Privacy Policy
This Privacy Policy explains what ShapeMirror collects, why, who we share it with, and what choices you have. Please read it carefully — by tapping Accept, you agree to it.
If anything below is unclear, contact us at support@shapemirror.com.
Who we are
ShapeMirror is a motivational visualization app. Throughout this policy "we", "us" and "our" refer to the company that operates ShapeMirror. "You" and "your" refer to the person using the app.
ShapeMirror is not a medical, clinical, or fitness-coaching service. See our Terms of Service for the full disclaimer.
Who can use ShapeMirror
You must be at least 18 years old. We do not knowingly collect data from anyone under 18. If we discover an account belongs to a minor, we delete the account and the data.
What we collect
We collect only what we need to operate the app safely and to deliver the motivational features.
Account information
- Email address (used for sign-in and account recovery)
- Display name (if you provide one)
- Google "sub" identifier (if you sign in with Google)
- Apple "sub" identifier (if you sign in with Apple)
- Account creation date, last login date
Fitness profile
The onboarding flow asks for the following, one screen at a time:
- Age
- Gender (optional)
- Height
- Weight
- Goal type and optional target weeks
- Food allergies (selected from a controlled list)
- Daily work location (office / home / mixed / active job)
- Daily sitting hours band
- Activity level
- Health limitations (selected from a controlled list, e.g. knee pain, heart/breathing)
- Food preferences (e.g. halal, vegetarian)
We use this data to:
- compute a body-mass index (BMI) for the visualization;
- assign a safety-risk tier ("Standard", "Caution", "HighRisk") used only to soften the in-app motivational copy and warning banners;
- bias the AI visualization prompt.
You may edit or delete this data at any time from the in-app settings.
Uploaded photos and AI-generated images
When you use the visualization feature we collect the photo you upload in order to generate your visualization. As soon as your images are generated, we delete the original photo you uploaded from our servers. What we keep afterwards is:
- a privacy-protected copy of your photo — the same body, pose, and clothing, but with your face obscured by the identity-protection mode you chose (a soft blur, sunglasses, or a phone held over the face) — used as your "before" image;
- the AI-generated outputs, so they remain available in the gallery;
- copies of rejected uploads and of strikes, for safety review (see below).
The original upload is held only transiently while the images are being generated; if a generation does not finish, it is kept briefly so you can retry, and it is deleted once the retry succeeds or you delete your account. Our app serves the privacy-protected copy you chose, never the raw original you uploaded.
We send these images to OpenAI for moderation (omni-moderation-latest), suitability checks (gpt-4o-mini vision), and image generation (gpt-image-1 / equivalent). We may also send the photo and prompt to Google (Gemini) as a fallback image generator when OpenAI is unavailable. OpenAI and Google each process the images per their own published data-usage policies.
Face data
Some people choose to include their face in the photo they upload (for example, a full-length selfie). Because of that, this section explains exactly how any face contained in your photo is handled.
- We do not use facial recognition or biometric identification. ShapeMirror does not use Apple's TrueDepth camera, ARKit face tracking, Face ID, faceprints, face templates, or any face-matching, face-detection-for-identity, or identity-verification technology. We never create a biometric identifier or faceprint of you.
- "Face data" is only whatever face happens to appear in a photo you voluntarily upload. The visualization feature is designed to work from a neck-to-hip body photo and does not require your face. Including your face is optional.
- We help you hide it. Before an image is generated you choose an identity-protection mode: a soft photographic blur (the default) or sunglasses over the eyes — which obscure the face — or a natural mirror-selfie look. The blur and sunglasses modes make the result hard to identify; the natural mode gives the most realistic appearance but reduces identifiability less, and the app tells you this before you choose it so your choice is informed.
- Use. Any face in your photo is used solely to generate your own personal, motivational visualization and, where you enabled it, to apply the privacy protection above. It is never used to identify, authenticate, verify, profile, track, or advertise to you, and it is never used for any purpose other than producing the image you requested.
- Sharing / processing. To generate the image, the photo (which may contain your face) is sent to our AI image processors — OpenAI and, as a fallback, Google (Gemini) — solely to produce the result, and each processes it per its own published policies. We do not otherwise disclose it, we never sell it, and we never use it to train any model we own.
- We delete your original photo. The photo you upload — the one that may contain your face — is used only to generate your visualization and is then deleted from our servers as soon as generation completes. We keep only a privacy-protected copy (with the protection mode you chose applied) and the AI-generated image; the app serves that copy, never the raw original you uploaded. (The original is held only transiently during generation, and kept briefly if a generation fails so you can retry.)
- Storage. The privacy-protected copy and generated images are stored on our own servers (hosted in Europe with Hetzner) and protected in transit by TLS.
- Retention & deletion. They are retained only while your account exists, plus a short backup grace period (typically 30 days) after you delete them or your account. You can delete your account — and with it the protected copy and generated images — at any time from in-app Settings.
Meal and food photos
When you use the nutrition features you may photograph a meal, a product, or the inside of your fridge. We store the original image on our servers (Hetzner, Europe) and send it to OpenAI (vision models such as gpt-4o / gpt-4o-mini) to identify the food and estimate its nutrition. These photos are used ONLY to produce your food analysis; they are never used to identify you or to train any model we own. They are retained while your account exists (unconfirmed draft photos are swept within about 24 hours) and deleted on account deletion, subject to a short backup grace period.
Voice recordings
When you use voice logging to say what you ate, we record a short audio clip, store it on our servers, and send it to OpenAI (whisper-1) to convert it to text. We keep the clip and its transcript to power the food log and to prevent abuse of the voice quota; you can delete them with your account. We never use your voice for identification, advertising, or model training.
Safety-strike audit data
To protect the app and our AI provider accounts from abuse we keep an audit row every time the photo-safety gate rejects an upload OR every time downstream moderation blocks a generation. Each row stores:
- which rule was triggered;
- which moderation layer produced the verdict;
- the friendly message we showed you;
- a SHA-256 hash of the rejected image (to spot repeated uploads of the same photo);
- the storage key of the rejected image (so an admin can review);
- the provider request id (admin diagnostics only);
- timestamp.
If you accumulate too many strikes (see Terms) we may automatically restrict your account (cooldown, 24-hour block, 7-day block with admin review, or permanent block for severe categories). These records are retained for compliance and abuse-prevention purposes for as long as your account is open and for a reasonable period after closure.
Device and connection data
We log technical metadata necessary to operate the app safely:
- IP address (used for rate-limiting, fraud-prevention, and the legal-consent audit record)
- User-Agent header
- Client app identifier and version (
mobile-android,mobile-ios,web, plus the app version) - Error and crash diagnostics (the originating UI event, the API call that failed, and the resulting status code — we deliberately do NOT try to capture the internals of React rendering errors)
Legal consent records
Every time you tap Accept on the Terms or Privacy gate we record an evidence row including:
- which document and version you accepted;
- the date and time of acceptance;
- the IP address and User-Agent header on the request;
- a snapshot of your account email address at the time;
- the client app and version.
These records are stored for compliance evidence and may be retained indefinitely.
What we do NOT collect
- We do not collect your contacts, phone book, calendar, or location.
- We use the microphone only when you tap the voice button to speak your meal or ingredients — see "Voice recordings" above. We do not otherwise access it.
- We do not use facial recognition, faceprints, or any biometric identifier. We do not use Apple TrueDepth / ARKit face data, and Face ID is disabled in the app.
- We do not knowingly collect any special-category personal data beyond what you voluntarily provide on the onboarding screens (e.g. self-reported health limitations) or within a photo you choose to upload.
- We do not request, store, or process payment information at this time. If we add paid features in the future this policy will be updated.
How we use your data
We use your data to:
- Operate the app — create your account, sign you in, store your profile, generate visualizations.
- Keep the app safe — moderate uploaded photos, prevent abuse, enforce the safety-strike system, run our anti-fraud checks.
- Personalise motivational copy and warnings — soften the tone for Caution / HighRisk tiers; lean toward low-impact suggestions for users with relevant limitations.
- Comply with legal obligations — keep audit records of consent and abuse, respond to lawful requests.
- Improve the app — aggregate, non-identifying statistics about feature use and errors.
We do not sell your personal data to third parties. We do not use your uploaded photos or any face contained in them to train any model that we own.
Who we share data with
We share data only with the parties strictly required to run the app:
- OpenAI — for image moderation, suitability checks, and image generation. OpenAI processes the photo and prompt content per its own published policies. We send only what is needed for the request (no full account profile).
- Google (Gemini) — used only as a fallback AI image generator when OpenAI is unavailable. When used, we send the photo (which may contain your face) and the prompt to Google's Gemini API, which processes it per Google's published policies. This is separate from "Sign in with Google", below, which only shares an account identifier and email.
- Hosting provider (Hetzner) — operates the servers that host the app and the database. Data at rest is stored in their infrastructure.
- Google / Apple (sign-in) — when you sign in with their account, we receive an identifier and an email; we do not share your fitness profile or photos with them.
- Pexels — when we need a stock photo for a recipe, we send the recipe or food name to Pexels to search their image library. No account data or your own photos are sent.
- Open Food Facts — when you scan a product barcode, we send the barcode number to the Open Food Facts database to look up product and nutrition information.
Sharing with other users
If you connect with a friend in the app, they can see a feed of your logged activity (meals, workouts, water, movement, and progress summaries); your uploaded photos are stripped from this feed. When you save a meal, a de-identified copy of the recipe (title, ingredients, macros — with a stock photo, never your own photo) may be added to a catalog other users can browse. You control connections in Settings.
We may disclose data to law-enforcement or other authorities if we have a good-faith belief that we are legally required to do so, or to protect the rights, safety, or property of ShapeMirror, our users, or the public.
We may transfer data to a successor entity if we are acquired or restructured. We will notify you (in-app or by email) before this happens so you can choose to delete your account first.
How long we keep your data
- The original photo you upload for a visualization: deleted from our servers as soon as your visualization is generated (held only transiently during generation, and kept briefly if a generation must be retried).
- Account, profile, the privacy-protected copy of your photo, and AI-generated images: for as long as your account exists, plus a short grace period after deletion (typically 30 days) for backups to roll off.
- Safety-strike rows and rejected images: retained for the lifetime of the account and for a reasonable period after closure for abuse-prevention and dispute-resolution purposes.
- Food-scan (fridge) images and detection metadata: may be retained in de-identified form (detached from your account) for a limited period after account deletion for abuse-prevention and analytics; they are not linked back to you.
- Legal consent records: retained indefinitely as compliance evidence.
- Logs and diagnostics: rotated on a short cycle (typically 30–90 days).
Your rights
Depending on where you live, you may have rights under data-protection laws (GDPR, UK GDPR, CCPA, and similar). These typically include the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your data (subject to legal exceptions — e.g. abuse audit rows may be retained);
- Object to or restrict certain processing;
- Withdraw consent at any time (this does not affect processing already performed);
- Lodge a complaint with your local data-protection authority.
You can delete your account at any time from in-app settings. For any of the other rights, email support@shapemirror.com.
Security
We take reasonable technical and organisational measures to protect your data, including TLS 1.2+ encryption for all network traffic in transit, encryption at rest for stored photos, audio clips, and database contents on our hosting provider's infrastructure, hashed credentials, isolation between the web and mobile databases, server-trusted capture of IP / User-Agent / email on consent and strike rows, and strict role-based access on the admin panel.
No system is perfectly secure. We can't guarantee that a determined attacker will never get access. Please use a strong, unique password and enable two-factor authentication on your email provider.
International data transfers
ShapeMirror is operated from Europe and our servers are hosted with Hetzner in Europe. When we use OpenAI or Google (Gemini) for moderation and image generation, your data (including a photo that may contain your face) may be transferred to those providers' infrastructure, which may include data centres outside Europe. We rely on the protections those providers publish for such transfers.
Changes to this Privacy Policy
We may update this Policy from time to time. When we do, we bump the version number, and the in-app consent gate will ask you to accept the new version before you can continue using gated features.
Contact
Questions about your data? Email support@shapemirror.com.
By tapping Accept on the in-app consent gate, you confirm that you have read and understood this Privacy Policy. We record the date and time of your acceptance, the IP address and device that the request came from, the email address on your account, and the client app and version you used to accept. This record is kept as proof of consent.