Skip to main content

Photo handling

  1. The photo arrives inline in start_skin_scan, or from the person’s browser on the upload page.
  2. Skan resizes it to at most 1900 px on the long edge and strips metadata such as location.
  3. In the same request, Skan sends it to its analysis provider (Haut.AI). It is never written to Skan storage: there is no photo bucket, and nothing is kept in a database row or a Durable Object.
  4. The provider deletes its copy of the image within an hour.
  5. Skan stores the numeric scores and returns a result.
Face masks and overlays are not requested or returned.

Retention

A photo sent through an assistant conversation also remains in that conversation, under the assistant platform’s own privacy policy. Deleting the Skan scan doesn’t remove it. The upload link avoids this.

What the connector never returns

  • Raw database rows or provider identifiers. Every output field is allowlisted by the tool’s schema.
  • Prices, stock levels or purchase links.
  • Tokens, internal URLs or stack traces in errors.
Analytics events carry no photos, scores or tokens.

Policies