Privacy Policy
mannequin
Last Updated: 10 September 2026
At mannequin, we respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable local data protection laws.
This Privacy Policy explains who we are, how and why we collect, store, use and share your personal data when you use the mannequin mobile application (the “App”), your rights under European law, and how you can exercise them.
We do not sell your personal data, we do not display advertising, and we do not track you across other applications or websites.
1. DATA CONTROLLER AND CONTACT INFORMATION
is the controller of the personal data described here. Questions, requests or complaints: kuba@mint-labs.io.
2. CATEGORIES OF PERSONAL DATA WE COLLECT AND SOURCES
We collect personal data directly from you when you use the App, as well as indirectly from third-party services (Apple and RevenueCat) when you authenticate or subscribe.
A. Data Collected Directly From You
- Identification and Contact Data: the display name and email address transmitted by Sign in with Apple, which may be an Apple Private Relay address. We do not collect a postal address or telephone number, and no password is created or stored — authentication is performed entirely by Apple.
- Demographic Data: the age range you select during onboarding. This is optional and may be skipped. We do not collect your date of birth, gender or language.
- Preference Data: the wardrobe you browse (men's or women's), your temperature unit, your appearance preference, and your reminder settings.
- User Generated Content & Digital Wardrobe Data:
- Garment Data: the garments you add and their attributes — category, type, colour, secondary colour, pattern, material, warmth, formality and fit — together with any garment you exclude from suggestions and any short personal notes you choose to write about a garment (for example, to tell two similar items apart).
- Garment Photos: photographs of clothing items you capture with the camera or select from your device photo library.
- Normalized Garment Images: a cleaned, product-style image of a garment, generated from your Garment Photo by our image subprocessor when you add an item by photo, and stored with the item as its picture unless you choose the recolourable template illustration instead — a choice that is honoured even where the image finishes generating only after you have saved the item. Where a single photograph shows several garments — items laid out together, or an outfit you are wearing — the part of the photograph containing each garment is used to generate that garment's own image, so each piece can have its own picture. Where you keep that picture, a second derived image is generated the same way — a worn-view cutout of the same garment on a transparent background — and stored with the item to compose your outfit previews.
- Outfits & Styling Plans: custom outfit combinations, saved outfits, and the days and trips for which you plan them.
- Catalogue Suggestions: where a garment you own is absent from our catalogue, the description you provide in your own words, together with an optional photograph.
- Activity Data: actions indicating which suggested outfit combinations you accept, adjust or decline, retained as a running tally across formality, warmth and fit; and corrections you make where automated recognition has misidentified a garment. We do not collect a profile description or profile picture, the App has no members to follow and no ratings or reviews, and we do not retain search history.
- App Feedback: where we ask whether you are satisfied with the App, your answer together with any comments you choose to provide, and the App version and platform from which they were sent.
- Location & Environmental Data:
- Coarse Coordinates: device coordinates, obtained only while you are using the App and only with your consent, and rounded to approximately one kilometre before any use. No location history is compiled.
- Manual Location: a city or region you select yourself for weather matching.
B. Data Collected Automatically
The App contains no crash-reporting service and no advertising identifier. We do not record your screen or replay your sessions, do not retain search history, do not derive your location from your IP address, and do not fingerprint your device.
Product Analytics (Mixpanel): the App records a limited set of product-usage events — that you signed in (and whether the account was newly created), that onboarding was started or completed, that a garment was added, that an outfit was saved or planned, that you locked a garment or opened the accessories drawer while assembling a look, that an automated garment scan failed or that you kept none of what it suggested, that you corrected the garment a scan proposed, that the paywall was viewed, that a plan was chosen on it, that a subscription was started or a previous purchase restored, and that an account was deleted — together with your account identifier, the App version and the platform, and transmits them to Mixpanel, our analytics processor, on servers located in the European Union. Our servers additionally record the subsequent stages of a subscription — that it renewed, was cancelled, encountered a billing problem, expired, or was reactivated — together with the product, store, currency and the reason the store gave, and keep a record of whether your subscription is currently in trial, active or lapsed. We use these events solely to understand which features are used and to improve the App. They contain no garment photographs, no location data and no contact details; where an event concerns a garment it carries only its broad category and the catalogue archetype it was matched to — never your photographs, the names you give things, or a listing of your wardrobe — and they are not used for advertising or shared for any other purpose.
Alongside those events we keep a small profile against your account identifier, so that usage can be understood by group rather than only event by event. It records the objectives you chose during onboarding, which wardrobe you are currently using, and how many garments you have saved — a count only, never the garments themselves. It contains no new categories of information: each of these is data you have already provided to the App.
Two further limited records exist, each necessary to operate a specific feature rather than to observe you:
- Usage Counters & Scan Records: one record per automated garment scan and per generated garment image, comprising your account identifier, a timestamp, the wardrobe scanned, how many garments were recognised, which catalogue archetypes were suggested and how confidently each was matched, a reference to the generated image where one was stored, and an identifier linking the scan to the garments you save from it. The usage allowances are calculated from these records; the photograph itself is never part of them.
- Technical Context of Feedback: the App version and platform accompanying feedback that you elect to send.
C. Data Collected From Third Parties & System Integrations
- Account Identification Credentials (from Sign in with Apple): unique Apple user identifier, display name, and email address (or Apple Private Relay anonymous email).
- Subscription & Transaction Status (from the Apple App Store & RevenueCat): active subscription tier, trial status, product identifier, store, purchase timestamps, transaction identifiers and renewal dates. (We never process or store credit card or payment account details; payment processing is handled exclusively by Apple.)
D. Notifications and Reminders
Reminders are scheduled and displayed by your own device. Where you enable reminders — a daily prompt, a notification when the weather changes, a packing reminder before a trip, or a note concerning garments you have not worn — your device schedules and presents them locally. The App uses no push notification service: we hold no push token, our servers transmit nothing to you, and the content of a reminder never leaves your device. Reminders remain disabled until you enable them, and may be disabled individually in the App or entirely in iOS Settings.
For completeness, the App does not access your contacts, your calendar, your photo library beyond the images you expressly select, your browsing activity, or any advertising identifier.
3. PURPOSES, LEGAL BASES, AND RETENTION PERIODS
Under Art. 6(1) GDPR, we process your personal data only when we have a valid legal ground. The table below is exhaustive as to the processing we carry out.
| Processing Purpose | Categories of Data Involved | GDPR Legal Basis | Retention Period |
|---|---|---|---|
| Account Creation & User Management | Apple User ID, Email Address, Display Name | Art. 6(1)(b) GDPR (Contract performance) | Retained until you delete your account or request erasure. |
| Digital Wardrobe & Styling Services | Garment Data, Garment Photos, Saved Outfits, Styling Plans | Art. 6(1)(b) GDPR (Contract performance) | Retained until individual items are deleted, and in no event beyond account closure. |
| Automated Garment Attribute Recognition | The single Garment Photo submitted for the scan | Art. 6(1)(b) GDPR (Contract performance) | Transmitted to our recognition subprocessor and processed to answer that single request. It is not used to train that provider's models and is retained by it only for the limited period permitted under our agreement with it, after which it is deleted. The photograph itself remains in your wardrobe until you delete the item. |
| Garment Photo Normalization | The Garment Photo submitted (in whole, or the portion showing a particular garment where one photograph holds several), and the derived Normalized Garment Images (the cleaned product-style image and, where you keep it, the worn-view outfit cutout) | Art. 6(1)(b) GDPR (Contract performance) | The photograph is transmitted to our image subprocessor and processed in real time solely to generate the cleaned image — once per garment it shows, and, where you keep the photo as the item's picture, again for the worn-view cutout, which is generated up to three times if a result is unusable; it is not used to train that provider's models. The derived images are stored in your wardrobe until you delete the item or your account. |
| Personalisation of Styling Suggestions | Activity Data, Garment Data, Styling Plans | Art. 6(1)(b) GDPR (Contract performance) | Retained until account deletion. The learned preference may be reset at any time in Settings. |
| Improvement of Automated Recognition | Corrections to automated recognition results | Art. 6(1)(f) GDPR (Legitimate interest in recognition accuracy) | Recognition rules are derived in aggregate, and only where several distinct users have made the same correction, such that no rule is attributable to you. The underlying records are retained until account deletion. |
| Completion of the Garment Catalogue | Catalogue Suggestions, including any optional photograph | Art. 6(1)(f) GDPR (Legitimate interest in providing a catalogue) | Retained until account deletion. |
| Product Improvement & Satisfaction Measurement | App Feedback, App version, platform | Art. 6(1)(f) GDPR (Legitimate interest in service improvement) | Retained until account deletion. |
| Product Analytics | Product-usage events with account identifier, App version and platform, the profile traits described in Section 2.B (stated objectives, active wardrobe, number of garments saved), and server-recorded subscription lifecycle events and status (see Section 2.B) | Art. 6(1)(f) GDPR (Legitimate interest in understanding which features are used) | Retained until account deletion, or until you object (see Section 9). |
| Onboarding Personalisation | Demographic Data (age range) and the objectives you state for the App | Art. 6(1)(a) GDPR (Consent — both questions are optional and may be skipped) | Retained until you ask us to amend or clear them (write to kuba@mint-labs.io) or delete your account. The objectives you state determine where the App opens; the age range is stored with your profile and does not presently influence the suggestions you are shown. |
| Local Weather Integration for Outfits | Coarse Coordinates or Manually Selected City | Art. 6(1)(a) GDPR (Consent, for device location) or Art. 6(1)(f) GDPR (Legitimate interest, for a city you select yourself). The legitimate interest is to provide localised weather-adjusted outfit suggestions to users who prefer not to share their GPS location. | For Coordinates: processed in real time to fetch the forecast and immediately discarded; they are never stored on our servers. You can withdraw your location consent at any time in iOS Settings. For Selected Cities: your five most recent selections, and any per-day selections in the planner, are stored locally on your device and never on our servers; the oldest selection is replaced as you pick new ones, and all of them are removed when you delete the App. |
| Subscription Verification & Access Control | Subscription status, product identifier, expiry date | Art. 6(1)(b) GDPR (Contract performance) | Retained until account deletion. |
| Fair Use Limits & Protection of the Service | Usage Counters & Scan Records (account identifier, timestamp and scan-outcome metadata per scan — never the photograph) | Art. 6(1)(f) GDPR (Legitimate interest in preventing abuse and protecting systems) | The allowance is calculated over a recent window only — the current day (UTC), the past 30 days for picture generations on a paid subscription, or the free-trial period during a trial; the records themselves are retained until account deletion. |
Account Inactivity and Storage Limitation
To respect the principle of storage limitation (Art. 5(1)(e) GDPR), we do not retain your personal data indefinitely. If your account remains completely inactive (meaning you have not logged in or interacted with the App) for a continuous period of 24 months, we will consider the account abandoned. We will send an email notification to your registered address, and if you do not log in within 30 days of that notice, we will automatically and permanently delete your account and all associated personal data (including digital wardrobe records, saved plans, and garment photographs) from our active databases.
4. SHARING AND RECIPIENTS OF PERSONAL DATA
We do not sell your personal data. To operate the App, we share necessary data with trusted third-party service providers. These recipients are classified either as our Data Processors (who act strictly on our documented instructions under Article 28 GDPR) or as Independent Data Controllers (who process data under their own privacy policies).
Our Data Processors (Subprocessors bound by DPAs)
- Supabase — provides hosting, database management, secure file storage and authentication services. Your digital wardrobe, photographs and account credentials reside securely on Supabase's servers.
- Anthropic — when you scan a garment, that single photograph is transmitted to Anthropic's Claude API to automatically identify its attributes. It is processed in real time solely to answer that request and is not used by Anthropic to train their models.
- Google (Gemini API) — when you add a garment by photo, that photograph is transmitted to Google's Gemini API to generate a cleaned, product-style image of the garment. Where the photograph shows several garments, the portion of it containing each garment is sent separately, so that each piece can be given its own picture; and where you keep an image as the item's picture, the photograph is sent again — up to three times in total if a result is unusable — to generate the worn-view cutout used in your outfit previews. Where the photograph showed several garments, each generated image — and, in every case, the generated cutout — is sent once again (never your photograph) for an automatic check that it depicts the right kind of garment before it is stored. Each is processed in real time solely to answer those requests and is not used by Google to train its models.
- RevenueCat — manages mobile subscription states and verifies whether your subscription is active. RevenueCat receives your unique account identifier and transaction/purchase details; they never receive your digital wardrobe records or garment photographs.
- Mixpanel — receives the product-usage events described in Section 2.B, together with your account identifier, App version and platform, on servers located in the European Union, together with the profile traits described in Section 2.B. Mixpanel never receives your garments or their photographs, your email address or your location; where an event concerns a garment it carries only its broad category and the catalogue archetype it was matched to, and the profile records only how many garments you have saved.
Independent Controllers and External Integrations
- Apple — acts as an independent data controller for Sign in with Apple authentication and App Store subscription payments (governed strictly by Apple's own privacy policy). Additionally, the App utilises Apple's built-in, local on-device geocoder to resolve coordinates to a city name; this geocoding is performed entirely locally on your device. Apple also operates the rating prompt, where you indicate that you are satisfied with the App.
- Open-Meteo — resolves weather forecasts and, for trip dates beyond the forecast horizon, seasonal climate averages for the destination. To retrieve this weather data, the App transmits approximate, rounded coordinates (or your manually searched city name) to Open-Meteo's API. No account identifiers, user credentials, or IP addresses (which are discarded immediately after the network session) are sent to or stored by Open-Meteo.
We do not share your personal data with any other third parties, except where we are legally compelled to do so by applicable EU or Member State law.
5. INTERNATIONAL DATA TRANSFERS
When personal data is transferred outside the European Economic Area (EEA), specifically to the United States (e.g. Anthropic, Google, RevenueCat), we ensure appropriate safeguards under Chapter V GDPR:
- EU–U.S. Data Privacy Framework (DPF): where recipients are certified under the DPF adequacy decision (Art. 45 GDPR).
- Standard Contractual Clauses (SCCs): where DPF certification is unavailable, transfers are governed by the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR), complemented by technical safety measures — encryption in transit, data minimisation, and non-retention commitments.
You have the right to request and obtain reference to the appropriate or suitable transfer safeguards and the means by which to obtain a copy of them or where they have been made available. To exercise this right and request a copy, please email us directly at kuba@mint-labs.io.
6. DATA SECURITY ARCHITECTURE
We implement robust technical and organisational security measures to protect your personal data (Art. 32 GDPR):
- Data Encryption: all network data transmission is encrypted.
- Isolation by Account: your garment photographs are stored in a private bucket which is not publicly readable and is scoped to your account, and access to your wardrobe records is enforced at the database level, so that one account cannot read another's.
- Strict Privacy Isolation: mannequin does not access your contacts, your calendar, your full device photo library (access is limited to images you select) or your browsing history. We do not track you across third-party websites or applications.
7. AUTOMATED DECISION-MAKING AND PROFILING
We use algorithms to generate personalised outfit recommendations. The inputs are the garments in your wardrobe and their attributes, the feedback you have given to previous suggestions (“nudges”), what you have already planned, the local weather forecast, and the automated garment recognition described in Section 3 — the result of which you may always correct.
- No Legal or Significant Effects (Art. 22 GDPR): this processing constitutes basic feature tailoring and profiling for styling utility only. It does not produce legal effects or similarly significant consequences for you. You remain free to accept, adjust, decline or ignore any outfit suggestion, and to compose every outfit by hand.
8. STATUTORY AND CONTRACTUAL REQUIREMENTS
Providing your Apple ID credentials, holding an active subscription, and providing wardrobe data are contractual requirements necessary to create an account and access the core functionality of the App. Failing to provide this data will prevent you from using the digital wardrobe and automated styling features.
All remaining data is optional, and withholding it leaves the remainder of the App operational:
- Camera and photo library access: a wardrobe may be assembled entirely from the archetype gallery, without taking a single photograph.
- Live location data: if withheld, you may select a city manually, or use the App without weather-adjusted recommendations.
- Notification permission: reminders remain disabled unless you enable them.
- Age range and stated objectives: both may be skipped during onboarding.
- Catalogue suggestions and feedback: transmitted only where you elect to send them.
9. YOUR GDPR DATA SUBJECT RIGHTS
Under the GDPR (Articles 15–22), you have the following rights:
- Right to Access (Article 15 GDPR): you have the right to obtain confirmation as to whether or not your personal data is being processed, and, where that is the case, access to the personal data alongside detailed information regarding the processing. A copy of the personal data undergoing processing will be provided, provided that doing so does not adversely affect the rights and freedoms of others.
- Right to Rectification (Article 16 GDPR): you have the right to request the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you also maintain the right to have incomplete personal data completed, including by means of providing a supplementary statement or updating your details directly in the App.
- Right to Erasure / “Right to be Forgotten” (Article 17 GDPR): you have the right to request the permanent deletion of your personal data where one of the legal grounds applies. These grounds include scenarios where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent on which the processing is based, or where you object to processing pursuant to Article 21(1) and there are no overriding legitimate grounds for processing. Should legal obligations or overriding legitimate grounds require the retention of your data, you will be formally notified following an evaluation of your request.
- Right to Restriction of Processing (Article 18 GDPR): you have the right to request that we restrict the processing of your personal data under specific conditions (such as where the accuracy of the data is contested for a period enabling verification, where the processing is unlawful and you oppose erasure, or where the data is required by you for the establishment, exercise or defence of legal claims). During a restriction period, such data shall, with the exception of storage, only be processed with your consent, for legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest. You will be informed prior to the lifting of any such restriction.
- Right to Data Portability (Article 20 GDPR): you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, and the right to transmit those data to another data controller without hindrance. The App does not presently provide an export function; on request, we will produce the file for you.
- Right to Withdraw Consent (Article 7(3) GDPR): where processing is predicated upon your consent, you maintain the right to withdraw that consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent prior to its withdrawal. Camera, photo library, location and notification permissions may each be withdrawn in iOS Settings, and you may ask us at any time to amend or clear your onboarding personalisation answers by writing to kuba@mint-labs.io; the remainder of the App continues to function without them.
Right to Object (Article 21 GDPR). You have the right to object at any time, on grounds relating to your particular situation, to any processing of your personal data which is based on our legitimate interests (Article 6(1)(f) GDPR), including any profiling related to those interests. If you object, we will immediately stop processing your personal data for those purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defence of legal claims. You can exercise this right easily, free of charge, and at any time by contacting us at kuba@mint-labs.io.
Deletion within the App. You may delete individual garments and outfits at any time. To delete your entire account and everything attached to it — wardrobe, outfits, photographs and plans — open Settings → Account → Danger zone → Delete account and type delete to confirm. Deletion is immediate and permanent. Please note that deleting your account does not cancel an active subscription; subscriptions are managed in your Apple ID settings. If you are no longer able to open the App, write to us from the address associated with your account and we will carry out the erasure on your behalf.
Exercising your rights. You may exercise any right set out above by contacting us at kuba@mint-labs.io. We will respond to your request without undue delay and, in any event, within one month of receiving it. Where permitted by applicable law, this period may be extended by up to two additional months where necessary due to the complexity or number of requests. If we extend the response period, we will inform you within the initial one-month period and explain the reasons for the delay.
10. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
If you have concerns about how we handle your data, we encourage you to contact us directly at kuba@mint-labs.io.
If you consider that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a competent supervisory authority (Art. 77 GDPR). You can contact Poland's supervisory authority directly:
(Prezes Urzędu Ochrony Danych Osobowych)
ul. Stawki 2, 00-193 Warsaw, Poland
https://uodo.gov.pl · kancelaria@uodo.gov.pl
You maintain the right to lodge this complaint with the Data Protection Authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
11. CHILDREN
The App is not directed at children and is not intended for any person under the age of 16, in line with our Terms of Service. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will delete it.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically to reflect changes in the App's features, legal requirements, or operational practices. We will notify you of any material updates by posting a prominent notice within the App before the changes take effect, and by updating the “Last Updated” date at the top of this policy.