Privacy Policy

Last updated: May 26, 2026

This Privacy Policy explains how Tarik Fatih PINARCI collects, uses, discloses, retains, and protects information when you visit https://lerin.app, use the Lerin mobile app, contact support, or interact with related services.

Who we are

The service is operated by Tarik Fatih PINARCI. Questions about this Privacy Policy, your privacy rights, or anything else about the app go to the same place: support@lerin.app.

Scope

This policy applies to the Lerin website, app, account features, customer support, product communications, AI-assisted product questions, scan features, and routine planning tools. It does not apply to third-party websites, app stores, payment providers, or services that we do not control.

Lerin is designed for skincare education and routine habit support. It is not a medical device, does not provide medical advice, and does not diagnose, treat, cure, mitigate, or prevent any disease or medical condition.

Information we collect

  • Account and contact information, such as name, email address, sign-in method, communication preferences, support messages, and account settings.
  • Skin profile and routine information you choose to provide, such as goals, visible concerns, skin type, sensitivities, allergies, products used, routine history, preferences, and progress notes.
  • Face scan and image information, such as camera images you submit, scan-quality checks, lighting and framing signals, derived visible skin observations, routine context, and progress history.
  • AI chat and product-question information, such as product names, ingredient questions, messages, responses, and context needed to personalize answers to your routine and skin profile.
  • App, device, and usage information, such as device model, operating system, approximate region, IP address, app version, language, feature events, crash logs, diagnostics, and security logs.
  • Purchase information, such as subscription status, plan type, transaction identifiers, and entitlement events received from the App Store or payment providers. We do not receive full payment card numbers from Apple.

We aim to collect only the information needed for the feature you use. If a feature can work with less precise or less sensitive information, the product should prefer that lower-data option.

Face scans and sensitive information

Face scans, skin observations, and health-adjacent profile details can be sensitive. We use them only to provide scan quality checks, visible skin-signal explanations, routine personalization, progress tracking, product-question context, safety checks, support, security, and service improvement.

  • We ask for consent where required before collecting or processing face scans or sensitive personal information.
  • We do not use face scans to identify you, authenticate you, create a faceprint, or build a biometric identification database.
  • We do not sell face scans, skin observations, or sensitive health information.
  • We do not share face scans or skin observations with advertising networks for cross-context behavioral advertising.
  • We do not allow third-party AI providers to use identifiable face scans or skin profile data to train general-purpose models unless we disclose that change and obtain any required consent.
  • We do not embed hidden identity markers, biometric templates, or tracking tokens in exported images or routine summaries.

Camera, photos, and device permissions

The app may request camera access to capture scans, photo-library access if you choose to upload an image, notification permission for routine reminders, and network access to sync account features. You can manage device permissions in system settings. Some features may not work if required permissions are disabled.

How we use information

  • Provide, operate, maintain, secure, and improve the service.
  • Deliver scan feedback, skin-signal explanations, personalized AM/PM routine steps, product-question answers, and progress history.
  • Personalize recommendations based on your scan history, routine, skin profile, product preferences, sensitivities, and app usage.
  • Provide customer support, troubleshoot bugs, detect errors, and measure product performance.
  • Prevent fraud, abuse, unauthorized access, security incidents, and misuse of face scan or AI features.
  • Send account, subscription, security, legal, transactional, and product-service messages.
  • Comply with legal obligations, enforce our Terms and Conditions, and protect rights, safety, and property.

AI processing

Lerin may use automated systems and AI service providers to analyze scans, explain visible skin signals, suggest routine adjustments, and answer product questions using your routine and skin profile context. AI outputs may be incomplete, inaccurate, or affected by lighting, image quality, available product data, or user input.

AI outputs are informational skincare support, not medical advice. Do not rely on AI outputs for diagnosis, treatment, emergency care, prescription decisions, or decisions about serious skin symptoms.

We may route requests through AI infrastructure providers that help generate or evaluate responses. Those providers are permitted to process information only to provide the service, maintain security, comply with law, or perform contractually allowed operations.

When we disclose information

We disclose information only as needed for the service, as described in this policy, or with your direction.

  • Service providers, including hosting, database, security, analytics, crash reporting, customer support, payment entitlement, and AI infrastructure providers.
  • App stores and payment providers, including Apple, for purchases, subscriptions, refunds, fraud prevention, and entitlement management.
  • Professional advisers, auditors, insurers, and legal providers where needed for business operations and compliance.
  • Authorities, regulators, courts, or other parties when required by law or when necessary to protect rights, safety, security, or prevent misuse.
  • Business transfer recipients if we are involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.

Advertising and tracking

We do not sell personal information, sell sensitive personal information, or share personal information for cross-context behavioral advertising. If we introduce advertising, tracking, or third-party SDK behavior that changes this, we will update this policy and provide any legally required choices or consent prompts.

The website may use essential cookies or similar technologies for security, session management, analytics, and performance. Browser settings may let you block or delete cookies, but some features may stop working. We do not currently respond to browser "Do Not Track" signals because there is no common industry standard for them.

Messages and notifications

We may send service emails, account notices, security alerts, purchase messages, and support responses. If you enable push notifications, we may send routine reminders or product updates. You can manage marketing emails through unsubscribe controls and push notifications through system settings.

Retention and deletion

We keep information only for as long as reasonably needed for the purposes described in this policy, unless a longer period is required or permitted by law. Retention periods can vary by data type, account status, legal requirement, security need, and backup schedule.

  • Account information is generally kept while your account is active and for a limited period after closure where needed for legal, security, accounting, or dispute purposes.
  • Face scans, derived skin observations, routine history, and AI chat context should be deletable from product controls or through a verified privacy request, subject to legal and security limits.
  • Account deletion requests should remove or de-identify active account data within a reasonable period after verification, while backups, logs, invoices, fraud records, and legal records may remain for limited retention periods.
  • Logs, backups, and security records may persist for limited periods before automatic deletion or overwrite.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption in transit, secure storage practices, least-privilege production access, logging, and vendor review. No method of transmission or storage is perfectly secure.

If you believe your account, scan data, or routine history has been accessed without authorization, contact us promptly at support@lerin.app.

Consumer health data

Residents of states with dedicated consumer health data laws, including the Washington My Health My Data Act and Nevada SB 370, have additional rights over face scans and the skin observations derived from them. Those rights, the third parties involved, and how to exercise or appeal a request are set out in the Consumer Health Data Privacy Notice. We do not sell consumer health data.

Health app breach notices

If we maintain identifiable health information and experience a breach of unsecured information, we will evaluate notice obligations under applicable laws, including the FTC Health Breach Notification Rule for certain non-HIPAA health apps and similar technologies. Required notices may include notice to affected users, regulators, and in some cases media outlets.

Breach notices, where required, may describe what happened, what information was involved, steps we are taking, steps users can take, and how to contact us.

HIPAA

Consumer wellness apps are not automatically covered by HIPAA. Unless Lerin is acting for a HIPAA covered entity or business associate, HIPAA may not apply. If we later integrate with healthcare providers, health plans, EHRs, or covered-entity workflows, we will reassess HIPAA, business associate, security, and breach-notification requirements before launch.

Your privacy choices and rights

Depending on where you live, you may have rights to access, know, correct, delete, export, restrict, object to, or appeal certain processing of personal information. You may also have the right to withdraw consent where processing is based on consent.

To exercise rights, contact support@lerin.app. We may need to verify your identity and account before completing a request. We will not discriminate against you for exercising applicable privacy rights.

California notice

If California privacy law applies, California residents may have rights to know, access, delete, correct, limit certain uses of sensitive personal information, opt out of sale or sharing, and appeal or complain as permitted by law.

Categories we may collect include identifiers, customer records, commercial information, internet or app activity, device information, approximate geolocation, sensory information such as images, inferences, and sensitive personal information such as health-related skin observations where you provide them. We do not sell personal information or share it for cross-context behavioral advertising.

EEA, UK, and Swiss users

If GDPR-style laws apply, we process personal data using legal bases such as consent, contract necessity, legitimate interests, legal obligations, and, where applicable, explicit consent for special category data. You may have rights to access, rectify, erase, restrict, port, object, withdraw consent, and complain to a data protection authority.

Information may be transferred to countries that may not provide the same level of data protection. Where required, we use appropriate transfer safeguards, such as contractual protections.

Adults only

Lerin is intended only for people who are 18 years of age or older. People under 18 should not use the service or submit account information, face scans, skin profile details, product questions, or routine data. If you believe someone under 18 has provided personal information, contact us so we can take appropriate steps to delete it.

De-identified and aggregated data

We may use de-identified or aggregated information for analytics, product quality, model evaluation, safety, research, reporting, and service improvement. We do not attempt to re-identify de-identified information except to test whether de-identification protections are effective or as permitted by law.

App Store privacy disclosures

Apple requires accurate App Privacy disclosures and an accessible privacy policy. Before App Store submission, the App Store privacy labels, in-app consent flows, account deletion flow, third-party SDK list, analytics behavior, purchases, and this policy should match the app's actual data practices.

Changes to this policy

We may update this policy to reflect changes to the service, data practices, law, or business operations. The updated date above shows when this policy last changed. If a change materially affects your privacy rights or sensitive information, we will provide additional notice where required.