MiraMake
Privacy Policy
Ryota Masuda ("we", "us", the operator) sets out below how we handle your information in the iOS app MiraMake (Japanese name: ミラメイク, the "App").
This is the English version. 日本語版はこちら / 繁體中文版. In case of any discrepancy, the Japanese version prevails.
Your face photo never leaves your device
All face analysis runs on your iPhone. The only thing that ever leaves is what you send by tapping "Ask AI": the 11 gap numbers and three plain words for your facial balance. Your photo is not sent. The "professional makeup review reservation" in an earlier version has been withdrawn, so this app no longer has any path that uploads a photo.
1. Information we collect
All face analysis in the App runs entirely on your iPhone. Photos you take for analysis are never transmitted anywhere.
The only data we receive on our server is the data you send when you tap "Ask AI", namely:
- Your total score (0 to 100)
- For each of the 11 measurements: the name of the measurement, the words for your current and goal features, and the size of the gap
- Three plain words for your facial balance (close-set or wide-set, childlike or mature, straight or curved)
- The language the advice should be written in (Japanese, English or Traditional Chinese)
No photo is sent. We do not send your name, email address, phone number or any device identifier either, so the numbers we receive are not tied to any individual. The App has no account registration.
2. Face data
This section sets out, in one place, the collection, use, disclosure, sharing, storage, retention, and deletion of face data.
2.1 Face data we collect
- Face photos that you take with the standard front-facing camera of your iPhone, or that you choose from your photo library.
- The photo you register as your "goal face".
- Numerical values computed from those photos on your device: a face feature vector (512 dimensions), the coordinates of 106 facial landmark points, 19 geometric ratios derived from those points, and an 8-category face shape label.
The App does not use the TrueDepth camera, ARKit face tracking, depth data, or Face ID. We never use face data to identify, verify, or authenticate a person, and we never match your face against any other person's face (no facial recognition).
2.2 How we use face data
- To show a similarity score between your face and the goal face that you yourself registered.
- To show a map of the differences by facial region, so you can practise your makeup.
All of this computation is performed on your iPhone. Neither your face photos nor the values listed in Section 2.1 are transmitted anywhere for analysis.
2.3 Disclosure and sharing with third parties
- We never sell, provide or share face data with third parties
- We never use face data for advertising, marketing, profiling, or to train machine learning models of ours or of anyone else
- The numbers you send with "Ask AI" are passed to the Gemini API of Google LLC so that the text can be written. No photo is passed. Google retains what is sent for 55 days to monitor for abuse (Gemini API logging policy)
2.4 Where face data is stored
- On your device: face photos and analysis results are stored in the App's own container, encrypted so that they cannot be decrypted while the device is locked, and excluded from iCloud backup. Deleting the App deletes this face data.
- On our server: there is no path that stores a face photo. The numbers you send with "Ask AI" are processed only to write the advice, and are not stored on our server.
2.5 Retention and deletion of face data
- On your device: retained until you delete it or delete the App. Diary records are deleted automatically after 7 days for free users (Plus subscribers keep them until they delete them). After a Plus subscription ends there is a 30-day grace period, during which no records or photos are deleted. The AI makeup advice you have read is deleted on the same schedule as the record it belongs to.
- On our server: we do not store face data.
- You can erase the face data on your device at any time from the App's settings screen (Section 6).
3. Purposes of use (all data, including data other than face data)
- Writing makeup advice when you tap "Ask AI"
- Finding the short videos that come with that advice (only the search words are passed to the YouTube Data API)
- Counting how many requests are made per day so that our running costs stay under a ceiling
We do not use it for advertising or to sell data to third parties. We do not track your behaviour.
4. Storage location and retention period
- Location: we do not store face data. The advice request travels through a Supabase Edge Function (operated by Supabase, Inc., United States).
- Retention: on-device storage is as described in Section 2.5. What remains on the server is the daily request count and a cache of video search results, neither of which is tied to any individual.
5. Disclosure to third parties and use of processors
- We never sell or provide the information we collect to third parties
- Writing the advice is entrusted to Google LLC (Gemini API), and searching for videos is entrusted to Google LLC (YouTube Data API). No face photo is passed to either.
- Relaying the request and the cloud platform are entrusted to Supabase, Inc., which processes data only on our instructions and never for its own purposes.
6. Deletion requests and contact
You can erase the face data and the analysis records on your device at any time, from the App's settings screen or by deleting the App. No face data of yours remains on our server, so there is nothing to request a deletion of.
If you have a question about this policy, please contact us below.
Contact: m.ryota1222@gmail.com
7. Payment information
Payments for MiraMake Plus (subscription) and in-app purchases are processed by Apple. We do not receive your credit card details.
8. Camera and notifications
- Camera: used to take and analyse your face photo. Photos are stored on your device only and are never sent to our server (Section 2.4)
- Notifications: makeup reminders are local notifications generated on your device. They do not pass through any external server.
9. Security
Communication with our server is encrypted using HTTPS. Because face photos are never sent to our server, no photos exist on our server. Face photos on your device are stored with a protection class that prevents decryption while the device is locked.
10. Changes to this policy
If we revise this policy, we will publish the revision on this page. We will also notify you in the App of any significant change.