Privacy Policy
Effective Date: 24th July 2026
Last Updated: 24th July 2026
1. Introduction
Buena Logica Technologies Private Limited ("Fashually," "we," "us," or "our") operates the Fashually mobile application and related services (collectively, the "Service") — an AI-powered fashion photoshoot studio that lets you see yourself, or an AI model, in any outfit, pose, or background.
This Privacy Policy explains what personal data we collect, how and why we use and share it, how long we keep it, and the choices and rights available to you — wherever in the world you use Fashually.
We wrote this Policy to apply globally, not just to users in any one country. Where a specific law gives you rights beyond what's described generally below, Section 16 explains those rights region by region.
2. Scope of This Policy and Age Requirement
This Policy applies to everyone who uses the Service, regardless of location. It's designed to reflect the requirements of multiple data protection frameworks, including (without limitation):
- The EU General Data Protection Regulation and the UK GDPR
- The California Consumer Privacy Act, as amended by the CPRA, and comparable U.S. state privacy laws
- India's Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025
- Other applicable data protection and privacy laws around the world
Age requirement. Fashually is intended for adults. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account or use the Service. See Section 15.
3. Information We Collect
3.1 Information You Provide Directly
Account information. Fashually does not support email/password sign-up. You can only create an account by signing in with your Google Account or Apple ID. When you do, Google or Apple shares certain basic profile information with us — typically your name, email address, a unique account identifier, and (if available) a profile photo — depending on the permissions you approve at sign-in. We never receive your Google or Apple password.
Profile and personal avatar information. To build your personal avatar, we ask you to provide:
- A selfie (face photo)
- Full-body photos: front view, left side view, right side view, and back view
- Age
- Height
- Weight
- Location (city and country)
We treat your selfie and body photos as sensitive biometric information. Section 6 explains exactly how we handle this category of data.
AI model avatars. Instead of, or alongside, your personal avatar, you can choose a ready-made AI-generated model avatar (male or female) that isn't based on your own likeness. Both your personal avatar and any AI model avatar you select can be used to generate Looks.
Looks you create. When you use an avatar to try on outfits, poses, or backgrounds, we process the resulting images ("Looks") along with any outfit references, styling choices, or prompts you provide to generate them.
Community content (coming soon). Once launched, our Community feature will let you choose, Look by Look, whether to share a Look publicly and whether to allow other users to recreate it. See Section 9.
Communications. If you contact us for support or send us feedback, we collect what you tell us along with your account details.
3.2 Information Collected Automatically
- Device information: device type, operating system and version, unique device identifiers, and mobile advertising identifiers (such as Google's Advertising ID or Apple's IDFA, where you've allowed tracking).
- Usage data: the features you use, screens you view, session length, and similar interaction data.
- Log data: IP address, approximate location derived from your IP address, access times, and crash/diagnostic reports.
3.3 Information From Third Parties
- From Google or Apple, at sign-in: the basic profile information described above.
- From advertising partners: technical and interaction data related to the ads shown to you (Section 10).
- Age-signal integration (planned): if we integrate Apple's or Google's age-verification signals in the future, we may also receive an age-range or verification-status signal about your account from them. This isn't active yet — we'll update this section with specifics before it is.
4. How We Use Your Information
We use the information described above to:
- Create and maintain your account
- Generate your personal avatar and any AI model avatars you select
- Generate the Looks you request
- Operate, maintain, and improve the Service
- Provide customer support and respond to your requests
- Power Community features once launched (Section 9)
- Detect, prevent, and address fraud, abuse, and security issues
- Show you ads through Google AdMob, and — once available — personalize Store recommendations based on your profile (Section 10)
- Comply with our legal obligations and enforce our Terms of Service
We do not use your selfie or body photos to train Fashually's own general-purpose AI models without asking for your separate, opt-in consent first.
5. Our Legal Basis for Processing
Where the GDPR, UK GDPR, or a similar framework applies to our processing of your personal data, we rely on the following legal bases:
- Consent — for your biometric data (your selfie and body photos), and for optional features like Community sharing and personalized advertising.
- Performance of a contract — to create your account and provide the core Service you've asked for, like generating a Look.
- Legitimate interests — for security, fraud prevention, and improving the Service, balanced against your rights and interests.
- Legal obligation — where we need to retain or disclose information to comply with the law.
Because your selfie and body photos are biometric data capable of identifying you, we treat this as a special, more sensitive category of data and rely specifically on your explicit consent to process it — see Section 6.
6. Biometric Information — Special Notice
We know photos of your face and body are sensitive, so we're calling out how we handle them separately from the rest of this Policy.
What we collect: your selfie and your four full-body photos (front, left side, right side, back), used to build your personal avatar.
Why: solely to generate your personal AI avatar and the Looks you request. We do not use this information for facial recognition against other people, surveillance, or any purpose beyond generating your avatar and Looks, unless you separately agree to something else.
Consent: we ask for your explicit, separate consent before processing this information. You can withdraw that consent at any time (Section 16). If you do, we'll stop generating new avatars or Looks from this data and delete the underlying photos — though Looks you've already generated may remain unless you delete them separately.
Retention and destruction: we keep your selfie and body photos for as long as your account is active, or until you delete them or your account, whichever happens first.
No sale, no unnecessary sharing: we do not sell or license your biometric information to anyone, and we only share it as described in Section 7 — to generate the Look you've asked for.
Age assurance (planned): we're evaluating using your selfie to estimate an age range, as an extra safeguard alongside our 18+ requirement. This isn't active yet — before we turn it on, we'll update this section with the specific provider involved, what's retained, and your rights over that additional processing.
Where biometric-specific laws apply to you (for example, in Illinois, Texas, and Washington in the United States), we follow the disclosure, consent, and retention practices those laws require.
7. AI-Generated Content and Our Third-Party AI Providers
To generate your avatar and Looks, we currently send the necessary photos, measurements, and prompts to two AI providers:
| Feature/Model | Provider | Headquarters | Used For |
|---|---|---|---|
| ChatGPT | OpenAI | United States | Prompt/image generation |
| Gemini | United States | Prompt/image generation |
We access both providers under their standard commercial API terms — we have not negotiated custom data processing agreements with either. As of this Policy's last update, both providers' standard terms exclude content submitted through their business/paid API tiers from being used to train their general-purpose models.
We're evaluating additional AI providers for possible future use, including Flux (Black Forest Labs), Ideogram, Z-Image (Alibaba), Krea, and Seedance (ByteDance). None of these are active today. Before sending any user content to a new provider, we'll update this section with that provider's standard policy on training use and, where its standard terms would permit training on submitted content, what we're doing about it before that provider goes live.
These providers act as our processors (sometimes called sub-processors) and are contractually required, under their standard terms, to use your information to provide the AI generation service we've requested.
We may add, remove, or change AI providers over time. We'll update this Policy when we do, and — for the biometric data described in Section 6 — we'll seek fresh consent if the change is material.
8. How We Share Your Information
We do not sell your personal information. Outside of what's described in Section 7, we share information only as follows:
- With service providers who support our infrastructure — for example, cloud hosting, analytics, or customer support tools — under contracts that limit their use of your information to providing services to us.
- With Google AdMob, for advertising purposes (Section 10).
- Publicly, only if you choose to share a Look to the Community (Section 9) — and only the Look and sharing settings you select, never your underlying profile details like your age, height, weight, exact location, or contact information.
- For legal reasons — to comply with the law, respond to lawful requests from public authorities, or protect the rights, property, or safety of Fashually, our users, or others.
- In a business transaction — such as a merger, acquisition, financing, or sale of assets, in which case your information may be transferred as part of that transaction, subject to this Policy or a successor policy that offers equivalent protections.
9. Community Features (Coming Soon)
We're building a Community feature that will let you optionally share the Looks you create or recreate with other users. Here's how it's designed to work:
- Sharing is opt-in and Look-by-Look. You decide, for each Look, whether to keep it private or share it publicly to the Community.
- You control recreation. When you share a Look, you can set whether other users are allowed to "recreate" it — that is, use its outfit or styling as a starting point to generate their own version on their own avatar.
- Anyone can browse; only members can recreate. You don't need a Fashually account to view public Looks in the Community, but you do need to be signed in to recreate one.
- A shared Look is public. If the Look you share was generated using your personal avatar, it may show your likeness, and it will be visible to anyone who visits the Community — including people without an account. Please keep this in mind before sharing a Look based on your personal avatar rather than an AI model avatar.
- You can unshare. You can make a previously shared Look private again, or delete it outright, at any time.
- Deleting your account removes your Community posts too. See Section 17.
10. Advertising and Google AdMob
We currently show ads through Google AdMob. AdMob (and Google) may collect and use information such as your device identifiers, advertising ID, IP address, and in-app interaction data to show and measure ads, including personalized ads where you've allowed it. You can learn more about, and manage, Google's advertising practices through Google's own privacy and ad settings.
Your choices:
- You can limit ad personalization through your device settings (for example, Apple's App Tracking Transparency prompt, or resetting/limiting your Android advertising ID).
- Where required — including in the EEA, UK, and Switzerland — we'll ask for your consent to personalized advertising through a consent management tool before showing you personalized ads.
- If you're in California, or another U.S. state with a comparable law, you have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising. Because AdMob may use identifiers for personalized ads, this may qualify as a "share" under those laws even though we don't sell data for money. See Section 16.2.
Future Store and personalized ads. When our in-app Store feature launches, we plan to show you targeted product recommendations based on your profile information — for example, your style preferences, body measurements, and the Looks you've created. This is a form of profiling for advertising purposes. Before this feature goes live, we'll update this Policy with more detail and, wherever the law requires it, ask for your consent first.
11. Cookies and Similar Technologies
Our app, and the third-party SDKs we use (such as Google AdMob), may use cookies, mobile identifiers, and similar technologies to operate the Service, remember your preferences, and measure and personalize ads.
12. International Data Transfers
Fashually is a global service, and your information may be transferred to, stored, and processed in countries other than the one where you live — including the United States and other countries where our service providers and AI partners operate.
None of our current AI providers are headquartered outside the United States. If we add providers in the future that are headquartered in, or process data in, countries without a data protection adequacy decision from the European Commission or the UK Government — for example, Z-Image (Alibaba) or Seedance (ByteDance), both headquartered in China — we will put appropriate safeguards in place before transferring personal data to them, such as the European Commission's Standard Contractual Clauses, the UK's International Data Transfer Addendum, or another lawful transfer mechanism recognized under GDPR Chapter V, UK GDPR, India's DPDP framework, or equivalent regimes elsewhere.
If you'd like more information about the safeguards used for a specific transfer, contact us using the details in Section 20.
13. Data Retention
We keep your information for as long as your account is active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements.
| Data Category | Retention |
|---|---|
| Account and profile information | Until account deletion, plus 27 days for backups and legal purposes |
| Selfie and body photos | See Section 6 |
| Generated Looks | Until you delete them or your account |
| Community posts | Until you unshare/delete them, or delete your account |
| Device, log, and usage data | Until you delete your account |
14. Data Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, access controls, and regular security reviews. No method of transmission or storage is completely secure, and we can't guarantee absolute security.
15. Children's Privacy
Fashually is intended for users who are 18 or older (or the age of majority where you live). We do not knowingly collect personal information — and in particular, biometric information such as photos — from anyone under this age. If we learn we've collected information from someone under the required age, we will promptly delete their account, including their avatar photos, generated Looks, and anything they shared to the Community. If you believe a minor has used the Service, please contact us using the details in Section 20.
16. Your Privacy Rights
Your specific rights depend on where you live. To exercise any of these, contact us using Section 20 — we may need to verify your identity first.
16.1 European Economic Area, UK, and Switzerland
If the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to our processing
- Receive a portable copy of data you provided to us
- Withdraw consent at any time, without affecting processing that already took place
- Lodge a complaint with your local data protection authority
16.2 United States
If the CCPA/CPRA, or a comparable state law (such as those in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or Montana), applies to you, you have the right to:
- Know what personal information we collect, use, and disclose about you
- Delete personal information we hold about you
- Correct inaccurate personal information
- Opt out of the "sale" or "sharing" of personal information — which may include our use of advertising identifiers through AdMob
- Limit the use of "sensitive personal information," a category that includes your precise location and your biometric information (selfie and body photos)
- Not be discriminated against for exercising any of these rights
We honor Global Privacy Control (GPC) signals as a valid opt-out request wherever legally required.
If you're a resident of Illinois, Texas, or Washington, additional rights and disclosures apply specifically to biometric information under those states' laws — see Section 6.
16.3 India
If India's Digital Personal Data Protection Act, 2023 applies to you, you have the right to:
- Obtain a summary of the personal data we process about you and the processing activities involved
- Correct, complete, and update your personal data
- Erase personal data that's no longer necessary for the purpose it was collected
- Have a readily available way to register a grievance with us
- Nominate another individual to exercise your rights if you die or become incapacitated
- Withdraw consent at any time
You can reach our Grievance Officer using the details in Section 20.
16.4 Other Jurisdictions
If you're elsewhere — for example, Canada, Australia, Brazil, or another country — you may have similar rights to access, correct, or delete your personal information under your local law (such as PIPEDA in Canada, the Privacy Act 1988 in Australia, or the LGPD in Brazil). Contact us, and we'll do our best to honor your request under the law that applies to you.
17. Account Deletion
You can delete your Fashually account at any time from within the app. When you do:
- We delete your profile information, personal avatar photos, saved Looks, and any Looks you shared to the Community.
- This process completes within 28 days
- Deletion is permanent. We can't restore your account or content once this process is complete.
18. Third-Party Links and Services
The Service may contain links to third-party websites or services, including sites belonging to our AI providers or advertisers. We aren't responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies separately.
19. Changes to This Policy
We may update this Privacy Policy from time to time, including as we launch new features such as the Community and Store features described above. We'll post the updated Policy with a new "Last Updated" date, and where changes are material, we'll provide additional notice — such as an in-app notification — or seek your consent again, wherever the law requires it.
20. Contact Us
If you have questions about this Privacy Policy, or want to exercise any of your privacy rights, contact us at:
Buena Logica Technologies Private Limited
First Floor, Sri Prem Prasad Complex, 1 New BEL Road, RMV 2nd Stage, Bangalore, Karnataka, India 560 094
Email: hi@fashually.com
