Privacy Policy

mannequin

Last Updated: 10 September 2026

At mannequin, we respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable local data protection laws.

This Privacy Policy explains who we are, how and why we collect, store, use and share your personal data when you use the mannequin mobile application (the “App”), your rights under European law, and how you can exercise them.

We do not sell your personal data, we do not display advertising, and we do not track you across other applications or websites.

1. DATA CONTROLLER AND CONTACT INFORMATION

Mint Jakub Konieczny, Bretanii 9E, 05-500 Józefosław, Poland · NIP PL9512504458
is the controller of the personal data described here. Questions, requests or complaints: kuba@mint-labs.io.

2. CATEGORIES OF PERSONAL DATA WE COLLECT AND SOURCES

We collect personal data directly from you when you use the App, as well as indirectly from third-party services (Apple and RevenueCat) when you authenticate or subscribe.

A. Data Collected Directly From You

B. Data Collected Automatically

The App contains no crash-reporting service and no advertising identifier. We do not record your screen or replay your sessions, do not retain search history, do not derive your location from your IP address, and do not fingerprint your device.

Product Analytics (Mixpanel): the App records a limited set of product-usage events — that you signed in (and whether the account was newly created), that onboarding was started or completed, that a garment was added, that an outfit was saved or planned, that you locked a garment or opened the accessories drawer while assembling a look, that an automated garment scan failed or that you kept none of what it suggested, that you corrected the garment a scan proposed, that the paywall was viewed, that a plan was chosen on it, that a subscription was started or a previous purchase restored, and that an account was deleted — together with your account identifier, the App version and the platform, and transmits them to Mixpanel, our analytics processor, on servers located in the European Union. Our servers additionally record the subsequent stages of a subscription — that it renewed, was cancelled, encountered a billing problem, expired, or was reactivated — together with the product, store, currency and the reason the store gave, and keep a record of whether your subscription is currently in trial, active or lapsed. We use these events solely to understand which features are used and to improve the App. They contain no garment photographs, no location data and no contact details; where an event concerns a garment it carries only its broad category and the catalogue archetype it was matched to — never your photographs, the names you give things, or a listing of your wardrobe — and they are not used for advertising or shared for any other purpose.

Alongside those events we keep a small profile against your account identifier, so that usage can be understood by group rather than only event by event. It records the objectives you chose during onboarding, which wardrobe you are currently using, and how many garments you have saved — a count only, never the garments themselves. It contains no new categories of information: each of these is data you have already provided to the App.

Two further limited records exist, each necessary to operate a specific feature rather than to observe you:

C. Data Collected From Third Parties & System Integrations

D. Notifications and Reminders

Reminders are scheduled and displayed by your own device. Where you enable reminders — a daily prompt, a notification when the weather changes, a packing reminder before a trip, or a note concerning garments you have not worn — your device schedules and presents them locally. The App uses no push notification service: we hold no push token, our servers transmit nothing to you, and the content of a reminder never leaves your device. Reminders remain disabled until you enable them, and may be disabled individually in the App or entirely in iOS Settings.

For completeness, the App does not access your contacts, your calendar, your photo library beyond the images you expressly select, your browsing activity, or any advertising identifier.

3. PURPOSES, LEGAL BASES, AND RETENTION PERIODS

Under Art. 6(1) GDPR, we process your personal data only when we have a valid legal ground. The table below is exhaustive as to the processing we carry out.

Processing Purpose Categories of Data Involved GDPR Legal Basis Retention Period
Account Creation & User Management Apple User ID, Email Address, Display Name Art. 6(1)(b) GDPR (Contract performance) Retained until you delete your account or request erasure.
Digital Wardrobe & Styling Services Garment Data, Garment Photos, Saved Outfits, Styling Plans Art. 6(1)(b) GDPR (Contract performance) Retained until individual items are deleted, and in no event beyond account closure.
Automated Garment Attribute Recognition The single Garment Photo submitted for the scan Art. 6(1)(b) GDPR (Contract performance) Transmitted to our recognition subprocessor and processed to answer that single request. It is not used to train that provider's models and is retained by it only for the limited period permitted under our agreement with it, after which it is deleted. The photograph itself remains in your wardrobe until you delete the item.
Garment Photo Normalization The Garment Photo submitted (in whole, or the portion showing a particular garment where one photograph holds several), and the derived Normalized Garment Images (the cleaned product-style image and, where you keep it, the worn-view outfit cutout) Art. 6(1)(b) GDPR (Contract performance) The photograph is transmitted to our image subprocessor and processed in real time solely to generate the cleaned image — once per garment it shows, and, where you keep the photo as the item's picture, again for the worn-view cutout, which is generated up to three times if a result is unusable; it is not used to train that provider's models. The derived images are stored in your wardrobe until you delete the item or your account.
Personalisation of Styling Suggestions Activity Data, Garment Data, Styling Plans Art. 6(1)(b) GDPR (Contract performance) Retained until account deletion. The learned preference may be reset at any time in Settings.
Improvement of Automated Recognition Corrections to automated recognition results Art. 6(1)(f) GDPR (Legitimate interest in recognition accuracy) Recognition rules are derived in aggregate, and only where several distinct users have made the same correction, such that no rule is attributable to you. The underlying records are retained until account deletion.
Completion of the Garment Catalogue Catalogue Suggestions, including any optional photograph Art. 6(1)(f) GDPR (Legitimate interest in providing a catalogue) Retained until account deletion.
Product Improvement & Satisfaction Measurement App Feedback, App version, platform Art. 6(1)(f) GDPR (Legitimate interest in service improvement) Retained until account deletion.
Product Analytics Product-usage events with account identifier, App version and platform, the profile traits described in Section 2.B (stated objectives, active wardrobe, number of garments saved), and server-recorded subscription lifecycle events and status (see Section 2.B) Art. 6(1)(f) GDPR (Legitimate interest in understanding which features are used) Retained until account deletion, or until you object (see Section 9).
Onboarding Personalisation Demographic Data (age range) and the objectives you state for the App Art. 6(1)(a) GDPR (Consent — both questions are optional and may be skipped) Retained until you ask us to amend or clear them (write to kuba@mint-labs.io) or delete your account. The objectives you state determine where the App opens; the age range is stored with your profile and does not presently influence the suggestions you are shown.
Local Weather Integration for Outfits Coarse Coordinates or Manually Selected City Art. 6(1)(a) GDPR (Consent, for device location) or Art. 6(1)(f) GDPR (Legitimate interest, for a city you select yourself). The legitimate interest is to provide localised weather-adjusted outfit suggestions to users who prefer not to share their GPS location. For Coordinates: processed in real time to fetch the forecast and immediately discarded; they are never stored on our servers. You can withdraw your location consent at any time in iOS Settings. For Selected Cities: your five most recent selections, and any per-day selections in the planner, are stored locally on your device and never on our servers; the oldest selection is replaced as you pick new ones, and all of them are removed when you delete the App.
Subscription Verification & Access Control Subscription status, product identifier, expiry date Art. 6(1)(b) GDPR (Contract performance) Retained until account deletion.
Fair Use Limits & Protection of the Service Usage Counters & Scan Records (account identifier, timestamp and scan-outcome metadata per scan — never the photograph) Art. 6(1)(f) GDPR (Legitimate interest in preventing abuse and protecting systems) The allowance is calculated over a recent window only — the current day (UTC), the past 30 days for picture generations on a paid subscription, or the free-trial period during a trial; the records themselves are retained until account deletion.

Account Inactivity and Storage Limitation

To respect the principle of storage limitation (Art. 5(1)(e) GDPR), we do not retain your personal data indefinitely. If your account remains completely inactive (meaning you have not logged in or interacted with the App) for a continuous period of 24 months, we will consider the account abandoned. We will send an email notification to your registered address, and if you do not log in within 30 days of that notice, we will automatically and permanently delete your account and all associated personal data (including digital wardrobe records, saved plans, and garment photographs) from our active databases.

4. SHARING AND RECIPIENTS OF PERSONAL DATA

We do not sell your personal data. To operate the App, we share necessary data with trusted third-party service providers. These recipients are classified either as our Data Processors (who act strictly on our documented instructions under Article 28 GDPR) or as Independent Data Controllers (who process data under their own privacy policies).

Our Data Processors (Subprocessors bound by DPAs)

Independent Controllers and External Integrations

We do not share your personal data with any other third parties, except where we are legally compelled to do so by applicable EU or Member State law.

5. INTERNATIONAL DATA TRANSFERS

When personal data is transferred outside the European Economic Area (EEA), specifically to the United States (e.g. Anthropic, Google, RevenueCat), we ensure appropriate safeguards under Chapter V GDPR:

You have the right to request and obtain reference to the appropriate or suitable transfer safeguards and the means by which to obtain a copy of them or where they have been made available. To exercise this right and request a copy, please email us directly at kuba@mint-labs.io.

6. DATA SECURITY ARCHITECTURE

We implement robust technical and organisational security measures to protect your personal data (Art. 32 GDPR):

7. AUTOMATED DECISION-MAKING AND PROFILING

We use algorithms to generate personalised outfit recommendations. The inputs are the garments in your wardrobe and their attributes, the feedback you have given to previous suggestions (“nudges”), what you have already planned, the local weather forecast, and the automated garment recognition described in Section 3 — the result of which you may always correct.

8. STATUTORY AND CONTRACTUAL REQUIREMENTS

Providing your Apple ID credentials, holding an active subscription, and providing wardrobe data are contractual requirements necessary to create an account and access the core functionality of the App. Failing to provide this data will prevent you from using the digital wardrobe and automated styling features.

All remaining data is optional, and withholding it leaves the remainder of the App operational:

9. YOUR GDPR DATA SUBJECT RIGHTS

Under the GDPR (Articles 15–22), you have the following rights:

Right to Object (Article 21 GDPR). You have the right to object at any time, on grounds relating to your particular situation, to any processing of your personal data which is based on our legitimate interests (Article 6(1)(f) GDPR), including any profiling related to those interests. If you object, we will immediately stop processing your personal data for those purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defence of legal claims. You can exercise this right easily, free of charge, and at any time by contacting us at kuba@mint-labs.io.

Deletion within the App. You may delete individual garments and outfits at any time. To delete your entire account and everything attached to it — wardrobe, outfits, photographs and plans — open Settings → Account → Danger zone → Delete account and type delete to confirm. Deletion is immediate and permanent. Please note that deleting your account does not cancel an active subscription; subscriptions are managed in your Apple ID settings. If you are no longer able to open the App, write to us from the address associated with your account and we will carry out the erasure on your behalf.

Exercising your rights. You may exercise any right set out above by contacting us at kuba@mint-labs.io. We will respond to your request without undue delay and, in any event, within one month of receiving it. Where permitted by applicable law, this period may be extended by up to two additional months where necessary due to the complexity or number of requests. If we extend the response period, we will inform you within the initial one-month period and explain the reasons for the delay.

10. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY

If you have concerns about how we handle your data, we encourage you to contact us directly at kuba@mint-labs.io.

If you consider that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a competent supervisory authority (Art. 77 GDPR). You can contact Poland's supervisory authority directly:

President of the Personal Data Protection Office
(Prezes Urzędu Ochrony Danych Osobowych)
ul. Stawki 2, 00-193 Warsaw, Poland
https://uodo.gov.pl · kancelaria@uodo.gov.pl

You maintain the right to lodge this complaint with the Data Protection Authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

11. CHILDREN

The App is not directed at children and is not intended for any person under the age of 16, in line with our Terms of Service. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will delete it.

12. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in the App's features, legal requirements, or operational practices. We will notify you of any material updates by posting a prominent notice within the App before the changes take effect, and by updating the “Last Updated” date at the top of this policy.