Chevoire — Privacy Policy
Version 1.4 — 8 August 2026
1. Who is responsible for your data
Chevoire is a hair-passport app. A barber or stylist photographs a finished haircut and records a short voice note explaining what they did; the client owns that record and can carry it to any other barber. The app also books appointments.
The controller of the personal data described here is Chevoire, the operator of the Chevoire app and of the Chevoire API.
Privacy contact: privacy@chevoire.com. We answer privacy requests from this address.
2. The people this policy covers
- Clients — people who own a hair passport.
- Stylists / barbers — people who capture styles and manage appointments.
- People photographed by a stylist. A stylist captures photos, video and voice notes of the person in the chair. If you are that person, this policy covers you even if the capture happened on the stylist's device. A stylist may only capture and upload media of someone who has agreed to it, and by uploading, the stylist confirms they have that person's consent (and, for a minor, a parent's or guardian's consent).
3. What we collect, and why
Account and sign-in data
| Data | Why |
|---|
| Email address | To identify your account, sign you in, and send account-security messages such as password-reset links |
| Unique username | Your public account name. A stylist can use the exact username to find you and send a connection request |
| Full name | Shown on your passport and to the stylists you work with |
| Password (email sign-in only) | Stored only as a bcrypt hash. We never store or see your password itself |
| Apple or Google account identifier (social sign-in only) | To recognise the same social account when you sign in again. We also receive the verified email address and any name you choose to share |
| Push-notification token and device platform (after permission) | So Apple or Google can deliver booking alerts to that device |
| City (optional) | Shown on passport entries so you can tell where a style was done |
| Salon name (stylist accounts, optional) | Shown to clients so they know who created an entry |
| Role (client or stylist) | Decides which part of the app you see |
| Account creation date | Account administration |
| Password-reset token digest, expiry and use time | To provide a one-time password-recovery link without storing the secret link itself |
Passport and session data — created when a style is recorded
| Data | Why |
|---|
| Photos of your hair, head and face (front, back, left, right) | They are the record of the haircut — the whole point of the passport |
| Short technique video (up to 30 seconds) | Shows the stylist's method so it can be repeated |
| Voice notes recorded by the stylist | The spoken explanation of what was done |
| Written notes, colour formula, per-zone specs (e.g. guard numbers) | The "recipe" a future stylist needs |
| Style name, category, salon name, city, date performed | Organises your history |
| Transcript of a voice note, if transcription is used (see section 5) | Makes a voice note searchable and readable |
| Session duration and status | Lets the stylist finish and publish a session |
Booking data
| Data | Why |
|---|
| Appointment date, time, duration, service name, optional note, status | To make and manage the booking between you and your stylist |
Relationship and sharing data
| Data | Why |
|---|
| The link between a stylist account and a client account, plus an optional note the stylist writes | So a stylist can publish to the right client's passport |
| Share codes you create, the access level you chose, the expiry date, and whether you revoked it | So you can show your passport to a new barber and take that access away again |
| Your account's internal ID (a random UUID) | Used internally to address your records and your media files |
A username search returns only the matching person's public identity card: name, username and profile image, plus salon and city for a stylist. It never grants passport access. A stylist searching for a client creates a pending request that the client must accept. A client scanning a stylist's salon QR or entering the stylist's username sees the identity card and must confirm before the connection becomes active.
Signing in with Apple or Google. If you choose one of these buttons, that provider confirms your identity to Chevoire and sends us a provider-specific account identifier, your verified email address (which may be an Apple private-relay address), and your name if you choose to share it. Chevoire does not receive your Apple or Google password.
What we do not collect
- We use no analytics, advertising or attribution SDK. There is no tracking of you across apps or websites, and no advertising identifier is read. Chevoire does not track you.
- We do not ask for your location. The app requests no location permission; the only location data is the city text you or your stylist type in.
- We do not read your contacts, your photo library at large (only the specific photo you pick), your browsing history, or your health records. Chevoire does not use HealthKit.
- We do not collect payment data. There are no purchases in the app.
- The app sends no crash or performance reports to us.
- Our server keeps short technical logs of each request (a request ID, the HTTP method, the path without its query string, and the response status). Our managed hosting provider also keeps platform logs, which can include IP addresses. These logs exist to keep the service running and to investigate abuse.
Demo mode. If you open the app without signing in, you see a demo passport built from stock photography and invented example content. Nothing you do in demo mode is uploaded and no account exists.
4. Permissions the app asks for
- Camera — to take the style photos and the technique video.
- Microphone — to record voice notes.
- Photo library — only when you choose to add a photo yourself; we receive only the photo you select.
- Notifications — optional, to alert a stylist about a new booking request and a client when the booking status changes.
You can refuse or later revoke any of these in your device settings. Refusing the camera or microphone means those capture features stop working. Booking still works without notifications, but you must open the app to see updates.
5. Voice notes and machine transcription (third parties)
Voice notes are audio recordings of a human voice. They often name the client and discuss their hair or scalp, so we treat them as sensitive.
Voice transcription is off by default. If you enable it in Account → AI & voice notes, a linked stylist can ask Chevoire to send a voice note to a hosted transcription service to return text. The recording leaves our server and may be processed outside your country. Chevoire blocks the request unless the client who owns that session has a current consent record.
Consent is optional and can be withdrawn from the same account screen. Turning it off blocks future audio transfers. Text already saved into a passport remains part of that record until the related record or account is deleted.
Chevoire configures the service not to store the interaction for product improvement. The service may retain limited security logs to detect abuse and meet legal duties.
We do not use your photos, video, voice or notes to train machine-learning models.
6. Where your data is stored
- Database — a managed database holds the account, passport, booking and sharing records described in section 3, but no media files.
- Media files — photos, video and voice notes are stored in private managed storage, separated by account, and are served only over an authenticated endpoint.
- Region — the API, database and media volume currently run in Singapore. If you use Chevoire from another country, those records are transferred to and processed in Singapore. We will use any transfer safeguards required by the law that applies to you.
- On your device — captured media is written to the app's private storage on the phone before and after upload. Your sign-in token uses secure device storage where available, with a private app-storage fallback if secure storage is temporarily unavailable. Deleting the app removes both.
- Transactional email — a transactional email provider delivers password-reset messages and booking-request alerts. It receives the destination address and the message being delivered. A booking email includes the client's display name, service, date and time, duration, and any booking note the client chose to add.
- Push delivery — Apple and Google notification services, together with our notification gateway, process a device push token and a short booking alert. Push alerts contain a booking identifier and status but never include the optional booking note.
Our managed hosting, transactional email and notification-delivery providers process data for us. Apple and Google process sign-in data when you choose their buttons and notification-delivery data when you enable alerts. The transcription provider described in section 5 is an additional processor only when that feature is enabled and you choose to use it.
7. Who your data is shared with
- The stylists you are linked to. A stylist you are linked with can create passport entries for you and see the entries and appointments that concern you.
- Anyone you give a share link or share code to. You choose the access level (full record, photos only, or a reference card) and when it expires; you can revoke it.
- Our processors — managed hosting, transactional email and notification-delivery providers; Apple or Google when you choose social sign-in or enable alerts; and the transcription provider in section 5 if and when it is enabled.
- Nobody else. We do not sell your data, we do not share it with advertisers or data brokers, and there is no third-party analytics in the app.
- Legal requests. We would disclose data if we were legally required to, and only to the extent required.
8. How long we keep it
- Account data, passport entries, session media, appointments, stylist links and share links are kept while your account exists, because your passport is meant to be a long-term record you keep.
- Share links stop working at the expiry date you chose (up to 90 days) or as soon as you revoke them. The row itself is removed with your account.
- Sign-in tokens expire 30 days after they are issued.
- Password-reset links expire after 30 minutes and stop working immediately after use.
- An unfinished social-signup registration record expires after 7 days.
- A device push token is kept while that device is registered for your account. Chevoire asks the server to remove it when you sign out, disables it if the notification provider reports that it is no longer valid, and deletes it with your account.
- Server request logs are short-lived operational logs; platform logs follow our hosting provider's retention schedule.
- When you delete your account, everything above is deleted as described in section 9.
9. Your rights, and how to exercise them
- Delete your account and your data — in the app. Open your account screen and choose Delete account. This immediately deletes your account record and, with it, your style entries, sessions, media records, appointment records, stylist links and share links, sign-in identities and unfinished registration records, and it deletes your uploaded photo, video and audio files from our storage volume. If you used Sign in with Apple, Chevoire also asks Apple to revoke the app's authorisation when possible. Deletion is permanent; we cannot restore a deleted passport.
- Get a copy of your data. Email privacy@chevoire.com from your account's email address and we will send you your account data, your passport entries and your media files.
- Correct your data. Ask us, or ask the stylist who wrote an entry, to fix it.
- Withdraw consent. Stop using the capture features, revoke camera and microphone access in iOS Settings, revoke your share links, or delete your account. If you were photographed by a stylist and want that media removed, email us with enough detail to find it and we will delete it.
- Object or complain. Write to privacy@chevoire.com. If you are in the EU/EEA or the UK, you also have the right to complain to your data protection authority.
Our legal bases, where the GDPR applies: performing the contract with you (running your account, your passport and your bookings), your consent (camera, microphone and photo access; capturing your image and voice; sharing your passport with someone else), and our legitimate interest in keeping the service secure and working.
10. Children
Chevoire accounts are for people aged 16 and over. We do not knowingly create accounts for younger users, and the app has no content aimed at children.
Barbers do cut children's hair. A stylist must not capture or upload photos, video or voice of a child without the agreement of that child's parent or guardian. If you are a parent or guardian and believe media of your child is in Chevoire, email privacy@chevoire.com and we will delete it.
11. Security — and its limits
What we do:
- Email-sign-in passwords are stored only as bcrypt hashes (cost 12); we never store the password. We never receive your Apple or Google password.
- Provider credentials needed to revoke a social sign-in authorisation are encrypted at rest and are removed with the account.
- Password-reset secrets are stored only as SHA-256 digests, are single-use and expire after 30 minutes. Changing or resetting a password invalidates older signed-in sessions.
- All traffic between the app and our API is over HTTPS/TLS.
- Requests are authenticated with a signed token; media files live under a per-account folder and are served only to a request that is entitled to them.
- Sign-in and registration attempts are rate limited.
- Uploads are limited in type and size, with a per-account storage ceiling.
What we do not claim:
- We do not apply our own encryption to media files at rest; they rely on the disk encryption our hosting provider provides.
- No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority as required by law.
12. Changes to this policy
If we change what we collect, why, or who we share it with, we will update this policy, change the version and date at the top, and update the copy inside the app. Significant changes will be announced in the app before they take effect.
Questions: privacy@chevoire.com