Face Shape and Color Analysis Mini-Program, in One Month (Privacy-First)
Posted on September 24, 2026
Background
A client needed a WeChat mini-program: users take selfies, the app analyzes their face shape and personal color season, generates a paid beauty report (with PDF download), and funnels high-intent users toward offline makeup coaching. Two constraints were fixed from day one:

- Privacy — face photos must never be uploaded. Not a compliance nicety; the product's license to exist
- Schedule — one month from frozen requirements to launch
My role
Solo, full-stack delivery: requirements freeze and specs, system architecture, algorithm adapters, front end and back end, the test suite, and the handover kit — technical design, testing guide, on-device regression checklist, and a client-facing launch checklist are all deliverables. ~26k lines: 9.3k back end (Python/FastAPI) + 16.4k front end (uniapp/Vue3/TS).
Technical decisions
The privacy-first pipeline is the foundation. wx.faceDetect extracts 106 landmarks and 3-zone skin RGB on the device; what crosses the network is a feature payload under 1 KB, and temp files are wiped immediately. The backend API's schema physically rejects base64/URL image fields — not "we promise not to send photos"; sending them is impossible.
Algorithms sit behind adapter interfaces (face shape / skin tone / recommendation independently replaceable): 36 landmarks match 7 face-shape templates plus classical proportion checks; 9 profile points yield nose projection and facial convexity — a "contour depth" shown only as high/mid/low per the client's call that raw scores feel too sensitive; 3-zone RGB goes through IQR outlier removal into HSV/Lab for the four-season color typing.
The commercial loop shipped complete:
The free tier is a 3-item hook; ¥19.9 unlocks the full eight-section report (same layout as the downloadable PDF), ending in the coaching referral:
Engineering calls worth noting: a MOCK_WECHAT switch makes login/pay/refund run end-to-end locally without WeChat credentials, with zero front-end change when flipped to the real chain; PDFs render via WeasyPrint with an automatic fallback to pure-Python fpdf2 when Pango is missing; and the admin console edits content as configuration — the client's 0903 content revision (copy red-lines, section changes) shipped without a single code change.
Content rules treated as engineering constraints: we froze a copy red-line with the client (no negative appearance wording; ratio data always framed positively), copy frozen at analysis time, old reports never retroactively rewritten — all captured in a domain glossary so "how we speak" and "how we code" share one source of truth.
Outcome
One month, one person, a complete loop: the privacy promise is enforced by architecture, not policy; the E2E black-box suite runs against the live server and catches deploy drift ("code updated, process not restarted"); the client iterates content through configuration instead of releases. 65 commits, 2026-08-24 to 09-24.
Runs as a WeChat mini-program — scan the QR code at the end of the Chinese edition to open it (WeChat required).