Best Me · Last updated 11 August 2026
Best Me lets you train a private AI model of your own face and use it to retake, restyle and repose your photos. Your photos are the whole product, so this page is specific about what happens to them.
This policy covers the Best Me mobile app and the API behind it. If you do not agree with it, please do not use the app.
To create a model of you, the app asks for a set of selfies. To retake a photo, it uploads that photo. These images are stored on our servers and sent to our AI provider for processing. This is the core function of the app and it cannot work without them.
Photographs of a face can, depending on how they are used, count as biometric data under laws such as the GDPR. We use your photos only to build and run a model for you, and never to identify you, to match you against any database, or for any surveillance purpose.
Your photos are never sent to Meta, to Firebase, or to any advertising or analytics service. They go only to us and to our AI provider.
Instead of an account, the app holds a random access token, and a random identifier generated on first launch that ties your account to your device so reinstalling the app resumes your existing account rather than silently creating a new one.
We do not store either value in readable form. We store only a one-way cryptographic hash (SHA-256, and for the device identifier a keyed hash). A leak of our database would not reveal a credential anyone could use.
This identifier is generated by the app. It is not your IMEI, your advertising identifier, or any other identifier that follows you between apps.
Best Me includes third-party software development kits that collect information about how the app is used and how it performs:
These tools receive technical and usage data. They never receive your photos or the model trained from them.
If you subscribe, Apple or Google processes the payment. We never see your card details. We store the purchase receipt token they give us, so we can confirm your subscription is valid and restore it if you reinstall.
Our servers process your IP address as an unavoidable part of serving requests, and use it to enforce rate limits that protect the service from abuse.
No name, email address, phone number, contacts, calendar, precise location, or browsing history outside the app.
On iOS, the app shows Apple's App Tracking Transparency prompt before any tracking takes place. If you decline, your advertising identifier is not used and the Meta SDK does not track you across apps and websites. You can change this at any time in Settings → Privacy & Security → Tracking.
On Android, you can delete or reset your advertising ID, and opt out of personalised advertising, in Settings → Google → Ads.
Declining tracking does not restrict any feature of Best Me.
| Who | What they receive | Why |
|---|---|---|
| WaveSpeed AI | Your uploaded photos and the model trained from them | They run the model training and image generation. They act as our processor. |
| Meta | App events, device and app information, advertising identifier where permitted. No photos. | Advertising measurement and audience targeting. |
| Google (Firebase Crashlytics) | Crash and diagnostic data, device and app information. No photos. | Finding and fixing crashes. |
| Apple / Google | Your purchase, handled entirely on their side | Subscription billing and restore. |
| Hetzner | Hosting for our servers and database | Infrastructure provider. They do not access your data. |
We do not sell your personal information for money. Under some laws, including the California Consumer Privacy Act, sharing advertising and app-event data with Meta for targeted advertising may count as a "sale" or "sharing" of personal information. To opt out, decline the tracking prompt on iOS or opt out of personalised advertising on Android, as described in section 3, or contact us.
Our servers are in Germany. Our AI provider, Meta and Google may process data outside your country, including outside the European Economic Area. Where that involves a transfer from the EEA or UK, it is made under the safeguards those laws require.
Access tokens and device identifiers are stored only as one-way hashes. Your credentials are held in your device's secure storage — the iOS Keychain or the Android Keystore. Databases are not reachable from the public internet, and access to our servers is restricted to key-based administrative login.
No system is perfectly secure, and we cannot guarantee absolute security. Generated image links are long, random and unguessable, but anyone you send one to can open it — treat a shared link as public.
Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your personal data, to object to it, and to withdraw consent. Because Best Me holds no name or email, we identify your data by your app installation — so please make requests from the device you use, or include your user ID from the app's settings screen.
You also have the right to complain to your local data protection authority.
Best Me is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has used the app, contact us and we will delete the data.
If we change this policy we will update the date at the top of this page, and for significant changes we will tell you in the app.
Questions, or a request about your data: coverlyai35@gmail.com