Privacy & biometric data.
Last updated July 2026 · applies to Callume at callume.com.
The short version: your photos are uploaded to one server we run, analyzed there, and then deleted, along with the face-geometry scan taken from them. The free read wipes your selfies the moment it finishes; for a full session your uploaded photos and their geometry are gone within 72 hours, and only your styling read and your PDF are kept so you can re-download them (up to a year, or until you delete the session). We keep a small timestamped record that you consented, because the law requires us to be able to prove it. No outside company receives your photos or your read. Payment runs through Polar; your connection runs through Cloudflare, which collects anonymized traffic analytics at its edge and sees technical metadata like your IP, never your images. We keep our own first-party, self-hosted analytics (page views and funnel steps, no third-party tag, never your IP), run no ads, never do face recognition, and never sell or share your data. It's styling guidance, not medical advice.
Who runs this
Callume is operated by an independent developer (the "we" here). Questions, access requests, or deletion requests: privacy@callume.com.
What we collect
- The photos you upload: selfies for the free read, and (for a full session) headshots, gray-card shots, eye close-ups, wrist, hair, and an optional side profile.
- Measurements derived from them: skin/hair/eye color in CIELAB, facial geometry (shape, proportions, angles) used only for styling, your drape votes, and the season verdict.
- A session name and timestamp: whatever you type, plus when it was created, and your IP address. Your IP is used to rate-limit abuse and is written into the consent record below.
- A consent record: when you agree to the terms, we store the date, the policy version, your IP, and your browser's user-agent string. This is the evidence that you consented, which biometric law requires us to keep, so it outlives the session it belongs to. We keep it for up to five years — matching the limitation period for biometric claims — then delete it.
- Your email: collected by Polar when you pay, and stored with your purchase. If document-recovery is switched on, you can ask for a short-lived link that reopens your reading on another device; when it is off, your document stays tied to the browser you bought on. No password, no account to manage, and we send nothing else to your address. We keep your email tied to your purchase for as long as your reading is available to re-download — up to a year — then it is deleted with the session.
- Payment info: handled entirely by Polar, our payment processor and seller of record. Polar collects your card and billing details to take the payment; we never see your card number. Polar's privacy terms cover what they hold.
No phone number, no precise location, no advertising trackers, no password, and no third-party or cross-site analytics (the only analytics are our own, first-party and self-hosted — detailed below). Your photos and your read are touched only by us; the infrastructure named at the end of this page (Polar, Cloudflare, and, when recovery is on, an email provider) sees only what it needs to do its job, and none of it receives your images.
Biometric notice and consent
To describe your facial structure for styling, Callume computes a scan of face geometry (landmark positions and proportions) from the photos you upload. Where such a scan is treated as a "biometric identifier" or "biometric information" (e.g. under the Illinois Biometric Information Privacy Act) or "special category data" (under the GDPR), the following apply:
- Purpose, and only this purpose: generating your color and styling read. We do not use it to identify you, match you across images, build a face-recognition template, or train models.
- Color, not identity: the eye close-up is used only to measure the color of your iris — we never read, store, or template the iris's pattern or texture, which is what an identifying "iris scan" would use. The personal colors in your document (for example, neutrals matched to your hair or an accent drawn from your skin tone) are computed from these color measurements, exist only in your reading, and are covered by the same retention schedule below.
- Consent: we collect and process it only after you affirmatively consent at upload. You may withdraw consent by not using the service and by deleting your session.
- Our legal basis: your explicit consent, given by ticking the box before you upload (GDPR Art. 6(1)(a), and for the face-geometry scan, Art. 9(2)(a)). No consent, no processing; withdraw it any time by deleting your session, and we stop.
- No sale, no disclosure: we never sell, lease, trade, or otherwise profit from your biometric data, and never disclose it to a third party — except where the law compels it (a valid court order or subpoena), in which case we disclose only the minimum required and, where we're legally allowed to, tell you first.
Retention & destruction schedule
This schedule is set in code and enforced by an automatic sweep. It exists before we ever hold your photos, and it is the same for every user:
- Free face read: your uploaded selfies (and the face-geometry scan derived from them) are deleted immediately after the analysis returns. Only non-biometric summary numbers (your season and a face-shape label) come back to you. The one thing kept is the consent record described above.
- Full session, your photos: the raw images you upload and the face-geometry scan taken from them are deleted within 72 hours of creation. Nothing that can re-identify your face is kept on the server past that; what remains is the derived styling read (color coordinates, a shape label, your palette) and your PDF.
- Full session, your read & PDF: the derived styling output — your season, your palette, the measured color values (skin, hair, eye, wrist) and the styling colors we compute from them, and your structure measurements (shape, proportions) — plus the bound PDF, are kept so you can re-download them, and are destroyed on the earlier of (a) your deletion of the session or (b) one year. None of it can reconstruct your photo or identify your face. That is well within the 3-year outer limit some biometric laws set.
- How the capture went: alongside your read we keep a small record of the light you were photographed in and how the camera behaved — the estimated color of the room's light, how much our independent light estimators disagreed with each other, the exposure the reference needed, how evenly your face was lit. It holds no image, no face geometry, and no measurement of your skin, hair or eyes: it is measurements of the room and the camera, not of you. We read it to work out which methods are actually working. It lives inside your session and is deleted when your session is — we deliberately do not copy it into a separate, longer-lived collection, because keeping something taken from your photograph for a purpose other than producing your own reading is exactly the kind of quiet scope creep this page exists to rule out.
- Method: destruction means the files are removed from the server's disk and the database records are deleted. That is what the code does, on the schedule above.
How it's processed & where it lives
Your photos are analyzed on one server we operate (currently in Germany). The face detection, color math, and structure analysis all run there in Python (MediaPipe, NumPy, colour-science) against bundled models. No cloud AI service or third-party analysis API ever receives your photos.
We keep first-party, self-hosted analytics on that same server: which pages are viewed and how far a visit gets through the read (a page view, a free read, a purchase), plus coarse context — the country Cloudflare resolves at its edge (never your IP), a mobile/tablet/desktop bucket, and, for a read, which season and confidence it produced (never a photo). We reuse a single first-party cookie — cc_owner, set for up to a year — to follow a visit through that funnel; it also keeps your session yours, it is the only identifier the analytics use, and it never leaves our server. There is no third-party analytics tag, no advertising, no cross-site tracking, and no fingerprinting. These rows are kept up to a year, then purged. Your IP address is used only to rate-limit abuse and to stamp the consent record — the analytics never touch it. Our legal basis for the analytics and abuse-prevention is our legitimate interest in running and protecting the service; for the consent record, our legal obligation to keep proof that you consented.
Who else is involved
Callume is a small operation, so a few services sit around it. None of them receives your photos or your reading:
- Polar is our payment processor and seller of record. It collects your card and billing details and your email to take the payment; we never see your card number.
- Cloudflare is the network in front of the server: it terminates TLS, blocks abuse, and delivers the site. It sees connection metadata such as your IP address in order to do that. It does not receive your images, and we do not run Cloudflare's web-analytics product.
- An email provider delivers document-recovery links, and only if you request one while recovery is switched on. It sees your email address and the link, nothing else.
Your rights
You can ask us what we hold about a session, and ask us to delete it. You can delete most of it yourself with the × on the home page, which removes the files and records. For anything else, email privacy@callume.com. If you're in the EU/UK you have the usual GDPR rights (access, erasure, objection, portability), including the right to lodge a complaint with your local data-protection supervisory authority; if you're in Illinois or another biometric-law state, the notice and consent above are provided to honor those laws.
Sensitive information: your coloring and face-geometry data are the only "sensitive personal information" we handle, and we already limit their use to the single purpose of generating your read. We never use them to infer anything else, and never sell or share them. If you're a California resident, that is the whole scope of our use; you can still email us to access or delete it.
Not medical or professional advice
Callume is styling guidance: colors and shapes that complement your coloring and features. It is not medical, dermatological, or professional advice, does not diagnose or assess any condition, and is explicitly not a beauty, attractiveness, or health score. Measurements are neutral numbers used only to suggest styling.
Age
Callume is for adults. You must be 18 or older to use it. We don't knowingly collect photos or biometric data from minors; if you believe a minor used it, email us and we'll delete the data.
Changes
If we ever change what we collect, how long we keep it, or where it's processed, this page is updated and re-dated before that change takes effect. Material changes to how we collect, use, or retain your biometric data take effect only after you agree to them again — the box you already ticked doesn't cover new terms.