ST✦

Privacy Policy

Last updated: October 1, 2026. Policy version 2026-10-01.

This policy explains what information Sculpt & Tell (cosmeticsurgeryinsider.com) collects when you visit, why we collect it, who we share it with, how long we keep it, and the choices you have.

Quick links: Notice at Collection · Your Privacy Choices · How long we keep information · Contact us

Who we are

Sculpt & Tell ("we", "us", "our") runs cosmeticsurgeryinsider.com and is the business responsible for the personal information described in this policy (in EU and UK terms, the "controller").

Email for every privacy question or request: hello@cosmeticsurgeryinsider.com.

We have not appointed a representative in the European Union or the United Kingdom.

Notice at Collection

This is a summary of the personal information collected when you use this site. "Sold or shared" uses the meaning in California and other US state privacy laws, where giving information to advertising companies so they can show targeted ads counts as a sale or sharing even when no money changes hands for the data itself. The sections below give the detail.

Identifiers

  • What: your IP address; cookie, device and advertising identifiers; session and page identifiers; characteristics of your device and browser that can be used to tell one device from another; a user ID or email address, if you give it to us or if the app or offer partner that sent you includes it in the link; a research participant ID, if you arrive from a research study.
  • Why: showing and measuring ads; detecting fraud and invalid traffic; keeping the site secure; analytics; managing how many visits each campaign receives; answering you; running research studies.
  • Sold or shared: yes. Your IP address and cookie and advertising identifiers are included in ad requests sent to advertising companies.
  • How long: most records up to 180 days and research records up to 365 days; samples kept to calibrate fraud detection, fraud-prevention providers' visit reports and our lookup table of IP addresses up to 24 months. Cookie lifetimes are listed under Cookies and similar technologies. Details: How long we keep information.

Internet and other electronic network activity

  • What: the pages you view and their addresses; the page, ad or link that brought you here, including the campaign and traffic-source details in that link; if you browse inside an app's built-in browser, the name of that app; how you interact with pages and ads, such as time on page, scrolling, clicks, and mouse, touch and keyboard activity (which can include the position and timing of pointer movements and touches and the timing of key presses, but not which keys you press); which ads were shown and whether they were visible; page performance information.
  • Why: showing and measuring ads; reporting to and settling payments with advertising partners; detecting fraud and invalid traffic; analytics.
  • Sold or shared: yes. The address of the page you are viewing is included in ad requests.
  • How long: most records up to 180 days and research records up to 365 days; samples kept to calibrate fraud detection up to 24 months.

Approximate location

  • What: country, region, city and time zone worked out from your IP address. We do not collect precise location such as GPS.
  • Why: detecting fraud and invalid traffic; reporting; advertising partners use it to choose ads.
  • Sold or shared: yes, because ad requests contain your IP address.
  • How long: most records up to 180 days; samples kept to calibrate fraud detection, fraud-prevention providers' visit reports and our lookup table of IP addresses up to 24 months.

Inferences

  • What: our assessment of whether a visit looks like it comes from a real person; on sites with rewarded content, a simple engagement category for your browser.
  • Why: deciding whether to show ads on a visit; analysing and improving our rewarded content.
  • Sold or shared: no. Our assessment of a visit is also disclosed to the traffic partner that sent it (see Who we share information with).
  • How long: up to 180 days for our own assessments and engagement categories; fraud-prevention providers' visit reports, which include their assessment, up to 24 months.

Commercial information

  • What: if you arrive from a rewarded offer in an app or offer wall, a transaction ID, details of the offer and a code for the app or offer wall you came from; some offer providers also include your user ID and email address.
  • Why: crediting the reward you earned; managing how many visits each campaign receives.
  • Sold or shared: a code for the app or offer wall you came from is included in requests to Google's ad server on rewarded pages. We send the transaction ID back to the offer provider at your direction.
  • How long: up to 90 days in our analytics systems; our record of rewards reported to offer providers up to 24 months; the rewarded-content cookie lasts up to one year.

Contact information you give us

  • What: your email address and anything you write to us; if you use an email sign-up form, also your IP address and browser details at the time.
  • Why: answering you; keeping a record of the sign-up.
  • Sold or shared: no.
  • How long: emails up to 24 months after we finish handling your message; privacy-request records for at least 24 months; sign-up records up to 24 months.

We do not collect sensitive personal information as defined by California law, such as government ID numbers, precise location or account log-ins, and we do not use or disclose sensitive personal information for purposes other than those the law allows without a right to limit, such as security and fraud prevention. Because ad requests include the address of the page you are reading, advertising companies can see what the page is about, including when the page covers a topic such as health or money.

To opt out of the sale or sharing of your personal information, see Your Privacy Choices.

Information we collect

Information you give us

  • Email. If you email us, we receive your email address and whatever you include.
  • Sign-up forms. Some of our sites show an email sign-up form. If you submit it, we store your email address, the site, the date and time, your IP address and your browser's user-agent string. We do not currently send newsletters or any other email to addresses collected this way.
  • Rewarded offers. If you come to this site to complete a rewarded offer, the offer provider gives us a transaction ID, offer details and a code for the app or offer wall you came from, and some providers also include your user ID and email address.
  • Research studies. If you take part in a research study, we receive your participant, study and session IDs from the study link. See Research participants.

Information collected automatically

Collection starts when you click one of our links. Our redirect service records your IP address, browser details, the referring page and the details in the link, and our servers can record technical characteristics of your connection, before the page loads. On the page, our code and our partners' code running in your browser then collect information about the visit, including on the first page you reach after clicking an ad or link.

  • Connection information: your IP address, the network provider it belongs to, and approximate location worked out from it.
  • Browser and device information: browser type and version, operating system, language and time zone settings, screen size, device memory and processor details, connection type, and other characteristics of your device, browser and network connection; if you browse inside an app's built-in browser, the name of that app.
  • Page and interaction information: the pages you view, the page or link that referred you, campaign and traffic-source details in the link you followed (which can include a click ID, a user ID, an email address or a search keyword passed by the site or app that sent you), time on page, scrolling, clicks, mouse, touch and keyboard activity (which can include the position and timing of pointer movements and touches and the timing of key presses, but not which keys you press), and which ads were shown and visible.
  • Identifiers stored in your browser: see Cookies and similar technologies.

Information from other companies

  • Advertising companies return ads and identifiers to your browser and may tell us about ads shown and clicked.
  • Fraud-prevention providers send us reports about visits to our sites, which include IP address, browser details, device type, country and network provider, along with their assessment of the visit.
  • Research panel providers pass participant, study and session IDs in the study link.
  • Offer providers pass a transaction ID, offer details and a code for the app or offer wall you came from in the link when you come to complete a rewarded offer; some also pass your user ID and email address.

How we use information

  • To show ads on this site, measure them, and report and reconcile ad revenue with our advertising partners.
  • To detect and prevent invalid traffic, fraud and abuse (explained in the next section).
  • To keep the site working and secure, fix problems, and understand how the site is used.
  • To provide rewarded content you choose to use, credit rewards, and analyse and improve our rewarded content.
  • To manage how many visits each campaign receives, including limiting repeat visits using the user ID a partner passes to us.
  • To run research studies that participants choose to take part in.
  • To answer your messages and handle privacy requests.
  • To comply with the law and protect our rights.

We do not collect, use or sell personal information to train large language models.

Fraud and invalid-traffic prevention

We and our security providers collect information about your device, browser and network connection and about how pages are used: for example your IP address and browser and device characteristics. Some of these characteristics, taken together, can distinguish one device or browser from another (this is sometimes called device fingerprinting).

We use this information to detect and prevent invalid traffic, fraud and abuse, including activity that would charge advertisers for visits that do not come from real people. If a visit looks invalid, we may not show ads on it. We also report these results, with the visit details behind them, to the traffic partner that sent the visit.

We don't publish the details of our methods, because doing so would help bad actors avoid them. We do not use this information to target ads to you. Opting out of sale or sharing does not stop this security use.

Advertising

This site is paid for by advertising. Most ads are chosen in real-time auctions. When a page loads, code in your browser sends ad requests to advertising exchanges (also called supply-side platforms). The exchanges pass the requests on to many advertisers and the technology companies that buy ads for them. Ad requests include your IP address, browser and device information, the address of the page, approximate location, and identifiers stored in your browser.

These companies use the information to decide which ad to show, to show you ads based on your interests and your activity on other websites (interest-based or personalised advertising), to limit how often you see an ad, and to measure ads. Under California and other US state privacy laws, this is a "sale" or "sharing" of personal information.

  • Advertising identity services. Our pages use advertising identity services, including Criteo, The Trade Desk's Unified ID and a shared first-party ID, which store identifiers in cookies and local storage so advertisers can recognise your browser across websites. We also record these identifiers with our own visit records. Some of these services are contacted as soon as a page loads.
  • Cookie syncing. Advertising companies exchange their identifiers for your browser with each other through small images and frames loaded on our pages.
  • Google. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to this site and other sites on the internet. On our sites, Google's ad tags run on rewarded and full-screen ad pages and on some older page layouts. On rewarded pages we also send Google's ad server the campaign and traffic-source details from the link that brought you, including the identifier the sending site or app assigned and a code for the app or offer wall you came from. You can opt out of personalised advertising from Google at Google Ads Settings. Learn more about how Google uses information from sites that use its services.
  • Rewarded content. If this site offers rewarded content (content you unlock by viewing an ad or completing an offer), we set a cookie on a separate service domain that we operate. It holds a random ID, lasts up to one year, and lets us recognise your browser across our sites so we can manage rewarded ads. We place the browser in a simple engagement category based on its past rewarded-ad activity and use it only to analyse and improve our rewarded content; we do not pass it to advertising companies. When you earn a reward (by watching the ad or, on some offers, by clicking it), we send the transaction ID to the offer provider so they can credit you. Automated checks on the visit and hourly limits decide whether and when we report it. Our redirect service does not set the rewarded-content cookie for visitors it locates in the European Economic Area, the UK or Switzerland.

Advertising companies use the information they receive under their own privacy policies. A list of the advertising companies and other third parties we sell or share personal information with is available on request at hello@cosmeticsurgeryinsider.com.

Cookies and similar technologies

Cookies are small files a website stores in your browser. Similar technologies include local storage, session storage, small images (pixels) and scripts that read information from your browser. "First-party" items belong to this site's domain; "third-party" items belong to another company's domain.

Needed to run the site and record your choices

  • Consent tool storage (first-party cookies and local storage on this site's domain, written by our consent platform's script, for visitors in the EEA, UK and Switzerland): record your consent choices, for example euconsent-v2 and addtl_consent. They last as long as the consent platform sets.
  • Link settings (first-party session storage): values from the link you arrived on, such as campaign settings and the traffic source. They are cleared when you close the tab.
  • Image delivery (first-party cookie, 30 minutes): marks visits that arrive through our links so images can be served in a lighter format.

Security and fraud prevention

  • Our security storage (first-party local storage and session storage): values used for security and fraud prevention. Most last only for your browser session; some local-storage values last 3 days, and some have no expiry and stay until you clear your browser's site data.
  • Our providers' storage (third-party): our fraud-prevention providers may store identifiers or values in your browser for the same purpose, for periods they set.

Advertising

  • _sharedid (first-party cookie, 365 days): a shared advertising ID that ad exchanges can read. We also record it, and the Criteo and Unified IDs, with our own visit records.
  • pbjs-unifiedid (first-party cookie, 60 days): The Trade Desk's Unified ID.
  • cto_bidid and cto_bundle (first-party cookies, 390 days, with copies in local storage that do not expire): Criteo's advertising IDs, set by our page from Criteo's response.
  • _sharedid_cst, pbjs-unifiedid_cst (first-party, same lifetimes): technical companions to those IDs.
  • Ad partner cookies (third-party): ad exchanges, advertisers, their technology providers and Google set and read cookies on their own domains, including through cookie syncing, for periods they set.
  • Rewarded-content ID (third-party cookie on our own service domain, up to 1 year): explained under Advertising.

Analytics and site operation

  • Our analytics (first-party session storage): session and page identifiers that tie the events of one visit together. They are cleared when you close the tab.
  • Site operation (first-party local storage and session storage, and a cookie on a service domain we operate that our pages check on each load): settings used to run, test and troubleshoot the site. The cookie lasts up to one year.
  • Session recording and analytics on older layouts: some older page layouts can load Microsoft Clarity or Inspectlet, session-recording analytics tools, and Google Analytics. They run only on sites where we have switched them on.

Content from other services

Our pages load fonts, code libraries and placeholder images from Google Fonts, jsDelivr, cdnjs, the jQuery CDN and Picsum. When your browser fetches them, those services receive your IP address, browser details and the address of the page.

Do Not Track and tracking across websites

Our sites do not respond to browser "Do Not Track" signals. A Global Privacy Control (GPC) signal is different from Do Not Track: Your Privacy Choices explains how we handle it. Other companies, including our advertising partners, can collect information about your activity over time and across different websites when you use this site.

Who we share information with

Sale and sharing for advertising

In the past 12 months we have sold or shared these categories of personal information: identifiers, internet and electronic network activity, approximate location, and commercial information (on rewarded pages, a code for the app or offer wall you came from). We sold or shared them with advertising exchanges and supply-side platforms, advertisers and their buying platforms, advertising identity providers, and Google, so that they could choose which ads to show you, show you ads based on your interests and your activity on other websites, limit how often you see an ad, and measure ads.

Service providers and other recipients

We also disclose personal information to the recipients below. Some act as our service providers under contracts that limit how they use it; others, including traffic partners and some fraud-prevention providers, use it under their own terms.

  • Hosting, content delivery and infrastructure providers, for running our websites, redirect links and data systems.
  • Database, analytics and data-processing providers, for storing and analysing the information described here.
  • Our consent platform, for showing the consent tool and recording choices.
  • Fraud-prevention providers, which receive device, browser, interaction and connection information, including IP address; the address of the page, including campaign and traffic-source details from the link that brought you; and a coded session identifier that lets us match their findings to our own records. For research participants this includes the participant ID.
  • Traffic partners, meaning the companies that buy or send visits to our sites, which receive reports about the visits they sent, including IP address, approximate location, device, browser and network characteristics, and our assessment of whether each visit was valid.
  • Offer providers, which receive the transaction ID when you earn a reward. When a campaign has reached its limit, we may send you on to the offer partner's other content and pass along the user ID and email address that partner's link gave us.
  • Authorities and others where required, for example to comply with law, respond to lawful requests, or protect rights and safety, and a buyer or successor if we sell or transfer our business.

In the past 12 months we disclosed identifiers, internet and electronic network activity, approximate location, inferences and commercial information to these recipients for these business purposes: running and securing our sites and links, storing and analysing data, recording consent choices, detecting fraud and invalid traffic, reporting on traffic, and crediting rewards.

We have no actual knowledge that we sell or share the personal information of consumers under 16.

Your Privacy Choices

Your right to opt out of sale, sharing and targeted advertising

You have the right to tell us not to sell or share your personal information and not to use it for targeted advertising. Here is how.

  • Email us at hello@cosmeticsurgeryinsider.com with the subject "Do Not Sell or Share". We will apply it as soon as possible and within 15 business days to any information we can link to the details you give us, such as an email address or research participant ID. We don't run user accounts, and ad requests are sent directly from your browser, so an email request cannot stop those ad requests for your browser.
  • Browser settings. Blocking third-party cookies limits cross-site identifiers set on other companies' domains; clearing cookies and other site data for this site removes the advertising IDs our pages store. Neither stops ad requests, which still contain your IP address and the page address.
  • Industry opt-out tools. You can opt out of interest-based ads from participating companies through the Digital Advertising Alliance, the Network Advertising Initiative and, in Europe, Your Online Choices. These opt-outs are stored as cookies, so they stop working if you clear cookies or change browsers.
  • Google. Use Google Ads Settings to turn off personalised ads from Google.
  • Global Privacy Control. Our sites do not currently treat a Global Privacy Control (GPC) signal as an opt-out, so advertising identifiers and cookie syncing continue when your browser sends one.

We do not yet provide an on-page control that opts your browser out. See Limits of our privacy controls today.

Visitors in the EEA, the UK and Switzerland

Content pages show a consent tool where you can accept or refuse advertising cookies and related processing. After you make a choice, a "Privacy" button at the bottom right of the page lets you change it. You can also email us to withdraw consent.

Your right to object. If you are in the EEA or the UK, you can object at any time to our use of your personal information based on legitimate interests, including fraud prevention and analytics, and you can object at any time to its use for advertising, including profiling for advertising. Email hello@cosmeticsurgeryinsider.com with the subject "Objection".

Limits of our privacy controls today

We want you to know where our controls do not yet reach:

  • No automatic opt-out signal. As described above, a Global Privacy Control signal is not treated as an opt-out, and there is no on-page opt-out control yet.
  • The consent tool does not appear everywhere. It is not shown on the first page you reach after clicking an ad or link, or on some rewarded-content pages.
  • Some processing does not wait for your consent choice. Our fraud-prevention and analytics collection, and some advertising requests, advertising identity services and cookie syncing, run when the page loads, whether or not you have made a choice in the consent tool, and they do not change if you refuse. Google's ad tags do read your choice.

Your rights

United States

Depending on the state you live in, you may have the right to:

  • know what personal information we collect, use, disclose, sell and share, and get a copy of it in a portable format;
  • have us delete it;
  • have us correct it if it is wrong;
  • opt out of its sale, sharing and use for targeted advertising;
  • in Oregon and Minnesota, get a list of the specific third parties we have disclosed your personal information to, and in Connecticut, a list of the third parties we have sold it to;
  • in Minnesota, question the result of profiling that has legal or similarly significant effects on you;
  • not be treated differently for using these rights.

We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects about you, such as decisions about credit, housing, insurance, education, employment or health care, so the right to opt out of that kind of profiling does not apply. Because we use and disclose sensitive personal information only for purposes the law allows without a right to limit, that right does not apply either.

European Economic Area, United Kingdom and Switzerland

You have the right to access your personal information, have it corrected or erased, restrict how we use it, object to how we use it (see "Your right to object" above), receive it in a portable format, and withdraw consent at any time without affecting earlier processing. You also have the right to complain to a data protection authority: in the UK the Information Commissioner's Office, in the EEA your local supervisory authority. If you are in the UK and have a complaint about how we use your information, email us first if you can: we will acknowledge it within 30 days and tell you what we will do.

How to make a request

  • Email hello@cosmeticsurgeryinsider.com. Say which site you visited, roughly when, and what you are asking for.
  • Verification. We do not run accounts, so most information we hold is linked to cookie or device identifiers, an IP address or a participant ID, not to your name. To find and verify it we may ask for details such as your IP address at the time, the approximate dates and times of your visits, or the email address or participant ID you used. For a request for specific pieces of information we may ask for at least three such details and a signed statement that you are the person the request is about. Because we do not run accounts, for some requests we may not be able to verify you to the standard the law requires; where we cannot, we will tell you and explain why.
  • Authorised agents. Someone can make a request for you if you give them signed permission. We may ask you to confirm your identity with us directly.
  • Timing. We will confirm receipt within 10 business days and respond within 45 days under US state laws (we may extend this by another 45 days and will tell you why), or within one month under EU and UK law (extendable by two months for complex requests).
  • Appeals. If we decline your request, you can appeal by replying with the subject "Appeal". We will answer within 45 days. If you are not satisfied, in California you can complain to the California Privacy Protection Agency or the Attorney General, and in other states to your state attorney general.

Legal bases for processing (EEA and UK)

  • Fraud and invalid-traffic prevention, and security: our legitimate interests, and those of advertisers and partners, in preventing fraud and keeping the sites secure.
  • Analytics and running the site: our legitimate interests in operating and improving the site.
  • Reading and storing information on your device: consent, collected through our consent tool, except where the reading or storage is strictly necessary for a service you asked for. Some of our collection does not yet wait for your choice: see Limits of our privacy controls today.
  • Advertising, and the cookies and device access it relies on: consent, collected through our consent tool. See Limits of our privacy controls today for the processing that does not yet follow that choice.
  • Rewarded content you choose to use: providing the service you asked for.
  • Research studies: our legitimate interests in running the study you chose to take part in; taking part is voluntary.
  • Answering you and handling requests: our legitimate interests, and compliance with legal obligations.

Assessing whether a visit is valid can lead to ads not being shown on it and, for rewarded offers, to a reward not being reported. That decision has no legal or similarly significant effect on you.

International transfers

Most of our data systems are in the United States, so information about visitors from the EEA, the UK and Switzerland is transferred to the United States. For transfers out of the EEA, the UK and Switzerland we rely on the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum. Email us for a copy of the safeguards that apply.

How long we keep information

  • Page, ad and interaction records: up to 180 days.
  • Redirect and link-click records: up to 180 days; in-app browser details up to 90 days.
  • Device, browser and network connection characteristics collected for fraud prevention: up to 180 days.
  • Rewarded-offer records: up to 90 days in our analytics systems; our record of rewards reported to offer providers, which includes session, click and app identifiers, up to 24 months; the rewarded-content cookie lasts up to one year.
  • Research study records: up to 365 days in our analytics systems; research participant profiles up to 24 months after your last study.
  • Samples of device and browser records, including IP address, kept to test and calibrate our fraud detection: up to 24 months.
  • Visit reports from fraud-prevention providers, which include IP address, browser details, device type, country and network provider: up to 24 months.
  • A lookup table of IP addresses seen on our sites, with the network operator, country and time zone of each: up to 24 months.
  • Email sign-up records: up to 24 months.
  • Emails you send us: up to 24 months after we finish handling your message.
  • Short-term event backups: about 3 days.
  • Server logs kept by our hosting and content-delivery providers: for the periods those providers set.
  • Privacy-request records: at least 24 months, as California law requires.

Research participants

If you take part in a research study through a research panel provider, we receive the identifiers the provider gives us and use them, together with information about your visit, for that study and for fraud and invalid-traffic prevention. We may share your participant ID with a fraud-prevention provider. We may mark a participant ID so that later visits are excluded from our measurements; you can still complete the study. Taking part is voluntary. Email us if you want more detail about how a study uses your information. If you are in the EEA or the UK, you can object at any time by emailing us.

Security

We protect personal information with reasonable technical and organisational measures, such as encrypted connections and limits on who can access our systems. No system is completely secure.

Children

This is a general-audience site. It is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, email us and we will delete it.

Changes to this policy

We review this policy at least once a year. When we change it, we update the "Last updated" date at the top. If a change materially affects how we use information we already hold, we will post a notice on this page before the change takes effect.

Contact us

Email: hello@cosmeticsurgeryinsider.com