Last updated: 6 October 2026
This policy explains what data Objektiv (“we”, “us”) collects when you use objektiv.ai, why we collect it, how we process and store it, and the controls you have over it. We have written it in plain language because informed consent only works if people can actually read the terms. Where the law uses specific words (controller, processor, lawful basis), we use them too, but the substance is what matters.
We collect only what we need to operate the product and provide your analyses. Specifically:
Photos are the most sensitive thing you give us, so the data flow is worth describing in detail.
When you submit an analysis, the photo is sent over an encrypted (HTTPS) connection to two AI providers in the United States: Google (Gemini API) for image analysis and image generation, and Anthropic (Claude API) for the chat features, the Deep Analysis and written texts such as bios. Both run under paid API terms that exclude your photos and prompts from being used to train their models. We pay these providers per call; we do not exchange data for service.
Closet photos and analysis photos are stored encrypted at rest in our private Supabase storage bucket. The bucket is not publicly readable. Files are served to the app through short-lived, signed URLs that expire within minutes. The download links in a data export you request yourself work for 7 days. Encryption keys are managed by Supabase under their standard server-side encryption.
The free tries you can run without an account (the face analysis trial, the celebrity lookalike and the pet reader) save neither your photo nor the result. To limit them per day we keep counters keyed to one-way hashes of your IP address, alone and together with your browser type. The counters hold no photo and no name and are deleted after three days.
We never sell your photos. We never share them with advertisers or data brokers. We never use them to train any model, our own or anyone else's. We never publish them. Other users see a photo only when you submit it yourself for community feedback or to the Subjektiv rating game, and only inside that feature. Otherwise the only people who can see a photo you uploaded are you (when logged in) and the operator of Objektiv, only for narrowly scoped debugging.
When you ask for an analysis in ChatGPT, our server downloads the photo you attached from OpenAI's temporary file link, sends it to Google (Gemini API) for a short check that it shows one adult with a visible face, and then for the analysis. A Deep Analysis goes to Anthropic (Claude API) instead. We do not store photos sent from ChatGPT.
Without connecting an Objektiv account, nothing is saved to an account. To limit free analyses per day we keep a counter keyed to a one-way hash of the anonymous ChatGPT user identifier or of the IP address. The counters hold no photo and no name and are deleted after three days.
When you connect your Objektiv account, analyses you start in ChatGPT are saved to your history and marked as coming from ChatGPT. ChatGPT then receives the results you ask for: analysis reports, your colour palette and, on request, the list of your closet items with image links that expire after 15 minutes. Health notes, declared conditions and ethnicity from your profile are not used for analyses started in ChatGPT. Whatever ChatGPT receives is processed by OpenAI under its own privacy policy. You can disconnect Objektiv in ChatGPT's settings at any time.
When you open the face lines on a results page, the face points are found by Google's MediaPipe library running in your browser. The photo is not uploaded again for this step and the measured points are not stored. MediaPipe sends Google anonymous usage statistics, see section 5.
Under the GDPR and equivalent regimes, we rely on the following lawful bases:
Profile data, analysis results, photos, closet items, and chat messages are kept for as long as your account exists, or until you delete them, whichever comes first. From Settings you can:
Backups are rotated on a 30-day schedule. If you delete your account, any residual copy in a backup snapshot will be overwritten within 30 days as the snapshot expires; we do not restore individual users from backups for any reason.
We rely on a small number of established providers to run the service. Each one is bound by a Data Processing Agreement and processes data only on our instructions.
We use the minimum cookies required to keep you signed in and the product working:
We do not use marketing cookies, advertising trackers, third-party retargeting pixels, or cross-site tracking of any kind.
Under the GDPR, the UK GDPR, the California Consumer Privacy Act, and most modern privacy regimes, you have the following rights with respect to your personal data:
To exercise any right, use the controls in Settings or email privacy@objektiv.ai. We respond within 30 days.
Our infrastructure providers operate globally. Data may be transferred to and processed in jurisdictions outside the one in which you live, including the United States. Where transfers leave the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) as the transfer mechanism. We do not transfer your data to any country that does not provide at least equivalent protections.
Objektiv is not intended for users under the age of 16. We do not knowingly collect personal information from minors. Do not upload photographs of children under 16, including your own, without verifiable parental consent. If we discover that we hold data on a minor without such consent, we will delete it promptly. If you are a parent or guardian and believe a minor has signed up, contact privacy@objektiv.ai.
We protect your data through encryption in transit (TLS 1.2+ on every connection), encryption at rest for all photos and database fields containing identifiers, least-privilege access controls on production systems, audit logging of administrative access, and regular dependency and penetration scanning. No system is perfectly secure; if a breach occurs that affects you, we will notify you and the relevant authorities within the statutory window (72 hours under the GDPR).
We may update this policy as the product evolves. If we make material changes (such as adding a new category of data we collect, a new third-party processor, or a new purpose for processing), we will notify registered users by email at least 14 days before the change takes effect. Non-material clarifications (typos, reordering, clarifying language) take effect when posted. The “Last updated” date at the top of this page always reflects the most recent change.
The data controller for objektiv.ai is the entity operating Objektiv. For privacy questions, data subject requests, or to report a security concern, email privacy@objektiv.ai. For general support, use the in-app help bubble in the bottom-right of any page.
See also our Terms of Service and FAQ.