Effective Date: 17 September 2026 (Updated: 22 September 2026).
This Privacy Policy applies to the iOS application "OptiPro Measure" (the "App"), developed and published by the OptiPro Measure Team ("we", "us", or "our").
Summary: OptiPro Measure processes TrueDepth camera and facial geometry data locally on your device to calculate optical eyewear fitting parameters. The developer operates no remote collection servers. We do not transmit your raw face mesh, depth buffers, or biometric data to external servers or third-party tracking services.
1. Overview and Architecture
OptiPro Measure is an optical dispensing measurement utility designed for optometry professionals, optical shops, and individuals to assist in calculating optical fitting parameters (such as pupillary distance and fitting height). The App operates on-device, requires no account registration or login, and contains no automatic network upload logic or tracking SDKs.
2. Collection of Face Data (TrueDepth API)
During an active optical measurement session, after the user grants camera access, the App utilizes Apple's TrueDepth front-facing camera system via ARKit (ARFaceTrackingConfiguration and ARFaceAnchor) to capture and analyze the following facial geometry and sensor information:
3D Facial Mesh Vertices and Topology: Real-time 3D vertex positions provided by ARFaceGeometry, used to detect facial contours, the nasal bridge, and nasal root topology.
Eye Center Coordinates and Gaze Information: Estimated 3D eye center transforms (leftEyeTransform, rightEyeTransform) and estimated gaze target point (lookAtPoint) in the face coordinate system.
Corneal and Pupil Landmarks: Spatial coordinates derived from eye transforms and facial geometry to estimate pupil centers and corneal apex positions relative to the facial coordinate system.
Front-Facing Depth Map Data: Captured depth sensor buffers (AVDepthData) used to determine measurement distance (verifying the 30–40 cm range) and assist in scale calibration.
Facial Blend Shapes: Blink coefficient values (eyeBlinkLeft, eyeBlinkRight) used exclusively to detect and discard frames affected by blinking during multi-frame measurement.
What We Do NOT Collect: We do NOT collect, generate, or store biometric templates for facial recognition, identity verification, user authentication, emotional tracking, advertising, or behavioral profiling.
3. Use and Purpose of Face Data
The face data processed via the TrueDepth API is used strictly for calculating physical optical parameters required for ophthalmic lens preparation and eyewear fitting:
Pupillary Distance (PD): Binocular far/near pupillary distance and monocular pupillary distances (left/right) relative to the facial midline.
Pupil Segment Height: Vertical distance from the pupil center to the lower rim of a simulated or physical eyeglass frame.
Corneal Vertex Distance (VD): Estimated distance from the corneal apex to the rear surface of the spectacle lens.
Frame Fitting Angles: Pantoscopic tilt angle and face form wrap angle.
Nasal Bridge Topology: Nasal root width, bridge height, and slope to assist with nose pad selection.
Gaze and Pose Compensation: Compensating for convergence angles and device tilt to minimize measurement error.
The App does NOT use face data for advertising, marketing, cross-app tracking, user identification, or commercial data mining.
4. Third-Party Sharing and Disclosure of Face Data
Developer Zero-Sharing Policy: We do not share, sell, rent, or disclose face data or biometric information to any third parties.
The App integrates no third-party SDKs for analytics, advertising, crash reporting, or user tracking.
The App has no background network upload services and operates offline.
User-Initiated Sharing: When the user explicitly chooses to export a measurement report (as a PDF or JSON file), the export is handled exclusively through the standard iOS system Share Sheet. The exported file is transmitted only to the specific destination chosen directly by the user (such as AirDrop, Mail, or local Files).
5. Storage, Retention, and Deletion of Face Data
We apply clear distinction and strict lifecycle management to all data categories:
Transient Raw 3D Face Data: All 3D facial mesh vertices, point clouds, eye transforms, and raw depth buffers exist solely in volatile runtime memory (RAM) while a measurement session is actively running. Once the measurement calculation completes, or when the user exits the measurement screen, or when the App is backgrounded or terminated, the App releases all memory references to these raw 3D mesh and depth buffers. Raw 3D face mesh models and raw depth data are never written to persistent disk storage.
Persistent Derived Measurement Results: Following a completed measurement, the App stores the derived scalar optical values (e.g., PD in millimeters, Segment Height, Vertex Distance), timestamp, user-selected virtual frame parameters, and device model information in a local JSON record within the App's isolated sandbox storage.
2D Verification Image: To allow the user and their optician to visually confirm pupil landmark alignment, the App saves one 2D static verification image with overlaid pupil cross-hair markers in the App's local sandbox storage. This image is stored locally on the device only.
Retention and Deletion: All persistent records and 2D verification images remain in local sandbox storage until deleted by the user. Users can delete individual measurement records or use "Clear History" in Settings to delete all stored records and images. Deleting the App from the iOS device removes all data stored in the App's sandbox.
6. User Data Rights and Controls
Users maintain full control over their data within the App:
Camera Permission Control: Users can grant or revoke camera access at any time in iOS Settings → OptiPro Measure. Without camera access, no measurement or face tracking can occur.
Local Record Management: Users can inspect, export, or permanently delete any stored measurement record directly within the App.
No Account Registration: The App requires no account creation, email address, phone number, or personal identity information.
7. Data Security
All processing is executed on-device using iOS system frameworks, Apple's Neural Engine, and isolated application sandboxing. The developer operates no remote database or sync servers for user measurement data.
8. Children's Privacy
The App is not directed to children under 13 years of age, and we do not knowingly collect personal information from children.
9. Contact Us
If you have any questions, feedback, or requests regarding this Privacy Policy or our face data practices, please contact us at: