Privacy Policy
Novame respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how Novame collects, uses, stores, and protects your information when you use our website and services.
By using Novame, you agree to the practices described in this Privacy Policy.
1. Information We Collect
Information You Provide
When using Novame, you may provide:
- Name or nickname
- Email address
- Age or age range
- Gender
- Skincare concerns
- Lifestyle information
- Skincare routine preferences
- Other answers provided during onboarding
This information helps us generate personalized skincare and nutrition guidance.
Facial Images and Skin Photos
Novame may allow you to upload photos of your face to enable features such as cosmetic skin analysis, age estimation, skin appearance tracking, and comparison of skin changes over time. These photos are analyzed using automated AI systems and are used solely for the purpose of providing Novame's skin analysis and personalization features.
Technical and Usage Data
When you use our platform, we may automatically collect device type, browser type, IP address, pages visited, and interaction events. This data is collected through analytics tools described in Section 5.
2. Biometric Data
Certain U.S. states, including Illinois (Biometric Information Privacy Act / BIPA), Texas, and Washington, regulate the collection and use of biometric identifiers, which may include facial images or data derived from them.
To the extent that facial images or derived facial geometry data collected by Novameconstitute biometric data under applicable state law, by uploading photos you provide informed written consent to Novame's collection, storage, and use of such data solely for the purposes described in this Privacy Policy. Novame does not sell biometric data. You may withdraw consent and request deletion of biometric data at any time by contacting support@novame.care.
3. Image Retention Policy
If you upload photos for analysis:
- Your images may be temporarily stored in our systems during and after analysis
- If you do not subscribe to a paid plan, uploaded images are automatically deleted 14 days after analysis
- If you become a paid subscriber, images may be stored longer to enable routine tracking, comparison of skin changes, and historical progress monitoring
Users may request deletion of stored images at any time by contacting support@novame.care.
4. How We Use Your Information
We use the information collected to:
- Generate personalized skincare routines and nutrition guidance
- Perform cosmetic skin analysis and estimate skin age patterns
- Improve AI models and recommendation systems
- Provide customer support
- Send transactional and marketing communications (where you have consented)
- Detect abuse or misuse of the service
- Comply with legal obligations
5. Legal Basis for Processing (GDPR)
For users in the EU, EEA, or UK, we process your personal data on the following legal bases:
- Consent — for photo uploads, biometric data processing, and marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Contractual necessity — to provide the core service you signed up for, including generating personalized recommendations.
- Legitimate interests — for platform security, fraud prevention, and service improvement, where these interests are not overridden by your rights.
- Legal obligation — where processing is required to comply with applicable law.
6. AI Processing and External AI Providers
Novame uses artificial intelligence to generate recommendations. Some information you provide may be processed by external AI providers including OpenAI, Anthropic (Claude), and other large language model providers. Information shared with these providers may include onboarding responses, skin-related information, routine preferences, and other data necessary to generate recommendations.
We work with providers that maintain strong security practices and, where required, have entered into data processing agreements. However, Novame does not control how third-party providers operate their own infrastructure. We encourage you to review the privacy policies of these providers.
7. Analytics and Tracking Technologies
Novame uses third-party services to understand how the platform is used. These may include:
- Google Analytics — usage and behavior analytics
- Meta Pixel — advertising performance measurement
- Klaviyo — email marketing and customer communications
- Supabase — database infrastructure
- Cloud infrastructure providers for hosting and storage
These tools may collect device type, browser type, IP address, pages visited, and interaction events.
Email Communications
By creating an account or submitting your email address, you consent to receive transactional emails (such as account confirmations and service updates) and, where separately consented, marketing communications from Novame. You may opt out of marketing emails at any time by clicking "Unsubscribe" in any email or by contacting support@novame.care. Opting out of marketing emails does not affect transactional communications.
8. Cookies and Similar Technologies
Novame may use cookies and similar technologies to maintain user sessions, remember user preferences, analyze usage patterns, and measure marketing performance.
You can manage cookie preferences through your browser settings or via our cookie consent tool if present on the platform. Disabling certain cookies may affect platform functionality.
Do Not Track
Some browsers send "Do Not Track" signals. Novame does not currently respond to Do Not Track signals, as there is no industry-wide standard for doing so. We will update this policy if our practices change.
9. Data Storage and Security
We take reasonable steps to protect your personal information, including encrypted password storage, secure authentication systems, encrypted data storage where applicable, and limited internal access to sensitive data. However, no internet-based system can be guaranteed to be completely secure.
Data Breach Notification
In the event of a data breach that is reasonably likely to result in risk to your rights or interests, we will notify affected users and relevant authorities as required by applicable law, including within 72 hours where required under GDPR.
10. Data Retention and Deletion
We retain personal data only as long as necessary to provide the service or comply with legal obligations:
- User account data — retained while your account is active
- Uploaded images (free users) — deleted 14 days after analysis
- Uploaded images (paid subscribers) — retained to support progress tracking features; deleted upon account closure or upon request
- Routine and personalization data — retained while needed to provide the service
- Analytics and usage data — retained per the policies of third-party analytics providers
Upon account deletion, we will delete or anonymize your personal data within a reasonable period, except where retention is required by law or for legitimate security purposes.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights:
- Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and who we share it with
- Right to Delete — request deletion of personal information we have collected, subject to certain exceptions
- Right to Correct — request correction of inaccurate personal information
- Right to Opt-Out — opt out of the sale or sharing of your personal information. Novame does not sell personal information for monetary consideration. We may share limited data with advertising partners (such as Meta Pixel); you may opt out by contacting us or using available browser or platform opt-out tools
- Right to Limit Use of Sensitive Personal Information — you may request that we limit use of sensitive data (including biometric data and photos) to purposes necessary to provide the service
- Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights
To submit a request, contact support@novame.care. We will respond to verifiable requests within 45 days. You may designate an authorized agent to submit requests on your behalf.
12. Rights for EU/EEA and UK Users (GDPR)
If you are located in the EU, EEA, or UK, you have the following rights under the GDPR or UK GDPR:
- Right of Access — request a copy of the personal data we hold about you
- Right to Rectification — request correction of inaccurate or incomplete personal data
- Right to Erasure — request deletion of your personal data where it is no longer necessary for the purposes it was collected
- Right to Restriction — request that we restrict processing in certain circumstances
- Right to Data Portability — receive your data in a structured, machine-readable format
- Right to Object — object to processing based on legitimate interests or direct marketing at any time
- Right to Withdraw Consent — withdraw consent at any time without affecting the lawfulness of prior processing
Data is processed in the United States. By using the platform, you acknowledge and consent to this international transfer. We rely on your consent as the transfer mechanism for this purpose.
To exercise your rights, contact support@novame.care. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (for example, the CNPD in Portugal, or the ICO in the UK).
13. International Users
Novame is operated from the United States. If you access the platform from outside the United States, your information may be transferred to and processed in the United States or other countries where our service providers operate. By using Novame, you consent to this transfer.
14. Children's Privacy
Novame is not intended for children under the age of 18. We do not knowingly collect personal data from children. If we learn that personal data from a child has been collected, we will delete it promptly.
15. Third-Party Links
Novame may contain links to third-party websites or services. We are not responsible for the privacy practices of external websites. Users should review the privacy policies of those sites before providing personal information.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically. If significant changes are made, we will update the "Last Updated" date and, where appropriate, notify users by email. Continued use of the service means you accept the revised policy.
17. Contact
Novame
support@novame.care
https://novame.care
KloudStep LLC, Novame
30 N Gould St Ste R
Sheridan WY 82801
United States