Privacy Policy

Last updated 5 September 2026

Overview

This policy explains what data is processed when you use the SMVRank website (smvrank.com) and the SMV app for iPhone ("SMV", "the app"), and why. Both are operated by the operator named in the Legal Notice. It covers only the data handling that actually takes place - nothing else.

Part 1 applies to the SMV iOS app. Part 2 applies to the SMVRank website. The sections on processors, children, your rights and contact apply to both.

Part 1 - The SMV iOS App: No Accounts

The app has no user accounts, no login and no password. On first use it generates a random identifier and a random secret on your device. These are stored only on your device and sent with requests to our server so that the server can recognise the same installation again (for example to count your votes once, to let you delete your own posts, and to apply fair-use limits). They are not linked to your name, email address, Apple ID or any other real-world identity.

Deleting the app deletes this identifier. Content you have posted in the community remains until you delete it or ask us to (see "Your Rights").

Onboarding Answers

During onboarding the app asks for a first name or nickname, gender, date of birth, height, weight and your interests. These answers are stored only on your device. Your gender and age are sent to our server together with your questions to the AI assistant so its answers fit you; nothing else from the questionnaire leaves your device. Your name is attached to your community posts as your display name.

Face Photos and AI Analysis

When you choose a front photo and a side photo for the face analysis, both are uploaded to our server (hosted on Vercel) and forwarded to the Google Gemini API for a one-time automated analysis of visible facial features. The photos are kept on your device so the app can show them to you; the server does not keep the photo files themselves.

To return the same result for the same photo without re-analysing it, our server stores a cryptographic hash of the normalised photo (from which the photo cannot be reconstructed) together with the numeric analysis result and your random device identifier. Requests are also logged (identifier, hashed IP address, time and outcome, no image) to enforce fair-use limits and detect abuse.

Google processes the photo under its own terms for the Gemini API. We do not use your photos to train any model. The analysis is an automated, informational estimate, not a medical or scientific assessment.

AI Assistant

Messages you send to the in-app assistant, together with your current analysis scores, gender and age, are sent to our server and forwarded to the Google Gemini API to generate a reply. The conversation is stored only on your device. Our server logs each request (identifier, hashed IP address, token counts and outcome, never the message text) to enforce usage limits and monitor cost.

Community

Posts, comments, votes, reports and blocks you create in the community are stored on our server in a database hosted by Supabase, together with your random device identifier and display name. Images you attach to posts are downscaled on your device and stored on the server as part of the post. Posts and comments are visible to all users of the app; they do not show your identifier.

Reports you submit are reviewed by us. Content that violates the Terms of Use may be hidden or removed, and repeat offenders may be blocked from posting. You can delete your own posts and comments in the app at any time.

Subscriptions and Purchases

SMV Premium is sold as an auto-renewable subscription through Apple's In-App Purchase system. Apple processes the payment; we never see your payment details. To check whether a subscription is active we use RevenueCat, a subscription management service, which receives your purchase and subscription status from Apple together with an anonymous RevenueCat user ID and basic device information (such as device model, OS version and app version). RevenueCat processes this data on our behalf under its own privacy policy.

Creator Program Applications

If you apply to the Creator Program, the name, email address and social media handle you enter are sent to our server and stored so we can review the application and contact you about it. They are used for no other purpose.

Storage on Your Device

The app stores your onboarding answers, photos, analysis history, routine progress, assistant conversation and settings in the app's private storage on your device. Deleting the app removes all of it.

What the App Does Not Do

The app contains no advertising, no third-party analytics or tracking SDKs, and does not access your contacts, location, microphone or camera. Photo access is limited to the pictures you explicitly select with the system photo picker.

Retention

Request logs are kept for up to 90 days. Stored analysis results, community content and creator applications are kept until you delete them or ask us to delete them, or until we remove them for violating the Terms. Subscription records are kept by Apple and RevenueCat as long as required for billing and accounting.

Part 2 - The SMVRank Website: Hosting & Server Logs

SMVRank is a web application served from standard server infrastructure. Like most web servers, basic technical request logs (such as IP address and timestamp) may be generated as part of normal operation, purely to keep the service running and secure.

Uploaded Face Photo (Website)

When you upload a photo for AI face analysis on the website, it is transmitted to the configured Google Gemini API for a one-time analysis of visible facial aesthetics. SMVRank does not permanently store your uploaded photo on its own servers.

The analysis result is embedded in a signed token that your browser holds for the rest of the calculator session (valid for up to 1 hour), so the photo does not need to be re-analyzed as you continue.

Separately, a compressed, intelligently-cropped copy of your photo may be kept temporarily in your browser's own session storage, purely so it can be shown back to you on your Face Card. This copy stays in your browser, is never uploaded anywhere beyond the one-time analysis above, and is cleared when you restart or close your browser session.

Calculated Results (Website)

Your Physical/Overall SMV result is calculated on our server from the inputs you provide and is stored in a signed, browser-only cookie for up to 2 hours, solely so your result survives the checkout redirect to and from Stripe. This cookie cannot be read or modified by you or anyone else without invalidating its signature.

Email Address (Website)

Before checkout, you are asked for an email address. It is kept in your browser's session storage and sent to our server only when you proceed to payment, so it can be passed to Stripe Checkout to prefill the payment email field. It is not currently used for newsletters, marketing, or any purpose beyond this.

Payment (Website)

One-time payments on the website are processed through Stripe Checkout. SMVRank does not directly handle or store your full card details - that data is handled by Stripe under its own privacy policy and security infrastructure.

Cookies & Browser Storage (Website)

SMVRank uses one strictly-necessary cookie (the signed result cookie described above) to let you unlock and view a result you have paid for, plus browser session storage for the temporary items described above. None of this is used for advertising or cross-site tracking, and SMVRank does not use any marketing or advertising tools.

Analytics (Website)

The website uses Vercel Analytics to measure aggregated usage, such as page views and visitor counts. It does not use cookies for this purpose and does not track you individually across other websites. The data is used only in aggregate to understand overall site traffic.

Processors

We rely on the following service providers, each of which processes data only as needed to provide their service: Vercel (hosting of the website and the app's API), Google (Gemini API for the AI analysis and assistant), Supabase (database for the app's community and request logs), RevenueCat (subscription status), Apple (App Store and In-App Purchase) and Stripe (website payments). Some of these providers process data outside the European Union under appropriate safeguards such as standard contractual clauses.

Children

SMVRank and the SMV app are intended for users aged 14 and older and are not directed at children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or request deletion of your data, to object to or restrict its processing, to data portability, and to lodge a complaint with a supervisory authority. Because there are no accounts, please include your community display name or the approximate time of the content or request in question so we can find the data. To delete everything stored for your installation (analysis results, community content, creator application), email us at the address below; we respond within 30 days.

Contact