Privacy policy.
Effective June 2026
Draft — pending counsel review
This is a working draft prepared for review by legal counsel. It describes how Upstyler currently operates but is not yet final. For questions, a current draft for a specific purpose (compliance review, DSAR), or to exercise a data right, email info@mlai.solutions.
Upstyler is built around two privacy defaults. First, the photos you submit for a verdict are processed and then discarded — we don’t keep them unless you choose to. Second, biometric data is never stored unless you explicitly opt in with a versioned consent record. This policy explains what we collect, why, how long we keep it, who processes it on our behalf, and the rights you have over it.
1. Who we are
Upstyler is operated by MLAI Solutions (“Upstyler,” “we,” “us”). We are the data controller for personal data processed through the Upstyler web app and marketing site at upstyler.ai. [counsel: confirm legal entity name, registered address, and EU/UK representative where required.]
2. Data we collect
We collect the following categories of data:
- Account data — email address and authentication identifiers, managed by our authentication provider (Clerk).
- Style profile — your style quiz answers, self-selected body type, dress-code preferences, age band, and home location (used for weather context).
- Wardrobe content — photos of your garments, plus the tags and embeddings derived from them.
- Outfit photos (biometric) — photos you submit for a verdict, and optionally a selfie for color analysis. See Section 4.
- Usage data — verdicts requested, lineups built, and feature interactions, used to operate the service and enforce plan limits.
- Payment data — we never store card details; payments are handled by Stripe, and we retain only a Stripe customer identifier and subscription status.
3. Why we process it (lawful basis)
We process account, style-profile, wardrobe, and usage data to provide the service you signed up for (performance of a contract) and to operate and secure it (legitimate interests). We process biometric data (faces and bodies) only on the basis of your explicit consent. We process payment data to administer your subscription. [counsel: confirm lawful-basis mapping for each jurisdiction.]
4. Biometric data and photos
Photos of people are the most sensitive data we handle, and we treat them accordingly:
- Photos submitted for a verdict are transient. They are stored only as long as needed to produce the verdict and are automatically purged within 30 days by a scheduled job. After that, we keep the scores and the written note, but not the image.
- A color-analysis selfie is optional and requires explicit consent. By default it is discarded immediately after analysis; saving it is off by default.
- Every biometric consent is recorded with a version and timestamp. If you revoke consent, the related feature is disabled and any stored data is purged within 30 days.
- Upstyler evaluates clothing choices only. We do not perform attractiveness scoring, facial recognition for identification, emotion recognition, or any biometric categorization of the person.
5. Data residency
Biometric data is stored in the region matching your account: EU users’ data is stored in EU regions, and US users’ data in US regions. We do not cross-region replicate biometric data.
6. Service providers (sub-processors)
We share data with vetted providers only to operate the service. Each is bound by a data-processing agreement, and our AI providers are contractually prevented from using your data to train their models:
- Clerk — authentication and account management
- Stripe — subscription billing and payments
- Cloudflare R2 — image storage (private buckets; short-lived signed URLs)
- Supabase — application database
- Modal — self-hosted image-embedding compute
- OpenAI, Anthropic, and Google — vision AI for verdicts and tagging (no training on your data; deletion on request)
- PostHog — product analytics (only with your consent)
- Sentry — error monitoring
- Resend — transactional email
[counsel: confirm the published sub-processor list and notification process for changes.]
7. Retention
We keep account, style-profile, and wardrobe data while your account is active. Verdict images are purged within 30 days; verdict scores and notes are retained for your history. On account deletion, we erase your data (see Section 8); backups are retained for up to 30 days before being overwritten.
8. Your rights
Depending on where you live, you have rights to access, correct, delete, port, and restrict processing of your data, and to withdraw consent at any time.
- Access / export — request a copy of your data; we respond within 30 days.
- Deletion — delete your account from settings; erasure completes within 24 hours (subject to the backup window above).
- Withdraw consent — turn off biometric features at any time; related data is purged.
EU/UK users may also lodge a complaint with their local data-protection authority. [counsel: add CCPA “Do Not Sell/Share” and BIPA-specific disclosures as required.]
9. Children
Upstyler is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18, and the verdict flow is disabled where a minor is detected.
10. Changes to this policy
We may update this policy as the product and the law evolve. Material changes will be announced in-app or by email, and the effective date above will be updated.
Questions about this policy? Contact MLAI Solutions at info@mlai.solutions.