Skip to main content
CB CutBrief
  • Product
  • Privacy
  • Terms
  • Support
  • Data Choices

Privacy

CutBrief: AI Barber Card Privacy Policy

This Policy explains how CutBrief handles personal data in the iOS app, backend services, customer support, and related features.

Effective date: August 2, 2026 Last updated: August 2, 2026 Applies in: United States

CutBrief: AI Barber Card is operated by Roman Shainurov, an individual developer based in the Republic of Cyprus (“CutBrief,” “we,” “us,” or “our”).

On this page

  1. Controller and contact
  2. Data we process
  3. Why we process data
  4. OpenAI photo workloads
  5. Recipients
  6. Retention
  7. Choices and rights
  8. International transfers
  9. Security
  10. No tracking, sale, or training
  11. Children
  12. Changes
  13. Contact and complaints

1. Data controller and contact

Roman Shainurov is the data controller for personal data handled by CutBrief, except where Apple or another provider acts as an independent controller under its own terms.

Privacy and support contact: romansh.projects@gmail.com

2. Data we process

We process only data needed to provide, secure, support, and account for the Service.

Photo and temporary media

On the paid path, after the Guided Brief and photo/appearance disclosure and permission, you may provide one photo for quality checks, coarse feature analysis, and recommendations and, only if you separately opt in, an optional visual simulation. The free path does not request a photo. The Service re-encodes and normalizes photos before external AI processing. Raw source photos are temporary and are scheduled for deletion no later than 24 hours after upload, including after completion, cancellation, or failure.

Guided Brief and structured preferences

We process your answers to the Guided Brief, including haircut goals, maintenance preferences, constraints, style preferences, and your confirmation of the structured summary. The Service does not require voice input or unrestricted free-form text for its launch flow.

Coarse derived features

The Service may derive coarse categories and confidence bands needed to prepare recommendations. CutBrief is not designed to identify you. It does not perform face recognition, identity matching, face embeddings, attractiveness scoring, ethnicity inference, personality inference, or medical diagnosis. It is not designed to retain raw facial landmarks, raw measurements, or reusable face-geometry templates.

Account and recovery data

When optional Sign in with Apple is used for cross-device purchase or history recovery, we process a protected Apple account identifier and internal, non-guessable account or app identifiers. These identifiers are used to associate purchases, Generation Pass allowances, history, and deletion requests with the correct account. Sign in with Apple is not required for an anonymous purchase or same-device Restore Purchases, and we do not use it for advertising.

Purchase and delivery records

Apple processes your payment method. CutBrief does not receive your full payment-card details. We may receive and retain StoreKit information such as the product identifier, transaction identifier, purchase status, refund or revocation status, and data needed to maintain a server-verified Generation Pass ledger and delivery record.

History, generated content, and sharing

One free Upgrade snapshot is stored only in local application storage on this device. It is not uploaded as paid History, included in server or account export/deletion, restored by StoreKit or Sign in with Apple, or recoverable across devices or after you clear local history or remove the app data.

After a successful paid run, the Service may store structured recommendation snapshots, the Barber Card package, and generated visual simulations in your history. Raw source media is not stored in history by default. If you create a public share link, we process a scoped share token and the content needed to display that card. Public share links expire after 72 hours by default and can be revoked earlier.

Support data

If you contact support, we process your message, support-visible app identifier, and information reasonably necessary to investigate the request. Please do not send photos, secrets, purchase tokens, or other sensitive material by email unless support expressly asks for it through an approved secure channel.

Network, security, and operational data

Our servers and infrastructure providers process network and technical data necessary to deliver and secure requests, which may include IP address, request time, service status, and limited device or application metadata. We do not use this data for advertising or cross-app tracking. Application logs are designed not to contain raw photos, signed media URLs, secrets, purchase tokens, Guided Brief text, or raw derived facial features.

3. Why we process data

Purposes, typical data, and legal bases
Purpose Typical data Legal basis where the GDPR applies
Provide the requested consultation, recommendations, Barber Card, account recovery, history, export, and deletion tools Photo, Guided Brief, coarse derived features, internal identifiers, history Performance of a contract or steps you request before entering into a contract
Analyze appearance for the paid Barber Card package through OpenAI Responses A normalized and re-encoded paid photo, controlled analysis instruction/schema, and technical request controls Performance of the paid service you request; a separate just-in-time disclosure and affirmative permission is still required before the photo is sent
Create an optional visual simulation through OpenAI Image API A normalized and re-encoded photo and controlled hairstyle transformation instructions Your separate, affirmative simulation consent
Verify purchases, maintain the Generation Pass ledger, deliver paid content, and handle refunds or revocations Apple transaction and delivery records, internal account identifier Performance of a contract; compliance with legal obligations where applicable
Protect the Service, prevent fraud and abuse, diagnose failures, and enforce rate limits Limited network, security, transaction, and audit data Our legitimate interests in operating a secure and reliable paid service, balanced against your rights
Respond to support, privacy, and legal requests Contact message, support identifier, request records Performance of a contract, legitimate interests, and legal obligations as applicable

Where processing depends on consent, you may decline or withdraw consent without losing access to processing that does not require that consent. Withdrawing consent does not affect processing that was lawful before withdrawal.

4. Separate OpenAI photo workloads

The core paid result is the structured set of Safe, Upgrade, and Bold recommendations and the Barber Card package. A generated image is an optional visual simulation, not an exact preview or guarantee of a real haircut result.

For paid appearance analysis, CutBrief intends to send OpenAI Responses a normalized and re-encoded paid photo plus a controlled analysis instruction and strict schema for coarse categories and confidence bands. The request uses store: false. CutBrief does not ask OpenAI to identify you, create a reusable facial template, infer ethnicity, attractiveness, personality, emotion, health or medical/scalp conditions, or invent hairstyles outside the curated ontology. If you decline photo/appearance permission, the paid photo package cannot start; the no-photo free Upgrade remains available.

After a separate simulation consent, the Image API request contains:

  • a normalized and re-encoded photo;
  • controlled hairstyle transformation instructions; and
  • technical request data needed to complete and safely operate the request.

Neither request is intended to include your Guided Brief, hairstyle ontology records, Barber Card, purchase/session/account identifiers, profile text, or stored raw face geometry. Coarse appearance output is not sent to the image-edit workload.

OpenAI states that API data is not used to train its models unless the API customer affirmatively opts in. CutBrief keeps model-training opt-in disabled. Under OpenAI’s standard API controls, input and output content may be retained for abuse monitoring for up to 30 days, and may be retained longer where required for safety or legal reasons. OpenAI also applies safety scanning to image inputs. OpenAI’s current description is available in its API data controls.

The planned store: false request disables the standard 30-day storage of the Response object. It does not disable default abuse-monitoring retention, eliminate every possible form of provider application state, or mean Zero Data Retention. Prompt caching, background mode, audio, conversations/tools, and image/file inputs can have separate state or safety-retention rules if used. Zero Data Retention and Modified Abuse Monitoring require eligibility and OpenAI approval.

The specific Responses model, payload/schema, project controls, and cost budget may change. Before paid photo processing is enabled, CutBrief will ensure that the photo disclosure accurately describes the live configuration and will update this Policy if needed.

If you decline optional simulation processing, you can still receive the core paid recommendations and Barber Card package. Partial simulation failure does not hide that delivered package.

5. Other recipients and service providers

Depending on the production configuration, data may be processed by:

  • Apple, for App Store distribution, StoreKit purchases, refunds, and Sign in with Apple;
  • OpenAI, for paid appearance analysis and, under a separate optional consent, visual simulation;
  • Cloudflare, for hosting and securing this public website and processing the limited network, request, and security metadata needed to serve it;
  • production hosting, database, queue, and object-storage providers, to operate the backend and store data according to the retention rules in this Policy; and
  • professional advisers or public authorities when disclosure is legally required.

We require processors to handle data only for documented service purposes and under applicable data-protection terms. We do not authorize service providers to use CutBrief photos or profile data for their own advertising. You may contact us for information about the current provider categories relevant to your data.

6. Retention

We use the following retention rules and criteria:

  • raw source photos: no longer than 24 hours after upload;
  • public share links and their share-scoped content: 72 hours by default, or earlier if revoked;
  • structured recommendations, Barber Cards, coarse derived features needed for the result, and generated simulations saved to history: until you delete the relevant session or account, subject to backup deletion cycles;
  • local free History: until you use Clear local history, remove the app, or clear its app data; it is not present in server/account backups or cross-device recovery;
  • account and Sign in with Apple linkage: while the account remains active, then deleted or irreversibly unlinked through the account-deletion process;
  • support records: for the time needed to resolve the request and meet applicable record-keeping or dispute obligations; and
  • minimal purchase, refund, delivery, privacy-request, security, and abuse-prevention records: only for as long as needed to meet Apple reconciliation, accounting, tax, fraud-prevention, dispute, or legal obligations.

Deletion from active systems may be followed by deletion through ordinary, access-restricted backup cycles. Apple and independent providers may retain their own transaction, security, or legal records under their policies.

7. Your choices and rights

The Service is designed to provide:

  • separate versioned choices for paid photo/appearance analysis and optional visual simulation;
  • Clear local history for device-only free snapshots, independently of server export/deletion;
  • the ability to withdraw optional consent for future processing;
  • export of your structured account or session data;
  • deletion of an individual session where available;
  • revocation of public share links; and
  • initiation of complete account deletion inside the app.

Depending on where you live, you may also have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to complain to a competent data-protection authority. You may exercise these rights in the app or by contacting us. We may need to verify that a request relates to the correct account or session. See the Data Choices guide for the available in-app paths.

Account deletion removes or irreversibly unlinks the account and associated CutBrief data, revokes Sign in with Apple authorization where applicable, and starts deletion with relevant processors. A short processing period may be necessary to complete queued deletions and backup cycles. The production deletion flow will state the expected completion time and provide confirmation.

Deleting a CutBrief account does not itself request an Apple refund and cannot delete purchase records that Apple retains independently. A consumed Generation Pass is not restored merely because an account is deleted.

8. International data transfers

Some service providers may process data outside the Republic of Cyprus, the European Economic Area, or your country. Where data-protection law requires safeguards for an international transfer, CutBrief uses an applicable mechanism, such as an adequacy decision or approved contractual safeguards. You may contact us for information about applicable transfer safeguards.

9. Security

We use measures intended to protect data in transit and at rest, restrict session access through opaque capability tokens, keep account secrets in secure device storage, separate vendor adapters from the mobile client, rate-limit costly operations, and avoid sensitive data in application logs. No system can guarantee absolute security.

10. No advertising, tracking, sale, or model training

CutBrief does not use third-party advertising SDKs and does not track you across apps or websites owned by other companies. We do not sell personal data or share it for cross-context behavioral advertising. We do not use your photo, Guided Brief, coarse derived features, or generated content for training or model improvement without a separate, affirmative opt-in. No such training opt-in is part of the Service.

The Service does not respond differently to browser or device “Do Not Track” signals because it does not use cross-site or cross-app behavioral tracking. We do not knowingly permit third parties to collect personal data through the Service over time and across unaffiliated apps or websites for advertising.

11. Children

The Service is only for people who are at least 18 years old and have reached the age of majority where they live. If the age of majority where you live is 19, you must be at least 19. We do not knowingly collect personal data from anyone who does not meet this requirement. If we learn that we did, we will take appropriate steps to delete it.

12. Changes to this Policy

We may update this Policy to reflect changes to the Service, providers, or law. We will publish the updated effective date and provide additional notice where required. Material changes will not retroactively expand an optional use of your photo without a new lawful basis or consent where required.

13. Contact and complaints

Questions, rights requests, and complaints may be sent to romansh.projects@gmail.com. If the GDPR applies, you may also complain to the data-protection authority in your country of residence, place of work, or place of the alleged infringement.

CB CutBrief: AI Barber Card

Roman Shainurov · Individual developer · Republic of Cyprus
romansh.projects@gmail.com

  • Privacy
  • Terms
  • Support
  • Data Choices

Recommendations require your judgment and a barber’s in-person assessment. CutBrief does not guarantee a haircut result and does not use advertising tracking.