Acupoint (the “App”) · Last updated: 18 September 2026 · Version 2.0.0
This Privacy Policy explains what information the Acupoint app collects, how it is
used, and the choices you have. Acupoint provides facial acupoint learning and
guided facial care, including optional camera-based guidance.
1. Who we are
Acupoint is operated by the developer of the App (“we”, “us”). If you have any
questions about this policy or your data, contact us at
support@acupoint.app.
2. Information we collect
Account information. If you choose to sign in, we use
Sign in with Apple or Google Sign-In. We receive a user identifier
and, depending on what you allow, your name and email address. Signing in is
optional; you can use core features as a guest.
Favorites and legacy progress. Favorites and older habit
profile/progress records are stored on your device when you use the App as a
guest. Signing in enables account-based cloud synchronization of that content.
Facial care records. The full facial care session history,
including completion dates, routes, and your optional comfort response, is stored
locally on your device. It is separate from legacy cloud-synced progress.
Limited events about the session, including the selected route and an optional
comfort response you submit, are also sent to analytics. These responses are
optional and are not camera recordings or a medical assessment.
Purchases. Apple processes the Acupoint Plus one-time purchase
and the monthly/yearly facial care subscriptions. We use verified transaction
and entitlement information to unlock and restore access. Analytics may include
product and transaction identifiers, purchase outcome, currency, and price.
We do not receive your payment-card details.
Usage and diagnostics. Firebase services collect usage events,
such as screens opened, searches entered in the App, feature interactions, session
duration, and notification interactions, together with app/installation identifiers,
device and operating-system information, and general location derived from network
information. Crash reports include stack traces and diagnostic information.
Starting with version 2.0.0, the App does not set your login account ID as the
Analytics or Crashlytics user ID. We clear values set by older versions and no
longer attach the push token to crash reports. SDK identifiers remain, so this
does not mean all analytics are anonymous or that no data is collected.
Notifications. Messaging services use installation identifiers
and push tokens. When eligible and enabled, a token is associated with your signed-in
account to deliver notifications. Local facial care reminders are scheduled on
your device. Turning off notification permission stops notification delivery; it
does not by itself disable all Firebase analytics or installation identifiers.
Feedback. If you send feedback, we receive your account ID,
message, feedback category, app and operating-system versions, device model,
submission time, and any contact information you choose to include, so we can
investigate or respond. Avoid including sensitive information in free-text fields.
Camera (AR features only). The front camera and face tracking
support facial acupoint positioning and facial care route guidance.
Camera frames and face geometry are processed in real time on your device;
the App does not record, store, or upload them to us or third parties.
3. How we use information
To provide your account, sync favorites and legacy progress, and keep local facial care records.
To unlock and restore purchases and subscriptions.
To understand usage, respond to feedback, and fix problems.
To configure feature availability and compatibility through Remote Config.
To send the reminders/notifications you have opted into.
To contact you about your use of the App, including occasional invitations to
take part in optional user research such as an interview or a short set of
questions. Taking part is always voluntary, is never required in order to use
the App or to receive support, and never involves a purchase. You can decline
or opt out of these invitations at any time by replying to the message or
writing to support@acupoint.app, and
we will not contact you for research again.
We do not sell your personal data, and we do not use your data for
third-party advertising.
4. Service providers
We rely on the following providers, who process data on our behalf:
Apple — Sign in with Apple, App Store purchases, push
notification delivery.
Google Firebase (Google LLC) — authentication, cloud database
for syncing account content and receiving feedback, analytics, crash reporting,
remote configuration, and messaging.
Google Sign-In (Google LLC) — optional account sign-in.
These providers handle your data under their own privacy policies and applicable
data-processing terms.
Google Analytics account-level data-sharing settings also allow Google to use
Analytics data for service improvement, aggregated business insights, technical
support, and account recommendations under its applicable terms. Google signals
and advertising personalization are disabled for this App's Analytics property.
Disabling these features does not remove analytics data already collected.
5. Data retention & deletion
You can request account deletion in Settings → Delete Account. This removes
the authentication account and associated cloud profile, favorites, legacy progress,
push-token records, and submitted feedback through the App's deletion flow. If an
error is reported, deletion may not have finished; retry or contact us. Uninstalling
the App alone does not delete your cloud account. Local facial care history can be
cleared in the App's data settings.
Clearing an SDK user ID, signing out, or deleting an account does not retroactively
erase analytics or crash reports already collected, including records sent by older
versions or queued for upload. Those records are subject to the service's retention
settings and deletion processes; local records and cloud account deletion are
separate. Deleting an account also does not cancel an Apple subscription; manage
subscriptions in your Apple account settings. For a copy or deletion request,
contact support@acupoint.app.
6. Children’s privacy
Acupoint is not directed to children under 13 (or the equivalent minimum age in
your country), and we do not knowingly collect personal data from them.
7. Data security & international transfer
We use reputable providers (Apple, Google) that apply industry-standard security
measures. Your data may be processed on servers located outside your country,
including the United States, with appropriate safeguards.
8. Your rights
Depending on where you live (for example under GDPR or CCPA), you may have the
right to access, correct, delete, or export your personal data, and to object to
certain processing. To exercise these rights, contact
support@acupoint.app.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last
updated” date above and, where appropriate, notify you in the App.
18 September 2026. We added user-research contact to Section 3, so
that we can invite people who use the App to take part in optional interviews or
answer a few questions about their experience. Participation is voluntary and you
can opt out at any time. No other data practice changed.