Estima

Privacy Policy

Last updated: 13 August 2026

Table of Contents

  1. Introduction
  2. Data Controller
  3. Data We Collect
  4. How We Use Data
  5. Legal Basis for Processing (GDPR)
  6. AI Image Analysis
  7. Automated Decision-Making
  8. Data Sharing and Sub-processors
  9. Data Retention
  10. Your Rights (GDPR)
  11. Data Security
  12. International Transfers
  13. Cookies
  14. Children's Privacy
  15. Changes to This Policy
  16. Contact

1. Introduction

This policy explains what happens to your data when you use Estima at estima.lazo.build (the "Service"), operated by LAZO.

The short version, before the detail:

2. Data Controller

The data controller is LAZO, an independent one-person studio that builds and operates its own products. The controller is an individual, not a company.

For anything in this policy, including access, correction, deletion and export requests, contact support@lazo.build. Requests sent there reach the controller directly.

3. Data We Collect

3.1 Account Data

When you sign in with Google we receive your email address, your name as held by Google, and your Google account identifier. We never receive or hold your Google password.

3.2 Profile Data

Whether you have short or long hair, which decides only which haircuts you are shown, your language, the fact that you accepted the Terms, and the fact that you confirmed you are 18 or over, each with a timestamp.

Your age confirmation is calculated in your browser. We do not receive or store your date of birth, only the outcome of the check.

3.3 Photographs

Held in memory for the duration of a single request, and only for as long as the analysis takes. Never written to disk, never placed in object storage, never linked to your account, and never retained after the request ends.

3.4 Readings and Results

What the analysis returns about the photographs: face shape, jawline, forehead, undertone, depth, contrast, chroma, eye colour, natural hair colour, hair texture, how light or dark your skin, hair, eyebrows and eyes read on a scale of 1 to 10, an assessment of the lighting, a confidence value, and any image quality flags.

Alongside it we store the result built from that reading, and the version of the reference data and prompt used.

3.5 Feedback You Send Us

If you tell us whether a reading matched you, we store your verdict (right, partly or wrong), which part of the reading it was about, and the optional note you type, up to 280 characters. It is stored against your account and the reading it belongs to.

Sending feedback is entirely optional and it never changes your reading. We use it to find where the reference data is systematically off. If you delete your account, your feedback goes with it.

3.6 Usage Data

How many scans you have run in the current period, so that plan limits can be applied.

3.7 Technical and Anti-abuse Data

To keep the Service within the capacity of its AI provider and to prevent abuse, we hold short-lived counters keyed to a one-way hash of your IP address and to a random identifier stored in a cookie. We do not store your IP address itself, the hash is salted and cannot be reversed, and the counters expire automatically.

4. How We Use Data

We do not use your data for advertising, we do not profile you for marketing, and we do not sell it.

Withdrawing consent does not affect processing that already happened.

6. AI Image Analysis

Your photographs are analysed by a third-party AI model. Specifically:

This is the one part of the process that is not in our hands, which is why it is stated before you upload and not afterwards.

7. Automated Decision-Making

The reading is produced by an automated system, and the result is derived from it by a fixed rule table. There is no human review of your individual scan.

This processing does not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR: it produces styling suggestions. It does not assess your health, your creditworthiness, your employment or your access to any service, and it does not rank or score you against anyone.

Where the system is uncertain, the Service says so. Where you disagree with a reading, you can tell us so, and say why if you want to. That feedback is stored alongside the reading and does not change it. Nothing about a reading is presented as a verdict on you.

8. Data Sharing and Sub-processors

We share data with the following providers solely to operate the Service:

That is the entire list. If we add an anti-abuse check, analytics or any other processor, this section changes before it goes live. We may publish anonymised, aggregated statistics that cannot identify anyone. We do not otherwise share or sell your personal data.

You can create a public link to one of your readings. It is off by default and nothing is public until you turn it on.

We never create a share link for you, and we never share a reading on your behalf.

9. Data Retention

10. Your Rights (GDPR)

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)), as well as the right to lodge a complaint with a supervisory authority in your country.

Two of these are built into the product rather than left to email:

For anything else, write to support@lazo.build. We answer within 30 days and may need to verify your identity first.

11. Data Security

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. International Transfers

Your data may be processed outside the European Economic Area, including in the United States, where providers such as Google and Vercel operate infrastructure. Where data is transferred outside the EEA we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision. Section 6 describes the transfer that matters most in your case.

13. Cookies

We set only what is strictly necessary to operate the Service: your sign-in session, the outcome of your age confirmation, and a random identifier used to count scan attempts. There are no advertising, tracking or analytics cookies, which is why you are not asked to dismiss a consent banner. Each cookie is listed in the Cookie Notice.

14. Children's Privacy

The Service is intended only for people aged 18 or over, which is higher than the age of digital consent under Article 8 GDPR. We ask for age confirmation before the first scan and we do not knowingly process the data of anyone under 18.

If you are a parent or guardian and you believe a person under 18 has used Estima, write to support@lazo.build and the account and all associated data will be deleted promptly.

15. Changes to This Policy

If this policy changes materially we will make it visible in the Service. The date at the top always reflects the current version. Changes that affect what happens to your photographs will be stated before you upload, not only here.

16. Contact

LAZO Email: support@lazo.build