Skip to content
BecomeTen

Privacy Policy

Last updated: 2 September 2026

This policy describes how Appinara s. r. o. processes your personal data when you use BecomeTen. A face photo is sensitive data, so we treat it with particular care.

Controller and contact

Appinara s. r. o., Juskova Voľa 66, 094 12 Juskova Voľa, company ID (IČO) 57623252, registered: Commercial Register of the District Court Prešov, section: Sro, insert no. 52598/P.

Data protection contact: hello@becometen.com.

No Data Protection Officer (DPO) is appointed — our processing does not require one under GDPR Art. 37.

What data we process

Face photo (biometric / special-category data under GDPR Art. 9).

Email address and basic profile data (sign-in via email or Google, and access delivery).

Analysis results, score and plan.

Payment data — processed directly by Stripe; we never see card details.

Technical data: session and language cookies, basic logs.

Consent records: the time and version of your consent to photo processing and of your consent to delivery before the withdrawal period ends (so we can prove they were given).

Legal basis

Face photo: your explicit consent (GDPR Art. 9(2)(a)). You can withdraw it at any time.

Paid service: performance of a contract (Art. 6(1)(b)).

Operation and security: legitimate interest (Art. 6(1)(f)).

Accounting and consent records: legal obligation (Art. 6(1)(c)) and demonstrating compliance (Art. 7(1)).

Emails about your scan (the next-scan reminder, one feedback question): sent to existing customers about the service they bought, on the basis of legitimate interest; every such email has an unsubscribe link and you can opt out in your account settings. Payment confirmations and security emails are necessary to perform the contract.

Automated rating: the score and plan are produced by AI without human review. This has no legal or similarly significant effect on you (Art. 22) — it is an informational service you bought; you can contact us at any time for an explanation or to contest it.

Recipients and processors

Rating and image generation use AI providers: Anthropic (rating) and OpenAI (AI potential image).

Application hosting and compute: Vercel — server functions run in an EU region (Ireland).

Payments: Stripe. Email: Resend. Photo storage: Cloudflare R2 (EU). Database: Turso (EU, Ireland).

Sign in with Google (optional): if you sign in with a Google account, Google shares your email and basic profile data with us and itself processes data as a controller.

Some providers (Anthropic, OpenAI, Stripe, Resend, Google) also process data in the USA. Transfers rely on Standard Contractual Clauses (SCC), or the EU-US Data Privacy Framework where the provider is certified.

Face-landmark detection for the visual report (guide lines and crops) runs entirely in your browser using a MediaPipe model served from our own servers. The landmark points are not sent to us or to any third party, are not stored, and are discarded when you close the tab.

Optional photo card: if you choose to export a card that contains your photo, you are sharing your own photo yourself. We do not publish it anywhere.

Retention

Free mode: the photo is kept only during analysis and then deleted; only the text analysis is stored if you save it.

Paid mode: the photo is stored encrypted in the EU (Cloudflare R2, AES256) until you delete the scan or your account.

Unfinished payment: an unpaid scan and its uploaded photo are deleted automatically within 48 hours.

Text analysis, score and plan: for as long as your account exists; deleted promptly when you close it.

Payment and consent records: 10 years under the Slovak Accounting Act (payments) and for the limitation period (consents) — no photo, only time, version and order id.

In-app steps (for example “paid”): at most 24 months, not linked to the photo.

Your rights

You have the right of access, rectification, erasure (Art. 17), restriction, portability, objection, and to withdraw consent.

You can delete a scan or your whole account at any time from the Account page, or ask us at hello@becometen.com.

You may also lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27 (dataprotection.gov.sk).

Cookies and traffic measurement

We use only strictly necessary cookies (login session, language choice). We use no analytics or marketing cookies, so we show no consent banner.

Traffic is measured with Vercel Web Analytics, which stores no cookies and does not identify you across sites; it derives an anonymous daily hash from your IP address and browser purely to tell visits apart. The legal basis is legitimate interest (Art. 6(1)(f)) — knowing how many people reach the site.

Separately, we record steps taken inside our own app (for example “scan started”, “photo uploaded”, “paid”) in our own database. No profiling, and nothing shared with third parties.

Changes to this policy

We may update this policy. We will announce material changes on this page and, where needed, by email.