Privacy Policy
The short version: one processor sees your photo just long enough to score it. We don't know who you are, and we like it that way.
Your permission
Before your first scan uploads anything, Crown asks for your explicit permission and names exactly what is shared and with whom. The question comes when you start a scan, before the camera opens. You can decline — no scan photo or scan context leaves your device without it. You can withdraw permission at any time in Settings → AI processing consent; scanning stops until you allow it again.
One thing happens before that question is asked, and you should know the order. When you open Crown, the app registers its anonymous identifier with Crown's server and checks with Apple that it is running on a real device, so it can tell you whether a scan is available. No photo and no scan context is sent at that point. What is sent, and what Apple records as a result, is described under Device authenticity signals below.
What Crown collects and shares
- Photos you scan. With your permission, your photo is sent over an encrypted connection through Crown's server to our AI processor, Anthropic, which analyzes it to produce your Hair Score and returns the result. Crown's servers do not store your photos. Anthropic processes them transiently under enterprise data-handling terms that prohibit using your images to train AI models.
- Scan context. Three onboarding answers — your age band, your stated concern, and your goal — are sent with each scan so the analysis and outlook can be personalized. They are not stored on Crown's servers beyond processing. Along with the photo, they are folded into the one-way request fingerprint in the table below, which Crown keeps for 7 days so a retried scan is not charged twice.
- Scan results. Hair Scores, zone scores, metrics, and scan dates are stored only on your device. Delete them anytime in Settings → Erase all Crown data. Deleting the app deletes them permanently — we never had them.
- An anonymous device identity. A random identifier manages your free scan and subscription status. It contains no personal information and we cannot link it to your name, email, or Apple ID.
- Hosting. Crown's server runs on Cloudflare. Every request to Crown passes through Cloudflare, and every server-side record described below is stored by Cloudflare on Crown's behalf.
- A registration abuse-prevention signal. Crown uses the IP address Cloudflare provides with a registration request only to enforce an hourly rate limit. The limiter stores a keyed one-way hash of that address — for IPv6, of the network prefix rather than the exact address — with an hourly count; it is not used for location, advertising, or analytics.
- Device authenticity signals, and a permanent per-device marker. When you open Crown, Apple's DeviceCheck confirms the request comes from a real Apple device. Crown also uses the two bits Apple stores against that device: once your free scan has been delivered, Crown sets one of them to record that this device's free scan is spent. That marker is held by Apple, not by Crown, and it is permanent in a way nothing else here is — it survives deleting the app, reinstalling it, erasing all Crown data, wiping your keychain, and deleting your server records. Only erasing the device itself clears it. It holds that one fact and nothing else; Crown cannot read it without a token generated on your device, and cannot enumerate or search devices with it. It is what keeps the free scan to one per device rather than one per reinstall. Apple's processing is governed by Apple's terms.
What we keep, and for how long
| Data | Where | Kept for |
|---|---|---|
| Photos | Crown servers: not stored. Anthropic: transient processing | Moments, then discarded |
| Scan request markers (includes a cryptographic fingerprint of the request, not the photo itself) | Crown servers | 7 days |
| Anonymous auth token mapping | Crown servers | 180 days |
| Device-authenticity token (used to read and set the marker described above) | Crown servers | 180 days |
| Free-scan-used marker for this device | Apple, against your device | Until the device is erased. Crown cannot remove it |
| Registration rate-limit data | Crown servers | Current keyed hash/count: until the UTC hour ends. Legacy raw-IP bucket: up to 2 hours |
| Free-scan-used flag (anonymous ID only) | Crown servers | Retained to keep the free scan one-per-person |
| Free-scan deletion tombstone (one-way) | Crown servers | Retained indefinitely, if you erase your data after using a scan |
| Scan quota counters (anonymous ID only) | Crown servers | Daily counters: up to 2 days; monthly counters: up to 40 days |
| AI-analysis counters (anonymous ID only) | Crown servers | Hourly: 1 hour; daily: up to 2 days; monthly: up to 40 days. A lifetime count of free analyses is retained |
| Subscription entitlement cache (anonymous ID only) | Crown servers | Up to 24 hours |
| Leftover records from an earlier version of Crown (anonymous ID only) | Crown servers | No expiry in code; they stay until you erase your Crown data |
| Scan results & history | Your device only | Until you delete them |
Settings → Erase all Crown data removes everything Crown has put on this iPhone: your scan results, the scans still awaiting confirmation, your three answers, your AI-processing permission record, your reminder settings, and the anonymous identifier itself — which otherwise survives deleting the app. Crown then reopens as if it were newly installed. Photos are not on that list because Crown never wrote one to your disk in the first place.
Server records are keyed by your anonymous Support ID and contain no photos, name, email, or Apple ID. Registration rate-limit data is keyed separately by a keyed hash of a network address and cannot be located from that Support ID. These records expire on the schedules listed above.
You can also see them and delete them, from inside the app. Settings → Your data shows what is on this iPhone and the accounting record Crown's server keeps under your anonymous ID — how many scans you have left and whether the free one is spent — and lets you copy it. Erasing your Crown data also asks Crown's server to erase its side, which removes your scan markers, quota counters, AI-analysis counters, entitlement cache, stored device-authenticity token, and access token. If that request cannot get through — you are offline, or the server is down — the erase on your iPhone still completes, but the server records are left to expire on the schedules above, and once your iPhone has minted a new identifier Crown can no longer reach them on your behalf.
Two things deliberately survive deletion. One is a one-way token derived from your anonymous identifier. It records that the free scan is spent and, if you had already used scans in the current day or month, that those periods are used up — so erasing does not hand back an allowance you had already spent. It cannot be reversed to that identifier and it holds no record of how many scans you ran. The other is the marker Apple stores against your device, described above. Without them, deleting and re-registering would hand out unlimited free scans and reset the paid scan limit every time. Deleting your data does not restore the free scan.
Questions can be sent to [email protected]; you may include the Support ID shown in Settings. One caveat, stated plainly: a Support ID names your records but does not open them. The only key is the access token held by your copy of the app, and Crown has deliberately not built a way around that — so support will point you back to Settings → Your data rather than read or delete anything for you.
What Crown does NOT collect
No name, no email, no account, no password, no phone number, no precise location, no contacts, no advertising identifier, and no analytics profile of your face or body. Crown has no named user-account database. Crown and RevenueCat do keep aggregate subscription analytics — how many people subscribe, renew, or cancel — tied only to the anonymous identifier.
Subscriptions
Purchases are processed by Apple. Crown uses RevenueCat to tell whether a subscription is active: RevenueCat receives your anonymous identifier and your purchase records from Apple, both from the app and from Crown's server, which asks RevenueCat about your subscription when you scan. Crown never receives your payment details or your identity. RevenueCat processes this data on Crown's behalf under its data-processing terms.
Health disclaimer
Crown provides wellness insights, not medical advice. Scores are informational estimates from photos and are not a medical assessment of any kind.
Age
Crown is intended for users 17 and older.
Changes & contact
We'll update this policy here if practices change. Questions: [email protected].