Back to Droplet

Private skincare decisions need a plain privacy posture.

Effective date: June 16, 2026. Droplet uses personal skin, product, and routine context to generate scans, reports, and routine guidance. This policy explains what information may be processed, why it is used, when it may be shared, and how users can request deletion or other privacy help.

Who this policy covers

This policy applies to Droplet websites, mobile applications, support channels, and related services. Droplet provides ingredient, formulation, routine, and profile-fit guidance for skincare products. It is not a medical device and does not provide medical diagnosis or treatment.

Early support and privacy operations are handled through parent company Synetra Systems.

The official public brand reference for this service is Droplet Skincare at joindroplet.com.

Information Droplet may use

Account and subscription

Account identifiers, authentication details, device and app information, subscription status, purchase entitlement metadata, support requests, security signals, and sync metadata.

Product evidence

Product photos, label images, ingredient lists, directions, product categories, scan outputs, saved products, and generated reports.

Skin context

Skin type, sensitivity, goals, allergies, avoid-list, age range, gender, climate context, routine preferences, and other profile details the user chooses to provide.

Routine memory

Products in routines, reminder times, completed steps, skipped steps, adherence history, saved products, notes, and settings.

App diagnostics

Crash logs, performance data, feature usage, approximate device information, and reliability signals used to maintain and improve the service.

How information is used

  • To create label scans, ingredient explanations, claim checks, risk summaries, and profile-aware verdicts.
  • To place products into morning, evening, or night routines with relevant usage cautions.
  • To remember saved products, past reactions, routine history, skipped products, and user preferences across supported devices.
  • To send reminders or notifications only when users enable them.
  • To provide support, maintain reliability, detect abuse, prevent fraud, manage subscriptions, and improve product safety.
  • To comply with applicable law, enforce terms, and respond to lawful requests.

Permissions

  • Camera access is used to scan product labels and packaging when the user chooses to scan.
  • Photo library access is used only when the user chooses to upload or select an image.
  • Notifications are used for routine reminders and app updates when enabled by the user.
  • Users can change app permissions in iOS or Android device settings.

Sharing and service providers

Droplet may share information with service providers that help operate the app, such as cloud hosting, authentication, database storage, image processing, AI processing, analytics, crash reporting, customer support, and subscription entitlement services. These providers are allowed to process information only to provide services to Droplet, protect the service, or comply with law.

Droplet may also disclose information if required by law, to protect users or the service, during a business transfer, or with the user's direction or consent.

Advertising and sponsorship

Droplet does not sell personal skincare profile data for advertising. Droplet does not use sponsored ranking, affiliate steering, or brand-paid placement as the basis for product guidance. If this changes, the policy and user-facing disclosures will be updated before using personal data for that purpose.

AI processing

Droplet may process product photos, label text, profile details, and routine context through automated systems to generate reports and suggestions. Outputs can be incomplete or wrong, especially when labels are unclear, product information changes, or user context is missing. Users should review outputs before acting on them.

Public guidance standards are described in Droplet editorial standards.

Retention and deletion

Droplet keeps information only as long as needed to operate user-facing features, provide support, satisfy legal or security obligations, maintain reliable sync, and resolve disputes. Deletion requests remove eligible account, report, routine, profile, and product-photo data unless retention is required for security, billing, legal, fraud-prevention, or dispute-resolution reasons.

User controls and rights

  • Access, correct, export, or delete eligible account, report, routine, and profile information.
  • Withdraw optional permissions such as camera, photo library, and notifications through device settings.
  • Request account deletion through the app or the public support page.
  • Opt out of marketing communications where applicable.
  • Appeal, object, restrict, or complain to a regulator where local privacy law provides those rights.

Security

Droplet uses reasonable administrative, technical, and organizational safeguards designed to protect personal information. No internet or mobile service can guarantee perfect security, so users should keep account credentials and device access protected.

International transfers

Droplet and its service providers may process information in countries other than the user's country of residence. Where required, Droplet relies on appropriate safeguards for cross-border processing.

Children

Droplet is not directed to children under 13, or the age of digital consent where a higher age applies. If a parent or guardian believes a child provided personal information, they can contact support to request deletion.

Changes to this policy

Droplet may update this policy as the product, law, or platform requirements change. Material changes will be reflected by updating the effective date and, where appropriate, providing additional notice in the app or on the website.

Contact and deletion requests

For privacy requests, account deletion, or questions about this policy, email support@synetrasystems.com, use the public Droplet support page, or use the in-app support flow. Include the account email or account identifier when possible so the request can be verified.