DressGenius Privacy Policy

How we collect, use, and protect your personal data

Effective Date: April 13, 2026
Last Updated: April 13, 2026

Table of Contents

  1. Introduction and Data Controller
  2. Personal Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Third-Party Data Sharing
  6. International Data Transfers
  7. Data Retention and Deletion
  8. Your Privacy Rights
  9. Data Security
  10. Children's Privacy
  11. CCPA-Specific Rights (California Residents)
  12. GDPR-Specific Rights (EU Residents)
  13. LGPD-Specific Rights (Brazilian Residents)
  14. Changes to This Policy
  15. Contact Us

1. Introduction and Data Controller

DressGenius is an AI-powered fashion consultant mobile application that analyzes your outfit photos, provides style recommendations, and helps manage your digital wardrobe. This Privacy Policy explains how DressGenius Tecnologia LTDA ("DressGenius," "we," "us," "our") collects, uses, discloses, and safeguards your information when you use our mobile application (the "Service").

Data Controller Information DressGenius Tecnologia LTDA
Located in: Ponta Grossa, Paraná, Brazil
Privacy Contact: support@dressgenius.app
Data Protection Officer (DPO): dpo@dressgenius.app

We are committed to complying with applicable privacy laws, including the General Data Protection Regulation (GDPR) for European residents, the Lei Geral de Proteção de Dados (LGPD) for Brazilian residents, the California Consumer Privacy Act (CCPA) for California residents, and comparable privacy laws in other jurisdictions.

2. Personal Data We Collect

We collect various categories of personal data to operate our Service and provide you with personalized fashion recommendations. Below is a comprehensive breakdown:

2.1 Registration and Authentication Data

When you create a DressGenius account, we collect:

2.2 Social Authentication Data

If you authenticate via third-party providers, we collect:

Provider Data Collected
Google OAuth Google user ID, email address, name, profile picture URL
Apple Sign-In Apple user ID (sub claim), email address (real or @privaterelay.appleid.com alias if you chose "Hide My Email"), name (only if you chose to share it on first sign-in)

Apple Sign-In — Private Relay: When you sign in with Apple and choose "Hide My Email", Apple generates a unique, randomized email address ending in @privaterelay.appleid.com and forwards messages to your real email. We only store the relay address — we never receive your real email. Push notifications are delivered via device tokens and do not depend on email.

Apple Sign-In — Security (SHA-256 nonce): To prevent replay attacks, our mobile app generates a cryptographically random 32-byte nonce per sign-in, sends its SHA-256 hash to Apple, and forwards the raw nonce to our backend. Our backend validates that the hash in Apple's identity token matches the raw nonce we received. This ensures each authentication token can only be used once and only by the client that initiated the request.

2.3 Profile and Photo Data

2.4 Outfit and Wardrobe Photos

2.5 Preference and Customization Data

We collect your AI analysis preferences as slider values (0–100 scale):

2.6 Device and Push Notification Tokens

2.7 Usage and Analytics Data

2.8 Error Logs and Diagnostic Data

2.9 Sharing and Social Data

2.10 Transactional Data

2.11 Communication Data

2.12 Closed Beta Program Data

If you participate in our Closed Beta Program (invite-only, capped at 75 users), we collect and make the following additional data visible to our administrators for cost control and program management:

This data is derived from the same usage tracking we already perform for all users (Section 2.7); what differs for beta participants is the administrative visibility of per-user totals in an internal dashboard, used to (a) enforce the monthly quota, (b) monitor aggregate AI costs during the pre-launch phase, and (c) inform graduation decisions when the beta program concludes. Beta data is retained under the same schedule as regular account data (Section 7.1) and you retain all rights described in Section 8 (including the right to leave the beta program at any time by contacting dpo@dressgenius.app).

3. How We Use Your Data

We use the personal data we collect for the following purposes:

3.1 Service Delivery and Personalization

3.2 Location-Based Services

3.3 Communications and Notifications

3.4 Account Management

3.5 Analytics and Improvement

3.6 Legal Compliance and Safety

3.7 Sharing Features

4. Legal Basis for Processing

We process your personal data based on the following legal foundations:

4.1 Consent

4.2 Contract Performance

4.3 Legitimate Interest

4.4 Legal Obligation

4.5 Vital Interests

5. Third-Party Data Sharing

We share your personal data with the following third-party service providers only to the extent necessary to deliver our Service. These services are contractually bound to use your data solely as instructed and maintain appropriate security safeguards:

Service Provider Purpose Data Shared
Google Gemini Vision API AI outfit analysis: colors, style, occasion, climate assessment Outfit photos (base64), location context, preferences
Google Gemini Chat API Conversational AI about outfit recommendations Chat messages, outfit analysis data, user preferences
OpenAI DALL-E / GPT-Image (if deployed) AI-generated outfit image creation Outfit context, color palette, style description
Anthropic Claude API (alternative) Alternative AI analysis and conversation Analysis context, messages, preferences
FASHN.ai Outfit photo editing and enhancement Outfit images, editing instructions
Google OAuth / Apple Sign-In Account authentication Email, name, profile picture, unique ID
Expo Push Service Sending push notifications to your device Push tokens, notification content
RevenueCat Subscription and in-app purchase management Purchase history, subscription status (PCI DSS compliant)
Open-Meteo API Weather data for contextual recommendations Location (anonymous, no user ID)
Render.com Hosting our backend servers All application data (encrypted in transit and at rest)
PostgreSQL / Supabase (planned) Database storage All personal data (encrypted)
Cloudflare R2 (planned) File storage (outfit photos, profile photos) Photos and generated images (encrypted)
Important: We do not sell or rent your personal data to third parties for marketing purposes. Sharing is limited to service delivery partners, and we maintain Data Processing Agreements with each provider.

5.1 Legal and Business Disclosures

We may disclose your information if required by law or in response to valid legal process (subpoena, court order, government request), to protect our rights, privacy, safety, or property, or to establish, exercise, or defend legal claims.

6. International Data Transfers

DressGenius is based in Brazil and operates services in multiple jurisdictions. Your data may be transferred to, stored in, and processed in countries other than your country of residence, including:

These countries may not have equivalent privacy laws. However, we implement appropriate safeguards:

Note for EU Residents: If you reside in the EU, we comply with GDPR Article 44–49 for international transfers. We use appropriate mechanisms such as Standard Contractual Clauses and conduct Transfer Impact Assessments to ensure adequate safeguards.

7. Data Retention and Deletion

7.1 Retention Period

Currently, we retain your personal data for the duration of your account and for as long as necessary to provide our Service, comply with legal obligations, and resolve disputes. Specific retention periods are as follows:

7.2 Account Deletion

You can request deletion of your account at any time through the app settings or by contacting support@dressgenius.app. Upon account deletion:

7.3 Right to Erasure

You may request deletion of specific data categories under GDPR (right to be forgotten) and LGPD. Requests are processed within 30 days, except where legal obligations require retention.

8. Your Privacy Rights

Depending on your location, you have certain rights regarding your personal data:

8.1 Universal Rights (All Users)

  • Right to Access: Request a copy of your personal data in a commonly used, machine-readable format
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (subject to legal requirements)
  • Right to Data Portability: Export your data in a structured, machine-readable format
  • Right to Restrict Processing: Limit how we use your data in certain circumstances
  • Right to Object: Opt out of certain processing activities (marketing, profiling)
  • Right to Non-Discrimination: We will not discriminate based on exercise of privacy rights

8.2 How to Exercise Your Rights

To exercise any of the above rights, please submit a written request to:

We will respond within 30 days (GDPR / LGPD) or as required by law. We may request proof of identity to verify the request.

9. Data Security

We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, and destruction:

9.1 Encryption

9.2 Access Controls

9.3 Infrastructure Security

9.4 Third-Party Security

9.5 Incident Response

In the event of a data breach, we will notify affected individuals within 72 hours (GDPR), 30 days (LGPD), or as required by law. Notifications will include the nature of the breach, data affected, and remedial steps.

Important: While we employ industry-standard security measures, no system is 100% secure. We recommend using strong, unique passwords and enabling two-factor authentication where available.

10. Children's Privacy (Age Requirement: 13+)

DressGenius is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. By using DressGenius, you confirm that you are at least 13 years old.

If we discover that a user is under 13, we will:

For users aged 13–18, we:

If you are a parent or guardian and believe a child has provided information to DressGenius, please contact support@dressgenius.app immediately.

11. CCPA-Specific Rights (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights regarding your personal information (as defined in CCPA § 1798.100 et seq.):

11.1 Right to Know

You have the right to request and receive:

11.2 Right to Delete

You may request deletion of personal information collected from you, except where exemptions apply (e.g., legal obligations, fraud prevention). We will delete the requested information within 45 days.

11.3 Right to Correct

You may request correction of inaccurate personal information.

11.4 Right to Opt-Out of Sale or Sharing

We do not sell or share your personal information for cross-context behavioral advertising. You may still opt-out of any future sale or sharing by contacting support@dressgenius.app.

11.5 Right to Limit Use

You may request that we limit our use of sensitive personal information (SSI) to necessary purposes. We do not use SSI for purposes not necessary to provide the Service.

11.6 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights. You will receive the same service quality and pricing, and we will not limit access to our Service.

11.7 How to Submit CCPA Requests

Send requests to:

Provide sufficient information to verify your identity (account email, account ID, or other identifying information). Authorized agents may submit requests on your behalf with proper power of attorney.

11.8 Household Requests

CCPA allows household requests for families using the same device or account. Contact our privacy team to coordinate household requests.

11.9 Shine the Light Law (CA Civil Code § 1798.83)

California residents may request information about personal information shared with third parties for marketing purposes. We do not share personal information for third-party direct marketing, so this request is not applicable. However, you may contact us for clarification.

12. GDPR-Specific Rights (EU Residents)

If you are a resident of the European Union, United Kingdom, or European Economic Area (EEA), the General Data Protection Regulation (GDPR) grants you specific rights:

12.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether your personal data is processed and to receive a copy of your data in a structured, commonly used, machine-readable format (e.g., CSV, JSON).

12.2 Right to Rectification (Article 16)

You may correct inaccurate or incomplete personal data without undue delay.

12.3 Right to Erasure / "Right to Be Forgotten" (Article 17)

You may request erasure of your personal data, except where:

12.4 Right to Restrict Processing (Article 18)

You may restrict processing of your data in cases of accuracy disputes, unlawful processing, or when you object but we still have a lawful basis.

12.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a portable, machine-readable format and to transmit it to another controller without hindrance.

12.6 Right to Object (Article 21)

You may object to processing based on legitimate interests or for direct marketing purposes at any time. We will cease processing unless we can demonstrate compelling legitimate grounds.

12.7 Rights Related to Automated Decision-Making and Profiling (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produces legal or similarly significant effects. DressGenius uses AI for recommendations, not binding decisions, so this right has limited application. However, you may request human review of AI analyses.

12.8 Right to Lodge a Complaint

If you believe we have violated your rights under GDPR, you have the right to lodge a complaint with your local Data Protection Authority (DPA). The supervisory authorities for major EU countries are:

12.9 EU Representative

For GDPR compliance, DressGenius Tecnologia LTDA designates a representative within the EU. Contact our DPO for representative details.

13. LGPD-Specific Rights (Brazilian Residents)

If you are a resident of Brazil, the Lei Geral de Proteção de Dados (LGPD, Federal Law 13.709/2018) grants you the following rights:

13.1 Right of Access (Lei 13.709, Art. 18)

You have the right to obtain information regarding how your personal data is processed, including:

13.2 Right to Rectification (Lei 13.709, Art. 19)

You may request correction of inaccurate or incomplete personal data.

13.3 Right to Erasure (Lei 13.709, Art. 17)

You may request deletion of your personal data, subject to exceptions including legal obligations and data necessary for the service's core functionality.

13.4 Right to Data Portability (Lei 13.709, Art. 20)

You may request your personal data in a portable, structured format and transfer it to other controllers.

13.5 Right to Block or Restrict (Lei 13.709, Art. 18, § 5º)

You may request that your data be blocked temporarily or permanently, in accordance with LGPD guidelines.

13.6 Right to Oppose Processing (Lei 13.709, Art. 18, § 6º)

You have the right to object to processing based on legitimate interests, legal obligations, or other lawful grounds.

13.7 Right to Information About Sharing (Lei 13.709, Art. 18, § 4º)

You have the right to know which third parties your data is shared with and for what purposes.

13.8 Right to Lodge a Complaint

If you believe we have violated your rights under LGPD, you may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/cidadania/pt-br/acesso-a-informacao/lgpd.

13.9 How to Submit LGPD Requests

Submit requests in Portuguese or English to:

We will respond within 15 business days. Requests may be extended for an additional 15 days with notice. We may request proof of identity.

13.10 Opt-Out of Marketing Communications

You may opt-out of marketing and promotional emails at any time by clicking the "unsubscribe" link in the email or contacting our privacy team.

14. Changes to This Privacy Policy

DressGenius may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the top of this policy indicates when it was last revised.

When we make material changes, we will:

Your continued use of DressGenius after changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you may delete your account.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Inquiries

Email: support@dressgenius.app
Data Protection Officer (DPO): dpo@dressgenius.app
Mailing Address:
DressGenius Tecnologia LTDA
Ponta Grossa, Paraná
Brazil
Response Time: 30 days (GDPR / LGPD) or as required by law

15.1 Customer Support

For general support or feature requests unrelated to privacy, visit the DressGenius app settings or contact support@dressgenius.app.

DressGenius Tecnologia LTDA
Dress smarter. Powered by AI.
Leia em Português | Terms of Service

© 2026 DressGenius Tecnologia LTDA. All rights reserved.