Privacy Policy
Last updated: July 3, 2026
Your face photos are stored only on your device — never on our servers. For analysis, a photo is read transiently and immediately discarded from our systems; it's never sold and never used to train AI. You can use Porio without creating an account, and you can delete everything, in the app, at any time.
This Privacy Policy explains how Porio ("Porio", "we", "us") collects, uses, and protects your information when you use our mobile app and website. Porio is operated from Victoria, Australia and complies with the Australian Privacy Principles under the Privacy Act 1988 (Cth). By using Porio, you agree to this policy.
01Your photo
Porio's core feature analyses a photo of your face. When you take a scan:
- A copy of your photo is saved on your device only, so you can view your photos by the date you took them and see your skin change over time. These photos never leave your phone except as described below, and are removed when you delete your scan history, your account, or the app.
- For analysis, the photo is encrypted in transit and sent to our secure backend, which forwards it to our AI provider. Server-side, it is processed transiently and immediately discarded — never written to storage by Porio, never shared beyond the analysis, never sold, and never used to train AI models.
- Server-side, only the result of the analysis is kept — your six skin signals (hydration, blemishes, texture, pores, redness, dark spots) and related scan metadata — so your history syncs with your reads.
Because facial images can be treated as sensitive information under privacy law, we designed Porio so that our servers simply don't hold them — your photos stay in your hands, on your device.
02Information we collect
| Data | What it is | Kept? |
|---|---|---|
| Face photos | The selfie you submit for a scan, and your dated photo timeline | On your device only — servers process transiently, then discard |
| Skin signals | Your scan results and scan history | Yes, linked to a pseudonymous user ID, until you delete them |
| Skin profile | Answers you give in onboarding (e.g. skin type, oiliness, goals) | Yes, until you delete them |
| Routine data | Your skincare routine and check-ins | Stored on your device |
| Account data | Nothing by default. If you optionally sign in with Apple or Google: your email and sign-in identifier | Yes, until you delete your account |
| Purchase data | Subscription status and purchase metadata (never your card details) | Yes, while your subscription is relevant |
| Diagnostics & usage | Crash logs, device type, app version, and in-app events (e.g. "scan completed") | Yes, in aggregate/pseudonymous form |
| Waitlist email | Only if you join the website waitlist | Until launch communications end or you unsubscribe |
Anonymous by default.Porio doesn't require an account. When you first open the app we create a pseudonymous user ID so your results stay yours. If you later sign in with Apple or Google, that same ID is linked to your sign-in — nothing else changes.
03How we use information
We use your information to provide your skin analysis and routine, personalise guidance to your skin profile, operate subscriptions, keep the app secure and working (including preventing abuse of our AI systems), communicate with you about the service, and comply with legal obligations. We do not use your photos or data for advertising, and we do not sell personal information.
04AI processing
Skin analysis and coaching are performed using Google's Gemini models via Google Cloud Vertex AI, accessed exclusively through our secure backend hosted on Supabase — the app never sends your photo directly to any AI provider.
- Processing occurs in a fixed cloud region and your photo is used solely to return your result.
- Under Google Cloud's Vertex AI terms, customer data is not used to train Google's models.
- Neither Porio, Google Cloud, nor Supabase retains your photo after the analysis completes.
05Not medical data
Porio provides a beauty observation, not a medical diagnosis, and does not knowingly collect medical records or protected health information. Results are informational only. If a scan surfaces something that could be medical, Porio will suggest seeing a dermatologist rather than analysing it.
06Who we share with
We share information only with the service providers that operate Porio, under confidentiality obligations, or where required by law:
- Google Cloud (Vertex AI) — transient AI analysis of your photo and coaching requests.
- Supabase — backend, database, and authentication.
- Apple App Store / Google Play — payment processing for subscriptions (we never see your card details).
- RevenueCat — subscription management and purchase metadata.
- Crash reporting and analytics providers — pseudonymous diagnostics and usage events; never your photos.
We do not sell your personal information, and we have no advertising or data-broker relationships.
07Data retention & deletion
- Photos: never retained on our servers — discarded when your scan completes. The copies in your on-device photo timeline are under your control and are removed when you delete your scan history, your account, or the app.
- Skin signals, profile, and account data: retained until you delete them. You can delete your scan history or your entire account and data directly in the app (Settings → Delete account), or by request — see our Data & deletion page.
- Waitlist emails: deleted after launch communications or on request.
- Diagnostics: retained for a limited period, then deleted or aggregated.
08Where your data is processed
Our backend and AI processing run in fixed cloud regions outside Australia. Where information is transferred internationally, we take reasonable steps to ensure it is handled consistently with this policy and applicable law.
09Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing:
- Australia: rights under the Privacy Act 1988 and the Australian Privacy Principles, including access and correction. Complaints can be made to us first, and to the OAIC.
- EU/UK (GDPR): rights of access, rectification, erasure, portability, restriction, and objection. Our lawful bases are performance of a contract (providing the service), legitimate interests (security, improvement), and consent where required (e.g. processing your photo).
- California (CCPA/CPRA): rights to know, delete, and correct. We do not sell or share personal information as defined by the CPRA.
To exercise any right, use the in-app deletion tools or contact porio.app@gmail.com. We respond within 30 days.
10Security
All data is encrypted in transit. Access to our systems is restricted and authenticated, and our backend verifies your identity and entitlement on every request. No system is perfectly secure, but not storing your photos removes the most sensitive risk entirely.
11Children
Porio is not intended for anyone under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has used Porio, contact us and we will delete the associated data.
12Changes
We may update this policy from time to time. Material changes will be notified in the app or by email where appropriate, and always reflected in the date above.
13Contact
Privacy questions or requests: porio.app@gmail.com
Porio, Victoria, Australia.