One phrase cannot explain the whole data journey

When a product says a feature runs on-device, the useful next question is which feature. The phrase describes where a particular computation happens. It does not automatically tell you whether the original photograph is backed up, whether an account exists, or whether diagnostic information is sent elsewhere.

The same care applies to “cloud-based.” That label does not, on its own, describe every safeguard, recipient, retention period, or user choice. Compare disclosed behavior rather than treating one broad category as proof of trustworthiness or misconduct.

This article explains the questions to separate. It does not audit named competitors or certify the security of the current HairLens website or a future app.

Processing and storage are different actions

Processing is the work performed on information, such as displaying a preview, resizing an image, or producing an estimate. Storage concerns where a copy remains. A feature can perform one action locally and another remotely.

Consider three hypothetical designs:

  1. A browser displays a selected image in the current page without uploading it through that feature. The user keeps the original file independently.
  2. An app performs a calculation on the device but offers an optional remote backup of photos and notes.
  3. A service sends an image to a server for processing and retains information according to its disclosed policy.

These examples are not descriptions of specific products. They show why “where is it processed?” and “where is it kept?” need separate answers. Ask both before drawing a conclusion about the whole experience.

Trace one feature from beginning to end

Choose the actual task you intend to use, such as adding a photograph to a record. Identify what you provide, what the feature does, which information leaves the device, and what remains after you finish.

Do not stop at the photograph. A record may also involve dates, notes, account details, estimates, or device information. Ask which of those are included in any transfer or stored entry. Avoid assuming that a statement about images also covers every other field.

A useful disclosure names the purpose and recipients at a level you can understand. If a help page and a privacy notice appear to describe different flows, ask the provider which applies to the current version of the feature.

Backups and accounts need their own explanation

A backup is another copy, not merely another word for processing. Ask whether it is required, optional, or unavailable, and where you can change the choice. Also consider copies made through other services you use, such as a device photo library, under those services’ own settings.

An account can add another set of information and controls. Check what is required to create it, which features depend on it, and what happens to your record if you stop using it. Signing out should not be assumed to mean that stored information has been deleted.

If you do not need an account for your main task, it is reasonable to ask why one is requested. The answer may be functional, but it should be explicit rather than inferred from a familiar sign-in screen.

Permissions should describe a specific choice

Read what a permission enables and whether the requested access matches the task. Ask what happens if you decline, and which controls let you change the choice later. A permission should not be interpreted as a blanket answer to every privacy question.

Withdrawing permission for future access is different from removing copies already created. For example, a hypothetical feature might stop accepting new uploads while existing remote entries remain until separately deleted. The provider’s actual controls and disclosures determine the behavior.

Do not test uncertain permissions with private photographs when documentation or non-sensitive sample material would answer your question. A trial should not require you to take an unnecessary privacy risk merely to learn how it works.

Ordinary requests, analytics, and diagnostics are not interchangeable

A website normally needs requests to load its pages and assets. That does not mean a selected photograph is necessarily included in those requests. Conversely, a statement that a photograph stays local does not establish that the website makes no requests of any kind.

Ask separately about visitor analytics, error reporting, diagnostics, and other optional services. Which information is collected, for what purpose, and under which settings? “No photo upload” is a narrower claim than “nothing ever leaves your device.”

If a product says there is no tracking, look for the scope of that statement rather than expanding it yourself. A meaningful explanation describes the relevant activity and any limits.

Check what exports actually contain

An export may include original images, a rendered summary, notes, or only part of the record. Ask what is included and whether you can open it without the service. If an estimate is exported, check whether its date and explanation come with it.

After an export, the file you saved is a separate copy. Deleting an entry in an app should not be assumed to erase that exported file from your own storage or from a place where you shared it.

Use non-sensitive example data to check an export if you choose to test the feature. Keep any discovered limitation in your evaluation notes rather than relying on the button’s label alone.

Read deletion scope carefully

“Clear,” “reset,” “delete entry,” and “delete account” may refer to different operations. Ask exactly what is removed and from where. If remote storage, backups, or retention requirements are involved, look for the provider’s explanation of timing and exceptions.

A confirmation should tell you what happened, not leave you inferring that every copy everywhere has disappeared. Clearing a browser preview is not the same operation as removing your original photograph from your computer.

This is a reason to read the scope, not to assume that every service is hiding something. A missing answer remains a question to resolve before you rely on the control.

The boundary of the current HairLens demonstration

The implemented onboarding demonstration can show a local preview of a selected file. It does not run an analysis service on that file, and its report is fixed sample content. The current demonstration does not establish a connected photo account, remote archive, or export-and-erasure workflow.

The website still loads pages and assets. Its browser search works with the site’s search index. These behaviors are separate from the question of uploading a selected photo. Read the existing technology page and the Privacy Policy, including its draft status, for the current scope.

A planned mobile app would require its own verified release disclosures. Do not infer its eventual data flow, security controls, or account behavior from this website’s local preview.

A disclosure checklist to keep

For each feature you consider, record:

  • The input and the specific operation performed on it.
  • Where processing happens and which information is transmitted.
  • Where copies remain, including optional backups.
  • Whether an account is required and what it stores.
  • The purpose and scope of permissions, analytics, and diagnostics.
  • What exports include and how they can be opened.
  • What each deletion control covers, including timing and limits.
  • The official source, product version where available, and date checked.

You do not need to turn this into a security certification. The purpose is to make your own decision with fewer assumptions. The app evaluation checklist puts these questions alongside usability and feature availability.

Back to the journal