Last updated: 15 September 2026
FroMe is a hairstyle app. Its main feature, try-on, shows you what a hairstyle would look like on you, which means it works with photographs of your face. This policy explains what we do with those photographs and with everything else you give us.
The service is provided by JDM Welzijn, a sole proprietorship registered in the Netherlands ("FroMe", "we", "us"). We are the data controller for the information described here. You can reach us at info@frome.app.
The short version. We use your face photo for one thing: making your try-on image. To do that we send it to one third-party AI service, Google's Gemini API, which is contractually bound to protect it to the same standard this policy sets out. We ask your permission in the app first. We do not sell it, we do not advertise with it, and we do not keep the photo you took. The finished try-on is saved to your account, deleted automatically after 365 days, and you can delete it — or your whole account — from inside the app at any time.
This is the part of the app that handles sensitive information, so it is first.
When you start a try-on, the app takes a photograph of your face using your device camera, and you position the hairstyle you picked over it. We ask for your explicit agreement before the camera opens the first time — on a screen that names the AI service your photo will be sent to and says exactly what is sent — and we record the fact, the date and the wording of that agreement on your account. The camera does not open until you agree, and declining leaves the rest of the app fully usable.
Two things leave your device when you tap the shutter: the photograph of your face, with the hairstyle you positioned drawn on top of it, and the description of the hairstyle you chose. Nothing else goes with them — not your name, not your email address, not your account identifier, not your device identifiers, not your location.
They are sent to one third-party AI service: Google's Gemini API (Google Ireland Limited / Google LLC), which generates the finished try-on picture and returns it to us. Google is the only third party that ever receives your face data.
Generating your try-on image is the only purpose. We do not use your face data to identify you, to build a faceprint, template, scan or other biometric identifier, to match you against other people or other photographs, to train any model of our own, or for advertising or any form of profiling. We do not sell or rent it, and we do not disclose it to anyone except as described here or where the law compels us to.
Google, in two capacities: the Gemini API, which generates the try-on, and Google Cloud / Firebase, where the app's infrastructure runs and the finished image is stored. Nobody else receives your face data.
Any third party with whom we share face data will provide the same or equal protection of that face data as stated in this privacy policy. Google is bound to that standard by a data processing agreement, which requires it to process your face data only on our documented instructions — that is, solely to generate your try-on — to keep it confidential, to apply appropriate technical and organisational security measures, not to use it to train or improve its models, not to use it for any commercial purpose of its own, and to delete it once processing and the abuse-detection window described below have passed. If a provider will not give us that commitment, we do not send them your face data.
We do not store the photograph you took — it is sent for processing and not written to our storage. The finished try-on image is saved to your account so you can come back to it, and:
Google keeps it for up to 55 days, and only to police its own service. Under the paid Gemini API terms, what we send is retained for a maximum of 55 days so that Google can detect abuse of the service and meet legal obligations it is under, and is then deleted. This window is set by Google and cannot be shortened or switched off by us. It is not used to train or fine-tune Google's AI models, other than the systems Google uses to enforce its own abuse policies. We have separately left Google's optional developer logging switched off, so no copy of your photograph is kept on our behalf or available to us.
We spell this out rather than saying the photograph disappears the instant your try-on is made, because that would not be true, and you should be able to rely on what this page tells you.
This is our written retention schedule and destruction policy for biometric information, published here as some jurisdictions require. We destroy the information when the purpose above is satisfied, or at the 365-day deadline, whichever comes first.
To revoke consent: open Profile → Face data for try-ons → Withdraw. We stop using face photographs immediately and the camera will not reopen until you agree again. Withdrawing does not undo processing already carried out before you withdrew, and it does not delete the rest of your account.
To delete your face data: withdrawing asks you, in the same step, whether your saved try-on images should be deleted too — your choice either way. You can also delete individual try-ons at any time from Profile → Your saved try-ons, and Profile → Delete account erases every try-on image and the consent record along with the account, immediately and permanently. None of these require you to contact us; if you would rather we did it, write to info@frome.app and we will action it within one month.
| What | Why | How long |
|---|---|---|
| Email address, and your name if your sign-in provides one | To create and secure your account | Until you delete your account |
| Sign-in identifiers from Apple or Google, if you use them | So you can sign in without a password | Until you delete your account |
| Your hair profile — gender, hair type, hair length | To recommend styles that suit you | Until you delete your account |
| Saved looks, collections and saved products | So your saved items are there next time | Until you delete them, or your account |
| Subscription status and try-on count | To unlock FroMe Pro and apply the free allowance | Until you delete your account |
| Technical logs from our servers — timestamps, error records, coarse device data | To keep the service running and diagnose faults | Up to 30 days in our infrastructure logs |
We do not run advertising, we do not track you across other companies' apps or websites, and we do not use third-party analytics or advertising identifiers.
FroMe Pro is billed by Apple or Google, not by us. Your card details never reach us. We use RevenueCat to tell us whether your subscription is active; it receives an anonymous identifier and your purchase status, and nothing about your face or your photos.
Each acts on our instructions under a data processing agreement that obliges it to protect your information to a standard no weaker than this policy describes. RevenueCat, Apple and Google Play never receive your face data, your photographs or your try-on images. Some processors are based in the United States, so your information may be transferred outside your country; those transfers rely on the European Commission's standard contractual clauses or an equivalent safeguard.
If you are in the UK or EU, we rely on:
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. Two of these are immediate and do not require asking us:
For anything else, write to info@frome.app. We respond within one month. If you are unhappy with our response you can complain to your data protection authority — in the UK, the Information Commissioner's Office.
You must be 13 or over to use FroMe, and you confirm this before your first try-on. If you are under 16, ask a parent or guardian before you use the app. We do not knowingly collect information from anyone under 13; if we learn that we have, we delete it.
Because families do use the app together, we allow a parent or legal guardian to create a try-on of their own child, and they must confirm that relationship before the camera opens. Nobody may photograph another person — child or adult — without being their parent or guardian, or without their agreement. If you believe a child's information has reached us any other way, contact us and we will delete it.
Traffic between the app and our servers is encrypted in transit, and stored files are encrypted at rest by Google Cloud. Your try-on images sit in a folder that only your signed-in account can read or write. API keys live in a managed secret store, never in the app.
If we change how we handle face photographs, we will ask for your agreement again inside the app before the next try-on — a new agreement, not a silent update. Other changes will be posted here with a new date at the top.
JDM Welzijn
Marga Klompelaan 41
1046 TV Amsterdam
the Netherlands
info@frome.app