Skip to content
Legal

Privacy

Last updated 3 October 2026

FacePlan is operated by Face Plan Ltd (company number 17469510, registered in England and Wales). Clinics and practitioners use it to plan and share skincare and treatment plans with their patients.

Who is responsible for what

Your clinic is the data controller for patient information. It decides what is recorded about you and why, and it answers your requests about your data.

Face Plan Ltd is the clinic's data processor. We store and protect that information and use it only to run the service for the clinic, on the clinic's instructions and under a written data processing agreement, and, with the clinic's permission, to produce the anonymised statistics described under "Aggregated insight" below. We help clinics answer patients' requests.

Face Plan Ltd is the data controller for practitioner accounts, billing, security records, enquiries sent to us, and visits to this website.

Face Plan Ltd is also the data controller for the anonymised, aggregated statistics described under "Aggregated insight" below.

What we hold

About patients, as recorded by their clinic:

Name, email address and phone number.

Your plan: the products, treatments, prices and advice your practitioner recommends, and your responses ("I'd like to buy this", "Already have this", "I've booked this").

Your practitioner's private notes, and any allergies, sensitivities, medications or contraindications they record. These are never shown to other clinics.

Progress photos, with the date they were taken and a record of the consent given for each one.

Messages between you and your practitioner.

A record of who changed a plan, and when.

About practitioners: name, email, a password hash (never the password) or, for those who sign in with Google, their Google account id, clinic name and logo, the clinic's library of products, treatments and advice, billing status, and when they accepted these terms. Card details are held by Stripe, never by us.

About other people: if you email us, your name, email address and what you wrote; if you visit this website, the security records described below.

Health information

Plans, notes, allergies, medications, photos, messages and dictated audio can reveal information about a person's health. Under UK GDPR this is special category data. It needs a lawful basis and an additional condition, and we protect it accordingly (see below).

Lawful basis

For patient information, the clinic chooses and records its lawful basis. Usually this is to provide the service the patient asked for (Article 6(1)(b)) or the clinic's legitimate interests (Article 6(1)(f)).

For health information, most aesthetics and skincare practitioners rely on the patient's explicit consent (Article 9(2)(a)). A clinic whose care is given by, or under the responsibility of, a regulated health professional with a duty of confidentiality (for example a doctor, nurse, dentist or pharmacist) may instead rely on the provision of health care (Article 9(2)(h) with the Data Protection Act 2018, Schedule 1, paragraph 2). Each clinic records its choice in the service, and where it relies on consent the practitioner confirms it for each patient.

Progress photos are only added with explicit consent, recorded each time.

For the clinic owner who holds the subscription: to provide the service under our contract (Article 6(1)(b)). For other practitioners in the clinic, who are not party to that contract: our and the clinic's legitimate interests in providing the service they use at work (Article 6(1)(f)).

Billing records: legal obligation (Article 6(1)(c)). Security records, enquiries and usage records: legitimate interests in running, securing and improving the service (Article 6(1)(f)).

How it is protected

All information is encrypted in transit and at rest, including plans and patient responses. Contact details, notes, allergies, medications, messages and photos are additionally encrypted by the service itself. Practitioners can only see patients of their own clinic, and plan links are personal and expire.

Photos

Progress photos are health information, so we give them the most protection.

A photo is added only with consent, given at upload and recorded with the photo.

Location and camera information is removed on upload.

Photos are encrypted in our database in London. They are never stored in a public place, and never sent in an email or a notification.

Only the clinic and the patient can see a photo, and only after the service checks who is asking. Each view, upload and deletion is recorded in an audit log.

The patient's plan link lasts 30 days, and the clinic can withdraw it at any time.

We use photos only to show them to the patient and their clinic. We never use them for AI training, analytics or marketing.

A deleted photo is removed from the service at once, and from our encrypted backups within 14 days.

Dictation and AI

Dictation is off unless a clinic turns it on. When it is on, what the practitioner says is recorded and sent for processing, and it will often include health details about the patient. The audio goes to Google Cloud Speech-to-Text to be transcribed, and the transcript goes to Google's Gemini API (or Anthropic's Claude API, if the clinic chooses it) to draft a plan. These providers process it outside the UK, in the United States and elsewhere.

We do not store the audio; only the plan the practitioner accepts is saved.

Google does not keep Speech-to-Text audio after returning the text (we do not enable its optional data logging).

The providers may keep what they receive for a limited period (Google up to 55 days, Anthropic up to 30 days) solely to detect misuse, and do not use it to train their models.

The practitioner reviews every draft before anything reaches a patient. We never use patient information to train AI models.

Emails

Emails are sent through a provider in the United States. A plan email to a patient contains a link, not the plan. Alerts between patient and practitioner can contain the patient's name, the product or treatment concerned, and message text.

Who processes data for us

Google Cloud

Hosting, database and backups

London, UK

Resend

Sending emails

United States; UK–US data bridge or the transfer Addendum

Stripe

Practitioner subscriptions and payments; no patient information

Ireland and United States; UK–US data bridge

Google Cloud Speech-to-Text and Gemini API

Dictation, only when a clinic turns it on

United States and elsewhere; UK–US data bridge

Anthropic (Claude API)

Dictation drafting, only if a clinic chooses it

United States; the transfer Addendum

Where data is processed in the United States, it is protected either by the UK–US data bridge (the UK Extension to the EU–US Data Privacy Framework, for providers certified to it) or by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Elsewhere, by UK adequacy regulations or the same Addendum. We tell clinics before we add or change a sub-processor. We never sell personal data or show advertising.

Security records

To keep the service secure we record IP addresses, browser and device details, sign-in activity, and who changed what and when.

How long we keep it

While a clinic subscribes, patient information is kept until the clinic deletes it. A practitioner can delete a patient, with everything linked to them, at any time.

When a subscription ends, or a free trial ends without one, the clinic has 30 days to export its data from Settings. A clinic that signs up without a free trial and does not subscribe has 30 days from sign-up. After that, all its patient information (patients, plans, notes, messages and photos) is permanently deleted.

Deleted information leaves our backups within 14 days.

Security and usage records are kept for up to 12 months, email copies for 30 days, enquiries for up to 2 years, and billing records for 6 years, as UK law requires.

Practitioner accounts are deleted on request once the subscription has ended.

Your rights

You can ask for a copy of your information, and ask for it to be corrected, deleted or restricted, or object to its use.

You can ask for your information in a portable, machine-readable form. Clinics can export everything they hold from Settings to answer such a request.

Where your information is held on your consent, including progress photos and any health information held on explicit consent, you can withdraw that consent at any time: ask your clinic, or delete a photo you added yourself. Withdrawing does not affect what was done before.

No decision about you is made by automated means alone (Article 22): a practitioner reviews every AI draft before it becomes your plan.

As a patient, ask your clinic first: it is responsible for your information, and we will help it.

For anything about the service itself, contact hello@faceplan.co.uk. You can also complain to the Information Commissioner's Office (ico.org.uk).

Emails to practitioners

We send practitioners only the emails the service needs. We do not send marketing; if we ever do, it will be as the law allows, with an unsubscribe link.

Cookies and browser storage

We use one essential cookie to keep you signed in, and no advertising or analytics cookies. If you sign in with Google, a second essential cookie protects that sign-in for up to ten minutes. Your browser also keeps the app's working state, which can include the patient information on screen; it is cleared when you sign out. On a shared computer, always sign out.

How the service is used

To improve the service we record which features are used (for example, that a plan was sent), without names, contact details or health information.

Aggregated insight

We produce anonymised statistics about how products and treatments are recommended and responded to across the service: for example, how often a product is recommended for a particular concern, or how often patients ask to buy it.

These statistics are combined across many clinics and patients. They contain no names, contact details, photos, notes, messages or anything else that could identify a patient or a clinic, and they are only produced where enough clinics and patients are included that no one could be identified from them. Anonymisation happens before the statistics are created; nothing identifiable leaves the clinic's data.

We may share these statistics with skincare brands and distributors, and may charge for them. They are not personal data, and no individual plan, patient or clinic is ever shared.

Who we are

Face Plan Ltd

Company number 17469510 · Registered in England and Wales

Registered office: 41 Thorpe Lane, Huddersfield, England, HD5 8TA

Contact: hello@faceplan.co.uk