Skip to content

Privacy Policy

Last updated: 6 October 2026

This policy explains what data Objektiv (“we”, “us”) collects when you use objektiv.ai, why we collect it, how we process and store it, and the controls you have over it. We have written it in plain language because informed consent only works if people can actually read the terms. Where the law uses specific words (controller, processor, lawful basis), we use them too, but the substance is what matters.

1. What data we collect

We collect only what we need to operate the product and provide your analyses. Specifically:

  • Account information. When you sign up, our authentication provider (Clerk) collects your email address and a hashed password (or an OAuth token if you sign in with Google or Apple). We receive a stable user identifier and your email; we do not see or store your password.
  • Profile information. Optional fields you provide to improve analysis quality: self-declared gender, age, ethnicity, and free-text health notes used to contextualise skin readings. You can leave any of these blank, and edit or delete them at any time from Settings.
  • Photos uploaded for analysis. Face, body, outfit, hair, and skin photos you submit so the AI can read them. Each photo is bound to the analysis it produced. Unless you untick “Keep my photos” before you start an analysis, its photos stay in your private storage until you delete the analysis or your account, so try-on, photo edits and progress tracking can use them.
  • Closet item photos. Pictures of garments you upload to your wardrobe. They stay while your account is active, because the closet needs them, until you delete the item or your account.
  • Generated analysis results. The structured JSON output of each analysis (scores, focus areas, recommendations) plus any saved outfits or roadmap items derived from it.
  • Chat messages. Messages you exchange with the in-app consultant chat. We store them so you can see your own history and so the model has conversational context across turns.
  • Payment information. Subscription and billing are handled entirely by Stripe. We never see, transmit, or store full card numbers, CVCs, or bank details. We receive a customer identifier, the last four digits of the active card, the brand, and the subscription status.
  • Usage events. Pageviews, feature interactions, and performance metrics so we can fix bugs and prioritise what to build. Before you sign in they are tied to a per-browser identifier; once you sign in they are linked to your account id, never to your name, email or photos.

2. How your photos are processed

Photos are the most sensitive thing you give us, so the data flow is worth describing in detail.

2.1 Transit to AI providers

When you submit an analysis, the photo is sent over an encrypted (HTTPS) connection to two AI providers in the United States: Google (Gemini API) for image analysis and image generation, and Anthropic (Claude API) for the chat features, the Deep Analysis and written texts such as bios. Both run under paid API terms that exclude your photos and prompts from being used to train their models. We pay these providers per call; we do not exchange data for service.

2.2 Storage at rest

Closet photos and analysis photos are stored encrypted at rest in our private Supabase storage bucket. The bucket is not publicly readable. Files are served to the app through short-lived, signed URLs that expire within minutes. The download links in a data export you request yourself work for 7 days. Encryption keys are managed by Supabase under their standard server-side encryption.

The free tries you can run without an account (the face analysis trial, the celebrity lookalike and the pet reader) save neither your photo nor the result. To limit them per day we keep counters keyed to one-way hashes of your IP address, alone and together with your browser type. The counters hold no photo and no name and are deleted after three days.

2.3 What we never do

We never sell your photos. We never share them with advertisers or data brokers. We never use them to train any model, our own or anyone else's. We never publish them. Other users see a photo only when you submit it yourself for community feedback or to the Subjektiv rating game, and only inside that feature. Otherwise the only people who can see a photo you uploaded are you (when logged in) and the operator of Objektiv, only for narrowly scoped debugging.

2.4 Using Objektiv in ChatGPT

When you ask for an analysis in ChatGPT, our server downloads the photo you attached from OpenAI's temporary file link, sends it to Google (Gemini API) for a short check that it shows one adult with a visible face, and then for the analysis. A Deep Analysis goes to Anthropic (Claude API) instead. We do not store photos sent from ChatGPT.

Without connecting an Objektiv account, nothing is saved to an account. To limit free analyses per day we keep a counter keyed to a one-way hash of the anonymous ChatGPT user identifier or of the IP address. The counters hold no photo and no name and are deleted after three days.

When you connect your Objektiv account, analyses you start in ChatGPT are saved to your history and marked as coming from ChatGPT. ChatGPT then receives the results you ask for: analysis reports, your colour palette and, on request, the list of your closet items with image links that expire after 15 minutes. Health notes, declared conditions and ethnicity from your profile are not used for analyses started in ChatGPT. Whatever ChatGPT receives is processed by OpenAI under its own privacy policy. You can disconnect Objektiv in ChatGPT's settings at any time.

2.5 Face lines on your results

When you open the face lines on a results page, the face points are found by Google's MediaPipe library running in your browser. The photo is not uploaded again for this step and the measured points are not stored. MediaPipe sends Google anonymous usage statistics, see section 5.

3. Lawful basis for processing

Under the GDPR and equivalent regimes, we rely on the following lawful bases:

  • Contract. To provide the analyses, closet, and chat features you have signed up for, we must process the data you submit to them.
  • Consent. Optional profile fields (ethnicity, health notes) are processed only with your explicit consent, given at the time you fill them in. You can withdraw consent by clearing the field.
  • Legitimate interests. Usage analytics, fraud prevention, and basic security logging rely on our legitimate interest in operating a reliable, abuse-resistant service.
  • Legal obligation. We retain billing records for the period required by tax and accounting law in the jurisdiction where Objektiv is incorporated.

4. Data retention and deletion

Profile data, analysis results, photos, closet items, and chat messages are kept for as long as your account exists, or until you delete them, whichever comes first. From Settings you can:

  • Export everything. A single click produces a JSON file with your profile, every analysis, every chat transcript, your closet and outfits, and a private download link for each stored photo. The links work for 7 days; export again for fresh ones. This is your right to data portability under GDPR Article 20.
  • Delete an item. Individual analyses, closet items, outfits, or chat threads can be removed one at a time. Deletion removes both the database row and the underlying file in our storage bucket within seconds.
  • Delete your account. Account deletion is irreversible and cascades. All profile rows, analysis rows, closet rows, outfit rows, chat rows, and the corresponding files in storage are removed within seconds. Stripe subscription and billing history is retained only for the legally-required period (typically 7 years for tax records) and then purged.

Backups are rotated on a 30-day schedule. If you delete your account, any residual copy in a backup snapshot will be overwritten within 30 days as the snapshot expires; we do not restore individual users from backups for any reason.

5. Third-party services

We rely on a small number of established providers to run the service. Each one is bound by a Data Processing Agreement and processes data only on our instructions.

  • Clerk. Authentication and session management. Receives your email and password hash. clerk.com/privacy
  • Stripe. Payment processing. Receives card details directly from your browser through their hosted checkout. They never pass through our servers. stripe.com/privacy
  • Supabase. Postgres database and encrypted object storage. Hosts profile rows, analysis rows, and photo files. supabase.com/privacy
  • Google (Gemini API) and Anthropic (Claude API). Google produces the analyses and generated images, Anthropic the chat replies, the Deep Analysis and written texts, per request. Data is in transit only, and both paid API terms exclude our traffic from model training.
  • Google (MediaPipe). Only when you open the face lines on a results page. The face points are found in your browser, so your photo stays on your device for this step. The MediaPipe library then sends Google anonymous usage statistics (which task ran, how long it took, how many calls failed and your device type) together with your IP address, as any web request does. It sends no image and no account data.
  • OpenAI (ChatGPT). Only if you use Objektiv inside ChatGPT. ChatGPT sends us the photos you attach there and receives the results you ask for, as described in section 2.4. openai.com/policies/privacy-policy
  • Sentry. Error reports from our servers, with email addresses, sign-in ids and payment ids removed before sending.
  • Resend. Sends the weekly progress email if you turn it on, and receives your email address, display name and that week's progress summary for it.
  • Vercel. Hosting and edge networking. Server logs are kept for a limited time for debugging and can include your account id and error details.
  • PostHog and Vercel Speed Insights. Pageview, product and speed analytics. We do not send email addresses or photo content to analytics. Events are linked to a per-browser identifier, and to your account id once you sign in.

6. Cookies and similar technologies

We use the minimum cookies required to keep you signed in and the product working:

  • Clerk session cookies. Strictly necessary. Without them you cannot stay logged in across pages.
  • Theme and UI preferences. Local-storage entries that remember dark mode and similar choices. Not transmitted to our servers.
  • Analytics identifier. A per-browser ID set by our analytics provider so we can count unique visitors. Once you sign in, it is linked to your account id.

We do not use marketing cookies, advertising trackers, third-party retargeting pixels, or cross-site tracking of any kind.

7. Your rights

Under the GDPR, the UK GDPR, the California Consumer Privacy Act, and most modern privacy regimes, you have the following rights with respect to your personal data:

  • Access. See what we hold on you. The export tool in Settings provides a complete machine-readable copy.
  • Rectification. Correct inaccurate profile data directly from Settings, or email us if a field is locked.
  • Erasure. Delete your account or specific items at any time from Settings.
  • Portability. Export your data as a portable JSON file with download links for your photos.
  • Restriction and objection. Stop us from processing your data for any non-essential purpose. Email us to invoke this right.
  • Withdraw consent. Where processing is based on consent (such as the optional health notes field), withdraw it at any time. Withdrawal does not affect processing that happened before withdrawal.
  • Lodge a complaint. You can contact your local data protection authority if you believe we are not complying with the law. We would prefer you contact us first so we can fix the issue.

To exercise any right, use the controls in Settings or email privacy@objektiv.ai. We respond within 30 days.

8. International transfers

Our infrastructure providers operate globally. Data may be transferred to and processed in jurisdictions outside the one in which you live, including the United States. Where transfers leave the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) as the transfer mechanism. We do not transfer your data to any country that does not provide at least equivalent protections.

9. Children

Objektiv is not intended for users under the age of 16. We do not knowingly collect personal information from minors. Do not upload photographs of children under 16, including your own, without verifiable parental consent. If we discover that we hold data on a minor without such consent, we will delete it promptly. If you are a parent or guardian and believe a minor has signed up, contact privacy@objektiv.ai.

10. Security

We protect your data through encryption in transit (TLS 1.2+ on every connection), encryption at rest for all photos and database fields containing identifiers, least-privilege access controls on production systems, audit logging of administrative access, and regular dependency and penetration scanning. No system is perfectly secure; if a breach occurs that affects you, we will notify you and the relevant authorities within the statutory window (72 hours under the GDPR).

11. Changes to this policy

We may update this policy as the product evolves. If we make material changes (such as adding a new category of data we collect, a new third-party processor, or a new purpose for processing), we will notify registered users by email at least 14 days before the change takes effect. Non-material clarifications (typos, reordering, clarifying language) take effect when posted. The “Last updated” date at the top of this page always reflects the most recent change.

12. Contact

The data controller for objektiv.ai is the entity operating Objektiv. For privacy questions, data subject requests, or to report a security concern, email privacy@objektiv.ai. For general support, use the in-app help bubble in the bottom-right of any page.

See also our Terms of Service and FAQ.