Real World Appeal
ResearchSeptember 7, 202611 min read

We opened the privacy policy of 26 face-rating apps. Six of them do not have one that works

An audit of 26 face-rating apps: 6 privacy policy links are broken, missing or unreadable, and one policy is a Google Doc about a different app.

a person reading terms on a phone screen
Photo: cottonbro studio

Your thumb is over “Allow access to photos.” Before you tap it, there is one basic question: can you actually open the privacy policy the app publishes? We clicked through to all 26 policies so you do not have to. The first finding is about availability, not fine print: six documents did not work for a person trying to read them.

Key numbers

  • 26 apps were audited, filtered from 286 unique results returned by the iTunes Search API to face-rating or face-analysis apps with at least 100 US ratings. Our method
  • 20 of 26 delivered a readable policy at the URL shown by Apple. Our method
  • 6 of 26 did not: two missing links, one 404, one unresolved domain, and two JavaScript-only pages. The six, named
  • 1 of 20 readable policies grants a licence over submitted photos. Source
  • 74 words was the shortest readable policy; the median was 1,397 and the longest was 6,955. Source
  • 10 of 20 readable policies say photos are processed on-device and/or deleted after processing. The counts

Table of contents

What did we actually check?

We checked whether the policy URL on each app's US App Store product page opened a readable document, then counted visible words and recorded what the document said. We did not intercept traffic, decompile anything, or test what any app actually does.

The pool came from the iTunes Search API using 12 category terms. It returned 286 unique apps; we kept apps whose name or description claimed to rate or analyse faces and that had at least 100 US ratings, then audited the top 26 by US rating count. All fetches happened on 7 September 2026.

That distinction matters. A privacy policy is a statement of intent by the developer, not a verified fact about the app's data flows. This is a document audit, and nothing more.

Six of 26 policies are not readable at all

Six of the 26 apps failed the basic test of providing a readable policy at the URL Apple shows: Beauty Meter, PSL - Looksmax & Ascend, U Max: AI Looksmax Face Rating, Aesthetica, Areum, and GlowUp — Become Hot.

AppDeveloperUS ratingsResult
Umax - Become HotImprovement Tech LLC51,463readable
LooksMax AIMnkybrain Labs, Inc.42,636readable
LooksMax Face Rating AI-LooxUPDIALIGHT INTERNATIONAL LP36,661readable
AnimalFace - looksmax ai scoreMorning Star Mobile Limited19,479readable
Thea - #1 Beauty AppThea Technology Inc.15,809readable
UCHAD: See Your PotentialPromi LLC13,226readable
PSL - Looksmax & AscendIQ Labs LLC10,870JavaScript-only page, no policy text in HTML
Ascension - Facial AnalysisAscension Tech LLC4,765readable
Moggr - Haircut & Looksmax AIFunny Media Labs, SOCIEDAD LIMITADA4,141readable
Mogged: Glow Up for MenMetellus Productions LLC3,234readable
Maxxing: LooksMaxxing Glow UpGlow Up LLC2,690readable
Beauty Meter - Are you pretty?Hanh Nguyen2,007no privacy policy link on App Store page
Umax AI:Face Scan & PSL RatingReyadh Redwan Ahmed1,840readable
Beauty Scanner - Face AnalyzerMAXLABS COMPANY LIMITED1,237readable
FaceKit: 3D Face AnalysisKramer Ventures GmbH1,159readable
Symme: Face Rating & AnalysisIlan Huche1,075readable
FaceTag - Face Ratio Analysisminical Inc.900readable, Japanese language
U Max: AI Looksmax Face RatingEmirhan Akyildirim881Google Doc readable, about a different app
Looksmaxxing - PSL Face RatingPRODIGYAI SOLUTIONS866readable
Aesthetica: AI Face AnalysisTalip Serhat Kildaci842HTTP 404
Ascendr - PSL Scale AscenderThe App Kitchen LLC804readable
AscendMax: Looksmax & AscendKazuo Corporation795readable
Areum: Facial Aesthetics ScanBounty Studio, Inc.695JavaScript-only page, no policy text in HTML
PSL Scale & Looksmax: LooksUPH2A Digital LLC606readable
GlowUp — Become HotRMGO512domain did not resolve
FaceRate: AI Looksmax ScoreRenaissance Apps LLC486readable

The failure modes are different, but the result for a careful user is the same: you cannot inspect the document before deciding whether to upload a face.

a hand holding a phone showing an app listing

Two policies are about a different app

Two readable documents raised an identity problem. U Max: AI Looksmax Face Rating links to a Google Doc that opens “Applies to: Looksmaxxing AI: Better You (the ‘Application’)” and says photos are not uploaded, transmitted, or stored on external servers. The App Store app is listed as “U Max: AI Looksmax Face Rating.”

FaceRate: AI Looksmax Score links to a policy that refers to “Onyx” and “Chart AI,” not FaceRate. That document says “Onyx does not collect or derive biometric face data” and describes features that do not match the app name. We report the mismatch; we do not infer what the app does.

What do the twenty readable policies say?

Across the 20 readable policies only, the clearest pattern is restraint: most claims concern stated handling practices, not verified behaviour.

FindingCount across 20 readable policies
Photos processed on-device and/or deleted after processing10 of 20
Use the word “biometric” somewhere10 of 20
Explicit “we do not sell” statement8 of 20
Mention a retention period8 of 20
Name a third-party SDK8 of 20
Binding arbitration or class-action waiver0 of 20
Company licence over submitted photos1 of 20

One policy, Maxxing: LooksMaxxing Glow Up, grants a licence over submissions. Our capture ends mid-sentence: “By submitting User Submissions to the Platform, including photographs and other media, you grant GlowUp a non-exclusive, worldwide, royalty-free license to use, process, analyze, and store your submissions for the purpose of generating Scores, providing Suggestions, and improving the funct” [our capture truncates here]. That is one app out of twenty, which is genuinely better than this category's reputation suggests.

Do not overread a keyword count. Fifteen of 20 readable policies contain “advertising,” but that cannot separate ad-partner disclosures from statements that photos are never used for advertising. We therefore do not report an advertising share.

Which apps did this well?

Several developers gave readers useful, concrete statements. That deserves credit, even when the statement remains only a policy promise.

  • LooksMax Face Rating AI-LooxUP says retained analysis results are not used for advertising, user tracking, facial recognition, biometric identification, or training AI models: policy.
  • PSL Scale & Looksmax: LooksUP says uploaded photos are not used for advertising, marketing, tracking, or training its own models: policy.
  • Mogged: Glow Up for Men says TrueDepth data is processed and stored only on-device and never transmitted: policy.
  • Beauty Scanner - Face Analyzer says it currently does not collect face data and processes everything locally: policy.
  • FaceTag - Face Ratio Analysis uses a 74-word Japanese policy saying the face photograph is not uploaded to a server and analysis happens on-device: policy.

Length is not a quality signal. The shortest policy describes a specific, privacy-protective design, while the longest may simply cover more legal topics. Read the sentence about your photo, not the word count.

What a privacy policy audit cannot tell you

This audit cannot tell you whether an app follows its policy. It cannot prove that on-device processing happens, that deletion is complete, or that a third-party SDK receives nothing.

It also cannot decide whether a face image is legally biometric information in every context. One policy calls face geometry biometric information under US state laws like BIPA; another contains a generic template row saying “Biometric information Fingerprints and voiceprints NO.” We report those words without extrapolating from them.

If you want the broader question of whether these products measure what they claim, see why AI cannot measure attractiveness, and the AI face analysis glossary for what terms like embedding and landmark actually mean. Privacy and validity are separate checks.

What to do before you upload a photo of your face

You can do a meaningful first check in 60 seconds:

  1. Open the App Store listing before installing.
  2. Tap the privacy-policy link Apple displays.
  3. Check the identity: does the document name this app, rather than another product?
  4. Find the photo sentence: does the image leave the device, and when is it deleted?
  5. Look for a deletion route: can you request deletion, and does the policy explain how?

If the link is missing, broken, unresolved, or blank without JavaScript, treat that as missing information. It is not proof of bad conduct, but it is a reason to pause.

Our own /test is free, has no paywall after upload, and shows how a photo reads rather than scoring you. It is not a validated clinical instrument either. For more context on the category, compare the questions in should I trust face-rating apps?, our earlier privacy audit, and what these apps actually charge once you are past the upload screen.

a privacy policy document open on a laptop

The bottom line

The first privacy question is not “does this policy sound sophisticated?” It is “can I open the document, and does it clearly apply to this app?” In this audit, 20 of 26 policies were readable, six were not, and one readable policy granted a photo licence.

A policy is useful evidence of stated intent, not a guarantee. Check it before you upload, and remember that a clean document still needs to be treated as a promise that deserves verification.

If you want a perception-focused result without a numeric beauty score, try /test and read what the photo communicates.

Sources

Frequently asked questions

Do face rating apps have privacy policies?

Usually, but not always in a usable form. Our audit found readable policies for 20 of 26 apps, while six had a missing, broken, unresolved, or JavaScript-only policy page; see our privacy audit.

Do face rating apps keep your photos?

The policies do not give one universal answer. Some say photos are processed on your device or deleted after processing, so check the specific app's policy and its deletion route before uploading.

Can a face rating app use my photo to train AI?

A policy may say it does not use uploaded photos to train models, but that is a statement of intent, not a verified technical finding. The AI face-analysis glossary explains the terms without treating marketing language as proof.

How do I check an app's privacy policy before installing?

Open the App Store listing, tap its privacy-policy link, confirm that the document names this app, and look for photo processing, deletion, and sharing language. This practical guide covers the same checks in more detail.

Is a privacy policy a guarantee?

No. It is a developer's statement of intent, not a guarantee that the app behaves exactly as described; this audit did not intercept traffic or decompile anything.

Test your own first-impression score

1 minute, two photos + a few quick details. Concrete improvement levers ranked by how much they actually move the dial.

Start the test

Related reading