Legal
Privacy Policy
Morph Inc. — Last updated: 2 September 2026 — Effective: 2 September 2026
1. Introduction
Botz Limited, a UK based business with:
- Company Registration Number: 15386986
- Registered Address: 5 Merchant Square, London W2 1AS, United Kingdom
Trading as Morph (“Botz”, “Morph,” “we,” “our,” or “us”) provides an AI-powered skin analysis application and related web services (the “Service”). This policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have over it.
This policy applies to all users of the Service. Where local law gives you additional rights — for example under the EU/UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended (“CCPA/CPRA”), or Canada’s PIPEDA — those rights are described in Sections 9 and 10.
Controller: Botz Limited, 5 Merchant Square, London W2 1AS, United Kingdom. For GDPR purposes, Botz Limited is the data controller for the personal information described here.
Contact: info@morph.inc
EU representative (Article 27): Amal Nathwani, 5 Merchant Square, London W2 1AS, United Kingdom
UK representative: Amal Nathwani, 5 Merchant Square, London W2 1AS, United Kingdom
2. Overview
The points below are a summary for convenience only. The numbered sections that follow are the operative terms.
- We collect facial photographs that you choose to take, and we derive skin metrics from them.
- In some jurisdictions those photographs may be treated as biometric or health-related data, which carries heightened legal protection. We treat them accordingly. We do not use them for identity verification, facial recognition, or matching you against any database.
- Your photographs are processed by us and by a small number of vetted service providers, including AI providers in the United States. They are not sold, not used for advertising, and — as set out in Sections 4 and 5 — not used to train any model, ours or a provider’s, unless you separately opt in.
- Photographs and derived metrics are deleted after 12 months of account inactivity, even if you never ask us to delete them. See Section 7.
- You can delete your account and all associated photographs from within the app at any time or request us to delete for you at info@morph.inc.
3. Information We Collect
3.1 Account information
| Data | Source | Required? |
|---|---|---|
| Email address | You, or your Google/Apple sign-in | Yes |
| Date of birth | You | Yes, we use it to enforce the minimum age in Section 11 |
| Gender, skin type | You | Optional |
| Authentication tokens | Google / Apple | Yes, if you use social sign-in |
3.2 Facial photographs and derived skin data
When you start a scan, the Service captures a standard photograph using your device camera. From that photograph our systems derive:
- Hydration and oiliness estimates
- Texture and pore metrics
- Redness and inflammation indicators
- Pigmentation and dark spot mapping
- Overall tone uniformity and a composite skin health score
We also store your scan history so you can track change over time, and any skincare routine information you enter.
A note on how this data is classified. We do not use Face ID, facial recognition, or any biometric authentication, and we do not attempt to identify you from your photograph. However, we recognise that a facial image processed to derive physiological characteristics may fall within the definition of biometric data under GDPR Art. 9, the Illinois Biometric Information Privacy Act (“BIPA”), the Texas Capture or Use of Biometric Identifier Act (“CUBI”), and comparable laws, and that inferences about skin conditions may constitute health data. Rather than dispute that classification, we apply the heightened protections it calls for: explicit written consent before any scan, purpose limitation, a published retention and destruction schedule (Section 7), contractual restrictions on our processors, and deletion on request. See Section 9.2 for our legal basis.
We do not sell, lease, trade, or otherwise profit from your photographs or any data derived from them.
3.3 Usage and device data
- Features accessed and frequency of use
- Device type, operating system and app version
- IP address, retained for security, fraud prevention and coarse analytics
- Crash and diagnostic logs
3.4 Website analytics
Our website uses Google Analytics with IP anonymisation enabled. Advertising storage, ad user data and ad personalisation signals are disabled.
Analytics cookies are not strictly necessary to deliver the website, so we set them only after you give consent through our cookie banner. You can decline, and you can change or withdraw your choice at any time through the “Cookie settings” link in the website footer. Declining does not affect your access to the Service. You may also opt out across all sites using the Google Analytics opt-out browser add-on.
Strictly necessary cookies are those required for sign-in, security and session management, and are set without consent, as permitted under UK PECR and the ePrivacy Directive.
3.5 What we do not collect
We do not collect payment details, geolocation, contacts, or biometric templates used for identification.
4. How We Use Your Information
| Purpose | Data used |
|---|---|
| Generate your skin analysis and appearance score | Photographs, derived metrics |
| Track progress over time | Scan history |
| Produce written insights and personalized routines | Derived metrics; photograph where a visual cross-check is required |
| Maintain your account and provide support | Account information |
| Security, fraud prevention and abuse monitoring | Usage data, IP address |
| Product analytics and quality improvement | Aggregated and de-identified usage data |
| Age verification | Date of birth |
| Legal compliance | As required |
We do not use your personal information for advertising, and we do not sell or share it as those terms are defined under the CCPA/CPRA.
Photographs and derived skin metrics are never used for product analytics, algorithm development, or model training — neither by us nor by any provider — unless you give separate, specific, opt-in consent through a distinct in-app control. Turning this control off at any point stops any future such use, though it cannot reverse processing already carried out.
5. How Your Analysis Is Generated
Your skin measurements are produced by Morph’s own image-processing pipeline running on our infrastructure: facial landmark detection, colour-space analysis, and detection models we train in-house.
Separately, we use large language models operated by Google (Gemini) in the United States to generate written insights, your personalised routine and a limited number of visual cross-checks. Where a visual cross-check is performed, the photograph itself is sent to the provider.
The following protections apply to that processing, under written agreements:
- Your data is not used to train the provider’s models, and it is not used to train ours (see Section 4).
- Providers may retain submissions only transiently for safety and abuse monitoring, after which they are deleted. They do not retain copies for their own purposes.
- No provider may sell your data, use it for advertising, or disclose it onward.
- We do not transmit your name, email address, or account identifiers alongside your photograph.
Changes of provider. If we add or change any provider that receives photographs, we will update Section 6 and notify you by email or in-app notification before the change takes effect, and we will seek fresh consent where the change requires it.
Automated processing. Your skin score and recommendations are generated automatically. They are informational only. They are not a medical diagnosis, do not produce legal or similarly significant effects within the meaning of GDPR Art. 22, and are not a substitute for advice from a qualified healthcare professional. If you are concerned about a skin condition, consult a doctor or dermatologist.
6. Who We Share Data With
We do not sell your personal information. We disclose it only to the following categories of recipient, and only as needed for them to perform services for us:
| Recipient | Purpose | Location | Receives photos? |
|---|---|---|---|
| Amazon Web Services | Database, authentication, encrypted storage | United States | Yes (at rest, encrypted) |
| Google Gemini | Written insights, routines, visual cross-checks | United States | Yes, for visual cross-checks |
| Google Analytics | Website analytics (IP anonymized) | United States | No |
| Google / Apple | Sign-in authentication | United States | No |
We may also disclose personal information where required by law, to respond to valid legal process, or to protect our rights or the safety of users.
Corporate transactions. In connection with a merger, acquisition, or sale of assets, we will notify you before your information becomes subject to a different privacy policy. Where processing relies on your explicit consent under GDPR Art. 9(2)(a), or on written release under BIPA or CUBI, that consent does not transfer automatically: a successor wishing to process your photographs or derived skin data for its own or different purposes must obtain fresh consent from you.
Each recipient acts as our processor or service provider under a written agreement restricting their use of your data to the purposes above.
7. Data Retention and Deletion
| Data | Retention |
|---|---|
| Photographs | While your account is active, and in any event deleted after 12 months without a sign-in, whichever comes first |
| Derived metrics and scan history | Same as above |
| Account information | While your account is active; deleted after 24 months without a sign-in |
| All of the above, after deletion request | Permanently deleted within 30 days |
| Backups containing deleted data | Purged on the backup rotation cycle, within 30 days |
| Provider-side transient copies | Deleted per provider terms, typically within 30 days |
| De-identified, aggregated analytics | May be retained indefinitely |
| Records we must keep by law | As required by the applicable law |
7.1 Inactivity deletion
We delete photographs and derived skin data 12 months after your last sign-in, regardless of whether you have asked us to. We will email you before we do so, at the address on your account. This is automatic and applies to every user, not only to those covered by a specific state statute.
7.2 How to delete your account
- Open Settings in the Morph app.
- Select Delete Account and confirm.
- If you cannot access the app, email info@morph.inc from your registered address with “Data Deletion Request” in the subject line.
Deletion is permanent and irreversible. You will lose all photographs, analysis history and progress data. Export your data first if you want to keep it (Section 9.1).
8. How We Protect Your Data
- In transit: TLS 1.2 or higher for all connections between your device and our servers, and between our servers and our providers.
- At rest: Encrypted storage for photographs and derived data.
- Access control: Staff access to personal data is limited to a need-to-know basis and logged.
- Testing: Periodic security review and dependency patching.
- De-identification: Where we use data for product analytics, we strip identifiers first.
- Assessment: We have carried out a Data Protection Impact Assessment for the processing of facial images and derived health inferences, and we review it when our processing changes.
We store, transmit and protect photographs and derived skin data using at least the standard of care we apply to other confidential information, and in a manner at least as protective as that required for BIPA-covered data.
We do not offer end-to-end encryption, and we want to be clear about why: our servers must be able to read your photograph in order to analyse it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach notification. If a breach affecting your personal data occurs, we will notify affected users and the relevant supervisory authorities within the timeframes required by applicable law (72 hours to the lead supervisory authority under GDPR, where the breach is likely to result in a risk to your rights).
9. Your Rights
9.1 Rights available to all users
| Right | How to exercise |
|---|---|
| Access — a copy of your data | Email us |
| Correction — fix inaccurate data | In-app profile settings, or email us |
| Deletion — remove your account and data | Settings > Delete Account |
| Portability — machine-readable export | Email us |
| Opt out — of marketing email | Unsubscribe link, or email us |
| Withdraw consent to scanning | Email us |
| Restriction / objection to processing | Email us |
Verifying your identity. Because these rights concern sensitive data, we verify every request before acting on it. Requests made by email must come from the address registered to the account; we may ask you to confirm a detail already on file, or to complete a verification step in the app. We do not ask for additional identity documents. If we cannot verify a request, we will tell you why and explain what would let us proceed, and we will not delete or disclose data on the basis of an unverified request.
We respond to requests within 30 days (or 45 days for CCPA requests, extendable once with notice). We will not discriminate against you for exercising any of these rights. You may designate an authorized agent to make requests on your behalf.
9.2 If you are in the EEA, UK or Switzerland
Our legal bases for processing:
| Processing | Legal basis |
|---|---|
| Facial photographs and derived skin/health data | Explicit consent (Art. 9(2)(a)) |
| Account creation and service delivery | Contract (Art. 6(1)(b)) |
| Security, fraud prevention, product improvement | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
We do not rely on legitimate interests for any processing of photographs or derived skin data. All such processing rests on your explicit consent, and you may withdraw it at any time; withdrawal does not affect processing carried out beforehand, and it does not affect your ability to use the parts of the Service that do not require a scan.
You also have the right to lodge a complaint with your local supervisory authority. In the UK, contact the Information Commissioner’s Office (ico.org.uk); in the EU, contact your national data protection authority.
9.3 If you are in California
We collect the following CCPA categories: identifiers; personal information under Cal. Civ. Code § 1798.80; characteristics of protected classifications (age, gender, where provided); biometric information; internet activity; and sensitive personal information (health-related inferences and biometric information).
We do not sell or share personal information, and we have not done so in the preceding 12 months. We use sensitive personal information only to provide the Service you requested and for purposes permitted under § 7027(m) of the CCPA regulations — you therefore have no separate right to limit its use, but you may delete it at any time. You may designate an authorized agent to make requests on your behalf.
9.4 If you are in Illinois or Texas
We obtain your written consent, and a release permitting the processing described in Sections 4, 5 and 6, before your first scan. We do not sell, lease, trade or otherwise profit from biometric data. Our retention and destruction schedule is published at Section 7. You may withdraw consent and require destruction at any time through Settings › Delete Account.
9.5 Other jurisdictions
Residents of Canada, Virginia, Colorado, Connecticut, Washington and other jurisdictions with comprehensive privacy or consumer health data laws have substantially equivalent rights. Contact us and we will honour them.
10. International Data Transfers
Morph is based in the United Kingdom and our infrastructure and AI providers are located in the United States. If you use the Service from outside the United States, your personal information including your photographs will be transferred to and processed there.
Where we transfer personal data out of the EEA, UK or Switzerland, we rely on:
- The EU Standard Contractual Clauses (2021/914), and the UK International Data Transfer Addendum, with our providers; and/or
- The EU-U.S. Data Privacy Framework and its UK Extension, where the recipient is certified.
We carry out transfer impact assessments where required. You may request a copy of the relevant safeguards by emailing info@morph.inc.
11. Children's Privacy
The Service is intended for users aged 17 and older. We do not knowingly collect personal information from anyone under 17, and we do not knowingly process biometric or health data belonging to a minor. If you believe a user under 17 has created an account, contact info@morph.inc and we will delete it promptly.
12. Changes to This Policy
We may update this policy. We will post the revised version here and update the “Last updated” date. For material changes, including any change to how photographs are processed, retained, or shared, we will notify you by email or in-app notification before the change takes effect, and where the change requires it, we will ask for your consent again.
13. Contact Us
Riva — Privacy Team
Email: info@morph.inc
Postal: Botz Limited, 5 Merchant Square, London W2 1AY, United Kingdom
Response time: We aim to respond within 48 hours and will always respond within the statutory deadline.