Privacy Policy
Last updated August 6, 2026
Your photo
Your selfie is processed entirely in your browser, on your device, the moment you select it. It is never uploaded, transmitted, or stored on any server. When you leave or refresh the page, it is gone. The share card you can generate is also drawn on your device.
Your quiz answers and result
Your reading — the tones measured from your photo, and the three numbers described under Payments below — along with your unlock status and, if you arrived through one of our links, a one-word source tag (like "tt"), are saved in your browser's local storage so your result is still there when you come back. Your season name is saved there only once you have bought the report, because until then your browser has not been told it. This data stays on your device — we never see it, with one exception you control: if the tones we measured look wrong to you and you say so, we ask whether we may send those colour values (the hex codes and the warmth, depth and clarity numbers) so we can improve the reading. Nothing is sent unless you agree, and what is sent carries no photo and nothing that identifies you. Clearing your browser data removes it (if that locks your paid report, contact us and we'll restore your access).
Payments
The full report is purchased through Stripe, our payment processor. Stripe collects the information needed to process your payment (such as your card details and email address) under Stripe's privacy policy. We never see or store your card number. We can see the receipt email you used at checkout, which we use to send you your report copy and to handle support and refunds.
If you buy the report, the checkout URL carries a one-word source tag (like "tt" or "friend") so Stripe can show us which link brought the purchase, and three numbers from your reading: whether your undertone read warm or cool, and how deep and how clear your coloring measured. They look like a1325000365000. We send those rather than your season name because your season is worked out on our server at that point, not in your browser — the same three numbers are already shown to you, in words and swatches, on your result screen. The checkout URL never contains anything that identifies you.
Anonymous usage analytics
We use PostHog, a product analytics service, in cookieless mode to count how HUE is used — pageviews and steps like "quiz started," "selfie analyzed," or "checkout clicked." PostHog runs with no cookies and no stored identifier of its own: nothing PostHog uses persists on your device, so PostHog cannot link separate visits to each other, let alone to you. The analytics see that a selfie was analyzed, and which season the analysis landed on — never the selfie, never the tones it measured, never your individual answers. Events are received by PostHog (PostHog's privacy policy) on our behalf.
Advertising
We advertise HUE on Facebook and Instagram. So those ads can be measured and shown to people who have already visited, this site loads the Meta pixel. It stores a first-party cookie named _fbp in your browser for 90 days, refreshed on each visit, and sends Meta your IP address, the page you are on, and which step you reached — for example "checkout clicked" or "purchase," with the amount. If you have a Facebook or Instagram account, Meta can connect that activity to it. That is cross-site tracking, and we are naming it plainly because it is the one place HUE is not private by default.
The pixel never receives your selfie, the tones measured from it, your individual answers, or your season. We deliberately withhold the season: it is an inference about your appearance, and it is not Meta's business.
We enable Meta's Limited Data Use setting, which restricts how your information is processed if you are in a US state whose privacy law provides for it.
To switch it off:
That stops the pixel loading at all on this device — no cookie is set and nothing is sent. We also honour Global Privacy Control automatically, so if your browser sends that signal you are already opted out and need do nothing here. Separately, Meta's own ad preferences control how it uses activity businesses send it.
What we don't do
- No user accounts and no sign-ups — we don't collect your name or email to use HUE.
- No ad trackers, no tracking cookies, no cross-site tracking, no session recording.
- No session recording, and no analytics cookies. We do run one advertising cookie for the Meta pixel — described in Advertising above; it is the only cookie this site sets.
- No selling, renting, or sharing of personal information — we don't hold any.
- We never sell or rent your personal information. Running the Meta pixel does count as sharing for cross-context behavioural advertising under California law — see Advertising above, including how to switch it off.
Third-party services
Like most websites, a few infrastructure providers technically receive your IP address when they serve you content:
- GitHub Pages hosts this site (GitHub's privacy statement).
- Stripe handles checkout, as described above.
- Resend sends your report email after a purchase — it receives the address you gave Stripe at checkout and your season's report content (Resend's privacy policy). The hand-off runs through a small function of ours hosted on Cloudflare; it stores nothing.
- PostHog receives the anonymous, cookieless usage events described above.
- Meta (Facebook/Instagram) receives the advertising events described under Advertising, together with the
_fbpcookie it sets and your IP address (Meta's privacy policy).
Children
HUE is not directed at children under 13, and since we collect no personal information through the site itself, none is knowingly collected from anyone.
Changes
If this policy changes, the new version will be posted here with an updated date. A change will never retroactively apply to data we don't have.
Contact
Questions? Email support@huebloom.app.