Privacy Policy
Last updated: 9 September 2026
1. Who we are
QUIPI Skin is an application operated by ARGEVASPEAND, S.L. (NRT L-712670-R), with registered address at Edifici Ginesta, Planta baixa 4a, El Tarter, AD100 Canillo, Principat d'Andorra ("Quipi", "we", "us"). Contact: quipi@quipiapp.com.
Representative in the European Union (Art. 27 GDPR): Hacker Mate Brand Incorporation Group, S.L. (CIF B-75626754), P. Sant Joan 9, 17500 Ripoll (Girona), Spain. European users may contact either entity.
2. What data we process
- Account data: your email address and login credentials.
- Photographs of your skin: the facial images you capture or upload for your analyses and, if you use "Ask Quipi", photographs of the skin area you are asking about.
- Photographs of your products: images of your cosmetics, used to identify them.
- Consultations ("Ask Quipi"): the questions you write and the answers generated. The photograph you send with a consultation is processed only to generate the answer and is not stored.
- Care profile: your answers to the questionnaire (age range, how your skin feels, sensitivity, routine, lifestyle).
- Results and activity: the analyses generated, your shelf, your routine, your habits and reminders, and your ratings of the app.
- Subscription status: whether you have an active paid plan (payments are processed entirely by Apple and Google; we never see your banking details).
About your facial photographs. They are the most sensitive category of data we process and we treat them with additional safeguards: (a) they are only captured after your explicit consent within the app, of which we keep a dated and timed record; (b) they are stored in a private space that only your account can access; (c) they are used exclusively to generate your analysis and to show you your progress; (d) they are not used to identify you biometrically, are not shared with third parties for commercial purposes and are not used for advertising; (e) you can delete them at any time by deleting your account from within the app.
Photographs submitted through "Ask Quipi" are processed to generate your answer and are not stored afterwards.
3. Why we process it, and on what legal basis
- To provide the service (skin analysis, routine, progress, reminders): performance of the contract (Art. 6(1)(b) GDPR) and, for facial images, your explicit consent (Arts. 6(1)(a) and 9(2)(a) GDPR), which you may withdraw at any time by deleting your account or writing to us.
- To manage your subscription: performance of the contract.
- Security and usage limits (preventing abuse of the service): legitimate interest (Art. 6(1)(f) GDPR).
- Product improvement through aggregated and anonymous metrics: legitimate interest.
4. How the AI analysis works
To generate your analysis, your photograph and your profile are sent in encrypted form to our artificial intelligence provider, Anthropic PBC (USA), acting as a data processor. Under the commercial terms of its API, Anthropic does not use this data to train its models and retains it only for the limited time necessary to provide the service and ensure its security. The international transfer relies on the safeguards of the applicable adequacy decision framework and/or standard contractual clauses.
The result of the analysis is indicative and cosmetic in nature: QUIPI Skin does not make medical diagnoses and does not replace assessment by a dermatologist.
5. Where your data is stored
Your account, your data and your photographs are hosted on Supabase, on servers located in the European Union. Photographs reside in a private bucket, accessible only through signed, temporary links tied to your session.
6. How long we keep it
For as long as your account is active. If you delete your account from the app (Home → "Delete my account and my data"), your photos, analyses, profile, shelf, habits, reminders and subscription data are erased immediately and irreversibly. We may retain minimal records required by legal obligations (for example, invoicing) for the periods provided by law.
7. Who we share data with
- Supabase Inc. — database and file hosting (EU).
- Anthropic PBC — AI processing to generate your analysis (USA).
- Apple / Google — management of paid subscriptions in their stores.
All of them act as data processors under contract. We do not sell your data and we do not disclose it to third parties for advertising purposes.
8. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability at any time by writing to quipi@quipiapp.com. Complete erasure can also be carried out by you, instantly, from within the app. If you believe we have not handled your rights properly, you may lodge a complaint with a supervisory authority: the APDA (Andorra), the AEPD (Spain) or the authority of your country of residence in the EU.
9. Minors
QUIPI Skin is not directed at children under 16 and we do not knowingly create accounts for them. If we identify an account belonging to a minor, we will delete it together with its data.
10. Security
We apply encryption in transit (TLS), per-user isolation through row level security policies, private file buckets and session-based access control. No system is infallible, but QUIPI Skin is designed on the principle of minimisation: we only ask for the data that is strictly necessary for the service.
11. Changes to this policy
If we make substantial changes, we will tell you within the app before they take effect. The date of the latest version always appears in the header.