Legal & Policy DocumentationLast Updated: September 2026

Privacy Policy

Effective Date: September 9, 2026

1. Architectural Principle: Forgetting as Default

Look Unlock is designed around a singular privacy commitment: your photo stays on systems we operate — it is never sold, and it is never used to identify you. On a public, shared fitting screen or boutique mirror, forgetting is the primary safety mechanism.

2. Information We Collect

At the in-store fitting kiosk:

  • Customer Photograph: A single photo captured or uploaded during the fitting session to generate the garment composite on your body.
  • Ephemeral Session ID: A temporary UUIDv4 generated purely in client device memory. It is destroyed immediately when the idle timer expires or when you tap “Start Over”.
  • Interaction Telemetry: Unidentifiable actions such as garment selection, try-on stage completions, and bag interactions. These records contain zero PII—no face, no name, no biometric vector.

For early-access account holders:

  • Account Credentials: Email address, voluntary display name, and encrypted authorization credentials managed via secure enterprise authentication protocols.

3. Exact Retention Windows & Automated Purge Lifecycles

We enforce deterministic time-to-live (TTL) limits across all storage categories:

Data CategoryLifespan (TTL)Purge MechanismBiometrics / PII
Source Photos & Rendered Results7 DaysAutomated scheduled sweep jobCustomer photo (purged)
Raw Interaction Telemetry90 DaysAutomated journal retention sweepZero PII / No face
Kiosk Shopping Bags72 HoursSession expiration sweepAnonymous basket
Aggregated Analytics RollupsIndefinitePermanent operational intelligenceZero PII (totals only)

4. Prohibition of Biometrics & Facial Recognition

We do not create, store, or extract facial recognition vectors or biometric identifiers. Image hashes used during inference are short-lived memory references strictly for duplicate suppression within a single live fitting session and are never cross-referenced across store visits or customer identities.

5. Secure Cloud Infrastructure & Data Isolation

Inference, fitting computation, and data persistence operate strictly on dedicated, isolated enterprise cloud environments:

  • Hardware-Isolated Database Security: Encrypted enterprise database infrastructure enforcing strict Row Level Security, isolated tenant encryption, and cryptographically signed session tokens.
  • Dedicated Private Compute Clusters: High-performance private GPU nodes executing our proprietary on-body garment fitting pipelines. Customer images are processed within ephemeral memory and subject to our strict 7-day automatic purge lifecycle.
  • Proprietary Descriptive Tagging: Semantic pipelines utilized strictly for garment attribute categorization. Customer faces, biometric data, and personal attributes are never transmitted to external systems or used for model training.

6. Your Rights

You have the right to request access to your account data, correction of inaccurate details, or immediate deletion of your account and any associated profile records before the automatic 7-day purge. To exercise your rights, reach us through our contact form.

7. Protection of Minors

The Service is not directed toward children under 18 years of age. We do not knowingly collect or process personal data from minors.

8. Policy Updates

As our early-stage research beta evolves, we may update this Privacy Policy. Any material adjustments to retention periods or processor relationships will be reflected on this page with an updated effective date.