Privacy Policy
Last updated: August 18, 2026
colorseason.app ("we," "us") is currently operated by an individual, not a registered company. This policy explains what happens to your photo and your data when you use the site, in plain terms.
Your photo
Before your photo ever leaves your browser, we strip its EXIF metadata and any embedded location data, and resize/compress it. Only that processed image is uploaded.
The uploaded photo is sent to a third-party AI vision provider for analysis. That provider only ever returns a description of photo quality and visible color relationships (skin/hair/eye tone, contrast) — it never receives or returns your identity, name, or any season "answer"; the actual season is decided by our own separate, deterministic rules engine. Depending on availability, the provider is either apimart.ai (a third-party API reseller providing access to OpenAI-compatible vision models) or Google's Gemini API directly.
We do not use face recognition, identity matching, face embeddings, or any reusable biometric template. We do not infer or store sensitive traits like race, health, or religion.
Your photo is deleted from our storage immediately once your analysis finishes — whether it completes, needs a retake, or fails — and in every case no later than 48 hours after upload regardless. You can also delete it immediately yourself from your result page at any time. Your photo is never embedded in your free result or paid report, and it is never included in any email we send you.
What we keep, and for how long
- Your uploaded photo: deleted on completion, always within 48 hours (see above).
- Your free result (season, colors, evidence confidence): kept for 7 days, then expires.
- A purchased full report: kept as long as your purchase/account exists, so you retain access. You can request deletion at any time (see "Your choices" below).
- Basic transaction and payment records: kept as long as required by applicable law, even after a refund.
Cookies and similar technology
We use a small number of cookies, all first-party, none used for cross-site ad tracking:
- Guest session — an anonymous, randomly generated identifier that lets you manage your own analysis (delete your photo, answer follow-up questions) without creating an account. We store only a cryptographic hash of it, never the raw value. Expires after 7 days.
- Report access — set only after a purchase, lets you view the specific report you bought without signing in.
- Sign-in session — set only if you sign in with an email link, so you can see your purchased reports from that browser later.
Analytics
We use PostHog to understand which parts of the product work, tracking a fixed, deliberate set of named events (like "photo uploaded" or "result viewed") — not automatic click/scroll capture, and not session recording. This data is not tied to your name or email, and is not persisted in your browser between visits.
We also use Microsoft Clarity for session recording and heatmaps, to see how visitors actually use the pages (where they click, where they get stuck). Clarity records page interactions and layout, not your photo — your photo is never rendered as a visible image anywhere on the page, so there is nothing for it to capture there. Form fields (like the email field on our sign-in page) are masked from recording.
Payments and email
When you purchase a full report, payment is handled entirely by Stripe on their own hosted checkout page — we never see or store your card number. We keep only that a purchase happened, which report it unlocked, and (if provided) the email address you paid with.
We send transactional emails only — a link to your result or report, or a sign-in link you requested — through Resend. We do not send marketing email, and we do not have a mailing list.
Who can use this service
This service is intended for people aged 18 and older.
Your choices
You can delete your uploaded photo immediately from your result page. For anything else — deleting a saved report, deleting your account, or asking what data we hold about you — email support@colorseason.app and we'll handle it directly.
Changes to this policy
If this policy changes in a way that meaningfully affects how we handle your data, we'll update the "Last updated" date above. Continued use of the site after a change means you accept the updated policy.
This policy is written to accurately describe how the product actually works today. It has not been reviewed by a lawyer, and it will be revisited as the service grows (for example, if a formal business entity is registered, or as we expand to markets with specific regulatory requirements like GDPR or CCPA).