← Back to home

MIX MY LOOK · SOREVIQ

Privacy

Last updated: 7 September 2026

Scope: iOS app, TestFlight and landing page

This privacy policy covers the native MixMyLook iOS app in private TestFlight testing and the promotional website at mixmylook.app and the previous addresses mixmylook.de and mixmylook.com. The iOS app is the primary application; no separate web app is planned. The app is in development and this landing page does not yet offer a public download link.

The app sections describe the current test version. The separate website sections apply only to visits to the landing page. Controller, contact and rights information applies to both services. Outstanding contractual and configuration questions are expressly identified below.

Controller for app and website

Stefan Wille
trading as SOREVIQ
Pfadstraße 9
71069 Sindelfingen-Maichingen
Germany
info@soreviq.de

For privacy questions and requests concerning your rights, contact info@soreviq.de.

Email enquiries

If you email us, we process your sender address, any name you provide, message content and technical message details to respond. The email link opens your email app; the website itself does not send a message.

The legal basis is Article 6(1)(f) GDPR for general enquiries, or Article 6(1)(b) GDPR for a contract or pre-contractual steps you request. Please include only information needed for your question.

After the enquiry is resolved, we delete it when it is no longer needed. Statutory retention obligations or the need to establish, exercise or defend legal claims may require longer retention, with use restricted accordingly. The email provider for info@soreviq.de, any further recipients and possible processing outside the EEA still need verification.

Your rights – app and website

Subject to the applicable legal conditions, you have rights to access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18) and portability (Article 20). You may withdraw any consent you have given for the future, without affecting the lawfulness of earlier processing.

Right to object: Where processing relies on Article 6(1)(f) GDPR, you may object under Article 21 on grounds relating to your particular situation. We will assess whether the processing must stop. Contact: info@soreviq.de.

Under Article 77 GDPR, you may complain to a supervisory authority, particularly in the country of your habitual residence, workplace or an alleged infringement. The authority at the provider’s location is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

iOS app: local data, photos and backups

Clothing, original and edited images, person photos, looks, downloaded try-on images and local profile details are stored on your device. Signing in does not synchronise this collection to the cloud. Only a separately selected online function transmits the data required for that function.

Apple Vision removes backgrounds on the iPhone without sending images to an image service. Camera access, selected photos and files are used for the import functions you choose. You can manage permissions in iOS.

Manual exports are independent backup files. You choose their destination, such as iCloud Drive, and whether to share them. Apple processes files saved in iCloud under its own terms. Local data remains until the relevant deletion or removal of the app’s data. Deleting data in MixMyLook does not automatically remove external backups or photo-library images. Enabled iCloud sync propagates changes and individual deletions to other devices; see the iCloud section for limits. Device-wide backups depend on your iOS settings.

The purpose is to provide the wardrobe management and display functions you request. Where personal data is processed to provide the service, the basis is Article 6(1)(b) GDPR. Local functions do not require uploading the entire wardrobe.

iOS app: optional iCloud synchronisation

You can enable iCloud separately in settings. Only then are clothing and accessory details, original and edited images, person photos and the default-photo reference, saved outfits and completed try-on images transferred to Apple CloudKit in your Apple account’s private area. Technical account and record identifiers, checksums, change states and deletion markers support identification and synchronisation. All participating devices must run an updated app version; older versions may not honour the cloud-deletion block. Devices must use the same Apple and MixMyLook accounts. Data counts towards your iCloud storage.

Local profile details, passwords and session keys, pending AI jobs, the credit ledger, the unsaved outfit draft and external backup files are not synchronised. The app makes a local recovery copy before the first sync. Offline changes or insufficient storage may leave data only on the device for a time. Immediate background synchronisation is not guaranteed.

The purpose is the device synchronisation you request (Article 6(1)(b) GDPR, where necessary for that function). Apple processes data for iCloud under its applicable terms. Exclusively European processing or verified end-to-end encryption for every data type is not promised. Specific provider roles, transfer safeguards and provider log retention remain to be reviewed.

Disabling sync stops further synchronisation but does not delete existing cloud data. Individual deletions propagate while sync is enabled; unreferenced image files can remain until full cloud deletion. The separate iCloud deletion function removes the collection and its image files. A minimal blocking record remains without a fixed automatic deletion period to prevent updated devices from uploading again; reactivation of this deleted account area is not currently supported. Local data and exports remain. Normal account deletion does not automatically delete iCloud. Sync is not an independent backup.

iOS app: image credits and offer preview

The local credit ledger stores balances, reservations, job identifiers and bookings for the local account. It supports display and assignment of requested image jobs (Article 6(1)(b) GDPR). It is neither synced through iCloud nor included in wardrobe exports; complete local-data deletion removes the ledger. Offers are previews. Actual purchases, payment processing and automatic subscription credits are not implemented. Before launch, this notice will be updated for actual purchase and transaction data processing.

Use from age 13: protecting minors

MixMyLook is intended for people aged 13 and over. This does not mean every online feature has been cleared for minors. The current test version has no verified age-assurance or parental-authorisation process.

In Germany, where an online service is offered directly to a child and processing relies on consent, a parent or guardian must provide or authorise that consent below age 16 (Article 8 GDPR). This particularly concerns the optional AI image processing described here. An App Store age rating, Apple account or simple confirmation checkbox does not replace verification. Other legal bases and the interests of minors require separate assessment.

Approval of these consent-based features for ages 13–15 remains outstanding until a suitable process is implemented and checked. OpenAI guidance additionally requires implementing Zero Data Retention before processing personal data below the applicable age of digital consent. This has not been confirmed for this project. Policy wording does not implement technical access restrictions. See Article 8 GDPR and OpenAI: Under-18 guidance.

In simple terms: your photos are not publicly shared. If you enable iCloud, Apple receives data to sync your devices. If you confirm an AI feature, selected photos go to the listed image services. Do not use photos of other people without the necessary permission. Ask a parent or guardian if unsure, and contact us for help deleting data.

iOS app: sign-in and email delivery

For sign-in, which is required in the current app version, Supabase processes your email address, account ID, authentication data and technical connection and security information. Resend delivers requested one-time codes and recovery emails, processing recipient addresses, message content and delivery information. Password sign-in transmits the entered password to Supabase for authentication. If your version offers Sign in with Apple, Apple processes sign-in and Supabase receives the identity token, provider identifier and shared email or relay address. Session keys are stored in the iOS Keychain. Signing in does not upload the optional local display name and profile photo as a wardrobe synchronisation.

Processing supports sign-in, recovery and account security (Article 6(1)(b) GDPR). Abuse prevention and technical security logs support our legitimate interest in secure testing (Article 6(1)(f) GDPR). Account-based test features require the necessary account data. Account data is retained until account deletion. Exact retention periods for authentication, delivery and provider logs remain to be confirmed.

iOS app: optional AI image processing

Only after your confirmation are the clothing or person photos selected for a particular operation and processing instructions transmitted via Supabase Edge Functions to the OpenAI API. Signing in alone does not upload images. Our own backend does not persist input images; it processes them temporarily for the request. Provider logs are a separate matter.

Optional transmission and AI processing of selected images is based on your consent (Article 6(1)(a) GDPR). You can avoid further AI requests and withdraw consent for the future using the contact below. This cannot reverse processing already completed. Declining does not exclude local wardrobe features. Only use person photos you are entitled to process. Try-on images are illustrative and are not used for biometric identification or reliable fit assessment.

OpenAI states that API data is not used for model training by default without explicit permission. Abuse-monitoring logs may contain content and generally be retained for up to 30 days, with possible legal or safety exceptions. Neither Zero Data Retention nor exclusively European processing is confirmed for this project. The settings and terms actually enabled for the service govern its processing.

iOS app: results, job data and retention

Generated images are temporarily made available in private Supabase storage. App access expires one hour after job reservation, not one hour after completion. Technical cleanup runs on later authenticated requests by authorised test accounts. Physical deletion at exactly one hour is not guaranteed; failures or a lack of subsequent requests may extend retention. Results saved on your device remain independently.

Account IDs, job and attempt identifiers, input checksums, status, error details and timestamps support access control, reuse and prevention of duplicate paid requests. The basis is Article 6(1)(f) GDPR, particularly our legitimate interest in abuse prevention and reliable cost control. These metadata currently have no automatic time-based deletion and generally remain until account deletion. A bounded retention policy for ongoing operation still needs to be defined. The one-hour image-access limit is not a deletion deadline for job metadata.

A separate cleanup record containing account ID, job ID, storage path and expiry remains until successful file cleanup, including after account deletion. Non-personal aggregate daily budget counters remain independently.

iOS app: account and local deletion

Account deletion in the app requests deletion of the Supabase sign-in account. For an Apple-linked account, Apple authorisation is revoked first; your Apple account itself is not deleted. Sessions are revoked and associated profile, test-access and job records are deleted. Following successful account deletion, the current local account data on that device is removed. A technical account-ID-to-local-folder association remains to prevent reassignment to a guest. Other local accounts are not deleted. A failed step must not be treated as complete deletion.

Temporary result files and their cleanup records are removed separately through the cleanup process; account deletion does not guarantee immediate file deletion. Local deletion alone does not delete a sign-in account or data already transmitted to providers. This account deletion does not automatically fully delete other devices, exports, iCloud collections, photo-library images or provider logs retained for legal or technical reasons. Sync must first be disabled and any pending cloud deletion completed. Contact us below for additional deletion requests.

Private TestFlight testing

Apple distributes the beta through TestFlight and processes invitation or account data, device and version details, installation and usage data, and crash diagnostics. TestFlight automatically collects and shares crash and usage data with Apple and us as the developer; this cannot be opted out of within TestFlight. With a private email invitation, your name and email address may also be visible to us. Optional feedback can contain text and screenshots; check for personal information before submitting it.

We use available test information to organise testing and fix faults, based on our legitimate interest in a stable, secure app (Article 6(1)(f) GDPR). Apple also processes data for its own purposes under its privacy notices. Apple specifies one year for beta feedback; crash and usage information may be retained until the issues are resolved. Retention for feedback separately kept by us still needs to be defined. MixMyLook account deletion does not automatically delete this information.

Apple: TestFlight and privacy

App recipients and international processing

Recipients or service providers include Supabase for authentication, backend and temporary results; Resend for authentication emails; OpenAI for confirmed AI requests; and Apple for TestFlight, iCloud synchronisation or iCloud backups you choose. Contracting entities and roles must still be finally established from the relevant agreements. Apple acts as an independent controller for some of its own services.

The Supabase project is configured in eu-central-1. This does not establish exclusively European processing: edge execution, support, subprocessors, email delivery and AI services may involve processing outside the EEA, including the US. Providers publish privacy and data processing terms addressing international transfers. The applicability of standard contractual clauses, an adequacy decision or other safeguards to the specific contracts remains to be verified. This notice does not assert that data processing agreements or particular transfer guarantees have been confirmed. You can request information and, where applicable, copies of relevant safeguards using our contact details.

Supabase · Supabase DPA · Resend · Resend DPA · OpenAI API – Data controls · OpenAI DPA · Apple

Outstanding private-beta questions

Final provider and mandatory details, contracting entities and data processing agreements, actual transfer safeguards and regional settings, provider and diagnostic log retention, feedback retention, and a bounded job-metadata retention period remain to be clarified. The flagged website and contact details below also require final review. This policy describes the current state; it does not certify that all legal and technical requirements have been conclusively reviewed.

Website: At a glance

This separate section applies only to visits to the promotional website at mixmylook.app and the previous addresses mixmylook.de and mixmylook.com. Processing in the iOS app and private TestFlight testing is described above. You can read everything without an account. There are no photo uploads, newsletter sign-ups or payments. The outfit demo does not send your choices to a server or call an AI service.

Website: Website delivery and hosting

This landing page is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, using the “Website 5.0” web hosting plan. Delivering the website requires processing connection data, including your IP address.

IONOS’s general web hosting documentation lists the requested file, referrer, browser, operating system, device type, access time and an IP address anonymised on collection. It specifies eight weeks of retention and no transfer of this visitor data outside the EU. These product details still need confirmation for the existing “Website 5.0” plan. IONOS: processing by web hosting.

The purpose is website delivery, stability and security. Where personal data is processed, the legal basis is Article 6(1)(f) GDPR: our legitimate interest in an accessible, secure website. The necessary connection data is transmitted automatically; without it, the website cannot be delivered.

The hosting provider processes data as part of providing the service. Final verification of the data processing agreement under Article 28 GDPR and the privacy-related hosting configuration remains outstanding; completion of that review is not asserted here.

Website: IONOS WebAnalytics — pending verification

IONOS describes WebAnalytics as enabled by default, using either log files or a pixel and, according to the provider, no cookies. Whether and how the “Website 5.0” plan enables it for these domains has not yet been verified. IONOS: WebAnalytics.

The website code itself does not embed an analytics service. Host-side statistics still need to be checked and either disabled where possible or described with their actual technology, legal basis, retention and any necessary consent. A cookie-free implementation does not by itself remove the need for that assessment.

Website: Outfit demo, cookies and storage

The demo only processes fictional garment identifiers, locked pieces and saved combinations in the open page’s memory. They are not sent to us, linked to an account, or stored in cookies, localStorage, sessionStorage or IndexedDB. Reloading or switching languages resets the selection; browser restoration may temporarily preserve the page state.

Separately from the demo, a language manually selected using DE/EN is stored as “de” or “en” under “mixmylook-language” in this browser’s localStorage until you clear website data or select another language. It is not sent to us. Without a saved choice, only the general entry address uses the preferred browser languages; direct language links retain their language. This storage serves your expressly selected language setting.

The animation pause also applies only to the open page. Any storage or access on your device required for the demo is solely for the function you expressly choose (section 25(2)(2) TDDDG). The demo creates no usage profile.

Website: External links and locally delivered content

Fonts are selected from those already on your device. Images, styles and scripts are served from the website’s own webspace. There are no embedded videos, social widgets or externally loaded webfonts.

SOREVIQ and other linked websites load only when you follow a link. Their privacy notices then apply. Your demo selection is not passed on. GitHub is used for development and version control; the delivered website does not load content from GitHub.

Website: No automated decisions

This landing page makes no automated decisions with legal or similarly significant effects and performs no corresponding profiling. The random mixer merely selects sample clothing.