Privacy Policy
Last updated: August 21, 2026 Effective version: v1.1
This policy explains the personal data we collect, store, and process when you use Styvora (the "App"). It is compliant with the Turkish Personal Data Protection Law (KVKK) and the EU General Data Protection Regulation (GDPR).
The list below covers every data type we declare in the App Store "App Privacy" form and in the app's privacy manifest (`PrivacyInfo.xcprivacy`); the two never say different things.
1. Data we collect
1.1 Account data
- Email address (required — for sign-in and OTP verification)
- Password (irreversibly hashed with bcrypt)
- Name / display name (optional — shown on your profile and board)
- User ID (the UUID assigned to your account — the primary key across all services)
- Preferred language (default: your device language — English if your device is set to a language we do not ship; you can change it at any time from Profile > Language)
1.2 Style profile data
- Style quiz answers (10–12 multiple-choice questions)
- Body measurements (height, weight, wardrobe size — optional)
- Computed Style DNA scores (simplicity, era, practicality axes)
All three fall under "other user content" in the App Store classification. Measurements are used only for size and fit; they are not processed as health or biometric data (see §1.10).
1.3 Wardrobe and photo data
- Clothing photos you upload and virtual try-on frames
- Tags extracted from AI vision analysis (category, color, brand)
- Favorite and wear markers
1.4 Other content you create
- Your chat messages with the AI stylist
- Voice input (only while the mic is on): when you dictate a message instead of typing it, iOS turns your speech into text. Depending on your device and its language, this runs on the device or the audio is sent to Apple's speech recognition service. The recording never reaches Styvora's servers — we only receive the resulting text, and only once you send the message. Never using the mic means no voice data at all.
- Notes and names you give your outfits
- The looks you pin to your style board and your taste signals (what you like and dislike)
1.5 Coarse location (optional — only if you allow it)
We read your device's coarse location to suggest weather-appropriate outfits and to send notifications in your local time. The details matter:
- Precision: location is read on the device in low-accuracy mode (roughly 1 km). Precise location is never requested, never sent, and never stored.
- What is stored: before reaching our servers the coordinate is additionally rounded to 2 decimals (a ~1 km square) — that is the most precise value we hold. It is stored alongside city, country code, and time zone (e.g. `Europe/Istanbul`).
- Weather provider: to fetch the forecast, that same low-accuracy coordinate is queried directly against Open-Meteo — with no identifier, email, or account data attached.
- City name: so the weather card can say "Istanbul" instead of a pair of numbers, the same low-accuracy coordinate (plus a two-letter language code, `tr` or `en`) is sent from your device to BigDataCloud's reverse-geocoding service. Only the coordinate and the language code are sent — no identifier, email, or account data. The answer (city + country code) is what we store; the request itself is never logged by us.
- Both lookups leave from the device, not our servers, and neither carries anything that identifies you. If either one fails, the card simply omits the weather or the city name.
- Where: in a separate `user_push_context` table — not mixed into your profile, and deletable on its own.
- When: updated once per session while the app is open. There is no background location tracking, and no location history accumulates (the row is overwritten each time).
- If you decline: you keep getting suggestions, just without weather context; the app keeps working.
- How to remove it: turn off the location permission in iOS/Android settings; deleting your account deletes this row too (see §6).
1.6 Device and notification data
- Device type + OS (User-Agent header)
- Device / notification identifier (FCM push token — to deliver notifications to the right device)
1.7 Usage data
- Product interaction: wear logs, the like/dislike you give a suggestion, which screens you view. Used to personalize how suggestions are ranked.
- Search queries: the searches you type across your wardrobe and the catalog are executed on the server.
- Crash and performance reports (Sentry). Your user ID is attached for diagnosis; no email, photos, or location are sent.
- Anonymous performance metrics (Grafana — no user ID)
1.8 Purchase data
- Subscription status and transaction ID (via RevenueCat). We never see your card details — payment happens entirely on the App Store / Google Play side.
1.9 Support and report data
- Reports you submit in the app (which content, which reason, your description) and support correspondence you send to support@.
1.10 Data we do not collect automatically
Styvora does not collect:
- Precise location or background location history — we take no location data beyond the coarse location in §1.5
- Contacts / address book
- Advertising identifier (IDFA / GAID) — the app runs no ad measurement, and no data is used for tracking
- Your browsing history
- Data from other apps
- Health, biometric, or financial account data
2. Where we store data
- Primary database: PostgreSQL, AWS EC2 Frankfurt (eu-central-1) region
- Photos: AWS S3, eu-central-1 region (optimal for Turkish + EU residents)
- Backups: encrypted S3 backups (disaster recovery only)
- Cache: Redis on EC2 (short-lived session data)
Your database records, photos, and backups stay inside the EU. The only exception is the limited set of service providers in §4: some of them (Sentry, RevenueCat, OpenAI, Anthropic) process outside the EU and receive only the data listed there. Those transfers are covered by EU Commission Standard Contractual Clauses (SCCs) or undertakings approved by the KVKK Board.
Two key-less lookup services — Open-Meteo (weather) and BigDataCloud (city name, based outside the EU) — are called directly from your device, never from our servers. They receive a coarse coordinate and nothing else: no identifier, no email, no account data. Nothing that identifies you leaves the EU through them.
One further flow leaves your device without passing through us: voice input (§1.4). The recording is handed to iOS speech recognition, which — depending on your device and its language — may process it on Apple's servers outside the EU, under Apple's own privacy policy. We never receive that audio. Beyond these, we do not move your data outside the EU.
3. Data visible to other users
Most of the app is yours alone. The single exception is Community Boards, and it is entirely opt-in: your board stays private until you tap "Publish my board".
If you publish your board, other users can see:
- Your display name and profile photo (avatar)
- The cover images, titles, and prices of the looks you pin (these are catalog product images)
- How many looks your board holds and when it was last updated
Never visible, even when you publish:
- Your email address
- Wardrobe photos you took yourself (wardrobe pins stay private to their owner)
- Your body measurements, Style DNA scores, quiz answers
- Your location, purchase history, or stylist conversations
Withdrawing: you can switch publishing off in Settings. Your board drops out of the community feed within 30 seconds at most, and a direct board link becomes unreachable immediately. You can also remove individual pinned looks at any time.
You can also block any user (blocking is mutual), and every board and look carries a Report option. The detailed rules live in the Community Guidelines document.
4. Third-party sharing
Styvora does not share your personal data with anyone for advertising, sale, or marketing.
Our limited service providers (all KVKK / GDPR compliant):
- OpenAI / Anthropic (US) — vision analysis and LLM inference (photos sent temporarily; OpenAI deletes within 30 days, Anthropic does not retain per-request)
- AWS (EU — Frankfurt) — server infrastructure provider
- AWS SES (EU) — OTP and notification emails
- Firebase Cloud Messaging (Google) — push notification delivery (device token)
- Open-Meteo (EU) — weather forecast, and turning a destination city name into coordinates for the trip planner (only the low-accuracy coordinate or the city name you typed is sent; no identifier or account data)
- BigDataCloud (Australia) — reverse geocoding: turns the low-accuracy coordinate into a city name for the weather card (only the coordinate + a `tr`/`en` language code is sent; no identifier or account data)
- Apple (US / EU) — speech recognition, only when you use voice input: iOS converts the recording into text either on the device or on Apple's servers, depending on device and language. We never receive the audio; we see only the text you choose to send (see §1.4)
- fal.ai / FASHN (US) — virtual try-on renders: in "Me" mode your uploaded full-body photo and the garment image are sent for rendering. Used only for that purpose; the result is served from our storage via a 24h signed link and is deleted when you delete your account
- Google Cloud Vision (US) — garment photo analysis (label and object detection; the photo is sent per request and is not used for training)
- Bright Data (US) — used as an intermediary to turn your photo into Google Lens results in "Find the exact item"
- Sentry (US) — crash and performance reporting (user ID attached; no content data sent)
- RevenueCat (US) — premium subscription management (user ID + transaction ID)
5. Your rights (KVKK Article 11)
At any time you can:
- Learn which of your data we store (data export)
- Request correction of incorrect data (rectification)
- Request deletion of data (right to be forgotten)
- Object to data processing
You can delete your account instantly from inside the app: Profile > Account > Delete my account. Deletion happens the moment you confirm; you do not have to email us and wait.
All other requests (data export, correction, objection) can be made via support@spaceailabs.ai. A response is guaranteed within 30 days.
6. Retention period
- Active account: As long as the account is active
- Dormant account (no sign-in for 12 months): Automatic anonymization + optional deletion notice
- In-app deletion (Profile > Account > Delete my account): Your account and data are deleted immediately and irreversibly — there is no waiting period and no restore path. Photos are erased from storage; your stored location row, board, pins, and block list are removed as well.
- After an emailed deletion request: Full deletion within 30 days (some logs such as IP addresses may be kept for 6 more months under legal obligation)
- Backups: encrypted database backups are taken nightly and 7 rotations are kept — roughly 7 days. Older backups are expired automatically, so data you delete disappears from backups too within about a week.
7. Children's privacy
Styvora does not provide services to users under the age of 13. If we discover we have accidentally collected data from a child, we delete it immediately.
8. Cookies / tracking
The mobile app does not use browser cookies and uses no data for tracking — your data is never matched with other companies' data and never sold to advertisers. Only local SharedPreferences (stays on device — never sent to the server):
- Onboarding completion flag
- Quiz answers (for editing answers)
- Language preference
- Premium subscription status (RevenueCat cache)
9. Security
- All connections encrypted over TLS 1.2+
- Passwords hashed with bcrypt cost=12
- JWT tokens short-lived (access 15 min, refresh 30 days)
- Server access via IAM-roled SSH only
- Daily encrypted backups via pgBackRest
10. Breach notification
Under KVKK Article 12, in the event of a security breach we notify the KVKK Authority and affected users within 72 hours.
11. Contact
For privacy questions and KVKK requests:
Email: support@spaceailabs.ai Data Controller: SPACE AI LABS YAZILIM HİZMETLERİ LİMİTED ŞİRKETİ ("SPACE AI LABS"; app brand "Styvora")
This document is prepared to cover the minimum content required for Apple App Store and Google Play Store review processes.