Privacy policy
Boirelle asks for a photograph of your face. That deserves a plain answer about what happens to it.
Last updated 18 August 2026
Who we are
Boirelle is operated by Defo Labs LTD, the data controller for everything described here. For anything on this page, write to privacy@boirelle.com.
The short version
- There is no account. We do not ask for your name or your email.
- Your selfie is analysed and then discarded. We do not keep it.
- We never sell your data, and we never use your face to train anything.
- This marketing site sets no analytics or advertising cookies.
Your selfie
Before your photo leaves your device it is scaled down to 1024 pixels on its longest edge and re-encoded. That smaller version is sent over an encrypted connection to our analysis endpoint, where it is passed to a vision model, read, and then dropped. It is not written to a database, not written to object storage, and not retained after the request finishes.
What we do keep, briefly, is the result — the seven readings and the summary sentence. That is held in server memory for up to thirty minutes so that changing your occasion or your time budget does not require analysing the photo a second time. It contains no image. After thirty minutes it is gone.
On iOS, the app saves your session — the selfie, the reading and the routine — inside its own storage on your phone, so you can look back at it. That copy never leaves the device, is not synchronised to us, and is deleted when you delete the app.
On the web, your reading and routine are kept in your browser’s local storage so you can return to them. Your selfie is not. Clearing your browser data removes them.
What else we process
- An install identifier. The iOS app sends a per-install identifier so we can rate limit fairly. It is not an advertising identifier, it is not linked to you, and it changes if you reinstall.
- Your IP address. Used to rate limit and to keep the service standing up. Not used to profile you.
- Your language setting. So the routine comes back in a language you read.
- Payment records. See below — we never see your card.
Cookies
The web app sets exactly one cookie: a signed, httpOnly cookie recording that you have unlocked your routine. It holds the payment reference and the time it was granted, nothing else, and it is signed so it cannot be edited. It is strictly necessary for the thing you paid for, so it does not require consent.
This marketing site sets no cookies at all.
Payments
Purchases in the iOS app are processed by Apple. Purchases on the web are processed by Stripe. Both handle your card details directly — those details never reach our servers. We receive only a confirmation that a payment succeeded and a reference for it.
Who else touches your data
- Anthropic — provides the vision model that reads the photo. The image is sent for analysis and is not used to train models.
- Stripe — payments on the web.
- Apple — payments in the iOS app.
- Our hosting provider — runs the servers the API answers from.
These are processors acting on our instructions. Nobody else receives your data, and we do not sell it to anyone under any circumstances.
Where your data goes
Processing may take place outside your country, including in the United States. Where that happens, transfers are covered by the appropriate safeguards, such as Standard Contractual Clauses.
Our legal basis
- Performing our contract with you — analysing your photo and building your routine is the thing you asked for.
- Legitimate interests — rate limiting and keeping the service secure and available.
- Legal obligation — keeping records of sales.
A photograph of a face can constitute biometric data where it is used to identify someone. Boirelle does not do that: it reads visible surface qualities of skin and features. It does not build a faceprint, it does not match you against any database, and it cannot recognise you in another photograph.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. Write to privacy@boirelle.com and we will answer within one month.
Because there is no account, the fastest deletion is in your own hands: delete the iOS app, or clear your browser storage for the web app. That removes everything held about you locally, and the server holds nothing beyond the thirty-minute window described above.
If you are unhappy with how we have handled your data, you have the right to complain to your local data protection authority.
Children
Boirelle is not intended for anyone under 16, and we do not knowingly process their data. If you believe a child has used it, write to us and we will act.
Changes
If this policy changes in a way that matters, we will change the date at the top and say so in the app.