Modello Privacy Policy
Edition of 21 August 2026. Published at https://www.modello.style/en/privacy.
Data controller (operator): Individual Entrepreneur MAKSIM POLIKANOV, identification number 304820433, registered address: Georgia, Tbilisi City 0108, Nino and Ilia Nakashidze Street N 1 (former Avlevi Area), Building N 3, Apartment N 3.
Contact for any questions about this policy, your data, and rights requests: hello@modello.style.
We have not appointed a Data Protection Officer (Art. 37 GDPR): the conditions that make the appointment mandatory do not apply to us. All requests are handled by the operator at the address above.
1. What this document is about
Modello is a clothing-advice service. We determine your colour type and body type, show you outfits and try them on your photo. This requires your data, and this document says which data, why, where it goes and how to take it back.
We describe only what we actually do. If the text says "deleted on request", the deletion function exists and works.
2. What data we process
Account data. Email address, the name you entered at registration, the registration date and the date of your last sign-in. The password is stored as an irreversible hash — we cannot see or recover it.
Figure answers. Shoulder-to-hip ratio, waist definition, where weight tends to go, torso and leg proportions. These are your own assessments, not measurements.
Photographs. Two kinds, both uploaded by you:
- *Selfie* — used once, to determine your colour type from the tone of your
skin, eyes and hair. We do not store the image itself: it is sent for analysis and does not remain in our database.
- *Figure photo* — used to show how an outfit looks on you.
Try-on results. Try-on images are kept in private file storage. Links used to display them in the app are valid for no longer than one hour: after that, access to the file closes automatically even if the link was saved.
We do not use photographs to establish your identity. We do not compare them with other images, build biometric templates from them, recognise faces or pass them to anyone for those purposes. To us a photograph is raw material for clothing advice.
Subscription and payment data. Plan, amount, currency, period, promo code, status. We do not receive or store bank card details — they are handled by the payment system.
Usage data. Number of try-ons, their dates, saved results, the remaining try-on allowance.
Invitation data. If you arrived via someone's link — the inviter's code and the date of the visit. If you invite others — counters of visits and registrations under your code. Partners receive numbers only: no addresses, no names, no photographs of the people they invited.
What we do not collect. When you follow an invitation link, we place no markers in your browser — no cookies and no other identifiers by which you could be recognised on a later visit. We do not record your IP address and do not build a browser fingerprint. Attribution works through the code: you enter it yourself at registration, or it arrives in the address of the link you followed. This means we cannot tell your repeat visit from someone else's first one — and we do not try: the partner's visit counter is inflated by this, and we preferred an imprecise number to an identifying marker on your device. We determine your location at country level only and do not store the IP address itself. We do not buy data about you from third parties and do not enrich your profile from outside sources.
3. Why we process it
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name, password | Creating and protecting the account | Performance of the contract with you |
| Figure answers | Determining body type and tailoring recommendations | Performance of the contract |
| Selfie (not stored) | Colour type determination | Your consent |
| Figure photo | Outfit try-on | Your consent |
| Subscription and payments | Providing the paid service, settlements, responding to payment disputes | Performance of the contract and accounting legislation |
| Usage | Enforcing plan limits, protection against abuse | Performance of the contract and our legitimate interest |
| Invitations | Calculating partner rewards | Performance of the contract with the partner |
| Onboarding funnel milestones | Understanding where onboarding is hard and fixing that step | Our legitimate interest (Art. 6(1)(f) GDPR) |
| "How did you hear about us?" answer | Understanding which channels bring people to us | Our legitimate interest (Art. 6(1)(f) GDPR) |
| Clicks through to shops from the "Find similar" block | Understanding which selections and shops are useful to people | Our legitimate interest (Art. 6(1)(f) GDPR) |
| Stylist chat conversation | Answering your questions about clothing | Performance of the contract |
Onboarding funnel measurement. We record which onboarding steps you reached: started, reached your portrait, entered the colour questionnaire, completed it. The record holds only the step name, your identifier and the time — no IP address, no device information, no cookies. This lets us see where people find it hard and fix that step. Basis: our legitimate interest (Art. 6(1)(f) GDPR). Retention: 180 days; deleting your account removes these records. You may object to this processing by writing to hello@modello.style.
How did you hear about us. After you receive your style analysis, we ask where you heard about us: Instagram, TikTok, a stylist's recommendation, a friend's recommendation, or "something else". The answer is optional — you can skip the question. The record contains only the option you selected, your account identifier and the time; there is no free text in it and we do not show a text input field. This helps us understand which ways of reaching people work and avoid spending money on those that do not. The answer does not affect the price or the content of your recommendations. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR). The record lives for as long as your account exists; deleting your account removes it. You may object to this processing by writing to hello@modello.style.
Clicks through to shops. Below the outfit verdict we show a "Find similar" block with buttons that take you to shops. When you press one, we record on our side which shop the click led to, which item category it was (top, bottom, dress, outerwear, shoes, accessory) and which market you are in. The record holds only these three attributes, your identifier and the time — no IP address, no device information, no cookies; we do not see the link itself or what you did next in the shop. This lets us understand which item categories and which shops are genuinely useful, and decide what to develop next on that basis. The click is an ordinary link: we tell the shop nothing about you. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR). Retention: 24 months — clothing runs on a yearly season, and comparing one autumn with the next needs a full cycle plus headroom. Deleting your account removes these records. You may object to this processing by writing to hello@modello.style.
Verdict on a wardrobe item. When you ask us to assess an item from your wardrobe, its photo is transferred to Anthropic (USA) for analysis. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR). The photo is stored with us until you delete the item or your account; the analysis result is saved only if you press "Save" yourself.
Category and colour suggestion. When you add an item to your wardrobe, its photo is transferred to Anthropic (USA) so that the model can suggest a category and a colour. This happens at the moment the photo is added, without a separate request on your part — in other words, the photo is transferred automatically. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR). A daily limit applies; if the limit is exhausted or the model is unavailable, the item is added as before: you fill in the fields manually. The photo is stored with us until you delete the item or your account. The model's suggestion is saved alongside your choice so that we can measure the quality of automatic detection.
Stylist chat. Your clothing questions and the stylist's answers are stored so that the conversation continues coherently: when replying, we take into account what you asked before. Questions are processed by our sub-processor Anthropic (USA) under standard contractual clauses; no photographs are sent to the chat — text only. The conversation is kept for 180 days, then deleted; deleting your account removes it immediately. Answers are written by artificial intelligence, and this is indicated on the screen.
4. Who we share data with
We do not sell data and do not share it for anyone else's advertising. Data goes only to those without whom the service does not work:
| Recipient | What it receives | Where it processes |
|---|---|---|
| FASHN AI | Figure photo, outfit image and a photo of an item from your wardrobe — for try-on | USA and South-East Asia — see the note below |
| Anthropic | Selfie for colour type determination; outfit images submitted for the "will this suit me" check; textual portrait data | USA |
| Supabase | Database and file storage | Germany (Frankfurt, eu-central-1) |
| Vercel | Running the application | Germany (Frankfurt, fra1) |
| Resend, Cloudflare | Sending and delivering emails | USA, EU |
| Paddle (Merchant of Record) | Payment data | EU and USA |
About FASHN AI specifically. This recipient in turn engages its own subcontractors and publishes their current list on its website. Image processing takes place not only in the USA but also in South-East Asia — this is confirmed by the recipient itself. The transfer is covered by the European Commission's Standard Contractual Clauses.
We cannot name the exact country for a specific try-on: the recipient chooses the route and does not report it to us. So we list all countries where processing is possible rather than the one where it happened. The duty to tell you this is ours, and we chose to name more rather than less.
How long your photo lives there. We transfer images as data, not as links. Per the recipient's written confirmation of 18 August 2026: the source photo is erased immediately after processing, and the result is kept for 60 minutes.
The recipient retains a technical record of the request itself — kept indefinitely, but it contains no photographs, only service marks: request number, time, status. Only we can link that record to you, through our own database — and that link is erased together with the try-on data.
We name the source plainly: this is the recipient's confirmation, not our own measurement. We cannot verify the periods on their side.
Each recipient operates under its processing terms. We transfer the minimum needed for the specific operation and do not grant them the right to use your data for their own purposes.
5. Retention periods
The table below mirrors the reference file src/lib/data-registry.ts and is edited there, not here: the periods are enforced by a daily clean-up job, and a mismatch between the text and the code would mean one of the two is wrong. A new data category is added to the table as a new row.
The selfie is not in the table because it is not stored at all: analysis happens at the moment of upload, and only the result is written to the profile — colour type name, palette and a short explanation. Verified against the code: the analysis route does not access file storage.
The outfit image submitted for the "will this suit me" check is not in the table for the same reason: it is not stored at all — analysis happens at the moment of upload, and we keep only the verdict text and the image's checksum for the cache. The image cannot be reconstructed from the checksum. Verified the same way: the check route does not write to file storage.
One exception, and it is not ours. Images are not stored by the service and are not used for training; if automated safety systems are triggered, the processor (Anthropic, USA) may retain the request materials for up to 2 years to investigate violations. That period is set by the processor and we cannot influence it — but omitting it would be untrue: the phrase "the image is not stored" is inaccurate without this caveat.
| What | How long |
|---|---|
| Account: email, password hash, confirmation and sign-in dates | While the account exists |
| Style profile: colour type, body type, measurements, language, year of birth | While the account exists |
| Figure photo | While the account exists — or until you replace or delete it |
| Wardrobe: item descriptions and photos | While the account exists |
| Assembled outfits and their contents | While the account exists |
| Personalised outfits | While the account exists |
| Sign-in methods and last sign-in date | While the account exists |
| Try-on jobs and the stylist verdict on an outfit | 90 days, then anonymised: verdict text and photo links are erased |
| Try-on results: links and images | 90 days or account deletion — whichever comes first |
| Outfit-verdict cache: image checksum, body type, gender, language, verdict text | 30 days, then deleted |
| Free-verdict usage records: who used it and when | 30 days, then deleted |
| Clicks through to shops: shop, item category, market | 24 months, then deleted |
| Consent journal | 3 years after consent withdrawal or account closure |
| Records of consent to immediate service after payment | 3 years after account closure; while the account is open — from the date of the record |
| Invitation link visits | 425 days, then deleted |
| Invitation-to-partner attribution and its events | While the account exists; anonymised after deletion |
| Waiting list | 730 days, then deleted |
| Granted closed-beta access | 730 days, then deleted |
| Subscriptions and try-on credit movements | Period set by accounting legislation |
| Partners and their contacts | Contract term plus the retention period for primary documents |
| Partner payouts | Retention period for primary documents |
| Database backups | 30-day rotation |
| Application logs | Period set by the hosting plan; they contain no free text about you |
| Photos at FASHN (try-on) | Source erased immediately after processing, result after 60 minutes |
| Request record at FASHN | Indefinite, but contains no photographs |
| Data at Anthropic | Per contract |
Separately — a service record that contains no data about you. We list it here because a promise of periods is worth little: it can only be checked if a trace of the checks themselves survives.
| What | How long |
|---|---|
| Daily clean-up run log: when it ran, how long it took, what it deleted | 365 days, then deleted |
5.1. Images of third parties in submitted materials
The outfit analysis feature lets you submit an image — for example, a screenshot from a social network — and find out whether the outfit shown in it suits your figure. Such images may include other people: models, content authors, bystanders.
What we do with the image. The image is transferred to our processor (Anthropic, USA) for analysis of the clothing: its cut, colour and silhouette. We do not identify people in the image, do not analyse their appearance, and expressly prohibit our systems from describing people — the analysis concerns the clothing, not the person.
What we store. The image itself is not stored by the service after the analysis (for the exceptional cases on the processor's side, see Section 5, "Retention periods"). We keep only the text of the clothing analysis and a technical fingerprint of the image (a sha256 hash, from which the image cannot be reconstructed) — for up to 30 days, with no link to the user who submitted it.
Legal basis. Any personal data of third parties appearing in such images is processed on the basis of legitimate interest (Art. 6(1)(f) GDPR): providing the user with the clothing analysis they requested — with safeguards that keep the impact on depicted persons to a minimum (processing without storage, a prohibition on analysing appearance, no identification). We cannot notify depicted persons individually — they are unknown to us and the image is not stored (Art. 14(5)(b) GDPR); this section serves as the public notice.
Your rights if you believe your image has been processed. You may object to the processing (Art. 21 GDPR) by writing to hello@modello.style. Please note: since images are not stored, we generally can neither confirm that a specific image was processed nor delete it — there is nothing to delete. Upon your request we will delete the stored analysis text if you provide the image itself so that we can compute its fingerprint.
6. Your rights
You can view your data in the app, correct it, withdraw consent to cross-border transfer in the settings, and delete the account — also in the settings, with no correspondence with us. On deletion we erase the profile, photographs, try-on results, consents and sign-in methods. Only anonymised settlement records remain if payments or partner rewards passed through your account: the reference to you in them is nulled.
Database backups are kept for 30 days on rotation — your data disappears from them within that period. We do not restore the data of those who asked for deletion: if a backup ever has to be deployed, deletions are applied again.
The record of which consents you gave and when is kept for 3 years. We need it as proof that we asked your permission; it contains no photographs and no descriptions of appearance.
Withdrawing the cross-border transfer consent immediately closes the functions that are impossible without it — above all try-on and colour type determination. The rest of the service remains available.
Rights requests: hello@modello.style. We reply within one month of receiving the request — the maximum period under Art. 12(3) GDPR. If a request proves complex, or there are several, the period may be extended by a further two months, and we will inform you of the extension and its reason within that same first month.
7. Specifics for Kazakhstan
This section describes the actual state of affairs and does not give a legal assessment. The question of how the Law of the Republic of Kazakhstan "On Personal Data and Their Protection" No. 94-V applies to our configuration is with our legal counsel; we will update the policy upon receiving the answer.
Where the data physically resides. The database and files are hosted in Germany — a Frankfurt data centre (eu-central-1); the application's server functions run there as well. We have no servers, legal entity, branch or representative office in Kazakhstan: the operator is an individual entrepreneur registered in Georgia.
We state this directly because the location of your data is a fact you are entitled to know before entrusting it — not a conclusion to be pieced together from other sections.
Cross-border transfer takes place on the basis of your separate consent — see the "Consent to Cross-Border Transfer" document published at https://www.modello.style/en/consent. The list of countries and recipients is given in Section 4.
Supervisory authority. You have the right to lodge a complaint with the authorised personal data protection body of the Republic of Kazakhstan.
8. Specifics for Russia
The service does not currently operate in Russia. We have no separate processing infrastructure in the Russian Federation: it has not been built or launched. All users' data is processed in Frankfurt, as described in Section 4.
The section remains in the policy because it describes the terms on which we would operate in Russia — and because naming the absence of that infrastructure directly is more honest than staying silent. Until it exists, what follows does not apply.
Localisation. Article 18 of Federal Law No. 152-FZ requires that Russian users' data be recorded, systematised and stored in databases located in Russia. This cannot be met without Russian infrastructure — so until it exists, we do not offer the service in Russia.
Photographs and biometrics. We do not use photographs to establish identity, so we do not treat them as biometric personal data. This approach follows the regulator's clarification of 09.03.2022 No. 09-3182-01. If we ever wish to use images for identification, that will require separate consent, and we will ask for it explicitly.
Sign-in methods. Registration and sign-in use an email address and password on our website. We do not use foreign authorisation services for sign-in.
Consent withdrawal and complaints. Consent is withdrawn in the app settings or by writing to hello@modello.style. You have the right to contact Roskomnadzor.
9. Children
The service is not intended for persons under 18. We do not knowingly collect children's data. If you are a legal guardian and discover that a child has registered, write to us — we will delete the account and the data.
10. Changes to this policy
A new edition is published at the same address with its date. The version of the consent you gave is stored together with a timestamp: we can always show which exact edition you agreed to. If changes affect the purposes of processing or the set of recipients, we will ask for consent anew rather than hide the edit in the text.