DRAFT — not yet legally reviewed. Written from a technical audit of the app and backend (September 2026). Every TODO must be filled in, and the whole document reviewed by counsel, before this is published or submitted to the app stores. See the open questions at the end.

Privacy Policy

MirrorMe — AI hairstyle preview

Effective date: TODO date · Last updated: TODO date

This policy explains what personal data MirrorMe (the "App") collects, why we collect it, who we share it with, and what rights you have. It applies to the iOS and Android apps and the backend services that support them.

1. Who is responsible for your data

The data controller is TODO legal entity name, TODO registered address.

For any privacy question or to exercise your rights, contact TODO privacy contact email.

2. What we collect

CategoryExamplesWhere it comes from
Account dataEmail address, display name, account identifierYou, via Sign in with Google or Sign in with Apple
Photos you providePhotographs you take in the App or choose from your photo library, and the hairstyle images generated from themYou
Purchase dataSubscription status, purchase and renewal historyApple App Store / Google Play, via RevenueCat
Device and technical dataDevice model, operating system version, app version, language, push notification token, IP addressCollected automatically
Usage and diagnosticsIn-app events, feature usage, crash reports and related stack tracesCollected automatically

We do not collect your precise location, contacts, calendar, health data, or advertising identifiers, and the App contains no advertising or cross-app tracking SDKs.

3. Your photos — how they are handled

This is the most sensitive data the App processes, so we describe it separately.

TODO — legal input needed: confirm whether facial imagery processed this way is treated as biometric / special-category data under GDPR Art. 9 and Turkish KVKK Art. 6 in your target markets, and whether explicit consent must be collected in-app.

4. Why we use your data, and on what legal basis

PurposeData usedLegal basis (GDPR)
Create and secure your accountAccount dataPerformance of a contract
Generate hairstyle previewsPhotos, account identifierPerformance of a contract
Manage subscriptions and entitlementsPurchase data, account identifierPerformance of a contract
Send you notifications about your generationsPush token, account identifierPerformance of a contract; consent where required
Keep the service stable and fix faultsDevice data, diagnostics, crash reportsLegitimate interests
Understand which features are usedUsage events, device dataLegitimate interests; consent where required
Prevent abuse and enforce usage limitsAccount identifier, request metadataLegitimate interests

5. Who we share data with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract:

ProviderWhat they receivePurpose
Google Firebase (Authentication, Cloud Messaging, Analytics, Crashlytics)Account identifier, email, device data, push token, usage events, crash reportsSign-in, push notifications, product analytics, crash reporting
fal.aiThe photo you submit and the generation promptAI image generation
Google (Gemini API)The photo you submit and the generation promptAI image and text generation
OpenAIText promptsAI text generation
Microsoft Azure (Blob Storage)Original and generated imagesImage storage
RevenueCatAccount identifier, purchase and subscription eventsSubscription management
Apple / GooglePurchase transactionsPayment processing and billing
TODO hosting providerAll backend dataApplication hosting

We may also disclose data where we are legally required to, or to establish or defend legal claims.

TODO — must be verified before publishing: confirm in each AI provider's current terms whether data submitted through the API may be used to train their models, and whether a zero-retention or enterprise data-processing term applies. If any provider retains or trains on submitted images, that must be stated plainly here.

6. How long we keep data

DataRetention
Account dataFor as long as your account exists
Photos and generated imagesUntil you delete them, or until your account is deleted TODO confirm backend behaviour
Purchase recordsTODO — typically retained for statutory accounting periods
Crash reports and diagnosticsTODO (Crashlytics default is 90 days)
Analytics eventsTODO (Firebase Analytics retention setting)
BackupsTODO — deleted data persists in backups until they rotate

7. International transfers

Our providers operate in the United States and other countries outside your own. Where data leaves the European Economic Area, the United Kingdom, or Türkiye, transfers are made under the safeguards permitted by applicable law, such as the European Commission's Standard Contractual Clauses. TODO — confirm the mechanism relied on for each provider, and the KVKK transfer basis for users in Türkiye.

8. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, withdraw consent, receive a copy in a portable format, and lodge a complaint with your supervisory authority.

Deleting your account. You can delete your account and its associated data from within the App, under Profile. This removes your account record and the images associated with it. Deletion cannot be undone.

To exercise any other right, contact TODO privacy contact email.

9. Security

Traffic between the App and our servers is encrypted in transit using TLS. Data at rest is encrypted by our cloud providers. Access to production systems is restricted to authorised personnel. No system is perfectly secure, and we cannot guarantee absolute security.

10. Children

MirrorMe is not directed to children under TODO age — must match the App Store and Google Play age rating you declare, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date above, and for material changes we will give notice in the App before the change takes effect.

12. Contact

TODO legal entity name
TODO registered address
TODO privacy contact email

TODO — if you have an EU or UK representative or a Data Protection Officer, name them here.