Privacy Policy

Last updated: February 15, 2026

1. Introduction

Personal Lookbook 4Cut ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our AI-powered fashion lookbook service. This policy complies with GDPR (EU/EEA/UK), CCPA (California), and PIPA (Republic of Korea). Data Controller: Personal Lookbook 4Cut, contact: info.plookbook4cut@gmail.com

2. What Data We Process

Photos (including facial biometric data)

We collect photos you upload for AI fashion photo generation. Legal Basis: Consent (GDPR Art. 6(1)(a), Art. 9(2)(a) for biometric data). Retention: Deleted immediately after processing. Photos are processed in memory only and never written to disk.

Payment Information

Payment processing is handled by Polar.sh (our Merchant of Record). We do not store your credit card information. Legal Basis: Contract performance (GDPR Art. 6(1)(b)). Polar processes payment data according to their privacy policy.

Locale Preference

We store your language preference and cookie consent choice in browser localStorage. Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)). These are user-controlled and strictly necessary for service functionality (ePrivacy Directive Art. 5(3)).

Access Tokens

We generate temporary access tokens for service authentication. Legal Basis: Contract performance (GDPR Art. 6(1)(b)). Retention: 7 days (auto-expire). Tokens allow up to 3 generation attempts in case of failures.

3. How We Use Your Data

  • AI Processing: Photos are analyzed by Google Gemini AI (generative AI model) to generate personalized fashion lookbook images. This is a limited-risk AI system for synthetic content generation.
  • Service Delivery: To provide you with your AI-generated lookbook results
  • Payment Processing: To process payments via Polar.sh, our Merchant of Record, which handles tax collection and payment compliance
  • Analytics (consent-based): With your consent, anonymized analytics data is collected via GA4 and Microsoft Clarity to understand usage patterns and improve the service. No data is used for advertising or marketing purposes

4. Data Retention and Deletion

Important: No Image Storage

Your uploaded photos are processed in real-time and immediately deleted after your lookbook is generated. We do not store your original photos on our servers. Photos are processed in memory only and never written to disk.

Generated Lookbooks

Generated lookbook images are sent directly to your browser and are NOT stored on our servers. Please download your results immediately as they cannot be retrieved later.

Payment Records

Payment transaction records are retained by Polar.sh for accounting and legal compliance purposes, as required by law.

5. Data Sharing and Third Parties

We share your data with the following third parties:

Google LLC (Gemini AI)

Your photos are processed by Google Gemini AI for color analysis and lookbook generation. Location: United States. Safeguards: EU-US Data Privacy Framework certified, Standard Contractual Clauses (SCCs), TLS encryption. Retention: Immediate deletion after processing. Google's privacy policy applies to this processing.

Polar.sh (Merchant of Record)

Polar.sh handles payment processing, tax collection, and payment compliance. Polar's privacy policy governs how they handle your payment information. We do NOT sell or share your personal information for advertising or marketing purposes.

We carefully select third-party providers that maintain high standards of data protection and privacy.

6. Data Security

We implement industry-standard security measures to protect your data:

  • TLS encryption for all data in transit
  • Memory-only photo processing (never written to disk)
  • Immediate deletion of photos after generation
  • No permanent storage of user photos
  • Secure access controls for payment data (handled by Polar.sh)

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Your Rights (GDPR, CCPA, PIPA)

Depending on your jurisdiction, you have the following rights:

  • GDPR (EU/EEA/UK): Right of access, erasure ("right to be forgotten"), data portability, withdraw consent, lodge complaint with your national Data Protection Authority
  • CCPA (California): Right to know what personal information is collected, delete personal information, opt-out of sale/sharing (we do NOT sell or share), non-discrimination for exercising rights
  • PIPA (Korea): Right to access (열람권), correction and deletion (정정·삭제권), request suspension of processing (처리정지 요구권)
  • Sensitive Data (CCPA): We process biometric identifiers (facial features) solely for service delivery and delete immediately after use

To exercise these rights, email info.plookbook4cut@gmail.com. We will respond within 30 days. Note: Since photos are not stored after processing, most data access requests will result in "no data found". You can also withdraw analytics consent at any time by clicking "Cookie Settings" in the footer.

8. Children's Privacy

Our Service is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe we have collected data from a minor, contact us immediately at info.plookbook4cut@gmail.com.

9. International Data Transfers

Your uploaded photos are transferred to Google LLC servers in the United States for AI processing. These transfers are protected by: EU-US Data Privacy Framework certification, Standard Contractual Clauses (SCCs) where applicable, encryption in transit (TLS 1.3), and immediate deletion after processing. For questions about international transfers, contact: info.plookbook4cut@gmail.com

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted with 30 days' advance notice. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

11. Contact Us & Supervisory Authorities

For privacy-related questions, data subject requests, or concerns, contact us at info.plookbook4cut@gmail.com. You have the right to lodge a complaint with the relevant supervisory authority: EU/EEA/UK - your national Data Protection Authority; California - California Privacy Protection Agency (cppa.ca.gov); Korea - Personal Information Protection Commission (pipc.go.kr).