Privacy
What we collect, why, and how to get rid of it.
Last updated 17 September 2026.
Short version: we collect what your plan needs and nothing else, we do not sell it, we do not advertise to you, and there is no third-party analytics on this site. If you want your data gone, email us and it is gone.
What we collect
Session bookings. When you book a session, we collect your name, email, country of residence, chosen time zone and appointment time, and any optional notes. For USA-only events we also record your eligibility confirmation. We use this information to arrange your session, send its calendar invitation, notify your host, and send confirmation, change and reminder emails. Booking does not subscribe you to marketing. Your name, email and appointment details are shared with Google Calendar and Google Meet to arrange the meeting. Your private management link lets you reschedule or cancel without creating an account. Contact hello@hairyoulove.com from your booking email to request a copy or deletion of your booking information.
A little about you. After account verification, we ask for a first name, gender, age range and approximate home location. These help us greet you in your local time and choose relevant hair-care questions and seasonal context. Name and location can be left blank; gender and age include a prefer-not-to-say choice. We do not infer medical conditions from these answers or collect your birthday.
Your answers to the consultation. What you tell us about your hair, your routine, your goals and your preferences, including anything you type into a free-text box. This is the substance of your plan.
Your email address, so we can verify your account, send you a sign-in link and tell you when your plan is ready. We ask for it in order to save your progress; it is how you get back to your plan on another device. If you sign in with Google instead, Google tells us the email address of the account you chose and that it is verified, plus an identifier for that account so we recognise it next time. We also request basic profile information so we can suggest your first name. You can change or remove that suggestion before saving it. We do not keep your picture or other Google profile details.
An email address you give us with a product request, if you ask us to add a product to the library and choose to leave one. It is used for exactly one message — telling you that product is in the library — and for nothing else. Leave it blank and the request still goes in.
An approximate location, from the network request your browser makes. Our hosting provider tells us the country, the city or region, and a latitude and longitude rounded to the nearest whole degree — roughly a sixty-mile square. We use the city or region and time zone for a local greeting and broad seasonal context, such as humidity and dry air. Location does not establish your tap-water hardness or the weather right now. You can correct or override it during the consultation, and you can leave it out.
How you moved through the consultation — which questions were answered, where people stop, how long it took. We use it to fix the parts that are confusing. It is stored against your consultation, not against an advertising profile, and it never leaves our own database.
Cookies for sign-in and site use. hyl_auth is set only after you sign in and keeps you signed in for ninety days; it is marked HttpOnly, Secure and SameSite=Lax, which means scripts cannot read it and it is not sent along with requests from other sites. hyl_vid is a random identifier with no meaning outside this site, kept for a year, used to count visitors and to understand which pages lead people to the consultation. It is not shared with anyone, and it is linked to your email address only if you give us one. There is no advertising cookie, no tracking pixel, and no third-party analytics on this site. (Email verification uses hyl_code, a secure, HttpOnly cookie lasting up to ten minutes that ties the code to the browser requesting it. Verification records are removed daily once they are more than two days old. If you sign in with Google, hyl_oauth exists for the ten minutes the hand-off can take and is then discarded.)
After a successful sign-in, hyl_signin_hint remembers your email address and whether you last used Google or email on this browser for up to a year. This lets us prefill your email and highlight Google when you return. It remains after signing out, but cannot sign you in or give access to your account. Deleting your account clears it on this browser; you can also remove it in your browser settings.
Feedback you send us. Every page has a small “Send feedback” circle. If you use it, we keep what you wrote, and — so we can understand it — a reconstructed image of the page as it looked when you opened the form, the last few minutes of your clicks and page changes on this site (as control names and page addresses, never what you typed or answered), any errors your browser reported, the timing of the requests it made, your browser and screen details, and, if you are signed in, your name and email. The image is built in your browser from the page itself: typed text and your private profile content are masked before it is made, you can look at it and remove it before sending, and nothing is sent until you press Send. If you are not signed in you can leave an email address for a reply; we do not verify it and it is not linked to any account. This is separate from the measurements below and is not used for them. If your browser sends Global Privacy Control we keep no history of your actions and only what you submit with the form. Feedback, its image and its diagnostics are kept for ninety days and then deleted; the notification email we send ourselves about it is deleted from our mailbox on the same schedule. Deleting your account deletes your feedback and its images immediately. A copy of your feedback is included in your account export.
What we measure
On every page we record which page it was, which links were clicked, roughly how long the page was open and how far down it was read, the site you arrived from, the approximate location described above, and whether you are on a phone, a tablet or a computer. Inside the consultation we record your progress through it. We never record what you typed, and we never record the content of your answers as part of this.
To keep our own testing out of these figures, we associate browser activity with a private, hashed network identifier for up to ninety days. When an administrator signs in, we remove matching activity and exclude that network for a year. We do not store raw IP addresses in these analytics records.
We keep the individual records for ninety days and the daily totals indefinitely. All of it stays in our own database; none of it is sold, shared or used to advertise to you anywhere. That “never record what you typed” promise is about these measurements; what you type into the feedback form is, of course, the feedback.
If your browser sends the Global Privacy Control signal, we set no identifier and record none of this. You can also clear the cookie at any time from your browser settings; a new one is only created if you come back.
A first name and an age range, if you give them: the name so your profile can greet you, the range because hair changes over the decades and some questions only apply at some ages. We never ask for a date of birth, and we never ask about your health beyond what the consultation’s own answer options collect.
How your plan is made
Your answers are analysed by our sophisticated, research-backed system and by service providers acting on our behalf, and combined with our researched product library to produce your plan. The analysis is automated. Your personal hair consultation is based on the answers you provide and our researched product library. It does not physically test your hair and it is not a medical diagnosis.
No decision made here has a legal effect on you. If you would rather a person looked at something, email us and one will.
Who else touches it
These companies process data on our behalf, under contract, for the purpose named and nothing else. We do not sell your data to anyone, and we do not share it with advertisers.
| Company | What they do |
|---|---|
| Supabase | Database hosting. Your answers, profile and plan are stored here. |
| Cloudflare | Website hosting, network security and email forwarding. Also the source of the approximate location described above. |
| Anthropic | Provides the automated analysis that turns your answers into written guidance. |
| Microsoft Azure | Sends our email — verification codes, sign-in links and plan notifications. |
| Stripe | Takes payment. Card details go to Stripe directly; we never see or store them. |
Google is different: if you choose Continue with Google, Google acts under its own terms, not ours. It confirms your email address to us and keeps its own record that you signed in to Hair You Love. Sign-in alone grants no calendar access. When you book a session, we send a Google Calendar invitation to your email address. Your host separately authorizes access to their calendar to check availability, create a meeting link and manage appointments. Only the host connects their calendar; participants do not need to grant us calendar access.
How long we keep it
Your answers, profile and plan stay for as long as you have an account, because that is what makes your plan readable when you come back. Sign-in links expire quickly and are single-use. The hyl_auth cookie expires after ninety days and hyl_vid after a year. Individual records of pages viewed are deleted after ninety days; only the daily totals are kept.
If you delete your account — in Account settings, or by asking us — we delete it. Records of a payment stay with Stripe, because tax and accounting rules require us to keep them.
We take a copy of our database every night so that we can recover from a disaster. Nightly copies are deleted after fourteen days and monthly copies after ninety days; a deleted account disappears from them on that schedule. Nobody reads those copies except to restore the service.
What you can ask for
Two of these you can do yourself, right now, in Account settings: download a copy of everything we hold about you, and delete your account and everything in it. Deleting is immediate in the live service and we cannot undo it for you; the backup copies described above expire on their own schedule.
For anything else — correcting something that is wrong, or a question about any of this — email hello@hairyoulove.com from the address on your account and ask us to:
- send you a copy of everything we hold about you;
- correct anything that is wrong;
- delete your account and everything in it.
We answer within one business day and act on deletion requests promptly. You do not need to give a reason.
Children
This service is for adults. We do not knowingly collect anything from anyone under 18. If you believe a child has given us information, email us and we will remove it.
Security
Traffic is encrypted in transit. There are no passwords on this site to be stolen — signing in works by a single-use emailed link, or through Google, which never shows us your password. Card details never reach our servers.
No system is perfect. If something goes wrong that affects you, we will tell you what happened rather than wait to be asked.
Changes
If this policy changes in a way that affects what we do with your data, we will say so on this page and date it. This version is from 17 September 2026.
Contact
Email hello@hairyoulove.com.