Skip to content
HAIR DRAW
How it worksWorse · Now · BetterFor doctorsPlansFAQAppSign inBook a demo
Sign in
EN
  • English
  • עברית
  • Português
  • Español
  • 한국어
Menu
How it worksWorse · Now · BetterFor doctorsPlansFAQAppBook a demo

HairDraw — Privacy Policy

Last updated: October 1, 2026

Version legal-2026-10-01.2 — effective October 1, 2026

This policy explains how personal data is handled when clinics use HairDraw, for two audiences: clinic users (doctors and staff) and patients of those clinics.

1. Who is responsible

  • Patient data (photos, drawings, simulations, consultation notes): the clinic that treats you decides how and why it is used; it is the controller. HairDraw (operated by Yaakov Lopes, sole proprietor, Be'er Sheva, Israel) processes it on the clinic's behalf under a data-processing agreement. Patients should direct requests first to their clinic; we will help the clinic answer them.
  • Clinic user data (account, billing, support, app usage) and de-identified product-improvement data: HairDraw is the controller.
  • United States: where HIPAA applies, the clinic is the covered entity and HairDraw its business associate under a Business Associate Agreement.
  • Contact / Data Protection Officer: privacy@hairdraw.app (or through the app, Settings › Legal). Representatives in the EU, UK and Brazil will be listed here when appointed.

2. Data we process

CategoryExamplesSource
Patient identificationname, sex, age or year of birth, contact (optional), clinic patient IDclinic
Facial and head imagesphotos of scalp, face, beard and eyebrow areascamera of the clinic's iPad or iPhone, or photos the clinic uploads in the web app
Consultation informationtreatment interest (hair, beard, eyebrows), planned area drawn by the doctor, notesclinic
Generated contentillustrative simulations, reports/PDFsproduced by the Service
Consent recordsthe doctor's standing attestation recorded with each patient (attestation id, doctor name, date), the patient's optional choices, date/timeaudit trail (app and web app)
Clinic usersname, e-mail, role, clinic, audit logs, login dataclinic / users
Billingplan, credits, invoices (purchases are made only on the web, at hairdraw.app; payment cards are handled by our payment provider, not by us)users
Technicaldevice model, app version, crash and performance data (no photos)app

Facial images of clinic patients are handled as sensitive or special-category data and, in some laws, biometric data. HairDraw does not use facial images to identify or recognise people, build face templates, or match faces across patients.

3. Purposes and legal bases

PurposeLegal basis (GDPR / UK GDPR)Legal basis (LGPD)
Consultation, capture and simulation for the patientClinic as controller: the patient's explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), obtained and recorded by the clinicClinic as controller: the patient's specific and highlighted consent (art. 11 I), obtained and recorded by the clinic
Hosting, backup and archive for the clinic (web app now; iPad and iPhone apps with full sync when available)processing on the clinic's instructions (Art. 28)operador, art. 39
Account, billing, support6(1)(b) contract; 6(1)(c) legal obligation (tax)art. 7 V and II
Security, fraud and abuse prevention, audit logs6(1)(f) legitimate interest; 6(1)(c)art. 7 IX and II
Product improvement using de-identified images (eyes blurred, no name)HairDraw as controller: explicit consent of the patient (Art. 9(2)(a)), recorded by the clinic as an optional choice, off by default; not available in the US regionconsent (art. 11 I), recorded by the clinic as an optional choice, off by default
Clinic presentations (optional, eyes blurred)clinic: patient's separate consentclinic: separate consent

HairDraw is an illustrative visual simulation tool, not a health, medical or clinical tool, so patient images are not processed on a health-care basis: the basis is the patient's explicit consent, obtained and recorded by the clinic as controller. Where other laws apply (for example PIPA in Korea, which requires separate consent, Israel's Privacy Protection Law, or US state biometric laws), the clinic likewise relies on the patient's consent. The patient may withdraw consent at any time.

How consent is recorded (the doctor's standing attestation). The clinic informs each patient and obtains their agreement before photos and simulations (HairDraw provides a patient information template). In the HairDraw apps and web app, the doctor gives a standing attestation once, not for each patient: the doctor attests that every patient they register was informed and agreed. The attestation (its id, the doctor's name and the date) is then recorded with each patient the doctor registers, together with the patient's optional choices. The patient does not confirm anything in the app; the clinic, as controller, remains responsible for informing the patient and obtaining and keeping their consent.

We do not sell personal data and do not use patient data for advertising.

4. Where patient data is stored, and cloud AI processing

  • Web app (hairdraw.app): patient data and images are stored on HairDraw's servers, in the EU region, encrypted, separated per clinic and accessible only to the clinic's authorized users.
  • iPad and iPhone apps: patient data and images are stored encrypted on the clinic's device; only what is needed for each generation (described below) is uploaded. Full synchronization with the clinic's account on HairDraw's servers will apply when available.

To create a simulation, a copy of the whole photo, together with a separate mask/reference image of the area drawn by the doctor, is sent over an encrypted connection to a third-party cloud AI provider acting as our subprocessor. No name or other identifiers are included. The generated image is returned to the clinic's device or, in the web app, to the clinic's account on HairDraw's servers. Under our contract with the provider, it does not use these images to train its models; it may keep them for a limited period (currently up to 55 days) only to detect abuse, then delete them.

Separately from the provider, HairDraw itself may use a de-identified copy (eyes blurred, no name) for product improvement only for patients whose optional consent the clinic recorded. This choice is off by default and not available in the US region (see section 3). The current provider list is available at Annex III of the DPA (Settings › Legal).

5. Recipients

Subprocessors (hosting, cloud AI, e-mail, analytics without photos, payment); professional advisers; authorities when legally required; a buyer in a business transfer, under the same protections. The clinic may share reports with the patient; exported images and PDFs always carry the "Illustrative simulation" notice.

6. International transfers

Data may be processed outside your country (for example in the United States or the European Union). HairDraw's servers are in the EU region; the cloud AI provider may process data in the United States or elsewhere. Where required we use: adequacy decisions; the EU Standard Contractual Clauses (Decision 2021/914) with the UK Addendum; clauses approved by the ANPD (Brazil, Resolution CD/ANPD 19/2024); and, for Korea, the notice/consent or other basis required by PIPA.

7. Retention

  • On the clinic's devices (iPad or iPhone): until the clinic deletes the patient or uninstalls the app.
  • On HairDraw servers, only while the clinic's subscription is active (EU region; the web app now, and the iPad and iPhone apps when full sync is available). A free trial counts as an active subscription until it ends. We do not keep clinic data for years after the subscription.
  • If the subscription stops (cancellation, non-payment, or a free trial that ends without a subscription):
  • Grace period (non-payment only), 30 days: if a renewal payment fails, the clinic keeps full access for 30 days while the payment can be fixed.
  • Then read-only, 90 days: after the grace period (or at the end of the paid period of a cancelled subscription, or at the end of a trial), the clinic's account becomes read-only for 90 days. Its users can still view and export everything (patients, photos, simulations, reports), but cannot add or change data. We notify the clinic's owners by e-mail and in the app 30, 7 and 1 days before deletion.
  • Then full deletion: at the end of the 90 days, we permanently delete all of the clinic's data from our servers: patients, photos, drawings, simulations, reports, consent records, audit records, users and legal acceptances. Paying again before that date restores full access and cancels the deletion.
  • Earlier deletion chosen by the clinic: in Settings › Data retention, the clinic may choose to delete patients with no activity for 6, 12 or 24 months (default: keep while subscribed). Those patients go to the Trash first. The clinic can choose a shorter period, never a longer one: no data is kept beyond the subscription.
  • Trash: deleted patients are moved to a Trash, where the clinic can restore them for 15 days; after that they are permanently erased, together with their photos and results. Automatic deletion under the clinic's data-retention setting also goes through the Trash.
  • What we keep after the deletion (minimum): only the billing record required by tax and accounting law, anonymized (an anonymized ledger of plans, credits and payments, with no patient data and no user names or e-mail addresses), and, to prevent repeated free trials, a salted hash of the e-mail address and of the user ID of the person who started a trial, kept for 24 months and then deleted. The hash cannot be turned back into the e-mail address; it is only compared with the hash of a new sign-up (legal basis: our legitimate interest in preventing abuse of free trials, Art. 6(1)(f) GDPR; art. 7 IX LGPD).
  • The clinic exports what it must keep: record-keeping laws (for example medical-record rules) may require the clinic to keep some records for longer than its subscription. HairDraw is not a record-keeping service: the clinic is responsible for exporting, before the deletion, everything it must keep, and for keeping it.
  • Cloud AI provider: transient, max 55 days for abuse monitoring.
  • De-identified product-improvement set (only patients with the optional consent): up to 5 years, or until consent is withdrawn.
  • Audit and consent records on our servers: while the subscription is active; they are deleted together with the clinic's data (above).
  • Billing: as required by tax law, in the anonymized form described above.

8. Security

Encryption at rest on the clinic's devices (iOS Data Protection, Complete class; excluded from iCloud backups) and in transit (TLS); access limited to authorized clinic users; audit trail of consent and key actions; separation of each clinic's data on the server (EU region); only the photo and the drawing mask are sent to the AI provider, with no name or other identifiers; staff confidentiality and access controls; incident response plan.

9. Your rights

Depending on your country you may: access, correct, delete, restrict or object; receive a portable copy; withdraw consent at any time (without affecting past processing); not be subject to solely automated decisions with significant effects (HairDraw makes none — the doctor decides); and complain to a supervisory authority (e.g. ANPD in Brazil, your EU authority, ICO in the UK, the Israeli Privacy Protection Authority, PIPC in Korea, AEPD in Spain). Patients: contact your clinic; you may also write to privacy@hairdraw.app and we will forward your request. In the US, HIPAA rights are exercised through your provider.

10. Children

The Service is not intended for patients under 18. Clinics must not process minors' data without the legally required guardian consent. We do not knowingly collect children's data for our own purposes.

11. Changes

We will post updates here and notify clinics of material changes.

12. Contact

HairDraw, operated by Yaakov Lopes (sole proprietor), Be'er Sheva, Israel

  • Privacy, data-protection requests and DPO: privacy@hairdraw.app
  • General contact and notices: contact@hairdraw.app
  • Security incidents and vulnerability reports: security@hairdraw.app

You can also contact us through the app (Settings › Legal).


This website

This website does not use cookies, analytics or third-party scripts. Our hosting provider may process technical data such as IP addresses in server logs for security purposes.

Demo requests

If you request a demo, we use your name, work email, clinic, country, role and the optional message only to reply to you. Please do not send patient information through the website.

Compliance

We handle data in line with the LGPD and the GDPR: encryption, consent, access logging and data-subject rights.

Contact

privacy@hairdraw.app.

← Back to home

HAIR DRAW

Doctor-controlled consultation simulations for hair transplant clinics.

All patient images on this site show fictional, AI-generated people. Simulations are illustrative and not a promise of results. HairDraw is a visual simulation tool; it does not diagnose or recommend treatment.

Product

  • How it works
  • Plans
  • FAQ
  • App
  • Book a demo

Legal

  • Privacy
  • Terms
  • Security
  • Billing & cancellation
  • Data Processing Agreement

Language

  • English
  • עברית
  • Português
  • Español
  • 한국어
© 2026 HairDraw. All rights reserved.HairDraw is operated by Yaakov Lopes (sole proprietor), Be’er Sheva, Israel · contact@hairdraw.app