Essential storage keeps sign-in, your bag and requested features working. With your permission, optional analytics, sampled session replay, error reports and affiliate tools help us understand and improve the site.

You can use the site without optional tracking and change your choice from the footer. Read the cookie details.

Skip to content
beautydew

Privacy

Current product behavior · last updated October 3, 2026

The short version

You can search and browse without an account. With optional consent,beautydew labs uses a first-party random session identifier to connect activity within a visit. When you are signed in, actions such as viewing a product, saving it, setting a profile preference, or submitting content can be recorded against your account. Some convenience data stays only in this browser. The sections below distinguish those states and explain what access and account deletion currently do.

Account and saved data

If you create an account, we store the account identity and sign-in records needed to authenticate you, plus profile fields and product features you choose to save. Depending on what you use, that can include a skin or hair profile, shelf and routine history, follows, reviews, community contributions, alerts, reaction reports, organization roles, and commerce records. No advertising-data-broker or ad-pixel integration is present in the current app code.

Check-in and journal notes are private by default. Reviews, public routines, forum posts, and other features explicitly presented as publishing actions can be visible to other visitors; their final ownership, licence, moderation, and removal terms require the review listed at the end of this policy before open launch.

Label scans, shared results, and photos

Skin journal photos are uploaded only when you choose Save. We store a resized copy without camera metadata, the date you choose, and any optional note. Only your signed-in account can view or download them; they are not published to the community or sent for AI analysis. They remain until you delete the photo or your account. Deletion removes access immediately and queues the stored file for removal, retrying if storage is unavailable. Your data export includes journal details and signed-in download links; you can also download each photo directly from your journal.

When you use a photo to read an ingredient label, optical recognition runs in your browser. The photo is not uploaded merely because you scanned it; recognized label text is sent to the server for ingredient matching.

If you choose Save scan while signed in, we store the decoded result and, when you selected a photo, that photo. The photo is re-encoded before storage, removing camera metadata such as GPS location. Your list at Saved scans is account-only.

A saved or deliberately shared result also receives a random result URL. That result page does not require sign-in and can be opened by anyone who has the URL; it is marked not to be indexed by search engines. It displays the decoded label result, not the saved photo. Do not share the URL if the recognized label text itself is sensitive.

Saved and shared scan records are removed after 180 days. Deleting a saved scan removes it from account history immediately and attempts to purge its photo straight after. Deleting your account removes the saved scan records immediately, and their photo files straight after — if the file store is briefly unavailable, the 180-day sweep clears whatever is left.

Data kept only on this device

Browser storage is used for convenience features such as a signed-out shelf, one product-fit hint, comparisons, recent products and searches, routine drafts, and temporary interface choices. Those records are not sent to the server merely because they exist in browser storage. You can clear them with the feature's own control where one is offered, or through the browser's site-data settings.

When you sign in, the signed-out shelf is offered to the account import flow and cleared locally after a successful import. A local search- history opt-out is checked before recent searches are written and clears the existing local recent-search list when turned on. Server analytics does not store the raw search phrase in its event metadata.

After optional consent, local storage also keeps a random, 30-minute activity-session state for audience measurement. Its random id is sent only if the page has been visible for at least ten seconds and the browser reports a trusted pointer, keyboard, or scroll interaction. It contains no page text, search phrase, account detail, or interaction coordinates.

Cookies and browser storage

The first-party cookies this site knowingly sets are listed below, with the names you would see in your browser's cookie list. Other local browser storage is summarized separately, and any configured third-party affiliate script is called out without inventing vendor cookie names.

You control optional tracking

Optional analytics, sampled session replay, browser error reports, visit attribution and the affiliate auto-link script stay off until you accept. Use Cookie preferences here or in the footer to change your choice. We remember the choice for 180 days on this browser. Your browser can block or delete cookies and other site data independently. Withdrawing consent reloads the page to stop loaded third-party tools; it does not sign you out or empty your bag.

Cookie details and browser controls

Signing in and buying

Required

Set when you sign in, and when you put something in your bag. Without them an account cannot stay signed in and a resubmitted checkout could order twice. Over HTTPS the sign-in names are prefixed — __Secure-authjs.session-token.

Measurement

Counts visits and which parts of the site get used. The Beautydew session can be associated with signed-in activity; the privacy policy explains that link and the retention windows.

Optional — controlled by Cookie preferences

Where a visit came from

Records the campaign tags and referring site of the visit that first brought you here, and attaches them to an order you place. It does not change your price and it blocks nothing.

Optional — controlled by Cookie preferences

Advertising and retargeting

Nothing. This site loads no advertising, retargeting or social pixel, so there is no cookie in this group and nothing here to turn off.

None set

Affiliate auto-link script

The optional browser-side affiliate auto-link script is not configured on this deployment. Some server-generated retailer links can still carry an affiliate tag without this script; those links are disclosed beside the action.

Not loaded

What this site does not load

  • No advertising or retargeting pixel, on any page.
  • No tag manager. When enabled, a masked, sampled PostHog session-replay pilot runs only after optional consent on eligible public pages.
  • Our own preference and visit cookies are host-only. Third-party cookie scope is controlled by the provider.
  • The analytics session can be associated with signed-in account activity; it is not described as anonymous once that happens.

Other browser storage

  • After optional consent, local storage keeps the qualified-session state. Functional storage can keep a guest shelf and fit hint, recent products and searches, comparisons, routine drafts, workspace display choices on this device.
  • Only after optional consent, the qualified-session id is sent after ten visible seconds and a browser-trusted pointer, keyboard, or scroll interaction; it carries no page text, search phrase, or interaction coordinates.
  • Session storage keeps short-lived interface state such as dismissed notices, collapsed trays, and an in-progress sign-in handoff for the current tab.
  • Clearing this site's browser data removes those device-only records; the privacy policy explains which guest data can be imported after sign-in.

Rejecting optional tracking does not change retailer prices or prevent shopping. Disclosed affiliate links may still include a commission reference when you choose to follow them. Contextual sponsored-placement billing uses short-lived, single-use impression tokens; financial, transaction and security records are kept separately from optional visit tracking and do not require an optional analytics identifier.

Website analytics

On the canonical production website, Google Analytics measures page visits and interactions such as searches, completed formula scans, source opens, and outbound purchase clicks. The tag does not load on local development, preview deployments, or non-canonical deployment aliases. Google can process browser or device information, referring pages, approximate location, and pseudonymous identifiers. We do not intentionally send account emails, phone numbers, postal addresses, raw formula text, personal routine answers, or raw search phrases to Google Analytics, and the implementation does not enable Google's user-provided-data feature.

Recognized personal routine and profile answers in a page URL stop the Google tag for that browser document. Our product-fit activation event records that a selection was made, without sending or storing the selected concern in that event. These controls reduce collection; they do not replace the consent and privacy choices described below.

Browsers that identify themselves as automated and browsers deliberately marked as internal are excluded before the Google tag loads. Because any sophisticated automated browser can imitate an ordinary browser, a raw Google Analytics user count is still a diagnostic estimate, not an exact count of people. We use a separate qualified session measure for the audience headline: one random 30-minute browser session that reaches ten visible seconds and a browser-trusted interaction. That is an exact count of consented sessions meeting the stated rule, not proof of a unique human. Visitors who decline are not included, so a lower count after this gate launches is not evidence that traffic fell.

With optional consent, behavioral activity is recorded in our own database. Signed-in rows can carry an account id. Signed-in and signed-out rows can carry the same random session id, so activity before and after a sign-in during one visit can remain connected. Product-view events are retained for 30 days; search and outbound-buy events for up to 365 days; other analytics events for up to 180 days; and qualified sessions for up to 180 days. Account deletion removes account-linked event and qualified-session rows, plus every row in either table sharing a session with them.

Optional analytics, visit attribution, sampled PostHog replay and browser error reports stay off until you choose Accept optional. Choose Reject optional to keep them off. Cookie preferences in the footer lets you change that choice; withdrawing reloads the page so already-loaded third-party tools stop running. Your choice is remembered for 180 days on this browser. If we cannot save the preference, optional tracking stays off. Browser Do Not Track and Global Privacy Control signals also keep it off. Essential sign-in, security, requested account features and transaction records continue to work. Owner and counsel review of launch markets, legal bases and provider terms remains required.

Google explains its processing in its partner-sites privacy explanation.

Traffic investigation with PostHog

When the PostHog investigation pilot is enabled, we send page visits, browser characteristics, and limited interaction events from public catalog pages to PostHog. A browser fingerprint can label a visit as suspicious; that label is not proof that the visitor is automated. We sample 1% of eligible sessions for masked session replay.

Recording masks page text and form inputs, and blocks forms, dialogs, images, and account navigation. Account, login, checkout, routine, and other private pages are excluded. URLs with query strings or fragments are excluded. Collection stops before navigation to an excluded page and stays off for that document. Request bodies, headers, and console logs are not recorded.

This pilot uses session storage for random browser identifiers, without linking them to your account. PostHog receives network information when your browser connects to it. Browsers marked as internal, browsers sending Do Not Track or Global Privacy Control, local development, and preview deployments are excluded. This investigation does not block visitors from using the website.

PostHog privacy information

Error monitoring

When configured, Sentry receives browser errors only after optional consent. Server error monitoring for service reliability and security continues independently of browser consent. An error report can include a sanitized route, stack trace, browser or server-runtime details, and a random request correlation id.

The current configuration does not intentionally send Sentry an account identity, cookies, request or response headers, request or response bodies, query parameters, local stack variables, generative AI inputs or outputs, arbitrary diagnostic extras, or breadcrumbs. Session replay, release-health sessions, Sentry Logs, metrics, and profiling are not enabled. A final scrubber removes common credentials, identity fields, private route identifiers, and database statements before an event leaves the application.

Retailer and affiliate-link measurement

An outbound retailer action can create an internal analytics event linked to the random browser session. The redirect service also keeps a separate commission-reconciliation record containing a random click id, destination, product or offer where known, retailer/network, surface, observed price, and time. That click ledger does not contain an account id or the analytics session id. An affiliate network can return the random click id with a reported conversion so commission can be reconciled. The destination retailer and any configured affiliate provider process the visit under their own privacy terms.

First-touch campaign tags and the referring domain can be stored in a first-party cookie and copied to an order if native commerce is later enabled. The cookie stores the referrer's domain, not its full URL, and it does not change the price shown to the visitor.

Email

Marketing email is opt-in and off by default. The public form joins the weekly watchlist for observed new listings and price drops. An account opt-in also permits one delivered-purchase review request and at most two reminders for an abandoned signed-in bag; a guest checkout address alone is never consent. You can opt in at sign-up, through the watchlist form, or in Email preferences, and unsubscribe without signing in. A suppression record is kept so a marketing address that opted out is not silently re-added.

When transactional email delivery is configured, account, security, safety, and order messages requested by the feature are separate from marketing consent. Provider delivery must be tested before the new site promises email recovery or receipts.

Access and correction

A signed-in member can use the privacy center and request a structured export at Download my data. The export offers 15 explicit categories rather than claiming to export an undefined “everything.”

Data categories available in an export
  • Identity: Your account identity, sign-in methods and revocable session history (never passwords or live session tokens).
  • Profile: Your skin and hair profile: type, concerns, age band, ingredients you avoid.
  • Consent: Your marketing, email and notification choices, and the records that enforce them.
  • Shelf: Your shelf products, use cycles, state changes, pauses, check-ins and imports.
  • Routines: Your routine placements, schedules, completions, introductions and private journal entries.
  • Saved: Products, posts, events, brands, ingredients, topics and people you saved or followed.
  • Reviews: Reviews you have written, including ratings and photos you attached.
  • Community: Your threads, replies, votes, reports, forum photos and in-app notifications.
  • Scans: Label and barcode scans you saved to your history, including retained image references.
  • Safety: Reaction reports, sensitivity history, appeals and recall matches linked to your account.
  • Alerts: Price watches and product-alert rules, events and delivery outcomes tied to your account.
  • Orders: Your carts, checkout records, orders, lines, fulfilment, returns, refunds and saved commerce details.
  • Organizations: Brand claims, organization memberships, role assignments and seller applications tied to you.
  • Contributions: Product or event submissions, corrections, pitches and contact requests linked to you.
  • Analytics: Pages and products your account viewed, searches it ran, and sessions that met the qualified-use threshold.

Account deletion and retained records

Account deletion is permanent, but it is not a promise that every record vanishes. The lists below are rendered from the same code-owned erasure plan used by the deletion flow. Self-service deletion pauses while an order, return or refund is active; while the member is the sole owner of an organization; while a reaction report remains under review; or when a staff reviewer is attached to a retained safety record. Those states must be resolved with the relevant operational team first.

Deleted

These records are removed rather than merely hidden or deactivated.

  • Account and profile: Your account row is deleted outright, and everything attached to it by a database cascade goes with it — shelf, routines, saved scans, favourites, passkeys and sessions.
  • Shelf, routines, journal and saved scans: Records are deleted. Journal and saved scan photo files are queued for removal from storage, with retries if storage is unavailable.
  • Reviews and forum posts: Deleted, along with any photos you attached to them.
  • Browsing and search history: Deleted — event and qualified-session rows carrying your account id, plus every row sharing a session with them. Nulling the account id alone would not de-identify anything, because the session id would still join the rows to each other.

Kept with account identifiers removed

The operational record remains, but the implemented erasure step removes or replaces the identifying fields named below.

  • Orders and payments: The order stays. Your account reference is removed, the order contact email is redacted, and the order shipping address is cleared. Order, tax, and transactional records may be retained where required under our retention policy. Related email-delivery records and message text may still contain personal information; they are subject to separate retention and data-minimization review.Why it remains: Financial record-keeping. A completed sale is the seller's transaction record and a tax document, and it does not stop being one because the buyer closes their account.
  • Support messages: For messages sent from your account email, the separate name and email fields are redacted. The message text is kept unchanged and may still contain personal information you included. Messages sent from other email addresses are not matched by this step.Why it remains: Legitimate interest in resolving and auditing complaints, and in defending legal claims.

Retained

These narrow staff, safety, audit, or aggregate records survive account deletion for the reason stated by the implementation.

  • Published safety statements you reviewed: Kept in full, including the reviewer reference. This only ever applies to staff reviewers, never to an ordinary member.Why it remains: Product-safety obligation. A published caution that could be withdrawn by its reviewer closing their account would make the safety record unreliable at exactly the moment it matters most.
  • Administrative audit trail: Kept. The link to your account is removed (the actor reference is nulled), and the point-in-time email snapshot the row was written with remains, because it is part of the record of what was done. Only staff accounts ever appear here.Why it remains: Append-only by policy (FN-06). An audit log that can be edited by the person it records is not an audit log; see docs/data/audit-retention.md.
  • Aggregate statistics: Counts and averages already computed from your activity stay, because they no longer contain it — nothing in them can be traced back to a person.Why it remains: Anonymous statistical data is outside the scope of an erasure right precisely because it is no longer personal data.

These are implemented data dispositions, not a counsel-approved retention schedule. No fixed statutory response time or long-term retention period is promised here until the policy review below is complete.

Questions or help with a request

Use the privacy center while signed in. If you cannot access the account or need help resolving a deletion blocker, email jaewonlee9642@gmail.com. We do not publish a response-time promise until the operating process and applicable legal deadline have been approved.

Owner and counsel review required before launch

This page is synchronized with current implementation behavior; it is not a substitute for approval of the policy choices below.

  • Final legal bases and retention schedule
  • Account eligibility, age, and treatment of minors' data
  • Health-adjacent profile, reaction, and safety information
  • Cookie consent and analytics rules for every launch jurisdiction
  • International processing, subprocessor register, and vendor contracts
  • Access and erasure response procedures and any statutory deadlines