Biometric Data Policy
Last updated: July 11, 2026
This policy explains how NeckPill handles the data involved in the app's optional face & neck scan feature. It supplements our Privacy Policy and serves as the publicly available written policy required by biometric privacy laws such as the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, and the Washington My Health My Data Act. In the EEA/UK/Switzerland the scan is processed on the basis of your explicit consent (GDPR Art. 9(2)(a)).
1. What Is Collected — and Where It Stays
If you choose to use the scan, the app uses your device's front camera to:
- capture a photo of your face, neck, and shoulders, and
- compute geometry measurements from it on your device — facial proportions, jawline contour, symmetry, and neck/shoulder outline widths.
All of this happens entirely on your device. The photo and the measurements are stored only in the app's private storage on your phone. We do not operate servers that receive, store, or process them — they are never uploaded, and we never possess them.
2. What It Is Used For — and Not For
- Used solely to show you a personalized, illustrative analysis inside the app and to tailor your training plan presentation.
- Never used to identify you or anyone else. There is no face recognition, no matching against any database, and no linking to your identity (NeckPill has no accounts).
- Never sold, leased, traded, shared, or otherwise profited from. Not disclosed to any third party.
- No scan data is included in analytics, crash reports, or attribution — only anonymous facts like "a scan was completed" and coarse score ranges are logged, never measurements or images.
3. Consent
The scan runs only after you give explicit consent on a dedicated in-app screen. If you decline, the scan is simply skipped and every other part of NeckPill works normally. You can withdraw consent at any time by deleting your scan data (Section 5) — the feature will not run again unless you consent again.
4. Retention Schedule
Your scan photo and derived measurements are retained on your device only, until the earlier of:
- you delete them in the app (immediate), or
- you uninstall NeckPill (the operating system removes all app data).
Because the data never leaves your device, there are no server copies and no backup copies held by us — under laws like BIPA we do not "possess" your biometric data at all; this policy nonetheless documents the retention and destruction rules the app enforces locally.
If a future optional feature ever requires processing your photo on a server (for example, an AI-generated preview image), it will be introduced only with a separate, explicit consent step, a defined server retention period of no more than 24 hours, and an update to this policy published before the feature is enabled.
5. Destruction Guidelines
- In-app deletion — the scan screen offers a delete option that permanently and immediately removes the photo and all derived measurements from the device. Deletion is irreversible.
- Uninstalling the app — removes the app's entire private storage, including all scan data, per iOS/Android platform behavior.
6. Security
Scan data is stored in the app's sandboxed private storage, protected by your device's standard encryption and OS-level app isolation. It is not synced, exported, or transmitted by NeckPill.
7. Changes to This Policy
We may update this policy — for example if scan-related features change. The updated version will be posted here with a revised date before any material change takes effect, and material changes to how scan data is handled will require your renewed in-app consent.
8. Contact
Questions or requests regarding this policy:
📧 support@neckpill.app
🌐 neckpill.app