Last updated: August 6, 2026
1. Data controller
NOVEXA STUDIO - FZCO (trade license No. 90184, issued by the Dubai Integrated Economic Zones Authority), registered office at DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai (United Arab Emirates). Full contact details: see Legal Notice.
NOVEXA STUDIO - FZCO acts as data controller within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679 (GDPR) for users located in the European Union and the European Economic Area, and within the meaning of UAE Federal Law No. 45 of 2021 (PDPL) for all other users. Because PeakMe is offered to users in the EU/EEA, the GDPR applies extraterritorially under its Article 3(2); the UK GDPR applies on the same terms to users in the United Kingdom.
Privacy contact / requests: via the contact form, which is monitored by the person responsible for data protection matters within the company. We are not required to appoint a Data Protection Officer under Article 37 GDPR (no large-scale monitoring, no processing of special categories as a core activity), but this channel fulfils the same practical function.
EU/UK representative (Art. 27 GDPR): where an Article 27 representative is required, the designated representative's identity and contact details are provided on written request via the contact form. Until such designation is published here, requests addressed to the contact form are treated with the same effect.
2. Data collected
- Account: email address, password (hashed, never in plain text), account creation and login timestamps.
- Glow-up / AI input: the photo you submit, your age range, gender, stated goal and quiz answers.
- AI output: the generated analysis, scores, transformed photo, 30-day plan, barber brief, routines, workout plan.
- Usage: daily progress, tasks completed, generations performed.
- Billing: subscription status, plan, payment history. We never receive or store your card number — it is handled solely by Stripe.
- Technical: IP address, user agent, device type, anonymised or short-lived server logs, security and consent logs (record of acceptance of the Terms, with timestamp and IP, as evidence).
- Support: the content of your messages and any photo or video you voluntarily attach as proof.
We do not knowingly collect data from persons under 18. If you believe a minor has created an account, contact us and the account and its photos will be deleted without delay.
3. Purposes and legal bases
For users in the EU/EEA/UK, each processing operation relies on a legal basis under Article 6(1) GDPR. For all other users, the equivalent legal bases of the UAE PDPL apply.
- Providing the service — AI analysis, photo transformation, personalised plan, progress tracking, account management, customer support. Basis: performance of a contract, Art. 6(1)(b).
- Processing your photo through AI — see article 5. Basis: performance of a contract, Art. 6(1)(b); additionally your explicit consent, Art. 9(2)(a), to the extent any part of the analysis could be regarded as revealing data of a special category. Consent is given by an unticked-by-default action before upload and can be withdrawn at any time.
- Billing, accounting, tax and anti-fraud — invoices, dispute and chargeback handling, detection of abusive use. Basis: legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f).
- Security and service integrity — logs, abuse detection, protection against attacks. Basis: legitimate interests, Art. 6(1)(f).
- Product improvement — aggregated or anonymised statistics only. Basis: legitimate interests, Art. 6(1)(f). Your photos are never used for this purpose.
- Transactional emails (account, payment, support). Basis: performance of a contract, Art. 6(1)(b). Marketing emails, if any, are sent only with your prior consent, Art. 6(1)(a), and every message contains an unsubscribe link.
- Establishing, exercising or defending legal claims — consent logs, payment records, support history. Basis: legitimate interests, Art. 6(1)(f), and Art. 9(2)(f) where relevant.
Where we rely on legitimate interests, we have carried out a balancing assessment; you may object at any time under Article 21 GDPR via the contact form.
4. Automated decision-making and profiling
PeakMe generates an automated aesthetic analysis of the photo you submit and derives a personalised plan from it. This is automated processing of a purely informational and inspirational nature: it produces no legal effect and no similarly significant effect on you within the meaning of Article 22(1) GDPR. It is not used for credit scoring, employment, insurance, access to a service, pricing personalisation, or any decision affecting your rights.
Logic involved: a general-purpose multimodal AI model receives your photo and your declared answers and returns a descriptive text analysis, indicative scores and recommendations, plus an illustrative transformed image. Scores are heuristic and non-scientific. Significance and consequences: the output is a suggestion; you decide freely whether to follow it. You may ask a human to review any result, express your point of view and contest it via the contact form.
5. Photos and AI processing — specific safeguards
Your photo is used only to generate your analysis and your transformed photo. It is:
- never used to train any AI model, ours or a third party's;
- never sold, rented, shared with advertising networks or used for advertising;
- never reviewed manually in the ordinary course of the service — access is possible only at your explicit request (e.g. to diagnose a bug you reported) or under a legal obligation;
- transmitted to our AI providers under contractual terms that prohibit training on customer data and require deletion after processing;
- stored encrypted at rest, accessible only from your authenticated account.
No biometric identification. PeakMe does not create a biometric template, does not perform facial recognition, does not attempt to identify or authenticate anyone from a face, does not build a face database, and does not perform emotion inference or biometric categorisation. The photo is processed as an ordinary image for aesthetic description. We therefore do not process biometric data "for the purpose of uniquely identifying a natural person" within the meaning of Article 9(1) GDPR. Where you nonetheless wish to rely on the highest standard of protection, we additionally obtain your explicit consent before any upload.
You can delete your photo and all associated results at any time from your account ("Delete my account") or via the contact form. Deletion is effective without undue delay.
6. Sub-processors and recipients
We use the following categories of processors (Art. 28 GDPR), each bound by a data processing agreement imposing confidentiality, security and deletion obligations, and prohibiting any use of your data for their own purposes:
- Hosting / CDN / security: Cloudflare, Inc. (USA/EU edge).
- Database, storage and authentication: Supabase (PostgreSQL, EU/US regions).
- AI processing: OpenAI and Google (Vertex / Gemini), accessed through the Lovable AI gateway, on zero-retention / no-training terms for API customer data.
- Payment: Stripe, acting as Merchant of Record — collects payment, calculates and remits applicable taxes, issues invoices, handles refunds and disputes. Stripe is an independent controller for its own compliance purposes. The bank statement descriptor is NOVEXA STUDIO (or a shortened form such as "NOVEXA" or "NOVEXA STU").
- Transactional email: our sending infrastructure on
notify.peakme.io(SPF/DKIM/DMARC).
We may also disclose data to competent authorities where required by a valid legal obligation, and to advisers or an acquirer in the context of a corporate transaction, subject to equivalent protection.
7. International transfers
PeakMe is operated from the United Arab Emirates and relies on providers located in the United States and elsewhere. Transfers of personal data outside the EEA are therefore necessary to provide the service. They are framed by:
- the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), incorporated into our agreements with Cloudflare, Supabase, Stripe, OpenAI and Google;
- where applicable, the EU–US Data Privacy Framework certification of the provider concerned;
- supplementary technical measures: TLS encryption in transit, encryption at rest, access restricted to authenticated accounts, data minimisation, short retention of the original photo;
- for transfers to the UAE, Article 46 GDPR safeguards (SCCs concluded with the controller entity) and, where relevant, the derogation of Article 49(1)(b) (transfer necessary for the performance of the contract you request).
A copy of the relevant safeguards can be requested via the contact form.
8. Retention periods
- Original uploaded photo: 30 days, then automatic deletion.
- Generated result (analysis, plan, transformed image): 12 months after your last activity, or immediately on your deletion request.
- Account data: for the life of the account, then deleted within 30 days of closure.
- Support messages and proof files: 24 months (dispute-handling window).
- Consent and acceptance logs: 5 years (evidence of contract formation).
- Billing and accounting records: the statutory retention period applicable in each jurisdiction (typically 5 to 10 years).
- Technical/security logs: 12 months maximum.
9. Your rights
Under Articles 15 to 22 GDPR (and the equivalent rights under the PDPL and other applicable laws), you have the right to:
- access your data and obtain a copy (Art. 15);
- rectify inaccurate data (Art. 16);
- erase your data (Art. 17) — available in one click from your account;
- restrict processing (Art. 18);
- data portability in a structured, machine-readable format (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- not be subject to a solely automated decision producing legal or similarly significant effects, and to obtain human intervention (Art. 22) — see article 4;
- withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand (Art. 7(3));
- define directives concerning the fate of your data after your death, where your national law provides for it.
Exercise these rights via the contact form. We reply within one month, extendable by two months for complex requests (Art. 12(3)). Identity verification may be requested where there is reasonable doubt.
Right to lodge a complaint: if you consider that your rights are not respected, you may lodge a complaint with the supervisory authority of your EU Member State of residence, place of work or place of the alleged infringement (Art. 77 GDPR) — for example the CNIL in France (www.cnil.fr) — with the ICO in the United Kingdom, or with the UAE Data Office under the PDPL. You also have a right to an effective judicial remedy (Art. 79).
10. Security
Measures implemented under Article 32 GDPR: HTTPS/TLS encryption in transit, encryption at rest with our providers, passwords hashed (bcrypt/argon2), signed and revocable sessions, PostgreSQL Row-Level Security so each user can only reach their own rows, private storage buckets with short-lived signed URLs, least-privilege access, and logging of sensitive operations. No system is infallible; in the event of a personal data breach likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours (Art. 33) and inform affected users without undue delay where the risk is high (Art. 34).
11. Cookies and analytics
We use only strictly necessary cookies for the operation of the service (session, security, preferences). Under Article 5(3) of the ePrivacy Directive, such cookies are exempt from consent.
No advertising cookies, no analytics cookies, no third-party tracking pixels (TikTok, Meta, Google Ads, etc.) are placed on your device, and we share no data with advertising networks. Our occasional advertising campaigns are delivered without targeting based on your on-site behaviour and without browser-side conversion tracking: that is why no cookie consent banner is displayed. Should this ever change, a compliant consent banner would be deployed before any non-essential cookie is set.
12. Changes to this policy
This policy may be updated to reflect changes in the service or the law. The date of the last update appears at the top of the page; material changes are notified by email or in-app before they take effect.