Client consent and photo permissions
Updated
A look with a person in it can't leave your device without a consent record. Not to your salon's page, not to Embrly's public surfaces, not through the share sheet. That's enforced in the database rather than trusted to a policy page — a look with no consent stays private to you, which is a perfectly normal thing for a look to be. The one exception is product shots: a shelf, a bottle, a color bowl — nobody in frame, nobody to ask — share without a consent record. If someone does appear in a product shot, record their okay the same way.
In the app: the capture flow, or open any look and use Record client consent
Why it works this way
Your public page and Discover promise clients that every face on them agreed to be there. The consent record is what makes that true — and it means a client never sees themselves online without remembering saying yes.
Each record stores the client's name or initials, confirmation they were 18 or older, and the date. The name is a private audit record: it is never shown on your page, on Discover, or anywhere public.
The four ways to record it
1. At capture. On the review screen there's a Client consent switch, with the hint "Without consent, this photo stays private to you." Turn it on, add their name or initials, and tick My client is 18 or older. Fastest option when your client is right there.
2. Later, from the look. Open the look and use Record client consent — same two fields, for when you skipped the form at capture time. The look's chip flips from Private — no consent to Client consent ✓.
3. The in-chair QR — client's own phone. From a look, show the QR. Your client scans it with their camera and lands on a page headed Two quick things, where they can say yes to sharing and leave a note about the visit.
The two are deliberately separate. Consent is the top card — "Okay to share your photos?" — with their name or initials and a tick box, unticked by default. The note is a different card underneath, and neither needs the other: they can do one, both, or neither. This matters most for the case it was built for — a client under 18 can still write you a note while a parent or guardian scans the same code and gives consent separately.
Each link lasts a week, and each half can be used once. Someone who consents in the chair can come back that evening and write the note.
There's also a Consent only, no note › version if a review would be awkward. Same scan, one card: "Okay to share your look?"
4. Bulk attestation, for past work. You can't retroactively get a form signed by a client from three years ago, so importing past work uses an attestation instead. On Add past work you pick up to 20 photos at a time and confirm: "I have permission from every client in these photos to display them publicly, and each was 18 or older when the photo was taken." Embrly records that statement under your name and today's date in place of the consent forms your clients gave at the time.
The attestation always covers exactly the batch on screen — add or remove a photo and it unticks itself, so you re-read it. If you can't say it about a photo, take that photo out of the batch.
What clients see
Plain language, no account, no signup. Your first name, what they're agreeing to, one tick box, one button. Afterwards: "Permission to share your photos is on record — nothing more to do here. You can ask [you] to take them down anytime." You get a notification the moment it lands.
The consent and note pages are private links. They're not indexed by search engines and can't be found by browsing.
Taking something down
There's no self-service undo for a client. If someone asks you to remove their photos, delete the look — the consent record goes with it, and it stops appearing anywhere. See Account settings, editing and deleting.
A client who can't reach you can email privacy@embrly.app and we'll work with you to resolve it. Treat a take-down request as final, not negotiable.
