Back to Home

Privacy Policy

Grwr AI Platform FZ-LLC

Last Updated: January 18, 2026

Effective Date: January 18, 2026

1. Introduction

Welcome to Jarreb ("App," "Service," "we," "us," or "our"), operated by Grwr AI Platform FZ-LLC, a company registered in the United Arab Emirates. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.

Jarreb is an AI-powered fashion platform that enables users to create virtual avatars, virtually try on clothing from various retailers, manage digital wardrobes, and receive personalized style recommendations.

By accessing or using Jarreb, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Password (stored in encrypted/hashed form)
  • Full name (optional)
  • Phone number (optional)

2.2 Profile Information

You may choose to provide additional profile information:

  • Display name
  • Profile photo
  • Country/region preference
  • Preferred currency
  • Timezone

2.3 Biometric and Body Data

IMPORTANT: This section describes our collection and use of sensitive biometric data.

To provide our virtual try-on and avatar generation services, we collect and process:

2.3.1 Face Data

  • What we collect: Photographs of your face that you voluntarily upload for avatar creation
  • How we use it: Your face photos are processed by our AI systems (Google Gemini and GrowerAI) to generate a virtual avatar representation of you. This avatar is used solely for virtual try-on visualization purposes.
  • What we do NOT do: We do not use face data for facial recognition, identity verification, authentication, or any biometric identification purposes. We do not create facial geometry maps or biometric templates for identification.

2.3.2 Body Data

  • What we collect: Photographs of your body (front, side, back views) that you voluntarily upload
  • How we use it: Body photos are analyzed by our AI systems to:
    • Generate your virtual avatar for try-on visualization
    • Estimate body measurements for size recommendations
    • Analyze body type and shape for personalized styling advice
  • Derived data: From your photos, our AI may derive:
    • Height and weight estimates
    • Body measurements (shoulder, chest, waist, hip circumference)
    • Body type classification (e.g., ectomorph, mesomorph, endomorph)
    • Body shape classification (e.g., rectangle, triangle, hourglass)
    • Recommended clothing sizes

2.3.3 Appearance Attributes

With your consent, we may analyze and store:

  • Skin tone and undertone
  • Hair color
  • Eye color
  • Face shape

2.3.4 Biometric Data Storage and Retention

  • Storage location: Your photos and derived biometric data are stored securely on Supabase servers (cloud infrastructure)
  • Retention period: We retain your biometric data for as long as your account is active. You may delete your avatar and associated photos at any time through the app settings.
  • Deletion: Upon account deletion or your request, all biometric data including original photos, generated avatars, and derived measurements are permanently deleted within 30 days.

2.3.5 Third-Party Processing of Biometric Data

Your face and body photos are processed by:

  • GrowerAI: For avatar generation and virtual try-on rendering. GrowerAI processes your images to create your avatar but does not retain your original photos after processing.
  • Google Gemini (Google Cloud AI): For body analysis, measurement estimation, and style recommendations. Google processes images according to their Cloud Data Processing terms.

You have the right to opt out of biometric data collection by not uploading face or body photos. However, this will prevent you from using the avatar and virtual try-on features.

2.4 Wardrobe Data

When you use the digital wardrobe feature:

  • Photos of clothing items you upload
  • AI-extracted attributes (category, color, brand, material, style)
  • Custom names and notes you add
  • Wear frequency and history

2.5 Style and Preference Data

To personalize your experience:

  • Favorite colors, brands, and styles
  • Style aesthetic preferences
  • Products you view, like, save, or try on
  • Outfits you create or like
  • Size preferences

2.6 Transaction and Subscription Data

For purchases and subscriptions:

  • Subscription plan and status
  • Credit balance and transaction history
  • Purchase history (managed through Apple App Store or Google Play)
  • RevenueCat customer identifier

Note: We do not collect or store payment card information. All payment processing is handled by Apple (App Store), Google (Play Store), or RevenueCat.

2.7 Communications Data

  • AI chat conversations with our styling assistant
  • Messages and recommendations provided
  • Conversation history

2.8 Device and Technical Data

We automatically collect:

  • Device type and model
  • Operating system and version
  • App version
  • Unique device identifiers
  • IP address
  • Timezone
  • Language settings

2.9 Advertising Identifiers

With your permission (where required by law):

  • iOS: Identifier for Advertisers (IDFA), Identifier for Vendors (IDFV)
  • Android: Google Advertising ID (GAID)

These identifiers are used for analytics and attribution purposes only.

2.10 Usage and Behavioral Data

We collect information about how you use the Service:

  • Features accessed and actions taken
  • Products viewed, liked, saved, or tried on
  • Search queries
  • Time spent in the app
  • Navigation patterns

3. How We Use Your Information

We use the information we collect to:

3.1 Provide Core Services

  • Create and manage your account
  • Generate your virtual avatar from your photos
  • Provide virtual try-on functionality
  • Manage your digital wardrobe
  • Deliver personalized style recommendations
  • Process subscriptions and credits

3.2 Personalization

  • Analyze your style preferences
  • Recommend products based on your taste
  • Suggest outfits tailored to your body type and preferences
  • Calculate recommended sizes

3.3 Service Improvement

  • Analyze usage patterns to improve features
  • Debug and fix technical issues
  • Develop new features and services
  • Train and improve our AI models (using aggregated, de-identified data)

3.4 Communications

  • Send service-related notifications
  • Respond to your inquiries and support requests
  • Send marketing communications (with your consent)

3.5 Safety and Security

  • Detect and prevent fraud
  • Enforce our terms of service
  • Protect the security of our services

3.6 Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and processes

4. How We Share Your Information

4.1 Third-Party Service Providers

We share information with service providers who assist us in operating the Service:

ProviderPurposeData Shared
SupabaseDatabase, authentication, file storageAll user data (encrypted at rest)
Google Cloud (Gemini AI)Body analysis, style recommendations, AI featuresPhotos for analysis, conversation data
RevenueCatSubscription and purchase managementUser ID, subscription status, purchase events
AlgoliaProduct searchProduct data, wardrobe items (for search functionality)
AmplitudeAnalyticsUsage events, device data, anonymized user ID
AppsFlyerAttribution analyticsInstall events, device identifiers, conversion data
OrttoMarketing automationEmail, name, subscription status, engagement events
Google Cloud TasksBackground job processingJob metadata (no personal data in transit)
UpstashReal-time updatesJob status updates (no personal data)
ElevenLabsVoice synthesisText for voice generation
GrowerAIThe parent engine orchestrating all agentsUser info

4.2 Business Transfers

If Grwr AI Platform FZ-LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or uses of your information.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, government agencies).

4.4 With Your Consent

We may share your information for other purposes with your explicit consent.

4.5 What We Do NOT Sell

We do not sell your personal information to third parties. We do not share your biometric data (face photos, body photos, measurements) with third parties for their own commercial purposes.

5. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:

Data TypeRetention Period
Account informationUntil account deletion + 30 days
Biometric data (photos, measurements)Until account deletion or user request + 30 days
Avatar and try-on resultsUntil account deletion or user deletion
Wardrobe itemsUntil account deletion or user deletion
Chat conversationsUntil account deletion or user deletion
Transaction history7 years (for legal/accounting purposes)
Usage analyticsAggregated indefinitely; identifiable data for 2 years

After the retention period, data is permanently deleted or anonymized.

6. Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption: Data encrypted in transit (TLS/SSL) and at rest
  • Access controls: Role-based access with principle of least privilege
  • Authentication: Secure authentication with hashed passwords
  • Infrastructure: Cloud infrastructure with SOC 2 compliance (Supabase, Google Cloud)
  • Row-Level Security: Database policies ensuring users can only access their own data
  • Regular audits: Security practices reviewed and updated regularly

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Your Rights and Choices

7.1 Access and Portability

You have the right to:

  • Access your personal data through the app
  • Request a copy of your data in a portable format
  • View and manage your profile information

7.2 Correction

You can update or correct your information through the app settings or by contacting us.

7.3 Deletion

You have the right to delete:

  • Your avatar and associated photos (in app settings)
  • Individual wardrobe items
  • Chat conversations
  • Your entire account and all associated data

Account Deletion Process

When you request account deletion:

1. Grace Period: Your account enters a 30-day grace period during which:

  • Your account is immediately deactivated and you cannot log in
  • Your data remains intact but inaccessible
  • You can cancel the deletion and restore your account by contacting us

2. Permanent Deletion: After 30 days, your data is permanently deleted including:

  • All personal information (name, email, phone)
  • All biometric data (photos, avatar, measurements)
  • All wardrobe items and try-on results
  • All chat conversations and preferences
  • All files stored in our systems

3. Legal Retention: Certain data is archived for legal and accounting purposes:

  • Transaction and subscription history (retained for 7 years)
  • This archived data is anonymized and cannot be used to identify you
  • It is automatically purged after the retention period expires

How to Delete Your Account

  • In-App: Go to Settings > Account > Delete Account
  • Email: Contact info@jarrebai.com with your account email
  • FormL Submit a Deletion form on our website

You will receive confirmation of your deletion request and the scheduled permanent deletion date.

7.4 Biometric Data Rights

You have specific rights regarding your biometric data:

  • Right to be informed: This policy describes how we collect and use biometric data
  • Right to consent: You choose whether to upload face and body photos
  • Right to delete: You can delete your avatar and photos at any time
  • Right to opt out: You can use the app without the avatar feature

7.5 Marketing Communications

You can opt out of marketing communications by:

  • Using the unsubscribe link in emails
  • Adjusting notification settings in the app
  • Contacting us at privacy@grwr.ai

7.6 Analytics and Advertising

  • iOS: You can limit ad tracking in Settings > Privacy > Tracking
  • Android: You can opt out of personalized ads in Settings > Google > Ads

8. Children's Privacy

Jarreb is not intended for children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children under these ages.

If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete such information promptly.

If you believe we may have collected information from a child, please contact us at privacy@grwr.ai.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including:

  • United States (Google Cloud, Amplitude, AppsFlyer)
  • European Union (Supabase infrastructure options)
  • Other countries where our service providers operate

We ensure appropriate safeguards are in place for international transfers, including:

  • Standard contractual clauses approved by relevant authorities
  • Data processing agreements with all service providers
  • Compliance with applicable data protection laws

10. Region-Specific Rights

10.1 European Economic Area (EEA) and United Kingdom

If you are in the EEA or UK, you have additional rights under GDPR:

  • Legal basis: We process your data based on consent (biometric data), contract performance (account services), and legitimate interests (analytics, security)
  • Right to object: You can object to processing based on legitimate interests
  • Right to restrict: You can request restriction of processing
  • Right to lodge a complaint: You can complain to your local data protection authority

10.2 California Residents

Under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):

  • Right to know: You can request details about information collected
  • Right to delete: You can request deletion of your information
  • Right to opt out of sale: We do not sell personal information
  • Non-discrimination: We will not discriminate against you for exercising your rights

Categories of personal information collected: Identifiers, biometric information, commercial information, internet activity, geolocation data, inferences.

10.3 Illinois Residents (BIPA)

Under the Illinois Biometric Information Privacy Act:

  • We obtain your informed written consent before collecting biometric data
  • We disclose our retention schedule (account lifetime + 30 days, or 3 years from last interaction, whichever is shorter)
  • We will not sell, lease, trade, or profit from your biometric data
  • We store and protect biometric data using reasonable security measures
  • We permanently destroy biometric data when the purpose for collection has been satisfied or within 3 years of your last interaction with us, whichever occurs first

10.4 Texas Residents

Under the Texas Capture or Use of Biometric Identifier Act:

  • We inform you before capturing biometric identifiers
  • We will not sell or disclose biometric identifiers without consent
  • We protect biometric data using reasonable care
  • We destroy biometric data within a reasonable time after the purpose expires

10.5 United Arab Emirates

We comply with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection:

  • Processing is based on your consent
  • Data is processed for specified, explicit, and legitimate purposes
  • You have rights to access, rectify, and erase your data

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy in the app
  • Sending you an email notification
  • Displaying a prominent notice in the app

The "Last Updated" date at the top indicates when the policy was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Grwr AI Platform FZ-LLC

For data subject requests (access, deletion, correction), please email privacy@grwr.ai with the subject line "Data Subject Request" and include:

  • Your name and email associated with your account
  • The specific right you wish to exercise
  • Any relevant details to help us locate your information

We will respond to your request within 30 days.

Notice at collection