Skip to content
ELVYA
How it worksMoodsJournalAbout
Release status

Sample wardrobe

01How it works02Moods03Journal04AboutRelease status

Legal

Privacy Notice

What Elvya collects, why it is used, where it goes, how long it is kept, and the controls available to you.

Version
2026-07-17
Effective
17 July 2026

On this page

  1. Scope
  2. Controller and contact
  3. The public website
  4. Data and sources
  5. Purposes and legal bases
  6. Required and optional data
  7. Photos, likeness, and AI
  8. Recommendations and profiling
  9. Optional analytics
  10. Optional App Store refund assistance
  11. Essential telemetry and local device data
  12. Recipients and processors
  13. International transfers
  14. Retention and deletion
  15. Export and erasure coverage
  16. Your rights
  17. Security, complaints, and changes

Scope

This notice explains how Elvya handles personal data in the mobile app, the public website, and related backend services.

Controller and contact

Elvya is the service name used by the controller for account, profile, wardrobe, recommendation, purchase, and privacy-settings data. Email privacy@updates.elvya.live to exercise privacy rights or ask for the controller, DPO, or representative details applicable to your location.

The public website

The public website does not create app accounts or accept wardrobe uploads. Its current site code stores the mood you select in your browser's local storage so it can restore that visual preference. It does not configure analytics, advertising, or cross-site tracking. See the Cookie Notice for the website-specific storage summary.

Data and sources

Elvya receives data you provide, including account details, optional style and sizing fields, city or coarse location, wardrobe and likeness photos, product links, outfit plans, feedback, and privacy choices. Elvya also generates garment metadata, recommendations, style memory, body-measurement estimates, avatars, try-on outputs, operation records, and security logs. Apple or Google supplies verified purchase, subscription, refund, and opaque transaction identifiers. The app and backend create session, device, local-cache, diagnostic, and optional analytics data.

Purposes and legal bases

Account, wardrobe, planner, store-purchase, and requested recommendation processing is necessary to provide the service or take steps you request. In this version, face, body, likeness, avatar, and try-on AI processing starts only after separate optional consent. Optional product analytics relies on consent. Security, fraud and abuse prevention, essential debugging, and minimized operational telemetry rely on legitimate interests, subject to a balancing assessment. Elvya may also keep records where a legal obligation applies.

Required and optional data

An email, password, Terms acceptance, and 18+ confirmation are required to create an account. Profile presentation, height, sizing, location, wardrobe, likeness, notifications, and analytics are optional. The app asks for camera, photo-library, location, or notification permission only when you choose a feature that needs it. You can revoke operating-system permissions, but the related feature may stop working.

Photos, likeness, and AI

Wardrobe photos may be analyzed to isolate garments and infer descriptive metadata. If you separately consent to likeness features, selected face or full-body references, height, measurements, garment images, and generated outputs may be sent to AI image or body-processing providers. Uploaded images are normalized and metadata such as EXIF is removed before storage. Raw full-body references are deleted after successful avatar generation where the workflow no longer needs them. Elvya does not use this workflow for face recognition, identity verification, cross-user matching, or health diagnosis. AI-generated measurements, avatars, recommendations, and try-on images are estimates, not guarantees of fit, availability, or exact likeness.

Recommendations and profiling

Elvya uses wardrobe metadata, profile preferences, feedback, dismissals, impressions, weather context, and style memory to rank outfit and styling suggestions. These recommendations do not make legal or similarly significant decisions about you.

Optional analytics

Optional analytics is off until you choose to enable it. When enabled, Elvya sends allowlisted screen, action, timing, result, and sanitized error-type events plus an SDK identifier to PostHog and the Elvya backend. It does not send wardrobe or likeness images, prompts, shopping links, filenames, measurements, precise location, arbitrary error messages, or stack traces.

Session replay, autocapture, console capture, performance capture, GeoIP enrichment, advertising, and cross-app tracking are disabled. Withdrawal disables both analytics destinations and removes queued analytics mutations without disabling the service. The release target for PostHog retention is 12 months; the live setting remains a release-verification item.

Optional App Store refund assistance

This choice is off by default and separate from analytics. If you enable it and Apple asks Elvya to assist with an App Store refund request, Elvya may send Apple the transaction identifier, whether the purchase was delivered, and the percentage of the purchase already consumed. Apple uses this information to inform its refund decision under its own terms. You can withdraw this permission at any time in Privacy Settings without losing app access or paid features; withdrawal does not affect information already shared while permission was active.

Essential telemetry and local device data

Elvya keeps minimized operational logs and traces needed to secure and operate the service. Production telemetry is designed to use route templates, request or operation correlation, status class, duration, exception type, and a sanitized error slug rather than raw user identifiers, URLs, messages, or stack traces. The release target for Honeycomb operational telemetry is 30 days; the live setting remains a release-verification item.

On your device, authentication tokens use protected storage; recreatable read models and media use cache storage; durable offline changes use app-support storage; and app-owned upload or export copies use managed temporary storage that is cleaned after the action and on sign-out or deletion. Sign out and clear device removes the signed-in session, local caches, queued data, and analytics identity but does not delete the server account.

Recipients and processors

Depending on the feature you use, recipients include Supabase for authentication, database, and private storage; OpenAI for image, metadata, body-estimate, and recommendation tasks; fal.ai for garment segmentation or configured body processing; PostHog for optional analytics; Honeycomb through OpenTelemetry for operational telemetry; Open-Meteo for weather requests; and Apple or Google for store billing. With separate optional permission, Elvya may also send Apple purchase delivery and consumption information to assist with an App Store refund decision. Apple and Google process billing under their own terms and privacy notices.

International transfers

Some providers may process data outside your country or the EEA. The provider region and transfer safeguard depend on the configured service and applicable contract. Contact privacy@updates.elvya.live for the safeguard relevant to your processing and how to obtain a copy. Elvya must verify the applicable vendor and transfer assessment before offering the affected processing in a new market.

Retention and deletion

Account, profile, wardrobe, outfit, planner, likeness, purchase, and style-memory records are generally kept for the account lifetime unless you delete them earlier or law requires a limited record. Current backend retention controls use these periods:

  • Recommendation candidate logs: 90 days.
  • Recommendation impressions and detailed snapshot traces: 30 days.
  • Backend usage events and daily aggregates: 365 days.
  • Weather contexts: 14 days.
  • Terminal operations and processing jobs: 30 days.
  • Processed outbox records: 14 days.
  • Failed or dead-letter records: 7 days.
  • Expired or revoked sessions: 90 days.
  • Expired or used password-reset tokens: 7 days.
  • Privacy export ZIPs: 7 days.
  • Consent and rights IP-address and user-agent fields: 30 days.

Release targets are 12 months for optional PostHog analytics and 30 days for Honeycomb operational telemetry; both live vendor settings require verification before release. Minimized consent and rights records remain only as long as needed to demonstrate compliance or handle legal claims; the final period requires legal-owner approval.

Export and erasure coverage

A complete export is prepared as a ZIP containing classified account records, owned media, PostHog subject data, checksums, exclusions, and a processor-coverage manifest. The server bundle expires after 7 days, each download link after 15 minutes, and the app deletes its temporary local copy after sharing. Delete Likeness Data removes likeness references, inferred measurements and body type, avatars, likeness assets, and user-specific try-on outputs while keeping unrelated wardrobe originals, outfits, user-supplied height, and sizing. Account deletion deactivates access and queues deletion from PostHog, Redis, Supabase Auth, account rows, and private storage. Required cloud logs, backups, and retention-only telemetry may remain until their fixed lifecycle expires.

Your rights

Depending on your location, you may have rights to be informed, access data, correct it, erase it, restrict processing, receive portable data, object to certain processing, and withdraw consent without affecting earlier lawful processing. Privacy Settings provides export, correction, access, rectification, restriction, objection, analytics withdrawal, likeness deletion, and account deletion controls.

Email privacy@updates.elvya.live if you cannot use the in-app controls. For the external account-deletion path, see Request account deletion.

Security, complaints, and changes

Elvya uses access controls, private storage, short-lived signed URLs, transport encryption, redaction, and scoped service access to protect personal data. Elvya aims to respond to verified privacy requests within one month unless a lawful extension applies. You may complain to the data-protection authority where you live, work, or believe a violation occurred. Material notice changes will receive a new version and, where required, an in-app notice or renewed choice.

ELVYA
How it worksMoodsJournalAboutRelease status
SupportPrivacyTermsCookies