MirrorMe — AI hairstyle preview
Effective date: TODO date · Last updated: TODO date
This policy explains what personal data MirrorMe (the "App") collects, why we collect it, who we share it with, and what rights you have. It applies to the iOS and Android apps and the backend services that support them.
The data controller is TODO legal entity name, TODO registered address.
For any privacy question or to exercise your rights, contact TODO privacy contact email.
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Email address, display name, account identifier | You, via Sign in with Google or Sign in with Apple |
| Photos you provide | Photographs you take in the App or choose from your photo library, and the hairstyle images generated from them | You |
| Purchase data | Subscription status, purchase and renewal history | Apple App Store / Google Play, via RevenueCat |
| Device and technical data | Device model, operating system version, app version, language, push notification token, IP address | Collected automatically |
| Usage and diagnostics | In-app events, feature usage, crash reports and related stack traces | Collected automatically |
We do not collect your precise location, contacts, calendar, health data, or advertising identifiers, and the App contains no advertising or cross-app tracking SDKs.
This is the most sensitive data the App processes, so we describe it separately.
TODO — legal input needed: confirm whether facial imagery processed this way is treated as biometric / special-category data under GDPR Art. 9 and Turkish KVKK Art. 6 in your target markets, and whether explicit consent must be collected in-app.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account | Account data | Performance of a contract |
| Generate hairstyle previews | Photos, account identifier | Performance of a contract |
| Manage subscriptions and entitlements | Purchase data, account identifier | Performance of a contract |
| Send you notifications about your generations | Push token, account identifier | Performance of a contract; consent where required |
| Keep the service stable and fix faults | Device data, diagnostics, crash reports | Legitimate interests |
| Understand which features are used | Usage events, device data | Legitimate interests; consent where required |
| Prevent abuse and enforce usage limits | Account identifier, request metadata | Legitimate interests |
We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract:
| Provider | What they receive | Purpose |
|---|---|---|
| Google Firebase (Authentication, Cloud Messaging, Analytics, Crashlytics) | Account identifier, email, device data, push token, usage events, crash reports | Sign-in, push notifications, product analytics, crash reporting |
| fal.ai | The photo you submit and the generation prompt | AI image generation |
| Google (Gemini API) | The photo you submit and the generation prompt | AI image and text generation |
| OpenAI | Text prompts | AI text generation |
| Microsoft Azure (Blob Storage) | Original and generated images | Image storage |
| RevenueCat | Account identifier, purchase and subscription events | Subscription management |
| Apple / Google | Purchase transactions | Payment processing and billing |
| TODO hosting provider | All backend data | Application hosting |
We may also disclose data where we are legally required to, or to establish or defend legal claims.
TODO — must be verified before publishing: confirm in each AI provider's current terms whether data submitted through the API may be used to train their models, and whether a zero-retention or enterprise data-processing term applies. If any provider retains or trains on submitted images, that must be stated plainly here.
| Data | Retention |
|---|---|
| Account data | For as long as your account exists |
| Photos and generated images | Until you delete them, or until your account is deleted TODO confirm backend behaviour |
| Purchase records | TODO — typically retained for statutory accounting periods |
| Crash reports and diagnostics | TODO (Crashlytics default is 90 days) |
| Analytics events | TODO (Firebase Analytics retention setting) |
| Backups | TODO — deleted data persists in backups until they rotate |
Our providers operate in the United States and other countries outside your own. Where data leaves the European Economic Area, the United Kingdom, or Türkiye, transfers are made under the safeguards permitted by applicable law, such as the European Commission's Standard Contractual Clauses. TODO — confirm the mechanism relied on for each provider, and the KVKK transfer basis for users in Türkiye.
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, withdraw consent, receive a copy in a portable format, and lodge a complaint with your supervisory authority.
Deleting your account. You can delete your account and its associated data from within the App, under Profile. This removes your account record and the images associated with it. Deletion cannot be undone.
To exercise any other right, contact TODO privacy contact email.
Traffic between the App and our servers is encrypted in transit using TLS. Data at rest is encrypted by our cloud providers. Access to production systems is restricted to authorised personnel. No system is perfectly secure, and we cannot guarantee absolute security.
MirrorMe is not directed to children under TODO age — must match the App Store and Google Play age rating you declare, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy. When we do, we will change the "Last updated" date above, and for material changes we will give notice in the App before the change takes effect.
TODO legal entity name
TODO registered address
TODO privacy contact email
TODO — if you have an EU or UK representative or a Data Protection Officer, name them here.