Your privacy matters to us. This Privacy Policy explains, in plain language, how Applabel LTD (“Applabel”, “we”, “us”) — a company incorporated in the Republic of Cyprus under registration number HE 420746, with its registered office at Panagioti Tsangari 14, 1st floor, Limassol 4047, Cyprus — collects, uses, shares and protects personal data when you use:
Applabel LTD is the data controller of your personal data within the meaning of the EU General Data Protection Regulation (“GDPR”). A particular Service may display a product-specific privacy notice (within the App or on its product website); in case of conflict for that Service, the product-specific notice prevails.
| Category | Examples |
|---|---|
| Account and registration data | Name or nickname, e-mail address, password (stored in hashed form), age or age range, gender (where you choose to provide it), language, timezone |
| Social sign-in data | Name, e-mail, profile picture and account identifier received from Apple, Google or Facebook when you sign in with those services |
| Content submitted to AI features | Prompts, texts, documents, audio recordings and images you submit to AI-powered tools; questions you send to an AI assistant or AI stylist |
| Photos and visual data | Photos of yourself and of your clothing that you choose to upload; derived style attributes (e.g., color type, hair/eye/skin tone categories); body measurements you enter — see Section 4 |
| Style and preference data | Style quiz answers, wardrobe items, wishlists, saved outfits, preferences (in Apps offering styling features) |
| Purchase and billing data | Subscription plan, purchase history, transaction identifiers. Full payment card details are collected by our payment processors (Apple, Google, Stripe) — we do not store them |
| Communications | Your name, e-mail address and the content of messages when you contact support or submit forms on the Website |
| Category | Examples |
|---|---|
| Device and technical data | Device type and model, operating system and version, browser type, app version, language settings, IP address, mobile advertising identifiers (IDFA/GAID, subject to your platform-level choices) |
| Usage data | Features used, session length and frequency, in-app events, interactions, crash logs and diagnostics, referral source |
| Approximate location | Country/city-level location derived from IP address (e.g., for localization, weather-based outfit suggestions and fraud prevention). We do not collect precise GPS location |
| Cookies and similar technologies | See Section 5 |
We do not request access to your full photo library, contacts or microphone beyond what a feature you actively use requires, and permissions you grant at the operating-system level can be revoked in your device settings at any time.
| Purpose | Data used | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Creating and managing your account; providing the Services and their features, including generating AI results, outfit recommendations and color analysis you request | Account data, user content, photos and visual data, style data, device data | Performance of a contract (Art. 6(1)(b)) | While your account is active; deleted within 30 days after account deletion |
| Processing purchases, subscriptions and credits; sending transactional messages | Purchase and billing data, account data | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records | Transaction records up to 7 years (tax law) |
| Responding to your inquiries and providing customer support | Communications, account data | Legitimate interests (Art. 6(1)(f)) — communicating with users; or contract, where support concerns your subscription | Up to 3 years after the ticket is closed |
| Maintaining, securing and improving the Services; debugging; preventing fraud and abuse; enforcing our Terms; establishing, exercising or defending legal claims | Device and usage data, security logs, records relevant to a claim | Legitimate interests (Art. 6(1)(f)) — keeping the Services safe and protecting our legal position | Security logs up to 12 months; claim-related records for the applicable limitation period |
| Analytics and product research (measuring feature usage and performance) | Usage data, device data (pseudonymized where possible) | Legitimate interests (Art. 6(1)(f)); consent (Art. 6(1)(a)) where required for cookies/SDKs | Up to 24 months, then deleted or aggregated |
| Marketing communications (e-mail, push) and measuring advertising campaigns | Contact data, advertising identifiers, usage data | Consent (Art. 6(1)(a)); legitimate interests (Art. 6(1)(f)) for non-intrusive first-party marketing where permitted | Until you opt out or withdraw consent, plus a record of the withdrawal |
| Optional wellbeing-related inputs, where a Service offers such features (e.g., mood or feelings you record) | The data you choose to enter | Explicit consent (Art. 9(2)(a)), withdrawable at any time | Until you delete the entry or your account |
| Complying with legal obligations and lawful requests of competent authorities | Any of the above, as required | Legal obligation (Art. 6(1)(c)) | As required by the relevant law |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you may object at any time (Section 12). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
3.1. Certain features are powered by third-party large language and image models, currently provided by OpenAI, L.L.C. and Google LLC (Gemini API). When you use these features, the content you submit (for example, a prompt, a document or a styling question) is transmitted to the relevant provider for processing.
3.2. What is not transmitted. We do not transmit your name, e-mail address, account identifiers or other directly identifying information to AI providers together with your content. Your original photos are not transmitted to AI providers; only anonymized categorical attributes derived from them (such as hair, eye and skin tone categories) are used to generate recommendations.
3.3. No training. Under our agreements, AI providers may not use content submitted through our Services to train their models. Providers may retain submitted content for a limited period solely for abuse and misuse monitoring (currently up to 30 days for OpenAI and a similarly limited period for Google) and delete it thereafter.
3.4. Please do not include in your prompts any special categories of personal data (such as health information) or other people’s personal data unless you have a lawful basis to do so. You are responsible for the content you choose to submit.
4.1. This Section applies to Apps that offer styling and wardrobe features. Our Apps process photos only when you actively select or take them; we do not access your photo library as a whole.
4.2. Your photos are used solely to provide the features you request — building your digital wardrobe, analyzing your color type, generating outfit recommendations and virtual try-ons. Photos and derived visual attributes are never shared with advertising partners and never sold.
4.3. Uploaded photos are stored for up to 90 days and then permanently deleted. Derived visual profile data (e.g., color type categories) is retained while your account is active and is automatically deleted after 90 days of account inactivity or upon deletion of your account, whichever occurs first.
4.4. Our color and style analysis features use automated image processing. It classifies general visual attributes (such as color tones), is not used to uniquely identify you, and we do not create biometric templates within the meaning of Art. 9 GDPR.
5.1. We and our partners use cookies, SDKs, pixels and similar technologies in three categories: strictly necessary (operating the Services, security, remembering your session), functional (remembering settings and preferences) and analytics/advertising (measuring usage and performance and, with your consent where required, attributing app installs and measuring advertising campaigns).
5.2. You can manage optional technologies through our consent banner (where shown), your browser settings, and your device’s advertising settings (e.g., “Allow Apps to Request to Track” on iOS and “Delete advertising ID” on Android). Disabling certain technologies may affect the functioning of the Services.
We share personal data only as described below and only to the extent necessary:
We do not sell or rent personal data, and we do not share it with non-affiliated companies for their own direct marketing.
| Category | Partners (current) | Data involved |
|---|---|---|
| Hosting, infrastructure and content delivery | Amazon Web Services EMEA SARL; Hetzner Online GmbH (Germany); BunnyWay d.o.o. (bunny.net) | All data stored in the Services, on servers located in the EU |
| Payments | Apple Inc.; Google LLC (app store billing); Stripe, Inc. (web billing) | Purchase and billing data |
| AI processing | OpenAI, L.L.C.; Google LLC (Gemini API) | Content submitted to AI features (see Section 3) |
| Customer support | HelpDesk (Text, Inc.) | Communications, account data |
| Mobile attribution and analytics | Adjust GmbH | Device data, advertising identifiers, install and event data |
| Advertising networks (campaign measurement and attribution) | AppLovin Corp.; Digital Turbine (AdColony); TikTok; Chartboost; Unity Technologies (ironSource); Pinterest; Snap Inc.; Meta Platforms Ireland Ltd.; Google LLC | Advertising identifiers, device data, aggregated event data — never your content, photos or prompts |
The current list of partners may change; we will keep this Section up to date. You can object to advertising-related processing and withdraw consent as described in Sections 5 and 12.
8.1. Our primary servers are located in the EU (Cyprus and Germany). Some of our service providers (for example, AI providers, payment and support providers, and advertising partners) are located in the United States or other countries outside the EEA.
8.2. Where personal data is transferred outside the EEA or the UK, we ensure an adequate level of protection through: (a) European Commission adequacy decisions (including, where applicable, the EU–US Data Privacy Framework for certified recipients); (b) the EU Standard Contractual Clauses and the UK Addendum/IDTA, together with supplementary measures where necessary; or (c) other lawful transfer mechanisms. You may request a copy of the relevant safeguards by contacting us.
| Data | Retention period |
|---|---|
| Account and profile data | While your account is active; deleted within 30 days after account deletion (except data we must keep by law) |
| Uploaded photos | Up to 90 days, then permanently deleted |
| Derived visual profile data | While your account is active; auto-deleted after 90 days of inactivity |
| Content submitted to AI features | Processed transiently to generate results; retained by AI providers for abuse monitoring for up to 30 days (Section 3) |
| Purchase and transaction records | Up to 7 years, as required by tax and accounting legislation |
| Support communications | Up to 3 years after the ticket is closed |
| Usage analytics | Up to 24 months, then deleted or aggregated |
| Security and access logs | Up to 12 months |
| Marketing preferences and consent records | Until you opt out or withdraw consent, plus a record of the withdrawal as evidence of compliance |
Personal data not listed above is retained no longer than necessary for the purposes described in this Privacy Policy and, as a general rule, no longer than 2 years after the relevant purpose has been fulfilled. Longer periods apply only where set out in the table above, required by law (e.g., tax and accounting records), or needed to comply with a legal hold or to establish, exercise or defend legal claims, in which case the data is retained for the duration of the hold or the applicable limitation period.
We apply technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest, pseudonymization where feasible, access controls on a need-to-know basis, logging and monitoring, staff confidentiality obligations, and vendor due diligence with data processing agreements. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; you also play a role by using a strong, unique password and keeping your credentials confidential. If we become aware of a personal data breach likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by Articles 33–34 GDPR.
We may create aggregated, anonymized or otherwise de-identified data from personal data by removing information that makes the data identifiable. Such data is no longer personal data, and we may use and share it for lawful purposes — including analytics, benchmarking, research and improving our Services — provided we do not attempt to re-identify it and we maintain it in de-identified form.
12.1. Subject to the conditions of the GDPR and other applicable law, you have the right to:
12.2. You can exercise most rights directly in the Services (e.g., account deletion in settings) or by contacting applabel@support-team.app. We respond within one month, extendable by two further months for complex requests, in which case we will inform you. We may need to verify your identity before acting on a request, and we may decline requests that are manifestly unfounded or excessive, or where an exemption applies — in each case explaining why.
12.3. You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence or place of work. The supervisory authority for Applabel is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (1 Iasonos str., 1082 Nicosia; www.dataprotection.gov.cy). We would, however, appreciate the chance to address your concerns first.
You are responsible for the accuracy of the information you provide to us and for keeping it up to date. If you submit personal data relating to another person (for example, a photo in which someone else appears), you confirm that you have a lawful basis to do so — such as that person’s permission — and that you have informed them about this Privacy Policy. We process such data on the understanding that this confirmation is true.
The Services are not directed at children. We do not knowingly collect personal data from children under 13 years of age (or under 16 in the EEA/UK, unless a lower age applies under national law). If you believe a child has provided us with personal data, please contact us and we will delete it. Minors above those ages may use the Services only with parental consent, as described in our Terms of Service.
15.1. This Section applies to residents of California and other US states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Texas) and supplements the rest of this Privacy Policy.
15.2. In the preceding 12 months we have collected the following categories of personal information as defined by the California Consumer Privacy Act (CCPA/CPRA): identifiers; customer records; commercial information; internet or other electronic network activity; audio/visual information (photos you upload); and inferences (e.g., style preferences). Sources, purposes and recipients are as described in Sections 1, 2, 6 and 7.
15.3. We do not sell personal information for money. Our use of advertising and analytics SDKs may constitute “sharing” for cross-context behavioral advertising under the CCPA; you may opt out at any time via your device settings (Section 5), via in-app privacy settings where available, or by contacting us. We honor opt-out preference signals such as the Global Privacy Control where technically applicable. We do not knowingly sell or share the personal information of consumers under 16 years of age.
15.4. You have the right to know, access, correct, delete and port your personal information, the right to opt out of sharing, the right to limit the use of sensitive personal information (which we use only to provide the Services), and the right not to be discriminated against for exercising your rights. You may submit requests to applabel@support-team.app; an authorized agent may act on your behalf with proof of authorization. We will verify and respond to verifiable requests within 45 days, extendable by a further 45 days where reasonably necessary.
We review this Privacy Policy regularly and may update it to reflect changes in our practices, the Services or applicable law. If we make material changes, we will notify you by reasonable means (e.g., e-mail, in-app notice or a notice on the Website) before the changes take effect and update the “Last updated” date above. Your continued use of the Services after the effective date constitutes acknowledgment of the updated Policy; where required by law, we will ask for your renewed consent.