gavel
Registration Contract
User Data & Privacy Agreement
Effective Date: May 7, 2026
·
Version: 1.0
·
Last Updated: August 11, 2026
1. Introduction
Welcome to OutfitLab. By creating an account and using our services, you ("User")
enter into this User Data & Privacy Agreement (the "Agreement") with OutfitLab ("Company",
"we", "us", or "our"). This Agreement governs how we collect, use, store, and process your
personal data, including all photographs, images, and content you upload to our platform.
Please read this Agreement carefully before registering. By checking the acceptance box on the
registration screen, you confirm that you have read, understood, and agree to be bound by all
terms herein.
2. Data We Collect
We collect and process the following categories of data:
-
Account Information: Name, email address, password (stored as a one-way
cryptographic hash), and any profile details you provide.
-
Wardrobe Images: All photographs of clothing and accessories you upload
to your digital wardrobe.
-
Personal Photographs: Body / person photographs you upload for the
virtual try-on feature.
-
Face-Related Processing: We do not use Face ID or create biometric face
templates. Try-on photos may include your face as part of a full-body image. We use automated
face detection only to preserve your appearance in try-on results, frame your photo, or blur
faces in third-party catalog images — not to identify you.
-
Usage Data: Outfit combinations, styling preferences, AI interaction
history, and in-app behaviour analytics.
-
Device & Technical Data: Device identifiers, IP address, browser
type, operating system, and app version.
-
Consent Records: When you accept this Agreement we record your IP
address, browser User-Agent, a timestamp, the version number of the Agreement you
accepted, and a SHA-256 hash of the Agreement text. This data is processed solely to
demonstrate that valid consent was obtained, as required by Art. 7(1) GDPR and
equivalent data-protection laws (e.g. Turkish KVKK Art. 12).
3. Grant of Licence to Your Data
By accepting this Agreement, you grant OutfitLab a
worldwide, non-exclusive, royalty-free, sublicensable, and transferable licence
to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute,
and display all data and content you upload or generate on the platform, including but not
limited to:
-
Wardrobe item images and metadata for AI model training, vector embedding generation
(via FashionCLIP), and product search indexing;
-
Personal photographs for virtual try-on processing and result generation;
-
Outfit combinations and styling preferences for AI recommendation engine improvement;
-
Anonymised and aggregated data for trend analysis, product development, and research
purposes.
This licence is granted for the duration of your account and for a period of
7 years following account deletion to allow completion of any ongoing
processing pipelines, research cycles, or legal obligations, after which your personally
identifiable data will be deleted.
4. Lawful Basis for Processing (GDPR / KVKK)
We process your personal data under the following lawful bases:
-
Art. 6(1)(b) GDPR – Performance of a Contract: Processing your wardrobe
images, try-on photographs, and account information is necessary to deliver the
OutfitLab service you signed up for.
-
Art. 6(1)(a) GDPR – Explicit Consent: Where we use your data for AI
model training, anonymised research, or marketing communications, we rely on your
freely given, specific, and informed consent as documented by this Agreement.
-
Art. 6(1)(c) GDPR – Legal Obligation / Art. 6(1)(f) Legitimate Interest:
We keep immutable consent records (including IP address) to fulfil our accountability
obligation under Art. 7(1) GDPR and to defend contractual claims within the applicable
limitation periods.
-
KVKK Art. 5(2)(a): For users in Turkey, your explicit consent under
this Agreement constitutes the lawful basis required by Turkish Law No. 6698.
5. How We Use Your Data
-
5.1 Provide and improve the OutfitLab platform, including wardrobe
management, outfit generation, and virtual try-on services.
-
5.2 Train and improve our AI and machine-learning models, including
FashionCLIP embeddings and outfit recommendation algorithms.
-
5.3 Process virtual try-on requests by passing your uploaded images to
authorised GPU processing providers under strict data processing agreements.
-
5.4 Personalise outfit recommendations, style suggestions, and in-app
content based on your wardrobe and preferences.
-
5.5 Communicate with you regarding your account, new features, and
relevant promotional offers (subject to your notification preferences).
-
5.6 Comply with applicable legal obligations, respond to lawful
requests, and enforce our Terms of Service.
6. Data Storage & Security
All uploaded images and user data are stored on Cloudflare R2 (object
storage) and our secured database infrastructure. We employ industry-standard encryption
(TLS in transit, AES-256 at rest), access controls, and regular security audits to protect
your data. Access to raw user images is restricted to authorised personnel and automated
processing systems only.
Consent audit records are stored in an append-only, immutable database table. Records
cannot be modified or deleted by the application layer; only a privileged purge process
operating after the retention period may remove them.
7. Third-Party Processing
To deliver virtual try-on results, your images may be transmitted to authorised third-party
GPU inference providers (such as FAL.ai, RunWare, or similar services). These providers act
as data processors under binding data processing agreements and are prohibited from using
your images for any purpose other than fulfilling the requested inference task.
We do not sell your personal data to third parties for advertising or marketing purposes.
8. Data Retention
Active accounts: Data is retained for the life of your account.
After account deletion: Personally identifiable data is deleted within
30 days. Consent records (and the minimal data required to identify whom the record
belongs to) are retained for 7 years from the date of consent to satisfy
the statute-of-limitations periods for contractual disputes (UK: 6 yrs; Germany: 3–10 yrs;
Turkey: 10 yrs). After this period, all remaining data is permanently deleted.
Anonymised & aggregated data (trend statistics, model weights derived
from aggregated embeddings) may be retained indefinitely as it cannot be linked back to any
individual.
9. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data via your profile settings;
- Delete your account and request erasure of your personally identifiable data;
- Portability — export a copy of your wardrobe data;
- Object to processing for direct marketing purposes at any time;
- Withdraw consent — note that withdrawal does not affect the lawfulness of processing based on consent before its withdrawal, and may prevent us from providing certain AI-powered features.
To exercise any of these rights, contact us at
[email protected].
10. Children's Privacy
OutfitLab is not directed to children under the age of 13 (or 16 in the European Union).
We do not knowingly collect personal data from minors. If you believe a minor has provided
us with personal data, please contact us immediately at
[email protected].
11. Changes to This Agreement
We may update this Agreement periodically. Material changes will be communicated via
in-app notification or email at least 14 days before taking effect.
Continued use of the platform after the effective date constitutes acceptance of the
revised Agreement. For major updates, we will ask you to explicitly re-accept the new
version before you can continue using the app.
12. Contact
If you have questions or concerns about this Agreement or our data practices: