Privacy Policy

Effective Date: April 7, 2026 · Last Updated: April 7, 2026

1. Introduction and Scope

This Privacy Policy ("Policy") describes how Tiloka ("we," "us," "our," or the "Company") collects, uses, processes, discloses, retains, and protects personal information and other data when you access or use our website, applications, and any related services, features, content, or functionality (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with any part of this Policy, you must discontinue use of the Service immediately. This Policy applies to all visitors, users, and others who access or use the Service, regardless of how they access it, including through web browsers, mobile applications, application programming interfaces, or any other means. We may update this Policy from time to time, and your continued use of the Service following the posting of any changes constitutes acceptance of those changes.

2. Information We Collect

We collect information in several ways depending on how you interact with the Service. The categories of information we may collect include, but are not limited to, the following:

2.1 Information You Provide Directly

When you create an account, use our features, or otherwise interact with the Service, you may provide us with certain personally identifiable information, including but not limited to your email address, display name, profile photograph, and any other information you choose to submit. When you upload photographs, images, or other visual media to the Service for the purpose of utilizing our clothing detection, wardrobe management, virtual try-on, or outfit planning features, you are providing us with that content and any metadata embedded within it, such as EXIF data, geolocation tags, timestamps, device information, and image dimensions. You may also provide information when you submit feedback, contact us with inquiries, respond to surveys, participate in promotions, or otherwise communicate with us through any channel.

2.2 Information Collected Automatically

When you access or use the Service, we automatically collect certain information about your device, browsing actions, and usage patterns. This information may include your Internet Protocol (IP) address, browser type and version, operating system and platform, device type and unique device identifiers, referring and exit URLs, pages viewed and the order of those pages, the amount of time spent on particular pages, the date and time of your visit, the number of clicks, scroll depth, interaction patterns, error logs, crash reports, and other diagnostic data. We may also collect information about your general geographic location based on your IP address, which may include your country, region, city, and approximate latitude and longitude. This information is collected through cookies, web beacons, pixel tags, log files, and other similar tracking technologies as described in Section 6 of this Policy.

2.3 Information from Local Storage

The Service utilizes client-side storage mechanisms, including but not limited to browser-based databases and local storage APIs, to store your wardrobe items, try-on results, outfit plans, saved looks, preferences, and other user-generated content directly on your device. This data is stored locally and is not transmitted to our servers unless you create an account and enable cross-device synchronization, in which case such data may be synced to our cloud infrastructure to provide you with a seamless experience across multiple devices and sessions.

2.4 Information Derived from Your Use

We may derive or infer additional information about you based on your use of the Service. For example, we may analyze your uploaded images using automated systems to detect and categorize clothing items, identify colors, patterns, fabrics, and seasonal attributes, and generate descriptive metadata. This derived information is used to provide and improve the Service and does not constitute a separate collection of personal information beyond what you have already provided.

3. How We Use Your Information

We use the information we collect for various purposes, including but not limited to the following: (a) to provide, operate, maintain, and improve the Service and its features, including clothing detection, wardrobe management, virtual try-on generation, outfit planning, and content sharing; (b) to create and manage your account, authenticate your identity, and provide you with customer support; (c) to process and fulfill your requests, including processing uploaded images through our automated detection and generation systems; (d) to personalize and enhance your experience with the Service, including by remembering your preferences and settings; (e) to communicate with you, including sending you technical notices, updates, security alerts, and administrative messages; (f) to monitor and analyze trends, usage, and activities in connection with the Service for purposes of understanding how users interact with the Service and identifying areas for improvement; (g) to detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities and to protect the rights, property, and safety of Tiloka, our users, and others; (h) to enforce our terms and conditions and other applicable agreements; (i) to comply with applicable laws, regulations, legal processes, and governmental requests; and (j) to carry out any other purpose described to you at the time the information was collected or for which you provide consent.

4. Legal Bases for Processing

If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or another jurisdiction that requires a legal basis for processing personal data, our legal bases for collecting and using the personal information described in this Policy depend on the specific context in which we collect it. We may process your personal information because: (a) we need to perform a contract with you, including to provide the Service and manage your account; (b) you have given us consent to do so, which you may withdraw at any time; (c) the processing is in our legitimate interests, such as improving and marketing the Service, and those interests are not overridden by your data protection interests or fundamental rights and freedoms; (d) we need to comply with a legal obligation; or (e) we need to protect the vital interests of you or another person. Where we rely on your consent to process your personal information, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.

5. Disclosure of Your Information

We do not sell, rent, or trade your personal information to third parties for their commercial marketing purposes. However, we may share or disclose your information in the following circumstances: (a) with service providers, contractors, and other entities who perform services on our behalf, such as hosting, data storage, authentication, image processing, analytics, error monitoring, and communication services, provided that such entities are obligated to maintain the confidentiality of your information and are prohibited from using it for any purpose other than providing services to us; (b) in response to a request for information if we believe disclosure is in accordance with, or required by, any applicable law, regulation, legal process, or governmental request, including to meet national security or law enforcement requirements; (c) if we believe your actions are inconsistent with our user agreements or policies, or to protect the rights, property, and safety of Tiloka or others; (d) in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company; (e) between and among our current and future parents, affiliates, subsidiaries, and other companies under common control and ownership; and (f) with your consent or at your direction.

When you use features that generate publicly accessible content, such as sharing a look or outfit via a public link, certain information associated with that shared content, including the images and any descriptive metadata, will be accessible to anyone with the link. You should exercise caution when deciding what information to make available through such features.

6. Cookies and Tracking Technologies

We and our service providers use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your interactions with the Service. Cookies are small data files that are placed on your device when you visit a website. We use the following categories of cookies:

Strictly Necessary Cookies. These cookies are essential to provide you with services available through the Service and to enable you to use some of its features, such as access to secure areas. Without these cookies, certain services you have asked for cannot be provided, and we only use these cookies to provide you with those services. These cookies enable core functionality such as session management and authentication and cannot be disabled.

Analytics and Performance Cookies. These cookies are used to collect information about traffic to the Service and how users use the Service. The information gathered may include the number of visitors to the Service, the websites that referred them to the Service, the pages they visited on the Service, what time of day they visited the Service, whether they have visited the Service before, and other similar information. We use this information to help operate the Service more efficiently, to gather broad demographic information, to monitor the level of activity on the Service, and to improve the Service. These cookies collect information in aggregate form and are anonymized.

Functional Cookies. These cookies allow the Service to remember choices you make when you use the Service, such as remembering your language preferences, remembering your login details, and remembering the changes you make to other parts of the Service which you can customize. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you visit the Service.

Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of the Service. You may also opt out of certain analytics tracking as described in the applicable cookie preferences on the Service.

7. Data Retention

We retain your personal information for as long as is necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements. In some circumstances, we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. For data stored locally on your device through client-side storage mechanisms, retention is controlled by you and your browser settings.

8. Data Security

We implement appropriate technical and organizational security measures designed to protect the security of any personal information we process. These measures include, but are not limited to, encryption of data in transit using industry-standard Transport Layer Security (TLS) protocols, access controls limiting access to personal information to those employees, contractors, and agents who have a business need to know, and regular monitoring and auditing of our systems and practices. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. We cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security measures and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from the Service is at your own risk. You should only access the Service within a secure environment and are responsible for maintaining the confidentiality of any account credentials used to access the Service.

9. International Data Transfers

Your information, including personal information, may be transferred to and maintained on computers and servers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we may transfer the data, including personal information, to the United States and other jurisdictions and process it there. Your submission of such information represents your agreement to that transfer. Where required by applicable law, we will ensure that appropriate safeguards are in place to protect your personal information in accordance with this Policy, which may include the use of standard contractual clauses approved by the relevant regulatory authority, obtaining your explicit consent, or relying on other lawful mechanisms for the transfer of personal data across borders.

10. Your Rights and Choices

Depending on your location and subject to applicable law, you may have certain rights regarding your personal information. These rights may include:

  • Right of Access. You may have the right to request confirmation as to whether we are processing your personal information and, if so, to request a copy of the personal information we hold about you.
  • Right to Rectification. You may have the right to request that we correct any inaccurate personal information we hold about you and to have incomplete personal information completed.
  • Right to Erasure. You may have the right to request that we delete your personal information in certain circumstances, such as when the personal information is no longer necessary for the purposes for which it was collected.
  • Right to Restriction of Processing. You may have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the personal information or when you have objected to the processing.
  • Right to Data Portability. You may have the right to receive the personal information you have provided to us in a structured, commonly used, and machine-readable format and to transmit that information to another controller without hindrance.
  • Right to Object. You may have the right to object to the processing of your personal information in certain circumstances, such as when processing is based on our legitimate interests.
  • Right to Withdraw Consent. Where we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
  • Right to Lodge a Complaint. You may have the right to lodge a complaint with a data protection supervisory authority in your jurisdiction if you believe that we have violated applicable data protection laws.

To exercise any of these rights, please contact us using the information provided in Section 15 below. We will respond to your request in accordance with applicable law. We may need to verify your identity before processing your request. Please note that certain information may be exempt from such requests under applicable law. We will not discriminate against you for exercising any of these rights.

11. California Privacy Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"). Under the CCPA/CPRA, you have the right to request that we disclose what categories and specific pieces of personal information we have collected about you, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting or selling personal information, and the categories of third parties with whom we share personal information. You also have the right to request deletion of personal information we have collected from you, subject to certain exceptions. We do not sell personal information as defined by the CCPA/CPRA, and we do not share personal information for cross-context behavioral advertising purposes. California residents may exercise their rights by contacting us as described in Section 15. We will not discriminate against you for exercising your CCPA/CPRA rights. If you are a California resident under the age of 18 and a registered user of the Service, you may request that we remove content or information that you have publicly posted. Please note that such removal does not ensure complete or comprehensive removal of the content or information, as another user or third party may have re-posted or archived the content.

12. Children's Privacy

The Service is not directed to individuals under the age of sixteen (16), and we do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under the age of 16 without verification of parental consent, we will take reasonable steps to delete that information as quickly as possible. If you believe we might have any information from or about a child under 16, please contact us using the information provided in Section 15. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we can take the necessary steps to remove such information from our systems.

13. Do Not Track Signals

Some web browsers transmit "Do Not Track" ("DNT") signals to the websites and other online services with which the browser communicates. There is currently no universally accepted standard for how companies should respond to DNT signals. At this time, the Service does not respond to DNT signals. If and when a final standard is established and accepted, we will reassess how to appropriately respond to these signals. For more information about DNT signals, please visit the applicable resources provided by your browser vendor or operating system provider.

14. Changes to This Policy

We may update this Privacy Policy from time to time in order to reflect changes to our practices, technologies, legal requirements, and other factors. When we make changes to this Policy, we will update the "Last Updated" date at the top of this Policy and, where required by applicable law, we will provide you with additional notice, such as adding a statement to the Service or sending you a notification. We encourage you to review this Policy periodically to stay informed about our collection, use, and disclosure of personal information. Your continued use of the Service following the posting of changes to this Policy will be deemed your acceptance of those changes. If you do not agree to the updated Policy, you must stop using the Service.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at @AndreyNovikoov on X. We will endeavor to respond to all legitimate inquiries within a reasonable timeframe and in any event within any timeframe required by applicable law. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.