Privacy Policy
Effective Date: August 10, 2025 | Last Updated: April 11, 2026
GSD Co., Ltd. ("Company") values the privacy of users of the VIREON PRIME:ON application ("App") and complies with applicable data protection laws. This policy explains how we collect, use, store, and protect your personal information.
1. Information We Collect
1.1 Account Information
- Email address, name, date of birth, gender
- Device serial number (for product registration)
- Login provider information (email, Google, Apple, Kakao)
1.2 Device and Usage Data
- Device model, OS version, app version
- BLE (Bluetooth Low Energy) connection data for PRIME:ON device communication
- Care session records (mode, duration, settings used)
1.3 Camera and Face Data
The App collects face data only with the user's explicit consent, granted during the onboarding process and before each camera session. Below is a detailed description of each type of face data collected, the reasons for storage, retention periods, and third-party sharing practices.
1.3.1 Facial Photos
- What is collected: Facial photos captured via the device camera.
- Reason for collection: Solely for AI-powered skin condition analysis (evaluating hydration, elasticity, pore size, skin tone, sensitivity, and oil/sebum levels).
- Storage duration: Facial photos are temporarily held in device memory only during the analysis process (typically less than 60 seconds). Photos are deleted immediately after the AI analysis is complete. Photos are never permanently stored on any server or device storage.
- Reason for this duration: Photos are retained only for the minimum time required to transmit them to the AI analysis service and receive results. No longer retention is necessary as the analysis produces numerical scores and text recommendations that are stored separately.
- Third-party sharing: Facial photos are transmitted to Google Gemini API exclusively for skin analysis processing. See Section 1.3.4 below for Google's data handling practices.
1.3.2 Face Contour Landmarks
- What is collected: Face contour landmark coordinate points detected using Google ML Kit Face Detection.
- Reason for collection: Used exclusively for real-time on-screen guidance to help users align their face correctly during photo capture.
- Storage duration: Face contour landmarks are processed in real-time in device memory and are not persisted to any storage. They exist only during the active camera session and are discarded when the camera screen is closed.
- Third-party sharing: Face contour landmarks are processed entirely on-device using Google ML Kit. No face contour data is transmitted to any server, including Google's servers. Google ML Kit runs locally on the device.
1.3.3 Face Calibration Data (Optional)
- What is collected: With explicit user consent, normalized face contour coordinate data (12 points), head angle measurements, and face aspect ratio.
- Reason for storage: Stored to enable face matching and camera alignment calibration in subsequent sessions, so users do not need to re-register their face position each time they use the AI Care feature.
- Storage duration: Retained for a maximum of 12 months from the date of creation, or until the user manually deletes it, re-calibrates, or deletes their account — whichever comes first.
- Reason for this duration: 12 months is chosen because facial features may change over time, making older calibration data less accurate. Users are encouraged to re-calibrate periodically for best results.
- Storage location: Stored locally on the user's device and in the user's Firebase Firestore document (encrypted in transit and at rest).
- Third-party sharing: Face calibration data is never shared with any third party. It is stored only in the user's own Firebase Firestore document and on their device.
- User control: Users can delete their face calibration data at any time through the camera settings within the app.
1.3.4 Third-Party Face Data Practices
The only third party that receives any form of face data is Google, through the Google Gemini API:
- Google Gemini API: Receives facial photos for AI skin analysis processing.
- Reason for sharing: Google Gemini API provides the AI model that analyzes facial photos to evaluate skin conditions. This analysis cannot be performed on-device due to the complexity of the AI model.
- Does Google store face data? According to Google's API data usage policies, data sent to the Gemini API for processing is not used to train Google's models and is not retained after processing is complete. Google processes the data transiently to generate the analysis response and does not store the facial photos. For more details, refer to Google Gemini API Terms of Service.
- Google ML Kit: Processes face detection entirely on-device. No face data is sent to Google's servers through ML Kit. Google ML Kit does not store any face data.
1.4 AI Analysis Results
- Numerical skin condition scores (hydration, elasticity, pore, skin tone, sensitivity, oil/sebum)
- Estimated skin age
- AI-generated text recommendations and improvement suggestions
- Recommended care mode configurations
2. How We Use Your Information
- Account Management: User authentication, profile management, and device registration
- AI Skin Analysis: With the user's explicit consent, facial photos are sent to Google Gemini API to analyze skin condition and provide personalized care recommendations. Users are informed of this processing before each analysis session.
- Face Alignment Guidance: Face contour data is processed entirely on-device to display real-time positioning guidance during photo capture. This data is not transmitted externally.
- Smart Device Control: Managing BLE communication with the PRIME:ON beauty device
- Progress Tracking: Storing analysis results and care session history to track skin condition changes over time
- Personalized Recommendations: Using analysis history to recommend optimal care routines
- Push Notifications: Sending care reminders, weekly reports, and app updates via Firebase Cloud Messaging
3. Data Sharing and Disclosure
We do not sell your personal information. Data is shared only with the following third-party services, strictly for the purposes described:
- Google Gemini API: With user consent, facial photos are transmitted for AI skin analysis. Google processes the images solely for analysis purposes in accordance with their privacy policies.
- Firebase (Google): Account authentication, data storage (Firestore), push notifications (FCM), and crash reporting (Crashlytics)
- Google ML Kit: Face detection processing occurs entirely on-device. No face data is transmitted to Google servers through ML Kit.
Face contour landmark data is processed entirely on-device and is never transmitted to any external server or third party. Users explicitly consent to facial photo processing during the onboarding process and are informed before each AI analysis session.
4. Data Retention and Deletion
4.1 Face Data Retention
- Facial Photos: Not stored. Temporarily held in memory during AI analysis (less than 60 seconds) and deleted immediately after processing. No facial photos are retained on any server or device storage.
- Face Contour Landmarks: Not stored. Processed in real-time during active camera sessions only. Discarded when the camera screen is closed.
- Face Calibration Data: Retained for a maximum of 12 months or until the user deletes it, re-calibrates, or deletes their account. This duration is chosen because facial features may change over time, making older calibration data less accurate.
4.2 Other Data Retention
- AI Analysis Results: Numerical scores and text recommendations (no photos) are retained until the user deletes their account.
- Care Session History: Retained until the user deletes their account.
- Account Data: Upon account deletion, all associated user data — including face calibration data, AI analysis results, and care session history — is permanently removed within 30 days.
5. Data Security
- All data transmission is encrypted using TLS/SSL
- FCM tokens are stored using encrypted secure storage on the device
- Firebase security rules restrict data access to authenticated users and their own data only
- Passwords are managed by Firebase Authentication and are never stored in plaintext
6. Children's Privacy
The App is not intended for use by children under the age of 14. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 14, we will promptly delete it.
7. Your Rights and Choices
You have the right to:
- Access and review your personal information through the App's Profile section
- Update or correct your personal information at any time
- Delete your account and all associated data (Profile > Delete Account)
- Opt out of push notifications through device settings
- Re-calibrate or delete face contour data at any time through the camera settings
8. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the App after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Company: GSD Co., Ltd.
- Email: jsb@wgsd.co.kr
- Website: https://vireon-primeon.web.app