1. Who We Are
LooksOnMe operates the website available at lookson.me and related product flows. For privacy questions, requests, or complaints, you can contact support@lookson.me.
For privacy-law purposes, LooksOnMe is the controller of the personal data described in this Privacy Policy, except where a third party independently controls its own processing, such as a payment provider or identity provider.
2. Personal Data We Collect
We collect personal data that you provide directly, data created through your use of the service, and limited technical data generated when you access the website.
Depending on how you use LooksOnMe, this may include:
- Account and profile data, such as your name, email address, authentication identifiers, and sign-in provider details.
- User content, such as the photo you upload, garment screenshots, generated try-on results, and related upload metadata.
- Transaction and billing data, such as the offer you selected, checkout session identifiers, customer identifiers, entitlement records, ledger entries, and subscription status. Full payment card details are processed by Stripe, not stored by LooksOnMe.
- Support communications, such as messages you send to support@lookson.me and the information you include in those messages.
- Usage and device data, such as IP address, browser information, referring pages, pages visited, actions taken in the product, approximate timestamps, and crash or error details.
- Cookie and similar-technology data, including essential cookies used for authentication, session continuity, locale preference, onboarding recovery, security, and an optional analytics consent cookie.
3. Sensitive Content and Photos
Because LooksOnMe processes user photos and generated visual outputs, some of the data you provide may be sensitive or highly personal. You should upload only content you are comfortable sharing for the purpose of receiving a try-on preview.
You must not upload photos or screenshots that you do not have the right to use, or content that is unlawful, exploitative, invasive of another person's privacy, or otherwise prohibited by our Terms of Use.
4. How We Use Personal Data
We use personal data only where we have a valid reason to do so, including to perform our contract with you, comply with legal obligations, pursue legitimate business interests, and, where required, rely on your consent.
We use personal data to:
- Operate the website and your account.
- Authenticate users and maintain sessions.
- Create, deliver, store, and display try-on previews.
- Process uploads and convert them into generation inputs.
- Process payments, subscriptions, credits, refunds, and billing support.
- Detect abuse, fraud, security incidents, and policy violations.
- Debug, monitor, log, and improve performance and reliability.
- Measure funnel performance and product usage when analytics consent has been granted.
- Respond to support requests, legal requests, and enforcement matters.
5. Legal Bases for GDPR and LGPD
If GDPR, UK GDPR, or LGPD applies to you, our main legal bases are: contract performance, legitimate interests, consent, and legal obligation.
More specifically, we generally rely on contract performance to provide sign-in, account, generation, and billing features; legitimate interests to secure, maintain, and improve the service; consent for optional analytics cookies where required; and legal obligation where we must keep records, handle disputes, or respond to lawful requests.
7. AI and Automated Processing
To create try-on previews, LooksOnMe processes your uploaded images with automated machine-learning tools. The current implementation sends generation inputs to Google Vertex AI after creating short-lived signed access URLs for the required files.
These tools help generate visual previews, but they can make mistakes or produce outputs that do not perfectly reflect real-life fit, appearance, texture, or garment behavior. We do not use the service to make legal, medical, employment, housing, or credit decisions about you.
9. International Transfers
LooksOnMe and its service providers may process personal data in countries other than the one where you live. Those countries may have different data-protection laws.
Where required, we rely on appropriate transfer mechanisms and contractual safeguards provided by our vendors or otherwise required by law.
10. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required by law, dispute handling, fraud prevention, or accounting obligations.
Current product retention rules reflected in the codebase include: anonymous unfinished upload drafts are intended to expire after 30 minutes; authenticated unfinished upload drafts are intended to expire after 7 days unless promoted sooner; and expired upload drafts and their associated stored assets are intended to be removed by an internal cleanup job.
Completed account data, generated results, and billing records may remain associated with your account until you delete the account or we no longer need the data for service, support, security, accounting, or legal purposes.
11. Your Rights and Choices
Depending on where you live, you may have the right to request access to personal data, correction of inaccurate data, deletion, portability, restriction, objection to certain processing, or withdrawal of consent where consent is the basis.
You can also choose whether to accept optional analytics cookies. If you no longer want to use the service, you may request account deletion through available account controls or by contacting support. The current product includes an account-deletion backend capability, but support assistance may still be required depending on the surface available to you.
If you are in the European Economic Area, United Kingdom, or Brazil, you may also have the right to lodge a complaint with your local supervisory authority or the Brazilian ANPD, as applicable. If you are in certain U.S. states, you may have rights to know, access, delete, correct, or opt out of certain processing, subject to legal exceptions.
12. California and Other U.S. State Privacy Notices
LooksOnMe may collect identifiers, commercial information, internet or network activity information, user-generated content, and inferences related to service operation. We collect these categories for the business purposes described above, such as providing the service, securing it, processing transactions, and improving it.
We do not believe the current implementation sells personal data for money. If cross-context behavioral advertising or sharing under certain state laws becomes relevant later, the policy and implementation should be updated accordingly.
13. Children's Privacy
LooksOnMe is not intended for children. Do not use the service if you are under the minimum age required in your jurisdiction to consent to online services.
If you believe a child provided personal data to LooksOnMe, contact support@lookson.me so we can investigate and take appropriate action.
14. Security
We use reasonable technical and organizational measures designed to protect personal data, including access controls, authenticated storage flows, signed URLs for file access, and provider access restrictions. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the last-updated date. Material changes may also be communicated through the product or by email where appropriate.
16. Contact
For privacy requests, data-protection questions, or complaints, contact support@lookson.me.