What happens to your palm photo.
A lifecycle view of capture, encrypted transit, temporary processing, deletion and the data that may remain for account or purchase functions.
Collect for a purpose, keep for a limited time
The EU GDPR names purpose limitation, data minimisation and storage limitation as core principles. Palmuse applies that idea to the most sensitive part of its experience: a palm photo should exist in the processing flow only as long as it is needed to create the requested reading or match result.
The photo lifecycle
- Before capture: your browser or device asks for camera access. You may also choose an existing image where the interface supports it.
- When you continue: the selected photo travels to Palmuse over HTTPS for validation and processing.
- During processing: Palmuse and its Google Gemini API provider process the image to create the requested AI-assisted reading.
- After completion or failure: Palmuse deletes the temporary file where possible.
- Safety net: an automated cleanup removes any remaining temporary palm-photo upload within 24 hours.
Photo data is not the same as account data
Deleting the temporary image does not necessarily delete the text of a saved reading, an account, or a purchase record. Those records have separate purposes:
- Reading history can let a signed-in user return to a saved result.
- Purchase and entitlement records support fulfillment, duplicate protection and restoring access.
- Operational logs help protect the service and diagnose failures.
- Billing records may need to be kept for accounting, tax, fraud prevention or legal obligations.
The Privacy Policy describes these categories and their purposes. The account-deletion page explains how to request deletion and what may be retained where law requires it.
Which providers are involved?
Palmuse uses hosting and infrastructure providers, Google Gemini API for AI-assisted readings, Firebase services when a user signs in, Google Play for Android purchases and Stripe Checkout for web purchases. Web card details are entered on Stripe Checkout; Palmuse does not receive or store the full card number.
Palmuse states that it does not sell personal data and does not use palm photos to train its own models.
Palm Match links have their own clock
An invite link lets another person add a palm from another device. Because the link opens a temporary shared flow, it expires within 24 hours. Do not post a live invite link publicly; send it only to the person you intend to invite.
Your controls
- Use supported flows as a guest.
- Sign in when you want to save your journey.
- Delete your account inside Palmuse under Profile > Delete Account.
- Submit a deletion request at palmuse.app/account-deletion.
- Contact support@palmuse.app with privacy questions.
Sources & verification
Sources are selected for the claims made on this page. Historical sources document traditions; they are not used as scientific proof.
-
General Data Protection Regulation, Article 5
EUR-Lex, European Union
Defines principles including purpose limitation, data minimisation and storage limitation.
-
Palmuse Privacy Policy
Palmuse
Current public disclosure for photo processing, providers, retention and user choices.
-
Delete Your Palmuse Account
Palmuse
Account-deletion instructions and data-retention explanation.
Your first Palmuse reading is free.
Use Palmuse on Android or directly in your mobile browser. Optional deeper readings are one-time unlocks — no subscription.