Privacy Policy
Last updated: April 2026
1. Data Controller
AuraVibe is a service operated by a Polish sole proprietorship (Jednoosobowa Działalność Gospodarcza). For the purposes of the EU General Data Protection Regulation (GDPR) and other applicable data protection laws, the data controller is:
Łukasz Dąbkowski - ML solutions (sole proprietorship, owner: Łukasz Dąbkowski)<br/>ul. Czterech Wiatrów 73<br/>02-860 Warszawa, Poland<br/>NIP: 7931575367<br/>REGON: 369542726<br/>Email: privacy@auravibe.dev
If you have any questions or concerns about how your personal data is handled, please contact us at the email address above.
2. Data We Collect
Account Data
When you create an account, we collect the following information:
- Email address — required for account creation and communication
- Display name — provided by you or imported from your Google account if you sign in with Google
- Google account information — if you use Google Sign-In, we receive your name, email, and profile photo URL from Google OAuth
- Gender identity — optionally provided during onboarding (you may select "Prefer not to say")
- Language preference — selected during onboarding to display results in your preferred language
Photos
AuraVibe uses photos to perform AI-powered analyses. The following types of photos may be collected:
- Facial photographs — used for color analysis (skin undertone, eye color, hair color determination)
- Full-body photographs — used for body shape analysis (together with your height measurement)
- Clothing/accessory photographs — used for the Style Matcher feature to assess compatibility with your color profile
Photos are sent to external AI service providers, currently including Google LLC, for analysis and are not retained after processing is complete.
Photo backup (optional, off by default): Photo backup is turned off unless you choose to enable it. If you opt in, photos you upload for analysis are backed up to your private, user-specific storage area in Firebase Storage so you can review past analyses alongside the original photo and access your history across devices. When backup is enabled, backed-up photos are:
- Stored in a user-specific path protected by Firebase Security Rules — only you can access them
- Retained until you explicitly delete them or delete your account
- Not used for AI model training, advertising, or shared with third parties
Photos that are not backed up are deleted immediately after AI processing is complete.
Text You Provide
When you use the Style Q&A feature, we collect the free-text question you type. Please include only styling-related information and avoid entering sensitive personal data — for example health, financial, or precise-location details — because your question is sent to our external AI service provider (currently Google LLC) to generate an answer and is stored in your private account until you delete it or delete your account.
Analysis Results (Stored in Cloud by Default)
After processing your photos, we store the AI-generated analysis results in our cloud infrastructure (Google Cloud Firestore) by default. Cloud storage is required to provide core Service features including analysis history, cross-device sync, and subscription management. Stored results may include:
- Color season classification, skin undertone, eye color, hair color, recommended color palettes, and styling advice
- Body shape classification, body proportions, frame size, and fit recommendations
- Clothing compatibility scores, color and fit assessments, and styling recommendations
Subscription Data (Web App Only)
If you subscribe to a paid plan through the AuraVibe website, payment processing is handled entirely by Stripe. AuraVibe stores only:
- Your Stripe Customer ID (an opaque identifier)
- Your subscription plan tier (e.g., Essentials, Selection, Designer, Runway)
AuraVibe never receives, processes, or stores your payment card details, billing address, or other financial information. The mobile app does not collect any payment data.
Usage Data
We automatically collect limited usage data to enforce subscription quotas and maintain service quality:
- Monthly feature usage counts (e.g., number of style matches used)
- Account creation and last sync timestamps
- Firebase user ID for account identification
Data We Do Not Collect
AuraVibe does not collect device location, contacts, browsing history, device identifiers (IMEI, MAC address), audio data, advertising identifiers, or data from other apps.
3. How We Use Your Data
We use your personal data for the following purposes:
- Providing the service — to perform color analysis, body shape analysis, and style matching based on photos you submit; to store your analysis results and preferences in the cloud; to back up your photos; and to sync data across your devices
- Managing subscriptions — to determine your subscription tier, enforce usage quotas, and communicate subscription-related changes
- Improving the service — to understand aggregate usage patterns (anonymized) and improve features, reliability, and performance. We do not use your photos or analysis results for training AI models.
- Security and abuse prevention — to enforce rate limits, authenticate API requests, and protect against unauthorized access
Legal Bases (GDPR)
| Purpose | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Color analysis and body shape analysis (photo processing) | Explicit consent (Art. 9(2)(a)) — special category data |
| Style matching | Consent (Art. 6(1)(a)) |
| Cloud storage of analysis results and preferences | Contract performance (Art. 6(1)(b)) — necessary to provide the Service |
| Photo backup | Contract performance (Art. 6(1)(b)) — default Service feature; photos may contain special category data processed under explicit consent (Art. 9(2)(a)) |
| Subscription management | Contract performance (Art. 6(1)(b)) |
| Rate limiting and security | Legitimate interest (Art. 6(1)(f)) |
| Service improvement (aggregated, anonymized) | Legitimate interest (Art. 6(1)(f)) |
4. Special Category Data
AuraVibe processes photographs that may contain biometric-adjacent data, including information about your skin tone, eye color, hair color, and body proportions. Under the GDPR, this data may qualify as special category data (Article 9).
We want to be transparent about how this data is handled:
- Processing basis: All photo-based analysis is performed only with your explicit consent (GDPR Article 9(2)(a)). By accepting these Terms during registration and then affirmatively choosing to submit a photo for analysis, you provide consent for each analysis session. You are never required to submit a photo, and you may withdraw consent by discontinuing use of the photo-based features.
- No identification: Your photos are not used to identify you or any other individual. The AI analyzes physical characteristics solely for the purpose of providing personalized styling recommendations.
- Storage: Photos are processed in real time by our external AI service providers and are not retained by the AI service. On the mobile app, photos are backed up to your private cloud storage by default for your convenience. On the web app, photos are not stored and exist only during the analysis request. You may delete backed-up photos at any time, or delete your account to remove all stored data.
- No AI training: Your photos and analysis results are not used to train or improve AI models.
- Withdraw consent: You may withdraw your consent at any time by discontinuing use of the photo-based features. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
Gender identity, if provided, is also considered special category data. Providing this information is optional, and you may select "Prefer not to say" at any time.
Given that AuraVibe processes biometric-adjacent data (facial features, body proportions), we have conducted a Data Protection Impact Assessment (DPIA) in accordance with GDPR Article 35 to evaluate the risks associated with this processing. Our technical and organizational safeguards — including transient-only photo processing, user-specific access controls, explicit per-analysis consent, and the prohibition on AI model training with user data — adequately mitigate the identified risks. A summary of this DPIA is available upon request by contacting privacy@auravibe.dev.
5. Data Sharing
We share your personal data only with the following third parties, and only to the extent necessary to provide the service:
Google LLC
- Firebase Authentication: Processes your email, password (hashed), and Google OAuth tokens for user authentication.
- Cloud Firestore: Stores your user profile, analysis results, and preferences by default as part of core Service functionality.
- Firebase Storage: Stores your backed-up photos by default in a user-specific, access-controlled path.
- AI Analysis Services (currently Google LLC): Receives photos (base64-encoded) along with gender and height data to perform automated image analysis. For the Style Q&A feature, it also receives the free-text styling question you type — together with your color and body profile and, when relevant, item names and match details from your Style Matcher history — to generate a written answer; this text is processed transiently and is not used to train AI models. Data is processed transiently and is not retained after the API response is returned. Our AI service providers are contractually prohibited from using your data to train their models. For a current list of sub-processors, see our Sub-Processor List.
- Google ML Kit (on-device): Face detection and pose detection run entirely on your device. No data is sent to Google for ML Kit processing.
Stripe, Inc. (Web App Only)
- Stripe processes your payment card details and billing address when you purchase a subscription on auravibe.dev. Stripe acts as an independent data controller for payment data.
- AuraVibe never receives or stores your payment card details.
- The mobile app does not interact with Stripe or collect any payment data.
Google Cloud Platform
- Our backend infrastructure (Cloud Functions) runs on Google Cloud Platform. All data processing occurs within Google's secure infrastructure.
We do not sell, rent, or trade your personal data to any third party. We do not share your data with advertisers, data brokers, or any entity not listed above.
6. International Transfers
AuraVibe's backend infrastructure is deployed in the European Union (europe-west1 region). However, some data processing involves international transfers:
- Firebase Authentication: User authentication data is processed in the United States by Google.
- Stripe: Payment processing may involve data transfers to the United States.
- AI Service: Photo analysis requests may be processed in global infrastructure.
Where data is transferred outside the European Economic Area (EEA), we rely on the following safeguards:
- EU-US Data Privacy Framework (for certified recipients)
- Standard Contractual Clauses (SCCs) as a fallback
- Google Cloud Data Processing Addendum and Stripe Data Processing Agreement
7. Data Retention
We retain your data according to the following schedule:
| Data Type | Retention Period |
|---|---|
| Account data (Firebase Auth) | Until you delete your account |
| Analysis results (local cache) | Until you delete them or sign out |
| Analysis results (cloud — stored by default) | Until you delete them individually or delete your account |
| Photos (backed up by default) | Backed-up photos: until you delete them individually or delete your account. Non-backed-up photos: deleted immediately after analysis. |
| Subscription data | Until you delete your account |
| Usage counters | Reset monthly; historical data expired after 13 months |
| AI processing data | Not retained beyond the request, except a single reference photo where you have separately consented (see the Reference photo row). |
Biometric Data Retention and Destruction Policy
This section is AuraVibe's written policy under the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)). It explains, for any biometric or biometric-adjacent data that may be involved in our facial and body photo analysis, how long such data is retained and the schedule and method for its permanent destruction. This policy is provided in addition to the Special Category Data and Data Retention sections above.
Scope
AuraVibe analyzes photographs you provide to generate color, body shape, and style recommendations. On-device face detection (Google ML Kit) locates facial geometry to frame the photo; the photo is then sent to our AI provider for visual analysis. We do not use this processing to identify, recognize, or verify the identity of any individual.
Retention Schedule
Biometric and biometric-adjacent data is retained only as long as necessary to provide the analysis you request, and no longer than the schedule below.
Destruction Schedule
Such data will be permanently destroyed when the earliest of the following occurs:
- You delete the specific analysis or photo from your history.
- You delete your account (Settings → Delete Account).
- Three (3) years after your last interaction with the Service.
Destruction Method
Cloud data (Firestore documents and any backed-up Firebase Storage photos) is permanently deleted via the Firebase Admin API. Photos not backed up are deleted immediately after AI processing completes. Local data on your device is cleared on sign-out. Deletions are permanent and irreversible.
No Sale or Disclosure
We do not sell, lease, trade, or otherwise profit from biometric or biometric-adjacent data, and we do not disclose it except as required to provide the Service (for example, to our AI processing provider) or as required by law.
Questions about this policy can be sent to privacy@auravibe.dev.
8. Your Rights
EU/EEA Users (GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under the GDPR:
- Right of access (Art. 15) — request a copy of all personal data we hold about you
- Right to rectification (Art. 16) — request correction of inaccurate personal data
- Right to erasure (Art. 17) — request deletion of all your personal data ("right to be forgotten")
- Right to restrict processing (Art. 18) — request that we limit how your data is used
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable JSON format, including your profile, analysis results, and preferences
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing
- Right to lodge a complaint — with a supervisory authority in your EU/EEA member state
California Users (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know — what personal information is collected, used, shared, or sold
- Right to delete — request deletion of your personal information
- Right to opt-out of sale/sharing — AuraVibe does not sell or share your personal information for cross-context behavioral advertising
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights
- Right to correct — request correction of inaccurate personal information
- Right to limit use of sensitive data — limit how we use your sensitive personal information
All Users
Regardless of your location, you can exercise the following controls directly within the app:
- Delete individual analyses from your history screens
- Delete individual backed-up photos from your history screens
- Delete your account entirely (which permanently deletes all cloud-stored data, including analysis results, preferences, and backed-up photos, within 30 days)
Cloud sync and photo backup are optional and turned off until you opt in. You can enable or disable cloud sync and photo backup at any time in Settings, and you can delete individual analyses, photos, or your entire account. Declining cloud features does not prevent you from using the Service.
9. How to Exercise Your Rights
You can exercise your rights in the following ways:
- In the app: Go to Settings > Delete Account to delete all your data, or use the history screens to delete individual analyses and photos
- By email: Send a request to privacy@auravibe.dev for data access, portability, rectification, or deletion requests
We will respond to your request within 30 days (for GDPR requests) or 45 days (for CCPA/CPRA requests). If we need additional time, we may extend the response period by up to 45 additional days (90 days total for CCPA requests), in which case we will notify you of the extension and the reason within the initial response period.
We may need to verify your identity before processing your request. If you have an AuraVibe account, we will verify your identity by requiring you to re-authenticate with your account credentials. If you no longer have an account, we may ask you to provide information that matches our records (such as the email address previously associated with your account) to verify your identity.
You may designate an authorized agent to submit a request on your behalf. We may require the authorized agent to provide signed written authorization from you, and we may require you to verify your identity directly with us or confirm that you authorized the agent to act on your behalf.
10. Data Security
We take the security of your personal data seriously and implement the following measures:
- All data is transmitted over HTTPS/TLS encryption
- Passwords are hashed by Firebase Authentication using industry-standard algorithms
- All API calls are authenticated with Firebase JWT tokens (1-hour expiration)
- Photos sent for AI analysis exist only transiently during processing and are not retained by Google
- Backed-up photos are stored in user-specific paths protected by Firebase Security Rules — only you can access your photos
- Backend API keys are stored in Google Cloud Secret Manager and are never embedded in the app
- Cloud data is encrypted at rest using Google Cloud's default encryption
- Local data on your device is stored in the app's private directory, protected by your device's operating system security
11. Children's Privacy
AuraVibe is not intended for use by children under the age of 16 in the European Union or under the age of 13 in the United States. We do not knowingly collect personal data from children under these age thresholds.
If we become aware that we have inadvertently collected personal data from a child under the applicable age limit, we will take steps to delete that information as promptly as possible.
If you are a parent or guardian and believe your child has provided personal data to AuraVibe, please contact us at privacy@auravibe.dev so we can take appropriate action.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Sending a notification to the email on your account
- Displaying a notice within the app
- Updating the "Last updated" date at the top of this page
We encourage you to review this policy periodically. For users in the EU/EEA, material changes to how we process special category data may require us to obtain your consent again.
13. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@auravibe.dev
- Postal address: Łukasz Dąbkowski - ML solutions, ul. Czterech Wiatrów 73, 02-860 Warszawa, Poland
- NIP: 7931575367 · REGON: 369542726
We aim to respond to all inquiries within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with a data protection supervisory authority in your jurisdiction.
As a personal project that does not engage in large-scale systematic monitoring or large-scale processing of special category data, AuraVibe has not appointed a Data Protection Officer under GDPR Article 37. For all privacy-related inquiries, the designated contact is privacy@auravibe.dev.
14. California Residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information, in addition to the rights described in Section 8.
You have the right to know what personal data is collected about you, the right to request deletion of your personal data, and the right to opt out of the sale of your personal information. AuraVibe does not sell your personal information to third parties and does not share it for cross-context behavioral advertising.
These rights are substantively covered by the existing GDPR provisions throughout this Privacy Policy, particularly in Section 2 (Data We Collect), Section 7 (Data Retention), and Section 8 (Your Rights). California residents may exercise any of these rights by contacting us at privacy@auravibe.dev.
We will not discriminate against you for exercising your CCPA rights. You will not receive different pricing, a different quality of service, or be denied access to the Service for exercising your privacy rights.
California residents may also request information under the California "Shine the Light" law (Civil Code Section 1798.83) about whether personal information has been disclosed to third parties for their direct marketing purposes. AuraVibe has not disclosed personal information to third parties for direct marketing purposes.
Under CPRA, photographs containing facial features and derived analysis data (skin tone, eye color, hair color, body proportions) may constitute "sensitive personal information" per Section 1798.140(ae). AuraVibe uses this data solely for providing styling analysis and does not use or disclose it for purposes beyond what is necessary to provide the Service.
AuraVibe does not offer financial incentives (such as discounts, payments, or different price levels) in exchange for the collection, retention, or sale of personal information. Subscription pricing reflects feature access, not the value of your personal data.
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other US states with comprehensive privacy laws have similar rights to those described above. We extend the rights in this section to all US residents regardless of state. To exercise your rights, contact privacy@auravibe.dev.
Categories of Personal Information Collected (per CCPA §1798.140(o))
| CCPA Category | Data We Collect |
|---|---|
| (A) Identifiers | Email address, display name, Firebase user ID |
| (B) Personal info per Cal. Civ. Code §1798.80 | Name, email address |
| (D) Commercial information | Subscription status, purchase history |
| (H) Visual information | Photos uploaded for analysis (processed transiently, not stored as biometric templates) |
| (F) Internet/network activity | Feature usage counters, app interaction data |
| (K) Inferences | Color analysis results, body shape analysis results, style recommendations |
Photos are analyzed for visual characteristics (skin tone, eye color, body proportions) to generate styling recommendations, and are not used for identity verification or to match or recognize individuals. Where biometric or biometric-adjacent data is involved, our handling, retention, and destruction practices are described in our Biometric Data Policy below.
16. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, AuraVibe will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users without undue delay via email and/or in-app notification, in accordance with GDPR Article 34. The notification will include the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
17. Automated Decision-Making and Profiling
AuraVibe uses artificial intelligence to analyze your photographs and provide color analysis, body shape analysis, and style matching results. This constitutes automated processing of your personal data.
These AI-generated results are recommendations for personal entertainment and general guidance only. No legally binding or similarly significant decisions are made solely by automated means based on this processing. Specifically:
- Results do not affect your access to services, pricing, or any contractual rights.
- The AI analyzes visual features (skin tone, eye color, hair color, body proportions) to classify seasonal color type and body shape category.
- You are free to disregard any recommendation. Results may vary based on photo quality and lighting conditions.
Under GDPR Article 22, you have the right to request human review of any AI-generated result. To request a review, contact privacy@auravibe.dev.
18. Policy Version History
We maintain an archive of previous versions of this document for transparency.
- Version 1.0 — April 2026 — Initial version
Previous versions are available upon request by emailing privacy@auravibe.dev.