Persona

Privacy Policy

Last updated 9 September 2026 · version 2026-09-09

Version2026-09-09
Last updated9 September 2026
Effective[[EFFECTIVE DATE]]
Applies tothe Persona mobile application for iOS and Android, the Persona web pages we operate (legal pages, share pages, the hosted design editor), and every service reached through them.
Contents
  1. 1. The short version
  2. 2. Who we are and how to reach us
  3. 3. What this policy covers
  4. 4. What we collect, why, and on what legal basis
  5. 5. Photographs, camera and photo library
  6. 6. Virtual try-on and biometric-adjacent data
  7. 7. Voice input and speech recognition
  8. 8. AI features: what leaves Persona and what does not
  9. 9. What we do not do
  10. 10. Who we share information with
  11. 11. Where your information is processed, and international transfers
  12. 12. How long we keep things
  13. 13. Security
  14. 14. Your choices inside the app
  15. 15. Your privacy rights, and how to use them
  16. 16. European Economic Area, United Kingdom and Switzerland
  17. 17. California
  18. 18. Other United States states
  19. 19. Canada, Australia, New Zealand, Brazil, India and elsewhere
  20. 20. Children and teenagers
  21. 21. Deleting your account
  22. 22. Cookies and similar technologies
  23. 23. Notifications and marketing
  24. 24. Automated decision-making and profiling
  25. 25. Data breaches
  26. 26. Changes to this policy
  27. 27. How to contact us

1. The short version

Persona is a marketplace where people design products, publish them, and buy from each other. To do that we need some information about you.

WE COLLECT what an account and an order need: your email, your username and profile, your date of birth, your delivery address, what you make, what you buy, and how you use the app.

WE DO NOT SELL your personal information, we do not share it for cross-context behavioural advertising, and we carry no advertising or ad-tracking SDKs in the app.

PAYMENTS are handled by Stripe. We never see your card number or your bank credentials.

PRINTING AND SHIPPING are handled by a print-on-demand fulfilment partner, who receives your name, delivery address and the artwork to be printed - and nothing else about you.

AI FEATURES send your prompts and images to AI infrastructure providers so they can produce your result.

TRY-ON PHOTOGRAPHS are private to your account, are never published, and have their own written retention and destruction schedule in Section 6.

YOU CAN DELETE your account and its data from inside the app, at any time. Order, tax and payment records are kept because the law requires it. Section 21 says exactly what goes and what stays.

The rest of this document is the detail. It describes the app as it actually behaves.

2. Who we are and how to reach us

2.1 Persona is operated by [[LEGAL ENTITY]], [[ENTITY TYPE]], of [[REGISTERED ADDRESS]], company number [[COMPANY NUMBER]]. For data protection law, we are the controller of the personal information described in this policy.

2.2 Contact us about privacy at privacy@[[DOMAIN]], or in writing at the address above. We answer privacy requests at that address, including requests to access, correct, export or delete your information.

2.3 Our representative in the European Union under Article 27 of the GDPR is [[EU REPRESENTATIVE]]. Our representative in the United Kingdom under Article 27 of the UK GDPR is [[UK REPRESENTATIVE]].

3. What this policy covers

3.1 This policy covers the Persona app, the web pages we operate, and the back-end services behind them.

3.2 It does not cover:

3.3 Where a third party acts as a controller in its own right rather than as our processor - Apple, Google, Meta and Stripe do, in parts of what they do - their own policy governs that processing, and we link to it in Section 10.

4. What we collect, why, and on what legal basis

"Legal basis" is a GDPR concept and applies if you are in the EEA, the UK or Switzerland. If you are elsewhere, read the "why" column - it is the same in every country.

---------------------------------------------------------------------
A. ACCOUNT AND IDENTITY
---------------------------------------------------------------------
What          Email address; password (stored only as a hash by our
              authentication provider); or the identifier returned by
              Apple, Google or Facebook if you sign in that way; account
              creation time; a unique account identifier.
Why           To create your account, sign you in, secure it, send you
              service messages and order confirmations, and recover
              access.
Legal basis   Performance of a contract; our legitimate interest in
              securing accounts.
Source        You.

---------------------------------------------------------------------
B. DATE OF BIRTH AND AGE BAND
---------------------------------------------------------------------
What          The date of birth you declare at sign-up, stored once and
              not changeable by you afterwards; the age band derived from
              it (13-15, 16-17, 18+); where the platform provides one, an
              age signal from Apple or Google.
Why           To keep under-13s off the service, and to decide which
              features your account may use: publishing, commenting,
              messaging, buying and receiving payouts are age-gated.
Legal basis   Compliance with a legal obligation (children's privacy and
              app store requirements); performance of a contract.
Source        You, and the platform.

---------------------------------------------------------------------
C. PUBLIC PROFILE
---------------------------------------------------------------------
What          Username; display name; biography; profile and cover
              images; links you add; follower and following counts;
              your published products; your public collections; your
              sales count; your comments.
Why           To give you a presence on Persona and to let other people
              find, follow and buy from you.
Legal basis   Performance of a contract.
Note          This information is visible to other users, and to anyone
              who opens a share link you or someone else creates.

---------------------------------------------------------------------
D. THINGS YOU MAKE
---------------------------------------------------------------------
What          Designs and their editable layers; drafts; uploaded images;
              print files; generated mockups; product titles,
              descriptions and tags; prices you set; saved collections;
              likes.
Why           To let you design, preview, publish and sell; to produce
              printable files; to display your work.
Legal basis   Performance of a contract.

---------------------------------------------------------------------
E. ORDERS AND DELIVERY
---------------------------------------------------------------------
What          Items ordered, quantities, sizes, colours and prices;
              delivery name, address, and phone number if you supply one;
              delivery method; order status; tracking numbers; the
              currency you paid in; the tax or duty applied; discounts
              and vouchers used; the order confirmation email address.
Why           To take, produce, ship and support your order, to calculate
              shipping and tax, to keep the invoice records the law
              requires, and to handle returns and disputes.
Legal basis   Performance of a contract; compliance with a legal
              obligation (tax and accounting records).

---------------------------------------------------------------------
F. PAYMENTS
---------------------------------------------------------------------
What          Payment status, amounts, currency, the last four digits and
              brand of a card where our payment provider returns them,
              payment and refund identifiers, dispute records, fraud
              signals. WE DO NOT RECEIVE OR STORE YOUR FULL CARD NUMBER,
              ITS SECURITY CODE, OR YOUR BANK CREDENTIALS.
Why           To take payment, to refund you, to detect and prevent
              fraud, and to answer a bank dispute.
Legal basis   Performance of a contract; legal obligation; legitimate
              interest in preventing fraud.
Source        You, through Stripe; and Stripe.

---------------------------------------------------------------------
G. CREATOR EARNINGS AND PAYOUTS
---------------------------------------------------------------------
What          Your earnings ledger; pending, available and withdrawn
              balances; payout requests and their status; your payout
              country; the connected-account identifier and verification
              status our payments provider returns; tax forms and tax
              identification numbers where the law requires us or our
              provider to collect them.
Why           To calculate and pay what you are owed, and to meet tax,
              accounting and anti-money-laundering obligations.
Legal basis   Performance of a contract; legal obligation.
Note          IDENTITY DOCUMENTS AND BANK DETAILS GO DIRECTLY TO STRIPE
              AND ARE NEVER STORED BY US.

---------------------------------------------------------------------
H. SUBSCRIPTIONS, CREDITS AND IN-APP PURCHASES
---------------------------------------------------------------------
What          Purchase receipts and identifiers from the App Store or
              Play, subscription tier and status, renewal and expiry
              dates, credit balances and the ledger of credits granted,
              spent and refunded, gift-card instruments, promotional
              codes and referral records.
Why           To grant what you bought, to meter AI features, to settle
              refunds, and to prevent abuse of promotions.
Legal basis   Performance of a contract; legitimate interest in
              preventing abuse.
Source        You, and the Store via RevenueCat.

---------------------------------------------------------------------
I. COMMUNICATIONS
---------------------------------------------------------------------
What          Direct messages and their attachments; comments and
              replies; conversation membership and read state; support
              messages and the reports you file; the photographs you
              attach to an order problem.
Why           To deliver messages to the person you sent them to, to run
              the comment system, and to handle your support case or
              report.
Legal basis   Performance of a contract; legitimate interest in keeping
              the service safe.
Note          DIRECT MESSAGES ARE NOT END-TO-END ENCRYPTED. We can access
              them where we need to for safety, to investigate a report,
              or to comply with the law.

---------------------------------------------------------------------
J. SAFETY, MODERATION AND ENFORCEMENT
---------------------------------------------------------------------
What          Reports you make and reports made about you; the reason and
              the details; blocks you set; the outcome of a review;
              automated artwork-screening results and the labels
              returned; enforcement history on an account.
Why           To keep Persona safe, to enforce our Terms, to operate a
              repeat-infringer policy, and to answer a legal complaint.
Legal basis   Legitimate interest in safety and in enforcing our terms;
              legal obligation.

---------------------------------------------------------------------
K. LEGAL ACCEPTANCE RECORDS
---------------------------------------------------------------------
What          Which version of the Terms and this Privacy Policy you
              accepted; a SHA-256 hash of the exact text; your locale;
              the app build; the server time of acceptance.
Why           So that both of us can establish what was agreed. This is
              contractual evidence.
Legal basis   Legitimate interest in being able to evidence a contract;
              legal obligation.

---------------------------------------------------------------------
L. DEVICE AND TECHNICAL DATA
---------------------------------------------------------------------
What          Device push token; app version and build; device model and
              operating system version; device language and region;
              country inferred from your device locale; IP address, seen
              transiently by our infrastructure and our providers as part
              of delivering a network request; performance traces (screen
              render times, network request durations and outcomes) from
              Firebase Performance Monitoring, together with the
              installation identifier that service uses; crash and error
              diagnostics in server logs.
Why           To deliver notifications, to keep the app working, to
              diagnose problems, to protect against abuse, and to choose
              the right currency and catalogue for your region.
Legal basis   Legitimate interest in operating and securing the service;
              performance of a contract.
Note          Your push token is removed from your account when you sign
              out, and is deleted when the notification service reports
              it as dead.

---------------------------------------------------------------------
M. USAGE AND ENGAGEMENT
---------------------------------------------------------------------
What          Product views, profile views, likes, saves, shares,
              searches, the source you arrived from, and the country
              code, each tied to your account.
Why           To rank and personalise what you see, to show creators how
              their designs are doing, and to detect manipulation.
Legal basis   Legitimate interest in operating, ranking and improving the
              service.
Retention     Individual event records are automatically deleted after 7
              days. Before they are deleted they are rolled up into daily
              aggregate statistics that do not identify a viewer.

---------------------------------------------------------------------
N. PHOTOGRAPHS, VOICE AND AI INPUTS
---------------------------------------------------------------------
See Sections 5, 6, 7 and 8, which describe these separately because they
are the most sensitive things Persona handles.

4.2 WE DO NOT COLLECT: precise geolocation; your contacts; your calendar; your health or fitness data; your browsing on other apps or websites; any advertising identifier; or biometric identifiers used to identify you. Persona contains no advertising SDK, no analytics SDK that profiles you across services, no attribution SDK configured for tracking, and does not ask for App Tracking Transparency permission because it does not track you across other companies' apps and websites.

5. Photographs, camera and photo library

5.1 Persona asks for camera and photo library permission only when you use a feature that needs it. You can refuse, and the rest of the app keeps working.

5.2 WHAT WE ASK FOR AND WHY:

  Camera            to take a photograph of yourself for virtual try-on,
                    and to take a photograph as evidence when you report
                    a problem with an order.
  Photo library     to choose an image to use in a design, to choose a
                    photograph of yourself for try-on, or to attach a
                    photograph to an order problem.
  Add to library    to save a mockup or a try-on image you generated to
                    your own photo library, when you ask us to.

5.3 We access only the specific images you choose. We do not scan or index your photo library.

5.4 A PHOTOGRAPH YOU ATTACH TO AN ORDER PROBLEM is stored with the support case, shared with our fulfilment partner where the claim needs their review, and kept with the case record.

5.5 AN IMAGE YOU PUT INTO A DESIGN becomes part of that design. If you publish the design, the image is published with it. Do not put a photograph of yourself, of another person, or of anything private into a design you intend to publish unless you mean it to be public.

6. Virtual try-on and biometric-adjacent data

THIS SECTION IS OUR WRITTEN POLICY ON BIOMETRIC-ADJACENT DATA AND INCLUDES THE RETENTION SCHEDULE AND DESTRUCTION GUIDELINES REQUIRED BY THE ILLINOIS BIOMETRIC INFORMATION PRIVACY ACT AND SIMILAR LAWS.

6.1 WHAT THE FEATURE DOES. Virtual try-on lets you upload or take a photograph of yourself and generates images approximating how a product might look on you. It is optional, it is off unless you turn it on, and it is private to your account.

6.2 WHAT WE COLLECT FOR IT:

6.3 WHY WE COLLECT IT. For one purpose only: to produce the try-on images you asked for, and to let you generate further try-on images without uploading your photograph again.

6.4 WE DO NOT USE IT TO IDENTIFY YOU. We do not use your try-on photograph, your derived avatar or the generated images to identify you, to verify you, to match you against any other image, to estimate your age, to infer any characteristic about you, or to build any profile of you. We do not run face recognition. We do not use it for advertising. We do not sell it, lease it, trade it, or otherwise profit from it.

6.5 YOUR CONSENT. We ask for your permission in the app before the feature runs, and the feature does not run without it. By choosing to use virtual try-on you consent to us and to the AI providers named in Section 10 collecting and processing your try-on photograph, your derived avatar and the generated images for the purpose in 6.3. YOU MAY WITHDRAW THIS CONSENT AT ANY TIME by deleting your try-on profile in the app; see 6.8.

6.6 WHO IT IS DISCLOSED TO. Your try-on photograph and the product image are transmitted to the AI infrastructure provider that runs the try-on model, for the sole purpose of generating your result. They are stored by us in our own cloud storage, in a location readable only by your account. They are not published, not attached to any product, not attached to any order, not visible to any other user, and not disclosed to our fulfilment partner. We do not disclose them to anyone else except where we are required to by law or by a valid warrant, subpoena or court order.

6.7 RETENTION SCHEDULE AND DESTRUCTION GUIDELINES. We permanently destroy your try-on photograph, your derived avatar and your generated try-on images at the EARLIEST of:

Destruction means the image files are deleted from our storage. Where a job record is retained for billing reconciliation, the image, the model input and the output URLs are removed from it first, leaving only the non-image fields.

6.8 HOW TO DELETE IT. In the app, open the try-on feature and delete your try-on profile. This deletes your photograph, your derived avatar, any retired versions of them, and redacts the associated job records. You can also email privacy@[[DOMAIN]] and we will do it for you.

6.9 ONLY UPLOAD A PHOTOGRAPH OF YOURSELF. Our Terms prohibit uploading a photograph of anyone else, and prohibit uploading a photograph of anyone under 18. If you upload someone else's photograph you may be breaking the law in your state or country as well as our Terms.

6.10 SPECIAL CATEGORY DATA. If you are in the EEA, the UK or Switzerland, a photograph of your face may be special category data under Article 9 of the GDPR when it is processed by technical means for the purpose of uniquely identifying you. We do not process it for that purpose. To the extent Article 9 applies, our basis is your explicit consent under Article 9(2)(a), which you may withdraw at any time as described in 6.8.

7. Voice input and speech recognition

7.1 Persona lets you describe a design out loud instead of typing it.

7.2 When you use it, your device's operating system converts your speech to text. On iOS this uses Apple's speech recognition, which may process audio on Apple's servers under Apple's own privacy policy. On Android it uses the device's speech service.

7.3 What Persona receives is the resulting TEXT, not an audio recording. We do not record, store or transmit your voice audio, and we do not keep a voiceprint.

7.4 The resulting text is treated exactly like a typed prompt - see Section 8.

7.5 Microphone permission is requested only when you use this feature and can be refused or revoked in your device settings at any time.

8. AI features: what leaves Persona and what does not

8.1 Persona uses machine-learning models for product mockup generation, in-editor image editing and upscaling, generating a design from a description, virtual try-on, and automated artwork screening.

8.2 WHAT WE SEND, AND TO WHOM:

Feature                    What is sent               To
------------------------   ------------------------   -----------------
Design from a description  your text prompt and the   Google Cloud
                           catalogue context needed   (Vertex AI,
                           to answer it               Gemini)
AI product mockups         the product image, your    fal.ai
                           design, generation
                           parameters
In-editor AI image edit    the image you are          fal.ai
and upscale                editing, your instruction
Virtual try-on             your try-on photograph     fal.ai
                           and the product image
Artwork screening          the flattened print file   Google Cloud
                                                      Vision

8.3 WHAT WE DO NOT SEND. We do not send your name, email address, delivery address, payment information, balance, messages, comments, followers, or any account identifier that would let a provider connect a request to you as a person. A provider receives the content needed to do the job and the technical metadata of the request.

8.4 WHAT PROVIDERS MAY DO WITH IT. Providers process what we send in order to return a result to us, and may retain it for a short period for operational, abuse-prevention and safety purposes under their own terms. Their policies are linked in Section 10. WE DO NOT AUTHORISE ANY PROVIDER TO USE YOUR CONTENT TO TRAIN ITS MODELS FOR ITS OWN PURPOSES, and where a provider offers a contractual term or an account setting that excludes training on customer content, we use it. Their own policies govern what they do, and we cannot guarantee a provider's compliance with its own terms.

8.5 WE DO NOT TRAIN OUR OWN MODELS ON YOUR CONTENT. Persona does not train machine-learning models on your designs, your photographs, your prompts, your messages or your purchases.

8.6 RESULTS. Generated images are stored in your account alongside the job record so you can use them. You can delete them. Failed and expired jobs, and outputs you never promoted into a design, are removed by a periodic clean-up.

8.7 AUTOMATED ARTWORK SCREENING. Before artwork leaves the design studio we send the flattened print file to Google Cloud Vision's SafeSearch service, which returns likelihood scores across several categories plus descriptive labels. We act on the adult, violence and racy scores to block artwork. The remaining scores and the labels are kept for the audit trail and are not used to block. If the service is unreachable, the check is recorded as "not run" and you are let through - a safety check that cannot run must not become an outage. Screening does not look at intellectual property and does not detect hate symbols; that is what the report system is for.

9. What we do not do

9.1 WE DO NOT SELL YOUR PERSONAL INFORMATION, and we have not sold it in the preceding twelve months. We do not sell the personal information of anyone under 16.

9.2 WE DO NOT SHARE YOUR PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING, as those terms are defined in California law, and we have not done so in the preceding twelve months.

9.3 WE DO NOT USE THIRD-PARTY ADVERTISING TRACKERS. The app carries no advertising SDK and no advertising identifier.

9.4 WE DO NOT TRACK YOU ACROSS OTHER COMPANIES' APPS AND WEBSITES. That is why the app does not ask for App Tracking Transparency permission.

9.5 WE DO NOT SEE YOUR CARD NUMBER, its security code, or your bank credentials.

9.6 WE DO NOT USE YOUR CONTENT TO TRAIN MODELS (Section 8.5).

9.7 WE DO NOT MAKE DECISIONS WITH LEGAL OR SIMILARLY SIGNIFICANT EFFECTS ABOUT YOU BY AUTOMATED MEANS ALONE. See Section 24.

10. Who we share information with

10.1 We share personal information only with the service providers that make Persona work, and only what each one needs.

---------------------------------------------------------------------
Google (Firebase and Google Cloud)
  Receives    account identifiers, authentication data, all Firestore
              and Storage content, push tokens and message payloads,
              performance traces, function logs.
  For         hosting, database, file storage, authentication, push
              delivery, serverless compute, performance monitoring.
  Role        processor
  Policy      firebase.google.com/support/privacy
              cloud.google.com/terms/cloud-privacy-notice
---------------------------------------------------------------------
Google Cloud Vision
  Receives    the flattened print file of a design at the studio gate.
  For         automated content screening.
  Role        processor
---------------------------------------------------------------------
Google Cloud Vertex AI
  Receives    the text of your design request and catalogue context.
  For         interpreting a design request into a product specification.
  Role        processor
---------------------------------------------------------------------
Stripe
  Receives    payment details you enter, order amounts, currency, billing
              information; and for creators, the identity and bank
              information required to verify and fund a payout account.
  For         processing payments, refunds and disputes; verifying and
              paying connected accounts; fraud screening; currency
              conversion.
  Role        processor for payments; independent controller for its own
              compliance, fraud and connected-account obligations.
  Policy      stripe.com/privacy
---------------------------------------------------------------------
Our print-on-demand fulfilment partner
  Receives    the recipient's name, delivery address, phone number where
              supplied, the items ordered, and the artwork to be printed.
  For         producing, packing and shipping your order, and reviewing a
              defect claim.
  Role        processor
  Note        They receive no email address for marketing, no payment
              information, no balance, and nothing about your Persona
              account beyond the order.
---------------------------------------------------------------------
Carriers used by our fulfilment partner
  Receives    the recipient's name, delivery address, phone number where
              supplied.
  For         delivering the parcel and providing tracking.
  Role        independent controllers
---------------------------------------------------------------------
Algolia
  Receives    public product and public profile information: titles,
              descriptions, tags, categories, prices, images, usernames,
              display names and public counters.
  For         search.
  Role        processor
  Note        No email address, phone number, delivery address, balance,
              date of birth or payment identifier is sent to Algolia.
  Policy      algolia.com/policies/privacy
---------------------------------------------------------------------
RevenueCat
  Receives    your Persona account identifier, Store purchase receipts
              and subscription events.
  For         validating in-app purchases and managing entitlements.
  Role        processor
  Policy      revenuecat.com/privacy
---------------------------------------------------------------------
fal.ai
  Receives    images and prompts you submit for AI mockups, AI image
              editing and virtual try-on, including your try-on
              photograph.
  For         running the models that generate your result.
  Role        processor
  Policy      fal.ai/privacy
---------------------------------------------------------------------
Apple
  Receives    your Sign in with Apple identifier if you use it; your
              purchase and subscription activity for items bought in the
              App Store; speech audio if you use voice input on iOS;
              push messages routed through Apple Push Notification
              service.
  Role        independent controller
  Policy      apple.com/legal/privacy
---------------------------------------------------------------------
Google (Sign-In and Google Play)
  Receives    your Google account identifier if you sign in with Google;
              your purchase and subscription activity for items bought
              in Play.
  Role        independent controller
  Policy      policies.google.com/privacy
---------------------------------------------------------------------
Meta Platforms
  Receives    the information Facebook Login sends when you choose to
              sign in with Facebook, and the technical data the Facebook
              SDK collects when it is present in the app.
  Role        independent controller
  Policy      facebook.com/privacy/policy
  Note        This applies only if you sign in with Facebook.
---------------------------------------------------------------------
Email delivery
  Receives    your email address and the content of transactional emails.
  For         sending order confirmations, shipping notices and account
              messages.
  Role        processor
---------------------------------------------------------------------

10.2 OTHER USERS. Your public profile and everything you publish is shared with other users by design, and with anyone who opens a share link. A direct message is shared with its recipient. A comment is public.

10.3 CREATORS DO NOT RECEIVE BUYER DETAILS. A creator whose design you buy sees that a sale happened and the amount they earned. They do not receive your name, email address, delivery address or payment information.

10.4 LEGAL AND SAFETY. We may disclose information where we believe in good faith that it is necessary to comply with a law, a regulation, legal process or an enforceable governmental request; to enforce our Terms; to detect, prevent or address fraud, security or technical problems; or to protect the rights, property or safety of Persona, our users or the public. We will tell you about a legal request for your information unless we are prohibited from doing so or believe telling you would create a risk of harm.

10.5 BUSINESS TRANSFERS. If we are involved in a merger, acquisition, financing, reorganisation, bankruptcy or sale of assets, your information may be transferred as part of that transaction. We will tell you, and the recipient will be bound by commitments no less protective than this policy or you will be given a choice.

10.6 WITH YOUR DIRECTION. We share information as you direct - for example when you use the system share sheet to send a product to another app.

10.7 AGGREGATED AND DE-IDENTIFIED INFORMATION. We may create and use aggregated or de-identified information that cannot reasonably be used to identify you. We maintain it in de-identified form and do not attempt to re-identify it, except to test that our de-identification works.

11. Where your information is processed, and international transfers

11.1 Persona's databases, file storage and server functions run in Google Cloud in the UNITED STATES (region us-central1, Iowa). Your information is therefore processed in the United States regardless of where you live.

11.2 Our providers may process information in other countries. Our fulfilment partner operates a network of print facilities worldwide and will route your order to a facility that can produce it, which may be in a different country from you; your delivery address is transferred to that facility.

11.3 IF YOU ARE IN THE EEA, THE UK OR SWITZERLAND, your personal information is transferred outside your country. We rely on:

11.4 You may ask us for a copy of the transfer safeguards we rely on by writing to privacy@[[DOMAIN]].

12. How long we keep things

12.1 We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires.

---------------------------------------------------------------------
Category                          Retention
---------------------------------------------------------------------
Account, profile, designs,        until you delete them, or until you
drafts, saved items, likes,       delete your account
collections, follows

Direct messages                   until deleted by a participant, or
                                  until either participant deletes
                                  their account

Comments                          until you delete them or the product
                                  is deleted

Try-on photograph, derived        as set out in Section 6.7
avatar and generated try-on
images

AI job records                    image inputs and outputs are removed
                                  on a periodic sweep; the non-image
                                  record is kept for credit and billing
                                  reconciliation

Engagement events                 7 days, then automatically deleted;
                                  daily aggregates are kept

Creator analytics aggregates      for as long as your account exists

Push token                        removed when you sign out, or when
                                  the notification service reports the
                                  token as dead

Server and function logs          a short operational period, typically
                                  not more than 30 days, except where a
                                  log is preserved for a security
                                  investigation

ORDERS, INVOICES, PAYMENTS,       KEPT AFTER ACCOUNT DELETION,
REFUNDS, EARNINGS LEDGER,         de-identified where we can, for as
PAYOUT RECORDS                    long as tax, accounting, consumer
                                  protection and anti-fraud law
                                  requires - typically SEVEN YEARS from
                                  the transaction

Legal acceptance records          KEPT AFTER ACCOUNT DELETION, as
                                  contractual evidence, for the
                                  limitation period applicable to a
                                  claim under the agreement

Moderation, report and            kept while needed to operate our
enforcement records               repeat-infringer and safety policies,
                                  and to answer a related legal claim,
                                  normally not more than TWO YEARS after
                                  the matter closes

Support cases                     while the matter is open and for a
                                  reasonable period afterwards, normally
                                  not more than THREE YEARS

Backups                           encrypted backups roll off on their own
                                  schedule; deleted data disappears from
                                  them as they are overwritten
---------------------------------------------------------------------

12.2 WHY WE KEEP TRANSACTION RECORDS AFTER YOU LEAVE. Tax and accounting law requires a seller to keep records of what it sold, to whom and for how much. A refund or a chargeback can arrive months after a sale. And the other party to a sale - the creator whose design you bought, or the buyer who bought yours - has their own record of it, which we cannot destroy on one side only. These records are not used to contact you and are not used to rebuild a profile.

13. Security

13.1 We take reasonable and appropriate technical and organisational measures to protect personal information, including:

13.2 NO SYSTEM IS PERFECTLY SECURE. We cannot guarantee absolute security, and you send information to us at your own risk. Use a strong, unique password, do not reuse it elsewhere, and tell us immediately if you think your account has been accessed by someone else.

13.3 IF YOU FIND A VULNERABILITY, report it to legal@[[DOMAIN]]. Do not exploit it, do not access data that is not yours, and give us a reasonable period to fix it before disclosing it.

14. Your choices inside the app

You can, at any time, from inside Persona:

- edit or remove your display name, biography, profile image, cover image and links; - change your username, subject to a limit of one change every seven days; - delete a design, a draft, a collection, a comment or a message; - take a published product down; - choose who may start a direct message with you; - block another account; - delete your try-on profile and its images; - turn push notifications off in your device settings; - see and manage your subscription in the App Store or Play; and - delete your entire account.

15. Your privacy rights, and how to use them

15.1 Depending on where you live, you may have some or all of these rights:

  ACCESS          to know what personal information we hold about you and
                  to get a copy of it.
  PORTABILITY     to receive it in a structured, commonly used,
                  machine-readable format, and to have it sent to another
                  controller where technically feasible.
  CORRECTION      to have inaccurate information corrected.
  DELETION        to have your information deleted.
  RESTRICTION     to have processing restricted in certain circumstances.
  OBJECTION       to object to processing based on legitimate interests,
                  and to object to direct marketing at any time.
  WITHDRAW        to withdraw a consent you gave, at any time, without
  CONSENT         affecting processing already carried out.
  NO              not to be discriminated against for exercising a
  DISCRIMINATION  privacy right.
  COMPLAIN        to complain to your data protection authority.

15.2 HOW TO EXERCISE THEM. Email privacy@[[DOMAIN]] from the address on your account, or use the in-app tools in Section 14 and Section 21. Tell us what you want. If you write from a different address we will ask you to verify that you control the account, because handing your data to someone impersonating you would be worse than a delay.

15.3 HOW LONG WE TAKE. We respond within 30 days, or within 45 days where United States state law allows, and we may extend once where the request is complex - we will tell you if we do.

15.4 COST. Free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded, excessive or repetitive, and we will explain why.

15.5 AN AUTHORISED AGENT may make a request on your behalf where the law allows it. We will ask for proof of your authorisation and may ask you to confirm it directly.

15.6 WHAT WE CANNOT ALWAYS DELETE. Some requests conflict with a legal obligation - see Section 12.2. Where we cannot delete something, we tell you which category it is and why.

16. European Economic Area, United Kingdom and Switzerland

16.1 CONTROLLER. [[LEGAL ENTITY]], [[REGISTERED ADDRESS]].

16.2 REPRESENTATIVE. Our Article 27 representative in the EU is [[EU REPRESENTATIVE]]. In the UK it is [[UK REPRESENTATIVE]]. You may contact them on any matter relating to our processing of your personal data.

16.3 LEGAL BASES. Set out per category in Section 4. In summary we rely on:

  Contract         to give you an account, to run the marketplace, and
                   to take and fulfil your orders.
  Legal obligation to keep tax, accounting and transaction records, to
                   operate an age gate, and to respond to legal process.
  Legitimate       to secure the service, prevent fraud and abuse, rank
  interests        and improve what you see, evidence agreements, and
                   defend legal claims. We have balanced these interests
                   against your rights and you may object at any time.
  Consent          for optional features you switch on, in particular
                   virtual try-on, camera and photo library access,
                   push notifications, and any marketing email. You may
                   withdraw consent at any time.

16.4 AUTOMATED DECISION-MAKING. See Section 24.

16.5 YOUR RIGHT TO COMPLAIN. You may lodge a complaint with the supervisory authority in the EEA or UK country where you live, work, or where you think an infringement occurred. In the UK that is the Information Commissioner's Office, ico.org.uk. We would rather you told us first, at privacy@[[DOMAIN]], so we can fix it.

16.6 If you do not provide information we need to perform our contract with you - an email address, a delivery address - we cannot provide the corresponding part of the service.

17. California

This section supplements the rest of this policy for California residents, under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

17.1 NOTICE AT COLLECTION. The categories of personal information we collect, the purposes, the sources, the categories of third parties we disclose to and the retention periods are set out in Sections 4, 10 and 12.

17.2 CATEGORIES WE COLLECT, in CCPA terms:

  Identifiers                        yes - name, username, email,
                                     account identifier, IP address,
                                     device identifiers
  Customer records information       yes - delivery address, phone
  (Cal. Civ. Code 1798.80(e))        number, payment status
  Protected classification           yes - date of birth / age
  characteristics
  Commercial information             yes - orders, purchases,
                                     subscriptions, credits, earnings
  Biometric information              possibly - see Section 6. We do not
                                     use it to identify anyone.
  Internet or network activity       yes - product and profile views,
                                     likes, saves, searches, app
                                     interactions
  Geolocation data                   coarse only - country inferred from
                                     your device locale. NO PRECISE
                                     GEOLOCATION.
  Audio, electronic, visual          yes - images you upload, designs,
  information                        try-on photographs. NO VOICE
                                     RECORDINGS.
  Professional or employment         no
  Education information              no
  Inferences                         yes - preference and interest
                                     signals used to rank what you see
  Sensitive personal information     see 17.4

17.3 SOURCES. You; your device; our service providers (payment, store, fulfilment); and the platforms you sign in with.

17.4 SENSITIVE PERSONAL INFORMATION. We collect account credentials (a password, held only as a hash by our authentication provider) and, where you use virtual try-on, information that may be treated as biometric information. WE USE SENSITIVE PERSONAL INFORMATION ONLY FOR THE PURPOSES PERMITTED BY SECTION 1798.121(a) AND ITS REGULATIONS - to perform the service you asked for, to secure your account, and to detect and prevent fraud. We do not use or disclose it to infer characteristics about you. Because of that, we are not required to offer, and do not offer, a separate "Limit the Use of My Sensitive Personal Information" control.

17.5 SALE AND SHARING. WE DO NOT SELL PERSONAL INFORMATION AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING. We have not done either in the preceding twelve months, including for consumers under 16. Because we do not, we do not provide a "Do Not Sell or Share My Personal Information" link; if that ever changes, we will add one and update this policy first.

17.6 DISCLOSURES FOR A BUSINESS PURPOSE. In the preceding twelve months we disclosed the categories in 17.2 to the categories of recipients listed in Section 10, for the business purposes described there.

17.7 YOUR CALIFORNIA RIGHTS. To know, to access a copy, to know the specific pieces, to delete, to correct, to opt out of sale or sharing (not applicable - see 17.5), to limit the use of sensitive personal information (not applicable - see 17.4), and not to be retaliated against for exercising any of them. Exercise them as in Section 15.2. We will not deny you goods or services, charge you a different price, or give you a lower quality of service because you exercised a right.

17.8 SHINE THE LIGHT. California Civil Code Section 1798.83 lets California residents ask about disclosures of personal information to third parties for their own direct marketing purposes. We make no such disclosures.

17.9 CALIFORNIA MINORS. If you are a California resident under 18 and a registered user, you may ask us to remove content you posted publicly, by writing to privacy@[[DOMAIN]]. Removal may not be complete or comprehensive - for example where the content has been copied by someone else or where the law requires us to keep it.

18. Other United States states

18.1 If you live in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island or another state with a comprehensive consumer privacy law, you have rights to confirm whether we process your personal data, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects.

18.2 WE DO NOT ENGAGE IN targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects, so those opt-outs have nothing to apply to. If that changes we will update this policy and provide the mechanism, including recognition of universal opt-out signals where the law requires it.

18.3 SENSITIVE DATA CONSENT. Where your state requires opt-in consent before processing sensitive data - which in several states expressly includes biometric data - we obtain it in the app before the feature runs. See Section 6.5.

18.4 APPEALS. If we refuse a request, you may appeal by replying to our decision or writing to privacy@[[DOMAIN]] with "Privacy Appeal" in the subject. We will respond within 45 days with a written explanation. If we deny your appeal, you may contact your state Attorney General, and we will tell you how.

18.5 WASHINGTON AND NEVADA. We do not collect or process "consumer health data" as defined by the Washington My Health My Data Act or Nevada SB 370, and we do not sell it. Try-on photographs are used only as described in Section 6 and are not used to infer any health condition, body measurement, or physical characteristic about you.

19. Canada, Australia, New Zealand, Brazil, India and elsewhere

19.1 CANADA. We handle personal information in accordance with PIPEDA and applicable provincial law, including Quebec's Law 25. You may access and correct your information and complain to the Office of the Privacy Commissioner of Canada. Your information is stored and processed outside Canada, in the United States, where it may be accessible to courts and authorities of that country.

19.2 AUSTRALIA AND NEW ZEALAND. We handle personal information in accordance with the Australian Privacy Principles and the New Zealand Privacy Act 2020. You may request access and correction, and complain to the OAIC or to the New Zealand Privacy Commissioner. We disclose personal information to overseas recipients, principally in the United States.

19.3 BRAZIL. We process personal data in accordance with the LGPD. You have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. Contact privacy@[[DOMAIN]].

19.4 INDIA. We process personal data in accordance with the Digital Personal Data Protection Act, 2023. You have rights of access, correction, erasure, grievance redressal and nomination. For grievances, contact privacy@[[DOMAIN]]; we will respond within the period the law requires.

19.5 ELSEWHERE. Wherever you live, you may write to privacy@[[DOMAIN]] and we will do our best to give you the same rights, whether or not your local law requires it.

20. Children and teenagers

20.1 PERSONA IS NOT FOR CHILDREN UNDER 13. We do not knowingly collect personal information from anyone under 13. Our sign-up asks for a date of birth and refuses to create an account for anyone under 13.

20.2 IF WE LEARN that we have collected personal information from a child under 13, we will delete it and close the account promptly. If you believe a child has given us information, write to privacy@[[DOMAIN]] and we will act.

20.3 TEENAGERS. Persona limits what younger accounts can do:

  13-15   browsing, designing and AI features. NO publishing, NO
          comments, NO direct messages, NO buying, NO payouts.
  16-17   adds publishing, comments, direct messages and buying.
  18+     adds payout accounts and withdrawing earnings.

20.4 We do not serve behavioural advertising to anyone, of any age, and we do not sell or share the personal information of anyone under 16.

20.5 PARENTS AND GUARDIANS may contact privacy@[[DOMAIN]] to review, correct or delete their child's information, or to close the account. We will verify the relationship before acting.

21. Deleting your account

21.1 TWO WAYS, AND THE FIRST IS IMMEDIATE.

In the app       Settings > Delete account. You confirm by typing
                 DELETE. Deletion runs immediately.
On the web       the delete-account page on our legal site, or email
                 privacy@[[DOMAIN]] from the address on your account with
                 the subject "Delete my account". We verify it is you and
                 action it within 30 days.

21.2 WHAT IS DELETED:

- your profile: display name, username, biography, photo, links - your username, released back to the registry - your designs and drafts, and every product you published is taken down - your uploaded files, including try-on photographs, derived avatars and generated try-on images - saved items, collections, likes and comment likes - your direct messages, your follows and your followers - your credit wallet and its ledger - your AI job records and generated outputs - your push tokens - your sign-in credentials

21.3 WHAT IS KEPT, AND WHY:

ORDERS, INVOICES, PAYMENT AND REFUND RECORDS, THE EARNINGS LEDGER AND PAYOUT RECORDS - de-identified where we can. Tax, accounting, consumer protection and anti-fraud law requires a seller to keep them, and the other party to a sale has their own record of the transaction which we cannot destroy on one side only.

LEGAL ACCEPTANCE RECORDS - which version of the Terms and this policy you accepted, and when. This is contractual evidence.

MODERATION AND ENFORCEMENT RECORDS where they are needed to operate our repeat-infringer policy or to answer a legal claim.

These are the only categories kept, they are not used to contact you, and they are not used to rebuild a profile.

21.4 WHAT WE CANNOT REACH:

- a message you sent to someone else, in their copy of the conversation, where the law requires us to leave their record intact; - a product someone has already bought or lawfully remixed; - anything you or someone else shared outside Persona; - a copy in an encrypted backup, until that backup rolls off.

21.5 WHEN DELETION IS BLOCKED. The app will not let you complete deletion while you hold an unpaid balance, owe us an amount, have a payout in transit, or have an order still being made or delivered. Deleting at that moment would destroy your claim to money or goods. Withdraw or wait, then delete. If you are stuck, write to support@[[DOMAIN]].

21.6 SIGNING OUT IS NOT DELETING. Signing out removes your push token from your account and nothing else.

22. Cookies and similar technologies

22.1 THE MOBILE APP does not use cookies. It stores data on your device to work: your sign-in session, cached images, your preferences, and a small amount of state the app needs between launches. You can clear all of it by deleting the app.

22.2 OUR WEB PAGES - the legal pages, the share preview pages, and the hosted design editor loaded inside the app - use only what is strictly necessary to serve the page and keep it secure. WE DO NOT USE ADVERTISING COOKIES, ANALYTICS COOKIES, OR THIRD-PARTY TRACKING PIXELS ON THEM.

22.3 The hosted design editor stores your work in progress locally in the browser view so that a dropped connection does not lose your design.

22.4 Because we use no non-essential cookies, we do not show a cookie consent banner. If that changes, we will implement consent before setting any non-essential cookie.

23. Notifications and marketing

23.1 TRANSACTIONAL MESSAGES. We send you emails and push notifications that the service requires: order confirmations, production and shipping updates, delivery notices, earnings releases, payout results, security alerts, changes to these documents, and replies to your support cases. You cannot opt out of these while you have an account, because they are part of the service. You can turn PUSH off in your device settings and still receive the email.

23.2 ACTIVITY NOTIFICATIONS. Follows, likes, comments, messages, remix activity. Control these in your device notification settings.

23.3 MARKETING. If we send marketing emails, we will ask for your consent where the law requires it, every message will carry an unsubscribe link, and unsubscribing will take effect promptly. We do not share your email address with anyone for their own marketing.

23.4 PUSH TOKENS. Your push token is stored with your account so we can reach your device, is removed when you sign out, and is deleted when the notification service tells us the token is dead.

24. Automated decision-making and profiling

24.1 WE USE AUTOMATED SYSTEMS to:

24.2 WE DO NOT MAKE DECISIONS THAT PRODUCE LEGAL EFFECTS CONCERNING YOU, OR SIMILARLY SIGNIFICANTLY AFFECT YOU, SOLELY BY AUTOMATED MEANS. Where an automated signal would lead to a serious outcome - removing a product, suspending or closing an account, withholding a payout - a person reviews it before it becomes permanent, and you can appeal to a person as described in the Terms.

24.3 The age gate is an automated check against the date of birth you supplied and, where available, the platform's age signal. If you believe it has the wrong result, write to support@[[DOMAIN]].

24.4 You may ask us for information about the logic involved in an automated decision affecting you, express your point of view and contest it, by writing to privacy@[[DOMAIN]].

25. Data breaches

25.1 We maintain procedures for detecting, investigating and responding to a personal data breach.

25.2 If a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the GDPR applies, and will notify you without undue delay where the risk is high.

25.3 Where United States state law requires notification, we will notify you and the relevant authorities in the time and manner that law requires.

26. Changes to this policy

26.1 We may update this policy. When we do we change the version and date at the top and publish the new text at the same address.

26.2 Where a change is material we will tell you in the app before it takes effect, and where the law requires consent we will ask for it.

26.3 We keep the version and hash of every published version, and your acceptance record identifies the exact text you agreed to.

27. How to contact us

Privacy, data rights, deletion   privacy@[[DOMAIN]]
General and orders               support@[[DOMAIN]]
Legal and reports                legal@[[DOMAIN]]
Copyright                        dmca@[[DOMAIN]]

[[LEGAL ENTITY]] [[REGISTERED ADDRESS]] Company number: [[COMPANY NUMBER]]

EU representative (GDPR Art. 27): [[EU REPRESENTATIVE]] UK representative (UK GDPR Art. 27): [[UK REPRESENTATIVE]]

================================================================================

================================================================================