top of page

Enbodie
Privacy
Policy

===============================================================
                                                        ENBODIE PRIVACY POLICY
===============================================================

 

Effective date: 20 June 2026  ·  Last updated: 20 June 2026


-------------------------------------------------------------------------------
THE SHORT VERSION
-------------------------------------------------------------------------------

  - Your photos, videos, name and address never leave your phone. Enbodie
    analyses your image on your own device, behind your device's own security
    and biometrics (Face ID or fingerprint). We never receive your pictures,
    your name or your home address.

  - What we do receive is the health information that analysis produces -
    such as skin and health markers - along with the profile details you
    choose to share (age, sex, ethnicity) and any wearable or health-device
    data you connect. We need these to give you accurate, personalised
    insight. Without them, Enbodie can't tell you anything useful.

  - This information is linked to your account so we can show you how your
    health changes over time. It isn't anonymous to us, and we protect it
    accordingly.

  - We never sell data that identifies you. Your name, address, photos and
    videos never leave your device, so we can never sell them. We may sell
    *aggregated* insights - patterns across groups of users, shaped so no
    individual can be picked out - to research and industry partners. This
    applies to adults only; we never include data from anyone under 18. You
    choose whether your data is included, and you can change your mind any
    time in Settings.

  - You're in control. You can see your data, correct it, download it, or
    delete your account at any time in Settings.


-------------------------------------------------------------------------------

IF YOU'RE UNDER 16
-------------------------------------------------------------------------------

This part is for you. Here's what Enbodie does with your information, in plain
words. If you're under 16, you can't set up Enbodie on your own - a parent or
guardian adds you to their family account so you can use it safely.

  - Your photos and videos stay on your phone. We never see them. Your phone
    works out the health stuff from your photo by itself - locked behind your
    Face ID or fingerprint - and only sends us the results, never the picture.

  - We do get a few things you tell us - like your age, your skin type, and
    anything from a fitness watch you connect - because we need them to give
    you advice that actually fits you.

  - We keep this linked to your account so you can see how things change over
    time, and we look after it carefully.

  - We never sell your information, and we never share it with other
    companies. Your information is only ever used to help you.

  - You're the boss of your information. You can look at it, fix it, or delete
    all of it whenever you want, in Settings.

  - If anything here doesn't make sense, ask a parent or an adult you trust,
    or email us at support@enbodie.me.


-------------------------------------------------------------------------------
ABOUT THIS POLICY
-------------------------------------------------------------------------------

This Privacy Policy explains how Enbodie Ltd ('Enbodie', 'we', 'us', 'our')
collects, uses, stores and protects your personal data when you use the Enbodie
mobile application, the website at enbodie.me, and related services (the
'Services'). If you're in the United States, see section 6.1 for your state
privacy rights.

Enbodie Ltd is registered in England and Wales (Company Number 15669188). Our
registered office is at 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United
Kingdom.

Data Protection Officer: dpo@enbodie.me


General enquiries: support@enbodie.me


===============================================================
1. DATA WE COLLECT
===============================================================

 

1.1 What stays on your device and never reaches us

Some of your most sensitive information is processed entirely on your own phone
and is never sent to us:

  - Your photos and videos used for skin or health analysis
  - Your name and address
  - The raw analysis of your images

Your device extracts the health information it needs from your image locally,
protected by your device's own security and biometrics. We never receive the
image itself.

1.2 What you provide to us

  - Account details: your email address and password, used to create and
    secure your account
  - Profile information you choose to share for analysis: age, sex, ethnicity,
    skin type, Fitzpatrick phototype, conditions and allergies
  - The health data points produced when your device analyses your image
  - Health metrics from any wearable or health device you choose to connect
    (for example heart rate, sleep and activity), where you give explicit
    consent
  - Your product routines and ingredient exposure history
  - Communications with our support team

1.3 Information collected automatically

  - Device and app usage (for example, features used and session length)
  - Technical identifiers (device type, operating system, app version)
  - Log data (for example, errors and performance) where needed to run the
    Services

1.4 Special categories of data

Some of the information you share with us - health information, and where
relevant ethnic origin - is 'special category' data under UK GDPR. We process
it only where you have given explicit consent, or where the law otherwise
permits, as described in our Data Consent and Marketing Preferences document.


===============================================================
2. HOW WE USE YOUR DATA
===============================================================

 

We use your data to:

  - Provide, maintain and improve the Services
  - Give you personalised health insight and product information
  - Track your health information over time so you can see how it changes
  - Process your consent and preferences
  - Communicate with you (account, security, support, and where you've
    consented, marketing)
  - Comply with our legal obligations and protect our rights
  - Improve our platform and AI using anonymised analysis, under our
    legitimate interest in research, where no individual is named or
    identified
  - Where you opt in, build aggregated, non-identifying insights that we share
    or sell to research and industry partners (see section 4)

 

We never sell data that identifies you. Your name, address, photos and videos
never leave your device, so they're never used in any analysis on our systems,
and we can never sell them. The aggregated insights we may share with partners
can't identify you, and contributing to them is always your choice.


===============================================================
3. LEGAL BASIS FOR PROCESSING
===============================================================

 

We process your data on the basis of:

  - Contract: to perform our agreement with you (for example, your account and
    core features)
  - Consent: where you've given clear, explicit consent (for example, health
    analysis, connecting a wearable or health device, marketing, and including
    your data in the aggregated insights we share with partners). These
    consents are separate - you can give or withhold each one, and you can use
    the core Services without agreeing to the others
  - Legitimate interests: where necessary for our or a third party's
    legitimate interests (for example, security and analytics), balanced
    against your rights
  - Legal obligation: where required by law


===============================================================
4. SHARING AND DISCLOSURE
===============================================================

 

We may share your data with:

  - Service providers (hosting, analytics, support) under strict
    confidentiality and data processing agreements
  - Regulators or law enforcement when required by law
  - Wearables and health platforms you choose to connect (for example, a
    fitness tracker or smartwatch) - we receive data from a device only if you
    connect it and grant permission, and you can disconnect it at any time

 

We don't share identifiable health data with advertisers, or for marketing,
without your explicit consent. Where you opt in, we may share or sell
aggregated insights - statistics and patterns across groups of users, shaped
so that no individual can be picked out - with research and industry partners.
This data can't identify you, never includes your images, name or address, and
you can withdraw from it at any time in Settings. We never include data from
users under 18 in these aggregated insights.


===============================================================
5. DATA RETENTION AND SECURITY
===============================================================

 

We keep your data only for as long as we need it for the purposes in this
policy, and as described in our Data Consent document (for example, your
account plus 30 days after deletion, and marketing consent records for three
years after you withdraw).

Because your images, name and address stay on your device, the information we
hold on our own systems is limited to the health data points and profile
details you share with us. We protect that information with appropriate
technical and organisational measures (encryption, access controls, secure
storage). Your data may be processed in the UK, the EEA, or in countries with
adequate safeguards (for example, standard contractual clauses) where we use
international providers.


===============================================================
6. YOUR RIGHTS
===============================================================

 

Under UK GDPR you have the right to:

  - Access - request a copy of your personal data
  - Rectification - correct inaccurate data
  - Erasure - request deletion in certain circumstances
  - Restrict processing - limit how we use your data in certain cases
  - Data portability - receive your data in a structured, machine-readable
    format
  - Object - object to processing based on legitimate interests, or to direct
    marketing
  - Withdraw consent - withdraw consent at any time where processing is based
    on consent
  - Complain - lodge a complaint with the Information Commissioner's Office
    (ico.org.uk)

To exercise your rights, contact dpo@enbodie.me or use in-app settings where
available (for example, delete account, manage preferences).

 

6.1 US and state privacy rights

We don't sell your personal information, and we don't share it for
cross-context behavioural advertising. The aggregated insights we may share
with partners aren't personal information - they can't identify you - and you
can opt out of contributing to them in Settings.

If you're in the United States, certain states (for example California,
Virginia, Colorado and Connecticut) give residents additional rights.
Depending on where you live, you may have the right to:

  - Know what personal information we collect and how we use it (this policy
    and our Data Consent document describe this)
  - Delete your personal information (subject to permitted exceptions)
  - Correct inaccurate personal information
  - Opt out of sale or share - we don't sell or share your personal
    information for cross-context behavioural advertising, so there's nothing
    to opt out of for those activities
  - Limit use of sensitive information - we use sensitive data (for example
    health and ethnicity) only with your explicit consent and for the purposes
    described at the point of collection; you can withdraw consent at any time
    in Settings
  - Non-discrimination - we don't discriminate against you for exercising your
    privacy rights

To exercise these rights, use in-app settings (data export, delete account,
consent preferences) or contact dpo@enbodie.me. We'll respond to verifiable
requests within the time required by applicable law (for example, 45 days for
California requests).


===============================================================
7. CHILDREN AND PARENTAL CONSENT
===============================================================

 

Enbodie is available to people aged 13 and over.

We built Enbodie so that your photos, videos, name and address never leave
your device. That design matters most for younger users, and it is part of why
we are able to offer the Services to teenagers safely.

  - Under 13: Enbodie is not for children under 13, and we do not knowingly
    collect their data.
  - 13 to 15: you cannot create or buy your own account. A parent or guardian
    gives you age-restricted access to core features by adding you to their
    Enbodie Family or Family+ account. The parent or guardian is the account
    holder and consents on your behalf.
  - 16 and over: you can create your own account and consent for yourself.

We check age when an account is created. Where someone signs in with Google or
Apple, their age range is confirmed through those providers' native
age-assurance signals (Apple's Declared Age Range API and Google's Play Age
Signals API), which share an age range without revealing a date of birth.
Because 13 to 15 year olds can only be added by a parent through a Family or
Family+ account, the email sign-up route cannot be used to set up a standalone
under-16 account.

 

If you believe a child under 13 has provided us with data, please contact
dpo@enbodie.me so we can delete it.


===============================================================
8. CHANGES TO THIS POLICY
===============================================================

 

We may update this Privacy Policy from time to time. We'll tell you about
material changes through the app or by email, and we'll post the updated policy
with a new 'last updated' date. Your continued use of the Services after
changes constitutes acceptance of the updated policy where applicable.


===============================================================
9. CONTACT US
===============================================================

 

Data Protection Officer: dpo@enbodie.me


Post: Data Protection Officer, Enbodie Ltd, 3rd Floor, 86-90 Paul Street,
London, EC2A 4NE, United Kingdom


General support: support@enbodie.me


-------------------------------------------------------------------------------
Enbodie Ltd · Registered in England and Wales · Company Number 15669188
3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom
Privacy Policy - last updated 20 June 2026.
===============================================================

Enbodie logo

Menu

Follow Us

Our Partnerships

growlondon.jpeg
British Beauty Council Logo
NVIDIA Inception program  logo
Innovate UK Logo

Contact Us

bottom of page