1. Who is responsible and how to contact us
LookHabit is operated by [operator not yet confirmed]. The person responsible for privacy requests is [privacy officer not yet confirmed]. Our public privacy and support address is hello@lookhabit.com.
The contact mailbox is being activated before public release. Do not send passwords, payment-card details, identity documents or clothing/person photos by email. This prelaunch draft is not a representation that a staffed privacy-request service is already operating.
2. Account and device information
The app can create a Firebase guest account with a persistent identifier; guest does not mean anonymous or untraceable. If you register or link an account, Firebase and your selected sign-in provider process account identifiers, email and authentication information. Password sign-in and password resets use Firebase Authentication.
The app also stores preferences such as language, appearance, temperature units, profile name and selected city. Some preferences are local to your device; account language may also be synchronized. Signing out or switching accounts does not automatically erase the previous account's local information.
3. Your wardrobe and style preferences
When you add or edit garments, LookHabit stores photos and information such as names, categories, colors, material/style attributes, favorites, scan provenance, wear history and laundry status. Wardrobe information is stored on your device and synchronized to your account when cloud services are available. Pending saves and photos may remain locally for retry.
Saved outfits, garment selections, wear/save/swap actions and stylist preference notes help organize and personalize styling. Some are synchronized to your account. The app's stylist-memory screen lets you view and delete saved preference notes. Deleting a note or garment does not necessarily delete prior AI requests, separate learning samples or copies you shared elsewhere.
4. Cloud AI and personal photos
Cloud features send relevant information through our Google Cloud backend to Google Vertex AI/Gemini. Clothing recognition can send clothing images; outfit suggestions and chat can send wardrobe attributes, recent messages, preferences, stylist notes and weather context. Try-on intentionally sends a person photo, selected garment reference images and an outfit description. Color analysis sends the selfie you select. AI providers process this information to produce the requested response.
The app does not add try-on person photos or color-analysis selfies to its garment-learning outbox. That is not a claim that no copy exists in provider processing, device pickers, diagnostics or sharing caches. Saved color profiles contain analysis results such as palette, undertone and contrast. Do not upload intimate images, sensitive documents, or other people's photos without their permission. Generated images are approximate previews, not measurements or guarantees of appearance or fit.
5. Automatic garment learning and model improvement
The current implementation automatically records garment-learning evidence during ordinary scanning, confirmation, rejection and later corrections. This may happen before you save a garment. Samples can include a cropped clothing image, predicted and corrected attributes, model/version identifiers, confidence and color diagnostics, event identifiers, timestamps and operating-system information. Cropping is not guaranteed to remove people, backgrounds or other identifying details. These records are associated with an account; they are not represented as anonymous.
The app queues samples locally and sends them to our backend automatically, retrying unavailable connections. We use this evidence to evaluate and improve clothing recognition and to develop and train LookHabit's garment models. Collection does not mean a sample immediately trains a production model. Deleting the wardrobe garment does not by itself delete its separate learning samples.
The current preview has no separate training opt-in or withdrawal switch. Normal scanning, saving a garment, accepting Terms or granting camera access must not be treated as proof of consent to an unrelated purpose. Required disclosures, legal authority, withdrawal handling and dataset-deletion controls must be resolved before public release; this draft does not authorize that processing.
6. Weather, planning and notifications
City search sends your search text to Open-Meteo's geocoding service; forecasts send the selected city's coordinates to its weather service. These services also receive normal connection information such as your IP address. The current app uses a city you choose rather than requesting device GPS. Weather and the activity you select can inform styling.
Agenda and planning choices are stored in app preferences; the current app does not import your device calendar or contacts. Optional reminders use device notification permission and the operating system's notification queue. Notification settings may remain after account deletion because they belong to the installation.
7. Purchases and service usage
Apple App Store or Google Play processes payment-card information. LookHabit uses account-linked purchase identifiers, store verification results, product/subscription state, usage allowances and credit balances to deliver purchases and prevent duplicate grants or fraud. We do not ask you to enter payment-card details into LookHabit.
Certain hashed transaction and account-ownership claims are kept separately from wardrobe content and can survive account deletion to prevent replay and support financial obligations. A hash can still be linkable information. Their final retention schedule and live store integration require verification before paid release.
8. Diagnostics and website connections
Release-mode app code enables Firebase Analytics and sends crash reports to Firebase Crashlytics. Events can include feature use, garment/photo counts, outfit activity, and color-analysis season, source and confidence. SDKs can also collect installation/device information and automatic events. Error reports contain errors and stack traces and may inadvertently include contextual information. The current account-deletion flow does not automatically erase all Analytics or Crashlytics records.
The marketing website has no added advertising trackers, analytics scripts, contact form or persistent browser-storage feature. Firebase Hosting and network providers still process ordinary requests, including IP addresses and technical logs. Clicking an email link opens your email service; sending mail shares the contents and address with the mailbox and email providers.
9. Who receives information
Google/Firebase services provide account authentication, databases, photo storage, hosting, backend processing, AI, analytics and crash reporting. Apple and Google provide selected sign-in and billing services; Open-Meteo supplies city lookup and weather. Authorized operators or contractors may access information needed for support, security, system operation and the model-development purposes described above. Access must be limited to the relevant task.
We may disclose information when legally required, to address fraud or security incidents, or in a business transfer subject to applicable law and notice. Files you choose to share are delivered to the recipient or app you select and are then subject to that recipient's practices. LookHabit's current product has no advertising-data sale or targeted-advertising integration.
10. International processing and security
Cloud processing can occur outside your province or country, including outside Québec and Canada. The current backend is configured in the United States, and AI requests may use global provider routing; this is not a promise of exclusively Canadian or single-region processing. Foreign authorities may have access under applicable law. Provider contracts and required transfer assessments must be verified before public release.
The app uses authenticated cloud requests, access controls and encrypted network transport. No system is perfectly secure, and no claim is made that stored content is end-to-end encrypted. Protect your device and sign-in credentials, and contact us if you suspect unauthorized access.
11. Retention and its current limits
Wardrobe, account and personalization records generally remain until they are removed or the account is deleted. Several current collections, including learning samples, failed upload queues and financial anti-replay claims, do not have an automatic age-based expiry. A final category-by-category retention and destruction schedule is a release requirement, not an implemented guarantee.
AI recovery receipts have a 24-hour eligibility window, but eligibility expiry is not immediate physical erasure. Completed account-deletion receipts are configured for expiry after 30 days; unresolved jobs are retained for retry. The existing photo-storage bucket has a seven-day soft-delete recovery period. New-project configuration, scheduled deletion, diagnostic retention and other backups still require live verification.
Exported training datasets and model-development artifacts are separate from account storage. Account deletion does not automatically traverse those exports or remove an example's influence from existing model weights. Do not interpret this draft as a promise of automatic model unlearning or an exemption from applicable deletion obligations.
12. Your choices and privacy requests
You can manage photo and notification permissions in device settings, edit or delete wardrobe items, remove saved stylist notes and initiate account deletion in LookHabit Settings. Declining access to a particular feature may prevent that feature from working. Uninstalling the app does not delete the cloud account or cancel a subscription. See the separate account-deletion page for scope and limitations.
Depending on your location and applicable law, you may request access, correction, deletion, a portable copy, restriction or objection to processing, or withdraw consent where processing relies on consent. Contact hello@lookhabit.com with the subject Privacy request. We may need proportionate information to verify ownership; do not send passwords or full payment information. You may complain to your local privacy authority, including Québec's Commission d'accès à l'information or the Office of the Privacy Commissioner of Canada.
There is currently no verified global training-withdrawal or exported-dataset deletion workflow. Those controls and an operational request channel are public-release gates; merely writing to an unactivated mailbox is not an effective privacy control.
13. Age eligibility
The proposed minimum age for the public app is [minimum age not yet confirmed]. This value and any required parental authorization, child-protection measures and store audience declarations must be confirmed before release. The prelaunch preview is not an invitation for children to submit personal information. Contact hello@lookhabit.com if you believe a child has provided information so the situation can be reviewed.
14. Changes and related documents
We will identify the effective version of this policy when approved for release. Material changes to data use require appropriate notice and, where required, renewed permission before the new processing begins. A website update alone does not authorize a new purpose. Read the Terms of Use and account-deletion information alongside this policy. Translations are provided for accessibility; mandatory rights under applicable law are not limited by language selection.