Legal
Privacy Policy
Effective August 2, 2026
Color Analysis Diva is operated by roshi LLC, a New Mexico limited liability company. "Color Analysis Diva" is the name of the service and brand.
Support and legal contact: diva@iknowcolors.com
The short version
We do not require an account, and we do not save customer photos, reports, or conversation transcripts in our databases or object storage. Photos, report content, chat, annotations, shopping preferences, and the generated PDF exist only in the active browser session and temporary request memory. The PDF downloads automatically when the report is ready. Refreshing or closing starts over.
What is processed
To provide the service, the app temporarily processes 5–10 photos, the labels you assign, the report, questions and requested edits, and optional shopping preferences. We do not ask for a name, birth date, or account profile. Email report delivery and voice are disabled for launch.
The browser removes EXIF, GPS, XMP, and textual image metadata before decoding the photo, redraws it, converts it to WebP, and strips metadata again. Photos and report content are never placed in our database, object storage, CDN, or backup.
Service providers
- Stripe processes payment, tax, receipt information, and the minimum fulfillment ledger: analysis status and the number of completed runs. Stripe retains records under its legal and processor obligations.
- OpenAI receives the qualified photos and analysis instructions needed for the report. It also receives report context and the question needed when you use Ask Diva. It does not receive a name, email address, IP address, or purchase ID. Requests use
store: falseand a purpose-specific pseudonymous safety reference. - The curated shopping catalog is compared with your selected shade and shopping preferences in temporary server memory. If a remote catalog feed is configured, the app fetches that feed without sending your photos, email, identity, report, or preferences to the feed host.
- When enabled, SerpAPI processes a minimal Google Shopping query containing only product category, shade wording, selected product color-temperature wording, and maximum budget. “Match my analysis” prefills that product term as warm, cool, or neutral, but never sends photos, identity, email, season label, purchase ID, session token, skin-undertone evidence, or the full report.
- When enabled, eBay processes the same minimal query through its Browse API. It receives the selected product color-temperature term, but not photos, identity, email, season label, purchase ID, session token, skin-undertone evidence, or the full report.
- Retailer, Google Shopping, and eBay fallback links contain that visible minimal query. Opening one sends the query to the destination under its own privacy policy.
- Email delivery through Resend is disabled for launch. If it is introduced later, it will require a separate opt-in before the address and PDF are sent.
- Voice is disabled for launch. If enabled after contract and technical review, the vendor may receive speech and a derived summary, never photos.
OpenAI may retain API inputs and outputs for abuse monitoring for up to 30 days unless and until stronger data controls are approved for our accounts. Their security, legal-hold, and abuse processes may apply even though we keep no content copy. We document our current processor-control requests and outcomes before sales open.
Logs and telemetry
Our application log is limited to route, method, status, and latency. A central redaction layer excludes request and response bodies, images, base64 data, prompts, report text, questions, email addresses, transcripts, cookies, tokens, and identifiers.
Cloudflare platform logs may separately contain IP address, user agent, referrer, requested URL, and country for up to 7 days. Paid purchase IDs are not placed in URLs. In-session analysis paths use a new random page ID that is not derived from a purchase or person.
No third-party analytics is enabled. If anonymous telemetry is added, it is limited to step ID, action name, outcome, latency bucket, confidence band, photo-retake count, thumbs rating, and error code. It will contain no content or identifiers and will not be joined to the purchase ledger.
Children
The service is intended for ages 13 and older. A parent or guardian must purchase and submit photos for a younger child. The service does not knowingly invite children under 13 to submit information directly.
Your choices
You can stop before uploading, skip Ask Diva, and skip shopping. Provider-discovered listings are labeled unverified and are kept separate from curated shade-verified products. Download is the only report-delivery method at launch. For privacy or support questions, use the contact page. Do not send photos to support; we cannot retrieve a report after its live session ends.