Last updated:
This Privacy Policy explains how the Coiffa app and support service handle information. Coiffa is provided by YAYA STUDIO AI AB ("YAYA", "we", "us"), a Swedish private limited company based in Gothenburg, Sweden (organisation number 559544-4315). Contact info@coiffa.ai with privacy questions or requests.
Account and professional profile
Coiffa supports Sign in with Apple, Google Sign-In, and email one-time-code sign-in. Depending on the sign-in method and information returned, Coiffa stores an account identifier, email address and email-verification state, display name and profile-photo URL when supplied, linked sign-in providers, account-creation and last-login timestamps, and optional onboarding answers such as professional role, years of experience, specialties, and onboarding-completion time.
For Apple sign-in, Coiffa stores Apple's app-scoped user identifier on the device so the app can request credential revocation during account deletion. The app attempts to remove that on-device identifier after successful Apple-linked account deletion.
These records support authentication, account and professional-profile state, prevention of silent recreation of a deleted account, and association of saved analyses and billing state with the correct account.
Client images, analyses, and AI processing
When a stylist requests an analysis, Coiffa processes submitted client photos and any reference or inspiration image, photo-angle and file-type metadata, the stylist's request and follow-up messages, and generated AI guidance. The account-linked analysis record stores image references, the request, conversation messages and results, processing state, timestamps, and analysis metadata so the analysis can run, recover safely, enforce usage, and appear in Analysis History.
Photos you choose to submit may include embedded metadata, which can be uploaded and processed with the photos.
Coiffa uses Google Cloud storage and AI services to process the client photos and reference images you choose to submit, your request, and relevant prior conversation messages to generate the guidance you request. Google provides these services to Coiffa. Do not rely on AI output without professional review: it can be incomplete, inaccurate, or unsuitable.
Your AI-processing permission
Before uploading photos or sending your request for a new analysis, Coiffa asks you to choose Allow AI processing if you have not already given current permission. This allows Coiffa to use Google Cloud services to store and process the photos you select and your request to generate your hairstyling guide. Your photos and request are not used to train AI models. Only upload photos you have permission to use.
You can choose Not now or dismiss the disclosure. Your selected photos and request stay on Home, and that analysis does not upload photos, send your request for AI processing, or use a credit. Opening the Privacy Policy does not give permission. Coiffa starts the analysis only after your permission is confirmed.
Your permission is remembered for your signed-in account. Coiffa stores the current consent version and the dates and times when permission was granted and, if applicable, withdrawn. We ask again before a new analysis if you withdraw permission or if the provider or processing service, the categories of data shared, or the processing purpose materially changes.
You can review your permission status and open this policy in Account → Privacy. When permission is active, select Withdraw AI consent and confirm Withdraw to withdraw it. You will need to allow AI processing again before starting another new analysis. Withdrawal does not interrupt an analysis already underway or delete your photos, requests, saved guides, account data, or consent record. Existing saved guides remain readable. For deletion options, see Retention and deletion and Your choices and requests below.
Billing and purchase information
Purchases are made through Apple's App Store, with RevenueCat used to manage purchase and subscription status. Coiffa shares an account identifier with RevenueCat and processes the purchase state needed to grant and reconcile access and credits.
Coiffa stores billing status and balances, product and entitlement identifiers, transaction identifiers or derived identifiers, purchase, refund, and reversal timestamps, and credit and support history. Coiffa does not collect full payment-card details.
Coiffa support can investigate a purchase, entitlement, restore, or refund issue and direct you to the appropriate Apple process. Apple determines eligibility for App Store refunds.
Service providers and recipients
- Apple: Apple sign-in and App Store purchase and subscription processing.
- Google: Google sign-in and account services, plus Google Cloud services for hosting, storage, and AI processing.
- Stytch: email one-time-code delivery and verification.
- RevenueCat: App Store purchase, subscription, entitlement, restore, and refund-event synchronization.
Under their applicable privacy commitments and data-protection terms, Apple, Google, Stytch, and RevenueCat provide the same or equal protection of user data as described in this policy and required by Apple's App Review Guidelines. These protections include safeguards against unauthorized access and procedures for handling privacy requests. Provider retention and deletion periods depend on the service and applicable obligations, as explained below.
You can read Apple's Privacy Policy, Google's Privacy Policy, Google Cloud's data-protection terms, the Twilio data-protection terms that apply to Stytch, and RevenueCat's data-protection terms.
Retention and deletion
Uploaded photos become eligible for automatic deletion when they reach 7 days old. This is not a guaranteed deletion time: deletion runs asynchronously. After deletion, photos leave normal access but may remain recoverable by authorized administrators for a further 7 days.
Account deletion requests removal of the account's uploaded photos. Uploads initiated before deletion may finish afterward and remain subject to the same automatic deletion process.
For Apple-linked accounts, the app requests Apple credential revocation before deletion. Coiffa then deletes the sign-in account, profile, saved analyses and conversations, and account-linked credit and billing records.
Your AI-processing permission record is kept with your account to remember whether you have allowed or withdrawn permission. Withdrawing permission keeps that record; deleting your account removes it from your live profile.
Some purchase-event records are retained after direct account identifiers and support details are removed or redacted. Those records are not anonymous: transaction, event, product and entitlement information, timestamps, processing state, and related credit records can remain. Derived identifiers used to prevent duplicate purchase claims can also remain linkable.
We must retain records needed for Swedish bookkeeping through the end of the seventh year after the calendar year in which the relevant financial year ends. Account deletion does not end this legal obligation. This requirement applies to accounting records and their supporting evidence, not automatically to every record associated with a purchase.
For other retained purchase events, the retention criteria are whether the records are still needed to reconcile purchases, resolve refunds or disputes, or establish, exercise, or defend legal claims. Derived purchase-integrity records are retained while needed to prevent a previously processed transaction from being claimed again. Coiffa retains a deletion-prevention record containing an account identifier and deletion time while needed to prevent the deleted account from being silently recreated by delayed requests or purchase events.
For operational logs, we determine retention by the time needed to diagnose service faults, detect abuse, and investigate security incidents, together with any applicable legal preservation requirement. Support correspondence is retained while needed to resolve the request and any related complaint, dispute, or legal obligation. These records are not all erased automatically when an account is deleted, and we do not promise a fixed automatic deletion deadline for them.
Copies in backups and provider recovery systems can remain after removal from live use. Their retention depends on the configured recovery window and the provider's deletion process. Account deletion therefore does not mean immediate erasure of every record.
Deleting your Coiffa account does not delete your Apple or Google account. It also does not automatically erase records held by Stytch or RevenueCat. Contact info@coiffa.ai for help with a request concerning those records.
Providers acting on our behalf retain data to supply the service and carry out deletion instructions, subject to their recovery processes and legal obligations. Apple and Google also determine retention for their own account and transaction services under their privacy policies. Their criteria include maintaining the account or service, preventing fraud, resolving disputes, and meeting legal or accounting obligations. Coiffa's photo-deletion window is not a deadline for erasing every provider-held copy.
Your choices and requests
You can initiate account deletion from the Account screen. Contact info@coiffa.ai to ask about the handling described here, make a privacy request, or get help with deletion. We may ask for information needed to identify the relevant account.
Support correspondence
When you contact support, Coiffa processes the information and attachments you choose to provide to answer, investigate, and document the request. This can include your account email, problem description, product name, approximate purchase date, a redacted transaction reference, app version, iPhone and iOS version, and the substance of a privacy or deletion request.
Do not send passwords, one-time codes, full payment-card details, unnecessary receipt information, or client photos.
Changes to this policy
We will revise this page when Coiffa's data handling or approved policy changes and update the date above.