MirrelleJoin the beta
Legal

Privacy policy.

Last updated · April 30, 2026

This Privacy Policy explains how Mirrelle (“Mirrelle”, “we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you visit our website at mirrelle.com or use the Mirrelle mobile application (collectively, the “Service”). Please read this policy carefully. By using the Service you acknowledge you have read and understood it.

This document is provided for informational purposes. Consult with a qualified attorney for legal advice specific to your situation.

1. Who we are and how to contact us

Mirrelle is the data controller responsible for your personal data. Our designated contact for all privacy matters is:

We aim to respond to all privacy-related requests within 30 days. For complex requests we may extend this by a further two months and will notify you of any extension.

2. What personal data we collect

2.1 Website visitors

  • Waitlist email address. When you join our waitlist we collect your email address via ConvertKit. You may unsubscribe at any time via the link in any email we send.
  • Analytics data. We collect anonymised or pseudonymised data about how visitors use our website, including pages visited, time on page, referrer, browser type, device type, and approximate geographic region (country/city level). We use this to understand and improve our site.
  • Cookies. We set first-party analytics cookies and, when you click affiliate links, third-party affiliate-network cookies. See Section 10 for details.

2.2 App users (registered accounts)

  • Account information. Your email address, or — if you sign in with Apple — an Apple-issued anonymised email relay address. We also store the date your account was created and the date of your last sign-in.
  • Style profile. Your responses to the onboarding swipe quiz (which looks you liked or skipped), stated budget range, preferred brands, and any free-text style notes you provide. This builds a numeric “style embedding” used to personalise recommendations.
  • Selfie and optional full-body photo. You may upload a selfie (and optionally a full-body photo) so Mirrelle can create your Digital Twin. See Section 3 and Section 4 for how these are handled. These images are stored encrypted at rest in encrypted cloud storage and are deletable by you at any time in one tap from your profile.
  • Digital Twin data. The numeric representations derived from your photos: facial landmarks, estimated skin tone, and estimated body proportions. These are stored as numerical vectors, not as photographs or images. They are used solely to render personalised AI try-on outputs.
  • Generated look history. The AI-generated outfit looks we produce for you, stored so you can revisit them in the app.
  • In-app behaviour. Which products you tapped, saved, or purchased through; look generation requests; subscription status and tier; and crash or error reports.
  • Device and connection data. Device type, operating system version, unique installation ID, push notification token, IP address, and approximate location (country/region) derived from IP. We do not collect precise GPS location.

3. How and why we use your data

  • To provide the Service. Creating and managing your account; processing your uploaded photos to generate your Digital Twin; running the AI stylist pipeline to build personalised outfit recommendations; and rendering virtual try-on (VTO) images.
  • Photo moderation and safety. Every uploaded photo is passed through automated server-side moderation (NSFW content detection and an age estimator) before any other processing occurs. Images that fail moderation are immediately rejected and permanently deleted. We do not store or process images that fail this check.
  • To operate and improve the Service. Diagnosing and fixing bugs; measuring feature performance; conducting A/B tests; and improving the recommendation and generation models (using aggregated, de-identified signals only — your photos are never used to train third-party models without your explicit consent).
  • Marketing communications. Sending you waitlist updates, product launch emails, and (for app users who opt in) personalised style tips and product recommendations. You can opt out at any time.
  • Affiliate commission tracking. Attributing purchases you make through affiliate links to Mirrelle so we can receive the commissions that fund the Service. See our Affiliate Disclosure and Section 10.
  • Legal obligations. Complying with applicable law, responding to lawful requests from authorities, and enforcing our Terms of Service.

4. Special note on your photos and Digital Twin

We treat your uploaded photos with particular care because they contain sensitive biometric-adjacent information. Here is exactly what happens:

  • Upload and transit. Photos are transmitted over TLS (HTTPS) and immediately uploaded to encrypted object storage (Supabase Storage backed by Cloudflare R2).
  • Moderation first. Before anything else, automated moderation checks the photo for nudity and estimates the age of any persons in the image. Photos that fail either check are rejected and deleted immediately — no further processing occurs.
  • Twin extraction. Passing moderation, we extract numeric representations: facial landmark coordinates, a skin-tone vector, and estimated body proportions. These numbers are stored as your “Digital Twin” in our database.
  • Raw photo retention. After twin extraction is complete, the original raw photo is retained in encrypted storage only as long as needed to support re-generation of your twin if you update your profile. It is not used for any purpose other than generating your twin and providing the VTO feature.
  • No advertising use. Your photos and Digital Twin data are never used for advertising targeting, sold to third parties, or shared with affiliate networks. They are not used as training data for any AI model operated by a third party without your explicit, separately obtained consent.
  • Deletion. You can delete your photos and Digital Twin at any time from your in-app profile settings. Deletion is permanent and propagates to all our storage systems within 30 days.

5. Legal bases under GDPR

For users in the European Economic Area (EEA), the United Kingdom, and jurisdictions covered by equivalent data protection law, we process your personal data under the following legal bases:

  • Contract (Art. 6(1)(b) GDPR). Processing your account data, photos, Digital Twin, and style profile is necessary to perform the Service you have signed up for.
  • Legitimate interests (Art. 6(1)(f) GDPR). Analytics, fraud prevention, security monitoring, improving the Service using aggregated signals, and affiliate commission attribution — where these do not override your rights and freedoms.
  • Consent (Art. 6(1)(a) GDPR). Sending marketing emails and setting non-essential cookies (including analytics and affiliate cookies) where consent is required by applicable law. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Legal obligation (Art. 6(1)(c) GDPR). Where processing is required to comply with applicable law.
  • Special category data. Digital Twin data may constitute processing of biometric data in some jurisdictions. Where it does, we rely on your explicit consent (Art. 9(2)(a) GDPR), obtained during app onboarding before you upload any photo.

6. How long we retain your data

  • Account and style profile. Retained for the life of your account, plus 90 days after deletion to allow account recovery, then permanently deleted.
  • Raw uploaded photos. Retained while needed for twin generation and the VTO feature, and deleted when you delete your twin or your account. Maximum retention is 2 years of account inactivity before automatic deletion.
  • Digital Twin vectors. Same retention period as your account. Deleted immediately upon request.
  • Generated looks. Retained for the life of your account and deleted with your account.
  • Waitlist email. Until you unsubscribe, or until we conclude the waitlist program.
  • Analytics data. Aggregated analytics retained indefinitely. Pseudonymised event logs retained for 24 months.
  • Financial records. Transaction records required by law retained for 7 years.

7. Who we share your data with (sub-processors)

We do not sell your personal data. We share it with the following sub-processors solely to operate the Service:

  • Supabase Inc. (United States / EU region) — Postgres database, object storage, and authentication. Data is stored in secure data centres, with EU residency where the provider offers it.
  • Anthropic, PBC. (United States) — Claude AI model used as the “Stylist Agent” that selects products and drafts outfit descriptions. We send only your style profile and product metadata, not your photos or Twin vectors, to Anthropic.
  • Replicate, Inc. (United States) — Machine learning model execution for CLIP-based style embeddings and face restoration. Your Digital Twin vectors and generated looks are processed here.
  • FASHN.ai. (United States) — Virtual try-on rendering: we send your full-body photo or Twin and the selected garment images to generate the try-on preview. Used only to produce your look; not used to train their models.
  • Cloudflare, Inc. (United States / global CDN) — object storage for generated images, Workers edge runtime for our API, DNS, and email routing for our @mirrelle.com addresses.
  • Railway Corp. (United States) — Hosting and delivery for this website (mirrelle.com). Processes only standard web-server request data.
  • ConvertKit, LLC. (United States) — Email delivery for our waitlist and transactional communications. Processes waitlist email addresses.

Planned sub-processors (not yet in use). As the mobile app launches we expect to add analytics (e.g. PostHog), crash reporting (e.g. Sentry), and subscription management (e.g. RevenueCat). We will update this policy and put the required agreements in place before any of them process your personal data.

Before we send production personal data to any sub-processor, we put a Data Processing Agreement (DPA) in place. The current list of sub-processors may be updated as the Service evolves.

We may also disclose personal data to law enforcement or regulatory bodies where required by law, or to protect the rights, property, or safety of Mirrelle, our users, or others.

8. International data transfers

Some of our sub-processors are located in the United States. When we transfer your personal data from the EEA, the UK, or other jurisdictions with equivalent protections to the United States, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our DPAs with each US sub-processor.
  • The UK International Data Transfer Agreement (IDTA) for transfers from the United Kingdom.
  • Where available, sub-processor certification under the EU-US Data Privacy Framework (DPF).

Wherever possible, we configure our sub-processors to store and process EU/UK user data within European data centres.

9. Your rights

Depending on where you live, you may have the following rights in relation to your personal data. To exercise any of these rights, contact us at privacy@mirrelle.com.

9.1 Rights under GDPR (EEA and UK users)

  • Right of access. You may request a copy of the personal data we hold about you.
  • Right to rectification. You may ask us to correct inaccurate data or complete incomplete data.
  • Right to erasure (“right to be forgotten”). You may ask us to delete your personal data. Deletion of your account from the app settings page exercises this right automatically.
  • Right to data portability. You may request a machine-readable export of the personal data you have provided to us.
  • Right to object. You may object to processing based on legitimate interests (including profiling for recommendations) or for direct marketing.
  • Right to restriction. You may ask us to restrict processing of your data in certain circumstances, for example while a dispute about accuracy is resolved.
  • Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of prior processing.
  • Right to lodge a complaint. You have the right to lodge a complaint with your local supervisory authority. In the UK: the Information Commissioner's Office (ico.org.uk). In the EU: the supervisory authority in your member state.

9.2 California rights under CCPA/CPRA

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know. You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
  • Right to delete. You may request deletion of your personal information, subject to certain exceptions.
  • Right to correct. You may request correction of inaccurate personal information.
  • Right to opt out of sale or sharing. Mirrelle does not sell your personal information and does not share it for cross-context behavioural advertising purposes. There is nothing to opt out of, but you may contact us at privacy@mirrelle.com to confirm this.
  • Right to limit use of sensitive personal information. You may request that we limit use of your sensitive personal information (including biometric data such as your Digital Twin) to uses that are necessary to provide the Service.
  • Right to non-discrimination. We will not discriminate against you for exercising any of your CCPA rights.

To exercise CCPA rights, submit a verifiable consumer request to privacy@mirrelle.com. We respond within 45 days (extendable by a further 45 days where reasonably necessary).

10. Cookies and affiliate cookies

When you visit mirrelle.com we may set the following types of cookies:

  • Strictly necessary cookies. Required for the website to function (e.g., security tokens, session identifiers). These cannot be disabled.
  • Analytics cookies. If and when we add a website analytics provider, these will measure website usage, and will be set only with your consent where required by law.
  • Affiliate-network cookies. Set by affiliate networks (Awin, Impact, ShareASale, Rakuten Advertising, Amazon Associates, and direct merchant programs) when you click an affiliate link. These allow us to be credited for any resulting purchase. See our Affiliate Disclosure for a full explanation of how affiliate tracking works.

You can manage or disable non-essential cookies via your browser settings. Disabling affiliate cookies means purchases you make through our links will not be attributed to us.

11. Children and age restriction

The Service is rated 17+ and is intended for users aged 17 and over. We do not knowingly collect personal data from anyone under the age of 17. Onboarding requires a self-attestation of age. If our automated moderation identifies that an uploaded photo may contain a minor, the photo is immediately rejected and deleted, and the account may be suspended pending review.

If you believe we have inadvertently collected data from a person under 17, please contact us immediately at privacy@mirrelle.com and we will delete that data promptly.

12. Security

We implement technical and organisational measures appropriate to the risk of processing, including: TLS encryption in transit; AES-256 encryption at rest for stored photos and Twin vectors; access controls and least-privilege policies for all staff with data access; and regular security reviews. No method of transmission over the internet is completely secure; we cannot guarantee absolute security but we take our obligations seriously.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by updating the “Last updated” date at the top of this page and, where required by law, by sending a notice to your registered email address or displaying a prominent in-app notification before the change takes effect.

Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you should delete your account and stop using the Service.

14. Contact us

For all privacy-related enquiries, data access or deletion requests, or complaints: