Embla

Privacy Policy

Last updated: 25 August 2026

This Privacy Policy explains how Kilter Digital (a Norwegian sole proprietorship / enkeltpersonforetak, org. no. 936 936 768, owned by Filip Jolma Helland Kilter) (“we”, “us”, the data controller) collects and uses your information when you download, install and use the Embla mobile application (“the app”).

The photograph of your face is never stored on our servers. It lives only on your device. When you request an analysis it exists inside the single request that reads it: it is sent once to the model that analyses it, and it is gone from our systems when the response returns. There is no image storage in our backend, no database column holds image data, and no log line contains the photograph. This is an architectural property of the service, not a policy promise we could quietly change.

1. What we collect

Your capture photograph

When you take a capture, the app takes one photograph of your face and measures your face on your device. The photograph is stored only on your device, in the app’s private storage, protected with iOS file encryption. It is never backed up to iCloud by the app, and it appears outside the app only if you yourself choose to save or share your Face File card.

To produce your analysis, the app sends the photograph, together with the measurements described below, to our backend, which forwards it once to an AI vision model to write the qualitative part of your Face File. As stated above, the photograph is not retained at any point in that path, by us. It is not posted anywhere, it is not shared with other users, and it is never used to train models.

Two other features send an image the same way, each inside a single request that we do not retain: the one-time Potential illustration sends your capture photograph once to an AI image model as the identity reference for the drawing, which is returned to your device and kept only there; and a photo you choose to attach in the Ask chat is sent once so the answer can address it.

Your face measurements and geometry

To take its readings, the app computes the following from the camera feed, entirely on your device:

None of this is a biometric template: the app does not perform face recognition, does not create data that could identify you among other people’s faces, and does not compare your face against anyone else’s. The three-dimensional face mesh never leaves your device. When you request an analysis, the labelled measurement values (not the raw landmark coordinates and not the mesh) accompany the photograph in the same single, unretained request described above.

Your Face File

The measurements, landmark coordinates, readings and plan that make up your Face File are kept on your device. If your phone is signed in to iCloud, the app also mirrors your Face File — never your photographs and never the three-dimensional face mesh — to your own private iCloud database, so it survives a new phone. That copy lives in your personal iCloud account, where we cannot read it, and “Delete everything” in the app’s Settings removes it too. There is no Embla account and nothing to sign in to.

An anonymous app identifier

Embla works without an account. To deliver analyses and subscription access, the app generates a random, anonymous identifier for your install. It is not your name, email or phone number, and we do not use it to build a profile of you. The same identifier is what our analytics and attribution tools see (described under “Advertising measurement” and “Usage analytics” below), so usage data stays pseudonymous.

Device integrity and usage counters

Our backend stores an Apple App Attest device key and attestation receipt to confirm that requests come from a genuine, unmodified copy of the app, and a count of how many analyses that device has used in the current week so we can apply fair-use limits. It also records that a one-time “potential” drawing was made for your device. That record is the fact that it happened; the drawing itself is returned once and lives only on your device.

Purchases

Subscriptions are processed by Apple and managed through our subscription provider, RevenueCat. We receive your subscription status, for example active or expired, and never your payment-card details, which are handled entirely by Apple.

Technical and diagnostic data

Our servers process the technical information needed to operate the service securely, such as request metadata, rate-limiting counters and error logs. Structured logs carry labels, latency and model identifiers only. This is used to run and protect the service, not to track you across other apps.

Advertising measurement

To understand which marketing campaigns lead to installs, the app reports conversion values to Apple’s privacy-preserving SKAdNetwork and AdAttributionKit. This does not identify you. The app also uses AppsFlyer, a mobile measurement partner, for install attribution. If you allow tracking in the iOS App Tracking Transparency prompt, AppsFlyer may read your device’s advertising identifier (IDFA) to attribute your install and purchases to the advertising campaign that brought you here; if you decline, no advertising identifier is read and measurement stays within Apple’s aggregate frameworks. Our subscription provider reports purchase events — the plan and price, never your payment details, your photograph or your measurements — to AppsFlyer on our behalf, and attribution results may be shared with the advertising platform that showed you the ad (for example TikTok) to measure campaign performance. We also use Apple’s AdServices framework to attribute installs from Apple Search Ads; that framework does not use the advertising identifier and does not involve the tracking prompt. You can change your tracking choice at any time in iOS Settings > Privacy & Security > Tracking.

Usage analytics

So we can see where the app loses or confuses people, the app records product events — for example which onboarding screen was viewed, that a scan completed, or that a subscription started — tied to the random install identifier described above. We use PostHog, hosted in the EU, to store and chart these events. They never contain your name, your photograph or any measurement from your Face File.

If you contact us

If you email us, we process the contact details and content you choose to provide, in order to respond.

2. How and why we use it (legal bases)

We do not sell your personal information, and we do not use your photograph or your measurements for advertising.

3. The analysis and AI processing

Your analysis combines deterministic measurements computed on your device with a written reading generated by an AI model, accessed through the OpenRouter API. The photograph and the measurement values are sent for that single request and are not retained by us afterwards. The one-time Potential drawing and Ask-chat photo attachments follow the same single-request path through the same API. For every request that carries an image, we instruct our routing provider to use only model providers that do not retain submitted content and do not train on it. The request sent to the model carries no name and no account or device identifier — only the image, the measurement values and the instructions for the reading.

Embla is a cosmetic and informational product. It is not a medical device, it does not diagnose, treat or prevent any condition, and its readings are estimates rather than clinical findings. See our Terms of Use.

4. Service providers

We share the minimum necessary data with providers who process it on our behalf:

These providers may use the data only to deliver their service to us, and process it under their own privacy policies. The app does not show ads and does not embed ad-serving networks. If we change the tools we use, we will update this Policy and the App Store privacy labels accordingly.

5. Data retention

We retain your capture photograph for zero time. On our servers it exists only for the seconds it takes to complete the single analysis request, and is gone when the response returns. The copy on your device, along with your Face File — the landmark coordinates, face mesh, measurements, readings and plan — remains on your device until you use “Delete everything” in the app’s Settings or remove the app; both erase the photograph, the face mesh and the Face File. If your phone is signed in to iCloud, the backup copy of your Face File in your private iCloud database remains until you use “Delete everything”, which removes it too. Server-side records are limited to your entitlement status, your device attestation key, weekly usage counters and the one-time drawing record — none of which contain your photograph, your face geometry or any measurement — kept for as long as necessary to provide and protect the service or as required by law. You can ask us to delete the server-side data associated with your install.

6. Your rights

Because we operate from Norway, which is in the EEA, the GDPR applies. Subject to its conditions, you have the right to:

To exercise any of these, email us at the address below. You can control camera access in iOS Settings, manage tracking permission under Privacy & Security > Tracking, and manage or cancel subscriptions in your Apple ID settings. Removing the app deletes your on-device Face File.

7. Security

We use industry-standard measures including encryption in transit, scoped access, hardware app-integrity checks and rate limiting. On your device, your photograph, face mesh and Face File are stored with iOS file encryption. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. The strongest protection for your photograph is that on our side it is never written down anywhere.

8. Children

Embla is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it promptly.

9. International transfers

Our providers may process data in countries outside the EEA, including the United States. Where this happens we rely on appropriate safeguards, such as the EU Standard Contractual Clauses or an adequacy decision, as required by law.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, noted in the app.

11. Contact

For any privacy question, or to exercise your rights, contact the data controller:

Kilter Digital (enkeltpersonforetak)
Org. no. 936 936 768
Kong Haralds gate 46A, 4041 Hafrsfjord, Norway
Email: fk.apps.customer@gmail.com