What happens to your selfie in an AI makeup app
Last updated:
Your selfie usually leaves your phone, and whether that is safe comes down to four questions most privacy policies never answer.
In most generative makeup apps your photograph leaves your phone. It is uploaded, handed to a company that runs the model, painted, sent back, and held somewhere until something deletes it. Whether that is safe comes down to four things the app either tells you or does not: whether the image leaves the device, who else gets it, whether it trains a model, and how long it is kept.
Privacy policies in this category rarely answer all four. The silence is the part worth reading.
The path a photograph takes
Six stages, in order. A policy can be silent about any of them and still sound reassuring.
- Capture. You take a selfie, or pick one from your camera roll, and it sits on your phone with nobody else holding a copy. The file also carries the time, the device model, and sometimes the GPS coordinates of where you were standing, depending on the platform and how the app receives it.
- Upload. A generative try-on sends that photograph to a server, because the models that paint photographic-quality makeup onto a face are run on servers rather than on phones. An on-device AR filter skips this step. That is the difference that matters most.
- The provider. The company whose app you installed is usually not the company running the model. The app passes your photograph to an inference provider, and often to a face-detection service before that. More than one company can touch a single photograph in the time it takes to paint one look.
- The return. A second photograph comes back. It is derived from your face, so under the GDPR's definition of personal data it is your personal data as much as the original was, and the same retention rules cover it.
- Storage. The uploaded photograph, the returned look and any face template computed along the way are three separate things, kept for three different lengths of time. Policies that name a retention period often name it for only one of them.
- Deletion. Something has to remove the files, on a schedule, including from backups. "You may request deletion" and "we erase this within seven days" are different commitments. One is a queue. The other is a clock.
The stage that surprises people is the third one. Checked on 22 August 2026, the top ten Google results for "virtual makeup try on" were all brand-owned try-on pages, Maybelline twice, then Urban Decay, Ulta GlamLab, Chanel, NYX, Jane Iredale, Too Faced, L'Oreal Paris and MAC, and every one of them runs on a Perfect Corp or ModiFace back end. The company whose logo is on the page is not the company handling your face. It does mean two policies to read. The second one is harder to find.
The four questions
Does my photograph leave my phone?
Answer this one first. If the photograph never leaves the phone, the other three questions shrink to almost nothing. An on-device AR filter tracks your face and paints colour onto the video frames locally, so the frames never touch a network. A generative try-on renders in the cloud, so the photograph is transmitted, and no amount of good intent changes that.
On-device processing has less to leak, because there is nothing sitting on a server to leak. It also cannot produce a finished photographic look, so the two are not two ways of doing the same job. If you want a complete look on your own face, you are uploading. The only question left is what the app does next, and an app that will not tell you which of the two it is doing has answered that already.
Who else gets my photograph?
Ask for names, not categories. "We may share your data with trusted third-party service providers" is the standard formulation and it commits to nothing. A policy that lists the providers by name, and states that they act on the app's instructions and may not use your images for their own purposes, has told you something you can check. One that does not has told you only that sharing happens.
Do AI makeup apps train on my photographs?
Distinct from sharing, and the question apps dodge most. You grant training use yourself, often through a broad content licence in the terms of service rather than in the privacy policy, phrased as a worldwide, royalty-free licence to reproduce and modify the content you upload for the purpose of improving the service. Read the terms as well as the policy. If a licence like that is present and nothing narrows it, your face is a training input whether or not the privacy page says so.
How long does an AI makeup app keep my photograph?
Look for a number and a trigger. A number without a trigger, such as "we retain data as long as necessary", is not a retention period. A useful commitment names both, in the shape of "erased within seven days of the deletion request" and "24 months after your last interaction".
The four questions, by type of app
| Question | On-device AR filter | Cloud generative try-on | How to check for yourself |
|---|---|---|---|
| Does the photograph leave the phone? | Usually no, frames are processed locally | Yes, the render happens on a server | Load the filter, then turn on airplane mode. If the overlay keeps tracking your face, that part is running locally |
| Who else gets it? | Often nobody, though analytics may still report events | The inference provider, sometimes a face-detection service before it | Look for named processors rather than "third parties" |
| Is it used to train a model? | Rarely relevant, there is nothing to collect | Depends on the contract with the provider | Search the terms of service for "license", "licence" and "improve" |
| How long is it kept? | Nothing to keep, unless you save the video | Uploads, looks and face templates may each have their own period | Search the policy for a number of days or months |
App Store privacy labels are a starting point rather than an answer. They are written by the developer, in Apple's own categories, and the data types Apple asks about do not include how long anything is kept.
What Looksmith answers
Looksmith is an iOS app from Mirable Labs, Inc. Looksmith is coming soon to iOS, and Mirable Labs publishes the privacy policy now at /privacy and the biometric retention schedule at /retention. The retention schedule is published in draft and marked as not yet in force, which is the honest state of a policy written before the app it governs. What follows is what those documents say, described rather than paraphrased into something stronger.
| Question | What the Looksmith documents say |
|---|---|
| Does the photograph leave the phone? | Yes. Looksmith renders on servers, not on the phone, and the in-app consent says so in those words |
| Who else gets it? | Providers acting as processors under written contract, barred from using your images for their own purposes. The privacy policy currently lists them by category, not by name |
| Is it used to train a model? | No. The retention policy bars Looksmith and its providers from using face data to train, fine-tune, benchmark or improve any model |
| How long is it kept? | Looksmith keeps your Likeness until you delete it, and destroys face data 24 months after your last interaction at the outside |
Does Looksmith train on my photographs?
No. The Looksmith retention policy states that Looksmith will not use your face data, or permit any provider to use it, to train, fine-tune, evaluate, benchmark or otherwise improve any model.
Apply this page's own test to Looksmith and one thing does surface. The Looksmith terms of service at /terms do carry a content licence, worldwide and royalty-free, to host, store, reproduce and modify your inputs "strictly for the purposes of operating and improving the Service for you". That is the clause shape the question above tells you to look for. What narrows it here is the retention policy, which rules out model training in so many words, and the fact that the licence ends when you delete the content. Read both, and judge the pair rather than either one.
Looksmith asks for a separate written consent before it processes your face into biometric features. That consent sits on its own screen rather than being folded into account setup, and you can withdraw it. A single checkbox covering account creation, marketing and biometric processing at once is a decision about installing the app. It is not a decision about your face.
How long does Looksmith keep my selfies?
Looksmith keeps your selfies as a Likeness, the reusable set of photographs your looks are painted onto, for as long as you keep it in your account, so that you are not uploading again for every look. The Likeness is the thing that persists.
Once a deletion trigger fires, stored copies are erased within seven days. Looksmith's outer bound is 24 months after your last interaction, or sooner if the purpose for collection has been satisfied. That bound covers your face data. Account, tax and diagnostic records outlive it, on the separate schedules the privacy policy names, and the retention policy at /retention is the single place the face-data timings are stated so that they cannot drift between documents.
How do I delete my Looksmith account and photographs?
When Looksmith ships, account deletion is in Settings then Account, and it removes your Looksmith account, your Likeness, your looks and your Bag. Deleting only your face data is a separate control, Settings then My Likeness then Delete, because Looksmith asks for biometric consent on its own screen rather than folding it into account setup.
Reading a policy in five minutes
Open the privacy policy and the terms of service side by side and search both for four strings: "days", "months", "train" and "license". Search "licence" as well, because a British-drafted document spells it that way. If those searches return nothing specific, the app has not answered the four questions, whatever the opening paragraph about taking your privacy seriously says.
Two more signals are worth the time. A policy that names its subprocessors has accepted an obligation it could have avoided. And a recent date at least tells you someone opened the document more recently than the app last changed.
None of this tells you whether the app is any good. Safety and quality are separate, and an app can fail either one on its own. But four searches take five minutes. Most people spend longer choosing which selfie to upload.
Looksmith renders a full makeup look onto your own face and lists the products it used. iOS, coming soon.
You’re on the list.