Effective Date: 7/22/2026
Last Updated: 7/22/2026
Version: 2026-07-22
1. INTRODUCTION AND SCOPE
This Privacy Policy (the “Policy”) describes the manner in which Because Love, LLC, a Florida LLC having its principal place of business at 1317 Edgewater Dr #3776, Orlando, FL 32804 (“Company,” “we,” “us,” or “our”), collects, uses, discloses, retains, and otherwise processes Personal Information in connection with:
the “Because Love” mobile application, in any version distributed through the Google Play Store, the Apple App Store, or otherwise (the “App”);
the website located at https://because.love and any subdomains thereof (the “Website”);
the online retail store operated at https://because.love for the sale of apparel and related merchandise (the “Shop”); and
any electronic mail communications, newsletters, or other messaging we send to you (collectively with the App, Website, and Shop, the “Services”).
By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described herein, you must refrain from accessing or using the Services.
This Policy does not apply to any third-party website, application, or service that may be linked to or from the Services, whose data practices are governed by their respective privacy policies.
2. DEFINITIONS
“Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, and includes “personal data” as that term is defined under Regulation (EU) 2016/679 (“GDPR”).
“Processing” means any operation performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, or destruction.
“User Content” means any text, image, journal entry, affirmation, testimonial, comment, photograph, or other material that you create, upload, submit, transmit, or otherwise make available through the Services.
“Service Provider” means an entity that Processes Personal Information on our behalf and pursuant to our documented instructions, and includes a “processor” as defined under the GDPR.
3. CATEGORIES OF PERSONAL INFORMATION COLLECTED
3.1 Information You Provide Directly
(a) Account and Registration Data. The App may be used on an anonymous or pseudonymous basis. Where you elect to create a persistent or authenticated account, we collect your electronic mail address, a display name or username, an authentication credential or third-party authentication token, and, at your election, a profile image.
(b) User Content. We collect and store User Content that you elect to submit, including without limitation: journal entries; manifestation, gratitude, and reflection logs; entries associated with structured practices (including the 55×5, 369, and comparable exercises); “evidence” or “wins” records; affirmations you author, select, or favorite; textual prompts you supply for the generation of images; photographs you upload for use with face-replacement or personalized image-generation features, the collection and Processing of which are additionally governed by Section 16 (Biometric Data) of this Policy and subject to a separate consent obtained within the App prior to upload; short videos and their audio tracks that you record or upload for sharing to the community social feed; and comments, reactions, or messages directed to other users. Content you publish to the social feed (including wins, gratitudes, journal entries, images, and short videos) is disclosed to other users as described in Section 6.2.
(c) Order and Transaction Data (Shop). In connection with purchases from the Shop, we collect your full name, billing address, shipping address, electronic mail address, telephone number (where supplied), order contents, order value, and order history. We do not collect, store, or Process your full payment card number, card verification value, or comparable payment instrument credentials, which are transmitted directly to and Processed by our payment processors as described in Section 6.
(d) Subscription and Credit Data (App). In connection with subscriptions, credit purchases, and in-app purchases, we collect a transaction identifier, purchase token, product identifier, purchase and renewal timestamps, entitlement status, and credit balance and consumption records.
(e) Communications Data. Where you contact us, respond to a survey, or subscribe to a mailing list, we collect the contents of such communication together with your contact details and any metadata associated therewith.
3.2 Information Collected Automatically
(a) Device and Technical Data. Internet Protocol address; device model, manufacturer, and identifier; operating system and version; App version; browser type and version; language and locale settings; time zone; screen dimensions; and network carrier information.
(b) Usage and Analytics Data. Dates and times of access; features accessed; screens viewed; session duration and frequency; interaction events; navigation paths; referring and exit pages; crash reports; diagnostic logs; and error traces. Analytics and diagnostic data do not include the contents of User Content — including journal entries, photographs, prompts, or onboarding selections — nor any data concerning your health or the categories described in Section 3.4.
(c) Approximate Location Data. Approximate geographic location (country, region, and city level) derived from your Internet Protocol address. We do not collect precise geolocation data from your device’s location services.
(d) Cookies and Similar Technologies. As further described in Section 9.
3.3 Information Received from Third Parties
We may receive Personal Information from: (i) authentication providers, where you elect to authenticate by such means; (ii) payment processors and application store operators, in the form of transaction confirmations, subscription status, refund and chargeback notices, and partial payment instrument details (such as the last four digits and expiration date of a payment card); (iii) fulfillment vendors, in the form of shipment, tracking, and delivery status; and (iv) where we conduct marketing campaigns, advertising and analytics partners, in the form of aggregate campaign measurement data. We do not currently employ any install-attribution or referral-tracking software development kit; where we introduce such a program, this Policy will be amended prior to its introduction.
3.4 Information Concerning Health, Wellness, and Beliefs
You acknowledge that User Content submitted to the Services may, by its nature and at your sole election, disclose information concerning your physical or mental health, your financial circumstances, your religious, spiritual, or philosophical beliefs, or other categories of information that may constitute “special categories of personal data” under Article 9 of the GDPR or “sensitive personal information” under applicable United States state law.
We do not require, request, or solicit such information. Where you elect to submit it, you do so voluntarily, and, to the extent applicable law requires a lawful basis for the Processing of such information, you provide your express consent to our Processing thereof for the purpose of operating the Services and delivering the features you have requested. You may withdraw such consent at any time by deleting the relevant User Content or your account. We do not use such information for advertising, profiling, or inference purposes, and we do not sell or share it.
Consumer health data, as defined under the Washington My Health My Data Act and comparable state laws, is additionally governed by our standalone Consumer Health Data Privacy Policy, which describes the categories of such data we may process, the purposes of processing, our sharing practices, and your rights with respect thereto.
The Services are not a medical device, are not intended to diagnose, treat, cure, or prevent any disease or condition, and do not constitute medical, psychological, financial, or legal advice.
4. PURPOSES OF PROCESSING AND LEGAL BASES
We Process Personal Information for the purposes and upon the legal bases enumerated below. Where the GDPR or a comparable regime applies, the identified legal basis governs.
| # | Purpose | Categories Processed | Legal Basis (GDPR Art. 6) |
|---|---|---|---|
| 1 | To provision, operate, maintain, and deliver the Services and the features you request | 3.1(a), 3.1(b), 3.2(a) | Performance of a contract, Art. 6(1)(b) |
| 2 | To create, store, synchronize, and display your journal entries, affirmations, and generated images | 3.1(a), 3.1(b) | Performance of a contract, Art. 6(1)(b); consent, Art. 6(1)(a) and Art. 9(2)(a), as to Section 3.4 data |
| 3 | To generate images and textual content by means of artificial intelligence systems in response to your prompts | 3.1(b) | Performance of a contract, Art. 6(1)(b); consent, Art. 6(1)(a), as to uploaded photographs |
| 4 | To publish User Content you have designated for publication to the community feed | 3.1(a), 3.1(b) | Consent, Art. 6(1)(a) |
| 5 | To process, fulfill, ship, and provide support in respect of Shop orders | 3.1(c) | Performance of a contract, Art. 6(1)(b) |
| 6 | To administer subscriptions, credit balances, renewals, refunds, and entitlements | 3.1(d) | Performance of a contract, Art. 6(1)(b) |
| 7 | To detect, investigate, and prevent fraud, abuse, and unauthorized access, and to enforce our terms | 3.1, 3.2 | Legitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c) |
| 8 | To measure, analyze, and improve the performance, usability, and reliability of the Services | 3.2(a), 3.2(b) | Legitimate interests, Art. 6(1)(f); consent, Art. 6(1)(a), where required |
| 9 | To moderate User Content and respond to notices of alleged infringement or unlawful content | 3.1(a), 3.1(b) | Legitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c) |
| 10 | To transmit transactional and service-related communications | 3.1(a), 3.1(c), 3.1(e) | Performance of a contract, Art. 6(1)(b) |
| 11 | To transmit marketing communications and newsletters | 3.1(a), 3.1(e) | Consent, Art. 6(1)(a); legitimate interests, Art. 6(1)(f), as to existing customers where permitted |
| 12 | To comply with legal, regulatory, tax, and accounting obligations | 3.1(c), 3.1(d) | Legal obligation, Art. 6(1)(c) |
| 13 | To establish, exercise, or defend legal claims, and in connection with a corporate transaction | 3.1, 3.2 | Legitimate interests, Art. 6(1)(f) |
Where we rely upon legitimate interests, we have conducted a balancing assessment and concluded that such interests are not overridden by your interests or fundamental rights and freedoms. You may obtain further information concerning such assessment, and may object to such Processing, by contacting us as provided in Section 17.
5. ARTIFICIAL INTELLIGENCE FEATURES
Certain features of the App employ third-party artificial intelligence systems to generate imagery, affirmations, or other content. Where you invoke such a feature:
the textual prompt you supply, together with any parameters and any image you supply as an input, is transmitted to one or more third-party model providers and their infrastructure vendors acting as our Service Providers;
such providers Process the transmitted data for the purpose of returning generated output to us, and are contractually restricted from using such data for their own independent purposes;
we do not intentionally transmit your name, electronic mail address, or account identifiers to such providers as part of a generation request; provided, however, that we cannot control the contents of a prompt you compose, and you should refrain from including Personal Information within prompts;
generated outputs are stored in our object storage infrastructure and associated with your account for the purpose of delivering the feature to you; and
we do not use your prompts or User Content to train, fine-tune, or otherwise develop artificial intelligence models, and we have contracted with our providers on terms that prohibit their use of such data for the training of their models. We may Process de-identified and aggregated data, which does not identify you and which we will not attempt to re-identify, for the purpose of improving the Services.
Retention and Processing by third-party model providers of transmitted data for their own abuse-detection and legal-compliance purposes, for limited periods, is governed by their respective terms and privacy policies.
6. DISCLOSURE OF PERSONAL INFORMATION
We do not sell Personal Information. We disclose Personal Information solely as follows:
6.1 Service Providers. We engage Service Providers to perform functions on our behalf, bound by written agreements imposing confidentiality obligations and restricting Processing to our documented instructions. The categories of Service Providers we engage, and their functions, are:
| Category | Function | Data Disclosed |
|---|---|---|
| Cloud database, authentication, and serverless compute infrastructure | Hosting of account data, User Content, and application logic | 3.1(a), 3.1(b), 3.1(d), 3.2(a) |
| Object storage and content delivery infrastructure | Storage and delivery of generated images, profile images, and community feed media (images and short videos) | Generated imagery, profile images, and published feed content (images and short videos). Face-replacement source photos are kept on the user’s device and are not stored here. |
| Payment processors | Authorization, capture, settlement, refund, and chargeback handling | 3.1(c), 3.1(d), payment instrument data (collected directly by processor) |
| Application store operators | Processing of in-app purchases, subscriptions, and refunds | 3.1(d) |
| Artificial intelligence model providers and aggregators | Generation of images and content in response to prompts | 3.1(b), as described in Section 5 |
| Product analytics providers | Measurement of feature usage and performance | 3.2(a), 3.2(b) |
| Electronic mail and messaging providers | Transmission of transactional and marketing communications | 3.1(a), 3.1(e) |
| Print-on-demand and fulfillment vendors | Manufacture, packing, and shipment of merchandise | 3.1(c) |
| Carriers and logistics providers | Delivery of merchandise | Name, shipping address, telephone number |
| Website hosting and e-commerce platform providers | Operation of the Website and Shop | 3.1(c), 3.2(a) |
| Professional advisors | Legal, accounting, and audit services | As reasonably necessary |
A current, itemized list of our Service Providers, identified by name, is available upon written request pursuant to Section 17.
6.2 Other Users and the Public. User Content that you affirmatively designate for publication — including posts to the community or “wins” feed, gratitudes, journal entries you choose to share, images, short videos, comments, reactions, and your display name and profile image — is disclosed to other users of the Services and may be publicly accessible. Content you publish in this way may reveal personal, emotional, or health-related information about you; by publishing it, you make it visible to others, and where applicable law treats such content as consumer health data, you consent to that disclosure (see our Consumer Health Data Privacy Policy). Such publication is irrevocable to the extent that other persons may have viewed, copied, or redistributed such content prior to its deletion. Where you join or create a group within the Services, content you submit to that group — including shared notes, messages, and materials submitted for AI-generated summaries — is disclosed to the members of that group. Journal entries and other content not designated for publication or group sharing remain private to your account and are not disclosed to other users.
6.3 Legal and Protective Disclosures. We may disclose Personal Information where we determine in good faith that such disclosure is necessary to: (i) comply with applicable law, regulation, legal process, subpoena, or governmental request; (ii) enforce our terms of service or investigate potential violations thereof; (iii) detect, prevent, or address fraud, security, or technical issues; or (iv) protect the rights, property, or safety of the Company, our users, or the public.
6.4 Corporate Transactions. In connection with, or during negotiations concerning, any merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or dissolution, Personal Information may be disclosed to, or transferred to, a counterparty or successor in interest, subject to the continued application of this Policy or a successor policy affording no less protection. We shall provide notice of any such transfer.
6.5 With Your Direction. We may disclose Personal Information to any other person where you direct or consent to such disclosure.
7. INTERNATIONAL TRANSFERS
We are established in the United States. Personal Information collected by us is Processed and stored in the United States and may be Processed in such other jurisdictions in which our Service Providers maintain facilities. The data protection laws of such jurisdictions may differ from those of your jurisdiction of residence.
Where we transfer Personal Information from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction not the subject of an adequacy decision, we effect such transfer pursuant to appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), together with the United Kingdom International Data Transfer Addendum where applicable, and, where warranted, supplementary technical and organizational measures. A copy of the relevant safeguard may be requested pursuant to Section 17.
8. RETENTION
We retain Personal Information for no longer than is necessary for the purposes for which it was collected, save where a longer retention period is required or permitted by law. Our retention criteria are as follows:
| Category | Retention Period |
|---|---|
| Account data and User Content | For the duration of the account, and for a period of thirty (30) days following a deletion request, after which such data is purged from production systems |
| Anonymous session data (unauthenticated App use) | Until the local application data is cleared or the account is claimed or abandoned; abandoned anonymous accounts are purged after 24 months of inactivity |
| Generated imagery | For the duration of the account, subject to the foregoing |
| Content published to the community social feed (wins, gratitudes, shared journal entries, images, short videos) | For the duration of the account; provided that content removed for violation of our terms may be retained in a moderation record for up to 12 months. Videos and images are stored and delivered via our media/CDN provider |
| Order and transaction records | Seven (7) years, or such longer period as required by applicable tax, accounting, and consumer protection law |
| Subscription and credit records | Seven (7) years |
| Analytics data | 14 months from collection |
| Server, access, and security logs | 90 days from generation |
| Marketing list membership | Until withdrawal of consent or unsubscription, and thereafter a suppression record indefinitely for the purpose of honoring such withdrawal |
| Support correspondence | 3 years from resolution |
Backup media are retained on a rolling basis and are overwritten in the ordinary course within one hundred fifty (150) days. Personal Information subject to a deletion request may persist in backup media until such overwriting occurs, during which period it is not accessible for ordinary Processing. Where backup media are restored to production, previously honored deletion requests are re-applied to the restored data. This 150-day cycle is set so that a deletion (purged from active systems within 30 days) is fully eliminated, including from backups, within the six (6) months required for consumer health data.
We may retain Personal Information notwithstanding the foregoing where necessary to comply with a legal obligation, resolve a dispute, prevent fraud or abuse, or establish, exercise, or defend legal claims.
9. COOKIES AND SIMILAR TECHNOLOGIES
The Website and Shop employ cookies, local storage, and similar technologies. The App employs local device storage and does not use cookies except within embedded web views.
(a) Strictly Necessary. Required for authentication, session management, shopping cart persistence, load balancing, and security. These may not be disabled without impairing the Services.
(b) Functional. Retain your preferences, including language and display settings.
(c) Analytics and Performance. Enable us to measure usage and improve the Services.
(d) Advertising and Attribution. Where employed, enable measurement of the effectiveness of marketing campaigns.
Where we place cookies falling within categories (b), (c), or (d) and applicable law requires consent, we obtain your consent beforehand and provide a consent management interface through which you may withdraw it. You may additionally configure your browser to refuse or delete cookies; such configuration may impair the functionality of the Services.
Do Not Track. Our Services do not respond to “Do Not Track” browser signals. Where required by applicable law, we honor the Global Privacy Control (GPC) signal as a valid request to opt out of the sale or sharing of Personal Information.
10. RIGHTS OF DATA SUBJECTS AND CONSUMERS
10.1 Rights Under the GDPR and UK GDPR
Where you are situated in the European Economic Area, the United Kingdom, or Switzerland, you possess the following rights, subject to the conditions and exceptions provided by applicable law: the right of access (Art. 15); the right to rectification (Art. 16); the right to erasure (Art. 17); the right to restriction of Processing (Art. 18); the right to data portability (Art. 20); the right to object to Processing carried out upon the basis of legitimate interests, including profiling (Art. 21); the right to object to Processing for direct marketing purposes at any time (Art. 21(2)); the right to withdraw consent at any time without prejudice to the lawfulness of Processing carried out prior to such withdrawal (Art. 7(3)); and the right to lodge a complaint with a supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77).
10.2 Rights Under United States State Privacy Laws
Where you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another jurisdiction affording comparable rights, you possess, subject to the conditions and exceptions provided by applicable law: the right to know and to access the categories and specific pieces of Personal Information collected, the sources thereof, the purposes of collection, and the categories of recipients; the right to delete Personal Information; the right to correct inaccurate Personal Information; the right to data portability; the right to opt out of the sale or sharing of Personal Information and of targeted advertising; the right to limit the use and disclosure of sensitive Personal Information; the right to opt out of profiling producing legal or similarly significant effects; and the right not to be subjected to discriminatory treatment for the exercise of any of the foregoing.
Washington and Comparable Consumer Health Laws. Rights with respect to consumer health data under the Washington My Health My Data Act, the Nevada consumer health data law, and comparable statutes — including rights of access, deletion, and withdrawal of consent — are described in, and may be exercised as set forth in, our standalone Consumer Health Data Privacy Policy.
Illinois. The collection and Processing of photographs submitted for face-replacement features, and of any biometric identifiers or biometric information derived therefrom, are governed by Section 16 (Biometric Data) of this Policy, which includes our retention and destruction schedule as required by 740 ILCS 14/15(a).
Statutory Disclosures. We do not and have not, within the twelve (12) months preceding the Effective Date, sold Personal Information or shared Personal Information for purposes of cross-context behavioral advertising, nor have we sold or shared the Personal Information of any consumer known to us to be under sixteen (16) years of age. We do not use or disclose sensitive Personal Information for purposes other than those enumerated in Section 7027(m) of the California Consumer Privacy Act Regulations, and accordingly the right to limit is not applicable. We do not engage in profiling producing legal or similarly significant effects. We do not employ automated decision-making producing legal or similarly significant effects concerning you.
10.3 Exercise of Rights
You may exercise the foregoing rights by: (a) using the account, export, and deletion controls available within the App on the Settings screen; (b) using the unsubscribe mechanism contained in any marketing communication; or (c) submitting a written request to .
We shall verify your identity prior to responding to a request, by reference to your control of the electronic mail address associated with your account or, where you have no account, by reference to such information as is reasonably necessary to match the identifying information in our possession. Where your account was created anonymously and is not associated with an electronic mail address, verification may require demonstration of control of the account through an authenticated session within the App, and requests submitted by other means may be unverifiable. We shall not require the creation of an account for the purpose of submitting a request.
We shall respond within thirty (30) days of receipt of a verifiable request, or within forty-five (45) days where United States state law affords such period, in each case subject to such extension as applicable law permits, of which we shall notify you. Requests are honored without charge, save where manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act, and shall state our reasons.
Authorized Agents. You may designate an authorized agent to submit a request on your behalf, in which case we may require written proof of the agent’s authorization and may require you to verify your identity directly with us.
Appeals. Where we decline to act upon your request and you are a resident of a jurisdiction affording a right of appeal, you may appeal such decision by written notice to bearing the subject line “Privacy Appeal.” We shall inform you in writing of the outcome of the appeal, and our reasons, within forty-five (45) days. Where an appeal is denied, you may contact your state Attorney General to submit a complaint.
11. CHILDREN
The Services are not directed to, and are not intended for use by, any person under the age of sixteen (16) years, and we do not knowingly collect Personal Information from any such person. Persons under the age of eighteen (18) may use the Services only with the involvement and consent of a parent or legal guardian.
Where we become aware that we have collected Personal Information from a child under thirteen (13) years of age without verifiable parental consent, or from a child under sixteen (16) years of age in a jurisdiction in which such age constitutes the threshold for consent to information society services, we shall delete such information without undue delay. A parent or guardian who believes that a child has provided Personal Information to us may contact us pursuant to Section 17.
12. MARKETING COMMUNICATIONS
We transmit marketing communications only where you have subscribed, opted in, or, where permitted by applicable law, where you have purchased a product from us and have not objected. Every marketing communication contains a functioning mechanism by which you may unsubscribe without charge. You may additionally unsubscribe by written notice to . Withdrawal of consent to marketing communications does not affect our transmission of transactional and service-related communications, including order confirmations, shipping notices, security notices, receipts, and notices of material amendment to our terms or this Policy, from which you may not opt out while you maintain an account or a pending order.
Legacy Subscribers. Certain electronic mail addresses in our possession were collected in connection with a previously operated directory service. Where you were a subscriber to such service, you were afforded, and continue to be afforded, the ability to unsubscribe at any time by the means described above.
13. SECURITY
We implement and maintain technical and organizational measures designed to protect Personal Information against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, together with the risks to data subjects. Such measures include encryption of data in transit by means of Transport Layer Security; encryption of data at rest; row-level access controls restricting each user’s data to that user; authentication and access controls upon administrative systems; and the delegation of payment instrument Processing to processors maintaining certification under the Payment Card Industry Data Security Standard.
Notwithstanding the foregoing, no method of transmission over the Internet and no method of electronic storage is entirely secure, and we cannot and do not warrant the absolute security of Personal Information. You are responsible for maintaining the confidentiality of your authentication credentials and for all activity occurring under your account.
Where a personal data breach occurs, we shall notify the competent supervisory authority and affected data subjects to the extent and within the periods required by applicable law.
14. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to, or embed content from, third-party websites, applications, and services. We do not control, and are not responsible for, the privacy practices or the content of such third parties. Your interaction with such third parties is governed by their respective privacy policies, which we encourage you to review.
YouTube. Certain content within the App is embedded from YouTube by means of the YouTube API Services. By viewing such content, you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms) and Google may collect data in connection with such embedded playback as described in the Google Privacy Policy (https://policies.google.com/privacy).
15. AMENDMENTS
We may amend this Policy from time to time. The Effective Date and Version appearing at the head of this Policy indicate the most recent amendment.
Non-material amendments — including corrections, clarifications, updated contact details, and changes that are more protective of you — take effect upon posting.
Material amendments — including any change to the categories of Personal Information we collect, the purposes for which we Process it, the categories of recipients to whom we disclose it, or your rights hereunder — take effect only after we provide conspicuous notice within the Services (and, where you have supplied an electronic mail address, by electronic mail) not less than 30 days in advance, and after you accept the amended Policy. Your continued use of the Services does not constitute acceptance of a material amendment. This Policy and our Terms of Service are presented and accepted together; a single acceptance covers both.
Where an amendment affects Processing carried out upon the basis of your consent — including Processing governed by Section 16 (Biometric Data) of this Policy or by our Consumer Health Data Privacy Policy — we shall obtain fresh consent through the applicable in-app consent mechanism before the amendment applies to that Processing. Consent for such Processing is obtained separately and is not given by acceptance of this Policy.
Each version of this Policy is archived and identified by version number and Effective Date, and prior versions are available upon request.
16. BIOMETRIC DATA (FACE-REPLACEMENT AND IMAGE-GENERATION FEATURES)
This Section describes how we handle photographs submitted for face-replacement and personalized image-generation features, and any biometric identifiers or biometric information that may be derived from them. It is provided to comply with the Illinois Biometric Information Privacy Act (740 ILCS 14) and comparable laws, including Tex. Bus. & Com. Code §503.001 and RCW 19.375 (Washington). The retention and destruction schedule in Section 16.5 constitutes our publicly available written retention schedule and destruction guidelines as required by 740 ILCS 14/15(a).
16.1 Scope. This Section covers (a) photographs you voluntarily submit for use with face-replacement or personalized image-generation features; and (b) to the extent, if any, that a biometric identifier or biometric information within the meaning of applicable law is derived from such a photograph in the course of generating your image. We do not intend or design our features to create such data, and whether generative image models produce it is unsettled; this Section applies to any such data regardless. “Biometric identifier” and “biometric information” have the meanings given in 740 ILCS 14/10. Photographs submitted for other purposes (such as a profile image) are addressed elsewhere in this Policy.
16.2 What we collect and why. When you use a face feature, we collect the photograph you select and transmit it to our image-processing providers, Google LLC (via the Gemini API) and OpenAI, LLC (via the image generation API), whose generative image models use the photograph to produce a new image resembling you, solely so that the person in the generated image looks like you. We collect this data for exactly one purpose: fulfilling your image-generation request. We do not extract, measure, or store a scan of your facial geometry, and we do not use the photograph to identify you, verify your identity, surveil you, or match you against any other person, photograph, database, or record.
Your own photo only. The face features may be used only with photographs of yourself; uploading photographs of other people for these features is prohibited by our Terms of Service. Adults only. The face features are available only to users eighteen (18) years of age or older, and we do not knowingly collect photographs or biometric data from any person under eighteen.
The photo you select is kept on your device so you can reuse it for future generations; you can remove it at any time in the app.
16.3 Consent. We collect your written consent — by affirmative checkbox — before you may submit a photograph, through a dedicated in-app dialog disclosing that a photograph is being collected and disclosed to Google LLC and OpenAI, LLC, the purpose, and how long it is stored. The dialog is not pre-checked and is not bundled with any other consent or with acceptance of our Terms of Service. We record each consent event (account identifier, timestamp, and policy version). If this Section materially changes, we obtain fresh consent before further collection. You may withdraw consent at any time at Settings → Withdraw photo/face consent; withdrawal disables the face features and stops further collection but does not undo processing already completed.
16.4 Disclosure. We disclose photographs and any derived biometric data only to Google LLC and OpenAI, LLC, acting as our Service Provider under a written data processing agreement that limits processing to fulfilling your request and prohibits any independent use, including the training of artificial-intelligence models. We do not disclose them to any other person or entity except where required by valid legal process or applicable law. We do not — and will never — sell, lease, trade, or otherwise profit from your photograph or any biometric identifier or biometric information.
16.5 Retention and destruction schedule.
| Data | Where | Retained until |
|---|---|---|
| Photograph you submit | Our servers | Not stored — transmitted for processing and not retained after your generation request completes. |
| Photograph, and any biometric data that may be derived from it | Google LLC and OpenAI, LLC | Google retains up to 55 days for abuse monitoring (configurable to 7/14/28/55), then deletes; OpenAI retains up to 30 days for abuse monitoring, then deletes. Neither uses it for model training on the paid API. |
| Generated images | Your account’s storage | Until you delete them or your account |
| Consent records | Our servers | Duration of your account plus five (5) years |
Destruction guideline. Any biometric identifier or biometric information is permanently destroyed when the initial purpose for collecting it has been satisfied — upon completion of your image-generation request — or within one (1) year of your last interaction with the App, whichever occurs first. This is earlier than the three-year outer limit BIPA permits. Generated images are not biometric data and are governed by the retention schedule in Section 8.
16.6 Security. We protect photographs and any biometric data using a reasonable standard of care within our industry, at least as protective as that used for other confidential and sensitive information we hold: encrypted transmission (TLS), access restricted to the processing necessary to fulfill your request, and no retention beyond the schedule above.
17. CONTACT
Inquiries, requests, and complaints concerning this Policy or our Processing of Personal Information may be directed to:
Because Love
Attn: Privacy
1317 Edgewater Dr #3776
Orlando, FL 32804
Data Controller. Because Love is the controller in respect of the Processing described herein.
Supervisory Authorities. Data subjects in the European Economic Area may lodge a complaint with the supervisory authority of their Member State; data subjects in the United Kingdom may lodge a complaint with the Information Commissioner’s Office; residents of California may contact the California Privacy Protection Agency or the Office of the Attorney General.

