Privacy Policy
Last updated: 2026-09-19
This policy explains what Look AI does with your information. It covers the Look AI mobile app and this website, both published by Better Life With Apps.
The short version
- There is no signup. We do not ask for your name or your email address to let you use the app.
- What you upload is private by default and is never listed publicly.
- To generate your result, what you upload is sent to OpenAI, which processes it on our instructions.
- Everything we store sits on servers we control in Helsinki, Finland, inside the EU.
- You can have your account and your data deleted at any time — see how to delete your account.
1. Your account
Look AI has no email-and-password signup. We do not collect a name or an email address in order to let you use the app. An account is created anonymously from a hash derived from your installation of the app.
Against that account we store:
- a randomly generated user identifier (UUID);
- the installation hash the account was created from;
- your platform (iOS or Android), the app version, your language and your country;
- session tokens that keep you signed in on that installation.
2. The content you provide
When you use Look AI you provide the selfie you upload, together with the cut, colour or makeup you pick from the catalogue.
Uploads are private by default. They are never publicly listed, and they are served only through short-lived signed links that expire.
3. AI processing
To produce a result, the content and prompts you provide are sent to OpenAI, which acts as a processor on our instructions and generates the output images and text.
The portraits the app generates from your selfie are stored on our servers so that you can open them again, re-download them and export them later.
4. Purchases
Subscriptions are sold through the Apple App Store and Google Play and are processed through RevenueCat. We store a billing subject identifier and the state of your subscription.
We never see or store your card number.
5. Diagnostics and analytics
To find crashes, fix problems and configure the app remotely, we use:
- Firebase Analytics — how the app is used;
- Firebase Crashlytics — crash reports;
- Firebase Remote Config — remote configuration of the app;
- Sentry — error diagnostics.
On iOS we ask for App Tracking Transparency permission. Your consent choice is recorded on our servers against your user record.
In-app feedback (Wiredash)
The feedback form in the app is provided by Wiredash. Each time the app starts, at most once every 30 minutes, it checks in with Wiredash, whether or not you ever send feedback. The check-in carries a random identifier that Wiredash's code creates on your device, the app's version, build number and build commit, its bundle ID, whether it is a production or development build, your device's language setting, and your operating system and its version. The first time it runs, it also sends a one-off first-launch event. None of this includes your user ID, your uploads or anything you have written. For this data, Wiredash's documentation says it works out your country from the connection's IP address and does not store the address (Wiredash: analytics privacy). We rely on our legitimate interest in operating the feedback form (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
When you choose Send feedback in the app's settings, the app sends Wiredash your message, your email address if you enter one, and a screenshot if you add one. You can draw on the screenshot before sending it; it shows whatever is on the screen at that moment, including what you have uploaded and the results you have made. With your feedback go device and app details (platform, operating-system version, device model, screen size, language setting, and the app's version and build) and details we add so that we can follow up: your user ID, the app's name, whether it is the production or development version, and your subscription status. We read your feedback in Wiredash to answer it and to fix the app. We do this at your request and in our legitimate interest in improving the app (GDPR Art. 6(1)(b) and (f); KVKK Art. 5(2)(c) and (f)).
6. Where your data is stored
Our backend runs on our own servers at Hetzner in Helsinki, Finland, inside the EU. The PostgreSQL database, the Redis queue and the private MinIO object storage that holds your files all run on infrastructure we control in the EU.
Feedback you send from the app, and the feedback form's check-ins, are kept by Wiredash, not on our servers. Wiredash GmbH is based in Germany, but its privacy policy says that data may be transferred to the United States, processed there and stored on Google Cloud servers (Wiredash: privacy policy).
7. Who your data reaches
Besides the infrastructure above, your data reaches only the service providers we need to run Look AI:
| Provider | What it is used for |
|---|---|
| OpenAI | Generating your output from the content and prompts you provide |
| Hetzner | Hosting our servers, database, queue and object storage in Finland (EU) |
| Apple App Store, Google Play | Selling and billing subscriptions |
| RevenueCat | Processing subscription state |
| Google Firebase | Analytics, crash reporting, remote configuration, and App Check device attestation that keeps the backend reachable only from a genuine copy of the app |
| Wiredash | The in-app feedback form: its check-ins and the feedback you send (Wiredash GmbH, based in Germany; according to its privacy policy, data is stored on Google Cloud and may be transferred to the United States) |
| Sentry | Error diagnostics |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
8. How long we keep things
- Your original uploads are deleted once they have been processed successfully.
- Generated assets and exports carry an explicit expiry timestamp and are removed when it is reached.
- Your account record is kept for as long as the account exists.
- Feedback you send stays at Wiredash until it is deleted there. Deleting your account does not remove it; write to us if you want it removed.
- Records of visits to this website's
/getpage contain no IP address or identifier; the oldest file is deleted as the record grows.
9. Deleting your account
You can have your account deleted at any time by writing to privacy@blwapps.com; the deletion page explains what to include, and a delete control inside the app is being added. Deleting revokes your access immediately and queues a deletion request. After a short safety delay, the stored objects, asset rows, job inputs, analytics links, consent records and billing identity attached to your account are removed, leaving only a non-identifying tombstone record and the audit evidence that the deletion happened. A documented legal hold can pause a deletion.
Full instructions, including what to do if you have already uninstalled the app, are on the account and data deletion page.
10. Your rights
Under the GDPR and the Turkish personal data protection law (KVKK), you can ask us to give you access to your personal data, correct it, erase it, restrict how we process it, hand it over in a portable form, or stop processing it altogether. Under the CCPA, we do not sell or share personal information.
To exercise any of these, write to privacy@blwapps.com. Because we do not ask for your name or email address when you use the app, please read the deletion page first — it explains what we need in order to find your record.
11. Children
Look AI is not directed at children under 13, or under 16 in the European Economic Area, and we do not knowingly create accounts for them.
12. This website
This website is a set of static pages. It sets no cookies, runs no analytics or tracking scripts, and loads nothing from other websites. It is served from the same server in Helsinki as our backend.
When someone shares the app from its settings, the link they send opens this website's /get page and carries a ref tag naming where the link came from, such as app_share. The page sends you on to the App Store, Google Play or this website's home page and passes the tag along. When /get is opened, our server records only the time, the website, the page address with its tag, and whether the page loaded: no IP address, no cookies, no device identifiers. We use these records to count how many visits share links bring. The App Store and Google Play may count installs that came through the tag in the statistics they give us.
13. Changes to this policy
When the app changes in a way that affects this policy, we update this page and change the date at the top.
14. Contact
Privacy questions and requests: privacy@blwapps.com
Everything else: support@blwapps.com