At a glance
- Your color analysis stays on your iPhone. Selfies and measurements never leave your device. We only keep the result, such as “Soft Autumn”.
- We pixelate faces before uploading. This happens on your iPhone before a photo reaches our server. The only exception is the glow-up preview, and only with separate consent.
- AI only with your consent. Product photos, outfit check, glow-up, and the AI stylist use Google Gemini. Google does not train models on this data.
- No tracking, no ads. We don’t sell data and don’t embed advertising or analytics services.
- You stay in control. Export your data, delete everything, delete your account, and withdraw consent right in the app.
- Payments go through Apple only. We never see payment details, just the status of your subscription.
Controller
The controller responsible for processing personal data in the Mainfit app and on these web pages is:
HK MEDIA GmbHKirchenstraße 10
25335 Elmshorn, Germany
Managing director: Haris Khawaja
Phone: +49 4121 830240
Email: [email protected]
For any privacy question, reach us at [email protected]. We have not appointed a data protection officer because we are not required to (Section 38 BDSG). Confirm whether an appointment is required (O3).
This policy covers the Mainfit iPhone app and its web pages (legal texts, password reset).
What is stored where
Mainfit does as much as possible right on your iPhone. Our server only receives what your closet needs across devices, what the AI features need, and what your subscription needs.
| Data | Where |
|---|---|
| Selfie series and color measurements (skin, hair, eyes) | only in your iPhone’s memory, never stored |
| Color season and contrast level (color analysis result) | iPhone and server |
| Location for the weather | only on your iPhone |
| Outfit check and glow-up history (the list with your photos and notes), data export | only on your iPhone |
| Outfit check result, glow-up with plan, pixelated photo, and preview image | server, for a limited time (see Retention periods) |
| Account or guest data, style profile, consents | server, mirrored on your iPhone |
| Photos of your items, product photos, items, outfits, worn days | server, cached on your iPhone |
| Subscription status | Apple, server, and iPhone |
Guest and account
Using Mainfit as a guest
On first launch, the app quietly creates a guest session. It generates a random installation ID and stores it in your iPhone’s keychain. An account is optional, even before you subscribe.
- Purpose
- Linking your data to this iPhone without requiring sign-up
- Data
- Installation ID, guest ID, access token, language
- Legal basis
- Art. 6(1)(b) GDPR (terms of use); storage in the keychain under Section 25(2) no. 2 TDDDG
- Retention
- Guest accounts without a subscription are deleted 30 days after last use; guest accounts with a past subscription 12 months after it expired
Account with email, Apple, or Google
With an account, your closet is available on any iPhone. When you create one, your guest data moves into it. With Sign in with Apple we receive an Apple user ID and, if you choose, your name and email address (including a “Hide My Email” relay address). With Google we receive your Google ID, email address, and name as confirmed by Google. Passwords are stored only as a hash (Argon2id).
- Purpose
- Sign-in, syncing between devices, password reset
- Data
- Email address, password hash, display name, Apple or Google IDs, and for Apple an encrypted token used to revoke access when you delete your account
- Legal basis
- Art. 6(1)(b) GDPR
- Recipients
- Apple or Google verify the sign-in as independent controllers
- Retention
- Until you delete your account; we revoke the Apple token with Apple when you do
To delete your account, go to Profile → Delete account in the app. We immediately delete your account, items, outfits, uploads, AI results, and device tokens; a background job removes the image files right after. An active Apple subscription does not end this way. Cancel it in your iPhone Settings.
Photos and closet
Photos of your clothes
When you photograph an item or import it from Photos, the app pixelates detected faces on your iPhone (the face area plus a 20% margin), downsizes the image, and then uploads it. From the photo we create a crop, a product photo, a thumbnail, and a cutout. All images are stored privately on our server and are only reachable through signed links that expire after 24 hours.
- Purpose
- Your digital closet, outfit suggestions, syncing between devices
- Data
- Photos (faces pixelated), items with category, colors, material, and notes, outfits, worn days, laundry and archive status
- Legal basis
- Art. 6(1)(b) GDPR
- Retention
- Until you delete the item, all data (“Delete everything”), or your account
Pixelation uses Apple’s on-device face detection. If a face isn’t detected, for example because it is partly covered, it may stay unpixelated. Only photograph other people with their permission.
Items without AI never send a photo to Google: you keep the photo and the cutout made on your iPhone.
AI features with Google Gemini
Product photos, outfit check, glow-up, and the AI stylist (chat) use Google’s Gemini API. Before anything is sent to Google for the first time, the app asks for your explicit consent. Without it, only the on-device features work.
What is sent to Google
- Purpose
- Recognizing and describing clothing, creating product photos and checking them for accuracy, rating outfits, creating glow-up plans and previews, answering questions to the AI stylist
- Data
- Photos of your clothes and outfits with faces pixelated, crops, your style preferences and color season, a short list of your items, occasion and weather values (temperature, conditions, no location), your chat messages. Never your name, email address, or facial measurements
- Legal basis
- Your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time
- Recipient
- Google as processor (paid Gemini API) Confirm the contracting entity (Google LLC or Google Ireland) and data processing terms.
- At Google
- Google does not use prompts or results from the paid Gemini API to train its models. Google keeps them for a limited time to detect abuse and policy violations, possibly outside the EU
What we keep
- Product photos and cutouts of your items: like the photos of your items.
- Outfit check: we never store the photo. We keep the result (scores, tips) for 24 hours at most, so a repeated request after a dropped connection gets the same answer and doesn’t count twice; then we delete it. Your history lives only on your iPhone.
- Glow-up: we automatically and completely delete the glow-up with its plan, pixelated photo, and preview image after 30 days.
- AI stylist: we don’t store the content of your messages. We only count them for your monthly allowance.
- For every AI request we keep a cost ledger without content: type of request, model, volume, estimated cost, and time. Set a retention period for the cost ledger.
Glow-up preview with your face
For “Create preview image”, the AI needs you in the picture. Only for this does the app upload the same photo without pixelation, and only after a second, separate consent right at the button. We delete this photo immediately after the preview is created, even if it fails. The preview carries the visible label “AI preview”.
- Legal basis
- Art. 6(1)(a) GDPR. We do not analyze the photo biometrically to identify anyone. Confirm classification under Art. 9 GDPR.
We label generated images as AI-generated: in the image metadata (IPTC “Digital Source Type”) and in the app as “AI product photo” or “AI preview”. The AI stylist identifies itself as an AI and can make mistakes.
You can withdraw your consent at any time in the app under Profile → AI features. Withdrawal applies to all new requests immediately; jobs already running may finish. Processing before withdrawal remains lawful.
Color analysis on your iPhone
To find your color season, the app records a short series with the front camera and measures skin, hair, and eye color. This happens entirely on your iPhone using Apple’s Vision framework:
- The images are processed in memory only, never written to storage, and never transmitted.
- The measured color values exist only during the analysis. Afterwards, only the result remains: color season, contrast level, and how confident the estimate is.
- Only the color season and contrast level are sent to our server, so suggestions match on all your devices.
- We don’t create face profiles and we don’t identify anyone.
The legal basis for the stored result is Art. 6(1)(b) GDPR. You can skip the analysis or choose your color season manually.
Subscription through Apple
You buy and manage Mainfit Pro exclusively through Apple. Apple handles purchase, payment, invoicing, refunds, and cancellation as an independent controller. We never receive payment details, your Apple Account, or your address.
- Purpose
- Unlocking Pro features, showing your trial and expiration date, honoring refunds and revocations
- Data
- Information signed by Apple: transaction IDs, product, purchase and expiration time, trial, renewal status, grace period, refund or revocation, environment (e.g., sandbox), and the account ID the app passes along with the purchase
- Source
- Your app after each purchase and launch, and Apple’s server notifications (App Store Server Notifications)
- Legal basis
- Art. 6(1)(b) GDPR
- Retention
- Until you delete your account; afterwards, the subscription record stays without any link to an account so later refunds and revocations can be matched Set a maximum period.
If someone presents a subscription that previously belonged to another Mainfit account (same Apple Account, different account), the entitlement moves to the presenting account, together with this month’s allowance usage. This can happen at most once in 24 hours and three times in 30 days. We log the move with the account IDs; for the limits we keep only the time and usage per subscription, without account IDs, for 40 days at most. If an account is deleted, we likewise keep its subscription’s usage for the month until another account takes the subscription over.
Free photos and DeviceCheck
Without a subscription you can try 3 free product photos, once per iPhone. So this can’t be repeated endlessly by reinstalling or creating new accounts, we use Apple’s DeviceCheck: the app creates a device token that our server uses to read or set two flags Apple stores per device for Mainfit. We use one of them for “free photos used up”. Apple receives no photos and no account data in the process.
- Purpose
- Preventing abuse of the free product photos
- Data
- DeviceCheck token (not stored), installation ID, count of free product photos used
- Legal basis
- Art. 6(1)(f) GDPR; our legitimate interest is protecting paid AI services from repeated free use Check Section 25 TDDDG for the device token.
- Retention
- Installation ID and counter remain after you delete your account, without any link to an account or photos Set a maximum period.
Weather and location
For outfits that match the weather, the app queries Apple Weather (WeatherKit) with your location, but only if you allow location access. The request goes directly from your iPhone to Apple; your location never reaches our server. Without access, the app estimates the weather based on the season.
The legal basis is your consent through iOS location permission (Art. 6(1)(a) GDPR), which you can withdraw in your iPhone Settings at any time. According to Apple, it processes the location for weather requests without linking it to your Apple Account. Confirm Apple’s role (independent controller or processor).
Notifications
The app schedules your daily outfit and the reminder before your trial ends as local notifications on your iPhone; nothing is sent to us for this. For “Product photos ready”, we may send a push notification through the Apple Push Notification service. For this we store your device’s push token.
The legal basis is your notification permission in iOS (Art. 6(1)(a) GDPR). You can turn it off in your iPhone Settings. The push token belongs to your account until you sign out on the device or delete your account.
Servers, security, support
Servers and logs
Our server is hosted by Add hosting provider, server location, and data processing agreement (O7). When accessed, it processes technically necessary data: IP address, time, requested address, app version, browser or app identifier (user agent), and a request ID.
- Purpose
- Operation, security, troubleshooting, protection against overload (e.g., request limits per IP address)
- Legal basis
- Art. 6(1)(f) GDPR
- Retention
- Request-limit counters for one day at most; server logs 14 days, then deleted automatically
Everything is transmitted encrypted (TLS). We store images privately, serve them only through expiring signed links, and store passwords only as hashes. So paid requests don’t count twice after a dropped connection, we keep their response for 24 hours.
Support and emails
If you write to us, we process your message and address to reply. “Report a problem” in the app only attaches diagnostic data (e.g., app and iOS version, device model) if you agree. Password reset emails are sent through Add email service (O9).
- Legal basis
- Art. 6(1)(b) GDPR, otherwise (f) (answering inquiries)
- Retention
- Until the request is resolved Set a period for support correspondence.
These web pages
The legal pages (privacy policy, terms, legal notice) set no cookies, load no fonts, scripts, or images from third parties, and use no analytics. Only the server logs described above are processed.
“New password” page
The page for resetting your password (the link in the password email, /passwort/neu/…) sets two strictly necessary cookies: one for the session and one that protects the form against forged requests (CSRF). With the session we store your IP address and your browser identifier (user agent).
- Purpose
- Accepting your new password securely
- Legal basis
- Cookies: Section 25(2) no. 2 TDDDG (strictly necessary); session data: Art. 6(1)(b) and (f) GDPR
- Retention
- 2 hours, as long as the session
Recipients and transfers
| Recipient | Purpose |
|---|---|
| Google (Gemini API) | AI features, only with consent; processor |
| Apple | Sign in with Apple, App Store and subscription, DeviceCheck, weather (WeatherKit), push notifications |
| Google (sign-in) | only if you sign in with Google |
| Hosting provider | Running our server; processor |
| Email service | Sending password emails; processor |
Google and Apple may process data in the United States or other countries outside the EU. Google LLC and Apple Inc. are certified under the EU-U.S. Data Privacy Framework, covered by the European Commission’s adequacy decision of July 10, 2023. The European Commission’s standard contractual clauses apply in addition. Confirm the transfer mechanism for each recipient.
We don’t sell data or share it for advertising. We only disclose data to authorities where the law requires it.
Retention periods
| Data | How long |
|---|---|
| Selfie series and color analysis measurements | never stored |
| Photos for the outfit check | never stored |
| Outfit check result | 24 hours at most, then deleted |
| Photos of your items, product photos, cutouts | until you delete the item or your account |
| Glow-up plan, glow-up photo (pixelated), and preview image | 30 days, then deleted automatically and completely |
| Glow-up photo without pixelation | deleted right after the preview is created, even if it fails |
| Guest account without subscription | 30 days after last use, including photos |
| Guest account with a past subscription | 12 months after the subscription expired |
| Account, profile, items, outfits | until you delete them or your account |
| Responses to paid requests | 24 hours |
| Push token | until you sign out on the device or delete your account |
| Session of the “New password” page (cookies, IP address, browser identifier) | 2 hours |
| Server logs | 14 days |
| Moves of a subscription between accounts (time, usage, no account IDs) | 40 days at most |
| Installation ID and free photo counter | beyond account deletion Set a maximum period. |
| Subscription record after account deletion | without a link to an account Set a maximum period. |
“Delete everything” in the app removes items, outfits, uploads, checks, glow-ups, and their images, but keeps your account, profile, consents, and subscription. “Delete account” removes everything.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20). You can do much of this right in the app:
- Export data: Profile → Export data creates a ZIP on your iPhone with your items, outfits, profile, and images.
- Correct: You can edit items, style preferences, and your color season anytime.
- Delete: single items, “Delete everything”, or “Delete account”, even before subscribing via the account menu on the subscription screen.
- Withdraw consent: AI features and glow-up preview under Profile, location and notifications in your iPhone Settings. Withdrawal applies going forward.
Objection (Art. 21 GDPR): Where we process data based on legitimate interest (abuse prevention, security), you can object on grounds relating to your particular situation. Email us at [email protected].
Complaints: You can lodge a complaint with a data protection authority, for example the one responsible for us: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
You are not obliged to provide data. Without consent there are no AI features, without location the app estimates the weather, and without an account your closet stays on this iPhone. Mainfit makes no automated decisions with legal effect (Art. 22 GDPR); suggestions and AI results are recommendations.
Age, tracking, changes
18+: Mainfit is for adults. If you indicate that you are under 18, the app blocks use on this iPhone. As a guest, it also deletes the guest session and its data on our server. If you are signed in with an account, it signs you out and deletes the data on your iPhone; your account on our server remains until you ask us to delete it ([email protected]). The app remembers the block on this iPhone; we don’t store the “under 18” answer on our server.
No tracking: We use no advertising, analytics, or tracking services, don’t track you across other companies’ apps and websites, and therefore don’t ask for permission to track.
Changes: When the app changes, we update this policy. The version dated at the top of this page applies. We’ll inform you about material changes in the app.
This English version is provided for convenience. Decide which language version prevails.