Privacy Policy
Last Updated: April 26, 2026
Effective Date: April 26, 2026
1. Introduction
Welcome to Hairli. This Privacy Policy explains how Yusuf Şahan Tarhan ("we," "us," or "our") collects, uses, shares, and protects your information when you use the Hairli mobile application (the "App"). Hairli is an AI-powered tool that lets you preview different hairstyles and hair colors on your own photo.
We are committed to minimizing data collection and being transparent about what we do with the limited information we handle. By using Hairli, you agree to this Privacy Policy.
Operator Information:
- Name: Yusuf Şahan Tarhan
- Email: [email protected]
- Jurisdiction: Turkey
2. Information We Collect
2.1 Anonymous Account Identifier
Hairli does not require you to create an account, sign up with email, or provide your name, phone number, or any other personal identifier. When you first launch the App, we generate a random anonymous identifier (a UUID) so that we can track your remaining credits and subscription status. This identifier is not linked to your real-world identity.
2.2 Photos You Provide
To generate a hairstyle preview, you choose a photo from your photo library or take a new one with the camera. The photo is sent to our processing service to be transformed by the AI model. Photos typically contain your face, since the App is designed to apply new hairstyles to a person in the image.
We do not store your photos on our servers. Photos are transmitted only to perform the requested transformation and are not retained, logged, or saved to any database after the AI response is returned to your device. The original photo and the generated result remain on your device unless you choose to share or save them yourself.
2.3 Style Selections
Each generation request includes the haircut style and hair color you selected (e.g. "Bob", "Platinum Blonde"). These selections are sent to the AI model along with your photo, but they are not associated with your identifier in any persistent record.
2.4 Subscription and Credit Data
We maintain a small record tied to your anonymous identifier with the following fields:
- Number of remaining generation credits
- Total credits used
- Subscription status (active or inactive)
- Total credits purchased over time
- Timestamp of when the record was created
We do not directly collect or store any payment card information. All purchases are processed by Apple's App Store and managed by RevenueCat. We only receive a confirmation that a purchase or subscription event occurred for your anonymous identifier.
2.5 Locally Stored Data
The following items are stored only on your device and are never transmitted to us:
- Authentication session token (so you stay signed in across launches)
- Favorited haircuts and hair colors
- Onboarding completion flag
- Selected app language
2.6 Information We Do Not Collect
- We do not collect your name, email, phone number, or address.
- We do not collect device identifiers (IDFA), advertising IDs, or location data.
- We do not use any analytics, telemetry, or crash-reporting SDKs.
- We do not track you across other apps or websites. Hairli does not present an App Tracking Transparency prompt because no tracking occurs.
- We do not send push notifications.
3. Face Data Handling
Because Hairli is built around photos of people, the photos you upload typically contain your face. Apple requires us to clearly explain how this kind of data is handled. Please read this section carefully.
3.1 What "Face Data" Means in Hairli
Hairli does not perform facial recognition, identity verification, biometric identification, or face-based authentication. We do not build a faceprint, face template, or any mathematical representation of your face. We do not match your face against any database. We do not attempt to identify who you are from your photo.
The only thing the AI does with your photo is generate a new image where the hair has been visually modified. The AI model needs to look at the photo as a whole image (including the face) in order to produce a realistic result, but it is not used as a biometric identifier.
3.2 What We Do With Your Photos
- Transmission: Your photo is sent over an encrypted connection (HTTPS) to our backend, which forwards it to Google Cloud and/or fal.ai AI services for processing.
- Processing: The AI generates a transformed image and returns it to your device.
- No storage: Neither the original photo nor the generated image is stored on our servers, written to any database, or kept in any persistent log. Once the response is returned, the photo is no longer in our possession.
- No training: We do not use your photos to train any AI model. Per Google Cloud's published terms, customer inputs to its enterprise AI services are not used to train Google's foundation models. Google and fal.ai may briefly cache inputs for abuse detection and operational integrity; we do not access these caches.
- No sharing: Your photos are never sold, shared with advertisers, or disclosed to any third party other than the service providers listed in Section 5, who process the photo solely to fulfill your generation request.
3.3 Your Control
You choose every photo you upload. You can revoke camera or photo library access at any time in your device's iOS settings. You are not required to upload a photo of yourself — the App will work with any photo you choose, although results may vary.
4. How We Use Information
- To provide the core feature: Generating hairstyle previews from the photo and selections you submit.
- To track credits: So that paid users receive the generations they purchased and free users see their remaining quota.
- To manage subscriptions: Activating, renewing, or expiring subscription benefits based on events received from RevenueCat.
- To keep the App working: Maintaining your anonymous session so you do not have to start over each time you open the App.
We do not use your information for advertising, profiling, or any purpose other than operating the App.
5. Third-Party Service Providers
We rely on a small set of service providers to run the App. They process information only on our behalf and only for the purposes described below.
5.1 AI Processing — Google Cloud and fal.ai
Photo transformation is performed by AI image models running on Google Cloud and/or fal.ai. These providers process your submitted photo and style selections only to generate the requested hairstyle preview. Per Google Cloud's published terms, customer inputs to its enterprise AI services are not used to train Google's foundation models, and inputs are not retained beyond what is necessary to provide the service. See Google Cloud's privacy notice and fal.ai's privacy policy.
5.2 Apple App Store
All purchases are processed by Apple. Apple receives the information necessary to complete the transaction. We do not receive your payment details. See Apple's privacy policy.
5.3 RevenueCat
RevenueCat manages our subscription entitlements. It receives your anonymous user identifier and purchase events from Apple, and notifies our backend when your subscription status changes. See RevenueCat's privacy policy.
5.4 Backend Infrastructure
Our backend (authentication, database, and request routing) runs on standard cloud-hosting providers under industry-standard data-protection agreements. These providers process limited operational data (such as your anonymous identifier and connection metadata) solely to deliver the App's functionality. They do not use your data for any independent purpose.
6. Data Retention
- Photos: Not retained. Discarded after the generation response is returned.
- Generated images: Not retained. Returned directly to your device.
- Anonymous identifier and credit record: Retained for as long as the identifier remains in use. If you uninstall the App and clear its data, the local link to your record is lost; you may also email us to request deletion of the record itself (see Section 8).
- Locally stored data: Retained on your device until you delete the App or clear its storage.
7. Data Sharing and Disclosure
We do not sell your information. We do not share it with advertisers. We do not share it with any third party other than the service providers listed in Section 5, who process it strictly to operate the App on our behalf.
We may disclose information if required to do so by law, by valid legal process, or to protect against fraud, abuse, or threats to the security of the App.
8. Your Rights
Depending on where you live, you may have the following rights regarding your information:
- Access: Request a copy of the data associated with your anonymous identifier.
- Deletion: Request deletion of the credit and subscription record tied to your identifier.
- Correction: Request correction of inaccurate data.
- Objection / Restriction: Object to or restrict certain processing.
- Portability: Receive your data in a portable format.
- Withdraw consent: Stop using the App at any time.
Because Hairli does not collect your name or email, we may need additional information (such as your anonymous user identifier, which can be found in the App's settings) to locate your record before acting on a request. To exercise any of these rights, email [email protected].
9. Security
All network traffic between the App and our backend is encrypted via HTTPS/TLS. Authentication tokens are stored on your device using the platform's secure storage. We rely on the security practices of Apple, Supabase, Cloudflare, Google Cloud, fal.ai, and RevenueCat for data they handle on our behalf. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Children's Privacy
The App has an Apple App Store age rating of 9+. However, because Hairli processes photos of people (including faces), we ask that the App not be used by children under 13. Children between 9 and 13 should only use Hairli with the involvement and consent of a parent or legal guardian. We do not knowingly collect information from children under 13. If you believe a child under 13 has used the App, please contact us and we will delete any associated record.
11. International Data Transfers
The App is operated from Turkey, and our service providers operate globally. By using the App, you acknowledge that your information may be processed in countries other than your own, including the United States and the European Union. Where required, transfers are protected by appropriate safeguards offered by the relevant service providers (such as standard contractual clauses).
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. Material changes will be highlighted in the App or on this page. Your continued use of the App after a change takes effect means you accept the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or the way Hairli handles your information, please contact us:
- Email: [email protected]
- Operator: Yusuf Şahan Tarhan
By using Hairli, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
This Privacy Policy is governed by the laws of Turkey.