Evna
Biometric Privacy & Private Encrypted Security

Privacy Policy & Biometric Data Notice

Last updated: August 2026

Evna is dedicated to preserving your absolute biometric privacy and personal security. We never sell your personal data, never train public AI foundational models on your facial photographs, and enforce strict private encryption for all portraits.

Encrypted Private Storage

Raw selfies and data are encrypted at rest with AES-256 in private non-public Cloudflare R2 buckets.

Zero Model Training

We never use your facial photographs or biometric proportions to train public AI foundational models.

User Data Control

You retain complete ownership over your data and can request full deletion of your assets at any time.

1. Information We Collect & Biometric Proportions

When you take or upload a selfie, our client-side and secure edge gateway extract geometric landmark proportions (facial thirds, gonial jaw angles, cheekbone-to-temple widths) solely to deliver tailored hairstyle recommendations and stylist dossiers.

2. Private Encrypted Storage & User Data Controls

User photos are stored in private, non-public Cloudflare R2 buckets with AES-256 encryption. Upload access is granted exclusively through short-lived presigned URLs (15-minute expiration). You retain complete control over your data and may request immediate deletion at any time.

3. Automated Content Safety & Interception

To protect users and comply with statutory child safety obligations, images undergo real-time moderation screening on upload to verify that only safe, single-subject self-portraits are processed, blocking illegal or harmful content before database storage.

4. Zero AI Foundational Model Training

Your personal photographs and biometric measurements are never utilized to train, fine-tune, or improve public or proprietary foundational AI models without explicit, separate written authorization.

5. Statutory Compliance (BIPA, GDPR, CCPA/CPRA)

We adhere to the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, California Consumer Privacy Act (CCPA/CPRA), and EU General Data Protection Regulation (GDPR). You possess the right to access, delete, or request an audit of any session data.

6. Data Requests & Contacting Privacy Officers

For privacy inquiries, data deletion requests, or compliance questions, reach out directly to our Data Protection Officer at [email protected] or report safety concerns at [email protected].

Biometric Governance

GDPR • CCPA • BIPA Certified

Encryption Standard:

AES-256 / SSE-S3

Upload URL Expiration:

15 Minutes (900s)

Data Deletion:

User-Controlled (On Demand)

AI Model Training:

Strictly Prohibited (0%)