Before you publish this: this document is a starting template, not legal advice. Replace every bracketed placeholder, confirm the sections match what your app actually does, and have a lawyer review it — particularly the photo, health-adjacent data, AI processing and retention sections, and your obligations under India's Digital Personal Data Protection Act, 2023.
1. Who we are
HairGro ("HairGro", "we", "us") is a mobile application operated by [YOUR COMPANY PVT LTD], a company registered in India with its registered office at [REGISTERED ADDRESS], CIN [CIN].
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for the personal data described here. If you are in the United Kingdom or the European Economic Area, we act as the data controller under the UK GDPR / EU GDPR.
This policy explains what we collect when you use the HairGro app or this website, why we collect it, and what you can do about it.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Your mobile number, the one-time passcodes used to verify it, and your account creation date. | You, at sign-up |
| Scan images | Photographs of your scalp and hair that you capture or upload. | You, when you scan |
| Analysis results | Your hair health score, sub-scores, detected findings and the change in these over time. | Generated by us |
| Profile details | Optional information you choose to give us — age range, gender, hair type, medical or family history, medications, goals. | You, optionally |
| Chat content | Questions you send to the in-app assistant and the replies you receive. | You, in the app |
| Routine activity | Which routine steps you mark complete, and when. | You, in the app |
| Purchase data | Your subscription status, plan, trial state and renewal dates. | Apple App Store / Google Play |
| Device and usage data | Device model, operating system version, app version, language, crash logs, and anonymised usage events. | Collected automatically |
We do not collect your card or UPI details. Payments are handled by Apple, Google or [PAYMENT PROCESSOR]. We receive only a confirmation of your subscription status.
3. Your scalp photos
Photos are the most sensitive thing you give us, so they get their own section.
- We only ask for a photo when you start a scan. You can decline camera and photo library access and still browse the app.
- Photos are encrypted in transit (TLS) and at rest, and stored against your account identifier.
- We do not use your photos for facial recognition or biometric identification, and we do not attempt to identify you from them.
- We do not sell your photos, share them with advertisers or data brokers, or publish them.
- Our staff do not routinely view your photos. Access is limited to a small number of authorised personnel, is logged, and happens only where necessary to investigate a fault you have reported, to prevent abuse, or where the law requires it.
- You can delete an individual scan, or all of your scans, from within the app at any time. See section 11.
Depending on where you live, an image of your scalp together with information about hair loss may be treated as sensitive or special category data. Where that is the case, we process it only with your explicit consent, which you give when you take your first scan and can withdraw at any time.
4. How we use your data
- To create your scorecard. Your scan image is analysed to estimate hair density, hairline shape, scalp condition and breakage.
- To track your progress. We compare each scan against your earlier scans so you can see change over time.
- To build and adjust your routine. Your findings and profile details determine which steps you're given.
- To answer your questions. The in-app assistant uses your scorecard and profile so answers are relevant to you.
- To run your account. Signing you in, managing your trial and subscription, and providing support.
- To keep the service safe and working. Diagnosing crashes, preventing fraud and abuse, and improving reliability.
- To contact you. Service messages such as OTPs, trial reminders and billing notices. Marketing messages only if you opt in, and you can opt out at any time.
We do not use your data to make automated decisions that produce legal effects for you. Your scorecard is informational and does not restrict access to anything.
5. Consent and legal basis
Under the DPDP Act, we process your personal data on the basis of the consent you give at sign-up and at your first scan, and for certain legitimate uses permitted by the Act. Our consent notice tells you what we collect and why, and is available in English and in the other languages listed in the Eighth Schedule to the Constitution of India on request.
If you are in the UK or EEA, our legal bases are:
- Contract — to give you the service you signed up for.
- Explicit consent — for your scan images and any health information you give us (Article 9(2)(a) GDPR).
- Legitimate interests — to keep the service secure, prevent abuse, and improve it, where those interests are not overridden by your rights.
- Legal obligation — where we must keep records or respond to lawful requests.
You can withdraw consent at any time. Withdrawing it doesn't affect processing that already happened, and some features stop working without it — we can't produce a scorecard without a photo.
6. Who we share it with
We share personal data only with service providers who process it on our instructions, and only as much as they need:
| Provider | Purpose |
|---|---|
| [CLOUD HOSTING PROVIDER] | Hosting the app backend, database and encrypted image storage |
| [SMS / OTP PROVIDER] | Sending one-time passcodes to your mobile number |
| [AI MODEL PROVIDER] | Generating analysis and answering your in-app questions |
| [ANALYTICS PROVIDER] | Anonymised or pseudonymised product usage analytics |
| [CRASH REPORTING PROVIDER] | Diagnosing app crashes |
| Apple, Google | Processing subscription payments and renewals |
| [CUSTOMER SUPPORT TOOL] | Handling your support requests |
We may also disclose data where the law requires it, to enforce our terms, to protect someone's safety, or in connection with a merger or acquisition — in which case we'll tell you before your data becomes subject to a different policy.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
7. AI processing
Your scan images and questions are processed by machine learning models to produce your scorecard and answers. Some of this happens through third-party AI providers listed above.
We instruct those providers not to use your content to train their general-purpose models, and we contract for that where the provider offers it. If we ever want to use your images to improve our own models, we will ask for separate, specific, opt-in consent first — it will never be bundled into general sign-up consent, and declining will not reduce your access to the service.
Analysis outputs are estimates. They can be wrong, particularly with poor lighting, unusual angles, hair products, or hairstyles that obscure the scalp.
8. How long we keep it
| Data | Retention period |
|---|---|
| Scan images | Until you delete them, or [24] months after your last activity, whichever is sooner |
| Analysis results and routine history | For as long as your account is active |
| Chat history | For as long as your account is active, or until you clear it |
| Account and billing records | For the life of the account, then as long as tax and accounting law requires (typically [8] years in India) |
| Crash and security logs | [90] days |
| Deleted account data | Erased or irreversibly anonymised within [30] days, except where law requires retention |
Encrypted backups may hold copies for a further [35] days before they cycle out.
9. Security
We use TLS for data in transit, encryption at rest for scan images, access controls and audit logging for internal access, and regular reviews of our infrastructure. Access to production systems is limited to staff who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the Data Protection Board of India as required under the DPDP Act, and the relevant supervisory authority where the GDPR applies.
10. Your rights
Wherever you are, you can ask us to:
- Access a summary of the personal data we hold about you and who we've shared it with.
- Correct data that's inaccurate, or complete data that's incomplete.
- Erase your data, subject to legal retention requirements.
- Withdraw consent for any processing that relies on it.
- Nominate another person to exercise these rights if you die or become incapacitated (a DPDP Act right).
If the GDPR applies to you, you additionally have the right to data portability, to restrict or object to processing, and to lodge a complaint with your local supervisory authority.
To exercise any of these, write to [PRIVACY EMAIL] or use the controls in the app. We'll respond within [30] days. We may ask you to verify your identity via your registered mobile number first.
11. Deleting your data
In the app: Profile → Privacy → Delete my data. You can remove individual scans, clear your chat history, or delete your entire account.
By email: write to [PRIVACY EMAIL] from your registered contact, or use the deletion request section below.
Deleting your account ends your access immediately and removes your scans, scorecards, routine history and chat. It does not automatically cancel a subscription bought through the App Store or Google Play — cancel that in your store settings.
12. Children
HairGro is for adults. You must be 18 or older to create an account. We do not knowingly collect personal data from children. Where the DPDP Act requires verifiable parental consent for users under 18, we do not permit those accounts at all rather than attempt to obtain it. If you believe a child has given us data, contact us and we will delete it.
13. International transfers
Your data is primarily stored in [REGION, e.g. ap-south-1, Mumbai]. Some of our service providers process data outside India. Where we transfer personal data internationally, we do so in line with the DPDP Act and, for UK/EEA users, under Standard Contractual Clauses or another approved safeguard.
14. Cookies on this site
This website uses only what's needed to serve the pages and, if enabled, privacy-respecting aggregate analytics. We don't run advertising trackers or third-party ad pixels here. The app itself does not use cookies; it uses a device-stored session token to keep you signed in.
15. Changes to this policy
If we change this policy, we'll update the date at the top. For changes that materially affect how we use your data, we'll notify you in the app or by message before they take effect, and where the change requires it, ask for fresh consent.
16. Contact and grievances
For any question about this policy or your data:
Data Protection Officer / Grievance Officer
[NAME]
[YOUR COMPANY PVT LTD]
[REGISTERED ADDRESS]
Email: [PRIVACY EMAIL]
Phone: [PHONE]
We acknowledge grievances within [48] hours and aim to resolve them within [30] days, as required under Indian law. If you're not satisfied with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority if you're in the UK or EEA.