Policy

Privacy Policy

This Privacy Policy explains how Gillian Sarah handles personal information when you use our AI makeup tutorial reel service.

Who we are

GILLIAN SARAH LIMITED operates Gillian Sarah at gilliansarahs.com. You can contact us at support@gilliansarahs.com.

Information we collect

We collect account details, billing identifiers, prompts, uploaded selfies, product shelf photos, mood boards, generated images, generated videos, support messages, device data, cookie preferences, and usage records such as credit balance, asset delivery status, and plan history.

How we use information

We use information to provide the product, parse your look request, generate candidate images and reels, maintain credits, process payments, prevent abuse, provide support, comply with law, and improve reliability. Private uploads are not used to train foundation models.

Legal bases under GDPR

Where GDPR or UK GDPR applies, we process account, generation, billing, and support information to perform our contract with you, comply with legal obligations, protect legitimate interests such as fraud prevention and service security, and use consent where required for optional analytics or marketing.

Payments

Payments are handled by Stripe. We receive payment status, subscription status, invoices, refunds, disputes, and limited billing references. We do not store full card numbers.

Selfies and face-related content

Selfies are used to produce your requested makeup content and related assets. Do not upload another person unless you are that person or have clear permission. You may request deletion of stored uploads and generated assets, subject to fraud prevention, billing, and legal retention needs.

Sharing

We share information with service providers that support hosting, storage, AI generation, analytics, payments, fraud prevention, and customer support. We do not sell personal information.

International transfers

We may process information in the United Kingdom, the European Economic Area, the United States, and other locations where our providers operate. Where required, we use appropriate transfer safeguards such as standard contractual clauses or provider data processing terms.

Your rights

Depending on where you live, you may request access, correction, deletion, portability, objection, restriction, or opt-out of certain uses. Email us to exercise these rights.

CCPA and US state privacy rights

We do not sell personal information. If applicable law gives you privacy rights, you may request access, deletion, correction, portability, and opt-out from certain sharing or targeted advertising. We will not discriminate against you for exercising those rights.

Children and teens

The service is not for children under 13. Users aged 13 to 17 may use the service only with parent or guardian consent. We do not knowingly collect information from children under 13.

Retention and security

We keep information only as long as needed for the service, legal obligations, security, billing, and dispute evidence. We use administrative, technical, and organizational safeguards, but no online system is perfectly secure.

Deletion limits

A deletion request may not immediately remove records that we must keep for payment records, tax, fraud prevention, dispute handling, security logs, legal compliance, or backup integrity.

Effective date

This policy is effective 2026-05-02.