How to tell if a beauty app is safe with your photos
Last updated:
A beauty app is safe with your photographs when five checks, done in about ten minutes, turn up clear answers instead of silence.
A beauty app is safe with your photographs when five checks, done in about ten minutes, turn up clear answers instead of silence. Check the App Store privacy label, the stated retention period, the plain answer on training, the in-app way to delete, and whether processors are named rather than described in categories. This page runs all five, then runs them again against Looksmith itself.
The ten-minute checklist
Run these five checks in this order, before the photograph leaves your phone. Each one has a shape a good answer takes and a shape a bad one takes, and most apps in this category will show you both kinds somewhere in the same policy.
| Check | Good answer looks like | Bad answer looks like |
|---|---|---|
| App Store privacy label | Sensitive Info or User Content checked, filed under Data Linked to You | Nothing checked, for an app that plainly uploads a face |
| Retention period | A number and a trigger, such as "erased within 7 days of deletion" | "As long as necessary," or no mention at all |
| Training on your images | A plain sentence ruling it in or out, stated in the policy itself | No mention, or a broad licence to "improve the Service" with nothing narrowing it |
| Deletion | A control inside the app, under Settings | An email address and a promise to "process your request" |
| Processors | Named companies, or a statement that they act only under contract | "Trusted third-party service providers" |
What does the App Store privacy label actually tell you?
Every iOS app carries a label on its product page, called App Privacy, and it sorts what a developer says it collects into named categories: Contact Info, Health & Fitness, Financial Info, Location, Sensitive Info, Contacts, User Content, Browsing History, Search History, Identifiers, Purchases, Usage Data, Diagnostics, Surroundings, Body and Other Data. A photograph of your face belongs under Sensitive Info, which Apple's own definition names as covering biometric data specifically, and usually under User Content as well. Each category then sits in one of three buckets on the product page: Data Used to Track You, Data Linked to You, or Data Not Linked to You. A face-rendering app that recognises you across sessions should be filing under Linked, not Not Linked, and if it is filing under Not Linked at all you have found something worth a second look.
What the label does not ask for is the part you actually need. Apple's developer guidance defines collecting as transmitting data off the device in a way that lets the developer, or a partner, keep reaching it for longer than the request in front of you needs. Nowhere does it require a developer to state how long that data is kept, or whether it trains a model on it. The label tells you what kind of thing leaves your phone. It was never built to say for how long, or toward what, beyond the one feature you asked for. Treat it as the first of the five checks, not the whole answer.
What does it mean if the retention period is missing?
Search the policy for a number, in days, months or years, attached to your photographs specifically. If none turns up, that is not an oversight you should forgive, because a company that has decided how long it keeps a photograph of your face has already written that number down somewhere for its own engineers to build against. "We retain data as long as necessary to provide the service" is not a retention period. It is a sentence that defends any length at all, including forever, and it would survive unedited whether the real answer was thirty days or never deleted. Treat the absence of a number as the answer: the company has either not decided, or has decided not to say.
Is training on your photographs addressed at all?
Most privacy policies in this category say nothing about training, in either direction, and that silence is worth noticing on its own before you go looking for a specific promise. A policy does not need to swear it never trains on your images. It needs to say something, because when a policy is quiet here the terms of service usually carry a broad content licence that covers the same ground without naming it. Search the privacy policy and the terms for "train," "improve" and "licence," spelled the British way too. If none of the three turns up anywhere in either document, you have not ruled anything out. You have found a pair of documents written before anyone thought to ask.
Is email-only deletion a warning sign?
Not automatically, but it is friction placed between you and your own photograph on purpose. A control inside the app removes the file when you tap it, and you can watch it happen. An email address routes the same request through a person, a queue and a promised response window, and the company you are trying to leave is the one setting how long that window is. Open the settings screen before you upload anything and look for a delete control with your photographs named on it specifically, not folded into a generic "manage my data" link. An email-only route is not by itself a reason to stop. It is a second question worth asking about how quickly the company wants you gone.
Why does it matter whether an app names its processors?
Because "trusted third-party service providers" describes every company in this category equally and commits none of them to anything. A policy that names the cloud host, the company running the model, and the analytics vendor has accepted an obligation anyone can check against those companies' own published terms. A policy that stops at "processors" and "providers" has told you a category exists without telling you who is in it, which is the gap between a claim and a name.
Running the checklist on Looksmith
Looksmith is the app this page exists to explain, so it should pass its own checklist or say plainly where it does not. Here is that checklist, run against the Looksmith privacy policy and the biometric retention policy it links to, both current as of this page's publish date.
| Check | What Looksmith's documents say |
|---|---|
| App Store privacy label | Nothing to check yet. Looksmith is coming soon to iOS and has not published a listing |
| Retention period | Stated, with a number and a trigger for six separate cases |
| Training on your photographs | Addressed directly, and ruled out, in the privacy policy itself |
| Deletion | In-app, with email offered as a second route rather than the only one |
| Processors named | No. Categories only |
Looksmith erases stored copies of your Likeness within 7 days of you deleting it, and starts that same 7-day window 24 months after your last interaction if you simply stop using the app. That schedule sits in a retention document that is itself marked as a draft, not yet in force. Looksmith addresses training in the privacy policy in plain language, stating that it does not train its own models on your photographs, your face data or your generated looks, and does not permit its providers to either. On deletion, Looksmith stops using your Likeness immediately when you tap Settings, then My Likeness, then Delete, and erases the stored copies within 7 days; deleting your whole account works the same way from Settings, then Account. Email is offered too, but it is not the only route out.
The unflattering part sits in the checklist's last row. Looksmith's privacy policy lists the companies that touch your photograph by category, cloud hosting, the AI providers, authentication, analytics, support tooling, email delivery, rather than by name. Looksmith's own retention policy is candid about a related gap in writing most companies would leave unstated: it says plainly that the processor list does not yet name the storage provider, and that the app does not yet link to the retention page from its own settings screen. Both are true as of the date on this page. A document that admits what it has not finished is a better sign than one that reads as complete and is not, but it still fails the processor check above, and it is fair to hold it to that.
Should a policy marked "draft, not yet in force" count as passing?
Only partly. A retention schedule with real numbers in it, published inside a document that says it is not yet in force, is further along than a policy that names no numbers at all, because someone has done the arithmetic and written down what they intend to be held to. It is not the same thing as a policy that has already taken effect. Read Looksmith's retention schedule as a stated intention rather than a finished answer, and check again once the document drops the word draft.
Run the five checks in that order, in that amount of time, on any app before the photograph leaves your phone. A star rating tells you whether people liked how the app looked. A retention number, a named processor and a delete control under Settings tell you what happens to your face after you close it, which is the part a rating was never built to answer.
Looksmith renders a full makeup look onto your own face and lists the products it used. iOS, coming soon.
You’re on the list.