Chevoire

Hair passport

Chevoire — Privacy Policy

Version 1.4 — 8 August 2026


1. Who is responsible for your data

Chevoire is a hair-passport app. A barber or stylist photographs a finished haircut and records a short voice note explaining what they did; the client owns that record and can carry it to any other barber. The app also books appointments.

The controller of the personal data described here is Chevoire, the operator of the Chevoire app and of the Chevoire API.

Privacy contact: privacy@chevoire.com. We answer privacy requests from this address.

2. The people this policy covers

3. What we collect, and why

Account and sign-in data

DataWhy
Email addressTo identify your account, sign you in, and send account-security messages such as password-reset links
Unique usernameYour public account name. A stylist can use the exact username to find you and send a connection request
Full nameShown on your passport and to the stylists you work with
Password (email sign-in only)Stored only as a bcrypt hash. We never store or see your password itself
Apple or Google account identifier (social sign-in only)To recognise the same social account when you sign in again. We also receive the verified email address and any name you choose to share
Push-notification token and device platform (after permission)So Apple or Google can deliver booking alerts to that device
City (optional)Shown on passport entries so you can tell where a style was done
Salon name (stylist accounts, optional)Shown to clients so they know who created an entry
Role (client or stylist)Decides which part of the app you see
Account creation dateAccount administration
Password-reset token digest, expiry and use timeTo provide a one-time password-recovery link without storing the secret link itself

Passport and session data — created when a style is recorded

DataWhy
Photos of your hair, head and face (front, back, left, right)They are the record of the haircut — the whole point of the passport
Short technique video (up to 30 seconds)Shows the stylist's method so it can be repeated
Voice notes recorded by the stylistThe spoken explanation of what was done
Written notes, colour formula, per-zone specs (e.g. guard numbers)The "recipe" a future stylist needs
Style name, category, salon name, city, date performedOrganises your history
Transcript of a voice note, if transcription is used (see section 5)Makes a voice note searchable and readable
Session duration and statusLets the stylist finish and publish a session

Booking data

DataWhy
Appointment date, time, duration, service name, optional note, statusTo make and manage the booking between you and your stylist

Relationship and sharing data

DataWhy
The link between a stylist account and a client account, plus an optional note the stylist writesSo a stylist can publish to the right client's passport
Share codes you create, the access level you chose, the expiry date, and whether you revoked itSo you can show your passport to a new barber and take that access away again
Your account's internal ID (a random UUID)Used internally to address your records and your media files

A username search returns only the matching person's public identity card: name, username and profile image, plus salon and city for a stylist. It never grants passport access. A stylist searching for a client creates a pending request that the client must accept. A client scanning a stylist's salon QR or entering the stylist's username sees the identity card and must confirm before the connection becomes active.

Signing in with Apple or Google. If you choose one of these buttons, that provider confirms your identity to Chevoire and sends us a provider-specific account identifier, your verified email address (which may be an Apple private-relay address), and your name if you choose to share it. Chevoire does not receive your Apple or Google password.

What we do not collect

Demo mode. If you open the app without signing in, you see a demo passport built from stock photography and invented example content. Nothing you do in demo mode is uploaded and no account exists.

4. Permissions the app asks for

You can refuse or later revoke any of these in your device settings. Refusing the camera or microphone means those capture features stop working. Booking still works without notifications, but you must open the app to see updates.

5. Voice notes and machine transcription (third parties)

Voice notes are audio recordings of a human voice. They often name the client and discuss their hair or scalp, so we treat them as sensitive.

Voice transcription is off by default. If you enable it in Account → AI & voice notes, a linked stylist can ask Chevoire to send a voice note to a hosted transcription service to return text. The recording leaves our server and may be processed outside your country. Chevoire blocks the request unless the client who owns that session has a current consent record.

Consent is optional and can be withdrawn from the same account screen. Turning it off blocks future audio transfers. Text already saved into a passport remains part of that record until the related record or account is deleted.

Chevoire configures the service not to store the interaction for product improvement. The service may retain limited security logs to detect abuse and meet legal duties.

We do not use your photos, video, voice or notes to train machine-learning models.

6. Where your data is stored

Our managed hosting, transactional email and notification-delivery providers process data for us. Apple and Google process sign-in data when you choose their buttons and notification-delivery data when you enable alerts. The transcription provider described in section 5 is an additional processor only when that feature is enabled and you choose to use it.

7. Who your data is shared with

8. How long we keep it

9. Your rights, and how to exercise them

Our legal bases, where the GDPR applies: performing the contract with you (running your account, your passport and your bookings), your consent (camera, microphone and photo access; capturing your image and voice; sharing your passport with someone else), and our legitimate interest in keeping the service secure and working.

10. Children

Chevoire accounts are for people aged 16 and over. We do not knowingly create accounts for younger users, and the app has no content aimed at children.

Barbers do cut children's hair. A stylist must not capture or upload photos, video or voice of a child without the agreement of that child's parent or guardian. If you are a parent or guardian and believe media of your child is in Chevoire, email privacy@chevoire.com and we will delete it.

11. Security — and its limits

What we do:

What we do not claim:

12. Changes to this policy

If we change what we collect, why, or who we share it with, we will update this policy, change the version and date at the top, and update the copy inside the app. Significant changes will be announced in the app before they take effect.


Questions: privacy@chevoire.com

Served from the copy compiled into the Chevoire API. The canonical source is PRIVACY.md in the app repository; if the two ever differ, that file is the authority.