Lash Create
Privacy Policy
Last updated: 18 July 2026
This app is provided by Fat Octopus Apps ("we", "us"). This Privacy Policy explains what information Lash Create handles and how. Please read the section that matches how you use the app.
Two ways to use Lash Create
Lash Create can be used in two different ways, and the privacy practices differ between them:
- The design tool (free & Premium). Take or pick a photo, try lashes on, and save your designs. This works entirely on your device with no account and your images are never uploaded to us.
- Business plans (salon CRM). Optional paid plans for lash professionals that add client records, bookings, consultations, and a shared team workspace. These plans require an account and store your salon's data in the cloud so it syncs across your devices and your team, and is backed up.
Throughout this policy, "Business plans" means the paid Individual and Salon tiers. If you only use the free or Premium design tool, the account and cloud sections below do not apply to you.
Summary
- The design tool keeps your photos and designs on your device. We have no server copy of your images.
- Business plans require an email-and-password account and store the salon data you enter (including your clients' details) in the cloud.
- Business plans can optionally publish a public booking page. It shows the salon details you choose (including an optional cover photo), and lets clients send you a booking request with their contact details.
- Business plans can optionally list the salon in a public directory on the web, showing only the business details and photos you choose to publish.
- Business plans can optionally take payments from clients online — booking deposits, full payment, gift cards, and prepaid bundles — through Stripe. Card details go directly to Stripe and the salon's own connected Stripe account; we never see or store card numbers.
- Business plans include messaging between a salon and its clients, plus a private team chat, and can send push notifications. These are stored in the cloud so they sync across devices.
- The app includes the TikTok Business SDK and Firebase Analytics for measuring advertising and improving the app. You can decline cross-app tracking when prompted.
- App subscriptions are processed by Apple, with subscription status managed through RevenueCat.
Account information (Business plans)
To use a Business plan you create an account with your email address and a password. Authentication is handled by Google Firebase Authentication on our behalf. We use this to:
- Create and secure your account, and sign you in across devices.
- Send a verification email to confirm your address.
- Send password-reset emails when you request them.
Firebase stores your email and a securely hashed password, and assigns your account a unique identifier. We use that identifier to link your account to your subscription and to your salon. We never see or store your password in readable form.
When you create your salon you can also optionally provide a contact phone number. We use it only to help you get set up and to provide account support — for example contacting you by email, phone, or WhatsApp where you've given us a number. Your phone number is kept private: it is never shown on your booking page or public listing, and it is not used for advertising.
Your salon data in the cloud (Business plans)
When you use a Business plan — whether the solo Individual plan or the team Salon plan — the information you enter is stored in Google Cloud Firestore and Firebase Storage so it can sync across your devices, be shared securely with any staff you invite (Salon plan), and be backed up. Each salon's data is restricted to that salon's active owner and staff.
The salon data we store on your behalf includes your salon setup (name, services, lash and adhesive brands, styles, pricing, promotions and package deals, gift cards, prepaid bundles, and message templates), your team members (names and display colours), bookings and appointment history, lash recipes, inventory and expenses, messages (described below), and your client records (described next).
Client information you enter (Business plans)
Business plans let you, as a lash professional, keep records about your own clients. This is personal information about other people, so it deserves special care. The records you can store about a client include:
- Contact details — name, phone number, email, address, and social handles (Instagram, WhatsApp), where you choose to enter them.
- Consultation & health information — notes such as allergies, sensitivities, eye conditions, lash health, natural-lash retention, patch-test dates, consent status, and intake answers. Some of this is health-related and should be handled accordingly.
- Appointment & service history — dates, services, lash styles, products used, payment records, and rebooking dates.
- Photos — client profile photos and design snapshots you save against an appointment.
Your responsibilities. When you enter a client's information you are the controller of that information, and we process it on your behalf to provide the app. You confirm that you have a lawful basis and any necessary consent to store and use your clients' details — including health-related notes — in the app, and that you will respond to your clients' requests about their own data. We act only on your instructions and do not use your client records for any purpose other than running the app for you.
Team & staff invites (Salon plan)
A Salon owner can invite staff using a one-time invite code. When a staff member redeems a code, their account is linked to the salon so they can access the shared workspace. The owner controls what staff can see through in-app sharing settings (for example, whether staff can view client photos or health notes), and the owner can revoke a staff member's access at any time. Revoking access removes that person's ability to open the salon on their device.
Your public booking page (Business plans)
Business plans can optionally turn on an online booking page — a public web page (at a link such as book.lashcreate.app/your-salon) that you can share or embed on your own website. The page is unauthenticated, so anyone with the link can view it. You control whether it is switched on.
What the page shows. Only the business details you choose to publish: your salon name and location, your logo, an optional cover banner photo, your bookable services and (if you enable prices) their prices, your opening hours, and a link to your reviews. These are business details, not your clients' information.
Logo and banner images. Your logo and cover banner are stored in Firebase Storage and are publicly readable so the page can display them. When you upload one, the app resizes and compresses it and strips embedded metadata (such as EXIF and any GPS location) before storing it.
When a client requests a booking. A visitor chooses a service and time and submits their name, contact details (phone and/or email), and any notes for you. If the salon uses a promo or friend-referral code, the visitor may also enter that code. We use this to create a booking request for your salon and to email a confirmation. This information becomes part of your salon's bookings and client records described above, with you as the controller. Booking-confirmation emails are sent on our behalf by Resend. If the salon has switched on online payments, a deposit or the full amount may be taken at this step (see Online payments below); otherwise the page takes no payment and you approve each request.
Your public directory listing (Business plans)
Separately from your booking page, you can choose to list your salon in the public Lash Create directory on the web (at lashcreate.app/directory). Listing is optional — it appears only if you turn it on and set your salon location — and you can remove it at any time by switching it off in the app.
What the listing shows. Only the details you provide: your salon name and location (country, city, and area), a short tagline, your name, role, photo and introduction, your services and styles, your team members' names, roles and photos, recent-work and facility photos you add, your social links, and a link to your booking page. It never includes your clients' information or your private contact details (such as the phone number above). Because the directory is a public web page, anyone with the link can view what it shows, and the photos on it are stored so they can be displayed publicly.
If your subscription ends. Your listing may remain visible for up to 30 days after a plan lapses, with booking switched off, before it is removed. This gives you time to renew without losing your place in the directory. You can remove the listing sooner at any time from the app.
Online payments (Business plans)
A salon can optionally connect a Stripe account to take payments from clients — for example a booking deposit, the full service price, a no-show or late-cancellation fee, a gift card purchase, or a prepaid bundle. This is switched off unless the salon sets it up.
How card details are handled. When a client pays, their card and payment details are collected by Stripe and charged directly to the salon's own connected Stripe account. Stripe acts as the payment processor. We never see, handle, or store card numbers. We store only what's needed to run the app for the salon — the fact and amount of a payment, its status, and the Stripe reference for it — as part of the salon's booking and client records.
The salon's Stripe account. To connect Stripe, the salon owner completes Stripe's own onboarding. The salon is Stripe's customer (a "connected account"), holds the client relationship for those payments, and is responsible for refunds and any payment disputes through their own Stripe dashboard. Stripe's handling of payment data is governed by Stripe's Privacy Policy.
Messages & notifications (Business plans)
Business plans include messaging so a salon and its clients can chat about a booking, and a private team chat for a Salon's owner and staff. The messages you send are stored in Google Cloud Firestore so they sync across devices and, for team chat, are shared with the salon's staff. Client-facing chat can also send automated replies to common questions. As with other salon data, you are the controller of messages you exchange with your clients.
To let you and your clients know about new messages, booking requests, and reminders, the app can send push notifications. If you allow notifications, we register a device notification token with Google Firebase Cloud Messaging, which delivers the notification to your device via Apple's push service. Appointment and rebooking reminders you set are scheduled on your device. You can turn notifications off any time in iOS Settings.
How your photos are handled
Design tool: when you take a photo with the camera or pick one from your library, the image is processed entirely on your device and is never uploaded to us. Designs you save are stored locally; if you choose to save a design to Photos, that copy is added to your iOS Photos library.
Business plans: client profile photos, saved design snapshots, and result photos are uploaded to your salon's private Firebase Storage so they sync to your team and devices. They are stored privately, used only to show those images inside the app, and deleted from storage when you delete the associated client, appointment, or salon.
Booking-page logo and cover banner are different: because your booking page is public, these two images are stored so that anyone with the page link can view them. They are business branding you choose to publish, not private client photos. As noted above, embedded metadata is stripped from them on upload.
Face data
Lash Create uses Apple's on-device Vision framework (specifically VNDetectFaceLandmarksRequest) to automatically detect where each eye sits in a photo you take or select. The detection produces only 2D pixel coordinates that describe the position, approximate width, and rotation angle of each eye in the image.
No facial recognition is performed. No biometric identifiers (face descriptors, face vectors, faceprints, or any equivalent) are created, stored, or transmitted. The eye coordinates are used for one purpose only: to automatically place lash extensions on the correct position over each eye so you don't have to drag them into place manually.
The eye coordinates exist only in memory during the current editing session. They are not saved to disk, exported, transmitted to a server, shared with any third party, or used for any purpose other than positioning lashes. They are released from memory as soon as you close the editor, open a different photo, or quit the app.
If you save a design, the saved file is the composited image (your photo with the lashes drawn on it). The underlying eye coordinates are not included in any saved file.
Subscriptions & payments
Lash Create offers auto-renewable subscriptions (Premium for the design tool, and Individual and Salon plans for Business). These app subscription payments are processed by Apple via the App Store, and we never see your payment information. (Payments a salon takes from its own clients are separate and handled by Stripe — see Online payments above.)
We use RevenueCat to manage subscription status and entitlements. When you subscribe, RevenueCat receives your purchase details from Apple (such as the product, price, currency, and Apple's purchase receipt) and an identifier for your account (your account's unique identifier for Business plans, or an anonymous identifier otherwise). This is used only to determine whether your subscription is active and which features to unlock.
Apple's handling of purchase data is governed by Apple's Privacy Policy, and RevenueCat's by RevenueCat's Privacy Policy.
Advertising, analytics & tracking
We use two measurement tools to understand how people find and use the app:
- TikTok Business SDK — measures which of our ads lead people to install and subscribe. Through it we collect your device's advertising identifier (IDFA, only if you allow tracking), a TikTok-assigned identifier, install/launch/session activity, and purchase conversion events (product, price, currency). This data is shared with TikTok and may be used to track you across other companies' apps and websites for advertising attribution.
- Firebase Analytics (Google) — measures in-app usage (such as which screens and features are used and the steps of the onboarding and purchase funnels) to improve the app. Events include product identifiers and basic interaction data, not your name, your clients' details, or your photos.
Because the TikTok SDK involves tracking, iOS asks for your permission through the App Tracking Transparency prompt. If you choose "Ask App Not to Track," your IDFA is not shared and measurement relies on Apple's privacy-preserving methods (SKAdNetwork) instead. You can change this any time in Settings → Privacy & Security → Tracking.
TikTok's handling of this data is governed by TikTok's Privacy Policy, and Google's by Google's Privacy Policy.
Permissions
Lash Create requests the following permissions and uses them only for the stated purpose:
- Camera — to capture a new photo for lash design or a client record.
- Photos (Read) — to let you pick an existing photo from your library (for a lash design, a client record, or your booking-page logo and cover banner).
- Photos (Add) — to save your finished designs to your iOS Photos library when you choose to.
- Notifications — if you enable them, to remind you about upcoming appointments and rebookings (scheduled on your device), and to alert you to new messages and booking requests (sent as push notifications via Firebase Cloud Messaging).
You can revoke any of these permissions at any time in iOS Settings.
Service providers
We share data only with the providers needed to run the app, and only for that purpose:
- Apple — App Store subscription payments and push-notification delivery.
- Google (Firebase) — account authentication, cloud database (Firestore), file storage (Firebase Storage), push notifications (Cloud Messaging), and analytics, for Business plans and app measurement.
- Stripe — processing the payments a salon takes from its own clients (deposits, full payment, no-show fees, gift cards, and bundles).
- RevenueCat — subscription status and entitlement management.
- Resend — sending account emails and booking-page confirmation emails on our behalf.
- TikTok — advertising measurement and attribution.
Data retention & deletion
You stay in control of your data:
- Client and salon records. You can delete individual clients, appointments, or other records from inside the app at any time; deleting a record also deletes its associated photos from cloud storage.
- Your account and salon. To delete your account and the salon data associated with it, contact us at support@lashcreate.app and we will delete it.
- Subscriptions. You can cancel any time in iOS Settings; cancelling does not delete your data.
Security
Data sent to and from the cloud is encrypted in transit. Account access is protected by your email and password, and salon data is restricted so that only the salon's active owner and staff can access it. No method of storage or transmission is completely secure, but we take reasonable steps to protect your information.
International transfers
Our service providers, including Google, Stripe, RevenueCat, and TikTok, may process data on servers located in the United States and other countries. Where data is transferred internationally, those providers apply appropriate safeguards.
Children
Lash Create is not directed to children. We do not knowingly collect personal information from children under 13, and the advertising measurement described above relies on tracking only where permission has been granted through iOS. If you believe a child has used the app, contact us and we will help.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available at this URL. The "Last updated" date above will reflect any changes.
Contact
Questions about this Privacy Policy, or a request about your data? Email support@lashcreate.app — we reply within 1–2 business days.