We collect information that you provide directly to us, information generated through your use of the Services, and information obtained from third-party sources. The categories of information we collect are described below.
2.1 Account Information
When you create an account, we collect:
- Full name
- Email address
- Date of birth
- Account credentials (password hash β we never store plaintext passwords)
- Profile photograph (optional)
- Preferred language and communication preferences
2.2 Health and Treatment Data
To provide our core Services, we collect and process the following health-related and treatment data, which may constitute sensitive personal data or protected health information under applicable law:
- Skin type and skin assessment results
- Complete treatment history, including type of procedure, date, provider, and clinical notes
- Injection zones and treatment mapping (specific facial or body areas treated)
- Products used in each treatment (product name, manufacturer, batch/lot number, units or volume administered)
- Product reactions, adverse events, or allergies reported by you or your provider
- Treatment outcome assessments and follow-up records
- Provider-entered clinical observations
We treat all health and treatment data with the highest level of protection and do not sell, rent, or share this data with third parties for advertising, marketing, or any purpose unrelated to providing the Services.
2.3 Photographs
Our Services allow you and your providers to capture and store before-and-after treatment photographs. With respect to these photographs:
- Photos are uploaded only with your explicit consent or at the direction of your treating provider with your authorization
- All EXIF metadata, including GPS coordinates, is automatically stripped from photographs before they are uploaded to our servers
- Photographs are stored in encrypted form and are accessible only to you and providers you have explicitly authorized
- Photographs are not used for machine learning, model training, facial recognition, or any purpose other than displaying your treatment record
2.4 Biometric Authentication Data
The App supports Face ID and Touch ID for app-lock functionality. This biometric data is processed entirely on your device using Apple's Secure Enclave technology. Aesthetic Pass never receives, transmits, stores, or has access to your biometric data (fingerprints, facial geometry, or other biometric identifiers). We receive only a success or failure confirmation from the operating system's authentication framework.
2.5 Device and Technical Information
When you use the App or visit our Website, we automatically collect certain technical information:
- Device type, model, and operating system version
- Unique device identifiers (e.g., IDFV for iOS)
- Apple Push Notification Service (APNs) device tokens, used exclusively for delivering notifications you have opted into
- App version and build number
- IP address (automatically truncated/anonymized for analytics)
- Browser type and version (for Website visitors)
- General crash logs and performance diagnostics
2.6 Location Information
We may request access to your device's location services solely for the purpose of displaying nearby verified aesthetic providers. Location data is used in real-time to return search results and is not persistently tracked, stored on our servers, or associated with your account profile. You may deny or revoke location access at any time through your device settings, though this may limit the functionality of the provider-finder feature.
2.7 Usage Data
We collect anonymized and aggregated information about how you interact with our Services, including:
- Pages and screens viewed
- Features accessed and actions taken
- Session duration and frequency of use
- Navigation paths within the App
This data is used solely to improve the user experience and is not linked to your health or treatment records.
2.8 Payment Information
We do not directly collect or store your full credit card numbers, bank account details, or other financial account information. Payment processing is handled by the following third parties:
- Apple App Store (StoreKit 2) — processes all in-app subscriptions purchased on iOS, including Bio Age Premium Monthly ($14.99/month) and Bio Age Premium Annual ($99/year). Apple sends us subscription status events (purchase, renewal, expiry, refund) via the App Store Server Notifications V2 webhook. We do not receive your payment instrument; we receive only an opaque original transaction ID and the resulting subscription state. Apple's privacy policy is available at apple.com/legal/privacy.
- Stripe — processes payments for the web Bio Age Premium subscription ($19.99/month) and for clinic subscriptions. Stripe receives the payment-related information necessary to process transactions and is PCI-DSS Level 1 certified. Stripe's privacy policy is available at stripe.com/privacy.
We store the following purchase-related metadata in our database to operate the subscription: subscription status (free / active / past_due / canceled / expired / refunded / revoked), expiration timestamp, payment processor (apple or stripe), and an opaque transaction identifier. We do not store credit card numbers, CVV codes, bank account numbers, or any other primary payment instrument data.
2.9 Bio Age Estimation Data
The Aesthetic Pass app includes an optional Bio Age feature that estimates biological skin age from a facial photograph using an on-device AI model (MiVOLO, converted to ONNX/CoreML). The model runs entirely on your device; we do not upload raw photographs or facial geometry to our servers for inference.
The numerical result of each Bio Age scan (the estimated age in years), the timestamp of the scan, and the model version used are stored in our Supabase database alongside your treatment history. This data is treated as health-related personal data under the GDPR (Art. 9) and is protected with the same encryption and access controls as your treatment records.
Medical disclaimer: Bio Age is a cosmetic estimator for aesthetic guidance only. It is not a medical or diagnostic assessment. Do not rely on Bio Age results for medical decision-making.
2.10 Subscription Auto-Renewal & Right of Withdrawal
Subscriptions to Bio Age Premium (iOS App Store and web Stripe) auto-renew at the end of each billing period unless cancelled at least 24 hours before the period ends. You can manage or cancel your iOS subscription at any time in iOS Settings → Apple ID → Subscriptions, or directly within the Aesthetic Pass app under Settings → Manage Subscription.
EU Right of Withdrawal (Widerrufsrecht). If you are a consumer in the European Union and purchase a Bio Age Premium subscription, you have the right to withdraw from the contract within fourteen (14) days of purchase without giving any reason, in accordance with § 312g of the German Civil Code (BGB) and Article 16(m) of Directive 2011/83/EU. To exercise this right for an iOS App Store purchase, request a refund through Apple at reportaproblem.apple.com. For Stripe (web) subscriptions, contact us at info@drylabs.de with an unequivocal statement of withdrawal.
Loss of withdrawal right: By performing a Bio Age scan beyond the free 3-scans-per-month tier within the 14-day withdrawal window, you expressly request immediate performance of the digital service and acknowledge that you thereby lose your right of withdrawal in accordance with § 356(5) BGB and Article 16(m) Directive 2011/83/EU.
Detailed subscription terms, pricing, refund policy, and cancellation procedures are set out in § 9 of our Terms of Use.