Contents
Plain English summary: We collect your email to create your account, your photo to power the AI try-on feature, and basic usage data to improve the app. We never sell your personal data. You can delete everything at any time.
Section 01
Who we are
Vestyl is an AI-powered virtual try-on and social fashion app. We are the data controller for the personal information you provide when using our website (vestyl.app) and our mobile application.
Business name: Vestyl
Contact email: hello@vestyl.app
Data protection contact: privacy@vestyl.app
ICO Registration Number: C1899834
If you have any questions about how we handle your data, please contact us at privacy@vestyl.app. We aim to respond within 5 working days.
Section 02
What data we collect
Information you give us
- Account information: your name and email address when you sign up
- Profile photo: a photo of yourself that you upload to use the AI try-on feature
- Profile name: a display name for your public profile
- Content you post: try-on images, comments, and interactions on the social feed
- Communications: messages you send us via email or contact forms
Information we collect automatically
- Usage data: how you interact with the app — pages visited, features used, time spent
- Device information: device type, operating system, app version
- Log data: IP address, browser type, referring URLs, crash reports
- Cookies and similar technologies: see Section 7 for full details
Information derived from your photo
When you upload a photo for AI try-on, it is transmitted to FASHN AI, our third-party AI provider, which analyses the image to generate a try-on image. This processing constitutes biometric data under UK GDPR. We only do this with your explicit consent — see Section 5 for full details.
Section 03
How we use your data
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account | Name, email | Contract performance |
| Generating AI try-on images | Your photo, derived biometric data | Explicit consent |
| Displaying your profile and posts on the social feed | Display name, profile photo, try-on images | Contract performance |
| Sending you service emails (account, updates) | Email address | Contract performance |
| Improving the app and fixing bugs | Usage data, crash reports, device info | Legitimate interests |
| Analytics to understand how the app is used | Anonymised usage data | Legitimate interests |
| Preventing fraud and ensuring security | IP address, usage patterns | Legitimate interests |
| Complying with our legal obligations | As required by law | Legal obligation |
We do not use your data for automated decision-making that has a significant legal or similarly significant effect on you.
Section 04
Legal basis for processing
Under UK GDPR, we must have a legal basis for processing your personal data. We rely on the following:
- Contract performance (Article 6(1)(b)): processing necessary to provide the Vestyl service you signed up for
- Explicit consent (Article 6(1)(a) and Article 9(2)(a)): processing your photo and derived biometric data for AI try-on — you give this consent separately when using the try-on feature, and you can withdraw it at any time
- Legitimate interests (Article 6(1)(f)): improving the app, fraud prevention, and security
- Legal obligation (Article 6(1)(c)): complying with laws that apply to us
Section 05
Your photos and AI processing
This section is important. Please read it carefully before using the AI try-on feature.
What happens when you upload a photo
- Your photo is uploaded securely and transmitted via API to our third-party AI provider, FASHN AI
- FASHN AI processes your photo alongside the selected clothing item to generate a try-on image
- The AI-generated image is returned to Vestyl and displayed to you in the app
- FASHN AI processes your photo solely for the purpose of generating the try-on image on our behalf
FASHN AI — our AI image provider
The virtual try-on feature is powered by FASHN AI, a third-party AI image generation service. When you use the try-on feature, your photo is transmitted to FASHN AI via a secure API call. FASHN AI acts as a data processor on our behalf, meaning they process your photo on our instructions. Please note that under their current Terms of Use, FASHN AI retains a licence to use submitted images to improve their services — see the section below for full details.
You can read FASHN AI's privacy policy at fashn.ai/privacy-policy. If you have concerns about your photo being transmitted to FASHN AI, you can choose not to use the try-on feature — all other parts of Vestyl remain fully accessible.
How FASHN AI may use your photo
Under FASHN AI's Terms of Use, by submitting images to their service, users grant FASHN AI a licence to use, copy, modify, and process those inputs for the purpose of improving and operating their services. This means that photos transmitted to FASHN AI via the Vestyl app may potentially be used by FASHN AI to improve their AI models.
Vestyl is actively seeking a Data Processing Agreement (DPA) with FASHN AI under Article 28 UK GDPR which would restrict this usage. Until such an agreement is confirmed, we want to be fully transparent with you about FASHN AI's current terms. We will update this section as soon as a DPA is confirmed with FASHN AI.
Your consent
We only process your photo for AI try-on with your explicit consent. This consent is:
- Freely given: you can use other parts of the app without uploading a photo
- Specific: it covers only AI try-on processing, not any other purpose
- Informed: you are told exactly what will happen to your photo
- Easily withdrawable: you can withdraw your consent at any time in Settings → Privacy → Delete my photo data
What we do NOT do with your photo
- We do not use your photo to train AI models without separate, additional consent
- We do not share your photo with third-party brands or advertisers
- We do not use your photo for any purpose other than generating try-on images
- We do not generate intimate, sexual, or offensive images
Deleting your photo data
You can delete your uploaded photo and all derived data at any time. Go to Settings → Privacy → Delete my photo data. Deletion is permanent and takes effect within 30 days.
Section 05b
Security of your data
Technical and organisational measures
- Encryption in transit: all data is encrypted using TLS
- Encryption at rest: personal data, including photos and derived biometric data, is encrypted at rest
- Access controls: access to personal data is restricted to authorised personnel only, on a need-to-know basis
- API security: all API calls to FASHN AI use secure authenticated connections
- Regular review: we regularly review our security practices as the product evolves
Data breach notification
- Notify the ICO within 72 hours of becoming aware of the breach (Article 33 UK GDPR)
- Notify you directly without undue delay if the breach is likely to result in a high risk to your rights (Article 34 UK GDPR)
Section 06b
Marketing communications
We may send you marketing or promotional emails about Vestyl. We will only do this with your explicit consent. You can opt out at any time by:
- Clicking the "Unsubscribe" link at the bottom of any marketing email
- Going to Settings → Notifications → Email preferences in the app
- Emailing us at privacy@vestyl.app
Section 08
How long we keep your data
| Data type | How long we keep it |
|---|---|
| Account information (name, email) | For the duration of your account, plus 30 days after deletion |
| Your uploaded photo | Until you delete it, or until your account is deleted |
| Biometric data derived from your photo | Deleted within 30 days of photo deletion or consent withdrawal |
| AI-generated try-on images | Until you delete them, or until your account is deleted |
| Social feed posts and comments | Until you delete them, or until your account is deleted |
| Usage and analytics data | Up to 26 months (anonymised after 14 months) |
| Affiliate tracking data | Up to 36 months (as required by affiliate network contracts) |
| Legal and compliance records | Up to 7 years where required by law |
Section 09
Your rights
Under UK GDPR, you have the following rights regarding your personal data:
Right to access
You can request a copy of the personal data we hold about you. We will respond within one month.
Right to rectification
If any data we hold about you is inaccurate or incomplete, you can ask us to correct it.
Right to erasure
You can ask us to delete your personal data. You can also delete your account directly in the app at Settings → Account → Delete my account.
Right to withdraw consent
Where we process your data on the basis of consent, you can withdraw at any time. Go to Settings → Privacy → Manage my consents.
Right to restrict processing
In certain circumstances, you can ask us to restrict how we process your data.
Right to data portability
Where we process your data by automated means on the basis of consent or contract, you can ask us to provide it in a portable format.
Right to object
You can object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds.
Right to complain to the ICO
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Section 10
Children
The Vestyl app, and in particular the AI try-on feature which involves uploading and processing photographs, is intended for users aged 18 and over.
We do not knowingly collect personal data from anyone under the age of 18. If you believe we may have collected data from a child, please contact us at privacy@vestyl.app immediately.
Section 11
Changes to this policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by sending an email to the address associated with your account and displaying a prominent notice in the app.
Important: For any changes that affect how we process your biometric data, we will always seek your fresh explicit consent before the new processing begins.
Section 12
Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please get in touch.
