Privacy policy

Your photos stay under your control.

This policy explains how Smile Monitor handles photos, cosmetic analysis data, subscription status, and deletion.

Last updated 16 August 2026

Operator and contact

Smile Monitor is operated by Samir Khedjam. Samir Khedjam is the data controller for the app and this website.

Privacy requests can be sent to hello@swtchd.io.

A static information site

This website has no cookies, analytics, advertising, contact forms, or tracking scripts. Cloudflare serves the static files and may process ordinary request metadata for delivery and security under its own service policies.

Local history and photos

Smile photos and smile-only display crops are stored in complete-protection, backup-excluded app files. Tracking details, routine events, immutable results, settings, and reminders are stored locally for the features you choose to use.

There is no Smile Monitor account and no cloud photo history. Saved local history remains available offline and after subscription access ends.

Explicit, request-scoped photo processing

The app asks for explicit photo-processing consent before camera permission or analysis. For an accepted photo, it creates bounded, metadata-stripped JPEGs for the current image and any required comparison roles.

The frozen request is sent over HTTPS to the Smile Monitor service on Cloudflare and forwarded once to OpenAI for bounded cosmetic interpretation. The request uses store set to false so the Responses API does not create stored response state.

The OpenAI production project currently uses default data controls. OpenAI may retain customer content in abuse-monitoring logs for up to 30 days, or longer when required by law or reasonably necessary for safety. A flagged image may be retained for safety review.

Smile Monitor does not store image bytes, encoded image bodies, request bodies, face geometry, landmarks, masks, embeddings, or free-form provider prose in its service database or logs. Those items are also excluded from Smile Monitor analytics and crash traces.

Face and mouth photo data

Smile Monitor processes the front-camera photo you choose to take. It can contain your face, mouth and teeth. Apple Vision temporarily detects one face rectangle, lip landmarks and pose on your iPhone only to guide framing, check capture quality, create the smile crop and assess whether photo conditions support a comparison.

Smile Monitor does not use Face ID or TrueDepth depth data. It does not create or keep a face template, embedding or identity profile, recognize or identify a person, infer age, ethnicity, emotion or attractiveness, or use face data for advertising or marketing. Landmark coordinates and live preview frames are discarded on device after the immediate check and are never saved, sent or logged.

After you continue through the disclosure and take a photo, bounded metadata-stripped JPEG copies of the accepted current photo and any required comparison photos are sent through Smile Monitor’s Cloudflare service to OpenAI solely for the visible cosmetic analysis you requested. Cloudflare and OpenAI receive no face landmark coordinates from the app. Smile Monitor stores no image bytes in its service database or logs.

Protected originals and smile crops remain on your iPhone until you use Delete All or remove the app. OpenAI may retain request content in abuse-monitoring logs for up to 30 days, or longer when required by law or reasonably necessary for safety. A flagged image may be retained for safety review. Smile Monitor has no server photo copy to delete.

Limited operational data

The service currently keeps limited pseudonymous installation, request, and billing records needed to secure requests, verify app and subscription status, and audit bounded request outcomes. These app-scoped records never include photos, face geometry, names, email addresses, or inferred identity.

Apple’s signed app transaction is checked ephemerally. Its raw signed value and raw transaction identifier are not stored or logged. A one-way app-scoped allowance subject and capped count of successful photo analyses prevent included use from resetting after deletion or reinstall. These records contain no photo, face geometry, name, email address, or inferred identity.

Apple and RevenueCat manage purchase and subscription records separately under their own terms.

Cloudflare, OpenAI, RevenueCat, and Apple

Cloudflare delivers this website and runs Smile Monitor’s request boundary. OpenAI processes accepted photo copies under the default data controls and retention limits described above. RevenueCat checks subscription entitlement through an app-scoped identifier. Apple processes App Store purchases, billing, and subscription management.

These providers may process operational data in countries where they maintain services. Smile Monitor requires each service provider to limit personal data to the service, security and legal purposes described here and to protect it to the same or an equivalent standard required by this policy and applicable law. Face Data may not be used for advertising, marketing, profiling or identification.

Bounded service records

A structured replay result may remain for up to 24 hours. A terminal request record and its provider audit may remain for up to 30 days. An inactive operational installation ledger may remain for up to 400 days.

Scheduled maintenance removes current operational data after these bounds in batches.

A minimal one-way app-scoped allowance subject, capped count of successful photo analyses, and pseudonymous billing identifier remain for the lifetime of the included-analysis offer so deleting app data or reinstalling cannot reset the allowance.

Smile Monitor includes the first three successful photo analyses. Further analyses require Smile Monitor Pro.

What deletion does

Delete All removes local tracking records, results, managed photos, preferences, reminders, offline entitlement cache, and the active device-bound installation identifier. The app also requests deletion of the current operational installation record and linked request state held by the service.

If the service is unavailable, local deletion still completes. A scoped credential may remain in the device Keychain for up to 30 days solely to retry service deletion when the app launches or returns to the foreground. The credential is removed after success or expiry.

A non-photo one-way app-scoped allowance subject and capped count of successful photo analyses remain so included use does not reset after deletion or reinstall.

Delete All does not cancel an Apple subscription, restore deleted local history after reinstall, or erase older device backups. Apple and RevenueCat subscription records persist independently. Manage an active subscription in Apple subscription settings.

Consent and privacy requests

You can decline photo processing and use completed local history. You can remove all app data through Delete All. You may also request access, correction, deletion, restriction, or objection where applicable under your local law.

The service has no named account that directly identifies you. Include only the non-sensitive context needed to understand your request. Never email a smile photo, technical identifier, or app token. Contact hello@swtchd.io.

Children

Smile Monitor is intended for adults and is not directed to children under 13. A parent or guardian who believes a child supplied personal data can contact us for review and deletion.

Protection by design

Local files use iOS file protection and backup exclusion. Network requests use HTTPS, scoped credentials, bounded payloads, and frozen request identifiers. Production analysis remains unavailable when required backend or billing configuration is missing.

No system can guarantee absolute security. Please report a suspected privacy or security issue promptly to the monitored contact address.

Changes to this policy

Material updates will appear on this page with a new revision date. Where required, the app will request renewed consent before a changed processing activity begins.

Privacy questions

Operator: Samir Khedjam. Email: hello@swtchd.io.