How HairAiChanger collects, uses, and protects your data
2026/04/28
Last updated: April 28, 2026
This Privacy Policy explains how HairAiChanger ("we", "us", or "our") collects, uses, and protects your information when you use hairaichanger.com (the "Service"). By using the Service, you agree to this policy.
When you sign up via Google OAuth or email, we receive your email address, name, and profile picture from the auth provider.
To generate AI hairstyle previews, you upload a photo of yourself. We process and store these photos in our object storage to power the generation pipeline. You can delete your account at any time, which removes your associated data.
AI-generated hairstyle images are stored so you can revisit and download them. They are tied to your account.
Payments are processed by Stripe. We do not see or store your card number. Stripe shares with us only the payment status, amount, and an internal customer ID for record-keeping and credit allocation.
We collect basic technical data — IP address, browser type, pages visited, and timestamps — to keep the Service secure and to debug issues.
See our Cookie Policy for details.
We do not sell your personal data or photos to third parties. We do not use your photos to train public AI models.
Your uploaded photo is sent to our image-generation provider (KIE / OpenAI-compatible API) solely for the purpose of producing your hairstyle preview. The provider processes the photo per their API agreement and is contractually restricted from using your data for unrelated purposes.
We share data with these processors only as needed:
All providers are bound by their own privacy policies and data-protection terms.
You can request deletion at any time by deleting your account in settings or emailing support@hairaichanger.com.
Depending on your jurisdiction (e.g. GDPR/EU, CCPA/California), you may have the right to:
Contact support@hairaichanger.com to exercise any of these rights.
The Service is not intended for users under 13 (or under 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We are based outside of every region we serve. Your data may be transferred to and processed in countries other than your own. We rely on standard contractual clauses and provider safeguards for international transfers.
We use HTTPS, encryption at rest for stored files, and access controls for our infrastructure. No system is 100% secure; we cannot guarantee absolute security but commit to industry-standard safeguards.
We may update this Privacy Policy. Material changes will be announced on this page with an updated "Last updated" date. Continued use of the Service after changes means you accept the updated policy.
Questions or requests: