Lash Create

Privacy Policy

Last updated: 18 July 2026

This app is provided by Fat Octopus Apps ("we", "us"). This Privacy Policy explains what information Lash Create handles and how. Please read the section that matches how you use the app.

Two ways to use Lash Create

Lash Create can be used in two different ways, and the privacy practices differ between them:

Throughout this policy, "Business plans" means the paid Individual and Salon tiers. If you only use the free or Premium design tool, the account and cloud sections below do not apply to you.

Summary

Account information (Business plans)

To use a Business plan you create an account with your email address and a password. Authentication is handled by Google Firebase Authentication on our behalf. We use this to:

Firebase stores your email and a securely hashed password, and assigns your account a unique identifier. We use that identifier to link your account to your subscription and to your salon. We never see or store your password in readable form.

When you create your salon you can also optionally provide a contact phone number. We use it only to help you get set up and to provide account support — for example contacting you by email, phone, or WhatsApp where you've given us a number. Your phone number is kept private: it is never shown on your booking page or public listing, and it is not used for advertising.

Your salon data in the cloud (Business plans)

When you use a Business plan — whether the solo Individual plan or the team Salon plan — the information you enter is stored in Google Cloud Firestore and Firebase Storage so it can sync across your devices, be shared securely with any staff you invite (Salon plan), and be backed up. Each salon's data is restricted to that salon's active owner and staff.

The salon data we store on your behalf includes your salon setup (name, services, lash and adhesive brands, styles, pricing, promotions and package deals, gift cards, prepaid bundles, and message templates), your team members (names and display colours), bookings and appointment history, lash recipes, inventory and expenses, messages (described below), and your client records (described next).

Client information you enter (Business plans)

Business plans let you, as a lash professional, keep records about your own clients. This is personal information about other people, so it deserves special care. The records you can store about a client include:

Your responsibilities. When you enter a client's information you are the controller of that information, and we process it on your behalf to provide the app. You confirm that you have a lawful basis and any necessary consent to store and use your clients' details — including health-related notes — in the app, and that you will respond to your clients' requests about their own data. We act only on your instructions and do not use your client records for any purpose other than running the app for you.

Team & staff invites (Salon plan)

A Salon owner can invite staff using a one-time invite code. When a staff member redeems a code, their account is linked to the salon so they can access the shared workspace. The owner controls what staff can see through in-app sharing settings (for example, whether staff can view client photos or health notes), and the owner can revoke a staff member's access at any time. Revoking access removes that person's ability to open the salon on their device.

Your public booking page (Business plans)

Business plans can optionally turn on an online booking page — a public web page (at a link such as book.lashcreate.app/your-salon) that you can share or embed on your own website. The page is unauthenticated, so anyone with the link can view it. You control whether it is switched on.

What the page shows. Only the business details you choose to publish: your salon name and location, your logo, an optional cover banner photo, your bookable services and (if you enable prices) their prices, your opening hours, and a link to your reviews. These are business details, not your clients' information.

Logo and banner images. Your logo and cover banner are stored in Firebase Storage and are publicly readable so the page can display them. When you upload one, the app resizes and compresses it and strips embedded metadata (such as EXIF and any GPS location) before storing it.

When a client requests a booking. A visitor chooses a service and time and submits their name, contact details (phone and/or email), and any notes for you. If the salon uses a promo or friend-referral code, the visitor may also enter that code. We use this to create a booking request for your salon and to email a confirmation. This information becomes part of your salon's bookings and client records described above, with you as the controller. Booking-confirmation emails are sent on our behalf by Resend. If the salon has switched on online payments, a deposit or the full amount may be taken at this step (see Online payments below); otherwise the page takes no payment and you approve each request.

Your public directory listing (Business plans)

Separately from your booking page, you can choose to list your salon in the public Lash Create directory on the web (at lashcreate.app/directory). Listing is optional — it appears only if you turn it on and set your salon location — and you can remove it at any time by switching it off in the app.

What the listing shows. Only the details you provide: your salon name and location (country, city, and area), a short tagline, your name, role, photo and introduction, your services and styles, your team members' names, roles and photos, recent-work and facility photos you add, your social links, and a link to your booking page. It never includes your clients' information or your private contact details (such as the phone number above). Because the directory is a public web page, anyone with the link can view what it shows, and the photos on it are stored so they can be displayed publicly.

If your subscription ends. Your listing may remain visible for up to 30 days after a plan lapses, with booking switched off, before it is removed. This gives you time to renew without losing your place in the directory. You can remove the listing sooner at any time from the app.

Online payments (Business plans)

A salon can optionally connect a Stripe account to take payments from clients — for example a booking deposit, the full service price, a no-show or late-cancellation fee, a gift card purchase, or a prepaid bundle. This is switched off unless the salon sets it up.

How card details are handled. When a client pays, their card and payment details are collected by Stripe and charged directly to the salon's own connected Stripe account. Stripe acts as the payment processor. We never see, handle, or store card numbers. We store only what's needed to run the app for the salon — the fact and amount of a payment, its status, and the Stripe reference for it — as part of the salon's booking and client records.

The salon's Stripe account. To connect Stripe, the salon owner completes Stripe's own onboarding. The salon is Stripe's customer (a "connected account"), holds the client relationship for those payments, and is responsible for refunds and any payment disputes through their own Stripe dashboard. Stripe's handling of payment data is governed by Stripe's Privacy Policy.

Messages & notifications (Business plans)

Business plans include messaging so a salon and its clients can chat about a booking, and a private team chat for a Salon's owner and staff. The messages you send are stored in Google Cloud Firestore so they sync across devices and, for team chat, are shared with the salon's staff. Client-facing chat can also send automated replies to common questions. As with other salon data, you are the controller of messages you exchange with your clients.

To let you and your clients know about new messages, booking requests, and reminders, the app can send push notifications. If you allow notifications, we register a device notification token with Google Firebase Cloud Messaging, which delivers the notification to your device via Apple's push service. Appointment and rebooking reminders you set are scheduled on your device. You can turn notifications off any time in iOS Settings.

How your photos are handled

Design tool: when you take a photo with the camera or pick one from your library, the image is processed entirely on your device and is never uploaded to us. Designs you save are stored locally; if you choose to save a design to Photos, that copy is added to your iOS Photos library.

Business plans: client profile photos, saved design snapshots, and result photos are uploaded to your salon's private Firebase Storage so they sync to your team and devices. They are stored privately, used only to show those images inside the app, and deleted from storage when you delete the associated client, appointment, or salon.

Booking-page logo and cover banner are different: because your booking page is public, these two images are stored so that anyone with the page link can view them. They are business branding you choose to publish, not private client photos. As noted above, embedded metadata is stripped from them on upload.

Face data

Lash Create uses Apple's on-device Vision framework (specifically VNDetectFaceLandmarksRequest) to automatically detect where each eye sits in a photo you take or select. The detection produces only 2D pixel coordinates that describe the position, approximate width, and rotation angle of each eye in the image.

No facial recognition is performed. No biometric identifiers (face descriptors, face vectors, faceprints, or any equivalent) are created, stored, or transmitted. The eye coordinates are used for one purpose only: to automatically place lash extensions on the correct position over each eye so you don't have to drag them into place manually.

The eye coordinates exist only in memory during the current editing session. They are not saved to disk, exported, transmitted to a server, shared with any third party, or used for any purpose other than positioning lashes. They are released from memory as soon as you close the editor, open a different photo, or quit the app.

If you save a design, the saved file is the composited image (your photo with the lashes drawn on it). The underlying eye coordinates are not included in any saved file.

Subscriptions & payments

Lash Create offers auto-renewable subscriptions (Premium for the design tool, and Individual and Salon plans for Business). These app subscription payments are processed by Apple via the App Store, and we never see your payment information. (Payments a salon takes from its own clients are separate and handled by Stripe — see Online payments above.)

We use RevenueCat to manage subscription status and entitlements. When you subscribe, RevenueCat receives your purchase details from Apple (such as the product, price, currency, and Apple's purchase receipt) and an identifier for your account (your account's unique identifier for Business plans, or an anonymous identifier otherwise). This is used only to determine whether your subscription is active and which features to unlock.

Apple's handling of purchase data is governed by Apple's Privacy Policy, and RevenueCat's by RevenueCat's Privacy Policy.

Advertising, analytics & tracking

We use two measurement tools to understand how people find and use the app:

Because the TikTok SDK involves tracking, iOS asks for your permission through the App Tracking Transparency prompt. If you choose "Ask App Not to Track," your IDFA is not shared and measurement relies on Apple's privacy-preserving methods (SKAdNetwork) instead. You can change this any time in Settings → Privacy & Security → Tracking.

TikTok's handling of this data is governed by TikTok's Privacy Policy, and Google's by Google's Privacy Policy.

Permissions

Lash Create requests the following permissions and uses them only for the stated purpose:

You can revoke any of these permissions at any time in iOS Settings.

Service providers

We share data only with the providers needed to run the app, and only for that purpose:

Data retention & deletion

You stay in control of your data:

Security

Data sent to and from the cloud is encrypted in transit. Account access is protected by your email and password, and salon data is restricted so that only the salon's active owner and staff can access it. No method of storage or transmission is completely secure, but we take reasonable steps to protect your information.

International transfers

Our service providers, including Google, Stripe, RevenueCat, and TikTok, may process data on servers located in the United States and other countries. Where data is transferred internationally, those providers apply appropriate safeguards.

Children

Lash Create is not directed to children. We do not knowingly collect personal information from children under 13, and the advertising measurement described above relies on tracking only where permission has been granted through iOS. If you believe a child has used the app, contact us and we will help.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will always be available at this URL. The "Last updated" date above will reflect any changes.

Contact

Questions about this Privacy Policy, or a request about your data? Email support@lashcreate.app — we reply within 1–2 business days.