Privacy

Last updated 9 September 2026

The short version: Bellanos works out where your skincare money should go. To do that it needs to know your goals, your budget and what is on your shelf. It does not need your face or your name, so it does not ask for them.

What we collect

Your goals
Which skin concerns you ranked, and in what order.
Your constraints
Annual budget, minutes a day, downtime tolerance, whether professional treatments are acceptable, how reactive your skin is.
Life stage (optional)
Only if you choose to tell us. It changes what is safe to recommend. You can skip it, and the plan is still produced.
Whether you are breastfeeding
A yes/no question. It changes what is safe to recommend, so anything without cleared guidance is routed to a clinician rather than into your plan.
Medications (optional)
Whether you take any of a short list (for example isotretinoin, or a prescription cream). It narrows what we are willing to recommend. You choose whether to say.
Your cabinet
The products you enter: a name you type, what the product does, roughly what it costs you a year, and whether you actually use it.
Free-text notes (optional)
Anything you type into the "is something worrying you?" box.
Technical data
A coarse browser family (e.g. "a Chromium browser") — and, deliberately, not your IP address. Our proxy strips IPs from its logs and the app never receives one, so we retain no visitor IP anywhere (verified by PLATFORM).

What we deliberately do not collect

  • Photographs of your face. Not optional, not stored, not analysed. We do not ask for them, and there is nowhere in the product to provide one. A budget question does not need your face, and it is the most sensitive thing we could hold.
  • Biometric identifiers. We create no face templates or embeddings, and we never use images for identification.
  • Medical records or health-service data. Bellanos gives cosmetic guidance. It does not diagnose, treat or screen for any condition, and it holds no clinical record about you.
  • Payment card details. If and when paid plans launch, card data is handled entirely by our payment processor. We never see or store a card number.

Why we are allowed to hold it

Some of what you tell us — whether you are pregnant or breastfeeding, which medications you take, and anything you type into the free-text box — is information about your health. We ask for it for one reason: so that we can leave things out of your plan that would be a bad idea for you. We do not use it for anything else.

In Canada, under PIPEDA, we rely on your express consent, given by choosing to answer those questions. Health information is sensitive, so consent is the right basis and it has to be a real choice: every one of those questions is optional, and the product still produces a plan if you skip them — it just cannot protect you from something it does not know about.

In the United States, we rely on your consent in the same way. Where state law treats what you tell us as consumer health data — Washington’s My Health My Data Act is the clearest example — we set out separately how we handle it, in our Consumer Health Data Privacy Policy.

You can withdraw that consent at any time by clearing the answers or deleting your data, and withdrawing it does not cost you access to anything else.

For everything that is not health information — your budget, your goals, the products you own — we rely on the fact that we cannot produce your plan without it. We do not sell any of it, and we never have.

How long we keep it

What you enter is held in your browser for the current session so you can move between screens. When you generate a plan, a guest account is created for you (no email or password needed), and your inputs and the resulting plan are stored on our servers — this includes your goals, budget, cabinet, and the health-related answers above where you gave them, so that a plan you return to is the plan you left. If you sign in with an email link, that plan becomes tied to your email.

You can export everything we hold, or delete your account and its data, at any time from your account settings. We keep data while your account is active and for up to 30 days after you delete it, except where we are legally required to retain records for longer. Server logs are kept for up to 30 days.

Who else sees it

No one buys it, and no one is given it in exchange for anything. We share personal data only with service providers who process it on our instructions — a hosting provider, an error-monitoring provider, an AI provider that reads product text you paste in order to interpret it, and (once paid plans launch) a payment processor. Each is bound by a data-processing agreement.

Providers and brands never receive your data, and never influence your plan. The system that decides what to recommend is structurally unable to see who has paid us — that is enforced by an automated test rather than by this sentence.

Where your information is

Bellanos is operated from British Columbia and your information is stored in Canada. If you are in the United States, that means your information is held outside the US, by a Canadian company, under Canadian privacy law as well as the US rules that apply to us.

If the business changes hands

Bellanos is operated by Regenrtiv. If the Bellanos service is one day transferred to a different company — including to a company set up for Bellanos itself — your information would move with it, so that your account, your shelf and your history keep working. If that happens we will tell you, the new operator will be bound by this policy until it publishes its own, and it must honour any consent you have withdrawn. We would not sell your information as a standalone asset, and nothing here permits that.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, delete it, give you a copy in a portable format, or stop using it. If you are in the EEA, the UK or Switzerland you also have the right to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority — in Switzerland, the FDPIC.

If you are in California you may request disclosure of the categories and specific pieces of personal information we hold, request deletion or correction, and you have the right not to be discriminated against for exercising those rights. We will not deny you service or charge you differently.

In Canada you may challenge our compliance with PIPEDA and escalate to the Office of the Privacy Commissioner.

Write to legal@bellanos.me. We respond within 30 days.

Cookies and analytics

We use no advertising cookies and no cross-site tracking, and we do not use Google Analytics or any third-party tracker. Strictly necessary storage keeps your answers in the browser while you use the product.

We do measure how the site is used, with analytics software we run ourselves on our own servers. It is cookieless, it does not follow you to other sites, and the information never leaves us — there is no third party receiving it. It records which pages were visited and where visitors arrived from, and a small number of counts such as how many people started or finished the questions.

It never records what you told us. Not your concerns, not your medications, not your life stage, not what you typed in the free-text box, and nothing that identifies you.

Children

Bellanos is for adults aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with data, contact us and we will delete it.

Who we are

Bellanos is a service operated by REGENRTIV DESIGN TECH LTD., a British Columbia company, 1480 Howe Street, Vancouver, BC V6Z 0G5. Questions about your data go to legal@bellanos.me.

Changes

If we change this policy in a way that materially affects you, we will say so prominently rather than quietly reposting it with a new date. The date at the top always reflects the current version.

Privacy — Bellanos