Trust Center

Your trust is the foundation of everything we build.

How KDERMAI protects your privacy, secures your data, and uses AI responsibly — across every product and integration.

Last updated: July 27, 2026

Privacy

Privacy Policy

KDERMAI is a personalized skin-intelligence platform. This policy explains what personal data we collect, why we collect it, how it is used, and the choices you have. It applies to members, specialists, and visitors.

Data we collect

  • •Account & profile: name, email, date of birth, skin type, concerns, lifestyle, and intake questionnaire answers.
  • •Skin images: front, left, and right profile photos (and optional supplemental close-ups) used for AI analysis.
  • •Analysis results: AI-derived skin scores, biomarkers, and specialist-curated plans.
  • •Usage & device: pages viewed, feature interactions, browser family, and device category — used for product improvement and security.
  • •Payment data: handled directly by our payment processor (Stripe); we do not store full card numbers.

How we use your data

  • •To provide your skin analysis, personalized routine, and specialist plan.
  • •To operate your account, send service notifications, and provide support.
  • •To improve our models and product — only with your consent where required.
  • •To comply with legal obligations and protect against fraud.

Sharing & subprocessors

We share data only with vetted processors that support core features: cloud storage (Cloudflare R2 / AWS S3), payments (Stripe), AI analysis (DermaGenome, OpenAI), email (Resend), SMS (Twilio), and bot protection (Cloudflare Turnstile). Each processor is bound by data-processing terms and limited to the minimum data necessary. We never sell your personal data.

Your rights

You may access, correct, export, or delete your data, and withdraw consent at any time. See the Data Deletion and GDPR / CCPA sections for how to exercise these rights.

Skin images may constitute special-category biometric data under applicable law. We process them only with your explicit consent and for the sole purpose of skin analysis. You can withdraw consent and request deletion at any time.
Security

Security Practices

Security is engineered into every layer of KDERMAI — from the application code to our cloud infrastructure and vendor relationships. Our controls are aligned with industry best practices and continuously reviewed.

Access control

  • •Role-based access with least-privilege defaults; admin actions require elevated roles.
  • •Multi-factor authentication enforced for all administrative and specialist accounts.
  • •Access granted on a need-to-know basis and reviewed on a regular cadence.

Application security

  • •Secure software development lifecycle with code review and automated checks.
  • •Input validation, output encoding, and parameterized data access to prevent common vulnerabilities.
  • •Bot and abuse protection via Cloudflare Turnstile and rate limiting.
  • •Centralized error and anomaly logging with alerting for suspicious activity.

Infrastructure & monitoring

  • •Cloud hosting on hardened, managed infrastructure with network segmentation.
  • •Continuous monitoring, uptime checks, and incident-response runbooks.
  • •Audit logging of sensitive administrative and member-data actions.

Vendor security

Subprocessors are assessed before onboarding and re-reviewed periodically. Data-sharing is governed by data-processing agreements and limited to the data necessary for each service.

Incident response & reporting

We maintain a documented incident-response process. If a security issue affects your data, we will notify affected users and regulators as required by law. To report a vulnerability, contact our team via the Contact page.

KDERMAI follows a coordinated-disclosure policy. We do not currently operate a public bug-bounty program; responsible reports are welcomed and acknowledged.
Responsible AI

Responsible AI

KDERMAI uses artificial intelligence to analyze skin images and generate personalized insights. We are committed to transparency, human oversight, fairness, and member control over how AI is used.

What our AI does — and does not do

  • •AI produces educational skin insights, not medical diagnoses.
  • •AI results are reviewed and curated by licensed specialists before being published to members.
  • •We do not use AI to make automated decisions that produce legal or similarly significant effects without human review.

Human oversight

Every member analysis is paired with specialist review. Specialists can adjust, override, or reject AI output. You may always request a human review of any AI-generated recommendation.

Fairness & bias

  • •We evaluate model performance across diverse skin tones and demographics.
  • •Training and validation data are reviewed to reduce representational gaps.
  • •We continuously monitor outputs for performance drift and bias signals.

Transparency

When you receive an AI-derived score or recommendation, it is labeled as such. You can request a plain-language explanation of the key factors behind a given result.

Data use for model improvement

We use de-identified or consented data to improve our models. We do not sell your data or use identifiable images to train third-party models without your explicit consent.

AI is a tool to support — never replace — the judgment of qualified professionals. Always consult a licensed clinician for medical concerns.
Data Lifecycle

Data Retention

We retain personal data only as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. The schedule below summarizes our standard retention periods.

Data categoryRetention periodBasis
Account & profile dataWhile your account is activeService provision
Skin imagesPer your preference; default until deletion requestAnalysis & your consent
AI analysis resultsLifetime of accountService & history
Specialist-curated plansLifetime of accountService provision
QA & telemetry events30 daysSecurity & quality
Application & audit logsUp to 90 daysSecurity & compliance
Payment records (via Stripe)Per processor policyFinancial compliance
BackupsUp to 30 days (rolling)Disaster recovery

When an account is closed, we delete or de-identify personal data within 30 days, except where retention is required by law (e.g., financial records, legal holds).

Need your data sooner? You can request earlier deletion at any time — see Data Deletion.
Your Rights

Data Deletion

You have the right to delete your account and associated personal data at any time. We make the process straightforward and honor requests promptly.

How to request deletion

  • •Use the in-app account settings to close your account, or
  • •Contact our Trust & Privacy team via the Contact page with the subject “Data Deletion Request.”

What happens next

  • •We verify your identity to protect against unauthorized deletion.
  • •Personal data is deleted or de-identified within 30 days.
  • •Skin images are removed from primary and backup storage.
  • •You receive a confirmation once deletion is complete.

What may be retained

Limited data may be retained where required by law or legitimate business needs — for example, financial transaction records, records of your deletion request, or data subject to a legal hold. Such data is minimized, access-restricted, and deleted once the legal basis expires.

Deleting your account is permanent and cannot be undone. Export any data you wish to keep before requesting deletion.
Healthcare

HIPAA Readiness

KDERMAI is a skin-intelligence platform, not a healthcare provider. By default we are not a HIPAA “covered entity” or “business associate.” However, we design our platform to support healthcare partners — such as clinics and licensed professionals — who may be subject to HIPAA.

How we support HIPAA-aligned partners

  • •Encryption in transit and at rest for protected data (see Encryption Overview).
  • •Role-based access, least-privilege defaults, and administrative audit logging.
  • •Documented subprocessors and data-processing agreements.
  • •Business Associate Agreements (BAAs) available for qualified enterprise partners on request.

Important limitations

  • •Members should not submit data as Protected Health Information (PHI) unless working with a covered partner.
  • •Our standard consumer offering is not configured as a HIPAA-regulated service.
  • •AI skin insights are educational and are not medical advice or a clinical diagnosis.
If you are a healthcare provider or clinic and intend to use KDERMAI with patient data, contact us to discuss HIPAA-aligned configuration and a BAA before processing any PHI.
European Union

GDPR Rights

If you are in the European Economic Area, the UK, or Switzerland, the General Data Protection Regulation (GDPR) gives you rights over your personal data. We process your data under the following lawful bases.

Lawful bases for processing

  • •Consent — for skin image analysis and optional marketing.
  • •Contract — to deliver your account and services.
  • •Legal obligation — to comply with applicable laws.
  • •Legitimate interests — for security, fraud prevention, and product improvement, balanced against your rights.

Special-category data

Skin images may reveal special-category biometric or health information. We process them only with your explicit consent and solely for skin analysis. You may withdraw consent at any time.

Your rights

  • •Access, rectification, and portability of your data.
  • •Erasure (“right to be forgotten”) and restriction of processing.
  • •Objection to processing and withdrawal of consent.
  • •Right to lodge a complaint with your supervisory authority.

International transfers

Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses and ensure a comparable level of protection.

To exercise any GDPR right, contact our Trust & Privacy team via the Contact page. We respond within one month, extendable by two months for complex requests.
California

CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you rights over your personal information.

Categories we collect

  • •Identifiers (name, email, device identifiers).
  • •Personal characteristics (skin type, concerns, date of birth).
  • •Sensitive personal information, including skin images.
  • •Usage and interaction data.

Your rights

  • •Know — request disclosure of the categories and specific pieces of information we hold.
  • •Delete — request deletion of your personal information.
  • •Correct — request correction of inaccurate information.
  • •Opt-out of sale — we do not sell personal information.
  • •Limit use of sensitive PI — restrict use beyond providing the service.

How to exercise your rights

Submit requests through the Contact page. We verify your identity, respond within 45 days, and provide information free of charge up to twice per year. Authorized agents may submit on your behalf with signed permission.

We do not sell your personal information and do not process it for cross-context behavioral advertising.
Tracking

Cookie Policy

KDERMAI uses cookies and similar technologies to operate the service, remember your preferences, measure performance, and protect against abuse. Our consent banner lets you choose which categories to enable.

Cookie categories

  • •Essential — required for core functionality, authentication, and security. Always on.
  • •Preference — remember your language and display choices.
  • •Analytics — help us understand usage and improve the product.
  • •Marketing — only with consent; used to measure campaign effectiveness.

First-party vs third-party

Most cookies are first-party, set by KDERMAI. Third-party cookies, where used, are set by trusted partners (for example, analytics or fraud-prevention providers) and limited to the data necessary for their function.

Managing cookies

You can review or change your consent at any time via the consent banner. You can also disable or delete cookies in your browser settings; some features may not function if essential cookies are blocked.

We do not use cookies to build cross-site behavioral-advertising profiles about you.
Cryptography

Encryption Overview

We protect your data with strong, industry-standard encryption — in transit and at rest — across our application, databases, and file storage.

LayerMethodScope
Data in transitTLS 1.2 / 1.3All network traffic
Data at rest (storage)AES-256Skin images & files (R2 / S3)
Data at rest (database)Provider-managed encryptionAll stored records
BackupsEncryptedRolling backups
PasswordsOne-way salted hashingCredentials
Secrets & keysSecrets vault (never in code)API keys & tokens

Key & secrets management

  • •Secrets are stored in a managed vault and never hardcoded in source.
  • •Access to keys is restricted and audited.
  • •Rotation policies apply to operational credentials.

Image storage

Skin images are uploaded to encrypted object storage with access controls that restrict retrieval to authorized requests on your behalf. Stored files are anatomically correct and never modified without consent.

Encryption is one layer of a defense-in-depth strategy — complemented by access control, monitoring, and secure development practices described in the Security section.
Questions

Frequently Asked Questions

Before you continue — important notice

KDERMAI provides AI-assisted skincare guidance reviewed by licensed specialists. By using this platform you agree to our terms and acknowledge the following:

✓Not a substitute for medical advice or diagnosis
✓Photos processed by AI for skincare analysis only
✓Specialist recommendations are professional opinions, not prescriptions
✓Data retained per our Privacy Policy — delete anytime in Settings