Privacy Policy
This policy explains how your personal data is processed when you use the Auralook mobile app (the “App”). It also serves as the notice required under the EU General Data Protection Regulation (“GDPR”) and Turkey’s Personal Data Protection Law No. 6698 (“KVKK”).
1. Data controller
Breed Software LLC
Contact: [email protected]
2. In short
- We don’t sell your data, use it for advertising, or track you across apps and websites. The App contains no advertising or analytics tools.
- Your clothing photos and (if you choose) your own photo are sent to a cloud-based artificial intelligence service provider to create outfit images. By accepting this policy when you sign up, you allow this.
- You can delete your account at any time from inside the App.
3. Data we process
Account information
- Your email address and password. Your password is stored on the server only as an irreversible hash (scrypt); we cannot see the password itself.
- Account ID, a hash of your session token, when your account was created and last signed in, and which version of the terms you accepted and when.
- Subscription status and expiry date, your monthly allowance usage and image pack balance.
Profile and style information
- Optionally, your name and profile photo.
- Fit preference (womenswear/menswear), body type, torso proportion and height; your answers to the color analysis questions and the resulting color palette; your outfit preferences (e.g. items you don’t want suggested).
Wardrobe data
- Photos of the clothes you add, frames from videos recorded with the in-app camera or picked from your gallery, and mirror selfies.
- Item details (category, color, fabric, cut, etc.), saved outfits, weekly plans and the notes you add to them (e.g. “Project meeting”), and your “Worn” records.
Personal model (optional)
- If you want to see outfits on yourself: up to three photos you select and a close-up face crop created automatically from them. These photos are used only to generate a model image that looks like you. No facial recognition, identity verification or biometric matching is performed, and the photos are not used to identify you.
Location
- If you allow it, your device’s approximate location, used only to get the weather where you are. Your location is rounded to about 1 km on your device and passed to the weather service through our server without being linked to your account; it is not stored. So that the same area’s forecast isn’t downloaded over and over, the forecast for the rounded location is kept temporarily in server memory for at most 36 hours; it is never written to disk or to logs. If you don’t allow it, the city in your profile is used. City search also runs on our server; the city name you search for is not sent to any other service and is not stored.
Purchase information
- If you buy a subscription or an image pack, the transaction ID and product ID provided by the store and the purchase and expiry dates. Your card and payment details stay with Apple or Google and never reach us.
Usage and technical records
- To calculate your image allowance and monitor the cost of the service: the number, type, time and cost of the images you generate and of AI operations (such as item recognition).
- A request counter to prevent abuse: your account ID when signed in, your IP address otherwise. The counter is held only in server memory for a few minutes and is not stored.
- Server logs contain the request path, response code and duration; they do not contain IP addresses, email addresses or photos.
Data that stays on your device
- Notification, language and appearance settings are stored on your device. Plan reminders are scheduled on your device; no push server is used.
- In-app video recording is silent; no audio is recorded.
4. Why we process your data and on what legal basis
- To provide the service (account, outfit suggestions, item recognition, outfit images, sync across devices, plan reminders, password reset): performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Processing your photos with artificial intelligence and transferring them abroad: your explicit consent (GDPR Art. 6(1)(a); KVKK Arts. 5(1) and 9). Sending your own photo for a personal model is additionally your choice each time.
- Verifying subscriptions and purchases and calculating your image allowance: performance of a contract.
- Security and abuse prevention: legitimate interest (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Legal obligations (e.g. accounting records, requests from authorities): legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).
5. Processing with artificial intelligence
The App’s core features work with a cloud-based third-party artificial intelligence service provider. In the cases below, the relevant images are sent first to our server and from there to that provider:
- When adding items from a photo or video: the photos and frames, to find and recognize items and create a product image on a white background.
- While shooting with the in-app camera: occasional small preview frames, to check whether an item is clearly visible.
- When an outfit image is generated: photos of the items in the outfit and the model image you selected.
- When a personal model is created and when outfit images are generated with it: the photos of yourself you selected and the face crop.
The provider processes this content only to produce the requested result and to prevent abuse, for a limited period under its contractual terms, and does not use it to train its artificial intelligence models. Images generated by artificial intelligence may not reflect reality exactly.
Generated outfit and product images are cached on our server so the same image isn’t charged twice. The photos of yourself you send for a personal model are not stored on our server; they stay on your device and are sent again when outfit images are generated. The generated personal model image is backed up to your account together with your wardrobe.
6. Who we share data with
We share your data only with the service providers needed to run the service, and only as far as needed:
- Cloud hosting, database and storage provider: our server; your account details, wardrobe backup and photos are kept here. Photos and generated images are stored in private (not publicly accessible) storage and are read only through our server, with your account’s authorization.
- Artificial intelligence service provider: the images listed in section 5.
- Email delivery service: your email address, only when sending a password reset code.
- Weather service: only your rounded approximate location, through our server; neither your account information nor your IP address is sent.
- Apple and Google: store transaction details, to verify your subscription and purchases.
- In-app purchase infrastructure provider: your account ID (a random identifier; your email address is not sent) and store transaction details, to verify purchases and link them to your account.
- Authorities: only when legally required.
We do not sell, rent or share your data with third parties for advertising.
7. International transfers
Our servers and the service providers above are located outside Turkey (mainly in the United States and the European Union), so your personal data is transferred abroad. This transfer is based on the explicit consent you give by accepting this policy at sign-up (KVKK Art. 9) and on the data protection commitments in our contracts with these providers. If you don’t accept this policy, an account cannot be created, because outfit images and item recognition don’t work without the transfer.
8. How long we keep data
- Your account details, wardrobe backup and photos are kept while your account is open.
- The backed-up photo of an item you delete from your wardrobe may remain on the server until you delete your account, as protection against accidental deletion. Write to us if you want it removed sooner.
- Password reset records are kept for up to 30 days; sessions until they expire or you sign out.
- When you delete your account, your account, sessions, wardrobe backup, photos and images generated only for you are deleted. Image usage records are kept for accounting but are anonymized and can no longer be linked to you. Shared cached images that another user also requested (images generated from the same items) may remain.
- Data on your device stays there until you delete the App or choose Profile → “Reset everything”.
- To delete your data without deleting your account, choose Profile → “Reset everything”: your wardrobe, photos, profile and color analysis are deleted from your phone and from the backup on our server; your account, subscription and image allowance stay.
9. Security
All traffic between the App and the server is encrypted (HTTPS). Passwords are stored as hashes; your session token is kept in your device’s secure key store (iOS Keychain / Android Keystore). No system is perfect; if a security breach occurs we will notify you and the relevant authorities within the legal time limits.
Only our authorized staff can access account and wardrobe data (clothing photos, saved outfits, profile and style information, generated images, subscription status), and only to the extent needed to answer support requests, keep the service secure and meet our legal obligations. Such access goes through a password-protected administration tool, and every access (who, when, which account) is logged.
10. Your rights
Under the GDPR and KVKK Art. 11 you have the right to know whether your data is processed, to access it and get a copy, to have it corrected, erased or its processing restricted, to object to processing, to withdraw your consent, to learn who your data has been shared with, and to claim compensation for damage.
- To delete your account: in the App, Profile → “Delete account” at the bottom. If you can’t access the App, email [email protected] from your registered address. Details: Account deletion.
- Withdrawing your consent is done by deleting your account; after that your images are no longer processed with artificial intelligence.
- For other requests: [email protected]. We respond within 30 days. You may also lodge a complaint with your local data protection authority (in Turkey, the Personal Data Protection Board).
11. Children
The App is not intended for children under 13, and we do not knowingly collect data from children under 13. If you are under 18, you should use the App with the permission of a parent or guardian. If you become aware that a child under 13 has created an account, write to us and we will delete it.
12. Changes
We may update this policy. The current version is always published at this address. For significant changes we will inform you in the App and, where required, ask for your consent again.
13. Contact
Breed Software LLC · [email protected]