1. Introduction
Welcome to Jarreb ("App," "Service," "we," "us," or "our"), operated by Grwr AI Platform FZ-LLC, a company registered in the United Arab Emirates. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.
Jarreb is an AI-powered fashion platform that enables users to create virtual avatars, virtually try on clothing from various retailers, manage digital wardrobes, and receive personalized style recommendations.
By accessing or using Jarreb, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (stored in encrypted/hashed form)
- Full name (optional)
- Phone number (optional)
2.2 Profile Information
You may choose to provide additional profile information:
- Display name
- Profile photo
- Country/region preference
- Preferred currency
- Timezone
2.3 Biometric and Body Data
This section describes our collection and use of sensitive biometric data.
2.3.1 Face Data
- What we collect: Photographs of your face that you voluntarily upload for avatar creation
- How we use it: Your face photos are processed by our AI systems (Google Gemini and GrowerAI) to generate a virtual avatar representation of you. This avatar is used solely for virtual try-on visualization purposes.
- What we do NOT do: We do not use face data for facial recognition, identity verification, authentication, or any biometric identification purposes. We do not create facial geometry maps or biometric templates for identification.
2.3.2 Body Data
- What we collect: Photographs of your body (front, side, back views) that you voluntarily upload
- How we use it: Body photos are analyzed by our AI systems to generate your virtual avatar for try-on visualization, estimate body measurements for size recommendations, and analyze body type and shape for personalized styling advice
- Derived data: From your photos, our AI may derive height and weight estimates, body measurements (shoulder, chest, waist, hip circumference), body type classification, body shape classification, and recommended clothing sizes
2.3.3 Appearance Attributes
With your consent, we may analyze and store: skin tone and undertone, hair color, eye color, and face shape.
2.3.4 Biometric Data Storage and Retention
- Storage location: Your photos and derived biometric data are stored securely on Supabase servers (cloud infrastructure)
- Retention period: We retain your biometric data for as long as your account is active. You may delete your avatar and associated photos at any time through the app settings.
- Deletion: Upon account deletion or your request, all biometric data including original photos, generated avatars, and derived measurements are permanently deleted within 30 days.
2.3.5 Third-Party Processing of Biometric Data
Your face and body photos are processed by:
- GrowerAI: For avatar generation and virtual try-on rendering. GrowerAI processes your images to create your avatar but does not retain your original photos after processing.
- Google Gemini (Google Cloud AI): For body analysis, measurement estimation, and style recommendations. Google processes images according to their Cloud Data Processing terms.
You have the right to opt out of biometric data collection by not uploading face or body photos. However, this will prevent you from using the avatar and virtual try-on features.
2.4 Wardrobe Data
When you use the digital wardrobe feature:
- Photos of clothing items you upload
- AI-extracted attributes (category, color, brand, material, style)
- Custom names and notes you add
- Wear frequency and history
2.5 Style and Preference Data
- Favorite colors, brands, and styles
- Style aesthetic preferences
- Products you view, like, save, or try on
- Outfits you create or like
- Size preferences
2.6 Transaction and Subscription Data
- Subscription plan and status
- Credit balance and transaction history
- Purchase history (managed through Apple App Store or Google Play)
- RevenueCat customer identifier
We do not collect or store payment card information. All payment processing is handled by Apple (App Store), Google (Play Store), or RevenueCat.
2.7 Communications Data
- AI chat conversations with our styling assistant
- Messages and recommendations provided
- Conversation history
2.8 Device and Technical Data
- Device type and model
- Operating system and version
- App version
- Unique device identifiers
- IP address
- Timezone and language settings
2.9 Advertising Identifiers
With your permission (where required by law):
- iOS: Identifier for Advertisers (IDFA), Identifier for Vendors (IDFV)
- Android: Google Advertising ID (GAID)
These identifiers are used for analytics and attribution purposes only.
2.10 Usage and Behavioral Data
- Features accessed and actions taken
- Products viewed, liked, saved, or tried on
- Search queries
- Time spent in the app
- Navigation patterns
3. How We Use Your Information
3.1 Provide Core Services
- Create and manage your account
- Generate your virtual avatar from your photos
- Provide virtual try-on functionality
- Manage your digital wardrobe
- Deliver personalized style recommendations
- Process subscriptions and credits
3.2 Personalization
- Analyze your style preferences
- Recommend products based on your taste
- Suggest outfits tailored to your body type and preferences
- Calculate recommended sizes
3.3 Service Improvement
- Analyze usage patterns to improve features
- Debug and fix technical issues
- Develop new features and services
- Train and improve our AI models (using aggregated, de-identified data)
3.4 Communications
- Send service-related notifications
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
3.5 Safety, Security & Legal Compliance
- Detect and prevent fraud
- Enforce our terms of service
- Protect the security of our services
- Comply with applicable laws and regulations
- Respond to legal requests and processes
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion + 30 days |
| Biometric data (photos, measurements) | Until account deletion or user request + 30 days |
| Avatar and try-on results | Until account deletion or user deletion |
| Wardrobe items | Until account deletion or user deletion |
| Chat conversations | Until account deletion or user deletion |
| Transaction history | 7 years (for legal/accounting purposes) |
| Usage analytics | Aggregated indefinitely; identifiable data for 2 years |
After the retention period, data is permanently deleted or anonymized.
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights & Choices
7.1 Access and Portability
- Access your personal data through the app
- Request a copy of your data in a portable format
- View and manage your profile information
7.2 Correction
You can update or correct your information through the app settings or by contacting us.
7.3 Deletion
You have the right to delete your avatar and associated photos, individual wardrobe items, chat conversations, or your entire account and all associated data.
Your account is immediately deactivated. Your data remains intact but inaccessible. You can cancel the deletion and restore your account by contacting us.
After 30 days, all personal information, biometric data, wardrobe items, try-on results, chat conversations, preferences, and stored files are permanently deleted.
Transaction and subscription history is archived (anonymized) for 7 years for legal and accounting purposes, then automatically purged.
7.4 Biometric Data Rights
- Right to be informed: This policy describes how we collect and use biometric data
- Right to consent: You choose whether to upload face and body photos
- Right to delete: You can delete your avatar and photos at any time
- Right to opt out: You can use the app without the avatar feature
7.5 Marketing Communications
You can opt out via the unsubscribe link in emails, notification settings in the app, or by contacting us at privacy@grwr.ai.
7.6 Analytics and Advertising
- iOS: Limit ad tracking in Settings > Privacy > Tracking
- Android: Opt out of personalized ads in Settings > Google > Ads
8. Children's Privacy
Jarreb is not intended for children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children under these ages.
If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete such information promptly.
If you believe we may have collected information from a child, please contact us at privacy@grwr.ai.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States, European Union, and other countries where our service providers operate.
We ensure appropriate safeguards are in place for international transfers, including:
- Standard contractual clauses approved by relevant authorities
- Data processing agreements with all service providers
- Compliance with applicable data protection laws
10. Region-Specific Rights
10.1 European Economic Area (EEA) and United Kingdom
If you are in the EEA or UK, you have additional rights under GDPR:
- Legal basis: Consent (biometric data), contract performance (account services), and legitimate interests (analytics, security)
- Right to object: You can object to processing based on legitimate interests
- Right to restrict: You can request restriction of processing
- Right to lodge a complaint: You can complain to your local data protection authority
10.2 California Residents
Under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):
- Right to know: You can request details about information collected
- Right to delete: You can request deletion of your information
- Right to opt out of sale: We do not sell personal information
- Non-discrimination: We will not discriminate against you for exercising your rights
Categories of personal information collected: Identifiers, biometric information, commercial information, internet activity, geolocation data, inferences.
10.3 Illinois Residents (BIPA)
Under the Illinois Biometric Information Privacy Act:
- We obtain your informed written consent before collecting biometric data
- We disclose our retention schedule (account lifetime + 30 days, or 3 years from last interaction, whichever is shorter)
- We will not sell, lease, trade, or profit from your biometric data
- We store and protect biometric data using reasonable security measures
- We permanently destroy biometric data when the purpose for collection has been satisfied or within 3 years of your last interaction with us, whichever occurs first
10.4 Texas Residents
- We inform you before capturing biometric identifiers
- We will not sell or disclose biometric identifiers without consent
- We protect biometric data using reasonable care
- We destroy biometric data within a reasonable time after the purpose expires
10.5 United Arab Emirates
We comply with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection:
- Processing is based on your consent
- Data is processed for specified, explicit, and legitimate purposes
- You have rights to access, rectify, and erase your data
11. Third-Party Links and Services
The Service may contain links to third-party websites or services (e.g., retailer websites for products). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy in the app, sending you an email notification, or displaying a prominent notice in the app.
The "Last Updated" date at the top indicates when the policy was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
14. Consent
By creating an account and using Jarreb, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.
For biometric data specifically, by uploading face or body photos for avatar generation, you provide explicit consent to:
- The collection of your biometric data (face and body photographs)
- The processing of this data by Grwr AI Platform FZ-LLC and our processors (GrowerAI, Google Cloud)
- The storage of your biometric data for the purpose of providing virtual try-on services
- The retention of this data until you delete it or your account is terminated
You may withdraw your consent at any time by deleting your avatar or contacting us.
Grwr AI Platform FZ-LLC
This Privacy Policy is provided in English. In the event of any conflict between the English version and any translation, the English version shall prevail.
