Privacy Policy & Biometric Data Notice
Last updated: August 2026
Evna is dedicated to preserving your absolute biometric privacy and personal security. We never sell your personal data, never train public AI foundational models on your facial photographs, and enforce strict private encryption for all portraits.
Encrypted Private Storage
Raw selfies and data are encrypted at rest with AES-256 in private non-public Cloudflare R2 buckets.
Zero Model Training
We never use your facial photographs or biometric proportions to train public AI foundational models.
User Data Control
You retain complete ownership over your data and can request full deletion of your assets at any time.
1. Information We Collect & Biometric Proportions
When you take or upload a selfie, our client-side and secure edge gateway extract geometric landmark proportions (facial thirds, gonial jaw angles, cheekbone-to-temple widths) solely to deliver tailored hairstyle recommendations and stylist dossiers.
2. Private Encrypted Storage & User Data Controls
User photos are stored in private, non-public Cloudflare R2 buckets with AES-256 encryption. Upload access is granted exclusively through short-lived presigned URLs (15-minute expiration). You retain complete control over your data and may request immediate deletion at any time.
3. Automated Content Safety & Interception
To protect users and comply with statutory child safety obligations, images undergo real-time moderation screening on upload to verify that only safe, single-subject self-portraits are processed, blocking illegal or harmful content before database storage.
4. Zero AI Foundational Model Training
Your personal photographs and biometric measurements are never utilized to train, fine-tune, or improve public or proprietary foundational AI models without explicit, separate written authorization.
5. Statutory Compliance (BIPA, GDPR, CCPA/CPRA)
We adhere to the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, California Consumer Privacy Act (CCPA/CPRA), and EU General Data Protection Regulation (GDPR). You possess the right to access, delete, or request an audit of any session data.
6. Data Requests & Contacting Privacy Officers
For privacy inquiries, data deletion requests, or compliance questions, reach out directly to our Data Protection Officer at [email protected] or report safety concerns at [email protected].
Biometric Governance
GDPR • CCPA • BIPA Certified
AES-256 / SSE-S3
15 Minutes (900s)
User-Controlled (On Demand)
Strictly Prohibited (0%)
