This is an English translation provided for convenience. The clinic operates in Ukraine and the Ukrainian version prevails in case of any discrepancy.
The data controller is individual entrepreneur (FOP) Balaban A. O., trading as the aesthetic medicine clinic The Touch (Dr. Marmeliuk's Clinic).
There are two roles here, and telling them apart matters because the app is being built as a platform. The app operator builds and maintains the service, owns the database and is responsible for everything described below. The clinic receives the request and performs the treatment. Both roles are currently filled by the same person, FOP Balaban A. O., so your data never leaves a single organisation. If other clinics join the platform, each will become a controller in its own right for the data it receives with your request — and we will update this section before that goes live.
Processing is carried out under the Law of Ukraine "On Personal Data Protection" No. 2297-VI and, for users located in the EU, under the General Data Protection Regulation (GDPR).
The rules for using the app itself are a separate document: Terms of Use. Both documents apply together.
We talk to you through three channels, and this policy describes all three:
The amount of data differs between channels. Through the website we receive only contact details for a call-back. In the app and the bot you can describe your skin and send photos, so those channels are described separately below.
Through the website we receive only what you type into the booking form:
We do not collect medical records, payment details or documents through the website.
There are four ways to sign in, and none of them uses a password: with your phone number (code by SMS), with your email address (code in an email), through Apple or through Google. The choice is yours; we simply put first the one that is usually more convenient in your country, but all of them are available.
If you sign in through Apple or Google, those services tell us only your
email address, your name (if you allowed it) and a technical account
identifier. We get no password and no access to your mail, contacts or
files. Apple lets you hide your real address — we then receive a relay
address like …@privaterelay.appleid.com, which is fine:
email reaches you through it, and we never see the real one.
The app then stores:
The assistant picks personal details straight out of the conversation and adds them to your profile. If you write "I'm 34 and I live in Odesa", your age and city are saved. Everything stored is visible in the Profile tab, and you can ask us to delete it.
You can send three kinds of images in the app:
Photos are kept in private storage: a direct link to the file does not work, and access is granted only through temporary links valid for 5 minutes. Your photos are visible to you and to the clinic staff handling your booking. Other users of the app have no access to them.
We do not use your photos for advertising, do not publish them and do not pass them to anyone other than the analysis services named in section 7.
A conversation about skin almost always touches on health. The assistant stores in your profile: skin type, concerns (acne, pigmentation, sensitivity and so on), allergies and medication you take. In the questionnaire we ask separately about pregnancy, breastfeeding or planning a pregnancy - not out of curiosity: these rule out whole classes of procedures and ingredients, and without the answer a care protocol could recommend something you must avoid right now. Face photos and analysis results also relate to health.
Under the GDPR this is a special category of data and may only be processed with your explicit consent. You give that consent when you send a photo or tell the assistant about your condition. You can withdraw it at any time by deleting your account (section 14) or by writing to us.
This information serves one purpose: so that the assistant and the cosmetologist do not recommend a treatment that is contraindicated for you. We do not share it with insurers, employers or advertising networks.
Menstrual cycle data is handled separately and more strictly than the rest. The “Cycle and skin” feature is off until you turn it on yourself: until that moment the app stores nothing about your cycle — not a single row. Once it is on, we store only the dates you logged yourself and the usual cycle and period length you entered. Phase and forecast are recomputed every time and are never stored. This data serves exactly one purpose — skincare guidance; it is not a medical forecast and not a method of contraception. In the app (“Cycle and skin” → “Your data”) you can switch the feature off, and erase every log permanently with one button, without deleting your account.
The assistant's replies and the photo analysis are produced by artificial intelligence. For this to work, your text and images are passed to two technology partners:
Both partners are located outside the EU. Transfers are made on the basis of Standard Contractual Clauses (SCC) under Article 46 GDPR.
No automated decision is taken here. The assistant gives recommendations, not a diagnosis: the treatment is ultimately chosen by a clinic cosmetologist at an in-person consultation. Selfie-based scores are approximate — they depend on lighting and angle, and we show them as bands ("low / moderate / pronounced") rather than exact numbers, so as not to suggest a precision a photo cannot give. You can always ask for a human to review your case.
Photographs of treatment results are published only with separate written consent given by the patient at the clinic. Images from the app never end up there — that is a separate process with a separate consent. You may withdraw it at any moment: call or write to us and the photo will be removed from the website within three business days.
We process data for three reasons, each with its own legal basis:
We do not use your contact details for mailings, do not sell them and do not show you advertising.
The services we use to run the app, the website and the bot:
Inside the clinic, access is limited to the administrators and doctors handling your booking. Data is disclosed to public authorities only in cases directly provided for by law.
What does not exist yet. The app is growing into a platform, so here are two future directions explained in advance — neither is live today:
Before any of this goes live we will update this policy and announce it in the app, as promised in section 19.
The website loads a few external components that may see your IP address:
There are no web analytics systems (Google Analytics, Meta Pixel and the like) on the website. The app contains no analytics, no advertising SDKs and no cross-app tracking: we do not ask for tracking permission because we do not track.
The database and photo storage are hosted by Supabase in the European Union (Ireland). Data leaves the EU only at the moment of analysis — to Anthropic and Perfect Corp, on the terms described in section 7.
Data we are legally required to retain (primary medical records) remains even after the app account is deleted.
You can delete your account inside the app, without contacting us: the Profile tab → Delete account. Deletion happens immediately and cannot be undone.
Your profile, conversation, photos, analysis results and booking requests all go with it.
If you previously talked to us in the Telegram bot and merged that history into the app, deleting the account unlinks the app, but the conversation in the bot remains — it lives separately. Write to us to have that deleted too.
You can also write to thetouchclinic1@gmail.com — we handle such requests within 30 days. A step-by-step guide, with a list of what exactly disappears and what is retained by law, is on the Account deletion page.
The app and the clinic's services are intended for people aged 18 and over. We do not knowingly collect children's data. If you are a parent and believe your child has created an account, write to us and we will delete it together with all its data.
We set no cookies for advertising or analytics. The website stores a technical Supabase session key used solely for staff sign-in to the internal panel.
The app keeps a session key on your device so it does not ask for a code on every launch. It sits in the phone's secure storage and disappears when you sign out.
You have the right to:
To exercise any of these rights, write to us by email or Instagram Direct. We reply within thirty calendar days.
Data travels over an encrypted HTTPS connection. Database access is restricted at row level: a request from your account physically cannot read anyone else's records. Photos sit in private storage and open only through temporary links. The staff panel has its own separate sign-in.
Keys to the AI services are stored on the server and never reach the app. We take reasonable protective measures, but no system on the internet offers a hundred-percent guarantee.
We may update this document. The current version always lives at thetouch.clinic/privacy-en.html, and the date at the top of the page shows which version is in force. We will announce material changes affecting the processing of health data inside the app.
For any question about your data, get in touch: