Mien Shiang Reflection

Privacy Policy

11 August 2026 · closed-test draft pending external review

The short version. A scan photo, its pixels, numerical measurements and the temporary 478-point face map are processed on your device and discarded after an accepted scan. Only allow-listed categories and three reflection sentences remain in one padded, encrypted local vault. The consumer app does not send scan data or reflection content to a server.

Scan processing and local history

When you use the live mirror, it is analysed on your device in temporary memory. The photo, pixels, face map and numerical measurements are not transmitted, are not uploaded, and are not written to IndexedDB. Before the reflection appears, categorical palace states, a baseline element, a coarse confidence band and the three sentences are committed inside one AES-GCM encrypted, padded vault blob.

The app asks the browser for persistent storage when you create the vault and checks that status at unlock. A grant reduces ordinary storage-pressure eviction but cannot prevent you from clearing site data or removing the app. If persistence is unavailable or denied, the app offers an encrypted .vault backup. Export remains recommended after a grant.

Vault security boundaries

Cryptography and IndexedDB run in a same-origin module Worker. Ordinary session keys are non-extractable Web Crypto keys. Browser isolation and this design reduce key-extraction and metadata risks; they cannot defeat active script injection while the vault is unlocked, compromised browser or operating-system software, user-initiated deletion, or physical extraction and offline guessing of a weak six-digit PIN wrapper. Memory overwriting is best effort, not guaranteed.

Optional product analytics

Product analytics is a separate, unchecked choice. If selected, a first-party endpoint operated with Cloudflare Worker and D1 receives a random installation identifier and operational events: app open, scan start, completion or abstention, reading view, share start or completion, consent withdrawal, and fatal error. Event properties are limited to app/platform version, random session identifier, coarse device tier, live-or-upload capture path, bounded failure code and duration band.

Product analytics does not receive a photo, pixels, face map, landmark, facial measurement, exact or coarse skin-tone value, reading, palace, element, compass value or spiritual result. Raw events are scheduled for deletion after 60 days; anonymous daily counts are scheduled for deletion after 395 days. Turning analytics off revokes local consent and requests deletion of the installation registration and its raw events. If offline, that deletion request is retained locally and retried.

Separate QA evidence build

Invited adult testers may receive a visibly marked QA build with a separate participant information sheet and consent. Its separate database receives a hashed participant code, attempt/completion/abstention, light/medium/deep/unknown coarse tone cohort, duration band, device/platform class, capture path and bounded failure code. It excludes photos, maps, exact colour values, measurements and readings. QA events are scheduled for deletion after 90 days and can be deleted through the QA study control.

Services and features not active

The pinned MediaPipe runtime and model are served from the same origin as the scanner rather than a model content network. Cloudflare acts as infrastructure processor only for the optional operational analytics and the separately consented QA study.

Consent, age and control

The closed test is for adults aged 18 or older. Camera/face processing consent, optional product-analytics consent, and QA-study consent are separate. Declining either optional data flow does not prevent normal scanning. Device camera permission can be revoked in system settings.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, and to data portability. The in-app controls erase local readings and optional event registrations. Requests concerning server-side optional events require the app’s random credential; the service intentionally has no account, name or email with which to identify an installation.

The app does not use facial geometry to verify or identify a person, compare different people, or infer race, religion, political views, sexuality, health, emotion, character or destiny. It does not sell personal information.

Regional disclosures

Australia. We treat the temporary face map conservatively as sensitive information for the purposes of the Privacy Act 1988 and Australian Privacy Principles. Explicit consent is requested before it is generated. Optional operational events do not contain it.

European Union and United Kingdom. Where GDPR applies, explicit consent is the lawful basis for temporary face processing and consent is also obtained separately for optional events. Applicable rights may include access, correction, erasure, restriction, objection and portability.

California. For CCPA/CPRA purposes, we do not sell personal information or use cross-context behavioural advertising. The app has no account and optional events are not linked to your identity.

Illinois. This BIPA disclosure is not a claim of exemption. No photo, face map or facial measurement is sent to the operator, sold, leased or traded.

Changes and contact

A material change to scan processing or optional data collection requires an updated policy and consent version before collection begins. The production contact address and controller identity must replace the placeholder below before external testing.

privacy@[yourdomain].com · privacy requests will be answered within 30 days.