RIVA by morph.← Back to home

Legal

Privacy Policy

Morph Inc. — Last updated: 2 September 2026 — Effective: 2 September 2026

1. Introduction

Botz Limited, a UK based business with:

  • Company Registration Number: 15386986
  • Registered Address: 5 Merchant Square, London W2 1AS, United Kingdom

Trading as Morph (“Botz”, “Morph,” “we,” “our,” or “us”) provides an AI-powered skin analysis application and related web services (the “Service”). This policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have over it.

This policy applies to all users of the Service. Where local law gives you additional rights — for example under the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended (“CCPA/CPRA”), or Canada’s PIPEDA — those rights are described in Sections 9 and 10.

Controller: Botz Limited, 5 Merchant Square, London W2 1AS, United Kingdom. For GDPR purposes, Botz Limited is the data controller for the personal information described here.

Contact: info@morph.inc

EU representative (Article 27): Amal Nathwani, 5 Merchant Square, London W2 1AS, United Kingdom

UK representative: Amal Nathwani, 5 Merchant Square, London W2 1AS, United Kingdom

2. Overview

The points below are a summary for convenience only. The numbered sections that follow are the operative terms.

  • We collect facial photographs that you choose to take, and we derive skin metrics from them.
  • In some jurisdictions those photographs may be treated as biometric or health-related data, which carries heightened legal protection. We treat them accordingly. We do not use them for identity verification, facial recognition, or matching you against any database.
  • Your photographs are processed by us and by a small number of vetted service providers, including AI providers in the United States. They are not sold, not used for advertising, and — as set out in Sections 4 and 5 — not used to train any model, ours or a provider’s, unless you separately opt in.
  • Photographs and derived metrics are deleted after 12 months of account inactivity, even if you never ask us to delete them. See Section 7.
  • You can delete your account and all associated photographs from within the app at any time or request us to delete for you at info@morph.inc.

3. Information We Collect

3.1 Account information

DataSourceRequired?
Email addressYou, or your Google/Apple sign-inYes
Date of birthYouYes, we use it to enforce the minimum age in Section 11
Gender, skin typeYouOptional
Authentication tokensGoogle / AppleYes, if you use social sign-in

3.2 Facial photographs and derived skin data

When you start a scan, the Service captures a standard photograph using your device camera. From that photograph our systems derive:

  • Hydration and oiliness estimates
  • Texture and pore metrics
  • Redness and inflammation indicators
  • Pigmentation and dark spot mapping
  • Overall tone uniformity and a composite skin health score

We also store your scan history so you can track change over time, and any skincare routine information you enter.

A note on how this data is classified. We do not use Face ID, facial recognition, or any biometric authentication, and we do not attempt to identify you from your photograph. However, we recognise that a facial image processed to derive physiological characteristics may fall within the definition of biometric data under GDPR Art. 9, the Illinois Biometric Information Privacy Act (“BIPA”), the Texas Capture or Use of Biometric Identifier Act (“CUBI”), and comparable laws, and that inferences about skin conditions may constitute health data. Rather than dispute that classification, we apply the heightened protections it calls for: explicit written consent before any scan, purpose limitation, a published retention and destruction schedule (Section 7), contractual restrictions on our processors, and deletion on request. See Section 9.2 for our legal basis.

We do not sell, lease, trade, or otherwise profit from your photographs or any data derived from them.

3.3 Usage and device data

  • Features accessed and frequency of use
  • Device type, operating system and app version
  • IP address, retained for security, fraud prevention and coarse analytics
  • Crash and diagnostic logs

3.4 Website analytics

Our website uses Google Analytics with IP anonymisation enabled. Advertising storage, ad user data and ad personalisation signals are disabled.

Analytics cookies are not strictly necessary to deliver the website, so we set them only after you give consent through our cookie banner. You can decline, and you can change or withdraw your choice at any time through the “Cookie settings” link in the website footer. Declining does not affect your access to the Service. You may also opt out across all sites using the Google Analytics opt-out browser add-on.

Strictly necessary cookies are those required for sign-in, security and session management, and are set without consent, as permitted under UK PECR and the ePrivacy Directive.

3.5 What we do not collect

We do not collect payment details, geolocation, contacts, or biometric templates used for identification.

4. How We Use Your Information

PurposeData used
Generate your skin analysis and appearance scorePhotographs, derived metrics
Track progress over timeScan history
Produce written insights and personalized routinesDerived metrics; photograph where a visual cross-check is required
Maintain your account and provide supportAccount information
Security, fraud prevention and abuse monitoringUsage data, IP address
Product analytics and quality improvementAggregated and de-identified usage data
Age verificationDate of birth
Legal complianceAs required

We do not use your personal information for advertising, and we do not sell or share it as those terms are defined under the CCPA/CPRA.

Photographs and derived skin metrics are never used for product analytics, algorithm development, or model training — neither by us nor by any provider — unless you give separate, specific, opt-in consent through a distinct in-app control. Turning this control off at any point stops any future such use, though it cannot reverse processing already carried out.

5. How Your Analysis Is Generated

Your skin measurements are produced by Morph’s own image-processing pipeline running on our infrastructure: facial landmark detection, colour-space analysis, and detection models we train in-house.

Separately, we use large language models operated by Google (Gemini) in the United States to generate written insights, your personalised routine and a limited number of visual cross-checks. Where a visual cross-check is performed, the photograph itself is sent to the provider.

The following protections apply to that processing, under written agreements:

  • Your data is not used to train the provider’s models, and it is not used to train ours (see Section 4).
  • Providers may retain submissions only transiently for safety and abuse monitoring, after which they are deleted. They do not retain copies for their own purposes.
  • No provider may sell your data, use it for advertising, or disclose it onward.
  • We do not transmit your name, email address, or account identifiers alongside your photograph.

Changes of provider. If we add or change any provider that receives photographs, we will update Section 6 and notify you by email or in-app notification before the change takes effect, and we will seek fresh consent where the change requires it.

Automated processing. Your skin score and recommendations are generated automatically. They are informational only. They are not a medical diagnosis, do not produce legal or similarly significant effects within the meaning of GDPR Art. 22, and are not a substitute for advice from a qualified healthcare professional. If you are concerned about a skin condition, consult a doctor or dermatologist.

6. Who We Share Data With

We do not sell your personal information. We disclose it only to the following categories of recipient, and only as needed for them to perform services for us:

RecipientPurposeLocationReceives photos?
Amazon Web ServicesDatabase, authentication, encrypted storageUnited StatesYes (at rest, encrypted)
Google GeminiWritten insights, routines, visual cross-checksUnited StatesYes, for visual cross-checks
Google AnalyticsWebsite analytics (IP anonymized)United StatesNo
Google / AppleSign-in authenticationUnited StatesNo

We may also disclose personal information where required by law, to respond to valid legal process, or to protect our rights or the safety of users.

Corporate transactions. In connection with a merger, acquisition, or sale of assets, we will notify you before your information becomes subject to a different privacy policy. Where processing relies on your explicit consent under GDPR Art. 9(2)(a), or on written release under BIPA or CUBI, that consent does not transfer automatically: a successor wishing to process your photographs or derived skin data for its own or different purposes must obtain fresh consent from you.

Each recipient acts as our processor or service provider under a written agreement restricting their use of your data to the purposes above.

7. Data Retention and Deletion

DataRetention
PhotographsWhile your account is active, and in any event deleted after 12 months without a sign-in, whichever comes first
Derived metrics and scan historySame as above
Account informationWhile your account is active; deleted after 24 months without a sign-in
All of the above, after deletion requestPermanently deleted within 30 days
Backups containing deleted dataPurged on the backup rotation cycle, within 30 days
Provider-side transient copiesDeleted per provider terms, typically within 30 days
De-identified, aggregated analyticsMay be retained indefinitely
Records we must keep by lawAs required by the applicable law

7.1 Inactivity deletion

We delete photographs and derived skin data 12 months after your last sign-in, regardless of whether you have asked us to. We will email you before we do so, at the address on your account. This is automatic and applies to every user, not only to those covered by a specific state statute.

7.2 How to delete your account

  1. Open Settings in the Morph app.
  2. Select Delete Account and confirm.
  3. If you cannot access the app, email info@morph.inc from your registered address with “Data Deletion Request” in the subject line.

Deletion is permanent and irreversible. You will lose all photographs, analysis history and progress data. Export your data first if you want to keep it (Section 9.1).

8. How We Protect Your Data

  • In transit: TLS 1.2 or higher for all connections between your device and our servers, and between our servers and our providers.
  • At rest: Encrypted storage for photographs and derived data.
  • Access control: Staff access to personal data is limited to a need-to-know basis and logged.
  • Testing: Periodic security review and dependency patching.
  • De-identification: Where we use data for product analytics, we strip identifiers first.
  • Assessment: We have carried out a Data Protection Impact Assessment for the processing of facial images and derived health inferences, and we review it when our processing changes.

We store, transmit and protect photographs and derived skin data using at least the standard of care we apply to other confidential information, and in a manner at least as protective as that required for BIPA-covered data.

We do not offer end-to-end encryption, and we want to be clear about why: our servers must be able to read your photograph in order to analyse it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Breach notification. If a breach affecting your personal data occurs, we will notify affected users and the relevant supervisory authorities within the timeframes required by applicable law (72 hours to the lead supervisory authority under GDPR, where the breach is likely to result in a risk to your rights).

9. Your Rights

9.1 Rights available to all users

RightHow to exercise
Access — a copy of your dataEmail us
Correction — fix inaccurate dataIn-app profile settings, or email us
Deletion — remove your account and dataSettings > Delete Account
Portability — machine-readable exportEmail us
Opt out — of marketing emailUnsubscribe link, or email us
Withdraw consent to scanningEmail us
Restriction / objection to processingEmail us

Verifying your identity. Because these rights concern sensitive data, we verify every request before acting on it. Requests made by email must come from the address registered to the account; we may ask you to confirm a detail already on file, or to complete a verification step in the app. We do not ask for additional identity documents. If we cannot verify a request, we will tell you why and explain what would let us proceed, and we will not delete or disclose data on the basis of an unverified request.

We respond to requests within 30 days (or 45 days for CCPA requests, extendable once with notice). We will not discriminate against you for exercising any of these rights. You may designate an authorized agent to make requests on your behalf.

9.2 If you are in the EEA, UK or Switzerland

Our legal bases for processing:

ProcessingLegal basis
Facial photographs and derived skin/health dataExplicit consent (Art. 9(2)(a))
Account creation and service deliveryContract (Art. 6(1)(b))
Security, fraud prevention, product improvementLegitimate interests (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))
Legal and regulatory obligationsLegal obligation (Art. 6(1)(c))

We do not rely on legitimate interests for any processing of photographs or derived skin data. All such processing rests on your explicit consent, and you may withdraw it at any time; withdrawal does not affect processing carried out beforehand, and it does not affect your ability to use the parts of the Service that do not require a scan.

You also have the right to lodge a complaint with your local supervisory authority. In the UK, contact the Information Commissioner’s Office (ico.org.uk); in the EU, contact your national data protection authority.

9.3 If you are in California

We collect the following CCPA categories: identifiers; personal information under Cal. Civ. Code § 1798.80; characteristics of protected classifications (age, gender, where provided); biometric information; internet activity; and sensitive personal information (health-related inferences and biometric information).

We do not sell or share personal information, and we have not done so in the preceding 12 months. We use sensitive personal information only to provide the Service you requested and for purposes permitted under § 7027(m) of the CCPA regulations — you therefore have no separate right to limit its use, but you may delete it at any time. You may designate an authorized agent to make requests on your behalf.

9.4 If you are in Illinois or Texas

We obtain your written consent, and a release permitting the processing described in Sections 4, 5 and 6, before your first scan. We do not sell, lease, trade or otherwise profit from biometric data. Our retention and destruction schedule is published at Section 7. You may withdraw consent and require destruction at any time through Settings › Delete Account.

9.5 Other jurisdictions

Residents of Canada, Virginia, Colorado, Connecticut, Washington and other jurisdictions with comprehensive privacy or consumer health data laws have substantially equivalent rights. Contact us and we will honour them.

10. International Data Transfers

Morph is based in the United Kingdom and our infrastructure and AI providers are located in the United States. If you use the Service from outside the United States, your personal information including your photographs will be transferred to and processed there.

Where we transfer personal data out of the EEA, UK or Switzerland, we rely on:

  • The EU Standard Contractual Clauses (2021/914), and the UK International Data Transfer Addendum, with our providers; and/or
  • The EU-U.S. Data Privacy Framework and its UK Extension, where the recipient is certified.

We carry out transfer impact assessments where required. You may request a copy of the relevant safeguards by emailing info@morph.inc.

11. Children's Privacy

The Service is intended for users aged 17 and older. We do not knowingly collect personal information from anyone under 17, and we do not knowingly process biometric or health data belonging to a minor. If you believe a user under 17 has created an account, contact info@morph.inc and we will delete it promptly.

12. Changes to This Policy

We may update this policy. We will post the revised version here and update the “Last updated” date. For material changes, including any change to how photographs are processed, retained, or shared, we will notify you by email or in-app notification before the change takes effect, and where the change requires it, we will ask for your consent again.

13. Contact Us

Riva — Privacy Team

Email: info@morph.inc

Postal: Botz Limited, 5 Merchant Square, London W2 1AY, United Kingdom

Response time: We aim to respond within 48 hours and will always respond within the statutory deadline.