Privacy
Last updated 17 September 2026
1. Who we are
FreshCutz is made by Take 220 Productions LLC, and this policy covers the app, the website at getfreshcutz.com, and everything attached to them. We are the ones responsible for your information, and you can reach us at info@getstarrd.app.
The short version, because you deserve it before the detail: FreshCutz reads a photo of your face to work out what suits you, and renders haircuts onto it. Reading your face means handling what some laws call biometric data, which is why we ask before the first read rather than burying it here. Section 4 is the one to read.
2. What we collect
Your photos
Two of them — a front view and a profile. We store them so we can render cuts onto them and so your finished cuts are still there when you come back. We also derive a reading of your face from them: face shape, hairline, hair type and density. That reading is what sorts the catalog for you.
Your renders
Every cut we render for you, kept against your account so your history survives closing the app.
Your phone number
You sign in with your mobile number and a one-time code sent by text. We store the number to identify your account, send those codes, and stop people abusing the free read. We do not collect your name, your email or your address, because nothing here needs them. Login texts may arrive branded “Starrd AI Apps” — that is us, see section 11.
What you bought
The product, the amount, the date and a transaction identifier. Never your card number — see section 6 for who handles that.
How you use the app
Device type, operating system, app version, and which screens and cuts you looked at. We use it to see what is working and fix what is not. On the website this is measured by Vercel Analytics, which is cookieless and aggregate — there is no advertising cookie here, no cross-app tracking, and nothing to consent to because there is no non-essential cookie to set. The only cookies we set are the ones that keep you signed in.
3. What we do with it
- Read your face and sort the catalog to it.
- Render the cuts you pick.
- Sign you in and keep your account yours.
- Take payment and keep your receipts.
- Answer you when you write in.
- Work out what is broken and what nobody uses.
- Stop fraud, abuse, and people farming free reads.
- Do what the law requires of us.
That is the whole list. We do not use your face to advertise to you, and we do not build a profile of you to sell.
4. Your face, and the law about it
Working out your face shape, hairline and hair type means processing what Illinois, Texas and Washington — and the GDPR, in its own words — treat as biometric data. Illinois in particular requires us to publish what we do with it and how long we keep it. This is that.
- We ask first. Nothing leaves your device until you agree, on a screen that says where it goes. We keep a dated record of that agreement. You can say no; you just will not get a read or a cut, because there is nothing to render without it.
- Only to cut your hair. We use it to read your face and render your cuts. We do not use it to identify you, we do not match it against anyone else, we do not train anything of our own on it, and we do not sell it.
- How long we keep it. Your photos and the reading taken from them are kept while your account is open and you are still using it. We destroy them when the reason we collected them has been met, or within three years of the last time you used FreshCutz, whichever comes first. Deleting your account does it immediately — see section 11.
- It has to be your face. Upload photos of yourself, or of someone who has told you it is fine. Never a photo of anyone under 18.
- You can take it back. Write to info@getstarrd.app and we will delete the reading and the photos it came from. In practice that means deleting the account, because we cannot render a cut without them.
5. Why we are allowed to (EEA and UK)
If you are in the European Economic Area or the UK, these are the legal bases we rely on under the GDPR and UK GDPR:
- Contract — to make your account, take your photos, and render the cuts you asked for.
- Explicit consent — for the face data specifically. It is special-category data under Article 9, and Article 9(2)(a) consent is the only basis we rely on for it. You can withdraw it at any time.
- Legitimate interests — to keep the service up, stop abuse, and understand what is worth building, weighed against your rights.
- Legal obligation — when the law requires it of us.
6. Who else touches your photos
These are everyone. Each has its own privacy policy covering what it does on its own systems, and this list is current as of the date at the top of this page.
- Supabase (running on AWS) — holds your account, your photos and your renders.
- Vercel — hosts the website and measures aggregate traffic.
- Twilio — delivers the one-time codes to your phone.
- hCaptcha (Intuition Machines) — checks you are a person before we send a code, so nobody can run our SMS bill up.
- Anthropic — reads your two photos to work out what suits you. This is the free read, and it is the first thing that sends your face anywhere.
- OpenAI — its image model puts each cut onto your face. We reach it through our API gateway Kie.ai, which carries the image between us and deletes what passes through it within fourteen days.
- Stripe — takes card payments on the web.
- Apple and RevenueCat — take and track payments in the app.
The ones handling your face get it for one job and nothing else. We use only providers whose terms hold your photos to a standard equal to our own — kept confidential, used solely to carry out the job we sent, and passed to nobody else — and we authorise none of them to train on your face. Anthropic and OpenAI, whose models actually see it, do not train on what comes through their APIs; Kie.ai, which carries the render between us and OpenAI, deletes generated media within fourteen days and its logs within two months.
Those are their published commitments and ours to enforce, not ours to make on their behalf — each company’s own policy is the document that binds it, and we would rather point you at them than promise you something we are not the ones keeping.
7. Where it goes
We are in the United States and your account lives there. Your photos also travel to the companies in section 6. Those companies are based in the United States, and they — or the infrastructure they run on — may process or store what you send in other countries.
Those places protect data differently, and sometimes less, than where you live. Where the law requires a safeguard for taking data out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses. Agreeing to the read is agreeing to these transfers, because there is no way to render your cut without them.
8. How it is kept
Everything is on Supabase, on AWS. Traffic is encrypted in transit. Your account rows are guarded by row-level security, so one person’s query cannot reach another person’s data, and your uploads sit in a private bucket only you can list.
One thing worth being straight about: finished renders are served from a public bucket. The addresses are long and random and we never publish them, but a person holding one can open it without signing in. That is how the image reaches your barber’s phone when you share it. Treat a render URL like the photo it is.
We take reasonable care, and no system is perfectly secure. We are not going to pretend otherwise.
9. What we never do with it
We do not sell your information, and we do not share it for advertising — including in the specific senses California law gives those two words. Your face is not a product. The only times anything leaves us are:
- To the companies in section 6, to run the service.
- When the law, a court, or a lawful government request requires it.
- To protect someone — you, another user, us, or the public — from real harm.
- If the company is ever sold or merged, in which case your information moves with it and this policy travels with your information.
10. How long we keep things
- Photos and the face reading — while your account is open, and no longer than the schedule in section 4.
- Your renders — while your account is open.
- Your account — until you delete it.
- Receipts — as long as tax and accounting rules make us, which is longer than the rest.
After a deletion, copies can survive in encrypted backups for a short while before those roll over. We may also keep a one-way fingerprint of a deleted phone number so the same number cannot farm the free credits again.
11. Deleting everything
There is a Delete account button on your account page, in the app and on the web. It removes your photos, every cut we rendered, your receipts and any credits left over. It cannot be undone and we keep no copy.
One thing worth knowing before you press it: your account is shared with our other apps. If you also use Starrd or ModMyCar, the same sign-in covers all three, and deleting takes everything with it — not just your haircuts.
You can also withdraw your agreement to face processing at any time by writing to us. Without it we cannot render a cut, so in practice that means deleting the account.
12. What you can ask us for
Depending on where you live, you can ask us to show you what we hold on you, correct it, delete it, hand you a portable copy, stop or limit what we do with it, or take back a consent you gave — the face one included. You can ask us to stop selling or sharing your information, though we do not do either. We will not treat you worse for asking.
Most of it you can do yourself on the account page. For the rest, write to info@getstarrd.app. We will check it is really you, and answer inside whatever time the law where you live allows us. You can send someone else to ask on your behalf. If you are in the EEA or UK and we handle it badly, you can complain to your national data protection authority.
13. If you live in California
In the last twelve months we have collected these categories of personal information:
| Category | What it is | Why |
|---|---|---|
| Identifiers | Phone number, account ID | Signing you in, support |
| Sensitive personal information | Photos of your face and the reading taken from them | Reading your face and rendering cuts, with your consent |
| Commercial information | What you bought and when | Payment and receipts |
| Internet and device activity | Device, OS, app version, screens viewed | Running and improving the app |
| Your content | Your photos and your renders | Giving you the thing you came for |
You have the right to know, delete and correct, to opt out of sale or sharing, and to limit what we do with sensitive personal information. We do not sell or share, and we already limit the sensitive category to the one purpose in section 4. We honour the Global Privacy Control signal your browser sends. To use any of this, write to info@getstarrd.app.
14. Under 18
FreshCutz is not for children. You need to be 18 to have an account, and you must never upload a photo of anyone under 18 — not your son, not your little brother, not as a joke. Rendering a haircut means processing a face, and a child’s face is not ours to process.
If we find out we are holding a child’s photo or a child’s face data, we delete it as soon as we know. Tell us at info@getstarrd.app if you think we have.
15. If this changes
We will post the new version here with a new date at the top. If a change is material — especially anything touching section 4 — we will say so, and where the law requires it we will ask for your consent again rather than assume it. Carrying on using FreshCutz after a change means you accept it.
16. Contact
Take 220 Productions LLC — info@getstarrd.app. A person reads it.