Camellia Labs — BIPA, CUBI/TRAIGA, and Equivalent Laws
Effective date: June 17, 2026
Last updated: June 17, 2026
Applies to: Facial geometry processed and photos handled by the Camellia Labs App
Purpose. This policy is the publicly available retention schedule and destruction guidelines required by the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14, and is written to also address the Texas Capture or Use of Biometric Identifier Act (CUBI) as amended by TRAIGA and equivalent laws. It explains how facial geometry and uploaded photos are handled, retained, and permanently destroyed.
Our handling of facial geometry differs fundamentally from our handling of photos. This distinction is central to this policy.
Key point: Facial geometry is destroyed immediately after analysis and is never stored.
Only the raw photo and the resulting skin assessment text are retained, and only until you delete them or close your account.
Before your first photo is taken, we present a standalone biometric and health-data consent screen — separate from our general Terms and Conditions and never pre-checked — that informs you, in writing:
We obtain your explicit, opt-in acknowledgment before the first photo upload. An in-app checkbox that you actively select constitutes valid written consent. We log the date and version of your consent.
We use facial geometry only as needed to produce your skin assessment, and we use your photos only to produce assessments and to enable progress tracking that you request. We do not use facial geometry or photos to identify you outside the App. We do not use your photos to train AI models. We do not sell, lease, trade, or otherwise profit from facial geometry or photos.
We retain biometric data and photos no longer than necessary, and in all cases consistent with the following schedule and applicable law:
Statutory backstop. Where a state law imposes a maximum retention period for biometric identifiers (for example, destruction within a set time after the last interaction), we will destroy the relevant data no later than that statutory deadline, regardless of account status.
When the retention trigger occurs, we permanently destroy the data as follows:
• Facial geometry — never written to disk; cleared from memory and the AI processing pipeline immediately after analysis.
• Photos — permanently deleted from primary storage and from all backup copies within 30 days of a deletion request or account closure.
• Assessments — permanently deleted from primary storage and all backup copies within 30 days of a deletion request or account closure.
• Verifiability — our systems can confirm when a specific user’s photos were deleted, and we confirm completion to the user in writing.
Destruction is permanent and irreversible. We do not retain de-identified copies of photos after a deletion request, except an anonymized record that a consent event occurred (date and version only), retained for legal compliance.
Facial geometry is never stored in either version and therefore is not subject to storage controls. While retained, photos are protected by the controls below.
We protect biometric data using a reasonable standard of care that is at least as protective as the standard we use for our other confidential and sensitive information, consistent with BIPA.
Our AI analysis providers receive photos solely to return an assessment. Under written data processing agreements, each provider confirms that it does not retain photos beyond the time necessary to return the result, does not use them for model training or any other purpose, does not sell or further share them, and deletes any retained copies within a defined timeline. The same requirements apply to our backup provider. No provider receives stored facial geometry, because facial geometry is never stored.
We do not disclose, redisclose, or otherwise disseminate biometric data unless you consent; the disclosure completes a transaction you requested; it is required by law or valid legal process; or it is otherwise permitted by applicable biometric privacy law. We never sell or profit from biometric data.
If photos or biometric-related data are involved in a breach of security, we will follow our breach response plan and provide notifications as required by the FTC Health Breach Notification Rule (notice to affected individuals within 60 calendar days of discovery; notice to the FTC within 10 business days and to prominent media if 500 or more individuals are affected). An unauthorized disclosure of a photo to a third party without your consent is itself a reportable breach.
Email privacy@camellialabs.com with the subject line “Data Deletion Request” and include the email address associated with your account. We complete deletion of retained data within 30 days, including all backup copies, and confirm completion to you in writing. For the full process and your other rights, see our Consumer Health Data Privacy Policy.
We may update this policy. We will post the updated “Last updated” date and, where the law requires, obtain new consent before applying material changes to how biometric data is processed, retained, or destroyed.
Questions about this policy can be directed to:
Camellia Labs
Email: privacy@camellialabs.com
Mailing Address: 4Tell, LLC
115 Melrich Rd
Ste 2
Cranbury, NJ
08512-3526