← Back to home

MIX MY LOOK · SOREVIQ

Privacy

Last updated: 6 September 2026

Scope: iOS app, TestFlight and landing page

This privacy policy covers the native MixMyLook iOS app in private TestFlight testing and the promotional website at mixmylook.de and mixmylook.com. The iOS app is the primary application; no separate web app is planned. The app is in development and this landing page does not yet offer a public download link.

The app sections describe the current test version. The separate website sections apply only to visits to the landing page. Controller, contact and rights information applies to both services. Outstanding contractual and configuration questions are expressly identified below.

Controller for app and website

Stefan Wille
trading as SOREVIQ
Pfadstraße 9
71069 Sindelfingen-Maichingen
Germany
info@soreviq.de

For privacy questions and requests concerning your rights, contact info@soreviq.de.

Email enquiries

If you email us, we process your sender address, any name you provide, message content and technical message details to respond. The email link opens your email app; the website itself does not send a message.

The legal basis is Article 6(1)(f) GDPR for general enquiries, or Article 6(1)(b) GDPR for a contract or pre-contractual steps you request. Please include only information needed for your question.

After the enquiry is resolved, we delete it when it is no longer needed. Statutory retention obligations or the need to establish, exercise or defend legal claims may require longer retention, with use restricted accordingly. The email provider for info@soreviq.de, any further recipients and possible processing outside the EEA still need verification.

Your rights – app and website

Subject to the applicable legal conditions, you have rights to access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18) and portability (Article 20). You may withdraw any consent you have given for the future, without affecting the lawfulness of earlier processing.

Right to object: Where processing relies on Article 6(1)(f) GDPR, you may object under Article 21 on grounds relating to your particular situation. We will assess whether the processing must stop. Contact: info@soreviq.de.

Under Article 77 GDPR, you may complain to a supervisory authority, particularly in the country of your habitual residence, workplace or an alleged infringement. The authority at the provider’s location is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

iOS app: local data, photos and backups

Clothing, original and edited images, person photos, looks, downloaded try-on images and local profile details are stored on your device. Signing in does not synchronise this collection to the cloud. Only a separately selected online function transmits the data required for that function.

Apple Vision removes backgrounds on the iPhone without sending images to an image service. Camera access, selected photos and files are used for the import functions you choose. You can manage permissions in iOS.

Manual exports are independent backup files. You choose their destination, such as iCloud Drive, and whether to share them. Apple processes files saved in iCloud under its own terms. Local data remains until the relevant deletion or removal of the app’s data. Deleting data in MixMyLook does not automatically remove external backups, photo-library images or data on other devices. Device-wide backups depend on your iOS settings.

The purpose is to provide the wardrobe management and display functions you request. Where personal data is processed to provide the service, the basis is Article 6(1)(b) GDPR. Local functions do not require uploading the entire wardrobe.

iOS app: sign-in and email delivery

For optional sign-in, Supabase processes your email address, account ID, authentication data and technical connection and security information. Resend delivers requested one-time codes and recovery emails, processing recipient addresses, message content and delivery information. Session keys are stored in the iOS Keychain. Signing in does not upload the optional local display name and profile photo as a wardrobe synchronisation.

Processing supports sign-in, recovery and account security (Article 6(1)(b) GDPR). Abuse prevention and technical security logs support our legitimate interest in secure testing (Article 6(1)(f) GDPR). Account-based test features require the necessary account data. Account data is retained until account deletion. Exact retention periods for authentication, delivery and provider logs remain to be confirmed.

iOS app: optional AI image processing

Only after your confirmation are the clothing or person photos selected for a particular operation and processing instructions transmitted via Supabase Edge Functions to the OpenAI API. Signing in alone does not upload images. Our own backend does not persist input images; it processes them temporarily for the request. Provider logs are a separate matter.

Optional transmission and AI processing of selected images is based on your consent (Article 6(1)(a) GDPR). You can avoid further AI requests and withdraw consent for the future using the contact below. This cannot reverse processing already completed. Declining does not exclude local wardrobe features. Only use person photos you are entitled to process. Try-on images are illustrative and are not used for biometric identification or reliable fit assessment.

OpenAI states that API data is not used for model training by default without explicit permission. Abuse-monitoring logs may contain content and generally be retained for up to 30 days, with possible legal or safety exceptions. Neither Zero Data Retention nor exclusively European processing is confirmed for this project. The settings and terms actually enabled for the service govern its processing.

iOS app: results, job data and retention

Generated images are temporarily made available in private Supabase storage. App access expires one hour after job reservation, not one hour after completion. Technical cleanup runs on later authenticated requests by authorised test accounts. Physical deletion at exactly one hour is not guaranteed; failures or a lack of subsequent requests may extend retention. Results saved on your device remain independently.

Account IDs, job and attempt identifiers, input checksums, status, error details and timestamps support access control, reuse and prevention of duplicate paid requests. The basis is Article 6(1)(f) GDPR, particularly our legitimate interest in abuse prevention and reliable cost control. These metadata currently have no automatic time-based deletion and generally remain until account deletion. A bounded retention policy for ongoing operation still needs to be defined. The one-hour image-access limit is not a deletion deadline for job metadata.

A separate cleanup record containing account ID, job ID, storage path and expiry remains until successful file cleanup, including after account deletion. Non-personal aggregate daily budget counters remain independently.

iOS app: account and local deletion

Account deletion in the app requests deletion of the Supabase sign-in account. Sessions are revoked and associated profile, test-access and job records are deleted. Following successful account deletion, the current local account data on that device is removed. A technical account-ID-to-local-folder association remains to prevent reassignment to a guest. Other local accounts are not deleted. A failed step must not be treated as complete deletion.

Temporary result files and their cleanup records are removed separately through the cleanup process; account deletion does not guarantee immediate file deletion. Local deletion alone does not delete a sign-in account or data already transmitted to providers. Other devices, exports, iCloud backups, photo-library images and provider logs retained for legal or technical reasons are not automatically fully deleted. Contact us below for additional deletion requests.

Private TestFlight testing

Apple distributes the beta through TestFlight and processes invitation or account data, device and version details, installation and usage data, and crash diagnostics. TestFlight automatically collects and shares crash and usage data with Apple and us as the developer; this cannot be opted out of within TestFlight. With a private email invitation, your name and email address may also be visible to us. Optional feedback can contain text and screenshots; check for personal information before submitting it.

We use available test information to organise testing and fix faults, based on our legitimate interest in a stable, secure app (Article 6(1)(f) GDPR). Apple also processes data for its own purposes under its privacy notices. Apple specifies one year for beta feedback; crash and usage information may be retained until the issues are resolved. Retention for feedback separately kept by us still needs to be defined. MixMyLook account deletion does not automatically delete this information.

Apple: TestFlight and privacy

App recipients and international processing

Recipients or service providers include Supabase for authentication, backend and temporary results; Resend for authentication emails; OpenAI for confirmed AI requests; and Apple for TestFlight or iCloud backups you choose. Contracting entities and roles must still be finally established from the relevant agreements. Apple acts as an independent controller for some of its own services.

The Supabase project is configured in eu-central-1. This does not establish exclusively European processing: edge execution, support, subprocessors, email delivery and AI services may involve processing outside the EEA, including the US. Providers publish privacy and data processing terms addressing international transfers. The applicability of standard contractual clauses, an adequacy decision or other safeguards to the specific contracts remains to be verified. This notice does not assert that data processing agreements or particular transfer guarantees have been confirmed. You can request information and, where applicable, copies of relevant safeguards using our contact details.

Supabase · Supabase DPA · Resend · Resend DPA · OpenAI API – Data controls · OpenAI DPA · Apple

Outstanding private-beta questions

Final provider and mandatory details, contracting entities and data processing agreements, actual transfer safeguards and regional settings, provider and diagnostic log retention, feedback retention, and a bounded job-metadata retention period remain to be clarified. The flagged website and contact details below also require final review. This policy describes the current state; it does not certify that all legal and technical requirements have been conclusively reviewed.

Website: At a glance

This separate section applies only to visits to the promotional website at mixmylook.de and mixmylook.com. Processing in the iOS app and private TestFlight testing is described above. You can read everything without an account. There are no photo uploads, newsletter sign-ups or payments. The outfit demo does not send your choices to a server or call an AI service.

Website: Website delivery and hosting

This landing page is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, using the “Website 5.0” web hosting plan. Delivering the website requires processing connection data, including your IP address.

IONOS’s general web hosting documentation lists the requested file, referrer, browser, operating system, device type, access time and an IP address anonymised on collection. It specifies eight weeks of retention and no transfer of this visitor data outside the EU. These product details still need confirmation for the existing “Website 5.0” plan. IONOS: processing by web hosting.

The purpose is website delivery, stability and security. Where personal data is processed, the legal basis is Article 6(1)(f) GDPR: our legitimate interest in an accessible, secure website. The necessary connection data is transmitted automatically; without it, the website cannot be delivered.

The hosting provider processes data as part of providing the service. Final verification of the data processing agreement under Article 28 GDPR and the privacy-related hosting configuration remains outstanding; completion of that review is not asserted here.

Website: IONOS WebAnalytics — pending verification

IONOS describes WebAnalytics as enabled by default, using either log files or a pixel and, according to the provider, no cookies. Whether and how the “Website 5.0” plan enables it for these domains has not yet been verified. IONOS: WebAnalytics.

The website code itself does not embed an analytics service. Host-side statistics still need to be checked and either disabled where possible or described with their actual technology, legal basis, retention and any necessary consent. A cookie-free implementation does not by itself remove the need for that assessment.

Website: Outfit demo, cookies and storage

The demo only processes fictional garment identifiers, locked pieces and saved combinations in the open page’s memory. They are not sent to us, linked to an account, or stored in cookies, localStorage, sessionStorage or IndexedDB. Reloading or switching languages resets the selection; browser restoration may temporarily preserve the page state.

The animation pause also applies only to the open page. Any storage or access on your device required for the demo is solely for the function you expressly choose (section 25(2)(2) TDDDG). The demo creates no usage profile.

Website: External links and locally delivered content

Fonts are selected from those already on your device. Images, styles and scripts are served from the website’s own webspace. There are no embedded videos, social widgets or externally loaded webfonts.

SOREVIQ and other linked websites load only when you follow a link. Their privacy notices then apply. Your demo selection is not passed on. GitHub is used for development and version control; the delivered website does not load content from GitHub.

Website: No automated decisions

This landing page makes no automated decisions with legal or similarly significant effects and performs no corresponding profiling. The random mixer merely selects sample clothing.