Privacy & biometric data.
Last updated August 2026 · applies to Callume at callume.com.
The short version: your photos are uploaded to one server we run, analyzed there, and then deleted, along with the face-geometry scan taken from them. The free read wipes your selfies the moment it finishes; for a full session your uploaded photos and their geometry are gone within 72 hours, and only your styling read and your PDF are kept so you can re-download them (up to a year, or until you delete the session). We keep a small timestamped record that you consented, because the law requires us to be able to prove it. No outside company receives your photos or your read. Payment runs through Polar; your connection runs through Cloudflare, which collects anonymized traffic analytics at its edge and sees technical metadata like your IP, never your images. We keep our own first-party, self-hosted analytics (page views and funnel steps, no third-party tag, never your IP) that you can switch off and we ask permission for in the EEA, run no ads, never do face recognition, and never sell or share your data. It's styling guidance, not medical advice.
Who runs this
Callume is operated by an independent developer (the "we" here). Questions, access requests, or deletion requests: privacy@callume.com.
What we collect
- The photos you upload: selfies for the free read, and (for a full session) headshots, gray-card shots, eye close-ups, wrist, hair, and an optional side profile.
- Measurements derived from them: skin/hair/eye color in CIELAB, facial geometry (shape, proportions, angles) used only for styling, your drape votes, and the season verdict.
- A session name and timestamp: whatever you type, plus when it was created, and your IP address. Your IP is used to rate-limit abuse and is written into the consent record below.
- A consent record: when you agree to the terms, we store the date, the policy version, your IP, and your browser's user-agent string. This is the evidence that you consented, which biometric law requires us to keep, so it outlives the session it belongs to. We keep it for up to five years — matching the limitation period for biometric claims — then delete it.
- Your email: collected by Polar when you pay, and stored with your purchase. If document-recovery is switched on, you can ask for a short-lived link that reopens your reading on another device; when it is off, your document stays tied to the browser you bought on. There is no password — signing in is an emailed link or Google, both of which prove the address is yours without us storing a secret — and we send nothing else to your address. We keep your email tied to your purchase for as long as your reading is available to re-download — up to a year — then it is deleted with the session.
- A nickname, if you set one: whatever you type in Settings, used to address you on your own account page. Nothing else reads it.
- A profile picture, only if you upload one: the account page's default picture is drawn from your own season's colors and stored nowhere — it is generated in your browser each time from your initial and your palette. If you would rather use a photo, you can upload one, and that image is stored on our server until you replace it, switch back to the drawn one, or delete your account. We re-encode it to a 256-pixel square, which strips the metadata phone cameras attach — including GPS coordinates — so what we hold is the picture and not where it was taken. It is never used for the color analysis, never shown to anyone else, and is served only to you.
- Which browsers are signed in: for each one, a coarse label like "Chrome on Windows", and when it first and last used the account. Browser and operating-system family only — no version numbers, no device identifier, no fingerprint. It exists for one purpose: so that when you look at the list you can recognize a browser that is not yours and sign it out. You can remove any of them at any time.
- Payment info: handled entirely by Polar, our payment processor and seller of record. Polar collects your card and billing details to take the payment; we never see your card number. Polar's privacy terms cover what they hold.
No phone number, no precise location, no advertising trackers, no password, and no third-party or cross-site analytics (the only analytics are our own, first-party and self-hosted — detailed below). Your photos and your read are touched only by us; the infrastructure named at the end of this page (Polar, Cloudflare, and, when recovery is on, an email provider) sees only what it needs to do its job, and none of it receives your images.
Signing in with Google — the one exception, stated plainly. If you choose the Google button rather than the emailed link, your browser talks to Google to prove the address is yours, and Google learns that you signed in to Callume. That is the whole exchange: we receive a verified email address and nothing else — no contacts, no profile, no advertising identifier — and your photos, your face geometry and your reading never touch Google at any point. The emailed link does the same job with nobody else involved, which is why both doors are offered side by side and neither is the default.
Sharing a reading is off unless you turn it on. If you do, we make a long random link — never your name, never a guessable address. The page behind it carries your season and that season's palette, and nothing else: no photos, no face geometry, no measurements, no confidence figures, no email. Turning sharing off deletes the link, and the old address stops working immediately.
Biometric notice and consent
To describe your facial structure for styling, Callume computes a scan of face geometry (landmark positions and proportions) from the photos you upload. Where such a scan is treated as a "biometric identifier" or "biometric information" (e.g. under the Illinois Biometric Information Privacy Act) or "special category data" (under the GDPR), the following apply:
- Purpose, and only this purpose: generating your color and styling read. We do not use it to identify you, match you across images, build a face-recognition template, or train models.
- Color, not identity: the eye close-up is used only to measure the color of your iris — we never read, store, or template the iris's pattern or texture, which is what an identifying "iris scan" would use. The personal colors in your document (for example, neutrals matched to your hair or an accent drawn from your skin tone) are computed from these color measurements, exist only in your reading, and are covered by the same retention schedule below.
- Consent: we collect and process it only after you affirmatively consent at upload. You may withdraw consent by not using the service and by deleting your session.
- Our legal basis: your explicit consent, given by ticking the box before you upload (GDPR Art. 6(1)(a), and for the face-geometry scan, Art. 9(2)(a)). No consent, no processing; withdraw it any time by deleting your session, and we stop.
- No sale, no disclosure: we never sell, lease, trade, or otherwise profit from your biometric data, and never disclose it to a third party — except where the law compels it (a valid court order or subpoena), in which case we disclose only the minimum required and, where we're legally allowed to, tell you first.
Retention & destruction schedule
This schedule is set in code and enforced by an automatic sweep. It exists before we ever hold your photos, and it is the same for every user:
- Free face read: your uploaded selfies (and the face-geometry scan derived from them) are deleted immediately after the analysis returns. Only non-biometric summary numbers (your season and a face-shape label) come back to you. The one thing kept is the consent record described above.
- Full session, your photos: the raw images you upload and the face-geometry scan taken from them are deleted within 72 hours of creation. Nothing that can re-identify your face is kept on the server past that; what remains is the derived styling read (color coordinates, a shape label, your palette) and your PDF.
- Full session, your read & PDF: the derived styling output — your season, your palette, the measured color values (skin, hair, eye, wrist) and the styling colors we compute from them, and your structure measurements (shape, proportions) — plus the bound PDF, are kept so you can re-download them, and are destroyed on the earlier of (a) your deletion of the session or (b) one year. None of it can reconstruct your photo or identify your face. That is well within the 3-year outer limit some biometric laws set.
- How the capture went: alongside your read we keep a small record of the light you were photographed in and how the camera behaved — the estimated color of the room's light, how much our independent light estimators disagreed with each other, the exposure the reference needed, how evenly your face was lit. It holds no image, no face geometry, and no measurement of your skin, hair or eyes: it is measurements of the room and the camera, not of you. We read it to work out which methods are actually working. It lives inside your session and is deleted when your session is — we deliberately do not copy it into a separate, longer-lived collection, because keeping something taken from your photograph for a purpose other than producing your own reading is exactly the kind of quiet scope creep this page exists to rule out.
- Your account, if you make one: your email, your nickname, an uploaded picture if you added one, and the list of signed-in browsers are kept for as long as the account exists, and are deleted when you delete it. They are not on a timer, because unlike a photograph they are not something we took from you — they are settings you can remove whenever you like.
- Method: destruction means the files are removed from the server's disk and the database records are deleted. That is what the code does, on the schedule above.
How it's processed & where it lives
Your photos are analyzed on one server we operate (currently in Germany). The face detection, color math, and structure analysis all run there in Python (MediaPipe, NumPy, colour-science) against bundled models. No cloud AI service or third-party analysis API ever receives your photos.
We keep first-party, self-hosted analytics on that same server: which pages are viewed and how far a visit gets through the read (a page view, a free read, a purchase), plus coarse context — the country Cloudflare resolves at its edge (never your IP), a mobile/tablet/desktop bucket, and, for a read, which season and confidence it produced (never a photo). We reuse a single first-party cookie — cc_owner, set for up to a year — to follow a visit through that funnel; it is the only identifier the analytics use, and it never leaves our server. There is no third-party analytics tag, no advertising, no cross-site tracking, and no fingerprinting. These rows are kept up to a year, then purged. Your IP address is used only to rate-limit abuse and to stamp the consent record — the analytics never touch it.
That cookie does two separate jobs, and you can switch off the second one without losing the first. Keeping your session yours — so your photos and your read belong to you and not to the next visitor — is what the cookie is necessary for, and it is always set. Measuring is the optional part. If you are visiting from the EEA we ask before measuring anything, and measurement stays off unless you say yes. Everywhere else it is on by default and you can turn it off here, permanently, at any time. Either way nothing is shared, nothing follows you to another site, and turning measurement off never limits what the site will do for you.
Our legal basis for the strictly-necessary cookie and for abuse prevention is our legitimate interest in running and protecting the service. For measurement there are two cases: in the EEA we ask first and rely on your consent, which you can withdraw above at any time; elsewhere we rely on that same legitimate interest in understanding how the site is used, and you can object to it above at any time. For the biometric consent record, our basis is the legal obligation to keep proof that you consented.
Who else is involved
Callume is a small operation, so a few services sit around it. None of them receives your photos or your reading:
- Polar is our payment processor and seller of record. It collects your card and billing details and your email to take the payment; we never see your card number.
- Cloudflare is the network in front of the server: it terminates TLS, blocks abuse, and delivers the site. It sees connection metadata such as your IP address in order to do that. It does not receive your images, and we do not run Cloudflare's web-analytics product.
- An email provider delivers document-recovery links, and only if you request one while recovery is switched on. It sees your email address and the link, nothing else.
Your rights
You do not have to ask us for any of this. If you have an account, its settings page will hand you a copy of everything and will delete all of it, on the spot, without a request or a reply from us. You can also delete a single session with the × on the home page.
- Where: your account settings.
- A copy of everything downloads as a zip: your account, your measurements, every reading as a data file, and the PDF of any you unlocked. Your photographs are not in it — they were deleted on the schedule above and we kept no copy, so there is nothing to give you.
- Deleting your account removes your readings, their PDFs, your measurements, your uploaded picture, your signed-in browsers, and the account itself. It cannot be undone, and a reading you paid for goes with it — which is why the page offers you the copy first.
- One thing survives, and we would rather say so than have you find out: the record that you consented to a biometric scan. Biometric law requires us to hold that evidence, and we keep it for up to five years as described above. It contains no photograph, no face geometry and no measurement of you — only the fact and date of your consent, the policy version, and the browser details recorded at the time.
For anything the page cannot do, email privacy@callume.com. If you're in the EU/UK you have the usual GDPR rights (access, erasure, objection, portability), including the right to lodge a complaint with your local data-protection supervisory authority; if you're in Illinois or another biometric-law state, the notice and consent above are provided to honor those laws.
Sensitive information: your coloring and face-geometry data are the only "sensitive personal information" we handle, and we already limit their use to the single purpose of generating your read. We never use them to infer anything else, and never sell or share them. If you're a California resident, that is the whole scope of our use; you can still email us to access or delete it.
Not medical or professional advice
Callume is styling guidance: colors and shapes that complement your coloring and features. It is not medical, dermatological, or professional advice, does not diagnose or assess any condition, and is explicitly not a beauty, attractiveness, or health score. Measurements are neutral numbers used only to suggest styling.
Age
Callume is for adults. You must be 18 or older to use it. We don't knowingly collect photos or biometric data from minors; if you believe a minor used it, email us and we'll delete the data.
Changes
If we ever change what we collect, how long we keep it, or where it's processed, this page is updated and re-dated before that change takes effect. Material changes to how we collect, use, or retain your biometric data take effect only after you agree to them again — the box you already ticked doesn't cover new terms.