1. IntroductionWelcome to the
Dressie AI Privacy Policy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the Dressie AI service (“Service”). We are committed to protecting your privacy and handling your personal information in an open and transparent manner.
Scope: This policy applies to all users of Dressie AI worldwide, including those who access the Service via our website or through third-party platforms such as the Dressie AI bot on
Telegram. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our practices, please do not use Dressie AI.
Who We Are: When this policy mentions “Dressie AI,” “we,” “us,” or “our,” it refers to the operator of the Dressie AI service. Dressie AI is operated by a company registered in the
Russian Federation. For purposes of data protection laws (like the EU’s GDPR), we act as the “data controller” of your personal data, which means we determine how and why your personal data is processed. Our contact information is provided at the end of this policy.
We may update this Privacy Policy from time to time (see Section 9 on Changes). We will notify you of any significant changes by posting the new policy on this page and updating the “Last Updated” date. We encourage you to review this policy periodically.
2. Information We CollectWe aim to collect
only the minimal personal data necessary to provide our Service. The following are categories of information we collect:
2.1 Personal Data You Provide Directly-
Username: When you use the Service, we may ask you to provide a username or handle. If you are using the Dressie AI Telegram bot, this may be your Telegram username. This identifier is used to keep track of your requests (orders) and to enable certain features (like retrieving your generated images or usage history). We do not require you to provide your real name, email address, or other contact details just to use the core Service. (If you choose to provide an email for support or create a full account when that feature is available, we will collect it, but that’s optional.)
-
Photos and Images: In order to use the virtual try-on feature, you will need to upload a photograph (or send it via Telegram) that you want to see clothing on. This photo
may be a personal photo of you or another image you choose to use. These photos are considered personal data when they depict an identifiable person (such as your face). We only use these photos to generate the requested output image and do not use them for any other purpose unless explicitly stated. Importantly, as described below, we do not store your uploaded photos beyond the processing period required.
-
Payment Information: If you make a purchase or payment through Dressie AI, you will provide payment details. Payment transactions are handled by third-party payment processors (e.g., credit card companies or payment platforms). We do not collect or store your full financial account details (such as full credit card numbers). We may receive a confirmation of payment and basic billing information from the payment processor (for example, that a certain amount was paid, and an order ID, along with your username or transaction reference). In some cases, we might collect limited billing information to comply with financial record-keeping (such as an email or billing address if required for invoicing or tax purposes), but we do not store sensitive payment data on our servers.
-
Communications: If you contact us directly (for example, by emailing support or sending a message for help), we will receive the information you provide in the communication. This may include your name, email address, the content of your message, and any attachments. We will use this information to respond to you and resolve any issues. Providing contact information for support inquiries is optional and will be used only for assistance and internal record-keeping.
2.2 Data We Collect AutomaticallyWhen you use the Dressie AI website (or any online service interface we provide), we may automatically collect certain information about your device and usage of the Service (“Usage Data”). This information may include:
- Device and Log Information: We may collect details such as your device type, operating system, browser type, and system configuration. We also log information about your use of the Service, such as the pages or features you access, the time and date of each request, and how you interact with various elements of our Service. For example, our servers may record a log when you perform an image generation or if you encounter an error.
- IP Address: We record the Internet Protocol (IP) address of your device when you connect to the Service. An IP address can indicate your general location (country, city, region) and is used primarily for security and fraud prevention (for instance, to detect and prevent malicious use of our Service). We do not use IP addresses to identify you as an individual, but under data protection laws, IP addresses can be considered personal data. We treat them with care and only use them as necessary to maintain and protect our Service.
- Cookies and Similar Technologies: We may use cookies, web beacons, or similar tracking technologies to provide and improve our Service experience. For instance, cookies might be used to keep you logged in (if we offer login sessions), to remember your preferences, or to collect analytics about how users navigate our site. These cookies typically do not collect personal information beyond what is described above (they might capture device identifiers or session tokens). You can control or disable cookies through your browser settings, but note that some parts of our Service might not function properly without them. We do not use cookies for advertising purposes on our Service at this time.
2.3 Information from Third-Party SourcesWe primarily collect data directly from you, but if you use a platform like Telegram to access Dressie AI, we may receive certain information through that platform’s API. For example, when you interact with the Dressie AI Telegram bot, we might receive:
- Your Telegram user ID and/or username, which we use to send responses back to you.
- The contents of messages you send to the bot (which includes the photos and commands for generation).
- Basic profile information that Telegram might provide to bots (this can include your display name or profile photo, though we do not actively store or use that info except as needed to identify your account in Telegram for replying).
We treat any information received from Telegram in line with this Privacy Policy. However, remember that your use of Telegram is also subject to Telegram’s own privacy policy and terms. We encourage you to review those if you have concerns, as Telegram is a third-party service beyond our control.
We do not purchase or obtain personal data from data brokers or third-party marketing lists. In the future, if we integrate with other services (for example, allowing login via Google/Facebook), we will update this policy to reflect any data we receive from those services.
3. How We Use Your InformationDressie AI uses the collected information for the following purposes, and we ensure we have a valid legal basis for each use (as outlined in Section 4 below):
- To Provide and Operate the Service: First and foremost, we use your data to deliver the Service you expect. For example, we use your uploaded photo to generate a virtual try-on image with the clothing you’ve selected. We use your username to keep track of your requests and to return the results to the correct user. We might use your device and log info to ensure the Service is displayed correctly and functioning on your device.
- To Process Transactions: If you pay for image generations or subscriptions, we use necessary information to process that transaction. This includes working with third-party payment processors, confirming payments, and providing you with the product or credit you purchased. We may also use purchase history (linked to your username or account) to manage usage limits (e.g., how many generations you have left if you bought a package) and to provide customer support related to billing.
- To Communicate with You: We may use your provided contact information (if any, such as an email for support) to respond to your inquiries, send you confirmations or alerts (for example, confirming a successful payment or notifying you when a generation is complete if such notification service exists). If you opt-in to any communications (like a newsletter or updates, though we currently do not send marketing emails by default), we would use your contact info for that purpose until you opt out.
- To Maintain & Improve the Service: We internally analyze how users interact with Dressie AI in order to improve the Service. For example, we might look at aggregated usage data to detect popular features or points where users drop off, which helps us improve the user interface. Technical data (like errors or logs) are used to troubleshoot problems, monitor performance, and increase the reliability and effectiveness of our algorithms and website. In some cases, we may use anonymized or aggregated data derived from user interactions or generated outputs to refine our AI models and improve clothing fit accuracy. Importantly, if we ever use data for AI training or improvement, we will anonymize and de-identify it first, so that it cannot be linked back to any individual user (e.g., stripping images of personal identifiers or facial features).
- To Enforce our Terms and Prevent Misuse: We use information (particularly usage data and automated monitoring) to detect, investigate, and prevent fraudulent transactions, spam, misuse of the Service (such as users violating the content rules in our Terms of Service), or security incidents. For instance, if we detect a single IP address making an unusually high number of generation requests in a short time, we might flag that for potential abuse (like an automated bot) and take action. Similarly, if a user uploads illegal content, we may use data to block that user and report the incident as required.
- For Legal Compliance: We may process your personal information as required by applicable laws and regulations. For example, keeping transaction records for financial regulations or responding to lawful requests by government authorities. Additionally, if necessary, we will use or disclose information to protect our rights, privacy, safety, or property, and/or that of our users or others – this could include releasing information to law enforcement if a situation poses a threat or as required by law.
We will not use your personal data for fully automated decision-making with legal or similarly significant effects on you without providing you with an opportunity for human review. The generation of images by our AI is automated, but it does not have legal effects on you – it’s purely a service you request. We do not profile users for advertising or other such purposes at this time.
4. Legal Bases for Processing (GDPR-specific)If you are located in the European Economic Area (EEA), United Kingdom, or another region with similar data protection laws, we are required to inform you of the legal bases we rely on to process your personal data. We typically rely on one of the following grounds:
- Contractual Necessity: When you request our Service (e.g., upload a photo for generation or make a purchase), we process your personal data in order to fulfill our contract with you and provide the Service you have asked for. For example, processing your photo and username to generate an output, or using your payment information to complete a transaction, is based on the contract between us (the Terms of Service, which you agree to by using the Service). Without this data, we cannot perform the core functions of our Service.
- Consent: In certain cases, we rely on your consent. For instance, by uploading a photo (which can be sensitive personal data if it shows your face), you consent to us processing that photo for the purpose of creating the try-on image. You also consent to us using cookies as described and to handling any optional data you provide (like if you sign up for a newsletter or share a testimonial, we would do so with your consent). Where we rely on consent, you have the right to withdraw it at any time (for example, you can delete your photo or stop using the Service, and you can disable cookies). Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
- Legitimate Interests: We may process your data as necessary for our legitimate interests, provided those are not overridden by your data protection rights. Our legitimate interests include maintaining the security of our Service, improving our product, and understanding how users engage with Dressie AI. For example, using IP addresses to prevent fraud, or analyzing usage patterns to improve the user experience, are actions based on our legitimate interest in running a secure and effective service. When we rely on this basis, we ensure that our interests are balanced with your rights – for instance, we anonymize data where feasible to mitigate privacy impact.
- Legal Obligation: We will process personal data if necessary to comply with a legal obligation to which we are subject. For example, retaining payment records for the period required by financial regulations or providing information to authorities if legally compelled (such as responding to a court order).
If we ever need to process sensitive personal data (like biometric information from photos) under GDPR definitions, and it’s not covered by your explicit consent or contractual necessity, we will ensure an additional legal basis applies (GDPR has certain conditions for sensitive data processing, such as if it’s manifestly made public by you or necessary for legal claims, etc.). Our intention, however, is to avoid sensitive data processing beyond the scope of your direct requests with consent (uploading your photo is a form of consent for that processing).
5. Data Storage and RetentionWe retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Below we outline our retention practices for different types of data:
- User Photos: Photos or images that you upload for virtual try-on are stored temporarily only for the duration of the image generation process. In practice, this means your photo is held in memory or short-term storage while our servers apply the AI model to it. Once the process is complete and the output image is generated (and delivered to you), we delete or irreversibly anonymize the uploaded photo. We do not keep a personal copy of your original photo on our servers after fulfilling your request. In some cases, a processed version of the image (with the clothing applied) may be stored for a short period (for example, cached for a few hours or days) to allow you to download it or to ensure service reliability, but this output image typically does not contain any more personal data than the original photo you provided. We will remove generated images from our servers after they are delivered or after a short retention window, unless you specifically save them in an account area (if such a feature is provided in future). Any temporary caching is purged regularly.
- Username and Basic Account Info: Your username and any associated usage records (like what images you generated, time stamps, or credits balance) are kept in our database to allow your ongoing use of the Service. We retain this information until it is no longer needed to provide the Service or until you request its deletion. Because we don’t collect much personally identifiable info, your username alone (which could be a pseudonym) might be kept indefinitely as an identifier in our system, unless you ask us to remove it or if we choose to purge inactive user data. If you request deletion of your data (see Section 8 on Your Rights), we will remove or anonymize the username in our records such that it can no longer be linked to you.
- Payment and Transaction Data: We retain transaction records (e.g., that a certain user purchased a certain package at a given time) as long as needed for accounting and compliance. Typically, financial records are kept for a minimum period as required by law (e.g., for tax or bookkeeping rules, often 5-7 years depending on jurisdiction). However, this data is kept secure and limited to what is necessary (we don’t store full card numbers, etc.). If you delete your account or username, we may still retain transaction records associated with an internal identifier for the legally required period, but we will dissociate them from your personal identity as much as possible.
- Logs and Technical Data: Server logs, which may include IP addresses and device information, are generally retained for a short period (a few weeks to a few months) for routine maintenance, analysis, and security monitoring. We may retain logs longer if investigating a security incident or to comply with legal requirements. Log data that are retained longer will be anonymized if used for long-term analytics.
- Communications: If you contacted us via email or other channels, we may retain those communications for a period of time to ensure we have a history of support requests (which can help in providing better service if you contact us again) and to improve our support processes. These communications will be retained as long as necessary for those purposes, typically not more than a couple of years, unless needed for legal purposes (e.g., if there’s a dispute we need to document).
- Anonymized Data: Any data that we anonymize (e.g., using portions of images to improve our AI that cannot be linked to an individual) may be retained indefinitely, since it contains no personal information and is solely used for improving our technology and service offerings.
Once the retention period expires or the purpose is achieved, we will securely delete or anonymize the personal data, so that it can no longer be attributed to an individual. For example, we may delete a username and its history from our live databases and retain only aggregate information. Do note that removal from backups may take additional time – if we have database backups, the data might remain encrypted in backup storage until those backups cycle out, but we have processes to ensure that deleted data isn’t easily recoverable or used from backups aside from restoration scenarios.
6. How We Share Your InformationDressie AI does not sell or rent your personal information to third parties for their own marketing purposes. We only share information in the following circumstances, and always in accordance with appropriate safeguards and legal requirements:
- Service Providers and Partners: We employ trusted third-party companies and individuals to help us operate and enhance the Service – for example, cloud hosting providers (to store and process data), payment processors (to handle billing), and technical partners (such as providers of AI computing infrastructure). These third parties may have access to your personal data only to perform tasks on our behalf and are contractually obligated not to disclose or use it for any other purpose. For instance, our cloud provider stores the data on secure servers and our payment processor handles your credit card transaction details. We ensure that these providers implement appropriate data protection measures. (For transparency, some typical providers might include services like Stripe for payments or cloud services like AWS/Google Cloud for hosting, but the specific providers can change. We can furnish a list of sub-processors upon request.)
- Telegram and API Integration: If you use the Service via Telegram, some of your data passes through Telegram’s systems (e.g., your messages and photos are sent to the Telegram bot, then to us). Telegram as a platform has its own access to that data as part of facilitating the message exchange. We do not control Telegram’s use of the data in transit; however, Telegram generally does not permanently store media sent through bots beyond a limited time and has its own privacy guarantees. We share responses (output images or messages) back to you through Telegram’s API. No other third-party (besides Telegram itself) receives your Telegram data from us.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court, regulatory agency, or law enforcement). For example, if we receive a subpoena or another legal demand for data and we are legally compelled to comply, we will provide the requested information. We will attempt to notify you of such requests when permissible, and we will only disclose what is strictly necessary. Additionally, we may disclose information that we believe, in good faith, is appropriate or necessary to (i) enforce our Terms of Service and other agreements, (ii) investigate or protect against harm to our rights, property or safety, or that of our users or the public, (iii) detect, prevent, or address fraud or security issues, or (iv) comply with an emergency that we believe in good faith requires us to disclose data to help prevent a death or serious bodily injury.
- Business Transfers: If Dressie AI or our company is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of that transaction. We will ensure that any such transfer is subject to confidentiality arrangements and that the successor organization continues to be bound by this Privacy Policy or one with comparable protections. You will be notified via a prominent notice on our website or via email of any change in ownership or uses of your personal data, as well as any choices you may have regarding your personal data in that event.
- Aggregated or Non-Identifiable Data: We may share aggregated information or information that does not identify you (such as statistical data about how many users tried on a particular outfit, or general usage patterns) with third parties for analysis, research, or promotional purposes. For example, we might publish trends about usage (e.g., “X% of users try more than 5 outfits per session”). Such information will not contain any personal data and cannot be linked back to you.
No Sharing for Advertising: We do not currently share your personal data with advertisers or ad networks. We do not sell or disclose personal information to third parties for purposes of targeted advertising or any “monetary or other valuable consideration” under relevant laws like CCPA. If this ever changes, we will update this policy and provide any necessary opt-outs.
Third-Party Links: The Service may contain links to third-party websites or services (for example, a link to a clothing retailer if you want to buy a product you tried on virtually). If you click on a third-party link, you will be directed to that third party’s site. We are not responsible for the content or privacy practices of those external sites or services. We encourage you to review the privacy policies of every site you visit. This Privacy Policy applies solely to data collected by Dressie AI for our own Service.
7. International Data TransfersDressie AI is based in Russia, and our servers and operations are primarily located in the Russian Federation. If you are using the Service from outside Russia, be aware that your personal data will be transferred to and processed in Russia (and potentially in other countries if our service providers operate in different jurisdictions, such as servers in the European Union or United States).
Data Protection Laws: Different countries have different data protection laws. Russia’s laws and the laws of other countries may not be equivalent to those in your home jurisdiction. For example, if you are an EU citizen, personal data transferred to Russia is not covered by an EU “adequacy decision,” which means the European Commission has not determined Russia’s data protection laws to be equivalent to EU standards. However, we want to assure you that regardless of where your data is processed, we will handle it with care and implement appropriate safeguards to protect it.
Safeguards: When we transfer personal data out of the EU/EEA or other regions with strict data protection laws, we rely on mechanisms such as:
- Your Consent: In many cases, by using our Service and providing information, you are consenting to the transfer of your personal data to Russia and other jurisdictions as necessary. For example, if you are in the EU and you upload a photo for processing, you understand your data will be processed on servers likely outside the EU (in Russia) to fulfill your request.
- Contractual Measures: We may use standard contractual clauses (SCCs) or similar contractual protections approved for use by the European Commission (or relevant authority) when engaging service providers in countries without adequacy decisions. These clauses contractually obligate the recipient of the data to protect it according to standards comparable to EU law.
- Technical Protections: We use encryption and other security measures (described in Section 8) that provide an additional layer of protection during transfer and storage. For instance, data in transit between your device and our servers is encrypted via HTTPS, which helps protect it from interception.
- Minimization: We minimize the personal data we collect and store as an additional way to mitigate privacy risks. By not storing your photos long-term and only keeping a username, the sensitivity of any transferred data is reduced.
Compliance with Russian Laws: Our operations in Russia also comply with Russian data protection regulations (such as Russia’s Federal Law on Personal Data No. 152-FZ). We ensure that local requirements for data handling (for example, obtaining consents, local storage requirements for Russian citizens’ data, if applicable, etc.) are met. For users outside of Russia, we treat the data under the principles outlined in this policy, which often go beyond what local Russian law might strictly require, in order to align with international standards like GDPR.
By using Dressie AI, you acknowledge that your information will be transferred to our facilities and those third parties with whom we share it as described in this Privacy Policy, which may be located in countries other than your own. We understand this can be important, and we are happy to address any specific questions you might have about international data transfer – feel free to contact us (Section 11) if you need more information.
8. Your Rights and ChoicesWe respect your rights to your personal data. Depending on your jurisdiction (e.g., if you are in the EU/EEA, UK, California, or other regions with data privacy laws), you may have some or all of the following rights regarding the personal data we hold about you:
8.1 Rights Under GDPR (for EU/EEA and Similar Jurisdictions)If you are in the European Union, EEA, UK, or a country with similar data protection laws, you have the following rights with respect to your personal data:
- Right to Be Informed: You have the right to be informed about how we collect and use your personal data (which is the purpose of this Privacy Policy).
- Right of Access: You have the right to request a copy of the personal data we hold about you. We will provide you with a copy of the data in a commonly used electronic form, unless doing so would adversely affect the rights and freedoms of others. For example, you can ask us to confirm if we are processing your personal data and to provide certain information about the processing (the categories of data, purposes, recipients, storage period, etc.), as well as a copy of your data.
- Right to Rectification: If any of your information is inaccurate or incomplete, you have the right to ask us to correct or update it. For instance, if you have a username that you want to change or if you provided an email for contact and it’s wrong, we will update it upon your request.
- Right to Erasure (Right to be Forgotten): You have the right to request the deletion of your personal data, particularly if it’s no longer necessary for us to retain it, or if you have withdrawn your consent (in cases where consent is required). This is not an absolute right – we may need to retain certain information for legal reasons (e.g., transaction records as mentioned) – but we will honor this right to the fullest extent possible. In practice, because we store very limited personal data, fulfilling a deletion request often means removing your username and any associated data from our systems.
- Right to Restrict Processing: You can ask us to restrict (temporarily halt) the processing of your personal data under certain circumstances – for example, if you contest the accuracy of the data, or if you want to restrict processing while an objection to processing is being considered. When processing is restricted, we can still store your data but not use it further until the issue is resolved (except for certain things like legal claims or protecting others’ rights).
- Right to Data Portability: You have the right to obtain your personal data from us in a structured, commonly used, and machine-readable format, and to have that data transmitted to another controller where technically feasible. This applies to personal data you have provided to us and which we process by automated means based on your consent or a contract. Given the limited data we have (perhaps just a username and usage history), we will provide such data in a simple format (like a CSV or JSON file) upon request.
- Right to Object: You have the right to object to our processing of your personal data in certain situations. You can object to processing based on legitimate interests if you believe it impacts your rights (unless we have compelling legitimate grounds that override your rights). You also have the absolute right to object to any direct marketing (though we currently do not do any direct marketing). If you object, we will stop processing your personal data unless we have overriding legitimate grounds or it’s needed for legal reasons.
- Right related to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects on you. As noted, Dressie AI’s image generation does not have such effects on you – it’s a service output you request. We do not use automated decision-making to, for example, approve or deny a loan or something with legal effect. Therefore, this right is generally not applicable in the context of Dressie AI, but we include it here for completeness.
To exercise any of these rights, please contact us using the information in Section 11 (“Contact Us”). We will respond to your request as soon as possible, and at least within the legally required timeframes (under GDPR, typically within 1 month, extendable to 3 months for complex requests – we will inform you if an extension is needed). We may need to verify your identity before fulfilling certain requests (to ensure that we don’t disclose data to the wrong person or delete the wrong account). This may involve asking for additional information or proof of identity. We will honor your rights free of charge, except in cases of manifestly unfounded or excessive requests (in which case we may charge a reasonable fee or refuse the request, but we would provide our reasoning in such case).
If you believe we have not addressed your data protection concerns adequately, you have the right to lodge a complaint with your local Data Protection Authority (DPA). For example, if you are in the EU, you can contact the supervisory authority in your country. We would, however, appreciate the chance to deal with your concerns first, so we invite you to contact us with any complaint and we will do our best to resolve it.
8.2 Rights Under CCPA (for California Residents)If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA, effective January 2023) provide you with specific rights regarding your personal information (collectively referred to here as “CCPA” rights). These include:
- Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell. This includes the specific pieces of information we have collected about you, the categories of sources of that information, the business purpose for collecting it, and the categories of third parties with whom we share it. Much of this is outlined in this Privacy Policy. You can also request the specific personal data we have about you (which is similar to the Access right above).
- Right to Delete: You have the right to request that we delete personal information we have collected from you (and direct our service providers to do the same), subject to certain exceptions. For example, we may retain information needed to complete a transaction, detect security incidents, comply with legal obligations, or other exceptions allowed by law. As noted, we already minimize our data retention, but if you send a deletion request, we will delete the personal data we have unless an exception applies.
- Right to Correct: Under CPRA, California residents also have the right to request correction of inaccurate personal information, similar to the rectification right described above.
- Right to Opt-Out of Sale or Sharing: The CCPA gives you the right to opt-out of the “sale” of your personal information (as defined by CCPA) and the sharing of your personal information for cross-context behavioral advertising. Note: Dressie AI does not sell personal information, and we do not share your personal information for cross-context behavioral advertising purposes. Therefore, there is no need for you to opt out, as we don’t engage in those practices. If that ever changes, we will provide a “Do Not Sell or Share My Personal Information” link or mechanism on our website as required by law.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. This means we won’t deny you service, charge you a different price, or provide a different level or quality of service just because you exercised your privacy rights. However, do note that if the exercise of your privacy rights limits our ability to process data (for example, if you ask us to delete all your data), we may not be able to provide you with certain services that rely on that data. But we will never punish you with lesser service just for making a privacy request.
To exercise your California privacy rights, you (or an authorized agent acting on your behalf) can submit a request to us via the contact methods in Section 11. We may need to verify your identity (for example, by confirming information we already have, or in some cases asking for additional proof) before fulfilling a CCPA request. For requests to know or delete, we will acknowledge receipt within 10 days and aim to respond within 45 days (which can be extended by another 45 days if needed, with notice to you).
Shine the Light: Separately from CCPA, California’s “Shine the Light” law allows users who are California residents to request certain information about our disclosure of personal information to third parties for their direct marketing purposes. Dressie AI does not share personal information with third parties for their own direct marketing purposes without your consent, so this is generally not applicable. But if you have questions about any such potential sharing, you can contact us for clarification.
8.3 Other Region-Specific Rights:If you reside in other regions (e.g., Canada, Australia, Brazil, etc.), you may have similar rights under your respective data protection laws (PIPEDA, Australian Privacy Act, LGPD, etc.). We aim to honor privacy rights universally. For example, even if you’re not in the EU or California, if you request a copy of your data or deletion, we will do our best to accommodate it in line with the principles described above. Feel free to reach out with any privacy-related requests or questions, regardless of your location.
8.4 Managing Your Information and Preferences:- Accessing and Updating: If you have an account interface on our Service, you might be able to view or edit certain personal data directly (for example, change your username if the system permits). For anything not accessible in your account, just contact us and we can update or provide the information.
- Deleting Your Data: As described, you can ask us to delete your personal data. Additionally, if you simply stop using the Service and want to ensure we delete any residual data, please contact us with that request. Because we don’t have a lot of identifiable data, often this will mean anonymizing your username or erasing any reference to it in our systems (except data we must keep for legal reasons).
- Withdrawal of Consent: If we rely on consent for any part of processing (for example, using your photo, sending marketing emails, etc.), you can withdraw that consent at any time. In practice, if you no longer want us to process your photos, you simply wouldn’t upload new ones and you can ask us to delete any that might still be in processing (though as noted, we delete them quickly anyway). For cookies, you can adjust your browser settings. For any optional communications, you can use the unsubscribe mechanism or contact us to opt out.
- Do Not Track: Some browsers have “Do Not Track” features. Our Service does not currently respond to “Do Not Track” signals in a different way from normal requests, because there is not a consensus on what “Do Not Track” means in a regulatory sense. However, we limit our tracking to what’s described (we don’t do cross-site tracking or advertising profiling). You can always block cookies or scripts via your browser if you want to limit tracking.
9. Data SecurityWe take the security of your personal data seriously and use a variety of technical and organizational measures to protect it. However, no system can be 100% secure, so we want to be transparent about how we safeguard your data and the residual risks.
Security Measures Implemented:
- Encryption: We use encryption protocols to protect data in transit and at rest. For example, any data transmitted between your device and Dressie AI is protected by HTTPS (TLS encryption). This means that the photos you upload and the results we send back are encrypted during transfer, reducing the risk of interception. Additionally, sensitive data stored in our databases (if any) is encrypted at rest, and access to those databases is restricted.
- Access Controls: Access to personal data within our organization is limited on a need-to-know basis. Our team members and any contractors are bound by confidentiality obligations. Administrative access to systems that contain personal data requires authentication (such as strong passwords, 2-factor authentication, keys) and is limited to authorized personnel. We regularly review who has access to what.
- Secure Infrastructure: We use reputable cloud service providers with robust security practices. These data centers implement their own physical and network security measures (including firewalls, intrusion detection systems, etc.). We keep our software and systems updated with security patches to protect against known vulnerabilities.
- Testing and Monitoring: We periodically test our Service for security vulnerabilities, both internally and via third-party security tools or audits. We monitor our systems for potential intrusion attempts or anomalies. In addition, if we integrate third-party components (like libraries or APIs), we ensure they are trusted and check for any known security issues.
- Data Minimization: As repeated, one of the best security measures is to hold less personal data. By not storing photos long-term and keeping minimal user information, we inherently reduce the risk exposure. Attackers cannot steal what we don’t have. Similarly, we avoid collecting highly sensitive data altogether.
- Backup and Recovery: We maintain backup routines for critical data (like user account info or transaction records) to ensure resilience. Backups are encrypted and secured. In case of any data loss or corruption, we have the ability to restore from backups.
No Guarantee: While we implement these measures and strive to protect your data, we cannot guarantee absolute security. No Internet, email, or cloud storage transmission is ever completely secure or error-free. You should also do your part by using unique, strong passwords for any accounts (if account creation is involved) and by keeping your own devices secure. If you suspect any security vulnerability or incident related to Dressie AI, please notify us immediately so we can take action.
Data Breach Procedures: In the unlikely event of a data breach that affects your personal data, we will act promptly to mitigate the damage. This includes identifying and fixing the vulnerability, and notifying affected users and relevant authorities as required by law. If a breach is likely to result in a high risk to your rights and freedoms (in GDPR terms), we will inform you without undue delay with the details of the data involved and recommendations for your protection. Our incident response plan is designed to handle such situations methodically.
10. Children’s PrivacyDressie AI is not intended for children under the age of 13. We do not knowingly collect or solicit personal information from anyone under 13 years of age. In fact, our Terms of Service require that users be at least 18 (or 13+ with parental consent as a minimum), so children under 13 should not use our Service or provide any personal data.
If you are under 13, please do not attempt to use Dressie AI or send any information about yourself to us, including your name, photo, or other personal information. If we learn that we have inadvertently collected personal data from a child under 13, we will delete that information promptly.
For teens between 13 and 18: We assume that any minors in this age range will use our Service only with parental permission and under supervision as outlined in our Terms. We encourage parents or guardians to be aware of and monitor their teenagers’ online activities. If you are a parent or guardian and you discover that your child under 18 has used Dressie AI without your consent, or if your child under 13 has provided personal information to us, please contact us. We will take steps to remove the data and (if under 13) terminate the child’s access to the Service.
We also do not knowingly use any user’s data for profiling or marketing to children. Because our service deals with photos, we urge all users: do not upload photos of minors unless you are the parent/guardian or have consent – this is part of our acceptable use policies for the Service, to protect children’s privacy.
11. Changes to this Privacy PolicyWe may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will not reduce your rights under this Privacy Policy without your consent. Any update will be indicated by a change in the “Last Updated” date at the bottom of this document.
If changes are significant, we will provide a more prominent notice, for example by posting a notice on our website’s homepage or alerting you within the Service (or via email, if you’ve provided one) prior to the change becoming effective. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
By continuing to use Dressie AI after any updates become effective, you agree to be bound by the revised Privacy Policy. If you do not agree to the changes, you should stop using the Service and can request us to remove your data as described above.
12. Contact UsIf you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us. We are here to help and address any issues you might have about your privacy.
Contact Information:
- Email:
dressie.app@gmail.com (for privacy inquiries or to exercise any of your rights, please email us – this is our dedicated privacy contact)
- Support: https://t.me/dressie_ai (for general questions or support related to the Service)
- Mailing Address: LLC "INTELLECTUAL SOCIAL SYSTEMS", 117105, Russia, Moscow, st. Novodanilovskaya naberezhnaya, 4A. (Please note this is our registered business address; for fastest response, use email.)
When contacting us about your personal data, please provide sufficient information for us to verify your identity (if applicable) and to locate your records (e.g., your username, the platform you use to access Dressie AI, and the nature of your request). We will respond as promptly as possible, and in any event within any timeframes required by law.
Thank you for trusting Dressie AI with your photos and personal data. We are committed to safeguarding your privacy and providing a secure, enjoyable experience. If you have any feedback or suggestions regarding privacy or any other aspect of our Service, we welcome your input. Your comfort and confidence in using Dressie AI are important to us.
Last Updated: 09/05/2025