BeforeCut

Privacy Policy

Last updated: July 17, 2026

BeforeCut is an AI hairstyle rehearsal app. This policy describes what data we handle, why we use it, where it is stored, how long we keep it, and how you can delete it.

  • No account, email, phone number, or Apple ID is required.
  • Your selfie is used to generate haircut previews and is deleted from our storage after 7 days.
  • OpenAI processes the selfie, visible face and hair features in that selfie, and prompts needed for hairstyle preview generation. The request passes through a gateway operated by BeforeCut.
  • No analytics SDKs, advertising SDKs, or tracking SDKs.
  • You can delete your device-linked data inside the app from Settings.

1. Data We Collect

Information you provide

  • A selfie photo, used to generate hairstyle previews on your face. This may include visible face geometry, facial proportions, hair shape, hairline, and shoulders as they appear in the image.
  • Your selected goal, length-change tolerance, and advisor chat messages, used to shape recommendations.
  • StoreKit purchase receipt data, used to verify unlock purchases with Apple and handle refunds.

Information generated on your device

  • A random device ID generated in the iOS Keychain, used to associate sessions with the same device without requiring an account.
  • An APNs push token, only if you grant notification permission, used to send a push when your previews are ready.
  • Your IP address transiently for rate limiting. It is not written to our database as a user profile.

Friend voting links

If you share a voting link, anyone with the link can pick one of the three haircut options. We store the selected option so we can show you group consensus. Voters do not need an account and do not type a name or comment.

2. What We Do Not Collect

  • We do not collect your Apple ID, email, phone, or legal name.
  • We do not scan your photo library beyond the selfie you choose.
  • We do not collect location, contacts, calendar, health data, or biometric identifiers.
  • We do not link your data across apps or websites for advertising.

3. Face Data and AI Processing

BeforeCut does not use Face ID, face recognition, face templates, or biometric identification. We do not identify who you are. We do not compare your face against other people.

When you choose or take a selfie and agree to send it, BeforeCut uses the visible face and hair information in that photo, including facial proportions, hairline, current hairstyle, and shoulders, only to generate haircut preview images and recommendation text for that consultation.

The selfie is uploaded to our backend, temporarily stored, and sent through a gateway operated by BeforeCut to OpenAI, L.L.C. OpenAI receives the selfie, visible face and hair features in that selfie, and hairstyle prompts to generate preview images and recommendation text. We do not send your device ID, APNs token, purchase transaction ID, or Apple account information to OpenAI.

BeforeCut deletes uploaded selfies from our storage after 7 days and generated images after 30 days. OpenAI states that API data is not used to train its models by default. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days unless longer retention is required by law or reasonably necessary to prevent harm. See OpenAI's API data controls. You can delete all device-linked data held by BeforeCut sooner from Settings in the app.

4. Third-Party Processors

  • OpenAI, L.L.C. processes the selfie, visible face and hair features in that selfie, and text prompts needed to generate hairstyle previews and advisory text. Requests pass through BeforeCut's self-operated gateway; that gateway does not use the content for another purpose.
  • Apple processes StoreKit purchases and APNs push delivery.
  • Cloudflare R2 stores uploaded selfies and generated images under opaque object keys.
  • BeforeCut's us-2 VPS hosts the backend API and web pages.

We do not sell your data or share it with advertising partners. We require these processors to provide the same or equivalent protection described in this policy and to process the data only to provide their contracted service, subject to applicable law.

5. Retention

  • Uploaded selfies: 7 days.
  • Generated preview and reference images: 30 days.
  • OpenAI API inputs and outputs: up to 30 days in abuse-monitoring logs under OpenAI's default API data controls.
  • Session metadata: kept so you can revisit results until you delete your data.
  • APNs push token: kept while valid and removed when Apple reports it as invalid.

6. Your Choices

You can delete your data at any time from Settings in the app. This removes your device record, sessions, proposals, votes attached to your share links, and corresponding media objects. You can also email us at noahjiang2@gmail.com.

7. Children

BeforeCut is not designed for children under 13. If you believe a child has used the app, contact us and we will delete associated data.

8. Security and Changes

We use TLS for traffic between the app, backend, and processors. Object storage keys are random and unlisted. If this policy changes materially, we will update the date above and, where appropriate, surface the change in the app.

9. Contact

Questions: noahjiang2@gmail.com