SkinCare Hub Privacy Policy

Last updated: July 11, 2026

Scope

This policy covers the SkinCare Hub website and separately describes the read-only SkinCare Hub ChatGPT app V1. The website can save decisions in this browser and, when the API is available, in an anonymous continuity workspace. The ChatGPT V1 tool path does not create that workspace or save website state.

SkinCare Hub provides cosmetic skincare decision support, not medical diagnosis, treatment, prescription guidance, or emergency care. Severe or worsening symptoms are routed toward professional care rather than stronger product recommendations.

Website Data And Anonymous Continuity

The website stores SkinCare Hub state in browser local or session storage so the catalog remains useful without an account. This can include a profile label; budget, goal, skin-profile, sensitivity, actives-comfort, and ingredient-avoid settings; shortlist products and Champion/Backup/Hold/Cut choices; watches; saved articles, profiles, and routines; routine-planner state; continuity state; and interface session preferences.

When the website API is available, the site automatically creates an anonymous SQLite-backed continuity workspace. “Anonymous” means no account or sign-in is required; it does not mean the server receives no ordinary network metadata. The server stores a one-way hash of the issued continuity token, workspace and device records, the saved-state categories above, workspace-owned routine drafts, watches and notification events/settings, and—only when a user supplies them—an email notification address or browser push endpoint, key material, and user-agent label.

Pair codes are eight characters and expire after 10 minutes. The service enforces bounded workspace, device, saved-state, watch, draft, notification, request, concurrency, and daily-use limits.

Website AI Explanations

If live grounded AI is configured, questions and bounded product, routine, or article context sent through the website’s shortlist, comparison, routine-rationale, or Learn tools are sent to OpenAI to generate the requested answer. Those server requests use store: false. If live AI is unavailable or a safety limit is reached, the website uses deterministic grounded fallback answers.

SkinCare Hub’s size-rotated API access logs record ordinary request metadata such as network address, time, request line—including URL query parameters such as catalog filters or routine settings—and response status. They do not log JSON request bodies, continuity-token headers, API keys, or raw OpenAI responses. The default is one current file plus up to five numbered backups, rotating each file at about 8 MiB; this is a size limit, not a fixed number of retention days.

Retention, Reset, And Deletion

Anonymous server workspaces are removed after 90 days without workspace activity. Activity is based on the latest workspace update or paired-device use. Browser storage is separate and remains until the user clears it, uses the controls below, or the browser removes it.

Reset shared data clears continuity documents, watches and notification events, push and email settings, pair codes, workspace-owned routine drafts, and workspace settings. It disconnects every previously paired browser, invalidates the old tokens, and gives the requesting browser one fresh empty server session. After the server confirms reset, the current browser clears its existing SkinCare Hub local and session state, stores that fresh empty continuity session, and refreshes the visible saved-state surfaces in place.

Delete shared workspace removes the complete current server workspace and all paired access without issuing a replacement in that response. After confirmation, the current browser clears its SkinCare Hub local and session storage. Until a later page load creates a new anonymous continuity session, new routine drafts and saved decisions remain in the current browser instead of being written as unowned server data.

Neither action can remotely erase local storage held by another browser while it is offline. Previously paired browsers are disconnected from the reset or deleted workspace, but users should clear SkinCare Hub site data on those browsers separately if they also want the offline copies removed. If a reset or deletion request is not confirmed, the current browser keeps its local data.

These controls apply to browser and continuity-workspace state. They do not recall requests already sent to a retailer or OpenAI, and they do not selectively rewrite access logs; those logs follow the size-based rotation described above and do not contain continuity-token headers or workspace identifiers.

Retailers And Other Services

Separate ChatGPT App V1 Contract

SkinCare Hub ChatGPT app V1 is a read-only cosmetic skincare decision assistant. A tool call may process the skincare question and context supplied in the current ChatGPT conversation, including search or comparison goals, cosmetic skin profile and sensitivity, pregnancy or breastfeeding context when provided, budget, retailer or category filters, ingredient avoid lists, selected product IDs, and AM/PM routine-placement context.

ChatGPT V1 does not persist a SkinCare Hub ChatGPT profile, pregnancy or sensitivity context, routine preview, selected products, comparison, shortlist, watch, notification preference, checkout state, continuity token, device identifier, OAuth data, or retailer account data. It does not create a website continuity workspace. No SkinCare Hub account or sign-in is required for V1.

ChatGPT conversation storage and account controls are handled by OpenAI under its applicable product terms and privacy controls; SkinCare Hub does not control ChatGPT conversation retention. The V1 tool surface does not log into retailer accounts, create carts, complete purchases, or return live affiliate IDs. This website-policy update does not change the existing ChatGPT public-submission hold.

Privacy Controls And Support

Website reset and deletion controls are available inside Skin Profile Lens → Saved → Device continuity. Users can also clear site data with their browser controls. Avoid sharing unnecessary medical, retailer-account, payment, or shipping information in website or ChatGPT questions.

For privacy, data-control, or implementation questions, contact privacy@skincarehub.app. This address does not promise account recovery or a response deadline.