Lookonic works on photos of you and your clothes, so how we handle them matters. This policy says what personal data we process, why, where it goes, how long we keep it, and the rights you have over it — in plain language, and completely.
Data controller: Anton Dokusov, trading as Lookonic — a sole trader in Spain; full details in clause 17.
Your wardrobe, portraits and looks live on your phone. Our server keeps no photos — only a finished render, for 24 hours, while the app collects it.
To recognise clothes, check portraits and render looks, photos leave the phone one step at a time, only when you act, to two AI providers in the United States — OpenAI and fal.ai — that work on our instructions and don't train on them.
On our server we hold your account: your Apple or Google sign-in ID and email, your credit balance and purchase history, a per-operation record of what each AI step cost us, and a short safety record. No name, no payment details, no location.
We don't use your photos to identify you or to infer anything about you: no face recognition, no profiling.
No advertising, no trackers, no selling of data. No analytics today either — if we ever add product analytics, this policy will say so first.
Delete your account and everything we hold about you goes — except a pseudonymous hash of your sign-in ID, so the welcome credit and a pause can't be reset by re-registering, and minimised purchase records, so a store receipt can't be reused.
You have every right the GDPR gives you — access, correction, deletion, objection, portability. Write to us; the Spanish data-protection authority (AEPD) hears complaints.
The numbered clauses below are the full notice; this box is a summary of them, not a replacement.
The data controller is Anton Dokusov, a sole trader (autónomo) registered in Spain, trading as Lookonic — "we", "us" and "our" below. Contact and legal details are in clause 17. We have not appointed a data-protection officer — the law doesn't require one for processing on this scale — so write to us directly at help@lookonic.app and the operator answers personally.
The Lookonic app for iPhone and Android, our server behind it, and our website at lookonic.app. It doesn't cover Apple, Google or the app stores, which handle your sign-in and payments under their own privacy policies, or what happens to a look after you share it out of the app. Our Terms of Service are the contract this policy sits alongside.
Lookonic is built to hold as little as possible about you. This is the complete list.
Nothing is uploaded until you act — adding a garment, saving your portraits, or generating a look. Each time, only what that step needs leaves the phone, over an encrypted connection, and our server holds it only for as long as the step takes. We keep no originals.
A pseudonymous code derived from your account ID accompanies our OpenAI requests so that OpenAI can attribute misuse to an account without knowing who you are; fal.ai receives no account identifier or email — only the images and the outfit description. No person at Lookonic reviews your photos in the normal running of the service: the operator alone has server access, for maintenance and emergencies. We don't use your photos, your looks or your wardrobe to train AI models, and we don't let our providers do so.
We don't rely on consent for any of the above, and we don't ask for consent to do things you wouldn't expect from the app. Camera and photo-library access are permissions you grant to the app in your phone's settings, and you can withdraw them there at any time. You have the right to object, at any time, to processing based on our legitimate interests — clause 11 explains how.
Photos of a face aren't automatically "biometric data" under the GDPR — they become that only when processed by technical means that let someone be uniquely identified. Lookonic never does that. Nothing in the pipeline recognises who you are, compares your face with anyone else's, or extracts a facial template. The models look at your portraits to check the framing — one person, face visible, full body visible — and to render clothes onto them, and that's all.
We also don't try to infer anything about you from your photos — not health, ethnicity, religion, or anything else a photograph might incidentally show — and we don't record such things. It is also why we ask you never to upload photos of anyone else: they haven't agreed to any of this.
We share personal data only with the providers we need to run Lookonic. OpenAI, fal.ai, Railway, Cloudflare and our email provider process it on our instructions, for the purposes below, under data-processing agreements that bind them to protect it at least as this policy does; none may use it for purposes of its own — beyond operating and securing its service — or to train AI models. Apple and Google act independently, as described below.
We don't sell personal data and don't share it with advertisers or data brokers. Today we run no analytics; if we add product analytics to understand how the app is used, we will update this policy first (clause 16). Our operational alerts carry only counts, never personal data. Beyond this list, we would disclose data only where the law requires it — a court order, for instance — or to a successor operator of Lookonic (Terms, clause 12), who would be bound by this policy.
Our server, database and render volume are in the United States, and OpenAI and fal.ai process data there too. The website is served from Cloudflare's edge network, so a page is delivered from a location near you, while Cloudflare may process its access logs in the United States. Transfers of your data out of the European Economic Area rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses built into each provider's data-processing agreement — backed by the minimisation you have read about: photos aren't stored, identifiers are pseudonymous, retention is short. You can ask us for a copy of these safeguards (clause 17).
You can delete your account at any time from the account screen in the app. If you can't reach the app, ask through the deletion page on our website or by email; we may ask you to confirm you own the account — for instance by writing from the email address linked to it — and we act within 30 days. Deletion cannot be undone.
When you delete: if you signed in with Apple we tell Apple to revoke Lookonic's access; we delete every render of yours; we delete your account and everything linked to it — sessions, credit ledger, spend and safety records, look jobs, purchase-validation attempts, the Apple token. If you delete from the app, it also wipes its own data — wardrobe, portraits, looks, session token, purchase journal — from your phone; if you ask by website or email, what is on your phone stays until you delete the app. Unused credits are forfeited (Terms, clause 12).
Two things stay:
Both are kept under our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR), the purchase records also to defend against claims (Art. 17(3)(e)); nothing else survives.
Under the GDPR you can ask us, at any time and free of charge, to:
Most of your data is already in your hands: your wardrobe, portraits and looks are on your phone, where you can view, share and delete them yourself. What we hold on the server about you is small, and we will send it on request. To exercise any right, write to help@lookonic.app; we may ask you to confirm you own the account first, and we answer within one month — up to three for a complex request, and we will tell you if that's the case.
If you think we have handled your data unlawfully you can complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, aepd.es — or to the authority of the country where you live, and you can bring a claim in court. We would ask you to write to us first: most concerns are resolved in a reply.
Every photo and note is checked automatically for prohibited content before it is processed, and a rejection blocks that one upload; a refusal by our render provider on its own content-policy grounds counts as a rejection too. Repeated rejections in a short period automatically pause look generation on your account for about a day. Purchases are validated automatically against the store's signed receipt. These steps have no human in the loop at the moment they happen; terminating an account is a decision a person makes.
None of this profiles you or produces a decision with legal or similarly significant effects. If you think an automated check got something wrong — a rejected photo, an unexpected pause, a purchase that won't validate — write to us and a person will review it.
Everything between the app, our server and our providers travels encrypted; the app refuses to talk to a non-encrypted server. Session tokens are stored only as hashes and never written to logs; stored credentials are encrypted; renders are kept apart from the database, out of our backups, and checked before delivery. Provider keys live only on the server. On your phone, the session token sits in the system keychain or keystore, and deleting your account from the app wipes the app's data.
No system is perfectly secure. If a breach ever puts your rights at high risk we will tell you, and the AEPD, as the law requires.
Lookonic is for adults: you must be 18 or older to sign in (Terms, clause 02), and it is not directed at children. We don't knowingly collect data from anyone under 18; if we learn we have, we delete the account. If you believe a minor is using Lookonic, tell us.
lookonic.app is a static site: no accounts, no cookies, no analytics, no third-party embeds — every part of a page, typefaces included, is served from lookonic.app itself. The only party that sees your visit is Cloudflare, which hosts the site and keeps ordinary access logs — IP address, page requested, time — for a limited period. Writing to us from the site, including through the deletion page, is handled as described in clauses 03 and 09.
We will update this policy when the service, our providers or the law change — for instance if we ever add product analytics to understand how the app is used. The date at the top shows the current version. If a change affects what we collect, why, or who we share it with, we will tell you in the app or by email before it takes effect, and where the law requires your consent we will ask for it.
For anything about your data — a question, a request under clause 11, a copy of the transfer safeguards, or a complaint: help@lookonic.app. We answer within a month.