Misa Privacy Policy

Effective Date: January 12, 2026

1. Types of Information We Collect

Misa collects information to provide and enhance our AI-powered eye makeup recommendation services. The information we collect, including specific data types collected and transmitted, falls into the following categories:

  • Personal Identification Information:
    • Collected data types: Email address (for account registration), name (optional), third-party account details (Google/Apple ID UID and basic profile info if signed up via these channels);
    • Collection method: Voluntarily entered by users during account registration, with explicit consent obtained before collection;
    • Transmission: Encrypted and transmitted to Misa's secure cloud servers only when account creation is confirmed by the user;
    • Usage scenarios: Account authentication, password recovery, customer service response, service-related notification delivery.
  • Image Data:
    • Collected data types: Facial photographs (JPG/PNG format, 720P-4K resolution) captured via the App's camera module or uploaded from device photo album, including facial feature coordinates (eye shape, eye size, eyelid type) extracted from images;
    • Collection method: Initiated by user active operation (clicking "shoot" or "upload" button), with one-time consent obtained for each image capture/upload;
    • Transmission: Processed locally on the user's device first; if cloud AI analysis is required, encrypted (AES-256) and transmitted to Misa's servers and [OpenRouter] servers with user explicit permission;
    • Usage scenarios: AI analysis of facial features to generate personalized eye makeup recommendations, preview of makeup effects on uploaded facial images.
  • Usage Data:
    • Collected data types: AI chat history (text content of makeup style requests), makeup style preference tags (e.g., natural, smoky, glitter), feature usage frequency (e.g., number of AI recommendation requests, photo upload times), device information (model, OS version, language settings, device ID), anonymized location data (latitude/longitude if location services are enabled);
    • Collection method: Automatically collected in the background during App usage, with opt-out option provided in App settings;
    • Transmission: Anonymized and encrypted transmitted to Misa's analytics servers in real-time during App usage;
    • Usage scenarios: Personalization of makeup recommendations, optimization of feature usage experience, regional customization of makeup styles (based on location data).
  • Technical Data:
    • Collected data types: IP address, access timestamps, app crash reports (stack trace, error logs), network type (Wi-Fi/cellular), App version number;
    • Collection method: Automatically collected by the App's technical logging module during runtime;
    • Transmission: Encrypted and transmitted to Misa's technical support servers when App is running or crashes;
    • Usage scenarios: Performance optimization, bug fixing, server load balancing, troubleshooting technical issues reported by users.

We do NOT collect sensitive personal information (e.g., race, religion, health records, financial information) unless voluntarily provided by you for specific service customization. All collected data is retained only for the period necessary to fulfill the stated usage scenarios, and no additional data beyond the specified types is collected or transmitted.

2. Purposes of Information Use

We use the collected information solely for the following legitimate business purposes, covering all usage scenarios of the data:

  • To provide and personalize AI eye makeup recommendations (core service functionality): Analyze facial image data and combine with user's makeup style preferences from chat history to generate tailored eye makeup suggestions;
  • To maintain account security and prevent unauthorized access to your Misa account: Verify personal identification information and device information to detect abnormal login behavior;
  • To improve App performance, fix bugs, and enhance user experience: Analyze technical data and usage data to identify and resolve App malfunctions, optimize feature interaction logic;
  • To respond to your inquiries, support requests, and provide customer service: Use email address and chat history to understand user issues and provide targeted solutions;
  • To send service-related notifications (e.g., policy updates, premium service reminders): Use registered email address to deliver notifications, with opt-out option for non-essential communications in App settings;
  • To conduct anonymized, aggregated analytics to understand user trends and improve our AI algorithms (no personal identifiers are retained in aggregated data): Analyze usage data to identify popular makeup styles, optimize AI recommendation accuracy;
  • To comply with legal obligations (e.g., responding to lawful government requests): Provide required data to regulatory authorities in accordance with legal procedures, while protecting user privacy to the maximum extent possible.

We will never use your facial image data for facial recognition marketing or unauthorized profiling. All data usage is strictly limited to the scenarios listed above, and no unstated usage scenarios will be added without prior user consent.

3. Third-Party Service Data Processing

Misa may engage trusted third-party service providers to support our operations, who may process your data on our behalf. The specific names of third-party AI services and related details are as follows:

  • Cloud Storage Providers: Amazon S3
    • Processed data types: Facial image data, encrypted account information;
    • Processing method: Secure storage with AES-256 encryption at rest and TLS 1.3 encryption in transit;
    • Usage purpose: Long-term secure storage of user-uploaded facial images (with user consent) and account data;
    • Data protection capability: Complies with SOC 2 Type II, ISO 27001, and GDPR requirements, with data protection capability equal to or higher than Misa's standards.
  • AI Processing Partners: OpenRouter
    • Processed data types: Facial feature coordinates (extracted from facial images), user's makeup style preference text (from AI chat history), anonymized usage data;
    • Processing method: Data transmitted to OpenRouter's servers via end-to-end encryption (E2EE), processed in isolated virtual environments, and deleted after AI analysis is completed (within 24 hours);
    • Usage purpose: Running AI algorithms to analyze facial features and generate personalized eye makeup recommendations;
    • Data protection capability: OpenRouter complies with GDPR, CCPA, and ISO 27001 certification, implements strict access control and data encryption measures, and has data protection capability equal to or higher than Misa's standards.
  • Payment Processors (e.g., Google Pay, Apple Pay)
    • Processed data types: Anonymized transaction ID (no payment card details or financial information);
    • Processing method: Encrypted transmission via the payment provider's secure gateway;
    • Usage purpose: Processing premium service payments;
    • Data protection capability: Complies with PCI DSS Level 1, the highest standard for payment data security, with data protection capability higher than Misa's standards.
  • Analytics Providers (e.g., Firebase Analytics)
    • Processed data types: Anonymized usage data (stripped of personal identifiers such as email, device ID);
    • Processing method: Aggregated and anonymized before transmission, stored in encrypted form;
    • Usage purpose: Anonymized usage tracking to understand App usage trends and optimize feature design;
    • Data protection capability: Complies with GDPR and CCPA, with data protection capability equal to Misa's standards.

All third-party providers are contractually obligated to protect your data and comply with applicable privacy laws (GDPR, CCPA, etc.). They are prohibited from using your data for their own commercial purposes. Misa has conducted strict audits on the data protection capabilities of all third-party partners, confirming that they meet or exceed Misa's data protection standards, including encryption requirements, access control, data retention policies, and breach response mechanisms.

4. Scenarios for Information Sharing

We will not sell, rent, or lease your personal information to third parties for marketing purposes. We may share your information only in the following limited scenarios, including specific sharing behavior and recipients:

  • With your explicit consent (e.g., sharing your makeup recommendation results with social media platforms such as Instagram/TikTok): Share only the generated makeup recommendation content (no raw facial images or personal identification information) to the selected social media platform at the user's active request;
  • To comply with applicable laws, regulations, or lawful government requests (e.g., court orders, subpoenas): Share the minimum necessary data (e.g., account registration information, usage logs) to the relevant government authority in accordance with legal procedures, and notify the user in advance unless prohibited by law;
  • To protect our legal rights, property, or safety (and that of our users or the public): Share relevant data (e.g., device information, usage logs) with legal representatives or law enforcement agencies in cases of suspected fraud, App security breaches, or threats to user safety;
  • In connection with a business transfer (e.g., merger, acquisition, or sale of assets): Transfer all collected user data to the acquiring entity, provided that the acquiring entity agrees to comply with the same privacy standards as stated in this policy, and notify users of the transfer in advance;
  • Anonymized/aggregated data (no personal identifiers) may be shared with partners for industry research or service improvement: Share aggregated data (e.g., popular makeup styles by region, average number of AI recommendation requests per user) with market research firms or technology partners, with no ability to identify individual users;
  • Sharing with OpenRouter for AI processing: Transmit facial feature coordinates (extracted from user-uploaded/shoot facial images) and user's makeup style preference text (from AI chat history) to [OpenRouter] servers for the sole purpose of generating personalized eye makeup recommendations. This data transmission is encrypted end-to-end, and OpenRouter is prohibited from retaining or using the data for any other purpose beyond providing AI analysis services to Misa.

All data sharing behavior is limited to the scenarios listed above. For any new data sharing scenarios not covered in this policy, Misa will obtain explicit written consent from the user before implementation.

5. Security Measures

We implement industry-standard technical and organizational security measures to protect your data from unauthorized access, disclosure, alteration, or destruction:

  • End-to-end encryption for facial image data transmitted between your device and our servers, as well as between our servers and OpenRouter's servers;
  • Secure cloud storage with AES-256 encryption for stored data;
  • Access controls (role-based permissions) for internal staff accessing user data, with multi-factor authentication required for all data access;
  • Regular security audits and vulnerability assessments of our systems and third-party partners (including OpenRouter) to ensure consistent data protection capabilities;
  • Automatic data deletion for facial images (default retention period: 30 days, unless you opt to save them); data shared with OpenRouter is automatically deleted within 24 hours after AI analysis is completed;
  • Secure password hashing (bcrypt algorithm) for account credentials.

While we take all reasonable precautions, no data transmission over the internet or storage system is 100% secure. We cannot guarantee absolute security, but we will notify you promptly of any data breach that may affect your privacy (in compliance with legal requirements). For data processed by OpenRouter, we require the same level of breach notification obligations, ensuring users are informed of any security incidents involving their data.

6. User Rights Regarding Data

You have the following rights over your personal data, in accordance with global privacy regulations (GDPR, CCPA, etc.):

  • Access Right: Request a copy of all personal data we hold about you, including data shared with third parties such as OpenRouter;
  • Correction Right: Update or correct inaccurate personal information (e.g., email address, makeup style preferences);
  • Deletion Right: Request permanent deletion of your data (including data stored on Misa's servers and data processed by OpenRouter, where we will instruct OpenRouter to delete the corresponding data immediately);
  • Data Portability: Request your data in a machine-readable format (e.g., CSV/JSON) for transfer to another service, including facial feature analysis results and makeup recommendation history;
  • Opt-Out Right: Opt out of non-essential data collection (e.g., usage analytics, marketing communications) or opt out of data sharing with OpenRouter (note: opting out of sharing with OpenRouter will disable the AI makeup recommendation feature);
  • Withdraw Consent: Revoke consent for data processing at any time (may limit access to certain App features, including the core AI recommendation feature if consent for sharing with OpenRouter is revoked).

To exercise these rights, contact us at Misa@gmail.com with your request – we will respond within 15 business days (or 30 days for complex requests) and provide free assistance for data access/deletion requests. For requests related to data processed by OpenRouter, we will coordinate with OpenRouter to fulfill your rights within the same time frame.

7. Children's Privacy Protection

Misa is not intended for use by children under the age of 13 (or the minimum age required by applicable local laws). We do not knowingly collect personal information from children:

  • If we discover we have collected data from a child without parental/guardian consent, we will immediately delete the data (including instructing OpenRouter to delete any related data processed on its servers);
  • Parents/guardians may contact us at Misa@gmail.com to request verification and deletion of any child's data;
  • We do not display targeted advertising to users we reasonably believe are children.

By using Misa, you confirm that you are over the age of 13 (or the applicable age in your jurisdiction) or have obtained parental/guardian consent to use the App. Parental/guardian consent is also required for any data sharing with OpenRouter related to minor users.

8. Policy Update Mechanism

We may update this Privacy Policy to reflect legal changes, service enhancements, or new data processing practices:

  • Updated policies will be posted in the App ("Settings > About > Privacy Policy") and will include the effective date of changes;
  • Material changes (e.g., new data collection categories, sharing practices, changes to third-party AI partners such as OpenRouter) will be notified to you via in-app alerts or email at least 30 days before taking effect;
  • Your continued use of Misa after the effective date of updates constitutes acceptance of the revised policy;
  • You may review the historical versions of this policy by contacting Misa@gmail.com.

If you disagree with the updated policy, you must cease using the App and request deletion of your account/data (including data shared with third parties such as OpenRouter).

Contact Us

For questions, requests, or complaints regarding this Privacy Policy or your data (including data processed by OpenRouter), please contact us at: Misa@gmail.com

We aim to respond to all privacy-related inquiries within 10 business days. For requests related to OpenRouter-processed data, we will coordinate with OpenRouter to provide a complete response within the same time frame.