Biometric Data Retention and Destruction Policy

Camellia Labs — BIPA, CUBI/TRAIGA, and Equivalent Laws

Effective date: June 17, 2026

Last updated:  June 17, 2026

Applies to:  Facial geometry processed and photos handled by the Camellia Labs App

Purpose. This policy is the publicly available retention schedule and destruction guidelines required by the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14, and is written to also address the Texas Capture or Use of Biometric Identifier Act (CUBI) as amended by TRAIGA and equivalent laws. It explains how facial geometry and uploaded photos are handled, retained, and permanently destroyed.

1. Definitions

  • Facial geometry: geometric facial feature data that may be processed by the AI model during analysis of an uploaded photo. This is a biometric identifier.
  • Photo: a raw facial image you choose to upload for skin analysis and progress tracking.
  • Skin assessment: the AI-generated text describing your skin condition. It is not a biometric identifier but is treated as consumer health data.
  •  Biometric data: for purposes of this policy, facial geometry, and — to the extent determined by counsel under applicable state law — any raw photo treated as a biometric identifier.

2. What We Process and What We Store

Our handling of facial geometry differs fundamentally from our handling of photos. This distinction is central to this policy.

Key point: Facial geometry is destroyed immediately after analysis and is never stored.

Only the raw photo and the resulting skin assessment text are retained, and only until you delete them or close your account.

Data

Processed?

Stored?

Notes

Facial geometry
Yes — may be processed by the AI during analysis
No — never written to storage
Discarded immediately after the assessment is produced
Photo
Yes — transmitted for analysis
Yes — retained for progress tracking
Retained until you delete it or close your account
Skin assessment
Generated
Yes
Retained with the photo; consumer health data

3. Consent Before Capture

Before your first photo is taken, we present a standalone biometric and health-data consent screen — separate from our general Terms and Conditions and never pre-checked — that informs you, in writing:

  • That facial geometry may be processed during AI analysis and is discarded immediately;
  • That your raw photo is retained for progress tracking until you delete it or close your account, after which it is permanently deleted within 30 days;
  • The specific purpose of the processing (to generate your skin assessment); and
  • That your photo is shared with our third-party AI provider solely for analysis, under a written agreement, with a separate consent obtained for that disclosure.

We obtain your explicit, opt-in acknowledgment before the first photo upload. An in-app checkbox that you actively select constitutes valid written consent. We log the date and version of your consent.

4. Permitted Uses

We use facial geometry only as needed to produce your skin assessment, and we use your photos only to produce assessments and to enable progress tracking that you request. We do not use facial geometry or photos to identify you outside the App. We do not use your photos to train AI models. We do not sell, lease, trade, or otherwise profit from facial geometry or photos.

5. Retention Schedule

We retain biometric data and photos no longer than necessary, and in all cases consistent with the following schedule and applicable law:

Data

Retention Period

Trigger for Destruction

Facial geometry
Not retained
Destroyed immediately upon completion of analysis
Photo
Until you delete it or close your account; in no event longer than required by law
Deletion request, account closure, or inactivity rule below
Skin assessment
Until you delete it or close your account
Deletion request, account closure, or inactivity rule
Inactive accounts
After 12 months of inactivity
Automated deletion of stored data

Statutory backstop. Where a state law imposes a maximum retention period for biometric identifiers (for example, destruction within a set time after the last interaction), we will destroy the relevant data no later than that statutory deadline, regardless of account status.

6. Destruction Guidelines

When the retention trigger occurs, we permanently destroy the data as follows:

•     Facial geometry — never written to disk; cleared from memory and the AI processing pipeline immediately after analysis.

•     Photos — permanently deleted from primary storage and from all backup copies within 30 days of a deletion request or account closure.

•     Assessments — permanently deleted from primary storage and all backup copies within 30 days of a deletion request or account closure.

•     Verifiability — our systems can confirm when a specific user’s photos were deleted, and we confirm completion to the user in writing.

Destruction is permanent and irreversible. We do not retain de-identified copies of photos after a deletion request, except an anonymized record that a consent event occurred (date and version only), retained for legal compliance.

7. Storage and Security Controls

Facial geometry is never stored in either version and therefore is not subject to storage controls. While retained, photos are protected by the controls below.

  • AES-256 encryption at rest, with keys managed through a dedicated key management service;
  • TLS 1.2 or higher for all transmission;
  • EXIF and other hidden metadata stripped before transmission and before storage;
  • Private, access-controlled storage with no public access; access only via short-lived links (no persistent public URLs); no caching in content delivery networks, proxies, or logging systems;
  • Role-restricted internal access, logged with timestamp and requester identity, with logs retained for at least 12 months; and
  • No human review of any stored photo without your explicit, separate consent for human review.

We protect biometric data using a reasonable standard of care that is at least as protective as the standard we use for our other confidential and sensitive information, consistent with BIPA.

8. Third-Party Providers

Our AI analysis providers receive photos solely to return an assessment. Under written data processing agreements, each provider confirms that it does not retain photos beyond the time necessary to return the result, does not use them for model training or any other purpose, does not sell or further share them, and deletes any retained copies within a defined timeline. The same requirements apply to our backup provider. No provider receives stored facial geometry, because facial geometry is never stored.

9. Disclosure Restrictions

We do not disclose, redisclose, or otherwise disseminate biometric data unless you consent; the disclosure completes a transaction you requested; it is required by law or valid legal process; or it is otherwise permitted by applicable biometric privacy law. We never sell or profit from biometric data.

If photos or biometric-related data are involved in a breach of security, we will follow our breach response plan and provide notifications as required by the FTC Health Breach Notification Rule (notice to affected individuals within 60 calendar days of discovery; notice to the FTC within 10 business days and to prominent media if 500 or more individuals are affected). An unauthorized disclosure of a photo to a third party without your consent is itself a reportable breach.

10. How to Request Deletion

Email privacy@camellialabs.com with the subject line “Data Deletion Request” and include the email address associated with your account. We complete deletion of retained data within 30 days, including all backup copies, and confirm completion to you in writing. For the full process and your other rights, see our Consumer Health Data Privacy Policy.

11. Changes to This Policy

We may update this policy. We will post the updated “Last updated” date and, where the law requires, obtain new consent before applying material changes to how biometric data is processed, retained, or destroyed.

12. Contact

Questions about this policy can be directed to:

Camellia Labs

Email: privacy@camellialabs.com

Mailing Address: 4Tell, LLC

115 Melrich Rd

Ste 2

Cranbury, NJ

08512-3526