Skip to main content

Privacy Policy

This Privacy Policy explains how HairWhatIf handles account information, uploaded photos, hairstyle previews, credits, support communications, providers, retention and privacy rights.

How HairWhatIf collects, uses, stores, discloses, transfers and deletes personal information.

HairWhatIf Privacy Policy

Version: 1.0 Last Updated: July 31, 2026

1. Who We Are

HairWhatIf is an AI-assisted virtual hairstyle preview service operated as the HairWhatIf online service ("HairWhatIf," "we," "us," or "our").

For the personal information processed in connection with the HairWhatIf website, application, user accounts, uploaded photos, hairstyle previews, customer support, and product operations, HairWhatIf is the data controller or personal information processor unless this Policy states otherwise.

Contact details:

  • Privacy inquiries: support@hairwhatif.com
  • Customer support: support@hairwhatif.com
  • Website: https://hairwhatif.com
  • Data Protection Officer: Not appointed
  • EEA representative: Not currently applicable
  • UK representative: Not currently applicable

2. Scope of This Policy

This Policy explains how HairWhatIf collects, uses, stores, discloses, transfers, and deletes personal information when you:

  • visit the HairWhatIf website;
  • create or use a HairWhatIf account;
  • upload or prepare a photograph;
  • select a hairstyle or submit a hairstyle-preview request;
  • view, keep, download, or delete a generated result;
  • purchase or use credits;
  • provide feedback or contact support; or
  • otherwise interact with HairWhatIf.

This Policy does not govern third-party websites or services that have their own privacy policies.

Preview-only operation

HairWhatIf may sometimes operate in a preview-only or local-preparation mode. When the Studio clearly states that photo preparation is local-only, the selected photo is processed in your browser and is not uploaded to HairWhatIf's servers.

When server-side upload or generation is enabled, the remaining sections of this Policy apply to that processing.

3. Information We Collect

3.1 Account and profile information

We may collect:

  • email address;
  • account identifier;
  • authentication and email-verification status;
  • account creation and last sign-in dates;
  • name, if provided;
  • country or region;
  • language and locale preferences;
  • authentication-provider information when you use an external sign-in provider;
  • session and account-security information; and
  • credit balance and account status.

We do not receive your password from an external OAuth provider. Password authentication, where offered, is managed through our authentication service provider.

3.2 Photos and image content

Depending on the available HairWhatIf features, we may process:

  • your target photograph-the photograph on which a hairstyle is previewed;
  • a hairstyle reference photograph that you own or are authorized to use;
  • cropped, resized, masked, or normalized versions of an uploaded image;
  • a deidentified hairstyle reference card or hairstyle description;
  • intermediate images created during processing;
  • generated hairstyle-preview candidates; and
  • the final delivered result.

Photographs containing a visible face may be considered sensitive personal information under some laws. HairWhatIf processes these photographs solely to provide the requested hairstyle-preview service and related safety, quality, and deletion functions.

3.3 Generation and service-use information

We may collect:

  • selected hairstyle or template;
  • requested hairstyle settings, such as color or style options;
  • generation mode;
  • consent and authorization confirmations;
  • job identifiers;
  • generation status and timestamps;
  • safe failure or rejection categories;
  • result expiry and retention status;
  • deletion-request status;
  • credit reservation, settlement, or release status; and
  • product usage and feature-interaction information.

3.4 Feedback and communications

When you provide feedback or contact us, we may collect:

  • satisfaction rating;
  • selected feedback reasons;
  • written feedback;
  • support correspondence;
  • the date and time of communications; and
  • information you voluntarily include in your message.

Providing product feedback does not automatically authorize HairWhatIf personnel to view your uploaded or generated images. If image access is needed for support, quality investigation, or troubleshooting, we will request separate permission unless access is required to address fraud, abuse, security, or a legal obligation.

Do not send sensitive images through email or support channels unless we specifically request them through an approved secure process.

3.5 Payment and transaction information

When payments are available, purchases are processed by Waffo Pancake.

Waffo Pancake may collect information such as:

  • name;
  • email address;
  • billing address;
  • payment-method information;
  • IP address;
  • order information;
  • tax information;
  • fraud-prevention information; and
  • invoice, refund, or chargeback information.

HairWhatIf does not receive or store your complete payment-card number.

HairWhatIf may receive limited transaction information required to provide the purchased product, including:

  • HairWhatIf account or customer identifier;
  • Waffo customer, checkout, order, payment, subscription, or transaction identifier;
  • product or credit-package identifier;
  • currency and payment status;
  • purchase, refund, dispute, or chargeback status; and
  • signed webhook-event information needed to reconcile the transaction.

Waffo Pancake independently determines how it processes information for payment collection, invoicing, taxation, fraud prevention, refunds, and chargebacks. Waffo Pancake's own terms and privacy notice apply to those activities.

3.6 Technical and security information

We and our infrastructure providers may automatically process:

  • IP address;
  • browser and device type;
  • operating system;
  • request date and time;
  • requested page or API route;
  • approximate country or region;
  • security events;
  • authentication events;
  • rate-limit events;
  • safe error codes;
  • cookie and session identifiers; and
  • limited diagnostic information.

HairWhatIf is designed not to place uploaded photos, generated images, raw prompts, signed image URLs, storage-object keys, or image data encoded as base64 into analytics or ordinary application logs.

3.7 Cookies and local storage

HairWhatIf may use:

  • secure session and authentication cookies;
  • language-preference cookies;
  • consent-preference storage;
  • security and fraud-prevention cookies; and
  • non-essential analytics cookies only after any legally required consent.

HairWhatIf does not intentionally store uploaded image files, image data encoded as base64, private storage-object keys, ownership tokens, or signed image URLs in browser local storage.

See the separate Cookie Policy for more information.

4. How We Collect Information

We collect information:

  • directly from you;
  • from your device or browser;
  • through your use of HairWhatIf;
  • from an authentication provider you select;
  • from Waffo Pancake in connection with a payment or transaction;
  • from service providers operating on our behalf;
  • from fraud, safety, or security systems; and
  • when required, from public authorities or other lawful sources.

HairWhatIf does not import photographs directly from social-media URLs or scrape third-party websites for user-submitted hairstyle references.

5. How We Use Information

We may use personal information to:

  • create, authenticate, maintain, and secure your account;
  • validate uploaded files and prepare images for processing;
  • generate the hairstyle preview you request;
  • preserve the target person's identity and restrict changes to the intended hair region;
  • evaluate result quality, image safety, edit locality, and technical integrity;
  • deliver, display, retain, download, or delete results;
  • operate credits, reservations, purchases, refunds, and transaction reconciliation;
  • maintain generation history and account records;
  • respond to support, privacy, and security requests;
  • investigate fraud, abuse, unauthorized image use, policy evasion, or security incidents;
  • enforce our Terms of Service and Acceptable Use Policy;
  • comply with tax, accounting, consumer-protection, privacy, and other legal requirements;
  • diagnose and improve service reliability;
  • perform aggregated or deidentified analysis; and
  • establish, exercise, or defend legal claims.

We will not use an uploaded target or reference photograph to advertise to you or to build an advertising profile.

6. Processing Grounds

The processing ground depends on the information, purpose, and applicable law.

Where the GDPR, UK GDPR, or similar law applies, we generally rely on:

  • Performance of a contract: to provide accounts, image processing, results, credits, downloads, deletion functions, and support.
  • Consent: where required for image processing, optional analytics, marketing, sensitive personal information, or an international transfer.
  • Legitimate interests: to secure HairWhatIf, prevent fraud and abuse, diagnose faults, maintain limited operational records, and improve service reliability, where those interests are not overridden by your rights.
  • Legal obligations: to comply with accounting, tax, consumer-protection, sanctions, law-enforcement, and regulatory obligations.
  • Legal claims: to establish, exercise, or defend claims.

Where another privacy law applies, including China's Personal Information Protection Law, we process personal information based on consent or another lawful basis available under that law.

Where separate consent is legally required-for example, for sensitive personal information or certain international transfers-we will request that consent separately before the relevant processing occurs.

You may withdraw consent through the available account or consent controls or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal. Some core HairWhatIf functions cannot be provided without processing the photograph and service data required for that function.

7. How HairWhatIf Processes Photographs

7.1 Limited purpose

HairWhatIf processes photographs only for hairstyle-preview creation, related quality and safety checks, delivery, user-requested retention, support authorized by the user, and deletion.

HairWhatIf is not designed for:

  • face swapping;
  • identity impersonation;
  • facial recognition;
  • identity verification using facial features;
  • celebrity cloning;
  • creation of a permanent face database;
  • unrestricted portrait generation; or
  • automated identification of a person.

7.2 No permanent facial template

HairWhatIf does not intentionally create or retain a permanent facial-recognition template, persistent face embedding, or reusable identity profile from an uploaded photograph.

Temporary technical measurements may be used during a generation request to assess identity preservation, edit locality, or image quality. They must not be repurposed for identifying the person or building a permanent identity database.

7.3 Target and reference separation

HairWhatIf distinguishes between:

  • the target photograph, which supplies the person, pose, clothing, and scene; and
  • the hairstyle reference, which supplies only authorized hairstyle characteristics.

Where a custom reference feature is enabled, HairWhatIf is designed to transform the reference into a limited, deidentified hairstyle card or description. The full original reference image should not be sent to an image-generation provider after that transformation unless the user is clearly informed and the processing has been separately approved.

7.4 AI service providers

A selected AI service provider may receive the minimum information required to perform a generation, such as:

  • the target photograph;
  • a hairstyle template or deidentified hairstyle reference card;
  • a hair-region mask;
  • limited hairstyle settings; and
  • a system-controlled, hair-only instruction.

Users are not permitted to enter unrestricted generation prompts unless HairWhatIf expressly introduces that feature and updates its policies and safeguards.

HairWhatIf will review a provider's retention, training, security, region, subprocessor, and contractual terms before enabling that provider for production.

HairWhatIf does not authorize an AI provider to use customer photos or results to train a general-purpose model unless we first provide a separate, clear notice and obtain any legally required consent. The current provider-specific terms and configuration must be stated in the Service Provider and Cross-Border Recipient List.

8. When We Disclose Information

We may disclose personal information to the following recipients only when reasonably necessary.

8.1 Infrastructure and authentication providers

These providers may host the website, authentication service, database, private object storage, network services, and backups.

The planned primary data platform is Supabase. Before publication, HairWhatIf must identify the actual production project region and applicable contractual safeguards in the Service Provider and Cross-Border Recipient List.

8.2 AI image-processing providers

The selected production AI provider may process the limited image and generation information described in Section 7.

HairWhatIf must publish the selected provider's name, processing location, purpose, information categories, and applicable retention terms before production processing begins.

8.3 Workflow providers

A workflow service may coordinate long-running generation jobs.

HairWhatIf's intended workflow boundary permits the workflow service to receive only a job identifier and limited, non-sensitive step metadata. Uploaded images, generated images, raw instructions, signed image URLs, and provider response bodies must not be placed in ordinary workflow-event payloads.

8.4 Monitoring and diagnostics providers

An approved monitoring provider may receive allowlisted technical information, such as a request identifier and safe error code.

Uploaded images, generated images, raw prompts, signed URLs, storage-object keys, and arbitrary provider error messages must not be sent to ordinary monitoring tools.

8.5 Analytics providers

Non-essential product analytics are disabled unless and until HairWhatIf selects an approved provider and implements any required notice and consent controls.

If analytics are enabled, HairWhatIf will restrict events to limited product-interaction information and will not intentionally send uploaded images, generated images, filenames, raw prompts, signed URLs, or face or hairstyle embeddings.

8.6 Waffo Pancake

When you make a purchase, HairWhatIf discloses limited account and product-mapping information to Waffo Pancake. HairWhatIf does not send photographs, hairstyle instructions, or generated results to Waffo Pancake.

Waffo Pancake independently processes payment, billing, tax, invoice, fraud, refund, dispute, and chargeback information under its own terms and privacy notice.

8.7 Professional advisers, authorities, and corporate transactions

We may disclose information:

  • to lawyers, accountants, auditors, insurers, or security advisers;
  • to comply with law, legal process, or a binding government request;
  • to protect users, HairWhatIf, or another person's rights and safety;
  • to investigate fraud, abuse, or security incidents; or
  • in connection with a merger, financing, acquisition, restructuring, or transfer of assets.

Where reasonably possible, we will limit disclosure to the information necessary for the relevant purpose.

9. International and Cross-Border Processing

HairWhatIf's operator, infrastructure, storage, AI provider, payment provider, or other service providers may be located in different countries.

Depending on the final production configuration, personal information may be processed outside your country or region. Those locations may have different privacy laws.

Where legally required, HairWhatIf will use safeguards such as:

  • an adequacy decision;
  • approved standard contractual clauses;
  • a data-processing agreement;
  • a certification or other legally recognized transfer mechanism;
  • security and data-minimization controls; or
  • your separate consent.

Before offering HairWhatIf to users in mainland China, HairWhatIf must complete and publish the applicable cross-border recipient information, including each overseas recipient's identity, contact method, purpose, processing method, information categories, retention arrangement, and method for exercising rights. HairWhatIf must also implement separate consent or another legally permitted transfer mechanism where required.

10. Retention and Deletion

HairWhatIf retains personal information only for as long as reasonably necessary for the stated purpose, subject to legal, security, accounting, dispute, and backup requirements.

10.1 Photo and generation retention

Unless a shorter period is displayed in the product:

InformationIntended retention
Photo selected during local-only preparationRemains on your device and in browser memory until you replace it, leave the relevant session, reload the page, or your browser removes it
Uploaded target photographDeleted within 24 hours after the generation reaches a terminal state
Uploaded custom reference photographDeleted within 24 hours after the generation reaches a terminal state
Deidentified hairstyle reference card and intermediate assetsDeleted within one hour after terminal processing
Delivered result30 days from delivery by default
Result explicitly marked "Keep"Up to 365 days from delivery
Result you request to deleteAccess is revoked promptly; physical storage deletion is processed asynchronously and retried if necessary
Failed, cancelled, or policy-blocked generation assetsDeleted according to the applicable terminal-state schedule, generally no later than 24 hours for original inputs and one hour for intermediate assets

Marking a result as "Keep" extends only the final result's retention. It does not extend retention of the target or reference photograph.

A displayed expiry time may be shorter where required by a provider, region, account setting, security event, or product configuration.

10.2 Account, consent, and operational records

Account information, generation metadata, consent records, credit history, deletion-request records, and limited security logs may be retained while your account is active and afterward where needed to:

  • provide account history and data export;
  • maintain an accurate credit and transaction ledger;
  • investigate security incidents or abuse;
  • demonstrate authorization and compliance;
  • reconcile refunds, disputes, and chargebacks;
  • meet tax, accounting, and legal requirements; or
  • establish, exercise, or defend legal claims.

HairWhatIf's account data export may include account details, profile information, generation history, feedback, and deletion-request history. It does not normally include private storage-object keys, provider identifiers, internal quality scores, security secrets, or other users' information.

10.3 Account deletion

When you submit a valid account-deletion request:

  • HairWhatIf locks or restricts product access.
  • New generations and storage writes are prevented.
  • Active jobs are cancelled where possible or allowed to reach a safe accounting state.
  • Private image objects associated with the account are removed.
  • HairWhatIf account-domain data is erased or deidentified where permitted.
  • The authentication account is deleted.
  • A minimal deletion receipt may be retained for up to 30 days before being removed.

Some information may be retained where required for accounting, taxation, fraud prevention, payment disputes, security, or legal claims. Waffo Pancake may separately retain transaction and accounting information under its legal obligations and privacy notice.

10.4 Backups and delayed deletion

Deletion from active product systems may occur before deletion from encrypted backups, provider logs, or legally required records.

Information remaining in backups is isolated from ordinary use and removed or overwritten according to the applicable backup cycle unless it must be retained by law.

11. Security

HairWhatIf uses technical and organizational measures intended to protect personal information, including:

  • private rather than public image storage;
  • owner-scoped access controls;
  • short-lived, purpose-limited access URLs;
  • server-side authorization checks;
  • encryption in transit;
  • restricted administrative access;
  • separation of public, authenticated, and administrative routes;
  • data-minimization rules for providers and logs;
  • bounded upload and response sizes;
  • safe error codes instead of arbitrary provider messages;
  • deletion queues with retry handling;
  • account reauthentication for sensitive actions; and
  • security, dependency, and privacy testing.

No system can guarantee complete security. You are responsible for protecting your login credentials and notifying us promptly of suspected unauthorized access.

12. Your Choices and Rights

Depending on your location and applicable law, you may have the right to:

  • know whether we process your personal information;
  • access or receive a copy of your information;
  • export information in a portable format;
  • correct inaccurate or incomplete information;
  • request deletion;
  • restrict or object to certain processing;
  • withdraw consent;
  • request an explanation of certain processing;
  • opt out of targeted advertising, sale, or sharing;
  • limit certain uses of sensitive personal information;
  • appeal a privacy-request decision where applicable; and
  • complain to a privacy or data-protection authority.

HairWhatIf does not sell personal information for money. HairWhatIf does not share personal information for cross-context behavioral advertising and does not use customer photos for targeted advertising.

You may exercise available account rights through:

  • the Account or Data Controls page;
  • the individual result's Delete control;
  • the account-data export function;
  • the account-deletion function; or
  • support@hairwhatif.com.

We may need to verify your identity before fulfilling a request. We will use information submitted for verification only for handling the request, preventing fraud, and maintaining the legally required request record.

We will not discriminate against you for exercising a privacy right. A service feature may become unavailable when the information required to provide that feature is deleted or when necessary consent is withdrawn.

Authorized agents

Where applicable law permits an authorized agent to act for you, we may request evidence of the agent's authority and may require you to verify your identity directly.

Complaints

You may contact us first at support@hairwhatif.com.

You may also have the right to complain to the data-protection, privacy, consumer-protection, or cybersecurity authority in your jurisdiction.

13. Additional Information for EEA, UK, and Swiss Users

Where applicable, you may request access, correction, erasure, restriction, portability, or objection, and may withdraw consent.

When we rely on legitimate interests, you may request information about the applicable balancing assessment.

HairWhatIf does not use uploaded photographs to make decisions that produce legal or similarly significant effects concerning you. Automated systems may perform image validation, content-safety checks, identity-preservation checks, quality checks, and policy rejection. These functions determine whether HairWhatIf can process or deliver a hairstyle preview, but they are not used to determine employment, credit, insurance, housing, education, healthcare, or other similarly significant eligibility.

Where required, you may contact us to contest or request information about an automated rejection.

14. Additional Information for Mainland China Users

Where China's Personal Information Protection Law and related rules apply, you may have rights to:

  • know and decide how your personal information is processed;
  • restrict or refuse certain processing;
  • access and copy personal information;
  • correct or supplement inaccurate information;
  • request deletion;
  • withdraw consent;
  • cancel your account; and
  • request an explanation of this Policy and our processing rules.

Photos containing an identifiable face may be treated as sensitive personal information. HairWhatIf processes such information only where there is a specific purpose and sufficient necessity, and it applies enhanced protection measures.

Where required, HairWhatIf will separately explain:

  • why processing sensitive personal information is necessary;
  • the possible effect on your rights;
  • the overseas recipients of your information;
  • the purpose and method of overseas processing;
  • the categories of information transferred; and
  • how to exercise rights against an overseas recipient.

Before offering HairWhatIf to users in mainland China as a targeted local launch, HairWhatIf will complete and publish any required cross-border recipient information and separate-consent mechanism.

15. Additional Information for U.S. Residents

Where an applicable U.S. state privacy law applies, the categories of personal information HairWhatIf may have collected include:

  • identifiers;
  • customer-record information;
  • commercial and transaction information;
  • internet or electronic-network activity;
  • visual information;
  • account, authentication, and security information;
  • approximate country or region;
  • hairstyle preferences and related service inferences;
  • user communications; and
  • sensitive personal information contained in account credentials or photographs.

HairWhatIf uses and discloses these categories for the business and commercial purposes described in this Policy.

HairWhatIf may disclose these categories to service providers, contractors, Waffo Pancake, professional advisers, authorities, or transaction parties as described in Section 8.

HairWhatIf does not sell these categories and does not share them for cross-context behavioral advertising.

Where required by law, you may request information about collection, use, disclosure, retention, and specific pieces of personal information, as well as correction or deletion. You may also have the right to limit certain uses of sensitive personal information and to appeal a denied request.

16. Adults Only and Third-Party Photographs

HairWhatIf is intended only for people aged 18 or older.

Do not upload:

  • a photograph depicting a minor;
  • a photograph where the person's age is ambiguous;
  • a photograph you do not own or have permission to use;
  • a photograph used for impersonation, deception, harassment, or abuse;
  • a celebrity or public-figure photograph for identity replication;
  • sexually explicit or illegal content; or
  • an image obtained through scraping or unauthorized copying.

By submitting a photograph, you confirm that:

  • every depicted person is an adult;
  • you own the image or have valid permission to use it for AI hairstyle processing;
  • you have provided any notice or obtained any consent required from the depicted person; and
  • your use complies with the Terms of Service and Acceptable Use Policy.

If another person believes their image was uploaded without authorization, they may contact support@hairwhatif.com. We may request sufficient information to locate and evaluate the content while avoiding unnecessary collection.

17. Business Transfers

If HairWhatIf is involved in a merger, acquisition, financing, reorganization, insolvency, or sale of assets, personal information may be disclosed as part of that transaction.

Any recipient must process the information consistently with applicable law and this Policy unless you are provided with a new notice where required.

18. Changes to This Policy

We may update this Policy to reflect changes in HairWhatIf, service providers, processing locations, legal requirements, or privacy practices.

The current version will display its effective date and version number. Where a change materially affects your rights or the processing of sensitive information, we will provide additional notice or obtain consent where required.

Previous versions and a summary of material changes are available by contacting support@hairwhatif.com.

19. Contact Us

For privacy questions, requests, complaints, or concerns:

HairWhatIf Email: support@hairwhatif.com Support: support@hairwhatif.com Website: https://hairwhatif.com

For payment, billing, invoice, tax, or payment-method privacy questions, you may also need to contact Waffo Pancake under its terms and privacy notice.

Appendix A - Service Provider and Cross-Border Recipient List

The table below describes the service providers and cross-border recipients used for HairWhatIf operations.

RecipientRole and purposeInformation receivedProcessing locationRetention or deletion terms
Supabase, Inc.Authentication, database, and private object storage processorAccount data, job and credit metadata, consent records, private uploaded and generated image objectsProject-selected hosted regionProduct-controlled deletion; backup terms depend on the selected plan and configuration
OpenAI-compatible image provider configured for HairWhatIfAI hairstyle image-processing providerTarget photograph, deidentified hairstyle card or template, hair mask, limited hairstyle settings, system-controlled instructionProvider-configured API endpoint and processing regionGoverned by the provider account terms and HairWhatIf's product retention controls
Inngest, Inc.Long-running workflow coordinationJob identifier and limited non-sensitive step metadata onlyInngest service regionsGoverned by Inngest account terms and HairWhatIf's event minimization controls
Vercel Inc.Website and API hosting, networking, securityRequest and device information; application traffic subject to data-minimization controlsVercel edge and serverless regionsGoverned by Vercel account terms, deployment logs, and product data-minimization controls
Waffo PancakePayment checkout, subscription, invoice, fraud, refund, and chargeback processingAccount/payment identifiers, product identifier, checkout metadata, transaction and payment status; no photos or generated resultsWaffo Pancake operating regions and subprocessorsGoverned by Waffo Pancake's terms, privacy notice, and legal/accounting requirements
Monitoring providerSecurity and service diagnostics, if enabledAllowlisted scalar telemetry, request identifier, safe error codeProvider-selected service regionNot enabled unless HairWhatIf selects and discloses a provider
Analytics providerConsent-based product analytics, if enabledLimited event names and coarse non-sensitive propertiesProvider-selected service regionNot enabled unless HairWhatIf selects and discloses a provider

Appendix B - Material Change Log

VersionEffective dateSummary
1.0July 31, 2026Initial published Privacy Policy