Your original upload is temporary. Your generated looks are private. New outfit images stay in your account until you delete them. We use Google for sign-in, Stripe for checkout, and Cloudflare, Vercel, and OpenAI to run the studio. We do not use advertising trackers.
1. Who is responsible
The controller responsible for personal data processed by Lookremix is:
Theo FuhrmannMoltkestraße 25
40477 Düsseldorf
Germany
lookremix@avayne.de
+49 174 6386022
This notice covers lookremix.app and its studio, accounts, library, and purchases. See also our imprint.
2. Visiting the site and keeping it secure
Cloudflare hosts and delivers the site. Its infrastructure processes connection and device information such as your IP address, request URL, time, browser information, and response status. Our application logs record route names, status codes, duration, environment, and limited error categories. They do not intentionally contain photo content, preference text, passwords, OAuth codes, or session tokens. See Cloudflare’s privacy policy for its infrastructure processing.
Sign-in and generation limits use pseudonymous identifiers derived from an IP address or account ID, with short-lived counters. This supports reliable delivery, abuse prevention, and troubleshooting, based on our legitimate interest in a secure, functioning service (Article 6(1)(f) GDPR).
3. Your Google account
When you choose Google sign-in, Google provides a stable account identifier, display name, verified email address when available, and profile-picture URL. We store these with your Lookremix account and create a protected session. We do not receive your Google password or request access to Gmail, contacts, or Drive. Access tokens used to obtain your profile are not saved in our account database.
Your browser may contact Google to display your profile picture. Google processes sign-in activity under its own privacy policy. We use account information to provide the account, private library, and credit balance you request (Article 6(1)(b) GDPR).
4. Photos, preferences, and AI generation
When you generate a look, we process the uploaded photo, chosen style, optional preference or occasion text, and requested number of images. Cloudflare validates and transforms the reference, removing embedded image metadata from the version sent onward. The photo preview remains in browser memory; Lookremix does not permanently store your original upload or preference text.
The prepared reference and instructions pass through Vercel AI Gateway to the OpenAI image model. This includes processing the appearance of the person in the photo. Lookremix does not create a facial-recognition database, use the photo to authenticate you, or intentionally infer health, ethnicity, or other sensitive characteristics. Upload only photos you have permission to use and avoid sensitive information in your instructions.
Each generation is a separate request using your uploaded reference and current choices. Previous looks are not automatically sent as conversation history. We process this information to supply your requested generation service (Article 6(1)(b) GDPR).
Temporary handling by Lookremix does not mean every provider retains nothing. AI providers may retain data for safety, abuse prevention, or legal obligations under their applicable terms. We do not promise zero retention across the entire processing chain. See Vercel’s privacy policy and OpenAI’s privacy policy for provider information.
5. Your private library
Generated images are saved in Cloudflare R2. Cloudflare D1 stores their ownership, style, creation time, and generation/credit reference. The app checks your signed-in account before listing, displaying, downloading, or deleting an image; the buckets are not public. Authorised administration and service-provider access may still be necessary to operate the service or resolve support requests.
You can download or delete images in your library. Deletion hides an image immediately and removes its file; temporary storage errors can delay physical deletion while maintenance retries. Downloaded copies are outside our control. Images created before the library was introduced were not stored and cannot be recovered. Providing the library is based on Article 6(1)(b) GDPR.
6. Purchases and credit accounting
Stripe hosts checkout. We send your account identifier, email when available, selected credit pack, and purchase reference to Stripe. Stripe handles the payment details you enter. We receive payment/refund status and transaction identifiers, and store purchase amounts, currency, credit allocations, and generation reservations. We do not store card numbers or security codes.
Payment processing and credit accounting fulfil your purchase (Article 6(1)(b) GDPR). Required tax/accounting records meet legal obligations (Article 6(1)(c) GDPR). Fraud prevention and resolving payment disputes also serve our legitimate interests (Article 6(1)(f) GDPR). Stripe processes some data for its own compliance and fraud-prevention purposes: Stripe privacy policy.
7. Cookies and browser storage
Lookremix uses these first-party cookies when you choose to sign in. Both are Secure, HttpOnly, and SameSite=Lax on the live site:
__Host-lookremix_session: keeps you signed in for up to 30 days, or until sign-out. Only a hash of the token is stored in our database.__Host-lookremix_oauth: protects Google sign-in against misuse. It expires after 10 minutes and is cleared when sign-in completes.
These cookies are necessary for your requested sign-in service (§ 25(2)(2) TDDDG). Associated account and security processing uses Article 6(1)(b) and (f) GDPR respectively. Blocking them prevents sign-in. Google and Stripe may use their own cookies on their sign-in and checkout pages, as explained in their policies.
We do not store authentication tokens in local storage, use advertising pixels, or send product-analytics beacons. Fonts are served with the app rather than loaded from Google Fonts.
8. How long we keep data
- Original photos and preference text: processed for the request without permanent storage by Lookremix. The preview disappears when you replace it, sign out, refresh, or leave.
- Generated images: kept until you delete them or request account closure. Failed or abandoned saved-image uploads are removed by maintenance after their request expires.
- Account and credit records: kept while the account is provided. Request closure by email. Records needed to fulfil remaining obligations, comply with retention laws, or establish or defend legal claims may be retained for those purposes.
- Session and sign-in records: sessions expire after 30 days at most; sign-in state after 10 minutes. Expired records are removed during sign-in or scheduled maintenance. Sign-out revokes the current session immediately.
- Rate-limit counters: one-minute generation windows and ten-minute sign-in windows, with automatic cleanup after expiry.
- Application logs: up to seven days in Cloudflare Workers Logs. Infrastructure security records also follow Cloudflare’s applicable retention practices.
- Accounting documents: German statutory periods depend on the document category: generally eight years for booking vouchers, six years for business correspondence, and ten years for books and certain records, calculated from the relevant year-end. Legal holds or ongoing tax matters can require longer retention. These duties do not require keeping your photos or generated images.
Deleted database records can remain in restricted disaster-recovery history for up to 30 days with Cloudflare D1 Time Travel. This is separate from R2 image files. Retention of independently processed Google, Stripe, Vercel, or OpenAI data follows their applicable policies and legal obligations.
9. Recipients and international processing
Providers include Cloudflare (hosting, delivery, image processing, storage, security), Vercel (AI Gateway), OpenAI (image generation through the gateway), Google (sign-in and profile pictures), Stripe (payments), and our email service provider (correspondence). We may disclose necessary records to professional advisers, courts, or authorities where required by law or to handle a legal claim. We do not sell your photos or account information.
Data may be processed outside the European Economic Area, including in the United States; we do not promise EU-only processing. Where a transfer requires GDPR safeguards, the providers’ applicable data-transfer terms use mechanisms such as the European Commission’s Standard Contractual Clauses; an adequacy decision may apply where its requirements are met. See the Cloudflare data-processing terms, Vercel data-processing terms, Stripe data-processing terms, and the linked Google and OpenAI policies. Contact us for information about the safeguards applicable to your data or a copy of the relevant safeguards.
10. Contact and your rights
Email lookremix@avayne.de for support, account closure, or privacy requests. We process your contact details and message to respond: Article 6(1)(b) GDPR for service/purchase enquiries, Article 6(1)(c) for statutory privacy requests, and Article 6(1)(f) for other legitimate correspondence. Do not email passwords or card details.
Subject to legal conditions, you can request access, correction, deletion, restriction, and portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. We may need proportionate identity verification to protect your account.
We normally respond to GDPR requests within one month. If a legally permitted extension is necessary, we will explain this within that month. You can complain to a supervisory authority, including where you live, work, or believe an infringement occurred. Our local authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany; poststelle@ldi.nrw.de.
11. Your choices and automated processing
You can browse public pages without an account. Google sign-in is required for an account, and a reference photo for personalised generation; preference text is optional. Buying credits requires the checkout information requested by Stripe. You may choose not to provide this information, but the corresponding feature cannot then be supplied.
AI creates outfit images and automated checks protect the service and account for credits. We do not use your images to make decisions producing legal or similarly significant effects about you within Article 22 GDPR.
12. Changes to this notice
We update this notice when the service or its processing changes. The revision date appears above. Contact us using the details in section 1 with questions about this version.