← Back to app

Privacy Policy

TheDress.ai Last Updated: March 2026 Effective Date: March 2026


1. Identity & Contact Details

TheDress.ai is operated by TheDress.ai, based in the United Kingdom.

DetailInformation
Service NameTheDress.ai
Registered AddressUnited Kingdom
Data Protection ContactTheDress.ai Privacy Team
Privacy Email[email protected]
Websitehttps://thedress.ai

If you are located in the European Economic Area (EEA) or the United Kingdom, TheDress.ai acts as the data controller for the personal data processed through this service. We have not appointed an EU/UK representative under GDPR Article 27 at this time. If you have questions about your data, please contact us at [email protected].


2. What Data We Collect

We collect the following categories of personal data:

2.1 Selfie Photos & Biometric Data

2.2 Account Data

2.3 Payment Data

2.4 Device & Usage Data

2.5 Cookies & Tracking Data


3. Purposes of Processing & Legal Basis

3.1 Under EU/UK GDPR

Data CategoryPurposeLegal Basis (Article 6)Additional Basis (Article 9, if applicable)
Selfie photos / biometric dataAI image generation -- creating visualizations of you in wedding attireConsent (Art. 6(1)(a))Explicit consent for biometric processing (Art. 9(2)(a))
Account dataAccount creation, authentication, service deliveryPerformance of contract (Art. 6(1)(b))--
Payment dataProcessing purchases, managing subscriptions, refundsPerformance of contract (Art. 6(1)(b))--
Payment dataTax and financial record-keepingLegal obligation (Art. 6(1)(c))--
Device & usage dataService improvement, bug fixing, performance monitoringLegitimate interest (Art. 6(1)(f))--
Cookies (GA4, Meta Pixel)Analytics and marketing attributionConsent (Art. 6(1)(a))--
All categoriesResponding to legal requests and enforcing our termsLegal obligation (Art. 6(1)(c)) / Legitimate interest (Art. 6(1)(f))--

Legitimate interest balancing: Where we rely on legitimate interest, we have conducted balancing assessments to ensure our interests do not override your fundamental rights. You may request a copy of these assessments by contacting us.

3.2 Under UK Data Protection Act 2018

We process your personal data in accordance with the UK Data Protection Act 2018 and the UK GDPR. The legal bases for our processing are set out in the table above.

3.3 Under Other Jurisdictions

For users in Singapore (PDPA 2012), India (DPDP Act 2023), and other jurisdictions, we process data based on consent and/or as necessary for the performance of a contract with you, in accordance with applicable local law.


4. Biometric Data Notice

This section provides specific disclosures required by laws governing biometric data, including EU/UK GDPR (Article 9), Illinois BIPA, and other applicable regulations.

What biometric data we collect

When you upload a selfie photo, the image contains your facial features. During the AI image generation process, facial geometry, facial landmarks, and other biometric identifiers may be extracted, inferred, or processed by Google's Gemini AI to generate the output image of you in wedding attire.

How biometric data is processed

  1. You upload a selfie photo through our app.
  2. The photo is transmitted securely (TLS-encrypted) to Google's Gemini API servers for AI image generation.
  3. Google Gemini processes facial features to generate the wedding attire visualization.
  4. The generated image is returned to our platform and stored temporarily.

Retention of biometric data

Biometric data is never sold

We do not sell, lease, trade, or otherwise profit from your biometric data. Biometric data is shared with Google Gemini solely for the purpose of generating your requested images.

Consent

Before uploading your first selfie, we request your explicit, informed consent to the collection and processing of your biometric data. You may withdraw consent at any time by deleting your account or contacting us.

> Illinois Residents: Please also refer to our standalone Biometric Data Policy (available at https://thedress.ai/biometric-policy) for disclosures required under the Illinois Biometric Information Privacy Act (BIPA), including written release requirements and specific retention and destruction schedules.


5. Third-Party Data Sharing

We share personal data with the following third-party service providers. We do not sell your personal data (see Section 8 for California-specific disclosures).

Third PartyData SharedRolePurpose
Google Gemini API (Google LLC, USA)Selfie photos, facial/biometric dataData processorAI image generation -- processing your photos to create wedding attire visualizations
Supabase (USA)Account data (email, hashed password, auth tokens), uploaded photos, generated imagesData processorAuthentication, database hosting, file storage
Stripe (Stripe Inc., USA)Billing name, email, payment method details, transaction dataIndependent controller / Data processorPayment processing, subscription management, fraud prevention
Google Analytics (GA4) (Google LLC, USA)Device data, usage data, IP address (anonymized where required), cookie identifiersData processorWebsite and app analytics, understanding usage patterns
Meta Pixel (Meta Platforms Inc., USA)Page view events, conversion events, IP address, browser/device dataIndependent controller / Data processorMarketing attribution, conversion tracking, ad optimization

All processors are bound by data processing agreements (DPAs) that require them to process personal data only on our instructions and to maintain appropriate security measures.

We may also disclose personal data:


6. International Data Transfers

TheDress.ai is based in the United Kingdom. Your personal data may be transferred to and processed in countries outside your jurisdiction, including the United States, where our key service providers (Google, Supabase, Stripe, Meta) operate.

Safeguards for EU/UK transfers

For transfers of personal data from the EEA or UK to countries not recognized as providing adequate protection, we rely on:

Safeguards for Asia-Pacific transfers

You may request a copy of the relevant transfer safeguards by contacting us at [email protected].


7. Data Retention

Data TypeRetention PeriodDeletion Method
Uploaded selfie photos30 days from uploadAutomatic deletion from storage
Generated wedding attire images30 days from creationAutomatic deletion from storage
Account dataUntil you delete your account, or 12 months of inactivityManual deletion on request; automatic deletion after inactivity period
Payment and transaction recordsAs required by applicable tax and financial law (typically 7 years)Deleted after legal retention period expires
Device and usage data (analytics)14 months (aligned with GA4 default retention)Automatic expiry within GA4 and Meta systems
Cookie consent recordsUntil consent is withdrawn or expiresCleared on withdrawal or expiry

When you delete your account:


8. Your Rights

8.1 EU/UK GDPR Rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

Response timeframe: We will respond to your request within 30 days. If the request is complex, we may extend this by a further 60 days with notice.

8.2 California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) grants you the right to:

CCPA Disclosure Table

Category of PI (per Cal. Civ. Code 1798.140)Examples CollectedSourcesBusiness PurposeThird Parties Disclosed To
A. IdentifiersEmail address, display name, IP address, Stripe customer IDDirectly from you; automatically collectedAccount creation, service delivery, payment processing, analyticsSupabase, Stripe, Google Analytics, Meta Pixel
B. Personal information (Cal. Civ. Code 1798.80(e))Name, email addressDirectly from youAccount management, communicationsSupabase, Stripe
D. Commercial informationPurchase history, transaction amounts, subscription statusDirectly from you; StripePayment processing, service deliveryStripe
F. Internet or electronic network activityBrowser type, pages visited, session data, referral sourceAutomatically collectedAnalytics, service improvement, marketing attributionGoogle Analytics (GA4), Meta Pixel
H. Sensory dataSelfie photographsDirectly from youAI image generationGoogle Gemini API, Supabase (storage)
Sensitive PI: Biometric informationFacial geometry/features from uploaded selfiesDirectly from you (inferred during AI processing)AI image generationGoogle Gemini API

Sale and sharing of personal information:

Sensitive personal information: We collect biometric data (selfie photos / facial features) solely for AI image generation. We do not use sensitive personal information for purposes beyond what is necessary to provide the service. You may limit this use at any time by not uploading photos or by deleting your account.

Authorized agents: You may designate an authorized agent to submit requests on your behalf by providing written authorization to [email protected].

Financial incentives: We do not offer financial incentives related to the collection of personal information.

8.3 Singapore PDPA Rights

Under the Personal Data Protection Act 2012, you have the right to:

8.4 India DPDP Act Rights

Under the Digital Personal Data Protection Act 2023, as a Data Principal you have the right to:

8.5 UK Data Protection Rights

Under the UK GDPR and Data Protection Act 2018, you have the same rights as described in Section 8.1 above.

8.6 General Rights (All Users)

Regardless of your location, you may:

To exercise any of these rights, contact us at [email protected]. We will verify your identity before processing your request.


9. Cookies & Tracking Technologies

We use cookies and similar tracking technologies on our website and app.

Cookies we use

Cookie / TechnologyProviderTypePurposeData Collected
Google Analytics (GA4)Google LLCAnalyticsUnderstanding site usage, page views, user journeys, performanceAnonymized IP, session ID, device data, pages visited, events
Meta PixelMeta Platforms Inc.MarketingConversion tracking, ad performance measurement, audience buildingPage views, conversion events, IP address, browser data
Session cookiesSupabaseStrictly necessaryAuthentication, keeping you logged inSession token
Consent cookieTheDress.aiStrictly necessaryRemembering your cookie preferencesConsent choices

Consent before loading

We implement a consent management platform that:

Manage your cookie preferences: Use the "Cookie Settings" option in the app footer to update your preferences at any time.

Do Not Track

We respect the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we treat it as a valid opt-out of the sale/sharing of personal information under the CCPA.


10. AI & Automated Processing

How we use AI

TheDress.ai uses Google Gemini AI to generate images of you in wedding attire based on the selfie photos you upload. This involves:

  1. Submitting your uploaded photo to the Google Gemini API
  2. AI processing of your facial features to generate a realistic visualization
  3. Returning the generated image for you to view and optionally save

No automated decision-making with legal effect

The AI processing performed by our service is purely creative and generative. We do not use AI or automated processing to make decisions that produce legal effects or similarly significant effects concerning you (e.g., we do not use AI for credit decisions, employment screening, or access to services).

EU AI Act transparency

In accordance with the EU AI Act (Regulation 2024/1689):

Human oversight


11. Children's Privacy

TheDress.ai is intended for users aged 18 and older. We do not knowingly collect personal data from children.

Age verification

Accidental collection

If we become aware that we have inadvertently collected personal data from a person under 18, we will:

  1. Immediately delete all personal data associated with that account, including any uploaded photos, generated images, and biometric data.
  2. Terminate the account.
  3. Notify the individual (or their parent/guardian, where feasible) of the deletion.

If you believe a child under 18 has provided personal data to us, please contact us immediately at [email protected].

Specific age thresholds by jurisdiction

JurisdictionMinimum Age for ProcessingBasis
EU/EEA16 (or lower as set by member state, minimum 13)GDPR Article 8
United Kingdom13UK GDPR / Age Appropriate Design Code
United States (COPPA)13Children's Online Privacy Protection Act
United Kingdom13UK GDPR / Data Protection Act 2018
Singapore18 (our policy)PDPA 2012
India18 (our policy)DPDP Act 2023

Our service applies an 18+ age requirement globally, which exceeds the minimum in all jurisdictions listed above.


12. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

Technical measures

Organizational measures

Limitation

While we take security seriously, no system is 100% secure. We cannot guarantee the absolute security of your data. If you suspect unauthorized access to your account, contact us immediately.


13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How we notify you

Your options

If you do not agree with an updated policy, you may delete your account before the changes take effect. Continued use of the service after the effective date of a revised policy constitutes acceptance of the changes (except where re-consent is required).


14. Contact Us & Complaints

How to reach us

MethodDetails
Email[email protected]
Postal MailUnited Kingdom (contact via email for postal address)
Data Protection ContactTheDress.ai Privacy Team, reachable at [email protected]

Response timeframes

JurisdictionRequest TypeResponse Time
EU/UK (GDPR)Data subject access / rights request30 days (extendable by 60 days for complex requests, with notice)
California (CCPA/CPRA)Consumer rights request45 days (extendable by an additional 45 days, with notice)
UK (DPA 2018)Data subject request30 days
Singapore (PDPA)Data access / correction request30 days
India (DPDP)Grievance30 days
All other jurisdictionsGeneral request30 days

Filing a complaint

If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:

JurisdictionAuthorityContact
United KingdomInformation Commissioner's Office (ICO)ico.org.uk
EU Member StateYour local Data Protection Authorityedpb.europa.eu
California, USACalifornia Attorney Generaloag.ca.gov
Illinois, USAIllinois Attorney Generalillinoisattorneygeneral.gov
SingaporePersonal Data Protection Commission (PDPC)pdpc.gov.sg
IndiaData Protection Board of Indiadpdboard.gov.in

We encourage you to contact us first so we can attempt to resolve your concern directly.


Appendix: Jurisdiction-Specific Notices

For Illinois Residents

If you are a resident of Illinois, our collection and use of biometric data (facial geometry from your selfie photos) may be subject to the Illinois Biometric Information Privacy Act (BIPA). Please refer to our standalone Biometric Data Policy at https://thedress.ai/biometric-policy for the required BIPA disclosures, including:

For Texas Residents

If you are a Texas resident, our use of biometric data is also governed by the Texas Capture or Use of Biometric Identifier Act (CUBI). We do not sell, lease, or otherwise disclose your biometric data. Biometric data is destroyed within a reasonable time (and no later than 30 days after the purpose for collection has been satisfied).

For Washington State Residents

Our collection of biometric data complies with Washington's Biometric Identifiers law (RCW 19.375). We provide notice and obtain consent before enrolling biometric identifiers and do not sell or disclose biometric data except as permitted by law.


This Privacy Policy is provided in English. If there is any conflict between a translated version and the English version, the English version shall prevail.

If you have any questions about this Privacy Policy, please contact us at [email protected].