This Privacy Policy explains the categories of personal information we collect, how it is secured, and your explicit rights under global privacy statutes.
1. Overview & Commitment to Privacy
At Kallign ("we", "us", or "our"), we believe that your biological skincare parameters, allergies, and personal preferences belong exclusively to you. This Privacy Policy outlines our transparent data practices across our website, web applications, ingredient decoding engines, camera scanners, and related services.
We operate on a strict data-minimization philosophy: we collect only what is strictly necessary to compute your dermatological compatibility scores, we never sell your personal information, and we never monetize your data through third-party advertising brokers.
2. Information We Collect
We collect information in two ways: information you explicitly provide when configuring your Beauty Profile, and technical metadata necessary to operate the platform.
A. Information You Provide to Us
• Account Information: Name, email address, username, and password hash if you choose to register an account.
• Age Verification Group: Selected during onboarding to enforce age-appropriate safety guardrails (Under 13, 13–17, or 18+).
• Beauty & Skin Profile Answers: Biological skin type, Fitzpatrick skin tone, target skin concerns, cosmetic style preferences, budget tier, and diagnosed skin conditions (18+ only).
• Allergy & Tolerance Checklists: Known cosmetic allergens, botanical sensitivities, and custom ingredients to avoid.
B. Information Collected Automatically
• Technical Diagnostics: IP address (anonymized), browser user agent, operating system, and session timestamps to ensure platform stability and protect against automated scraping.
• Local Storage Data: Client-side profile tokens and shopping bag items stored locally in your browser to enable offline guest usage without mandatory cloud account creation.
3. Children’s Online Privacy Protection Act (COPPA) Safeguards
Kallign is dedicated to safeguarding children's online privacy and complies rigorously with the United States Children's Online Privacy Protection Act ("COPPA") and international youth data protection standards.
For users under 13 years of age ("Children"), we implement the following non-negotiable architectural protections:
- •Age-First Gatekeeping: Age is the first question presented. No profile parameters, quiz answers, or cookies are stored prior to recording an age tier.
- •Verifiable Parental Consent (VPC): Account registration for users under 13 requires a verified parent or legal guardian email. We send an authentication token to the parent before establishing any profile record.
- •Restricted Closed-Choice Interface: Under-13 accounts are restricted strictly to predetermined cosmetic choices. Free-form open text inputs, unmoderated chat, public profiles, and financial questions are entirely disabled.
- •Non-Medical Cosmetic Language: Skin concerns for children are restricted to gentle, non-clinical cosmetic attributes (e.g., dryness, gentle hydration) and are never treated as health records.
- •Conservative Scoring Defaults: Dual-Engine recommendation algorithms automatically apply the strictest safety thresholds, completely blocking strong exfoliants, high-concentration AHA/BHA chemical peels, and retinoids.
- •Zero Commercial Exploitation: We never serve targeted advertisements, behavioral trackers, or marketing promotions to minor accounts.
4. Parental Rights & Account Controls
Parents and legal guardians retain complete legal authority over information associated with their child’s account. At any time, a verified parent may contact us to:
- •Inspect and review all personal information and skin profile answers collected from their child.
- •Request the permanent deletion of their child's account, profile data, and verification logs.
- •Revoke consent and prohibit any further collection or analysis of their child's data.
- •To exercise these rights, parents may email privacy@kallign.com with the subject line 'COPPA Parental Request'.
5. How We Use Your Information
We use your data solely for the following legitimate purposes:
• Computing personalized Ingredient Safety Scores (0–100) and Beauty Match Scores (0–100) for cosmetic products.
• Cross-referencing cosmetic ingredient formulations (INCI) against your declared allergies and sensitivities.
• Maintaining your secure authentication session and syncing your beauty profile across your authorized devices.
• Responding to your customer support, parental consent, or technical inquiries.
6. Zero Data-Sale Policy & Third-Party Disclosures
WE DO NOT SELL, RENT, LEASE, OR TRADE YOUR PERSONAL INFORMATION OR BEAUTY PROFILE DATA TO THIRD PARTIES, DATA BROKERS, OR ADVERTISERS FOR ANY MONETARY OR COMMERCIAL CONSIDERATION.
We share information exclusively with trusted infrastructure service providers strictly necessary to operate our platform:
• Database & Authentication Infrastructure: Supabase Inc. (ISO 27001 / SOC 2 Type II certified; enterprise data encryption at rest and in transit).
• AI & Optical Character Processing: OpenRouter & Secure Vision APIs (ephemeral packaging text parsing with zero training on personal health profiles).
All service providers are bound by strict data processing agreements ("DPAs") prohibiting them from using your data for any independent purpose.
7. Your Rights under GDPR, CCPA/CPRA & CalOPPA
Depending on your jurisdiction (including the European Union, United Kingdom, and California), you possess specific statutory rights regarding your personal data:
- •Right to Access: You may request a machine-readable copy of all personal data we hold about you.
- •Right to Rectification: You may update or correct your profile parameters at any time via the 'Edit Profile' interface.
- •Right to Erasure ('Right to be Forgotten'): You can instantly and permanently erase your account, profile row, and authentication records using the self-service 'DELETE ACCOUNT & DATA' button in your profile.
- •Right to Restrict Processing: You may opt out of automated recommendation scoring at any time.
- •Right to Non-Discrimination: We will never deny services, charge different prices, or degrade quality if you exercise your privacy rights.
8. Data Security & Retention
We implement industry-standard administrative, physical, and technical safeguards to protect your personal information:
• All communication is encrypted in transit using Transport Layer Security (TLS 1.3 / HTTPS).
• Database tables are protected with strict Row-Level Security (RLS) policies ensuring users can only read and write their own authenticated rows.
• Data is retained only for as long as your account remains active. Upon invoking account deletion, your records are permanently purged from active production databases.
10. Contact Our Privacy Officer
If you have questions, feedback, or legal requests concerning this Privacy Policy, please contact our Data Protection Officer at:
Email: privacy@kallign.com | legal@kallign.com
Address: Kallign Legal Compliance, 1209 Orange St, Wilmington, DE 19801
Privacy inquiries or COPPA notices: privacy@kallign.com
Review our Terms of Service →