Nitido
ENIT

Privacy Policy

Last updated: 13 September 2026

Nitido tells you which colours suit you, from a selfie. This page explains what happens to your data. The short version: your photos never leave your phone.

1. Who is responsible

Nitido is made and operated by Kevin Baur, an individual developer, not a company. The controller under the GDPR is Kevin Baur, Hochstraß 542, 3033 Klausen-Leopoldsdorf, Austria. For any question about your data, write to nitido@kevin-baur.com.

2. In short

3. Your photos

This is the most important section.

A measurement takes three quick photos with your front camera. They are analysed on your phone: face detection (Google ML Kit, running on the device, see section 8) finds skin and eyes, and the colour calculation runs inside the app. The photos are not sent to any server, neither to me nor to anyone else.

For the fitting-room view, the app keeps one cut-out portrait of your face in its private storage on your phone. The cut-out is made on the device with Apple’s built-in image analysis. It is replaced when you measure again and removed when you delete the app.

Photos of garments, taken with the camera or picked from your gallery, are also processed on the phone and kept only in the app’s storage there. When you pick an image, iOS gives the app only that one image; the app has no access to the rest of your photo library.

Photos are not part of the online backup. If you restore your data on a new phone, garments show their measured colours instead of a photo. A photo only leaves your phone if you share it yourself, for example a share card through the iOS share sheet; what happens then is governed by the app you share it with.

4. What is stored online, and where

So that your data survives reinstalling the app and can be restored on another phone, the following is stored with your account:

No photo, no image of your face and no facial geometry is stored online. The colour values describe your appearance. They are used only to calculate your palette and to improve the accuracy of the measurement, never to identify you or to draw conclusions about your origin or your health.

This data is stored with Supabase, hosted on Amazon Web Services in Frankfurt, Germany (EU). Supabase processes it on my behalf. Each account can only access its own data.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Using measurement values to improve the accuracy of the analysis: my legitimate interest in a correct result (Art. 6(1)(f) GDPR).

5. Purchases

Subscriptions are sold by Apple. I never see your payment details, your name or your Apple Account. Subscriptions are managed with RevenueCat (RevenueCat, Inc., USA). RevenueCat receives your anonymous Nitido user ID, the purchase and renewal status reported by Apple, and technical data such as device type, app version, country and IP address. RevenueCat processes this on my behalf; transfers to the USA are covered by the EU Standard Contractual Clauses.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Purchase records are kept as long as tax and accounting law requires.

6. Advertising measurement

Nitido is advertised on social media. The app contains no advertising SDK, does not ask for permission to track you and does not read your advertising identifier. Installs that come from an ad are reported by iOS itself through Apple’s SKAdNetwork, aggregated and without information about you.

When a subscription is started, RevenueCat can report that event to the platform on which Nitido is advertised (for example Meta or TikTok), so that I can see which campaigns lead to purchases. The report contains the event, the plan, price and currency, the time, and the technical data the platform needs to attribute it to a campaign, such as IP address and device type. It contains no photos and no measurement data. The platform processes this under its own privacy policy.

Legal basis: my legitimate interest in measuring whether advertising works (Art. 6(1)(f) GDPR). You can object at any time by writing to nitido@kevin-baur.com.

7. Usage statistics

To understand where the app works and where people get stuck, Nitido records anonymous usage events with PostHog (PostHog, Inc.), in PostHog’s EU cloud in Frankfurt, Germany. Examples: which step of the introduction was viewed, whether a measurement succeeded and which colour type came out, whether a subscription was started and with which plan, whether a garment was scanned and its score rounded to tens.

Sent with each event: a random ID generated by the app, app version, device model and operating system, and, for technical reasons, the IP address, which is not used to determine your location. Never sent: photos, your palette, individual colour values, names of outfits. There is no personal profile, no screen recording and no link to your account.

Legal basis: my legitimate interest in improving the app (Art. 6(1)(f) GDPR). Statistics are on by default. You can turn them off at any time in the app under “Statistiche d’uso”; from then on no events are sent.

8. Face detection and app updates

Face detection uses Google ML Kit. It runs entirely on your phone and images are not sent to Google. The ML Kit component does, however, send Google technical information about the device and the app and metrics about how the feature performs and is used.

When the app starts, it checks for updates with Expo (650 Industries, Inc., USA) and downloads them. The request contains the app version and platform and, for technical reasons, your IP address.

Legal basis for both: my legitimate interest in an app that works and stays up to date (Art. 6(1)(f) GDPR).

9. What Nitido does not do

No ads in the app, no advertising or tracking SDK, no tracking permission prompt, no advertising identifier, no screen recording, no cookies in the app, no push notifications, no location, no microphone, no access to your photo library beyond the single image you choose, and no sale of data.

10. Writing to me

If you write to me, I use your email address and your message to answer you, and delete them once the matter is settled unless the law requires me to keep them. Legal basis: Art. 6(1)(b) or (f) GDPR.

11. This website

This website is served by Cloudflare, which processes your IP address and technical request data to deliver the page and protect it from attacks. Visits are counted with DataFast without cookies. Fonts are loaded from this server, not from Google. Legal basis: my legitimate interest in a secure website and in knowing how often it is read (Art. 6(1)(f) GDPR).

12. How long data is kept

13. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict its processing, to receive it in a portable form, and to object to processing based on legitimate interest. Write to nitido@kevin-baur.com and I will handle it.

One practical limitation: if your account is anonymous, I have no way to confirm that an account belongs to you. In that case the reliable route is the in-app deletion, which works without any proof of identity because it runs from your own device.

You also have the right to complain to a data protection authority, for example in the country where you live (in Italy the Garante per la protezione dei dati personali) or the Austrian Datenschutzbehörde.

14. Children

Nitido is not directed at people under 16, and I do not knowingly collect their data. If you believe a child has given me personal data, contact me and I will delete it.

15. Changes

If this policy changes, the date at the top of this page changes with it. Significant changes will be pointed out in the app. The Terms of Use explain the subscription and the limits of the analysis.

16. Contact

Kevin Baur, nitido@kevin-baur.com