Last updated: May 14, 2026
This Privacy Policy describes how FaceLab ("we", "us", or "our") collects, uses, and protects your information when you use the FaceLab mobile application (the "App"). By using the App, you agree to the practices described below.
FaceLab uses your device's camera and TrueDepth sensor to capture photos and 3D face mesh data so the App can analyze facial features and generate AI-powered transformations.
To compute your facial-feature scores, photos you capture or upload are sent securely over HTTPS to OpenRouter (an API gateway at openrouter.ai), which routes the request to a multimodal AI model hosted by OpenAI. The model returns a JSON object containing numeric scores (eyes, jaw, cheekbones, etc.) and a short text summary. No AI-generated image is returned. The "Before / After" preview shown later in the app is your own captured photo, blurred and locked — not an AI transformation. Per OpenRouter's and OpenAI's published API policies, your inputs are not used to train models, and we do not retain a copy of your photo on our servers beyond the time needed to deliver the JSON result.
We may collect non-personal information to help us improve the App, such as:
In-app purchases and subscriptions are handled by Apple. We receive a transaction identifier and subscription status, but we never receive your payment card or Apple ID password.
Because face data is sensitive, this section provides a complete account of how FaceLab collects, uses, stores, and retains it. Anchor: #face-data.
What face data the App collects. When you tap "Start Scan" the App uses Apple's ARKit framework on devices equipped with a TrueDepth camera to:
ARFaceAnchor.geometry). FaceLab does not request or use Apple's face-blendshape coefficients, expression data, gaze tracking, lookAtPoint, or any identifying biometric template, and does not perform face recognition.Purpose of collection. The App uses face data solely to:
Face data is never used for advertising, identity verification, biometric authentication, training third-party AI models, or any purpose other than the features above. The "Before / After" preview shown on the final-sell screen is your own captured photo, blurred and overlaid with a lock icon — not an AI-generated transformation.
Sharing with third parties and storage location.
openrouter.ai/api/v1/chat/completions), which acts as our API gateway and routes the request to a multimodal AI model hosted by OpenAI. The model returns JSON containing numeric scores and a short text summary; no image is returned. Per OpenRouter's and OpenAI's published API policies, your inputs are not used to train models. API inputs may be retained by the processor chain for up to 30 days for abuse-monitoring purposes and are then deleted. FaceLab itself retains no copy of the photo on our servers after the JSON result is returned to your device.Retention.
Where in this policy face data is covered. Face data is described in this Section 1.5 and is also referenced in Section 1.1 (Photos and Face Data), Section 1.2 (AI Processing), Section 3 (Data Sharing), and Section 4 (Data Retention). The text quoted above is the controlling, authoritative description of FaceLab's face-data handling.
We do not sell your personal information. We share limited data only with the following service providers, and only as necessary to operate the App:
openrouter.ai) — API gateway that receives the still photo and routes it to OpenAI's multimodal model for facial-feature scoring. Returns JSON only; no image is returned.We may also disclose information if required to do so by law or to protect the rights, property, or safety of FaceLab, our users, or others.
Photos and face data captured in the App are stored on your device and remain there until you delete them or uninstall the App. Still photos sent to the OpenRouter → OpenAI processor chain for analysis may be retained by that chain for up to 30 days under its abuse-monitoring policy and are then deleted. FaceLab's own servers retain no copy of your photos or mesh data after the JSON result is returned. See Section 1.5 for the complete face-data retention statement.
We use industry-standard safeguards, including HTTPS for data in transit and Apple's secure storage APIs for data at rest. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
FaceLab can be used worldwide. If you use the App from outside the country where our servers and processors are located, your information may be transferred to and processed in that country.
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Significant changes will be communicated through the App or the App Store listing.
If you have questions about this Privacy Policy, contact us at sahindhamzani@gmail.com.