ARO

Privacy Policy

Last updated: 30 September 2026

At FashionAI, we take the privacy of your data seriously. This policy explains what information we process, for what purposes, on what legal basis, with whom we share it, how long we keep it, and what rights you have.

1. Data controller

  • Controller: Manuel Palacios, a natural person trading under the commercial name FashionAI
  • RFC: PAHJ840720EJ7
  • Address: Tultitlan 10, Delg. Tlalpan, 14340, Mexico City (Mexico)
  • Contact email: [email protected]

Data Protection Officer: we have not appointed one. If we do so in the future, we will publish their contact details here. For any questions about your data, write to us at [email protected].

Representative in the European Union (Article 27 GDPR): Juan Hernandez, Carrer Viladomat 161, 08015 Barcelona (Spain). You may contact him by writing to [email protected]. If you reside in the EU, you may contact either him or us for any matter relating to the processing of your data.

1.1. Which laws apply to your data

The controller is established in Mexico, and the service is also offered to people residing in the European Union. For that reason, two legal frameworks coexist and we always apply the more protective one:

  • If you reside in the EU or the EEA, the General Data Protection Regulation (GDPR) applies to you, because we target our service to people in the Union (Article 3(2)). Your data is processed by the controller from Mexico; details of suppliers and safeguards are set out in section 7.
  • If you reside in Mexico, the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations apply to you, together with the ARCO rights described in section 13.

This policy also serves as a full privacy notice for the purposes of the LFPDPPP.

2. What this policy applies to

This policy covers two things:

  • The FashionAI mobile app for Android and iOS.
  • The website arofashionai.com, which is informational and also lets you contact us and request deletion of your account.

Where something applies only to one of the two, we will say so expressly.

3. What data we process

3.1. In the app

In the table below, "Required" means that without that data we cannot provide the relevant feature, and "Optional" means that you may choose not to provide it: the app will still work, with the limitation described.

DataNatureWhat happens if you do not provide it
Account: email address and login credentials, managed by our authentication providerRequiredYou cannot create an account or use the app
Profile: gender, age, weight, height, sizes and body measurementsRequired for analysis and recommendationsWe cannot calculate your body shape or tailor items to your body
Professional context: sector, type of work, work city and scheduleRequired for Morning Briefing and work outfitsThose features are disabled or become much less accurate
City of residenceOptionalWe use your work city or generic weather
Style preferences, favourite brands and jewellery preferencesOptionalRecommendations are not personalised around those preferences
Metal allergiesOptional — see section 5We do not filter the metals in the jewellery we recommend
Photos of your face and body for image analysisRequired for analysisNo colour analysis, facial morphology or body-proportion analysis is possible
Photos of your garments for your wardrobeRequired for the wardrobeWe cannot identify or recommend your garments
Voice: audio from your conversation with the ARO assistantRequired to speak with AROYou can use the rest of the app, but you will not be able to talk to ARO
Usage data: recommended outfits, events and trips you plan, recommendation history and Morning Briefing settingsRequired to provide the service—
Reactions to outfits ("Improve my recommendations")Optional, with consent — see section 8Nothing happens: the service works the same
Technical data: device time zone, push notification identifier, and operational and security logsRequired—
Approximate device locationOptionalWe use the city you provided in your profile
Subscription data: plan status, credit balance and purchase identifiersRequired if you subscribe to a plan—

Regarding photos of your face and body: from them we derive characteristics such as your colour analysis, the shape of your face, your posture and your proportions. We explain this in detail in section 4.

Regarding voice: your audio is processed in real time in order to understand and respond to your requests, and a temporary transcription is generated in order to keep the conversation context. Neither the audio nor the transcription is stored on our servers: they exist only in memory during the session and disappear when it ends. We do keep the result (the outfit or event you asked for).

Regarding payments: the charge is processed entirely by the app store or the relevant payment provider. We do not store your card details.

3.2. Source of the data

Almost all data is provided directly by you. In addition:

  • If you sign in with Google, Google provides us with your email address and your account identifier. We never receive your password.
  • If you sign in with Apple, Apple provides us with a unique identifier for the app and, depending on the options you choose, your name and email address — which may be a private relay address. We never receive your Apple Account password.
  • If you buy a subscription, we receive the status of that purchase from the app store (plan, renewal date, cancellation) so that we can activate the service.

3.3. On the website

  • The data you provide when you write to us (your email and the content of your message).
  • Technical server logs, which are standard for any web hosting service (IP address, date and time of the request, browser), required for security and maintenance of the service.

4. Photos of your face and body: what we do and what we do not do

Photos of your face and body, and the characteristics we infer from them, are personal data. FashionAI does not use your images to identify you uniquely, verify your identity, perform facial recognition, or compare your face with a database of people.

Their sole purpose is to provide style analysis: colour analysis, face shape, morphological traits and proportions that help us recommend garments, cuts and colours.

If a future feature were to process biometric data for the purpose of identifying you uniquely, it will not be activated without prior specific information, a valid legal basis and, where required, your explicit consent.

Safeguards we apply:

  • We request separate explicit consent before you add your photos. It is not a hidden checkbox within acceptance of the terms: it is a separate action, with its own explanation. We do this as a voluntary safeguard given the practical sensitivity of a facial image.
  • We prohibit — by instruction and by contract — our artificial intelligence providers from generating facial recognition templates, identifying embeddings or any processing aimed at identifying people from your images.
  • We do not use your images to train artificial intelligence models.
  • Your photographs are stored in private storage and are served only through temporary links that expire.

You may withdraw your consent and request deletion of these images at any time, without affecting the lawfulness of prior processing.

4.1. Body photos: what to wear

To make your silhouette visible, we ask you to take body photos wearing close-fitting clothes, underwear or a swimsuit; the choice is yours. We never ask you for nude photos. Body photos have the same safeguards as your face photos: private storage, expiring temporary links, and deletion when you delete your account.

4.2. Automatic review of each photo

When you add a photo for analysis, we review it automatically to let you know whether you should retake it:

  • On our servers, we check its quality (lighting, sharpness and framing) and, for body photos, your posture: whether your whole body is visible, whether you are facing forwards or sideways as appropriate, and whether your arms are slightly apart. To do this, we locate body points such as shoulders, hips or knees, and the outline of your figure. This is not person recognition and cannot be used to find out who you are.
  • For the front-facing body photo, and only if you have given your consent, Google (Gemini) tells us whether your clothes reveal your silhouette and what type of garment you are wearing (for example, a “jumpsuit” or “swimsuit”).

Photos you discard before analysis are not stored. For each review, we keep, without the image, the result (whether the photo is suitable and, if not, why), geometric posture measurements (proportions and distances in pixels, not centimetres), and the AI's response about the clothing. We keep this in technical logs for 30 days to check that the review works and adjust its criteria. If we use it to adjust them, we may keep an extract identified only by your internal identifier — never your name or email address — for up to 3 months.

4.3. Human review, only with your permission

No one on our team views your photos as part of the service, unless you ask us to do so to resolve an issue. The only exception is with your separate express permission, for example if you take part in an app test: in that case, the controller may view your body photos to check whether the automatic review and silhouette analysis were accurate. Any notes made (for example, “close-fitting clothing” or “loose-fitting clothing”) do not include your name or email address and are deleted within 3 months at the latest. You may withdraw that permission at any time by writing to [email protected].

5. Metal allergies

In your jewellery preferences, you may indicate which metals you are allergic to. We use this for a single purpose: always excluding those materials from the jewellery we recommend.

This information may reveal data about your health, so:

  • It is optional. You may leave that section blank: if you do not select any metal, we understand that you have no allergies and the rest of the app works in the same way.
  • We only process it if you enter it voluntarily, and that act is your explicit consent for that specific purpose.
  • We do not use it for anything else: no commercial profiling, no segmentation, and it is not disclosed to third parties.
  • You may delete or change it at any time from that same screen, and it is fully deleted when you delete your account.

6. Purposes and legal bases

PurposeLegal basis
Create and maintain your accountPerformance of the contract (Art. 6.1.b GDPR)
Provide the service: wardrobe, ARO recommendations, Morning Briefing, events and tripsPerformance of the contract
Analyse your face and body photos, review each photo when you add it (quality, posture and clothing), and derive your colour analysis and morphologyExplicit consent (Art. 6.1.a and, as a voluntary safeguard, Art. 9.2.a GDPR)
Keep the result of those reviews, without images, to check and adjust their criteriaLegitimate interest in ensuring the review works well; you may object by writing to [email protected]
Human review of your body photos to calibrate the analysis (section 4.3)Separate explicit consent, which may be withdrawn at any time
Process your metal allergies in order to exclude materialsExplicit consent, given when you enter them voluntarily
Process your voice so you can speak with AROPerformance of the contract: this is the feature you request when you start the conversation
Use your device's approximate location to adjust weatherConsent, which you give by granting the permission and may revoke in your system settings
Send you the Morning Briefing and functional service noticesPerformance of the contract, based on the settings you choose
Store your pseudonymised reactions in order to calibrate recommendation qualityConsent (opt-in), revocable at any time
Manage your subscription, credits and billingPerformance of the contract and legal obligation
Handle reports of inappropriate content generated by AIPerformance of the contract and legitimate interest in service safety
Security, abuse prevention and legal complianceLegitimate interest and legal obligation
Handle your enquiries and the exercise of your rightsLegal obligation

We do not send marketing communications or newsletters. If we ever do, we will ask separately, with its own checkbox and an unsubscribe route in every message.

We do not carry out behavioural advertising or sell your data to third parties.

Where the legal basis is consent, that consent is freely given, specific, informed and revocable, and we do not make the rest of the service conditional upon giving it.

7. With whom we share data

We work with providers that, unless otherwise stated, process data on our behalf, under data processing agreements and following our instructions.

ProviderPurposeRoleLocation and safeguard
SupabaseAuthentication, database and storage of your imagesProcessorData hosted in the EU region (Ireland); support access outside the EEA may occur under Standard Contractual Clauses (SCCs)
Google CloudHosting of the service and technical logsProcessorService hosted in the EU region (Madrid); support access outside the EEA may occur under SCCs
Google (Gemini)Analysis of your images and generation of recommendations through AIProcessorMay involve processing outside the EEA; SCCs
LiveKitReal-time audio transport and delivery to the agent of the metadata needed to personalise and continue the session: internal identifier, language and plan, profile and measurements, preferences and professional context, location when available, and context from the chat, outfit plan, event, trip or briefingProcessorMay involve processing outside the EEA; SCCs
OpenAIOccasional language-processing backup when the main provider is not availableProcessorMay involve processing outside the EEA; SCCs
SerpAPI / Google ShoppingProduct search across shops. It does not receive data that identifies you: only the description of the garment being searchedProcessorMay involve processing outside the EEA; SCCs
OpenWeatherWeather data for the city or approximate coordinates of your plansProcessorMay involve processing outside the EEA; SCCs
Expo and Google (Firebase Cloud Messaging)Sending push notificationsProcessorMay involve processing outside the EEA; SCCs
RevenueCatValidation and technical management of subscriptions purchased through the app store; it receives user and purchase identifiers, product, subscription status and dates, but not your card detailsProcessorMay involve processing outside the EEA; SCCs
Apple App StoreCharging for subscriptions and credits purchased on iPhone or iPadIndependent controller for the purchase, receipt, refunds and subscription management, under its own terms and privacy policyApple Distribution International Ltd. for users in the EEA; outside the EEA, the Apple entity applicable to your region
Google Play (Google Ireland Ltd.)Charging for subscriptions and credits purchased on AndroidIndependent controller: it is the merchant of record, charges you and issues the invoice under its own terms and privacy policyGoogle Ireland Ltd., Ireland (EU)
Paddle.com Market Ltd.Gateway used in subscriptions completed before migration to the app storesIndependent controller as merchant of record for those transactionsUnited Kingdom, with European Commission adequacy decision
Apple (Sign in with Apple)Authentication with your Apple Account; it provides us with a unique identifier and, if you choose to share them, your name and email or private relay addressIndependent controller for authentication under its own privacy policyApple Distribution International Ltd. for users in the EEA; outside the EEA, the Apple entity applicable to your region
ZohoSupport mailbox and internal moderation noticesProcessorData centre in the EU

You may request information about, or a copy of, the safeguards applied to any international transfer by writing to [email protected].

In addition to the above, we may disclose data to public authorities, courts and tribunals where we are legally obliged to do so.

7.1. Artificial intelligence services: what we send and to whom

The service is generated using artificial intelligence operated by third parties. Given its importance, we explain separately what leaves the application, who receives it and why:

What we sendTo whomPurpose
Photos of your face and bodyGoogle (Gemini)To recommend garments (necklines, sleeves, lengths, patterns and fabrics) that best suit your morphology and proportions and, in the front-facing body photo, check whether your clothes reveal your silhouette. We calculate your colour analysis and face shape on our own servers, not at Google
Photos of your garmentsGoogle (Gemini)To identify the garment, its colour, fabric and level of formality
Audio from your conversation with ARO and its temporary transcript; in addition, through the LiveKit token, your internal identifier, language and plan, profile and measurements, preferences and professional context, location when available, and session context (chat, outfit plan, event, trip, briefing or initial request)LiveKit (secure transport and delivery of the audio and metadata to the agent) and Google (Gemini Live, to process the conversation and respond)To understand what you say, personalise the recommendation and maintain session continuity
Audio and text from that same conversation, only as a backupOpenAITo replace the main provider when it is unavailable
Your style profile (gender, age, measurements, sizes, professional context and preferences), the result of your image analysis (colour season, palette, face shape and advice, without your facial measurements), and the events and trips you planGoogle (Gemini) and, as a backup, OpenAITo build the specific recommendation we provide
The description of the garment being searched for, without any data that identifies youSerpAPI / Google ShoppingTo find that garment for sale in shops

Before sending personal data to these AI services, we explain it to you within the application itself and ask for your permission. You can review this information or withdraw your permission at any time under Profile → App Settings → Privacy & data.

These providers act as processors: they process your data solely on our instructions and are contractually required to provide a level of protection equivalent to ours. In particular:

  • We do not use your data or images to train artificial intelligence models, nor do we authorise these providers to do so.
  • We do not ask or allow them to create facial recognition templates or carry out any processing aimed at identifying people from their images.
  • Neither the audio nor its transcript is stored on our servers: they remain in memory during the conversation and disappear when it ends.
  • None of them receives your card details or password.

8. Pseudonymised style reactions

If you enable "Improve my recommendations", when you react to an outfit we store that reaction together with characteristics of the garments (colour, formality, type of print, texture and similar features).

These records do not include your identity, your email, your photos or your garment identifiers: instead, they carry a pseudonymous identifier generated cryptographically. Even so, because that identifier is stable, we treat them as pseudonymised personal data and apply the GDPR to them: they have retention periods, they are deleted when you delete your account, and you can exercise your rights over them.

They are used exclusively to calibrate recommendation quality. You can disable this at any time under App Settings → Privacy & data, without affecting the rest of the service.

9. Automated decisions and profiling

FashionAI builds an aesthetic profile based on the data you provide (your image analysis, your measurements, your professional context, your wardrobe and your history) and generates recommendations automatically using artificial intelligence systems. That is precisely the service you are subscribing to.

These decisions are aesthetic and indicative: they do not produce legal effects concerning you, nor do they similarly significantly affect you. We do not use them to decide personalised prices, access to the service, credit, employment, insurance or any other matter with relevant effects, nor to infer emotions. Accordingly, this does not amount to automated decision-making within the meaning of Article 22 GDPR.

In any event, you may write to [email protected] to request an explanation of a specific recommendation, express your point of view, or request a human review.

10. Device permissions

The app requests permissions only when necessary, explains what they are for before requesting them, and you may revoke them at any time in your operating system settings.

PermissionPurposeIs it shared with third parties?If you deny it
Camera and photosTo photograph or select your garments and your analysis imagesImages are sent to our AI provider for analysisYou will not be able to upload garments or run image analysis
MicrophoneTo speak with the ARO assistantAudio is transported and processed in real time by our voice and AI providersYou will not be able to use the voice assistant; the rest of the app works
Location (optional)To adapt recommendations to the real weather where you areWeather is requested using approximate coordinatesWe use your profile city
CalendarTo write the events and trips you prepare with ARO into your own calendar called "FashionAI"No. We do not read or process the rest of your personal calendarYour events stay in the app but will not appear in your phone calendar
NotificationsTo send you the Morning Briefing at the time you chooseDelivery is handled through Expo and Firebase Cloud MessagingYou will not receive the alert; the briefing remains available within the app

11. How long we keep your data

DataRetention
Account, profile, measurements and preferencesWhile your account remains active
Photos of your face and body and their analysisWhile your account remains active, unless you withdraw consent earlier
Photos you review and discard before analysisNot stored
Result of each photo review, without the image (section 4.2)30 days in technical logs; the extract used to adjust the review, up to 3 months
Notes from a human review (section 4.3)Up to 3 months
Wardrobe, garment photos and combinationsWhile your account remains active
Events, trips and their planningWhile your account remains active
Audio of your conversations with ARONot stored: processed in real time
Conversation transcriptionNot stored: exists only in memory during the session
Context of the latest conversation (to resume the thread)Until you open a new chat or delete your account
History of recommended outfits30 days
Morning Briefing cache14 hours
Pseudonymised reactions referred to in section 8While your account remains active
Reports of inappropriate contentWhile your account remains active
Proof of your consents and requests to exercise rightsWhile the account is active and afterwards for the limitation period applicable to potential claims
Technical and security logs30 days
Billing dataFor the periods required by commercial and tax legislation

When you delete your account, we immediately disable access and delete data from active systems. Backups are overwritten in line with their retention cycle of 7 days, remaining isolated and unused in the ordinary course other than recovery after an incident. We will keep only data subject to legal retention obligations for the periods required by law.

12. Deleting your account

You can delete your account and all your data from within the app itself: Profile → App Settings → Account → Delete account. We will ask for double confirmation because the action is immediate and irreversible.

When you delete it, we erase your login account, your profile and measurements, your image analysis together with photos of your face and body and, if you took part in an app test, the extracts and notes referred to in sections 4.2 and 4.3, your entire wardrobe with photos of your garments and their combinations, your events and trip calendar, your outfit history, the context of your conversations with ARO, your Morning Briefing settings, your consents, the content reports you submitted, your pseudonymised reactions, your subscription and your credit balance.

We retain only the billing records that tax law requires us to keep, and they are not used for any other purpose.

Important about your subscription: if you purchased it through Apple App Store or Google Play, it must be cancelled in the store, not by us. Cancel it before deleting your account — or immediately afterwards — under Settings → [your name] → Subscriptions → FashionAI on iPhone or iPad, or Google Play → Payments & subscriptions → Subscriptions → FashionAI on Android. The app expressly reminds you of this when you delete your account. If your subscription comes from an earlier purchase through our payment gateway, we cancel it when the account is deleted and, if for any reason that is not possible, we will let you know so you can resolve it.

If you cannot access the app, you have the full instructions and the alternative route at arofashionai.com/borrar-cuenta.

13. Your rights

You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and portability, and also withdraw the consent you have given, by writing to [email protected].

You may exercise erasure yourself immediately from within the app, as explained in section 12.

We will reply to your request within a maximum of one month. If you believe we have not dealt with your request correctly, you may lodge a complaint with the competent data protection authority in the state where you reside.

You can consult the national data protection authorities on the website of the European Data Protection Board.

14. Security

We apply technical and organisational measures to protect your data: encryption in transit, private storage of your images with access through temporary links, user-level access control in the database, and logging of security-relevant activity.

No system is infallible: if a security breach occurs that poses a risk to your rights, we will notify you and report it to the supervisory authority in accordance with the GDPR.

15. Cookies and similar technologies

The use of cookies and equivalent technologies, both on the website and in storage on your device within the app, is described in our Cookie Policy.

16. Minors

The app is not directed at minors. If we detect an account belonging to a minor without the required authorisation, we will delete it.

17. Changes to this policy

We may update this policy to reflect changes in the service or in the law. We will publish the current version on this page with its last updated date and will inform you within the app of any relevant changes.

Back to home