Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains how Kilter Digital (a Norwegian sole proprietorship / enkeltpersonforetak, org. no. 936 936 768, owned by Filip Jolma Helland Kilter) (“we”, “us”, the data controller) collects and uses your information when you download, install and use the Embla mobile application (“the app”).
1. What we collect
Your capture photograph
When you take a capture, the app takes one photograph of your face and measures your face on your device. The photograph is stored only on your device, in the app’s private storage, protected with iOS file encryption. It is never backed up to iCloud by the app, and it appears outside the app only if you yourself choose to save or share your Face File card.
To produce your analysis, the app sends the photograph, together with the measurements described below, to our backend, which forwards it once to an AI vision model to write the qualitative part of your Face File. As stated above, the photograph is not retained at any point in that path, by us. It is not posted anywhere, it is not shared with other users, and it is never used to train models.
Two other features send an image the same way, each inside a single request that we do not retain: the one-time Potential illustration sends your capture photograph once to an AI image model as the identity reference for the drawing, which is returned to your device and kept only there; and a photo you choose to attach in the Ask chat is sent once so the answer can address it.
Your face measurements and geometry
To take its readings, the app computes the following from the camera feed, entirely on your device:
- Facial landmark coordinates — the positions of features such as your eyes, brows, nose, lips and face outline, detected by Apple’s on-device Vision framework;
- on devices with a TrueDepth camera, a three-dimensional face mesh and metric measurements such as interpupillary distance and face width and height, from Apple’s ARKit face tracking;
- derived readings — proportions, symmetry values and similar figures calculated from the above.
None of this is a biometric template: the app does not perform face recognition, does not create data that could identify you among other people’s faces, and does not compare your face against anyone else’s. The three-dimensional face mesh never leaves your device. When you request an analysis, the labelled measurement values (not the raw landmark coordinates and not the mesh) accompany the photograph in the same single, unretained request described above.
Your Face File
The measurements, landmark coordinates, readings and plan that make up your Face File are kept on your device. If your phone is signed in to iCloud, the app also mirrors your Face File — never your photographs and never the three-dimensional face mesh — to your own private iCloud database, so it survives a new phone. That copy lives in your personal iCloud account, where we cannot read it, and “Delete everything” in the app’s Settings removes it too. There is no Embla account and nothing to sign in to.
An anonymous app identifier
Embla works without an account. To deliver analyses and subscription access, the app generates a random, anonymous identifier for your install. It is not your name, email or phone number, and we do not use it to build a profile of you. The same identifier is what our analytics and attribution tools see (described under “Advertising measurement” and “Usage analytics” below), so usage data stays pseudonymous.
Device integrity and usage counters
Our backend stores an Apple App Attest device key and attestation receipt to confirm that requests come from a genuine, unmodified copy of the app, and a count of how many analyses that device has used in the current week so we can apply fair-use limits. It also records that a one-time “potential” drawing was made for your device. That record is the fact that it happened; the drawing itself is returned once and lives only on your device.
Purchases
Subscriptions are processed by Apple and managed through our subscription provider, RevenueCat. We receive your subscription status, for example active or expired, and never your payment-card details, which are handled entirely by Apple.
Technical and diagnostic data
Our servers process the technical information needed to operate the service securely, such as request metadata, rate-limiting counters and error logs. Structured logs carry labels, latency and model identifiers only. This is used to run and protect the service, not to track you across other apps.
Advertising measurement
To understand which marketing campaigns lead to installs, the app reports conversion values to Apple’s privacy-preserving SKAdNetwork and AdAttributionKit. This does not identify you. The app also uses AppsFlyer, a mobile measurement partner, for install attribution. If you allow tracking in the iOS App Tracking Transparency prompt, AppsFlyer may read your device’s advertising identifier (IDFA) to attribute your install and purchases to the advertising campaign that brought you here; if you decline, no advertising identifier is read and measurement stays within Apple’s aggregate frameworks. Our subscription provider reports purchase events — the plan and price, never your payment details, your photograph or your measurements — to AppsFlyer on our behalf, and attribution results may be shared with the advertising platform that showed you the ad (for example TikTok) to measure campaign performance. We also use Apple’s AdServices framework to attribute installs from Apple Search Ads; that framework does not use the advertising identifier and does not involve the tracking prompt. You can change your tracking choice at any time in iOS Settings > Privacy & Security > Tracking.
Usage analytics
So we can see where the app loses or confuses people, the app records product events — for example which onboarding screen was viewed, that a scan completed, or that a subscription started — tied to the random install identifier described above. We use PostHog, hosted in the EU, to store and chart these events. They never contain your name, your photograph or any measurement from your Face File.
If you contact us
If you email us, we process the contact details and content you choose to provide, in order to respond.
2. How and why we use it (legal bases)
- To produce your analysis and plan from your capture, to perform our contract with you.
- To verify subscription entitlements and to apply fair-use limits, for contract performance and our legitimate interests in securing the service.
- To confirm requests come from a genuine copy of the app and to prevent abuse, for legitimate interests.
- To keep the service secure and reliable and to fix faults, for legitimate interests.
- To measure marketing performance in aggregate through Apple’s privacy-preserving frameworks, for legitimate interests. Identifier-based attribution through AppsFlyer runs only with your consent, given through the App Tracking Transparency prompt.
- To understand how the app is used and improve it, through pseudonymous product analytics, for legitimate interests.
- To respond to your messages, for legitimate interests.
We do not sell your personal information, and we do not use your photograph or your measurements for advertising.
3. The analysis and AI processing
Your analysis combines deterministic measurements computed on your device with a written reading generated by an AI model, accessed through the OpenRouter API. The photograph and the measurement values are sent for that single request and are not retained by us afterwards. The one-time Potential drawing and Ask-chat photo attachments follow the same single-request path through the same API. For every request that carries an image, we instruct our routing provider to use only model providers that do not retain submitted content and do not train on it. The request sent to the model carries no name and no account or device identifier — only the image, the measurement values and the instructions for the reading.
Embla is a cosmetic and informational product. It is not a medical device, it does not diagnose, treat or prevent any condition, and its readings are estimates rather than clinical findings. See our Terms of Use.
4. Service providers
We share the minimum necessary data with providers who process it on our behalf:
- Cloudflare: hosting and edge infrastructure for the backend and this site.
- OpenRouter, and through it the AI model provider serving the request: to generate the written analysis, the one-time Potential illustration and Ask-chat answers from the submitted photograph, measurements and messages.
- Apple: App Store distribution, in-app purchases, app integrity through App Attest, and iCloud (CloudKit) for the optional backup of your Face File to your own private iCloud database.
- RevenueCat: subscription management and entitlement verification.
- AppsFlyer: marketing attribution — linking installs and purchases to the advertising campaign that led to them, and forwarding those events to the advertising platform that showed you the ad (for example TikTok). Uses the advertising identifier only if you allow tracking.
- PostHog (EU-hosted): pseudonymous product analytics on how the app is used.
These providers may use the data only to deliver their service to us, and process it under their own privacy policies. The app does not show ads and does not embed ad-serving networks. If we change the tools we use, we will update this Policy and the App Store privacy labels accordingly.
5. Data retention
We retain your capture photograph for zero time. On our servers it exists only for the seconds it takes to complete the single analysis request, and is gone when the response returns. The copy on your device, along with your Face File — the landmark coordinates, face mesh, measurements, readings and plan — remains on your device until you use “Delete everything” in the app’s Settings or remove the app; both erase the photograph, the face mesh and the Face File. If your phone is signed in to iCloud, the backup copy of your Face File in your private iCloud database remains until you use “Delete everything”, which removes it too. Server-side records are limited to your entitlement status, your device attestation key, weekly usage counters and the one-time drawing record — none of which contain your photograph, your face geometry or any measurement — kept for as long as necessary to provide and protect the service or as required by law. You can ask us to delete the server-side data associated with your install.
6. Your rights
Because we operate from Norway, which is in the EEA, the GDPR applies. Subject to its conditions, you have the right to:
- be informed about how your data is used, which is this Policy;
- access the personal data we hold about you;
- rectify inaccurate data and complete incomplete data;
- erase your data;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with a supervisory authority. In Norway this is the Norwegian Data Protection Authority, Datatilsynet.
To exercise any of these, email us at the address below. You can control camera access in iOS Settings, manage tracking permission under Privacy & Security > Tracking, and manage or cancel subscriptions in your Apple ID settings. Removing the app deletes your on-device Face File.
7. Security
We use industry-standard measures including encryption in transit, scoped access, hardware app-integrity checks and rate limiting. On your device, your photograph, face mesh and Face File are stored with iOS file encryption. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. The strongest protection for your photograph is that on our side it is never written down anywhere.
8. Children
Embla is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it promptly.
9. International transfers
Our providers may process data in countries outside the EEA, including the United States. Where this happens we rely on appropriate safeguards, such as the EU Standard Contractual Clauses or an adequacy decision, as required by law.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, noted in the app.
11. Contact
For any privacy question, or to exercise your rights, contact the data controller:
Kilter Digital (enkeltpersonforetak)
Org. no. 936 936 768
Kong Haralds gate 46A, 4041 Hafrsfjord, Norway
Email: fk.apps.customer@gmail.com