Privacy Policy
Controller: ILVIO OÜ Registry code (registrikood): 17333912 Registered office: Järve 35A, 11314 Tallinn, Estonia Contact: info@ilvio.eu App: ILVIO (the "App"; previously referenced internally as "Magic Mirror") Website: https://ilvio.eu Effective date: 7 July 2026 Version: 1.1
1. Who we are and what this policy covers
ILVIO OÜ ("ILVIO", "we", "us", "our") is an Estonian private limited company and the data controller for personal data processed through the ILVIO mobile application, the ILVIO smart mirror hardware ("Mirror"), and the website at ilvio.eu.
This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).
If you disagree with any part of this policy, please do not use the App.
2. Summary (plain language)
- We collect the data you give us (email, photos of you and your clothes, preferences) plus technical data needed to run the service.
- We use specialised AI providers (Anthropic, Google, OpenAI, Replicate) to generate try-on images, categorise clothing, and power style assistance. Your data is sent to these providers under contracts that prohibit using it to train their models.
- We do not sell your data, run advertising, or use tracking cookies or third-party analytics SDKs.
- You can delete your data at any time from inside the App. To receive an export of your data, email info@ilvio.eu and we will send you a copy.
- Some processing (AI recommendations, style tag derivation) is automated. You can always override our suggestions, and we do not make decisions with legal or similarly significant effects about you based solely on automation.
3. Personal data we process
We group the data we process into the categories below. For each category we identify the legal basis under GDPR Article 6 (and, where applicable, Article 9), and the retention period.
3.1 Account and authentication data
Data: email address, hashed password, display name (optional), username/handle, account creation date, last sign-in time. Purpose: authenticate you, contact you about your account, enforce our Terms of Service. Legal basis: performance of a contract (Art. 6(1)(b)). Retention: for the life of your account; deleted within 30 days of account closure, except where we must retain records for legal reasons (see §9).
3.2 Profile and body data
Data: profile avatar, cover image, full-body reference photo used for virtual try-on, optional measurements (height, weight, shirt/pants/shoe size), optional body description, style preferences and tags, unit preferences. Purpose: personalise virtual try-on, recommendations, and fit guidance. Legal basis: performance of a contract (Art. 6(1)(b)) for the reference photo required by the try-on feature; consent (Art. 6(1)(a)) for optional measurements. Special-category note: your body reference photo may enable visual identification. We treat this image as sensitive and do not process it as biometric data within the meaning of Art. 9 GDPR — we do not use it to uniquely identify you, do not run facial recognition against it, and do not match it against any third-party dataset. The photo is used solely as visual input for the generative AI that produces try-on previews. Retention: for the life of your account; you can delete the reference photo at any time in Settings. Deleted files are purged from storage within 30 days.
3.3 Wardrobe and clothing data
Data: photos of clothing items you upload (original and background-removed versions); AI-generated metadata (category, colour, brand guess, fabric, fit, length, layering role, warmth level, temperature range, style tags, editorial description); wear history; favourites. Purpose: operate the wardrobe, generate outfit recommendations, power try-on. Legal basis: performance of a contract (Art. 6(1)(b)). Retention: until you delete the item or close your account.
3.4 Outfit checks, try-on results, and recommendations
Data: photos you submit for outfit checks; AI feedback and ratings; generated try-on images; generated outfit suggestions; the prompts used to produce them; whether you saved or dismissed a suggestion. Purpose: deliver the feature you asked for and let you revisit past results. Legal basis: performance of a contract (Art. 6(1)(b)). Retention: until you delete the result or close your account.
3.5 AI chat and conversation data
Data: messages you send to the AI style assistant; AI responses; conversation metadata (timestamps, session id). Purpose: provide multi-turn conversational assistance. Legal basis: performance of a contract (Art. 6(1)(b)). Retention: conversations are stored in your account so you can revisit them, and are deleted when you delete the conversation or close your account. AI providers do not retain the content for training (see §5).
3.6 Location data
Data: GPS coordinates (latitude/longitude) captured only when you open a feature that needs weather (recommendations, home screen weather widget); derived city name. Purpose: fetch weather for the recommendation engine. Legal basis: consent (Art. 6(1)(a)) — granted through your device's location permission and revocable at any time in device settings. Retention: coordinates are not stored server-side; only the derived city label may be cached on-device until you close the app.
3.7 Mirror (smart mirror) data
Data: BLE device name and hardware identifier; Wi-Fi SSID you select during setup; Wi-Fi password (transmitted directly to the Mirror over an encrypted BLE channel and not stored on our servers); mirror personality/voice preferences; audio recordings captured by the Mirror microphone during interaction; derived transcripts; photos captured by the Mirror camera when you request an outfit analysis. Purpose: set up and operate the Mirror; deliver voice assistant and outfit analysis features. Legal basis: performance of a contract (Art. 6(1)(b)); consent (Art. 6(1)(a)) for the always-available microphone and camera features (you can disable them per Mirror). Retention: Wi-Fi password: never stored on our backend. Audio: sent to OpenAI Whisper for transcription and discarded immediately; transcripts kept for the life of the conversation record. Photos: treated like outfit-check photos (§3.4).
3.8 Social and community data
Data: followers/following graph; privacy setting (public/private); posts (image + caption); comments; reactions; derived social metrics (follower count, etc.). Purpose: operate the social features you opt into. Legal basis: performance of a contract (Art. 6(1)(b)). Retention: until you delete the post/comment or close your account. If you delete your account, your posts and comments are deleted. Reactions to other users' posts may remain aggregated anonymously in counters (we delete the association with you). Note on third parties in your photos: if your uploaded image contains other recognisable people, you must have their permission to include them. See §11.
3.9 Pinterest integration (optional)
Data: Pinterest user id and username; titles, descriptions, and image URLs of boards and pins you grant us access to; AI-derived style analysis from those pins. Purpose: enrich your style profile and feed using your own Pinterest content. Legal basis: consent (Art. 6(1)(a)) — given by completing the Pinterest OAuth flow and revocable from Settings > Pinterest > Disconnect, or from your Pinterest account. Retention: until you disconnect; disconnection purges pins, derived analysis, and OAuth tokens within 30 days.
3.10 Technical and diagnostic data
Updated 2026-05-19. ILVIO ships Sentry crash reporting (
sentry_flutter). Sentry captures the stack trace plus device metadata (model, OS, app version) when the app crashes. Default PII forwarding is disabled (sendDefaultPii = false); in release builds a screenshot of the app at the moment of the crash is attached to the report so we can reproduce visual bugs. If a crash occurs while you are viewing your wardrobe or a try-on result, that image may appear in the attached screenshot. Screenshots are retained for 90 days and visible only to ILVIO engineers under a confidentiality obligation. Data: app version, device model, OS version, language, approximate request timing, and error reports (no tracking identifiers, no advertising IDs). Purpose: debugging, reliability, abuse prevention. Legal basis: legitimate interests (Art. 6(1)(f)) in keeping the service secure and functional. Retention: up to 90 days.
3.11 Data we do not collect
- Advertising identifiers (IDFA, Android AID).
- Third-party analytics telemetry (no Firebase Analytics, no Segment, no Mixpanel, etc.).
- Contacts, calendars, SMS, call logs.
- Health data from HealthKit / Google Fit.
- Payment card data — subscription payments are processed by Stripe on a checkout page in your browser; your card details never touch our servers. We receive only the subscription status (plan, active/expired) tied to your account.
4. How we use your data
We use your data only for the purposes stated in §3. Concretely:
- Run your account and keep it secure.
- Provide the features you invoke (wardrobe, try-on, assistant, recommendations, Mirror, social).
- Respond to support requests.
- Detect and prevent abuse, fraud, and security incidents.
- Comply with legal obligations (bookkeeping, tax, responses to lawful requests).
- Communicate material changes to the App or this policy.
We do not use your data for targeted advertising, behavioural profiling for marketing, or sale to third parties.
5. Automated processing and AI
The App uses AI extensively. You should know:
- Several AI outputs are fully automated: clothing categorisation, metadata enrichment, style-identity tag derivation, outfit recommendation ranking, and virtual try-on image generation.
- None of these produce decisions with legal or similarly significant effects within the meaning of GDPR Art. 22. You remain free to ignore any recommendation, and no benefit, price, or access decision is made solely by AI.
- AI output is inherently imperfect. Recommendations, categorisations, and try-on images may contain errors or visual artefacts. They are provided "as is" and should not be relied upon for purchasing, medical, or safety decisions.
- Training. We send data to AI providers only for real-time inference. Our contracts with these providers require that your data is not used to train, fine-tune, or otherwise improve their models. Data may be retained transiently by the provider for safety/abuse monitoring (typically 30 days) before being deleted. Provider-specific policies are linked in §6.
6. Processors and sub-processors
The following independent companies process your personal data on our behalf under Art. 28 GDPR data processing agreements. Each has its own privacy policy which governs their internal handling.
| Processor | What they do for us | Data categories sent | Primary processing location | Transfer safeguard |
|---|---|---|---|---|
| Supabase, Inc. (US) | Auth, Postgres database, storage, edge functions | All app data except AI prompt content (which passes through but is not stored with Supabase longer than the edge request) | Supabase's AWS region for this project: [eu-west-1 / other — confirm in dashboard] | EU Standard Contractual Clauses (SCCs); Supabase DPA [privacy] |
| Anthropic, PBC (US) | AI models for style assistant, metadata enrichment, categorisation, outfit analysis, recommendations | Wardrobe text + image metadata, chat messages, body description text | US | EU SCCs [privacy] |
| Google LLC / Google Ireland Ltd | Gemini models for virtual try-on image generation | Body reference photo, clothing photos, prompt context | US / EU | EU SCCs, adequacy under UK/EU-US Data Privacy Framework [privacy] |
| OpenAI, OpCo LLC (US) | Whisper (audio transcription), TTS, GPT-4o-mini (Mirror conversational AI) | Audio recordings, transcripts, chat text from Mirror | US | EU SCCs [privacy] |
| Replicate, Inc. (US) | Background removal on clothing photos | Clothing photos only | US | EU SCCs [privacy] |
| Pinterest, Inc. (US) — only if you connect | Read your pins and board metadata | OAuth token, pin metadata | US | EU SCCs, DPF [privacy] |
| OpenWeather Ltd (UK) | Weather data | GPS coordinates | UK | UK–EU adequacy decision [privacy] |
| Apple Inc. / Google LLC | App distribution, crash logs, in-app purchases | Anonymised purchase status, crash traces | US | EU SCCs / DPF |
| Functional Software, Inc. (Sentry) (US) | Mobile app crash reporting and performance monitoring | Crash stack traces, device/OS metadata, scrubbed breadcrumb events | US | EU SCCs [privacy] |
| Resend (Drift Labs, Inc.) (US) — only if enabled | Transactional email (account emails, moderation alerts) | Sender, recipient, subject, message body | US | EU SCCs [privacy] |
| Stripe Payments Europe, Ltd. / Stripe, Inc. (IE/US) | Subscription checkout, billing, and the customer portal | Email address, subscription plan and status. Card details are collected and held by Stripe only and never reach our systems; Stripe acts as an independent controller for its own payment processing | EU / US | EU SCCs; DPF [privacy] |
Sub-processors. Our processors rely on their own infrastructure providers (for example, Supabase runs on Amazon Web Services; Anthropic uses AWS and Google Cloud). These sub-processors are bound by the same contractual protections. An up-to-date sub-processor list is available on request to info@ilvio.eu.
We publish material changes to the processor list at least 14 days before they take effect via the App or email.
7. International data transfers
Some processors are located outside the European Economic Area (most commonly in the United States). For every such transfer we rely on one of the following GDPR transfer mechanisms, applied in this order of preference:
- An adequacy decision of the European Commission (e.g. UK, EU-US Data Privacy Framework where the processor is certified).
- Standard Contractual Clauses (SCCs, Decision 2021/914), supplemented with technical measures (encryption in transit via TLS 1.2+; encryption at rest; contractual restrictions on government access challenges).
- Where neither of the above applies to a specific transfer, we do not make the transfer.
We do not rely on your consent under Art. 49 GDPR as the primary basis for recurring operational transfers.
8. Security
We use industry-standard safeguards:
- TLS 1.2+ for all network traffic.
- AES-256 encryption at rest for storage buckets.
- bcrypt password hashing via Supabase Auth.
- Signed, short-lived URLs for all private media (wardrobe, try-on, outfit photos, base images, avatars).
- API keys held server-side in Supabase Edge Function secrets, never shipped in the mobile binary.
- Encrypted BLE channel (Wi-Fi Provisioning) for Mirror setup; Wi-Fi credentials are never persisted server-side.
- Principle-of-least-privilege database access via Postgres Row Level Security.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate without undue delay and, where required by Art. 34 GDPR, notify affected users directly.
9. Retention
In addition to the category-specific periods in §3:
- Account closure: when you delete your account, we purge personal data within 30 days, except:
- Data we must retain for tax and accounting purposes (Estonian Accounting Act — up to 7 years for transaction records).
- Data we must retain to defend legal claims (for the duration of the applicable limitation period).
- Backups — our encrypted database backups are rotated and fully overwritten within 35 days.
- Inactive accounts: an account with no sign-in for 24 consecutive months may be closed after two email reminders; associated data is then deleted per the above.
- Support correspondence: retained for up to 24 months for quality and audit purposes.
- Content reports: retained for up to 24 months from the date the report is closed, to maintain a moderation audit trail and defend against bad-faith reports.
10. Your rights under GDPR
You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — delete your data, subject to the retention exceptions in §9.
- Restriction — limit how we process your data in specific circumstances.
- Object — object to processing based on legitimate interests (§3.10).
- Portability — receive your data in a structured, machine-readable format and have it transmitted to another controller where technically feasible.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
How to exercise these rights. Rectification and erasure can be exercised directly in the App:
- Settings > Profile to edit your data.
- Settings > Account > Delete my account to initiate deletion.
To exercise your right of access or portability (receive a copy of your data), email info@ilvio.eu from the email address linked to your account and we will provide an export in a structured, machine-readable format. For all other rights, email info@ilvio.eu. We will respond within one month (extendable by two further months for complex requests, with notice).
Complaints. You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia; aki.ee) or with the supervisory authority in your EU country of residence or place of the alleged infringement.
11. Content you upload and third parties in your content
By uploading content (photos, captions, comments) you grant ILVIO a non-exclusive, worldwide, royalty-free licence to host, store, transmit, process, and display that content solely for the purpose of operating the App for you and, where you choose to share content publicly, for the purpose of delivering it to other users you have authorised. This licence ends when you delete the content or close your account, subject only to the technical retention periods in §9.
If your uploaded content contains other identifiable people, you warrant that:
- You have their informed permission to include them, and
- You have informed them that the image will be processed by ILVIO and the AI providers listed in §6.
You remain the owner of your content.
12. Social features and visibility
When you make your profile public, set a post's visibility to public, or accept a follower, you understand that:
- The content becomes visible to the users you permitted.
- Other users may view, screenshot, or otherwise copy visible content — we cannot control what they do after seeing it.
- Content you delete is removed from our systems on our retention schedule, but copies may remain with third parties who already saw it.
Comments and reactions you leave under another user's post are visible to viewers of that post.
12.1 Reports and moderation
You can report any post, comment, profile, or AI assistant reply you find inappropriate by tapping the overflow menu (⋯) or long-pressing the item. We collect:
- the report itself (your user ID, what you reported, the reason you selected, and any free-text notes you add);
- a reference to the reported content so our team can locate it.
We use this only to review the report, decide on moderation action, and keep an audit trail of what we acted on. Reports are kept for two years and then deleted, unless we need to keep them longer to comply with a legal obligation or defend a legal claim.
The user you report does not see who reported them. We aim to review reports within seven days. You can email info@ilvio.eu to follow up on a report, request its deletion, or appeal a moderation decision made against your own content.
This commitment supports our obligations under the EU Digital Services Act (Regulation 2022/2065) and Apple's App Review Guideline 1.2 for user-generated content.
13. Children
The App is not directed to children. You must be at least 16 years old to create an account. This is the strictest age of consent applied across the EU; we apply it uniformly regardless of the lower thresholds permitted in some Member States (including Estonia, which sets the threshold at 13).
If we learn that we have collected data from a child below that age without verifiable parental consent, we will delete it promptly. If you believe a child has provided us with data, contact info@ilvio.eu.
14. Cookies, tracking, and analytics
- The mobile App uses no cookies and no third-party analytics SDKs.
- The website ilvio.eu is a static informational site and sets no cookies of its own. When you start a subscription checkout you are taken to a page hosted by Stripe, which sets cookies strictly necessary for payment processing and fraud prevention (see Stripe's privacy policy).
- We do not participate in cross-site tracking.
- Apple App Tracking Transparency: we do not track you across apps or websites owned by other companies.
15. Payments and subscriptions
Subscriptions are processed by Stripe via a secure checkout page that opens in your browser from the App or from ilvio.eu. We do not receive your card details — Stripe collects and stores them. We receive only the subscription status (plan, active, expired, refunded) tied to your account so we can unlock paid features. Stripe is an independent controller for its own payment processing — see Stripe's privacy policy. If subscriptions are in future also offered through the Apple App Store or Google Play, the same principle applies: we receive only an anonymised subscription status from the store.
16. Changes to this policy
We may update this policy from time to time. When we make material changes we will:
- Post the new policy with a new version number and effective date,
- Notify you in-app or by email at least 14 days before the change takes effect (except where an earlier change is required by law),
- Where the change requires new consent (for example, a new category of processing based on consent), request that consent before activating the change.
Continued use after the effective date constitutes acceptance of non-consent-based changes.
17. Contact and data protection officer
For all privacy matters, including requests to exercise the rights in §10:
Email: info@ilvio.eu Post: ILVIO OÜ, Järve 35A, 11314 Tallinn, Estonia
We have not appointed a Data Protection Officer because our processing does not meet the thresholds of GDPR Art. 37. We will appoint one if the thresholds are met, and update this policy accordingly.
This policy is available in English. Where a translated version is provided, the English version prevails in case of conflict.