicit consent (Arts. 6(1)(a) and 9(2)(a)) — the consent screen you accepted, versioned and re-readable in settings. Account and subscription mechanics rest on contract (Art. 6(1)(b)). We do no legitimate-interest processing of your content.


7. Who processes data for us

Google (Firebase) — sign-in, database, and the AI service that writes report text; stored data in EU region europe-west4. Our AI features run on Google’s Gemini models through Firebase, pinned to Google’s Netherlands region (europe-west4), so the text we send is processed inside the EU. We never send your photos or your face to the AI. Google does not use this data to train its models; it may keep a short-lived copy for up to 90 days, in the same EU region, only to check for abuse of the service.

Apple App Store / Google Play — payment; we never see your card or bank details. RevenueCat — subscription status only (entitlement and transaction identifiers, no payment details). Subscription and purchase records are handled by RevenueCat, Inc. in the United States. That transfer is covered by the EU Standard Contractual Clauses (Module 2, controller to processor) in our data processing agreement with them. RevenueCat never receives your photos or your skin data.

When the app crashes or hits an error, we send a diagnostic report to Sentry so we can fix it. The report contains the technical error and stack trace, your device model, your operating system version and the app version. It never contains your photos, your face, your skin data, your email address or your IP address — we have turned off the setting that would attach personal identifiers. These reports are stored in Sentry’s EU region in Frankfurt, Germany (de.sentry.io), and are deleted after no longer than 90 days. We do this on the basis of our legitimate interest in keeping the app stable and secure (Article 6(1)(f) GDPR). You can object to this at any time — write to us and we’ll disable crash reporting for your account.

No advertising networks, no data brokers, no sale of data, ever. Your photos and personal details never appear in logs, analytics, or crash reports.


8. Your rights, and where each one lives

See it (Art. 15): everything the app holds is visible in the app; the export gives you a copy.

Fix it (Art. 16): rename areas, edit products and notes directly in the app.

Take it with you (Art. 20): Export your data in settings assembles one bundle on your phone — nothing uploads: photos, measurements, concerns, products and periods, your applied / skipped record, your cycle tags (the one thing that otherwise never leaves this phone), saved reports, and your consent record — machine-readable.

Delete it (Art. 17): Delete everything in settings wipes server first, then this phone, then the account itself. If the server can't be reached, nothing is deleted and the app says so plainly — it never pretends.

Restrict it (Art. 18): withdrawing consent stops all new processing (§9); for anything narrower, contact us. If you correct or delete something, the change reaches our processors too (Art. 19).

Complain (Art. 77): Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl — though we'd welcome the chance to fix it first.


9. Withdrawing consent (Art. 7(3))

Withdrawing is as easy as consenting: one sheet in settings. One sentence is the whole rule: whatever creates or syncs new data stops; whatever lets you see, export, or delete what exists stays. Capture, measurement, check-ins, reminders, new reports: stop. Your archive, saved reports, export, delete: stay yours. Nothing is deleted unless you choose it. You can consent again anytime — same terms, no penalty. Your subscription is separate — manage it in the store.


10. How long we keep things

As long as you choose — your archive is the product, so nothing expires on a schedule. When you delete your account we remove your data from our live systems straight away. Copies can still sit in our encrypted backups and recovery snapshots for up to 30 days, all held in the Netherlands; we don’t use them for anything except restoring the service after a failure, and they’re overwritten on schedule. Report patches: never stored at all. Your consent record: kept while your account exists, as proof of what you agreed to. Deleting the app is not deleting your data — data on the phone goes with it, but synced data waits on the server until you delete it in-app first, or write to us.


11. Subscriptions

Payment runs entirely through the App Store or Google Play. Withdrawing consent or deleting your data does not cancel a subscription — manage that in the store.


12. Age

Pentimento is not for anyone under 18. We don't knowingly process children's data; if you believe a child is using it, contact us.


13. Security

Data in transit is encrypted; server data is guarded by access rules tied to your account and app-integrity checks; on-device data sits behind your device's own protections. Above all we minimize what exists to protect: the most sensitive thing — your face — never leaves your phone in daily use.


14. Changes to this policy

This policy is versioned, like the consent text it mirrors. Material changes are announced in the app before they apply, and where the law requires it we ask for your consent again. Current version: v1.1 · august 2026.