Privacy · updated September 22, 2026
verifiable

Measured on your device.

Every measurement in a Canthion report is taken in your browser. Your photo leaves your device for one purpose only: on a paid Complete report, a crop of it is sent to draw your AI mock-ups. This page sets out exactly what goes where, how long it is kept, and how to have it deleted.

Your device
  • Your photostays here to be measured
  • The face model, running inside your browser
  • All 478 landmarks and every measurement
  • Skin, colour and symmetry analysis, and the written report
  • Your last photo, kept for 30 days so you can reopen the scan
Turn off Wi-Fi once the page has loaded and the free scan still works.
Our server Supabase, United States
  • No photo is stored here.
  • Cookieless usage events: pages and steps reached
  • Your email, if you give it, and your unlock
  • A one-way fingerprint of your measurements that ties a purchase to one face
  • If you sign in: the numbers of reports you save
Payments are handled by Stripe. We never see your card.
AI mock-ups Complete reports only
  • A crop of your front photo and a written instruction, one per look
  • OpenAI draws the picture. It does not train on it and deletes its logs within 30 days
  • The finished pictures are kept in a private cache so they are never drawn twice
  • No measurements, name or email go with it
On the free scan, nothing is uploaded at all.
What stays on your device, what reaches our server, and the one step that uses a photo.

On your device

The landmark model is downloaded to your browser and runs there. Detection, every proportion, the skin and colour readings, the symmetry and the written report are computed on your own processor. None of it is sent to us.

To let you come back to a scan, your browser keeps a few things locally: your last photo (in IndexedDB, for 30 days), your chosen reference group, your answers to the start questions, and your unlock. Clearing your browser's site data removes all of it.

AI mock-ups

A Complete report shows the plan's grooming drawn on your own photo: the cut, colour, facial hair, brows, makeup, glasses. Drawing hair that is not in your photo cannot be done on a phone, so this one step happens on a server.

The mock-ups are illustrations, not measurements or predictions. See the terms.

On our server

WhatWhyKept for
Usage events. A random visitor id and visit id generated in your browser, the pages and steps reached, scroll depth, buttons pressed, a coarse traffic source and timings. No cookies and no third-party analytics.To see where people give up, and fix it.400 days, then deleted automatically.
Your email address, if you give it: for your report link, a purchase, a gift, or sign-in.To send your report and restore it on another device. After a free scan we may send up to three short follow-up emails, each with a one-click unsubscribe.Until you ask us to delete it or unsubscribe.
Purchases. Your email, the tier, the amount and the Stripe reference. Card details stay with Stripe.To unlock the report and keep records the law requires.As long as tax law requires.
A face fingerprint. A one-way code computed from your measurements. It is not an image, and a face cannot be rebuilt from it.So one purchase unlocks one person's report.As long as the purchase record.
Saved reports, only if you sign in: the numbers, the reference group and the fingerprint. Never the photo.To reopen your report on another device.Five years on a paid account, two years on a free one, with a reminder first. Or until you delete it.
Referrals. Your code, the email it belongs to, and which friends used it.To open the sections referrals earn.Until you ask us to delete it.
AI mock-ups. The finished pictures, as above, and a log of each drawing (time, cost, whether it worked).So a report never pays for the same picture twice.Until you ask us to delete them.

Messages sent through the contact form are delivered to our inbox by email and are not stored on the server.

Who else handles your data

We use a small number of service providers, each only for the job listed. None of them may use your data for their own purposes.

We do not sell your data, share it for advertising, or use it to build profiles. There are no advertising or social-media trackers on this site.

Biometric data

Facial geometry is treated as biometric data in several places, including Illinois (BIPA), Texas (CUBI), Washington and the EU and UK (GDPR). Canthion computes your facial geometry on your device and does not send it to us. The mock-up step sends a photo to be drawn on; neither we nor OpenAI extract facial geometry from it, use it to identify you, or train on it. The fingerprint we store is a one-way code for matching a purchase, not a template that could identify a face.

Your rights

You can ask for a copy of what we hold about you, have it corrected, or have it deleted, including your email, saved reports, referral record and cached mock-ups. You do not need an account. Write through the contact form or to canthionanalysis@gmail.com from the address concerned, and we will act on it within 30 days. Records we must keep for tax are kept only for that purpose. Residents of California, the EU and the UK have these rights by law. We extend them to everyone.

Canthion is for adults. We do not knowingly collect data from anyone under 18, and we delete it if we learn we have.

If this policy changes, the date at the top changes with it, and anything material is set out here before it takes effect.

Verify it yourself

  1. Open the scan on a computer and press F12 (⌥⌘I on a Mac). Choose the Network tab.
  2. Run a free scan. You will see the site's own files, the face model downloaded to you, and a few small text requests to our server. None carries an image.
  3. Or disconnect from the internet once the page has loaded. The scan still runs.

The face-detection library, Google's MediaPipe, includes a usage logger that tries to report timings to Google. We block it in our code and in the site's security policy, so it never sends.