RESOLV

Case study · Health & wellness · In development

AI skin readings with biometric privacy designed in from the first line of code.

A mobile-first platform where customers take a guided selfie, receive an AI skin reading reviewed by a human advisor, and buy recommended products with local mobile money.

18
skin metrics in each AI reading
12 mo
automatic deletion of inactive scan photos
16
versioned database migrations
41
screens and API routes built

CaafimaadAI

The context.

Skincare advice in the Somali market is often informal, and damage from skin-lightening products is a widespread concern. Customers want guidance they can trust, products that suit their skin, and a way to pay that does not depend on an international card.

CaafimaadAI brings those together in one product. Because it processes facial photographs, which are a special category of personal data, privacy and consent were treated as core requirements rather than a legal page added at the end.

The challenge

What made it hard.

01

Biometric data

Facial photos are among the most sensitive data a consumer product can hold. Consent, retention and deletion all had to be explicit and enforceable.

02

AI with a human in the loop

Automated skin metrics are useful but not infallible, so readings needed a human advisor to review them before they become product recommendations.

03

Local payments

Customers pay with mobile money, which needs a server-side payment flow with verified callbacks rather than a card form.

04

Phones and patchy networks

Most customers are on mobile devices, so the product had to install like an app and stay usable on unreliable connections.

Our approach

How we solved it.

  1. 01

    Consent before capture

    A dedicated biometric consent notice explains what is collected, why, how long it is kept and how to withdraw consent, before any photo is taken.

  2. 02

    Retention enforced by code

    A scheduled job deletes scan photos after twelve months of inactivity, and customers can delete their own account from their profile.

  3. 03

    Advisor review and audit

    An advisor workspace reviews each reading, with service-level alerts for scans awaiting review and an audit view in the admin console.

  4. 04

    Hardened by default

    Row-level security on the database, rate limiting with a database fallback, magic-link sign-in and versioned, idempotent migrations.

Highlights

Also delivered.

  • Mobile-money checkout integrated through a server-side payment flow with webhook confirmation
  • Installable progressive web app for mobile customers
  • Product catalogue with curated collections, including recovery from skin-lightening damage
  • Admin console for products, orders, coupons, users, notifications and scans

Technology

The stack.

  • Next.js
  • TypeScript
  • PostgreSQL
  • Supabase
  • Row-level security
  • Redis rate limiting
  • Progressive web app

What comes next

Before launch: production deployment, live payment verification and a published privacy impact assessment for biometric processing.

Hurbad, Watin, TravelOS and CaafimaadAI are platforms built and operated by the Resolv team as our own ventures. We publish them because they are the clearest evidence of how we work: the same people, standards and methods we bring to client engagements.

Want this standard on your system?

A senior engineer reviews every enquiry and replies within one business day.