Legal
Effective Date: April 1, 2026 | Last Updated: April 23, 2026
1. Introduction
GENTIQ (“we”, “us”, “our”) is a mobile application developed and operated by GENTIQ UG (haftungsbeschränkt), registered in Austria. GENTIQ helps users build a digital wardrobe, generate AI-powered outfit recommendations, and virtually try on clothing.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the GENTIQ iOS application and related services. It applies to all users worldwide and is designed to comply with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), the California Consumer Privacy Act (CCPA/CPRA), and other applicable laws.
By creating an account or using GENTIQ, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the app.
2. Data Controller
The data controller responsible for the processing of your personal data is:
GENTIQ UG (haftungsbeschränkt)
Elias Mueller
Email: privacy@gentiqclo.com
Website: https://gentiqclo.com
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
3.2 Wardrobe Data
When you add items to your digital wardrobe, we process:
3.3 Outfit and Style Data
3.4 Face Data
This section describes in full how GENTIQ handles face data, including face photos, facial landmarks, and derived facial attributes. We understand that face data is sensitive, and we have designed our features to minimize collection, storage, and sharing.
(a) Whether face data is retained
GENTIQ does not retain face data on its servers. No face photo, facial landmark, facial geometry, or derived facial attribute is ever uploaded to or stored on GENTIQ’s backend infrastructure. The only on-device face data stored is the user’s own reference photo (if they choose to save one) and locally derived color analysis results — both of which remain on the user’s device and are never transmitted to us.
(b) Reasons for storing face data
The limited face data that is stored locally on the user’s device is stored solely to:
GENTIQ does not use face data for identification, authentication, advertising, profiling, model training, or any purpose other than the features described above.
(c) Length of time face data is stored and why
(d) Third parties we share face data with
GENTIQ shares face data with exactly one third party, and only when the user actively invokes the virtual try-on feature:
We do not share face data with OpenAI, Supabase, Resend, Apple, analytics vendors, advertisers, data brokers, or any other third party.
(e) Reasons for sharing face data with third parties
The user’s face photo is transmitted to Google Gemini for the sole purpose of rendering a virtual try-on image — that is, generating a synthetic image showing the user wearing a selected garment. Transmission happens only when the user explicitly initiates a virtual try-on request. The photo is not shared for any other purpose, including advertising, analytics, identification, or model training.
(f) Whether third parties store face data — and their practices
Google Gemini: Under our paid Google Gemini API agreement (Google Cloud Vertex AI / Gemini API terms), Google does not retain face photos submitted by GENTIQ beyond the active processing session and does not use them to train Google’s models.
(g) On-device face analysis (no transmission)
Separately from the virtual try-on feature, GENTIQ performs facial landmark detection and skin/hair/eye color analysis entirely on the user’s device using Apple’s Vision framework. No facial geometry, landmark data, color values, or derived attributes from this analysis are transmitted to GENTIQ, Google, or any other third party. This data stays on the device and is deleted when the user removes their photo, deletes their account, or uninstalls the app.
3.5 Location Data
With your explicit permission (iOS location prompt), we access your approximate location solely to retrieve local weather data for weather-appropriate outfit recommendations. We do not track, store, or share your precise location. You can revoke this permission at any time in your device settings.
3.6 Device, Usage and Ad-Measurement Data
We (and, where noted, Meta Platforms Inc. via the Facebook SDK) process the following categories of technical and usage data:
If you decline the App Tracking Transparency prompt, only the IDFV (not the IDFA) is used, and no cross-app tracking occurs.
3.7 Data We Do NOT Collect
4. Legal Bases for Processing (GDPR)
Under the GDPR, we process your personal data on the following legal bases:
Account creation and authentication
Performance of contract (Art. 6(1)(b))
Necessary to provide the GENTIQ service you signed up for.
Wardrobe storage and outfit generation
Performance of contract (Art. 6(1)(b))
Core functionality of the app you agreed to use.
Virtual try-on rendering
Consent (Art. 6(1)(a))
You actively choose to upload a photo for this feature. You can withdraw consent at any time.
Location-based weather recommendations
Consent (Art. 6(1)(a))
iOS permission prompt. Revocable at any time via device settings.
Anonymous usage analytics
Legitimate interest (Art. 6(1)(f))
Improving app stability and user experience. Minimal data, no profiling.
Ad-campaign measurement via Meta / Facebook SDK (IDFV + event data, before or without ATT consent)
Legitimate interest (Art. 6(1)(f))
Measuring the effectiveness of our own advertising and attributing app installs. No cross-app tracking occurs at this stage. You may object at any time by disabling tracking in iOS Settings → GENTIQ.
Advertising identifier (IDFA) processing by Meta / Facebook SDK
Consent (Art. 6(1)(a))
Only after you grant App Tracking permission via the iOS ATT prompt. Fully revocable at any time in iOS Settings.
Affiliate / partner-link click attribution (pseudonymous clickref + product ID + timestamp)
Legitimate interest (Art. 6(1)(f))
Necessary for commission reconciliation with Awin / Partnerize so that GENTIQ can be compensated for successful referrals. No personal identifiers are transmitted; the ranking of recommended products is independent of commission rates. You may object at any time by not tapping links marked as 'Werbung' / 'Advertisement'.
Subscription management
Performance of contract (Art. 6(1)(b))
Necessary to manage your premium subscription status.
Email communications (transactional)
Performance of contract (Art. 6(1)(b))
OTP verification, password resets, and account security notifications.
5. How We Use Your Data
We do not sell your personal data, and we do not build behavioural advertising profiles of our users. The only advertising-related processing we perform is measuring the effectiveness of the ads we ourselves run, as described in Section 6.
6. Third-Party Service Providers
We use the following third-party services to operate GENTIQ. Each provider processes data only as necessary and under contractual data processing agreements:
Supabase (US)
Authentication, database, file storage
Data: Account data, wardrobe items, photos
EU (eu-west-1)
OpenAI (US)
AI outfit generation, item analysis, and style reference processing
Data: Wardrobe item descriptions, occasion preferences, style reference photos (when you use style reference features)
US
Google Gemini (US)
Face photo analysis for virtual try-on and personalized recommendations
Data: Face/selfie photos (processed transiently for rendering)
US
Apple StoreKit
Subscription payments
Data: Transaction IDs (no financial details shared with us)
US / Global
Resend (US)
Transactional email delivery
Data: Email address, email content
US
Meta Platforms, Inc. (US)
Ad-campaign measurement and install attribution via the Facebook SDK
Data: Anonymised event data (app launch, sign-up, trial start, subscription start), IDFV, IDFA (only with ATT consent), device model, OS version, language, timezone, approximate network info
US
Awin Ltd (UK)
Affiliate-network attribution and commission reconciliation for outbound product links
Data: Pseudonymous click reference (clickref), product ID, timestamp. No name, email, or device identifier is sent. Cookie / IP tracking, if any, is set by the retailer on their own domain via SFSafariViewController, not by GENTIQ.
UK (adequacy decision)
Partnerize (UK)
Affiliate-network attribution and commission reconciliation (where a retailer uses Partnerize)
Data: Pseudonymous click reference, product ID, timestamp. Same scope as Awin.
UK (adequacy decision)
OpenAI: We send wardrobe item descriptions and occasion context to OpenAI’s API for outfit generation. When you use style reference features, the photos you select as style references may also be sent to OpenAI for analysis. We do not send your name, email, or any directly identifying information to OpenAI. Per OpenAI’s API data usage policy, data sent via the API is not used to train their models.
Google Gemini: When you use features that involve face photos (e.g., virtual try-on), your photo may be sent to Google’s Gemini API for processing. These images are processed transiently and are not retained by Google for model training under our API agreement. We do not send your name, email, or other account information alongside these photos.
Supabase: Our primary database is hosted in the EU region (eu-west-1) to ensure your data remains within the European Economic Area.
Affiliate networks (Awin, Partnerize): When you tap a product link marked as “Werbung” / “Advertisement” / “Sponsored” in GENTIQ, we open the retailer’s web page inside an iOS SFSafariViewController. The URL we open contains a pseudonymous click reference (“clickref”) that allows the affiliate network (Awin Ltd, UK; or Partnerize, UK, depending on the retailer) to reconcile a subsequent purchase back to GENTIQ for commission purposes. We do not transmit your name, email, Apple ID, IDFA, IDFV, or any other identifier to the affiliate network. Any cookies or IP-based tracking that occur during the retailer visit are set on the retailer’s own domain, inside SFSafariViewController — not inside GENTIQ — and are governed by the retailer’s and the affiliate network’s own privacy policies. The ranking of our product recommendations is independent of commission rates. Because the United Kingdom benefits from a European Commission adequacy decision, transfers to Awin / Partnerize are treated as transfers within the EEA for GDPR purposes.
Meta Platforms, Inc. (Facebook SDK): We use the Facebook SDK to measure the performance of our own ad campaigns and to attribute app installs. Meta receives anonymised event data (such as app launches, sign-up, trial start, and subscription start) together with device identifiers. If you grant App Tracking permission via the iOS ATT prompt, this includes the IDFA advertising identifier; otherwise only the IDFV (a non-resettable device identifier scoped to GENTIQ) is used, and no cross-app tracking takes place. We do not send Meta your name, email address, face photos, wardrobe photos, or any health, payment, or location data. You can disable Meta ad measurement at any time via iOS Settings → GENTIQ → Privacy → Allow Tracking (or the system-wide Allow Apps to Request to Track toggle). Data transferred to Meta in the United States is protected under the EU-US Data Privacy Framework and, where applicable, Standard Contractual Clauses. Meta’s handling of this data is governed by Meta’s Data Policy (facebook.com/privacy/policy) and the Facebook Business Tools Terms (facebook.com/legal/terms/businesstools); we do not control Meta’s retention periods but, per Meta’s published policy, ad-measurement events are typically retained for up to two years.
7. International Data Transfers
Several of our service providers — including OpenAI, Google, Apple, Resend, and Meta Platforms, Inc. (Facebook SDK) — are based in the United States. Our affiliate-network partners Awin Ltd and Partnerize are based in the United Kingdom, which benefits from a European Commission adequacy decision; transfers to the UK are therefore treated as transfers within the EEA. Where personal data is transferred to the United States or another third country, we ensure appropriate safeguards are in place:
You may request a copy of the applicable transfer safeguards by contacting us at privacy@gentiqclo.com.
8. Data Retention
Account data
Retention: Duration of account + 30 days
Trigger: Account deletion request
Wardrobe photos and metadata
Retention: Duration of account
Trigger: Item deletion or account deletion
Generated outfits and saved looks
Retention: Duration of account
Trigger: Manual deletion or account deletion
Face photos (stored on-device only)
Retention: Until user deletes photo, deletes account, or uninstalls app
Trigger: User action or account deletion
Virtual try-on (Gemini processing)
Retention: Not stored on our servers; not retained by Google beyond active session (seconds)
Trigger: Immediately after rendering
On-device color analysis (skin/hair/eye)
Retention: Stored locally in iOS secure keychain until removed by user
Trigger: User deletes photo or account
Usage analytics
Retention: 12 months (rolling)
Trigger: Automatic expiration
Meta / Facebook SDK ad-measurement events
Retention: Governed by Meta’s Data Policy; per Meta’s published policy, typically up to ~2 years. We do not control Meta’s retention schedule.
Trigger: Meta's own retention policy, or revocation of ATT consent via iOS Settings
Affiliate click logs (clickref, product ID, timestamp)
Retention: 24 months
Trigger: Automatic deletion after the commission reconciliation and accounting window closes
Subscription records
Retention: As required by tax/accounting law (up to 7 years)
Trigger: Legal obligation
When you delete your account, we erase all personal data within 30 days, except where retention is required by law (e.g., financial records for tax purposes).
9. Your Rights
9.1 Rights Under GDPR (EU/EEA Users)
Under the GDPR, you have the following rights:
9.2 Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have additional rights:
9.3 Exercising Your Rights
To exercise any of these rights, contact us at privacy@gentiqclo.com. You may also delete your account directly in the app via You → Settings → Delete Account.
We will respond to all requests within 30 days (or 45 days for CCPA requests, with notice if an extension is needed). We may ask you to verify your identity before processing your request.
9.4 Opting Out of Ad Measurement (Meta / Facebook SDK)
You can stop GENTIQ from sharing the IDFA with Meta at any time by disabling tracking for GENTIQ in iOS Settings → GENTIQ → Privacy → Allow Tracking, or by turning off Settings → Privacy & Security → Tracking → Allow Apps to Request to Track system-wide. After opt-out, GENTIQ will continue to send only minimal, non-IDFA ad-attribution events to Meta under the legitimate-interest basis described in Section 4; to object to that processing as well, contact us at privacy@gentiqclo.com and we will disable the Facebook SDK for your account.
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. If you discover a security vulnerability, please report it to security@gentiqclo.com.
11. Children's Privacy
GENTIQ is not intended for children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@gentiqclo.com.
12. Cookies and Tracking Technologies
GENTIQ is a native iOS application and does not use browser cookies. We do not use fingerprinting, and we do not participate in cross-context behavioural advertising networks.
We do, however, integrate the Meta / Facebook SDK for ad-campaign measurement and install attribution, as described in Section 6. In compliance with Apple’s App Tracking Transparency (ATT) framework, GENTIQ presents the ATT prompt before accessing the IDFA advertising identifier. If you deny the prompt (or disable tracking in iOS Settings), the IDFA is never accessed and no cross-app tracking occurs; only anonymised, app-scoped attribution events tied to the IDFV continue to be sent to Meta under the legitimate-interest basis described in Section 4, and you can object to that processing as described in Section 9.4.
13. Affiliate Links and Partner Referrals
GENTIQ contains affiliate / partner links. When you tap on a product link marked as “Werbung” / “Advertisement” / “Sponsored”, you are redirected to a third-party retailer’s website, opened inside an iOS SFSafariViewController. If you subsequently complete a purchase on that retailer’s site, GENTIQ may receive a commission from the affiliate network or the retailer. This commission comes at no additional cost to you.
The ranking and selection of recommended products in GENTIQ is independent of commission rates. We surface items based on their fit with your colour season, wardrobe, and occasion context — not based on which retailer pays us more.
13.1 What happens when you tap an affiliate link
13.2 Affiliate networks we work with
The United Kingdom benefits from a European Commission adequacy decision; transfers to Awin / Partnerize are therefore treated as transfers within the EEA.
13.3 Legal basis
We process click-attribution data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in receiving accurate commission payments for referrals we generate. The processing is limited to the pseudonymous clickref, product ID, and timestamp — no behavioural profile is built, and no personal identifier is shared with the affiliate network.
13.4 Transparency (DSA / UWG)
In line with the EU Digital Services Act and Austrian / German unfair-competition law, every link for which GENTIQ could receive a commission is clearly labelled as advertising (“Werbung” / “Advertisement” / “Sponsored”) at the point of tap. The commercial relationship between GENTIQ and the respective retailer or network is disclosed in this Privacy Policy and in our Terms of Service.
13.5 Opt-out
You can avoid affiliate tracking entirely by not tapping links marked as advertising. A separate in-app opt-out toggle is not required, because GENTIQ itself does not set personal tracking cookies and does not transmit identifiers to the affiliate network — the entire third-party tracking flow only starts once you have voluntarily opened the retailer’s page.
If you wish to delete the minimal click-log entries GENTIQ stores on its own servers, contact us at privacy@gentiqclo.com and we will erase the records associated with your account, subject to any legal obligation to retain accounting-relevant data.
14. Do Not Sell or Share My Personal Information
We do not sell, rent, lease, or share your personal information with third parties for their own marketing or advertising purposes. This applies to all users regardless of jurisdiction. We have never sold personal information and have no plans to do so. Affiliate commissions we receive from retailers are not a sale of your personal data: no personal identifier is transmitted to the retailer or the affiliate network as part of the referral (see Section 13).
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy within the app and, where appropriate, via email. The “Last Updated” date at the top of this document indicates when the most recent revision took effect. Your continued use of GENTIQ after a change constitutes acceptance of the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:
GENTIQ UG (haftungsbeschränkt)
Attn: Data Protection
Email: privacy@gentiqclo.com
Website: https://gentiqclo.com/privacy-policy
You also have the right to lodge a complaint with the competent supervisory authority. For Austria, this is the Österreichische Datenschutzbehörde (dsb.gv.at). For other EU member states, contact your local data protection authority.
GENTIQ Privacy Policy • Version 1.6 • April 23, 2026 • gentiqclo.com/privacy-policy