TrueMax
Privacy Policy
The short version
Your front photograph is analysed on your own device. The face measurement engine runs entirely inside your browser. The front photo is not uploaded for the measurement. Separately choosing a Goal preview sends the selected front photo and, if present, side photo once to create it.
A side profile is optional and has two separate choices. You can allow one cloud request to place its thirteen points, or place them on-device yourself. After review, a different optional consent can share that side photo and its point positions for up to 90 days to improve future placement.
Who we are
TrueMax ("we", "us") provides a facial measurement tool at truemax.app. You can reach us about anything in this policy at privacy@truemax.app.
What happens to your photographs
When you take or upload a front photo, it is decoded in your browser and measured there. The 478-point face mesh, every measurement derived from it, and your score are all computed on your device. The front photograph is not sent to a server as part of producing your result.
Photographs you have scanned are kept in your browser's own storage (IndexedDB) so you can see your previous scans. That storage is local to that device and that browser. Clearing your browser data removes it.
Optional Goal preview
Goal preview is available only to signed-in adult Max members. Before its first render, a separate consent explains the request and names the provider. If you agree, TrueMax sends the front photograph and, when the scan has one, the side photograph through our server to Higgsfield or OpenAI together with a bounded list of selected presentation goals. We do not send your name, chat history or measurements outside that goal recipe, and we do not store the source photographs for this request.
TrueMax keeps only the generated previews for up to 30 days, or for up to one year if you explicitly keep one. Generated previews are not used for training or advertising. OpenAI states that API data is not used for training by default and may retain abuse-monitoring data for up to 30 days. Higgsfield receives the uploaded references under its commercial privacy terms; its current integration does not give TrueMax a way to delete the provider upload. You can revoke Goal preview in Settings, which deletes every preview stored by TrueMax.
Optional cloud placement for a side profile
Before the first side-profile upload, we ask whether you want a cloud pass to place its thirteen points. If you agree, the reduced side image is sent through our server to Anthropic for one API request. TrueMax does not write the image to storage and uses the returned coordinates only to seed the review screen. Anthropic states that commercial API inputs are not used for model training by default and that inputs and outputs are normally deleted from its backend within 30 days, unless different retention terms apply or retention is required for safety or legal reasons. See Anthropic's commercial data-retention information.
If you decline, you can place the points on-device without an upload. If you are signed out, reach the daily cloud limit, or the request fails or reaches its bounded time limit, an on-device starting layout is used instead. You can review it, place points yourself, retake the photo or skip the side. Your choice is remembered in this browser and can be changed from the side-profile capture screen.
Separate side-profile landmark feedback
The thirteen points on a side profile are placed automatically and then shown to you for review, because automatic placement is the hardest part of the product to get right. After you confirm or correct them, a separate dialog asks whether you will send us that side photograph together with the automatic and the corrected point positions, so we can make the automatic placement better.
- If you decline, nothing is uploaded and no record is created.
- If you agree, we receive that one side photograph and the two sets of coordinates. Your front photograph is never included.
- It is stored in a private database table and a private storage bucket that no browser can read directly.
- It is deleted automatically after 90 days by a scheduled job. You can revoke one submission from Settings at any time; deleting your account also queues its images for removal.
- We keep a pseudonymous record of consent, revocation, expiry or deletion for up to 365 days. It contains submission and scan IDs, dates and the consent version, but not your account ID or photograph.
- It is used only to improve landmark placement. We do not sell it, publish it, or use it to build any dataset outside this purpose.
- Declining has no effect on your score, your plan, or anything else.
What else we hold
| Data | Why | Where |
|---|---|---|
| Email address | To identify your account and send confirmation, sign-in and password-reset messages | Supabase |
| Your saved scans, including score data and thumbnail images | So your history and progress exist | Your browser only. They are not synchronized to your account |
| Your onboarding profile: name, optional mobile number, date of birth, discovery source, goals, expectations and boundaries | To establish age-appropriate access and personalise your pathway | Supabase, readable only by your account and the service |
| Your height and weight, if you choose to give them | To calculate energy and macros for your daily plan on Max. They are never used in your face score | Supabase, readable only by your account and the service. Optional for adults in the post-signup quiz, editable or removable in Settings, and deleted with your account |
| Your daily streak and points | To show your day count, the light and your points balance. A day is counted when you tick a routine, answer a check-in or scan, never when you open the app | Supabase, readable only by your account and the service. Can be switched off in Settings, which hides it without deleting the record, and deleted with your account |
| Subscription status | To know which plan you are on | Supabase and Stripe |
| Payment details | To take payment | Stripe only. We never see or store your card number |
| Your stated goals and preferences | To personalise your plan | Your browser, and Supabase when supplied through onboarding |
| Optional Goal preview source photographs, selected goal recipe and generated previews | To generate the visual direction you explicitly request | Source photographs are passed in memory to Higgsfield or OpenAI and are not stored by TrueMax. Generated previews are stored privately in Supabase for up to 30 days, or up to one year when kept |
| Optional self-score feedback: your measured score, the score you chose, sex reference, scan ID and account ID | To review calibration. It never changes your score | Supabase, service-only; no photograph or free text is included |
| Max messages, recent chat history and a bounded summary of your scan scores and recommendations | To answer when you choose to use Coach Max | Sent through our server to Anthropic; no scan photograph is included |
| Rundown narration text | To generate voice audio when you request a narrated export | Sent through our server to ElevenLabs or, if it fails, OpenAI |
| Creator League application, post links and statistics, TikTok account link and tokens, Stripe recipient account status, and settlement and transfer records | To operate the League if you apply or connect TikTok | Supabase, TikTok and Stripe. TikTok tokens are server-only. Stripe collects legal identity and bank details directly; TrueMax stores the Stripe account ID and readiness status, not the bank details |
| Pseudonymous side-feedback consent events | To show when optional consent was granted, revoked or expired | Supabase for up to 365 days, without an account ID or photograph |
Row-level security is enabled on every table holding personal data, so one account cannot read another's rows.
Who we share it with
We do not sell your personal information. We do not share your photographs, scans, scores or conversations with anyone for advertising, and no advertising script runs on any page of this site. We use a small number of processors to run the service:
- Supabase: accounts, database and storage.
- Vercel: hosting and delivery of the website.
- Stripe: customer payments, subscription management, and identity, bank and payout handling for approved Creator League members.
- Anthropic: Coach Max replies, only when you use Max.
- ElevenLabs and OpenAI: generated narration, with OpenAI used as a fallback. OpenAI also generates staff-only fictional model images and may create a Goal preview only after its separate consent.
- Higgsfield: may create a Goal preview only after its separate consent.
- TikTok: two separate things. Account linking and post statistics, only for Creator League participants who connect TikTok. And, if you reached us by clicking a TikTok advert, a record that a purchase happened. See below.
If you arrived from a campaign link
Links we put in adverts, newsletters, video descriptions and profile
bios carry campaign parameters that say where the link was placed. They
are the standard utm_source, utm_medium,
utm_campaign, utm_content and
utm_term, and they describe the placement, not you. An
advert additionally carries a click identifier that the advertising
platform put there.
Three different things happen to them, and they are worth separating.
- Stored in your browser. Whichever of those parameters your link carried, ad or not, is written to this site’s local storage on arrival. A link with none of them writes nothing at all, which is most visits.
- Copied to Stripe if you buy. Those same parameters are attached to the payment record, and to the subscription if you start one, so we can see which placement a sale came from.
- Sent to TikTok only for an advert. The report described below happens only when the click identifier is present, which means only when you came from a TikTok advert. A newsletter or bio link has no click identifier and nothing is ever reported for it.
The report to TikTok contains no description of you. The click identifier, the amount and the currency. Not your email address, hashed or otherwise, and not your phone number, your name, your IP address or your device. Never a photograph, a scan, a score, or anything Coach Max said to you. The click identifier is a tracking identifier, and an advertising platform can use it to attribute the sale, build audiences and target adverts, which is why it is described here rather than folded into the list above.
In your browser all of it is kept for at most 30 days and discarded after that whether or not you buy anything, and it is dropped when you sign out. Clearing this site’s data in your browser removes the copy held there immediately.
If you do buy, a copy is kept by Stripe. The campaign parameters and, where there is one, the click identifier are written onto the payment record, and onto the subscription if you start one, so that they stay attached to the purchase for as long as Stripe keeps that record. Clearing your browser does not remove that copy. Where a subscription began with a TikTok advert, each renewal payment is reported in the same way as the first, with the same contents: the click identifier, the amount and the currency, and nothing that describes you. That reporting stops when the subscription does, and it never happens at all for a subscription that did not begin with an advert. Deleting your account removes the TrueMax side of it; to have the Stripe copy erased as well, email privacy@truemax.app and we will make the request on your behalf.
We may also disclose information where the law requires it.
Your rights
You can revoke an individual side-feedback submission from Settings, or delete your account from inside the app at any time. Account deletion removes your ordinary server-side account data, schedules any active subscription to stop, and queues any remaining side-profile feedback images you contributed for deletion. Scan history and thumbnails stored in your browser do not leave that browser and therefore are not removed from the device by server-side account deletion. Use the in-app history controls or clear this site's browser data to remove them. An unsettled Creator League payout must be resolved before deletion. Stripe and TrueMax may retain the minimum settlement, transfer, tax and verification records required by financial law; the public creator identity is removed or detached from that retained ledger. If you have uninstalled the app or cannot sign in, there is a route that does not need either. See deleting your account.
Depending on where you live, you may also have the right to access a copy of your data, correct it, restrict or object to processing, or complain to a data protection authority. Write to privacy@truemax.app and we will respond within 30 days.
Children
TrueMax is not intended for anyone under 13, and we do not knowingly collect information from children under 13. People under 18 are limited to specific plans. The Creator League is only available to adults aged 18 or over. If you believe a child under 13 has given us information, contact us and we will delete it.
Security
The site is served over HTTPS with a strict Content Security Policy. Server-side keys are never included in the browser. That said, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Changes
If we change this policy we will update the date above, and for anything that materially changes how we handle your data we will tell you in the app before it takes effect.