Legal
Privacy Policy
Cutmirror lets people try a haircut on their own head before they book the professional who can do it. That means we handle photos of your face, and we take that seriously. This policy explains what we collect, why we collect it, and the choices you have. It covers the Cutmirror mobile app for clients and the web portal for barbers and stylists.
Last updated: July 2, 2026
Information we collect
What we collect depends on whether you use Cutmirror as a client or as a professional.
- 01Account information. Your email address, and your name if you sign in with Apple or Google. We use one-time email codes instead of passwords.
- 02Face scans and photos. Clients capture a multi-angle scan (six images: five angles ear to ear, plus the crown) so we can render hairstyles on their own head. Scans include derived attributes such as hair length, texture, density, and hairline.
- 03AI try-on results. The rendered previews we generate for you, including which styles you tried, saved, or shared with a professional.
- 04Booking details. Appointments you book or accept, selected services, notes you add, and the cut sheet shared between client and professional.
- 05Payment information. Payments are processed by Stripe, and in-app subscriptions by RevenueCat and the app stores. We never see or store full card numbers. We keep records of charges, payouts, deposits, and refunds.
- 06Professional profile data. For barbers and stylists: business name, address, services, pricing, policies, portfolio photos, license details submitted for verification, and, if you connect it, your Google Calendar availability.
- 07Device and usage data. Device type, app version, push notification tokens, and product analytics events (screens viewed, features used, errors). Our analytics are first party: events go to our own servers, not to a third-party advertising or tracking network.
How we use your information
- 01Render AI hairstyle previews on your scans and tell you whether a cut is achievable on your hair.
- 02Match clients with nearby professionals and power search, booking, and scheduling, including calendar sync for professionals.
- 03Process payments, deposits, payouts, and subscriptions.
- 04Send transactional messages such as sign-in codes, booking confirmations, and appointment reminders by email and push notification.
- 05Check submitted license details against public state board records to award and display the Verified badge.
- 06Understand how the product is used, fix errors, and improve features.
- 07Prevent fraud and abuse, and comply with legal obligations.
We do not sell your personal information, and we do not use your face scans to train AI models for anyone else.
How face scans are handled
Your scan photos are uploaded over an encrypted connection and stored in access-controlled cloud storage. To produce a try-on, scan images are sent to our AI processing providers, one that analyzes hair attributes and one that renders the preview images and clip, and are used only to generate your results.
We use your face data for exactly one purpose: rendering hairstyle previews of you, for you. We do not use it to identify you, we do not create biometric identifiers or faceprints, we do not use it for advertising, and we do not use it to train AI models for anyone else.
When you book through Cutmirror, the professional you choose sees the cut sheet derived from your scan and try-on (style, lengths, feasibility read, and your notes) so they can prepare for the appointment. Professionals never receive your raw scan photos.
Retention: try-on results you do not save are automatically deleted from our systems after 30 days. Saved results and your scan photos are kept while your account is active so we can render new previews without rescanning, and are deleted when you delete a scan, delete your account in the app, or ask us to delete them.
When we share information
We share personal information only in the following situations.
- 01Between clients and professionals. When a booking is made, each side sees what is needed to complete it: the client sees the professional's public profile, and the professional sees the client's name, cut sheet, and appointment details.
- 02Service providers. Vendors who process data on our behalf: cloud hosting and storage, our AI rendering provider, Stripe for payments, RevenueCat for subscriptions, our transactional email provider, push notification delivery, and Google Calendar when a professional connects it. Each is bound by contract to use the data only to provide their service.
- 03Legal reasons. When required by law, or to protect the rights, safety, or property of Cutmirror, our users, or the public.
- 04Business transfers. If Cutmirror is involved in a merger, acquisition, or sale of assets, your information may transfer as part of that deal. We will notify you before your data becomes subject to a different policy.
Data retention
- 01Unsaved AI try-on results are deleted after 30 days.
- 02Saved try-ons, scans, and library content are kept until you delete them or close your account.
- 03Booking and payment records are kept as long as needed for accounting, dispute resolution, and legal compliance.
- 04Analytics events are kept in aggregate form for product improvement.
- 05When you delete your account, we delete or de-identify your personal information except where we are legally required to keep it.
Your choices and rights
- 01Delete your account directly in the app (Account > Delete account). This permanently removes your profile, scan photos, and try-ons.
- 02Access or correct your account data from the app or by contacting us.
- 03Delete individual scans and try-on results from your library at any time.
- 04Turn off push notifications in your device settings.
- 05Disconnect Google Calendar at any time from the professional portal, which revokes our access.
- 06Request a copy of your data, or ask us to delete it, by emailing us.
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to processing and the right to lodge a complaint with a supervisory authority. We honor these requests regardless of where you live.
Security
All data moves over encrypted connections (TLS) and is stored with access controls and encryption at rest. Authentication uses short-lived one-time codes or Apple and Google sign-in rather than passwords. Access to production data is limited to the people who need it to operate the service.
No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you as required by law.
Children
Cutmirror is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves. If we make material changes, we will notify you in the app or by email before they take effect. The date at the top of this page shows when it was last revised.
Contact us
Questions about this policy or your data? Email us at hello@thecutmirror.com.