Lookrank Privacy Policy
Last Updated: 2 August 2026
Entertainment product: Lookrank analyzes photos and generates appearance-related scores and visuals for entertainment and informal informational purposes only. It is not medical, psychological, or professional advice. See our Terms of Service for full disclaimers.
This Privacy Policy explains how Intelligent Vision LLC (“Lookrank,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use our websites, mobile apps, and related services (the “Service”).
We do not sell your personal information for money. We use personal data to provide the Service, security and abuse prevention, analytics, referral attribution, crash diagnostics, payments, and communications as described below. We do not use your data to build advertising profiles for unrelated third-party marketers.
Privacy Summary
- Under 13: No access. We do not knowingly collect data from children under 13.
- Ages 13–17: Limited accounts only (private profile; not eligible for public voting/leaderboard participation). See Section 11.
- Photos: Used to generate entertainment AI scores and optional generative visuals; retention depends on guest vs profile use (Section 7).
- Public sharing: Controlled by your privacy settings and age limits.
- Deletion: Available in-app / via our Account Deletion page and by emailing [email protected].
By using the Service, you acknowledge this Policy. Where consent is required by law for a specific processing activity, we will request it.
Return to Lookrank Homepage · Terms of Service
1. Who We Are
Lookrank is operated by Intelligent Vision LLC, a Wyoming limited liability company, 30 N Gould St Ste R, Sheridan, WY 82801, USA. Privacy requests: [email protected].
2. Information We Collect
a) Information you provide
- Account data: Email address, password (stored by our auth provider in hashed form), display name, and sign-in identifiers if you use Google sign-in.
- Profile & onboarding data: Gender, age bracket, privacy preferences, goals/preferences you select in onboarding, optional Instagram handle, and similar settings.
- Photographs: Photos you upload for profile, analysis, voting eligibility (where allowed), split tests, or related features. We may also store derived image data such as compact blur placeholders (thumbhashes) for faster loading.
- Community content: Votes, written feedback/tips, reports, and other messages you submit.
- BMI calculator inputs: Height, weight, and related calculator fields stay on your device. We do not upload them to our servers.
- Support communications: Content of emails or support requests.
- Payment-related data: We do not store full payment card numbers. App stores (e.g., Google Play) or Stripe process payments. We may receive transaction metadata (amount, date, subscription status, customer/purchase identifiers) needed to fulfill Pro access.
- Marketing consent records: If you opt in to marketing, we store evidence of that consent.
b) Information generated by the Service
- AI analysis results: Entertainment scores, textual assessments, rankings/percentiles, and related insights derived from your photos and/or community data.
- Generative visuals: Synthetic images or suggestions (e.g., stylized appearance, look-alike, hairstyle ideas) created from your inputs.
- Social/feature metrics: Leaderboard position (if eligible), similar-user matches, XP/daily goals, referral progress, Pro entitlement flags.
- Pro feature usage / progress data: Pro Path habit plans, completions, skips, and cycle progress, plus other Pro feature usage needed to run those features.
c) Information collected automatically
- Device & usage data: IP address, approximate region/country (from IP or CDN headers), device/browser type, app version, OS, pages/screens viewed, timestamps, diagnostic logs, and similar technical data.
- Device/session identifiers: App- or browser-generated identifiers stored locally (for example, for referral attribution, paywall experimentation, rate limiting, and abuse prevention). Some of these identifiers are also stored in our database with paywall and experiment event logs.
- Security / bot-prevention data: Tokens and related signals from Cloudflare Turnstile (or similar) when you sign up or sign in.
- Crash and performance diagnostics: We use Sentry to collect crash reports, stack traces, performance traces, and related diagnostics. We may associate diagnostics with an internal user id (not your email) so we can debug account-specific crashes.
- Product analytics: We use PostHog in the app to collect event data such as onboarding progress, screens/tabs viewed, votes submitted, share/referral actions, paywall and purchase funnel steps, and similar product interactions, plus device/app metadata (OS, app version, platform). Paywall-related events may include entertainment score values or coarse score buckets (for example AI score or estimated potential gain), not photos. When you are logged in we may associate events with an internal user id. We do not send your email, password, or photographs to PostHog. You can turn product analytics off in Settings.
- Paywall and experiment event logs: We also store paywall funnel and experiment events on our servers (including device/session identifiers and, where relevant, score or score-bucket fields used for conversion analysis).
- Cookies / local storage / SDKs: On web and in apps we use cookies, local storage, and software development kits for auth sessions, preferences, security, analytics, and reliability.
d) Face and appearance-related processing (important)
When you upload a photograph of your face or appearance, we process that image to provide the entertainment Service. This may include automated analysis of visual appearance characteristics to generate scores, assessments, and generative entertainment visuals.
- This processing is for entertainment scoring and product features, not for government ID verification, device unlock, or law-enforcement biometric identification.
- We do not create or retain biometric templates for identification (for example, we do not store faceprints used to uniquely identify you across unrelated contexts). We store the photographs you upload and derived entertainment outputs (scores, assessments, generative visuals) according to the retention rules in Section 7. Profile/account images are retained until you delete your account (or request deletion), not on a short auto-delete timer.
- We describe categories of processors below (including cloud AI/processing providers). We do not publicly disclose proprietary model architectures, prompts, thresholds, or internal pipeline details.
3. How We Use Information
- Provide, operate, personalize, and improve the Service (analysis, profiles, voting, leaderboards, Pro features, generative visuals).
- Create and secure accounts; authenticate users; prevent bots and abuse (including Turnstile and rate limits).
- Process subscriptions and restore entitlements (Google Play, Apple where applicable, Stripe/web).
- Run product experiments (e.g., paywall variants) and understand feature usage, including paywall and experiment event logs stored on our servers.
- Attribute referrals and prevent referral fraud.
- Send transactional emails (reports, receipts, security, support). Send marketing only with required consent/opt-out.
- Moderate content; handle reports/blocks; protect safety and legal rights.
- Monitor reliability and fix bugs (including Sentry crash reporting).
- Measure product usage and run experiments with PostHog (for example conversion and retention analysis), subject to your analytics preferences where offered.
- Comply with law and enforce our Terms.
- Create aggregated or de-identified statistics that do not reasonably identify you.
We do not use your uploaded images to train public foundation models for unrelated third parties. We may use aggregated/de-identified signals or limited internal evaluation under contractual controls with our processors to operate and improve Lookrank’s entertainment features. If that practice changes in a material way, we will update this Policy.
4. Legal Bases (EEA / UK and similar regimes)
Where GDPR/UK GDPR applies, we rely on:
- Contract: To provide the Service you request (account, analysis, Pro features you buy).
- Consent: Where required (e.g., certain marketing; certain sensitive-data processing where consent is the appropriate basis). You may withdraw consent without affecting prior lawful processing.
- Legitimate interests: Security, abuse prevention, referral fraud prevention, product analytics, crash diagnostics, service improvement—balanced against your rights.
- Legal obligation: Where we must retain or disclose information to comply with law.
Where we process special-category or biometric-like data under applicable law, we do so only as needed to provide the Service you request and/or with consent where required, and with appropriate safeguards.
5. How We Share Information
a) Other users (according to age + privacy settings)
If you are eligible and choose public or voters-only visibility, other users may see information such as display name, photos, scores, rank, and related profile content. Written vote feedback may be shown to the person rated. Users under 18 are limited as described in Section 11.
Profile/analysis data may sync across our website and apps.
b) Service providers (processors)
We share data with vendors who help us run the Service, under contractual obligations to use data only for our instructions:
- Supabase: Authentication, database, file storage, and backend functions. Our primary application database is hosted in the European Union (EU).
- Google: Account authentication (Google sign-in, where used) and cloud AI / machine-learning processing used to help generate entertainment analysis and related outputs from images you submit. We do not publicly itemize every Google product SKU or model name.
- Cloudflare: CDN, security, and Turnstile bot protection.
- Sentry: Crash reporting, performance monitoring, and error diagnostics (may include an internal user id when you are logged in; not your email).
- PostHog: Product analytics and experimentation in the app (event data and an internal user id when you are logged in; not your email). Hosted in the EU for our project.
- Stripe: Web/payment processing for applicable purchases (card data handled by Stripe).
- Google Play / Apple: In-app purchases and subscriptions billed through the applicable store; they process payment details under their policies.
- Mailjet: Transactional and (where consented) marketing email delivery.
- Simple Analytics: Privacy-oriented website analytics.
- Netlify: Website hosting/deployment.
- Other infrastructure providers we engage from time to time for hosting, storage, networking, or similar operations, bound by appropriate contracts.
c) Legal, safety, and business transfers
- To comply with law, lawful requests, or legal process.
- To protect rights, safety, and security of Lookrank, users, or the public.
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and notice where required.
d) No sale of images for ads
We do not sell your photos or scores as a standalone product to data brokers, and we do not license your identifiable photos for third-party advertising.
6. International Transfers
Your information may be processed in the EU, United States, and other countries where we or our providers operate. Our primary database is in the EU. Where we transfer personal data from the EEA/Switzerland/UK to countries without an adequacy decision, we use appropriate safeguards such as Standard Contractual Clauses (or UK IDTA/Addendum equivalents) where required.
7. Retention
| Data |
Typical retention |
| Guest / standalone analysis images |
Deleted from active systems within about 72 hours after delivery or cancellation, unless a longer premium-processing window (up to ~30 days) was disclosed for that product |
| Profile photos, scores, history, votes, feedback linked to an account |
Until you delete your account or we delete it for violation/inactivity/law, then removed from active systems within a reasonable period |
| Account email and Pro entitlement metadata |
For the life of the account; limited records may remain for accounting, fraud, and legal compliance |
| Referral / abuse / rate-limit logs (IP, device/session ids, email) |
Typically up to ~90 days, longer if needed for security incidents or legal holds |
| Sentry diagnostics |
According to our Sentry retention settings (generally limited months); contact us for details |
| PostHog product analytics events |
According to our PostHog project retention settings (generally limited months); contact us for details |
| Aggregated / de-identified analytics |
May be retained indefinitely |
| Deletion audit evidence (e.g., hash/timestamp logs) |
Up to six (6) years where needed for compliance |
Backups may retain residual copies for a commercially reasonable period before rotating out.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data (including encryption in transit and access controls). No method of transmission or storage is 100% secure. You are responsible for safeguarding your password and device.
9. Your Choices and Controls
- Privacy / visibility settings (subject to under-18 limits).
- Access to camera/photos: OS permission controls; denying permission limits photo features.
- Marketing opt-out: Unsubscribe links or email us.
- Product analytics opt-out: In-app Settings → Privacy & Analytics (disables PostHog event capture on that device). You may also email [email protected] to object to analytics processing where applicable law provides that right.
- Account deletion: In-app Settings and lookrank.com/delete-account, or email [email protected].
- Store subscriptions: Manage/cancel in Google Play or Apple subscription settings.
10. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent. Email [email protected]. We may need to verify your request. We respond within timeframes required by law (often within 30 days where GDPR applies).
EEA / Switzerland
You may lodge a complaint with a supervisory authority where you live or work. See the EDPB members list: edpb.europa.eu.
United Kingdom
UK GDPR / Data Protection Act 2018 rights apply. Complaints: ICO.
California / U.S. state privacy rights
If you are a resident of California or another U.S. state with consumer privacy law, you may have rights to know/access, delete, correct, and opt out of “sale” or “sharing” of personal information as those terms are defined by law. We do not sell personal information for money. We also do not knowingly “share” personal information for cross-context behavioral advertising as a core business practice. If you believe a right applies, contact [email protected] with the subject line “Privacy Request.” We will not discriminate against you for exercising privacy rights.
Sensitive information: Photos of your face and face-related analysis may be considered sensitive under some laws. We use this information to provide the Service you request. You may request deletion as described above.
Automated processing
Scores and rankings are automated entertainment outputs. They are not used by us to make legal or similarly significant decisions about you (such as credit, employment, insurance, or housing). Do not treat them as such.
11. Children Under 13; Users Under 18
Under 13 — no access
The Service is not directed to children under 13, and they may not use it. We do not knowingly collect personal information from children under 13. If you believe a child under 13 provided data, contact us immediately; we will delete the data and terminate the account.
Ages 13–17
Users aged 13–17 may use limited account features if they accurately declare their age and comply with our Terms. For these users we:
- Treat profiles as private;
- Do not make them eligible for public community voting/leaderboard participation reserved for eligible adult public profiles;
- Still process photos and account data as needed to provide available entertainment features and security.
Parents/guardians may contact [email protected] to request deletion of a minor’s account. Misrepresenting age violates our Terms and may result in deletion.
12. Third-Party Links and Platforms
The Service may link to Instagram, app stores, or other sites. Their privacy practices are their own. Authentication or payment via Google, Apple, or Google Play is also subject to those companies’ policies.
13. Changes to This Policy
We may update this Policy by posting a new version and changing the “Last Updated” date. Material changes may also be noticed in-app or by email where appropriate. Continued use after the effective date means you acknowledge the updated Policy.
14. Contact Us
- Email: [email protected]
- Postal: Intelligent Vision LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA
This Privacy Policy was last updated on 2 August 2026.