1. Who we are
Stylogram helps people discover beauty artists and beauticians — hair, makeup, nails, mehndi and spa professionals — near them, message them, and book and pay for an appointment. You can reach us at support@stylogram.app.
Stylogram is the name under which this Service is operated, and it is Stylogram that decides why and how the personal data described here is processed — in the language of data-protection law, we are the data fiduciary (also called the controller) for it. Indian data-protection law governs how we handle it.
One address reaches us for all of this: support@stylogram.app. Use it to ask what we hold, to have something corrected or deleted, or to complain about how your data has been handled — mark a complaint “grievance” and it goes to the person responsible for answering it. We reply within 30 days. If our answer does not satisfy you, you may take the complaint to the data-protection authority.
2. Data we collect
We collect only what the Service needs to work:
- Account data — your name, email address and profile photo, provided when you sign in with Google or Apple, or the email address you verify with a one-time code. Sign-in is handled by Amazon Cognito; we never see or store your Google, Apple or email password.
- Device identifier — an anonymous, randomly generated ID stored on your device. We use it to apply the free guest search allowance before sign-in, and to detect abuse.
- Location — your approximate coordinates, only if you tap “search near me” and grant the permission. It is used to rank results in that session and is not stored against your account.
- Chat messages — everything you write in a conversation, and the replies you receive. Where a message was screened (section 4), we also store the original text of that message separately for a limited period, and a record that a warning was raised against your account.
- Booking records — the service, date, time, location and price of a booking, its price and refund terms, the payments and refunds against it, the completion code and whether it was used, any photos the artist attached as proof the work was done, what either of you wrote when cancelling or reporting a problem, and how we settled it.
- Content you submit — reviews and ratings, and, if you are an artist, your listing details: services, prices, photos, working areas and contact information.
- Usage and diagnostics — pages viewed, searches run, approximate location derived from your IP address, browser and device type, and crash or error reports.
We do not collect or store your card or bank details. A payment you make goes through our payment provider, which handles them.
3. How we use it
- To run search and show you relevant artists, including nearby results.
- To authenticate you and keep your account secure.
- To carry your messages between you and an artist, and to answer them with the Stylogram concierge.
- To screen messages automatically for contact details, as described in section 4.
- To take, hold, release and refund payments for a booking, and to settle a booking that is disputed.
- To publish the reviews and listings you choose to submit, and to let artists claim, verify and manage their listings.
- To detect, prevent and investigate fraud, spam and abuse, and to enforce our Terms & Conditions.
- To measure and improve the Service, diagnose faults and understand which features are used.
- To send you service messages — sign-in codes, claim verification, booking updates, completion codes, reminders and notices about changes to the Service. We only send marketing messages if you have opted in.
We rely on your consent for location access and marketing, on the performance of our contract with you for account, chat, listing and booking features, and on our legitimate interests for security, moderation, abuse prevention and product improvement.
4. Automated screening of your messages
Every message sent in chat is scanned automatically before the other person sees it — yours and theirs, in every language and script. What the scan looks for, what it does to the message, and why we do it, are set out in section 6 of our Terms & Conditions. This section is what it means for your data.
- The text of your message is checked against pattern rules, and then read by an automated language model that catches what the patterns miss. No person reads it as part of this step.
- If something is matched, the delivered message has that part replaced with a label, and we store the original text of your message as a separate record.
- That original is not returned to the other person, is not shown in the app to anyone, and is not part of the conversation either of you can read. It exists so a person at Stylogram can check a moderation decision.
- A member of our staff can read it, but only by deliberately opening it for a specific message from the moderation console, and every time that happens it is recorded in our logs.
- We also count the warning against your account and keep a pointer to the message it came from. The pointer holds no message text.
- Section 10 says how long each of those is kept.
Screening is automated and imperfect. It sometimes removes text that was not a contact detail, and sometimes misses one. It does not decide anything about your account on its own: an account is only warned automatically, and any suspension or removal is decided by a person who has looked at the messages.
5. The concierge, and how your messages are processed
The Stylogram concierge is an automated assistant. To answer you, we send a request to a large language model hosted by Amazon Bedrock, an Amazon Web Services product. What goes in that request is: your messages in that conversation, the concierge’s own earlier replies, and the artist’s published information — their service menu, hours, cancellation terms and review summary. Your email address, your phone number if we hold one, and the other party’s contact details are not sent.
The automated screening in section 4 uses a second, separate model, and it is the one component that sees the original text of a message before anything is removed from it.
- We do not use your chat messages to train models, and we do not sell or share them for advertising.
- Both models — the one behind the concierge and the one behind the screening — run on Amazon Bedrock, under our own Amazon Web Services account and our contract with Amazon. We send a request and use the reply; we do not store your message with the model provider, and we have not turned on any feature that would keep it there after the reply is produced.
- The screening model runs on an Asia-Pacific inference profile, so the original text of a screened message stays within that region. The concierge model runs on a cross-region profile, which is the disclosure in section 6.
- We keep no copy of a request to a model beyond the conversation itself, and no log of ours records the text of one.
6. Where your data is processed
We host the Service — accounts, listings, bookings, chat history and uploaded photos — in the Asia Pacific (Mumbai) region of Amazon Web Services.
Your chat messages are an exception, and this is the important disclosure in this policy. The model that powers the concierge runs on a cross-region inference profile, which means that the text of a message you send in chat, and the artist information sent with it, may be processed on Amazon Web Services infrastructure outside India — the provider routes the request to whichever of its regions can serve it. It is processed to produce a reply and is not stored there by us.
The model used for automated screening runs on an Asia-Pacific inference profile, so the original text of a screened message is processed within the Asia-Pacific region.
Some of our other providers — analytics, error reporting and content delivery — also process data on servers outside India. All of this is done under contract with the provider concerned.
Sending chat content abroad is a deliberate, disclosed choice rather than an accident of hosting, and this section is the notice of it — written before you send a message rather than buried after the fact. We send the message text and the artist’s published information, and nothing else: not your name, not your email address, not your phone number, and not the other party’s contact details. Everything travels encrypted, is processed to produce a reply, and is not stored outside the Mumbai region by us.
All of it happens on Amazon Web Services infrastructure under our contract with Amazon, which requires them to process what we send only on our instructions and to keep it secure. If you would rather nothing you write is processed outside India, do not use chat: search, listings, bookings, reviews and photos stay in the Mumbai region, and only the chat features send anything to a model.
7. Sharing
We do not sell your personal data, and we do not share it with advertisers. It is shared in three situations:
- With the other party to a paid booking. Once a booking is paid for and the payment is held, the customer receives the artist’s name, phone number, WhatsApp number, social profile and the exact appointment location, and the artist receives the customer’s name and email address. This is the only point at which either side receives the other’s contact details, and each side receives only the other’s.
- With service providers who process data on our behalf under contract — listed below.
- Where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim, or to protect the rights and safety of our users.
- Amazon Web Services — hosting, database, file storage and authentication (Cognito), in the Asia Pacific (Mumbai) region.
- Amazon Bedrock — the language models behind the concierge and the message screening. See section 6 for where they run.
- Amazon SES — the emails we send you, including booking updates and completion codes.
- Our payment provider — taking, holding, releasing and refunding booking payments, and handling your card or account details.
- MSG91 — SMS and WhatsApp messages, where we send them.
- Cloudflare — website delivery, caching and protection against abusive traffic.
- Google Analytics — aggregated usage measurement.
- Sentry — crash and error reporting.
- Google Maps and Places — place lookup and mapping when you search by area.
If our business is transferred, your data may pass to the acquirer under this policy.
8. What is public, and what is not
Reviews you post are public, and display the name and profile photo on your account alongside the rating and text. Artist listings — including services, prices and the contact details an artist chooses to publish — are public and may be indexed by search engines. An artist’s exact location is not public: the Service shows a rounded approximate position to everyone except a customer with a paid booking.
Your conversations and your bookings are private to the two of you and to Stylogram staff who need to see them to run the Service.
Photos uploaded to the Service — portfolio photos, and photos an artist attaches to a completed booking — are stored at web addresses that are not listed anywhere but are not password-protected. Anyone who has the address can open the image. Do not upload a photo of a customer without their agreement.
9. Cookies and similar technologies
We use browser storage to keep you signed in, to remember the anonymous device identifier behind the guest search allowance, and to hold your display preferences. Google Analytics sets cookies to measure usage. You can clear this storage or block cookies in your browser settings, though sign-in and the guest allowance will not work correctly if you do.
10. How long we keep things
- Account data — for as long as your account is open.
- Reviews and artist listings — until you or the listing owner remove them.
- Chat messages — for as long as the conversation exists. Deleting your account deletes the conversations you started (section 12).
- The original text of a screened message — 90 days from when you sent it, after which it is deleted automatically. The record pointing at it is deleted at the same time, so the evidence and the pointer expire together.
- The count of screening warnings against your account — for as long as the account exists. It does not expire, because “this account has been warned eleven times” is the moderation fact, and only the messages were ever given a lifetime. The individual warnings you can see the detail of will be fewer than the count once they are older than 90 days.
- Booking records, including payments, refunds, completion, dispute text and how we settled it — eight years from the end of the financial year in which the booking was settled. They are the record of money that changed hands, so deleting your account does not delete them.
- Diagnostic logs and analytics data — up to 14 months.
- The anonymous device identifier — expires on its own within 30 days.
Eight years is the period our accounting and tax records have to remain available for, and a booking is one of those records: what was charged, what was refunded, what was paid out and why. It is also what we would rely on if a claim about a booking were brought long after the appointment. At the end of that period a booking record is deleted or reduced to figures that identify nobody.
The 90-day deletions above happen on their own and are not extended: the original text of a screened message goes at 90 days whether or not anything about that conversation is still open. What survives is the booking record and what either of you wrote in the booking itself.
11. Security
Data is encrypted in transit with TLS and at rest in our databases. Access to production systems is restricted and authenticated. Reading the original text of a screened message is a deliberate, separately logged action rather than something that happens when a moderation page loads. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
12. Your rights and choices
- Access and portability — request a copy of the personal data we hold about you.
- Correction — update your profile in the app, or ask us to correct data you cannot edit yourself.
- Deletion — delete your account and reviews yourself from the profile menu in the app, or ask us to do it.
- Withdraw consent — turn off location permission in your browser or device settings at any time, and reply STOP to opt out of listing messages.
- Grievance — raise a complaint about how we handle your data, and escalate to your data protection authority if you are not satisfied with our response.
Deleting your account has a particular effect on conversations, because a conversation has two people in it. Conversations you started as a customer are deleted outright, including the original text of any screened message in them. A conversation in which you were the artist belongs to the customer as well, so it stays and is unlinked from you. Booking records stay in either case, as section 10 says.
Email support@stylogram.app to exercise any of these. We respond within 30 days and may need to verify your identity first. Account deletion needs no request at all — you can do it yourself from the profile menu in the app; see Delete Your Account for what is removed and what stays.
13. Messages to businesses that have not signed up
Some listings are built from business information already published elsewhere, and nobody has claimed them. When a customer asks about one of those, we may send a single message to the business contact number on the listing to tell them somebody is asking and invite them to claim it. We rate-limit those invitations, and you can reply STOP to stop them or write to support@stylogram.app to have the listing removed.
14. Children
The Service is not directed at children under 18, and we do not knowingly collect their personal data. If you believe a child has given us data, write to support@stylogram.app and we will delete it.
15. Changes to this policy
We may update this policy as the Service changes. The “last updated” date above always reflects the current version, and we will give notice in the app before a material change takes effect.
16. Contact
Questions, requests or complaints about privacy — or anything else about the Service — reach us at support@stylogram.app. Tell us what you want done and which account or booking it concerns; we reply within 30 days, and we may have to check you are who you say you are before we act on a request about somebody’s data.