LipMax Privacy Policy
Effective date: 15 August 2026
LipMax is provided by HR DEVELOPMENT LLC, 5830 E 2nd St, Ste 7000 #31401, Casper, Wyoming 82609, United States ("HR DEVELOPMENT," "LipMax," "we," "us," or "our"). HR DEVELOPMENT LLC is the controller of personal data processed for LipMax.
This Privacy Policy explains how LipMax processes information when you use the LipMax iOS application (the "App"), visit the LipMax website, contact us, sign in with Apple or Google, or purchase a LipMax subscription through the Apple App Store.
Contact us about privacy or support at hzakzak8@gmail.com.
Key points
- Lip scans happen on your iOS device. The scan photo and facial landmarks are not uploaded to LipMax, OpenAI, or another server.
- Optional progress photos stay in the App's protected local storage. LipMax does not upload them.
- Everyone must sign in with Apple or Google. Our server stores a LipMax account ID and keyed hashes, not your raw Apple or Google account identifier, name, email address, ID token, or session token.
- LipMax subscriptions are sold only through Apple's App Store. LipMax does not receive your full payment-card details. LipMax offers no free trial.
- The online AI plan and AI coach use OpenAI and are available only to users aged 18 or older. OpenAI receives limited text, selections, scores, and a pseudonymous safety identifier; it does not receive photos, facial landmarks, your name, email address, Apple transaction JWS, or raw Apple transaction identifier.
- LipMax has no advertising, cross-app tracking, or product-analytics service, and we do not sell personal data.
- Delete Account removes your live LipMax server account and attempts to erase LipMax data and credentials stored by the App on that device. The App reports if any local cleanup cannot be confirmed. Account deletion does not cancel an Apple subscription, remove originals from your Apple Photos library, or delete your Apple or Google account.
1. Scope
This Policy applies worldwide to the App, LipMax's authentication and AI endpoints, the LipMax informational website, and support communications.
The website provides product information, support information, and legal notices only. It does not provide lip scanning, accounts, coaching, or checkout. Lip scanning and App Store purchases are iOS App functions.
This Policy does not govern Apple, Google, OpenAI, Cloudflare, or a destination you choose through the iOS share sheet when those parties process information for their own purposes. Their notices are linked below.
2. Age requirements and minors
The App is for people aged 13 or older. If you are under the age of legal majority where you live, you may use the App only with permission from a parent or legal guardian. A person under 13 may not create an account or use LipMax.
The online AI plan and AI coach are limited to users aged 18 or older. Users aged 13 through 17 may use eligible on-device and non-AI App functions with guardian permission, but LipMax does not send their profile information, scores, or coach questions to OpenAI. This restriction reflects OpenAI's current Under 18 API Guidance, including its requirements concerning minors' personal data and Zero Data Retention.
LipMax asks for an age band in the App. The age band remains on the device and is used to apply the age restriction; Apple and Google sign-in are not used to obtain your date of birth. We do not use age information for advertising or profiling.
If we learn that a person under 13 created an account, we will delete the live server account and associated server data. Because we do not keep an account email address on our server, we may need the user or guardian to make the request through a signed-in device or provide information that lets us securely identify the LipMax account. A guardian may contact hzakzak8@gmail.com.
3. Information processed by LipMax
"Processed" includes information handled only on your device as well as information sent to our server. The sections below distinguish between them.
3.1 Information that stays on your device
Depending on the features you use, the App processes or stores the following locally:
Scan photo and facial measurements. You may take a photo with the camera or select a photo using Apple's photo picker. The App uses Apple's Vision framework to locate the facial, eye or pupil, nose, mouth, and lip points needed to normalize measurements and calculate lip proportions. The source image and working landmarks are used in memory during the scan. LipMax does not upload or retain the source scan image or the landmark set. Temporary App copies are protected and removed after processing, after a failed scan, and during later crash-cleanup if an earlier cleanup did not finish.
Scan results and progress. The App may store the date of a scan, display and potential scores, component scores, recommended focus area, rescan history, plan progress, completed tasks, streaks, experience points, and badges in local App storage. Focus areas can include vertical balance, fullness, mouth proportions, cupid's bow, symmetry, philtrum, and lip-to-chin balance.
Profile and onboarding answers. The App may store your selected age band; gender expression; lip and appearance goals; current routine; aesthetic preferences; time commitment and timeline; perceived insecurity or self-consciousness; dating or attraction context; whether you are considering filler; smoking or vaping; hydration, sun, and climate habits; and descriptions such as dry, chapped, uneven-tone, or normal lips. These answers can be personal or sensitive. They remain local except for the smaller, specifically listed subset sent when an eligible adult deliberately uses an online AI feature, as described in Section 3.4.
Progress photos. If you choose to create progress photos, the App stores separate image files in its local Application Support directory. Those files use iOS file protection and are marked to be excluded from device backup. A progress photo may also be selected as the local profile image. LipMax does not upload progress photos.
AI results and coach history. The App stores the plan returned for you, plan progress, and up to the most recent 50 coach messages locally so that the features work on your device. The server does not maintain a chat history or plan history in the LipMax database.
Account display data and credentials. The App may retain the name, email address, provider user identifier, LipMax account identifier, sign-in provider, and LipMax session credential returned during Apple or Google sign-in. Credential material is stored using the iOS Keychain. This local information is used to display and maintain your signed-in session; our server does not store the name, email address, raw provider identifier, or raw session credential.
Settings and permissions. The App stores onboarding state, reminder choices, notification schedules, consent choices, and similar settings locally. Camera, photo-library or photo-picker, add-to-Photos, and local-notification access are requested through iOS when needed. LipMax does not request location, contacts, microphone, HealthKit, or App Tracking Transparency permission.
Apple may include some ordinary App data in an iCloud or device backup according to your Apple settings. LipMax specifically excludes its progress-photo files from backup, but HR DEVELOPMENT does not control backups that Apple creates or retains.
3.2 Account and sign-in information handled by our server
Sign-in is required. You can choose Sign in with Apple or Sign in with Google.
During sign-in, the App sends our server a short-lived provider ID token, a one-time LipMax challenge and state value, and, for Apple sign-in, an Apple authorization code. A provider token may contain claims supplied by Apple or Google, potentially including an email address. Our server verifies the token's signature, issuer, audience, expiration, subject, and nonce using the provider's public signing keys. The raw provider token, authorization code, state, nonce, and provider subject are handled transiently and are not saved in our database.
Our Cloudflare D1 database stores:
- a random LipMax account identifier;
- whether the sign-in provider is Apple or Google;
- a keyed HMAC-SHA-256 value derived from the provider's account subject;
- account creation and last-login timestamps;
- keyed HMAC-SHA-256 values for one-time challenges, state, and nonce, with creation, expiry, and consumption timestamps;
- a keyed HMAC-SHA-256 value derived from the LipMax session token, with creation, expiry, and revocation timestamps;
- keyed rate-limit values, including keyed values derived from an IP address; and
- for Apple sign-in only, an Apple refresh token encrypted with AES-256-GCM and bound to the keyed Apple identity. The encryption key is held as a Cloudflare Worker secret, not in D1. LipMax retains this refresh token only so it can ask Apple to revoke the Sign in with Apple grant when the LipMax account is deleted.
The raw LipMax session token is held by the App in the iOS Keychain. The keyed hashes are pseudonymous security identifiers: they are designed to prevent the database from revealing the original value, but they are still treated as personal data where applicable law says they are personal data.
3.3 Apple App Store subscription information
LipMax offers paid, auto-renewing subscriptions through Apple's in-app purchase system. There is no free trial. Apple controls checkout, billing, refunds, tax handling, payment credentials, subscription renewal, and the App Store purchase history under Apple's Privacy Policy.
The App provides our server an Apple-signed transaction in JSON Web Signature (JWS) form when a premium feature needs entitlement verification. The JWS can contain an original transaction identifier, transaction identifier, product identifier, bundle identifier, purchase and expiration dates, environment, ownership type, and status-related claims. Our server:
- verifies the JWS signature and certificate chain against Apple's trusted roots;
- checks that the bundle, environment, product, transaction type, ownership, dates, and other claims match LipMax's rules;
- contacts Apple's App Store Server API to confirm the current subscription status; and
- derives a keyed HMAC from the original transaction identifier for abuse prevention, per-subscription rate limits, and short concurrency controls.
The raw JWS and raw transaction identifiers are not stored in the LipMax application database and are never sent to OpenAI. LipMax does not receive or store your full credit-card or bank-account details. Apple may provide HR DEVELOPMENT with App Store financial, sales, and subscription reporting under Apple's own terms.
3.4 Online AI information — adults only
LipMax uses the OpenAI API for two adult-only functions. Before personal data is first sent to OpenAI, the App identifies OpenAI, shows what data will be sent and why, and asks for your explicit permission. Declining that permission prevents the online AI feature from sending data but does not prevent eligible on-device functions.
AI plan. When an eligible adult requests a plan, the App sends our server:
- selected goals, such as fuller appearance, symmetry, definition, glow-up, or smile;
- selected routine items, including whether the person currently uses nothing, balm, makeup, products, or filler;
- selected habits, such as hydration, smoking, sun exposure, or dry climate;
- selected lip descriptions: dry, chapped, uneven tone, or normal;
- selected time commitment and timeline;
- the display score, potential score, and focus category; and
- the Apple subscription JWS used to verify premium access.
After entitlement verification and validation, our server sends OpenAI the listed profile selections and scores, the allowed LipMax task identifiers, and a pseudonymous safety identifier derived with a keyed HMAC from the Apple original transaction identifier. The Apple JWS, raw transaction identifier, photo, facial landmarks, name, email address, provider account identifier, local age band, gender expression, insecurity answer, dating or attraction context, and progress photos are not sent to OpenAI. OpenAI returns a structured selection of LipMax task identifiers; LipMax, not OpenAI, supplies the task wording shown in the plan.
AI coach. When an eligible adult submits a coach question, the App sends our server the question, the Apple subscription JWS, and normal request metadata. Questions are limited to 500 characters. Some high-risk or unsupported questions are handled by fixed LipMax safety rules without being sent to OpenAI. For other eligible questions, our server sends OpenAI only the question, instructions, and the same pseudonymous safety identifier. OpenAI returns a safety category; LipMax shows a short response written and controlled by LipMax. OpenAI does not receive the Apple JWS or the other data excluded above.
Rescan comparison. The App may send previous and current score summaries plus the Apple subscription JWS to our server. Our server verifies the entitlement and creates the comparison response itself. Rescan comparison data is not sent to OpenAI.
OpenAI storage and training. LipMax uses OpenAI's Responses API with store: false, so LipMax does not ask OpenAI to keep the response as a retrievable response object. OpenAI states that API inputs and outputs are not used to train or improve its models unless the business customer expressly opts in. HR DEVELOPMENT does not authorize that opt-in for LipMax data. Under OpenAI's standard API controls, however:
- abuse-monitoring logs may contain prompts, responses, and related metadata for up to 30 days, unless OpenAI must retain them longer by law or reasonably needs longer retention to protect its services or a third party from harm; and
- prompt caching may keep encrypted key/value tensors in GPU-local storage for no more than 24 hours.
LipMax does not currently represent that its OpenAI project has Zero Data Retention. See OpenAI's official API data controls and business-data privacy commitments.
Do not put information in a coach question that you do not want sent to OpenAI. In particular, do not include a full name, email address, phone number, address, account credential, payment information, or another person's personal data.
3.5 Network, security, device, and website information
Cloudflare delivers the website and backend and receives network information needed to route and protect requests. This can include an IP address, request date and time, URL or endpoint, method, response status, user agent, protocol, Cloudflare Ray ID, and security or error information. The LipMax application database stores a keyed HMAC derived from an IP address for rate limiting instead of storing the raw IP address in its rate-limit tables. Cloudflare may still process the raw IP address as infrastructure provider.
Cloudflare Workers observability is used for operational and security logs, not product analytics. LipMax does not put scan photos, progress photos, provider tokens, Apple JWS values, coach questions, or full OpenAI prompts into its own custom application logs.
The website does not use advertising cookies, tracking pixels, product analytics, or browser local storage for a LipMax account. Cloudflare may use strictly necessary security mechanisms when needed to protect and deliver the site. Those mechanisms are not used by HR DEVELOPMENT to create advertising profiles.
3.6 Support communications and user-directed sharing
If you email us, we process your email address, message, attachments, and information you choose to provide. Support email is provided through Google, so Google processes the communication as our email service provider under its applicable terms and Privacy Policy.
If you use the iOS share sheet, LipMax creates a score card that does not contain the scan photo and passes it to the destination you select. Apple and the receiving app or person then process the shared item according to your instruction and their own practices. If you save an item to your Photos library, that new Photos copy is controlled by you and is outside LipMax's local App container.
4. Why we process information and our legal bases
The legal bases below apply where laws such as the UK GDPR or EU GDPR require a legal basis. Other jurisdictions may use different terminology.
| Purpose | Information | Legal basis |
|---|---|---|
| Run local scans and calculate an entertainment/self-improvement score | Photo, temporary landmarks and measurements, local score | Your consent and deliberate request; you may decline camera or photo access |
| Create and maintain a mandatory LipMax account | Provider token and code, provider subject, LipMax account and session data | Performance of our contract with you |
| Secure sign-in and prevent fraud, abuse, replay, and excessive use | Challenges, timestamps, keyed identifiers, network and security metadata | Our legitimate interests in protecting users, services, and costs; and performance of our contract |
| Verify and provide paid premium access | Apple JWS and status, product and expiry claims, keyed subscription rate identifier | Performance of our contract and steps you request; legal obligations where applicable |
| Provide an online AI plan or coach response to an adult | Limited profile selections, scores, question, pseudonymous safety identifier | Your explicit permission for the transfer to OpenAI and performance of the feature you request |
| Save progress and personalize the App locally | Local profile, results, photos, plan, messages, progress, preferences | Performance of our contract and your deliberate choices; consent where required for sensitive processing |
| Schedule reminders | Local reminder settings and notification permission | Your consent; you can turn notifications off in iOS Settings |
| Diagnose failures and protect infrastructure | Request, error, device/network and security metadata | Our legitimate interests in reliable and secure operation |
| Answer support and privacy requests | Email and request content | Performance of our contract, our legitimate interests in support, and legal obligations |
| Comply with law or establish, exercise, or defend legal claims | Information relevant to the obligation or claim | Legal obligation or legitimate interests, as applicable |
Where we rely on legitimate interests, we consider the necessity of the processing, its privacy impact, and your rights. We do not rely on legitimate interests to send an adult's personal profile information or coach question to OpenAI where explicit permission is required.
You can withdraw consent at any time by not using the relevant feature, changing iOS permissions, turning off notifications, declining the OpenAI permission, deleting optional local data, or deleting the account. Withdrawal does not make earlier lawful processing unlawful. If data is essential to a feature, withdrawing permission means that feature cannot operate.
5. Facial measurements and sensitive information
LipMax uses facial landmarks only to calculate lip proportions and an entertainment/self-improvement score on the device. LipMax does not use the measurements to identify who you are, authenticate you, compare you against a face database, infer a legal identity, or create a reusable face template or embedding. The source photo and landmark set are not uploaded to our server.
Some laws may nevertheless treat face geometry, an appearance photo, smoking information, or other profile answers as biometric, health-related, or otherwise sensitive personal information. LipMax minimizes that risk by keeping the source photo, landmarks, progress photos, and most profile details on the device and by requiring a deliberate action before processing.
LipMax is not a medical device, and its scans, scores, plans, and coaching are not a diagnosis, treatment, or substitute for professional medical or mental-health advice.
6. When information is disclosed
We disclose information only as described below:
Cloudflare. Cloudflare, Inc. hosts the website and API, processes requests at its network edge, provides Workers observability, and stores the server records listed in this Policy in D1. Cloudflare acts as a processor or service provider for customer data processed on our instructions. See Cloudflare's Privacy Policy, D1 data-location documentation, and D1 data-security documentation.
OpenAI. OpenAI processes the limited adult AI data described in Section 3.4 to classify a coach question or select plan task identifiers. LipMax does not use Anthropic or another AI provider for these features. OpenAI is not authorized by HR DEVELOPMENT to use LipMax API input or output for model training.
Apple. Apple provides iOS, camera and photo permission controls, the photo picker, Vision, Keychain, local notifications, Sign in with Apple, StoreKit, App Store payment and subscription administration, transaction signing, and the App Store Server API. Apple processes information for its own services under its privacy policy.
Google. Google provides Google sign-in and our Gmail-based support mailbox. Google receives information necessary for those services under its privacy policy. The App requests the openid, email, and profile sign-in scopes. Our server retains only the keyed provider subject and the server fields listed in Section 3.2; local display information may remain in the iOS Keychain.
A destination you choose. Information is disclosed when you direct the iOS share sheet, Photos, email, or another destination to receive it.
Legal, safety, and business needs. We may disclose information when reasonably necessary to comply with law or valid legal process; protect a person's safety; investigate fraud, abuse, or security incidents; enforce our agreements; or establish, exercise, or defend legal claims. If HR DEVELOPMENT is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, data may be reviewed or transferred subject to confidentiality and applicable law. We will not use such a transaction to override choices that law requires us to honor.
When a provider processes personal data on our behalf, we require protection consistent with this Policy, the provider agreement, and applicable law. Apple and Google also process some information as independent providers for their own services, and their own privacy notices apply to that processing.
7. How long information is retained
We use the periods below or, where no fixed period is possible, the stated criteria.
| Information | Retention |
|---|---|
| Source scan image and facial landmarks | Used only for the scan and deleted from the App's temporary working storage promptly after success or failure; crash remnants are removed during later cleanup |
| Local profile, score history, plans, progress, messages, settings, and optional progress photos | Until you remove the item, reset the App where offered, or complete Delete Account. If the App reports that local cleanup could not be confirmed, the local data remains until you retry or use a separate local-data deletion control. Uninstalling the App ordinarily removes its container from that device, subject to Apple-controlled backups |
| Active LipMax account, provider-identity HMAC, and encrypted Apple refresh token | Until account deletion; the live D1 row is deleted as part of account deletion |
| LipMax session | Valid for 30 days unless revoked earlier; after expiration it cannot authenticate and its row is removed in bounded maintenance batches during later service requests |
| Sign-in challenge, state, and nonce HMACs | Challenge is valid for 5 minutes; consumed challenges become eligible for deletion after 1 hour, and expired challenges are removed in bounded maintenance batches during later sign-in requests |
| Authentication and native-AI rate-limit HMACs | Become eligible for deletion 24 hours after last update and are removed in bounded maintenance batches during later service requests |
| Native AI concurrency lease | Normally deleted as soon as the OpenAI request finishes; otherwise it expires after 25 seconds and is removed in later maintenance |
| Account-deletion identity lease | Retained for up to 10 minutes after deletion begins to prevent an in-flight sign-in from recreating the account; then removed in later maintenance |
| Raw provider ID token, Apple authorization code, Apple transaction JWS, raw Apple transaction identifier, and AI request body in LipMax | Processed in memory for the request and not stored in the LipMax application database |
| Cloudflare Workers operational logs | Cloudflare controls the infrastructure copy. Under Cloudflare's current Workers Logs product limits, logs can be retained for up to 7 days. LipMax uses them only for security, reliability, and troubleshooting |
| Deleted D1 data in Cloudflare recovery history | Cloudflare controls the recovery copy. D1 Time Travel may preserve a recoverable historical version for up to 30 days, depending on the Cloudflare plan. It is not queried as part of the live account during ordinary operation and ages out under Cloudflare's recovery window. Restoring an older database could reintroduce an older row, so deletion requests must be reconciled before a restored database is returned to service. See Cloudflare's Time Travel documentation |
| OpenAI API content | store: false is used; separate encrypted prompt-cache state may remain up to 24 hours, and standard abuse-monitoring logs may remain up to 30 days, subject to the limited longer-retention exceptions described in Section 3.4 |
| Support and privacy correspondence | Until the request is resolved and for any additional period reasonably necessary to document compliance, prevent abuse, resolve a dispute, or meet a legal obligation; then deleted or de-identified |
Cleanup of short-lived D1 security records is deliberately bounded so maintenance cannot overwhelm the service. An expired record can therefore remain in the database after it has stopped being usable, until a later relevant request runs the next deletion batch. If a deletion operation is interrupted after an account is marked for deletion, common maintenance finalizes a stale deletion after 24 hours.
Apple and Google retain provider-account and purchase information according to their own policies and legal duties. LipMax account deletion does not control their retention.
8. Account deletion, sign-out, and subscription cancellation
Delete a LipMax account
Use Delete Account in the App's settings. When the server confirms that deletion succeeded, LipMax removes the following server data and the App attempts to erase the listed data on the current device:
- the live server account ID, keyed Apple or Google identity, encrypted Apple refresh token, and all LipMax sessions linked to that account;
- LipMax session and account credentials stored in the iOS Keychain; and
- local profile answers, scan and score history, plans, task progress, local coach messages, streaks, badges, settings, temporary App image copies, pending LipMax reminders, and LipMax progress photos stored by the App on that device.
If the App cannot confirm that Keychain records or other local data were removed, it reports the local cleanup problem even though the server account deletion remains complete. You can then retry the local cleanup. Because local data is not synced, repeat local cleanup on any other device on which you used LipMax.
If the App separately offers Delete My Data, that control erases local data and credentials from the current device without deleting the live LipMax server account. If its server sign-out request cannot be completed, the server session remains subject to the session period in Section 7 even though its credential has been removed from the device.
Short-lived keyed rate-limit records and the 10-minute deletion lease may remain for the security periods in Section 7. Cloudflare's isolated D1 recovery history may retain an older recoverable database state for up to 30 days. It is not queried as an active LipMax account during ordinary operation. If an older database is restored, deletion requests must be reconciled before that database is returned to service.
For an Apple-linked account, LipMax attempts to use the encrypted refresh token to revoke the Sign in with Apple grant. If Apple is unavailable or the token cannot be used, LipMax still deletes the account and tells the App that manual provider disconnection is required. For a Google-linked account, LipMax deletes its own records but does not hold a Google refresh token with which to revoke the Google connection. You can separately manage connected services in your Apple ID or Google Account. Disconnecting LipMax at Apple or Google does not by itself delete the LipMax account; use the in-App deletion control too.
Deleting the account does not delete the Apple or Google account, an original image in the Apple Photos library, a score card or other copy you saved outside the App, a message already sent to another person, or an Apple-controlled purchase record.
Deleting the account does not cancel an Apple subscription
An auto-renewing Apple subscription can continue after LipMax account deletion until you cancel it with Apple. To avoid another renewal, cancel through iOS Settings > your name > Subscriptions or Apple's subscription-management page. Apple, not HR DEVELOPMENT, controls cancellation timing, billing, and refunds. LipMax has no free trial.
Apple's developer guidance also confirms that account deletion and App Store subscription cancellation are separate processes. See Offering account deletion in your app.
Sign out or uninstall
Signing out attempts to revoke the current LipMax session on our server and removes the local active session. If the server cannot be reached, the server session remains subject to the session period in Section 7, but its credential is removed from that device. Signing out does not delete the account or other local progress. Uninstalling removes the App container from that device but does not reliably delete the server account, cancel the Apple subscription, or control an Apple backup. Use Delete Account when you want the server account and the App's data on the current device removed.
9. Your choices and privacy rights
You can:
- choose Apple or Google sign-in;
- decline camera or photo access and avoid scanning;
- decline or later withdraw permission to send adult AI data to OpenAI;
- use iOS Settings to change camera, Photos, or notification permission;
- omit optional progress photos and remove locally stored content;
- avoid placing direct identifiers or sensitive details in a coach question;
- sign out;
- delete the LipMax server account and LipMax data on the current device with Delete Account; and
- use Delete My Data, if offered, to erase only the current device's LipMax data without deleting the server account.
Depending on where you live, you may have the right to request access to, confirmation of, or a copy of personal data; correct inaccurate data; delete data; restrict or object to processing; receive portable data; withdraw consent; opt out of certain disclosures or automated processing; appeal a denied privacy request; and complain to a privacy or data-protection authority. We will not unlawfully discriminate against you for exercising a privacy right.
LipMax does not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising, or offer a financial incentive in exchange for personal data. Because LipMax does not engage in those activities, a Global Privacy Control signal does not change how the site operates.
To make a request, email hzakzak8@gmail.com, use Delete Account for the server account and current-device LipMax data, or use Delete My Data, if offered, for local data only. State that the request concerns LipMax and describe the right you want to exercise. For security, we may ask you to verify control of the signed-in App session or provide the LipMax account identifier. We will not ask for your Apple or Google password. Because the server does not store your name or email address, we may be unable to locate a server account using an email address alone.
An authorized agent may submit a request where local law permits. We may require evidence of authority and may ask the user to verify the request directly. A parent or legal guardian may exercise rights for a minor where applicable law permits or requires it.
If EU, EEA, UK, or Swiss data-protection law applies, you may lodge a complaint with the supervisory authority where you live or work, or where you believe a violation occurred. We encourage you to contact us first so we can try to resolve the concern. Our use of appearance scores or AI does not produce a decision with legal or similarly significant effects.
10. International processing and transfers
HR DEVELOPMENT is in the United States. Cloudflare, OpenAI, Apple, and Google operate in the United States and other countries. Information sent to the backend, identity providers, App Store, support mailbox, or OpenAI may therefore be processed outside the country where you live. Privacy laws and government-access rules can differ between countries.
LipMax does not promise that Cloudflare D1 or OpenAI processing remains in your country. Cloudflare can automatically choose a D1 primary location and may process request traffic across its global network. LipMax's OpenAI requests use the standard OpenAI API rather than a guaranteed country-specific endpoint.
Where restricted personal data is transferred internationally, the provider agreements make available legally recognized safeguards as applicable, including the European Commission's Standard Contractual Clauses and the UK Addendum. Cloudflare's customer DPA applies to free and paid Cloudflare customers, and OpenAI's DPA is incorporated into its API business agreement. You may request information about an applicable transfer safeguard at hzakzak8@gmail.com. Provider notices and DPAs are available at:
- Cloudflare Privacy Policy
- Cloudflare Data Processing Addendum
- OpenAI Data Processing Addendum
- Apple Privacy Policy
- Google Privacy Policy
11. Security
LipMax uses measures designed to reduce privacy and security risk, including:
- on-device image analysis and data minimization;
- iOS Keychain for local account and session credentials;
- iOS file protection and backup exclusion for App-managed progress photos;
- HTTPS for network requests;
- one-time sign-in challenges, state, and nonce validation;
- verification of Apple and Google token signatures and claims;
- HMAC-SHA-256 for provider identities, server session tokens, rate keys, and relevant Apple transaction identifiers stored in D1;
- AES-256-GCM encryption, identity binding, server-only keys, and controlled key rotation for Apple refresh tokens;
- cryptographic verification of Apple transaction JWS values and current entitlement checks with Apple;
- strict request size, format, and schema limits;
- bounded rate limits and per-subscription concurrency controls; and
- restricted operational logging that avoids deliberately logging content and credentials.
No device, network transmission, database, encryption system, or service can be guaranteed completely secure. Protect your device passcode, Apple or Google account, and LipMax session, and contact hzakzak8@gmail.com if you believe your account or data is at risk.
12. No advertising, tracking, sale, or product analytics
LipMax does not include advertising SDKs, ad pixels, cross-app tracking, data brokers, behavioral advertising, or a product-analytics SDK. We do not use App Tracking Transparency because LipMax does not track users as Apple defines tracking. We do not sell personal data or share it for cross-context behavioral advertising.
Cloudflare operational logs and keyed rate limits are used for delivery, security, abuse prevention, and troubleshooting, not to build marketing profiles or measure advertising.
13. Automated scores and AI output
The App automatically calculates appearance-related scores from on-device geometry. For eligible adults who request it, OpenAI selects plan task identifiers or classifies a coach question into a limited category. LipMax then supplies the task wording or curated answer.
These outputs are for entertainment and self-improvement. They do not identify you, diagnose a condition, make a medical decision, determine access to employment, education, housing, credit, insurance, public benefits, or another essential service, or otherwise create legal or similarly significant effects. You may choose not to scan and may decline the OpenAI feature.
14. Changes to this Policy
We may update this Policy when the App, providers, law, or our practices change. We will publish the updated Policy with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice or request consent where required before the new use begins.
We will update this Policy before adding advertising, tracking, product analytics, a new AI provider, server-side photo storage, or another materially different data use.
15. Contact
HR DEVELOPMENT LLC 5830 E 2nd St, Ste 7000 #31401 Casper, WY 82609 United States
Privacy and support: hzakzak8@gmail.com
When contacting us, please write LipMax privacy request in the subject line and do not send a password, full payment-card number, Apple authorization code, Google authorization code, ID token, transaction JWS, or other account secret.