Baseline Hair Check-in
Privacy Policy
Effective July 18, 2026
This policy explains how Goldlabs.io ("we," "us," or "Baseline"), located at 307 West 38th Street, 16th Floor, PMB 314, New York, New York 10018, handles information in the private Baseline iPhone pilot. Baseline is for adults age 18 and older and does not require an account.
Hair photographs and on-device information
Hairline and scalp photographs, face landmarks, capture-quality measurements, recorded hair conditions, and photo-session history stay in protected storage on the user's iPhone. They are not added to Photos, uploaded to us, used for advertising, or used to train a model.
Local photo history remains on the device until the user deletes it in the app or removes the app. The user can export a PDF containing photographs. Once the user chooses an export destination, the destination's privacy terms and retention practices apply.
Optional diagnostics
If the user separately opts in, Baseline sends limited diagnostics: workflow event, capture outcome, broad completion-time bucket, comparison-confidence label, app version and build, capture-protocol version, iPhone model, iOS version, and a random installation identifier used to join events from one installation.
Diagnostics do not include photographs, face landmarks, free-text notes, treatments, recorded hair-condition values, name, email address, advertising identifiers, or precise location.
How we use and disclose diagnostics
We use optional diagnostics only to evaluate pilot reliability and usability. We do not sell them, use them for advertising, or share them for cross-company tracking. Cloudflare processes and stores these diagnostics on our behalf as our infrastructure provider. We may also disclose information when required by law or to protect the security and rights of users, the public, or our service.
Retention and deletion
Uploaded diagnostic events are automatically deleted after 90 days. In the app, the user can turn sharing off and request immediate deletion under Profile > Optional diagnostics. This also clears diagnostics waiting on the device. Local photo history is managed separately under Profile > Privacy and data controls.
Consent and choices
Diagnostic sharing is optional. Declining or later withdrawing consent does not block any photo feature. A user can revoke consent and request deletion from the in-app controls described above. Because the pilot has no account, these controls use the installation's locally stored deletion credential.
Security
Baseline uses iOS file protection for local records and HTTPS for diagnostic transport. The diagnostic service hashes installation identifiers and deletion tokens before storing identity records, validates a fixed event schema, rate-limits requests, and supports explicit deletion. No system can be guaranteed completely secure.
Children
Baseline is not intended for anyone under 18. We do not knowingly collect pilot diagnostics from children.
Medical scope
Baseline documents and compares photographs. It does not diagnose a condition, count follicles, determine why hair changed, or advise starting or stopping treatment.
Changes to this policy
We may update this policy as the pilot changes. We will revise the effective date, and where appropriate provide notice or request renewed consent before materially changing how optional diagnostics are handled.
Contact
Privacy questions and requests: privacy@getbaselinehair.com.
Product support: support@getbaselinehair.com.
Mail: Goldlabs.io, 307 West 38th Street, 16th Floor, PMB 314, New York, New York 10018.