Legal

Privacy Policy

Last updated · 27 August 2026

Lookonic works on photos of you and your clothes, so how we handle them matters. This policy says what personal data we process, why, where it goes, how long we keep it, and the rights you have over it — in plain language, and completely.

The short version

Data controller: Anton Dokusov, trading as Lookonic — a sole trader in Spain; full details in clause 17.

Your wardrobe, portraits and looks live on your phone. Our server keeps no photos — only a finished render, for 24 hours, while the app collects it.

To recognise clothes, check portraits and render looks, photos leave the phone one step at a time, only when you act, to two AI providers in the United States — OpenAI and fal.ai — that work on our instructions and don't train on them.

On our server we hold your account: your Apple or Google sign-in ID and email, your credit balance and purchase history, a per-operation record of what each AI step cost us, and a short safety record. No name, no payment details, no location.

We don't use your photos to identify you or to infer anything about you: no face recognition, no profiling.

No advertising, no trackers, no selling of data. No analytics today either — if we ever add product analytics, this policy will say so first.

Delete your account and everything we hold about you goes — except a pseudonymous hash of your sign-in ID, so the welcome credit and a pause can't be reset by re-registering, and minimised purchase records, so a store receipt can't be reused.

You have every right the GDPR gives you — access, correction, deletion, objection, portability. Write to us; the Spanish data-protection authority (AEPD) hears complaints.

The numbered clauses below are the full notice; this box is a summary of them, not a replacement.

01

Who is responsible for your data

The data controller is Anton Dokusov, a sole trader (autónomo) registered in Spain, trading as Lookonic — "we", "us" and "our" below. Contact and legal details are in clause 17. We have not appointed a data-protection officer — the law doesn't require one for processing on this scale — so write to us directly at help@lookonic.app and the operator answers personally.

02

What this policy covers

The Lookonic app for iPhone and Android, our server behind it, and our website at lookonic.app. It doesn't cover Apple, Google or the app stores, which handle your sign-in and payments under their own privacy policies, or what happens to a look after you share it out of the app. Our Terms of Service are the contract this policy sits alongside.

03

The data we handle

Lookonic is built to hold as little as possible about you. This is the complete list.

  • Account. Which sign-in you use (Apple or Google), the user ID that provider assigns you for Lookonic, the email address it shares with us (with Apple this may be a private-relay address) and, with Google, the address of your Google profile picture; when the account was created, when you last signed in, and when you finished onboarding. We don't collect your name.
  • Sign-in sessions. A random token that lets the app prove it's you to our server. We store only a hash of it, with its expiry date.
  • Apple sign-in token. If you sign in with Apple, a token from Apple that we keep encrypted for one job: telling Apple to revoke Lookonic's access when you delete your account.
  • Photos and text. Photos of your clothes; two portraits of you, face and full body; and the note you can type when generating a look.
  • Looks. For each look you generate, a job record: the occasion, season, note, anchor garment and app language you chose; a text snapshot of your wardrobe's tags at that moment; the outfit the stylist produced (name, rationale, scene, picks); the finished render; and technical details of the render file.
  • Credits and purchases. Your credit balance and a ledger of every movement — the welcome credit, purchases, looks, and any hold placed on a credit while a look renders. For each purchase: which store, which product, its status, the credits granted, timestamps, and a keyed hash of the store's transaction identifier. Failed validation attempts are recorded too. We never see or store card or payment details — Apple or Google takes the payment.
  • Spend record. One row per AI operation, with the provider, what it cost us, how long it took and whether it succeeded.
  • Safety record. Each time a photo or note is rejected as prohibited content: the rejection code and the time; and, if rejections pile up, the end time of the resulting pause. Not the photo, not the text, not the moderation categories.
  • Technical. Our server's access log records the IP address, request path, response code and time of each request. We use your IP address and sign-in ID briefly, in memory, to rate-limit sign-in and purchase requests. Each tag or look request tells us the app's UI language. The app doesn't send your device model, OS version, advertising ID, push token or location, and today it contains no analytics, crash-reporting or advertising SDK.
  • Support. Whatever you write to us, and our replies.
  • On your device only. Your wardrobe photos and their tags, your portraits, your saved looks (image, picks, name, rationale, note), your session token and a small purchase-recovery journal. None of this is copied to us as a set — clause 04 says exactly what leaves the phone, and when. Your phone's own backup — iCloud or Google — may include the app's data under Apple's or Google's terms; you control that in your phone's settings.
04

What happens to your photos

Nothing is uploaded until you act — adding a garment, saving your portraits, or generating a look. Each time, only what that step needs leaves the phone, over an encrypted connection, and our server holds it only for as long as the step takes. We keep no originals.

  • Adding a garment: the photo goes to OpenAI, which checks it for prohibited content and recognises the garment; the tags come back to your phone. We store neither the photo nor the tags.
  • Saving your portraits: each portrait goes to OpenAI, which checks it for prohibited content and that it shows one clearly visible person — face, or full body, as the slot requires. Nothing is stored.
  • Generating a look: your styling request — occasion, season, your note, and the tags of your wardrobe as text — goes to OpenAI, which checks the note and picks the outfit. Then your two portraits and the picked garments' photos are checked by OpenAI and rendered by fal.ai. The finished render is held on our server for the app to collect, and deleted after 24 hours.

A pseudonymous code derived from your account ID accompanies our OpenAI requests so that OpenAI can attribute misuse to an account without knowing who you are; fal.ai receives no account identifier or email — only the images and the outfit description. No person at Lookonic reviews your photos in the normal running of the service: the operator alone has server access, for maintenance and emergencies. We don't use your photos, your looks or your wardrobe to train AI models, and we don't let our providers do so.

05

Why we use your data, and on what legal basis

  • To provide the service — running your account, tagging garments, checking portraits, styling and rendering looks, delivering them, managing credits and purchases, answering your messages: performance of our contract with you (Art. 6(1)(b) GDPR). Providing this data is a condition of using Lookonic — without a sign-in and photos there is nothing to style.
  • To keep the service safe and lawful — moderating photos and text, counting prohibited-content rejections, pausing an account, keeping the pseudonymous deletion record so limits and pauses can't be reset by deleting and re-registering, rate-limiting, verifying purchases and preventing a receipt from being reused, and revoking Apple sign-in access on deletion: our legitimate interests (Art. 6(1)(f)) in preventing abuse of a service that renders real people, protecting other people whose photos must never be used, protecting our access to the AI providers, and meeting our obligations to Apple and Google. We have weighed these against your interests: the data involved is minimal, pseudonymous wherever it can be, and none of it is used to profile you.
  • To keep the service viable — recording what each AI operation costs us and how it performed: our legitimate interest (Art. 6(1)(f)) in cost control and reliability.
  • To meet legal obligations (Art. 6(1)(c)) — for instance marking every render as AI-generated as the EU AI Act requires, answering lawful requests from authorities, and keeping the records consumer or tax law asks of us.

We don't rely on consent for any of the above, and we don't ask for consent to do things you wouldn't expect from the app. Camera and photo-library access are permissions you grant to the app in your phone's settings, and you can withdraw them there at any time. You have the right to object, at any time, to processing based on our legitimate interests — clause 11 explains how.

06

Faces, photos and sensitive data

Photos of a face aren't automatically "biometric data" under the GDPR — they become that only when processed by technical means that let someone be uniquely identified. Lookonic never does that. Nothing in the pipeline recognises who you are, compares your face with anyone else's, or extracts a facial template. The models look at your portraits to check the framing — one person, face visible, full body visible — and to render clothes onto them, and that's all.

We also don't try to infer anything about you from your photos — not health, ethnicity, religion, or anything else a photograph might incidentally show — and we don't record such things. It is also why we ask you never to upload photos of anyone else: they haven't agreed to any of this.

07

Who we share data with

We share personal data only with the providers we need to run Lookonic. OpenAI, fal.ai, Railway, Cloudflare and our email provider process it on our instructions, for the purposes below, under data-processing agreements that bind them to protect it at least as this policy does; none may use it for purposes of its own — beyond operating and securing its service — or to train AI models. Apple and Google act independently, as described below.

  • OpenAI (OpenAI, L.L.C., United States) — content moderation of every photo and note; garment recognition; portrait checks; outfit styling. Receives the images and text described in clause 04, the app language and the pseudonymous per-user code. Under OpenAI's API terms this data isn't used to train its models; OpenAI keeps it only to monitor for abuse, for the limited period in its API data policy (currently up to 30 days), then deletes it.
  • fal.ai (Features and Labels, Inc., United States) — rendering the look. Receives your two portraits, the picked garments' photos and a text description of the outfit, and returns the render. fal processes the files for the render only; we ask fal not to keep the request and to delete the files promptly after the job.
  • Railway (Railway Corp., United States) — hosts our server, our database and the storage that holds renders for 24 hours, in the United States.
  • Cloudflare (Cloudflare, Inc., United States) — serves the lookonic.app website from its global edge network. Receives the IP address and request details of anyone who opens a page, in the access logs described in clause 15. It receives no app data: the app does not talk to it.
  • Apple and Google — as sign-in providers they give us your provider ID and email under their own privacy policies, independently of us; if you sign in with Apple, we exchange the sign-in code with Apple, and ask Apple to revoke Lookonic's access when you delete your account. As stores they handle payment: the app gives them only an opaque per-account code with each purchase, never your email or account ID, and we verify each purchase using the store's own signed receipt.
  • Our email provider, which hosts the mailbox you write to.

We don't sell personal data and don't share it with advertisers or data brokers. Today we run no analytics; if we add product analytics to understand how the app is used, we will update this policy first (clause 16). Our operational alerts carry only counts, never personal data. Beyond this list, we would disclose data only where the law requires it — a court order, for instance — or to a successor operator of Lookonic (Terms, clause 12), who would be bound by this policy.

08

Where your data is processed

Our server, database and render volume are in the United States, and OpenAI and fal.ai process data there too. The website is served from Cloudflare's edge network, so a page is delivered from a location near you, while Cloudflare may process its access logs in the United States. Transfers of your data out of the European Economic Area rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses built into each provider's data-processing agreement — backed by the minimisation you have read about: photos aren't stored, identifiers are pseudonymous, retention is short. You can ask us for a copy of these safeguards (clause 17).

09

How long we keep things

  • Photos sent for tagging, checking or rendering: not stored — held in memory only for the seconds the step takes.
  • A look's job record and its render: deleted after 24 hours — or immediately if you delete your account.
  • Your account, credit ledger, purchase-validation attempts, spend record, safety record and Apple sign-in token: for as long as your account exists — deleted when you delete it (clause 10).
  • Sign-in sessions: a session stops working 60 days after sign-in; its record is deleted when you sign out and, in any case, when you delete your account.
  • After deletion: the pseudonymous record and the minimised purchase records described in clause 10 — for as long as we operate Lookonic, for the reasons given there; if the service closes, they are deleted with it.
  • Anything the law requires us to keep: for the period it sets.
  • Support correspondence: for as long as it takes to handle the matter, and up to a year after it is closed; longer only if needed for a legal claim.
  • Server access logs: kept by our host for a limited rolling period and not archived by us.
  • Database backups: made by our host on a rolling schedule; a deleted account drops out of them as they roll over. Renders are kept out of our backups.
  • On your device: until you delete an item, delete your account, or remove the app.
10

Deleting your account, and what stays

You can delete your account at any time from the account screen in the app. If you can't reach the app, ask through the deletion page on our website or by email; we may ask you to confirm you own the account — for instance by writing from the email address linked to it — and we act within 30 days. Deletion cannot be undone.

When you delete: if you signed in with Apple we tell Apple to revoke Lookonic's access; we delete every render of yours; we delete your account and everything linked to it — sessions, credit ledger, spend and safety records, look jobs, purchase-validation attempts, the Apple token. If you delete from the app, it also wipes its own data — wardrobe, portraits, looks, session token, purchase journal — from your phone; if you ask by website or email, what is on your phone stays until you delete the app. Unused credits are forfeited (Terms, clause 12).

Two things stay:

  • A pseudonymous deletion record: a keyed one-way hash of your provider ID that cannot be reversed to your identity, whether the welcome credit was ever issued, the end time of any pause still running, and the date. It contains no email, no name, no photo. It is used only if the same Apple or Google identity signs in again — to withhold a second welcome credit and to reapply an unexpired pause — and is kept for as long as we operate Lookonic, because the abuse it prevents has no expiry date.
  • Minimised purchase records: for each purchase, the store, the product, its status, timestamps and a keyed hash of the store's transaction identifier — with the credits granted and the link to your account removed, and only a pseudonymous link to the same deletion record. They are kept so a store receipt can never grant credits twice, and to answer a dispute the store may raise.

Both are kept under our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR), the purchase records also to defend against claims (Art. 17(3)(e)); nothing else survives.

11

Your rights

Under the GDPR you can ask us, at any time and free of charge, to:

  • access the personal data we hold about you, and get a copy;
  • correct it if it's wrong — your email and provider ID come from Apple or Google, so changes to those are made there;
  • delete it — the account screen does this instantly (clause 10);
  • restrict its processing while a dispute is settled;
  • receive the data you gave us in a portable, machine-readable form;
  • object to processing based on our legitimate interests (clause 05) — we will stop unless we can show compelling grounds that override yours;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (clause 12).

Most of your data is already in your hands: your wardrobe, portraits and looks are on your phone, where you can view, share and delete them yourself. What we hold on the server about you is small, and we will send it on request. To exercise any right, write to help@lookonic.app; we may ask you to confirm you own the account first, and we answer within one month — up to three for a complex request, and we will tell you if that's the case.

If you think we have handled your data unlawfully you can complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, aepd.es — or to the authority of the country where you live, and you can bring a claim in court. We would ask you to write to us first: most concerns are resolved in a reply.

12

Automated checks and decisions

Every photo and note is checked automatically for prohibited content before it is processed, and a rejection blocks that one upload; a refusal by our render provider on its own content-policy grounds counts as a rejection too. Repeated rejections in a short period automatically pause look generation on your account for about a day. Purchases are validated automatically against the store's signed receipt. These steps have no human in the loop at the moment they happen; terminating an account is a decision a person makes.

None of this profiles you or produces a decision with legal or similarly significant effects. If you think an automated check got something wrong — a rejected photo, an unexpected pause, a purchase that won't validate — write to us and a person will review it.

13

Security

Everything between the app, our server and our providers travels encrypted; the app refuses to talk to a non-encrypted server. Session tokens are stored only as hashes and never written to logs; stored credentials are encrypted; renders are kept apart from the database, out of our backups, and checked before delivery. Provider keys live only on the server. On your phone, the session token sits in the system keychain or keystore, and deleting your account from the app wipes the app's data.

No system is perfectly secure. If a breach ever puts your rights at high risk we will tell you, and the AEPD, as the law requires.

14

Children

Lookonic is for adults: you must be 18 or older to sign in (Terms, clause 02), and it is not directed at children. We don't knowingly collect data from anyone under 18; if we learn we have, we delete the account. If you believe a minor is using Lookonic, tell us.

15

The website

lookonic.app is a static site: no accounts, no cookies, no analytics, no third-party embeds — every part of a page, typefaces included, is served from lookonic.app itself. The only party that sees your visit is Cloudflare, which hosts the site and keeps ordinary access logs — IP address, page requested, time — for a limited period. Writing to us from the site, including through the deletion page, is handled as described in clauses 03 and 09.

16

Changes to this policy

We will update this policy when the service, our providers or the law change — for instance if we ever add product analytics to understand how the app is used. The date at the top shows the current version. If a change affects what we collect, why, or who we share it with, we will tell you in the app or by email before it takes effect, and where the law requires your consent we will ask for it.

17

Contact and complaints

For anything about your data — a question, a request under clause 11, a copy of the transfer safeguards, or a complaint: help@lookonic.app. We answer within a month.

  • Controller: Anton Dokusov, trading as Lookonic
  • Address: C/ Pare Palau, 5, entresuelo 3ª, 43001 Tarragona, Spain
  • Phone: +34684784775
  • Email: help@lookonic.app
  • VAT (NIF-IVA): ESZ3275721C
  • Supervisory authority: Agencia Española de Protección de Datos, aepd.es