Privacy policy · pre-launch draft

Your collection is personal data, not product inventory for sale.

This page states the intended V2 boundary and openly marks the legal and operational details that must be finalized before launch.

1. Scope and status

This is the pre-launch privacy draft for MakeupCast. The operating legal entity, jurisdiction-specific notices, processor list, and final retention schedule must be completed before public production launch.

2. Data we collect

When you create an account, the identity provider supplies an account identifier and account details needed for sign-in. MakeupCast stores the Beauty Passport, Today Casts, purchase checks, combination-level WearSessions, plan usage, subscription status, and settings you choose to provide. The no-account starter Passport is stored only in that browser.

3. Optional product photos

MakeupCast does not perform face analysis. If you choose Passport camera prefill, each request asks for separate consent and sends only the selected product-label photos through Vercel AI Gateway to OpenAI for structured label extraction. The browser and server resize and re-encode supported images, which removes embedded metadata from the forwarded copy. MakeupCast does not save the photos or automatically save the returned fields: the result is an editable draft that you must review. Provider-side handling is governed by the configured Gateway route and the applicable Vercel and OpenAI terms; zero-data-retention routing is used only when the operator has enabled and verified that account capability.

4. Location and weather

Weather is optional context. If you choose live weather, the MakeupCast server sends the city or broad-area name you entered to OpenWeather. The V2 flow does not request or store precise device coordinates. MakeupCast normalizes the response to Celsius temperature, whole-percent humidity, provider observation time, and a coarse city/country label, and may cache it for up to 30 minutes. A provider snapshot can be stored with a Today Cast or WearSession and included in your account export. Manually entered weather is not sent to OpenWeather.

5. Product evidence boundary

The separate Market Intelligence Core receives public product identifiers and sources only. MakeupCast does not send it your Clerk identifier, photos, private notes, stash, or personal WearSessions.

6. How data is used

Data is used to provide your Passport, create Today Casts, compare purchase candidates, learn from WearSessions, enforce plan limits, secure the service, and respond to support requests. Marketing use requires a separate lawful basis or consent where required.

7. Public-site analytics

Public marketing pages use Vercel Web Analytics for aggregate page-view reporting. The integration does not use analytics cookies, strips query strings before reporting, and does not send page views from account, sign-in, API, or private app routes. MakeupCast does not send custom analytics events containing product, account, or Beauty Passport data.

8. Service providers and third-party licenses

Production is designed to use Clerk for identity, MongoDB-compatible storage for app data, Vercel for hosting, public-site analytics, and optional AI Gateway product-label processing, OpenAI for the configured label-reading model, optional OpenWeather context, and a payment provider when billing is enabled. OpenWeather processes the server request under its own terms and privacy practices. Live weather that MakeupCast obtains from OpenWeather carries the provider attribution and the license applicable to MakeupCast's subscription; published self-service Open License terms identify CC BY-SA 4.0 and ODbL obligations, including ShareAlike where applicable. Manual and synthetic local-demo weather are excluded. See the Data attributions page for official source and license links. The final named processor and subprocessor list must match the accounts and routes actually configured at launch.

9. Retention and deletion

Active account data is kept to provide the service. You may export or delete Passport, Today Cast, purchase-check, and WearSession data. App-data deletion does not delete the separate sign-in identity, a valid plan entitlement, or operational usage counters, because deletion cannot be used to reset API limits. Usage counters are scheduled for automatic removal after 400 days. Full identity deletion is available through support; the production backup window and provider deletion workflow must still be tested before launch.

10. Security

Private APIs derive identity from the server-side session and scope records to that owner. Provider credentials remain server-side. No system is completely secure; suspected incidents should be reported to support@makeupcast.com.

11. Your choices and rights

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing. Contact privacy@makeupcast.com. Identity verification may be required before fulfilling a request.

12. Children

MakeupCast is not directed to children below the minimum digital-consent age in their jurisdiction. The final launch policy must state the supported minimum age and regional approach.

13. Changes and contact

Material policy changes will be dated on this page. Questions can be sent to privacy@makeupcast.com. Draft updated August 1, 2026.