Effective date: June 4, 2026
Last updated: June 4, 2026
Applies to: The Camellia Labs mobile application and related services (the “App”)
Camellia Labs (“Camellia,” “we,” “us,” or “our”) operates an AI-powered skincare personalization application that analyzes information about your skin to generate personalized routine recommendations. This Privacy Policy explains what information we collect, why we collect it, how we use and store it, who we share it with, how long we keep it, and the choices and rights you have.
Some of the information we collect — including facial photos, self-reported skin condition details, and AI-generated skin assessments — is health-related. Washington State residents and certain other consumers have additional rights regarding this information, which are described in our separate Consumer Health Data Privacy Policy. Where that policy applies, it governs our handling of consumer health data and should be read together with this Privacy Policy.
Camellia is for adults 18 and older. The App is not directed to children, and we do not knowingly collect or retain personal information from anyone under 18. See Section 9 (Children’s Privacy and Age Restriction).
This summary highlights important points. Please read the full policy for complete details.
We practice data minimization: we collect only what is necessary for the App’s AI to produce a useful and safe skin assessment and routine recommendation, plus the limited information needed to operate your account. The table below describes each category, why it is necessary, and whether it is stored.
*Date of birth versus age range. We do not store your date of birth. The date you enter at the age gate is evaluated only in temporary memory to confirm you are 18 or older, and is then discarded. Only the resulting age range is saved to personalize your experience.
We use the information we collect to:
We do not use your photos to identify you outside of the App.
When you choose to upload a photo, we strip hidden metadata (such as GPS location, device identifiers, and timestamps) from the image before it leaves your device environment, then transmit it over an encrypted connection to our third-party AI analysis provider. The provider analyzes the image and returns a skin assessment. During this process, facial geometry may be processed by the AI model.
Photo analysis is optional. You can skip it and still receive a routine based on your self-reported skin information. You may add photos over time to build a longitudinal progress record, and you may delete any photo at any time.
Before your first photo is taken, we present a separate, standalone biometric and health-data consent screen that explains how your photo and any facial geometry are handled and that your photo is shared with our AI provider solely for analysis. We obtain your explicit, opt-in consent before collecting a photo and a separate consent for sharing it with our AI provider. This consent is described further in our Consumer Health Data Privacy Policy and our Biometric Data Retention and Destruction Policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising or targeted advertising.
We share information only in the limited circumstances below:
Sharing health-related data with any party other than as described above requires your explicit, separate consent. Sharing consumer health data without authorization would constitute a reportable breach under the FTC Health Breach Notification Rule, and we treat it accordingly.
We maintain administrative, technical, and physical safeguards designed to protect your information. Our current measures include:
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
Because the App handles health-related data, we are subject to the FTC Health Breach Notification Rule (16 CFR Part 318). If your health-related information is involved in a breach of security, we will notify affected individuals without unreasonable delay and no later than 60 calendar days after we discover the breach. If 500 or more individuals are affected, we will also notify the Federal Trade Commission within 10 business days and notify prominent media outlets in the affected area. An unauthorized disclosure of your health-related data to a third party without your consent — such as sharing with an analytics platform, advertising network, or AI vendor — is itself a reportable breach, and we treat it accordingly. We maintain a written breach response plan covering both data in transit at our providers and data at rest in our systems.
We keep different categories of information for different periods:
The App is intended only for adults 18 and older and is not directed to children. We use a neutral age gate that does not default to any age and does not encourage anyone to misstate their age.
The date of birth you enter is evaluated in memory only and is never written to any database, log, analytics event, or third-party service before the age check resolves. If the age check indicates you are under 18, your session is ended immediately and nothing from it is retained — not your date of birth, device identifiers, IP address, or analytics events. No personal data is collected or kept from anyone the age gate identifies as under 18.
We do not knowingly collect personal information from anyone under 18. Consistent with the Children’s Online Privacy Protection Act (COPPA), we never knowingly collect personal information from a child under 13; any session identified as belonging to a user under 13 is terminated cleanly with nothing retained, and the same applies to users aged 13 to 17. If we later learn that an account belongs to someone under 18, we will promptly and permanently delete all associated data, including any stored photos and assessments. If you believe a minor has provided us information, contact us at privacy@camellialabs.com and we will delete it.
Depending on where you live, you may have some or all of the following rights. We honor these requests regardless of your state of residence to the extent practical:
How to make a request. Email privacy@camellialabs.com with the subject line “Data Deletion Request” (for deletions) or describe your request. Include the email address associated with your account; no other information is required.
Our response. We respond to rights requests within 45 days. We may extend this once by an additional 45 days where reasonably necessary, and will tell you if we do. Responses are free of charge up to twice per year. If we deny a request, we will explain why in writing and tell you how to appeal; you may also contact your state attorney general. Deletions are completed within 30 days, including backup copies, and we will confirm completion to you. For more detail on how deletion works for health data, see our Consumer Health Data Privacy Policy.
The App provides cosmetic and skincare personalization. It is not a medical device and does not provide medical advice, diagnosis, or treatment. AI skin analysis can be less accurate for some skin tones, lighting conditions, and devices. Always consult a qualified healthcare professional for medical concerns. See the Terms and Conditions for more detail.
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and notify you within the App or by email before the changes take effect, as required by law. We will not use previously collected information in a materially different way without your consent where consent is required.
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Camellia Labs
Privacy contact: privacy@camellialabs.com
Mailing address: 4Tell, LLC
115 Melrich Rd
Ste 2
Cranbury, NJ
08512-3526