Privacy Policy

Last updated: September 18, 2026

This Privacy Policy is prepared by İbrahim Mestav ("Styloom", "we", "the Operator"), the individual developer and operator of the Styloom mobile application (the "App"), and is also intended to satisfy the disclosure obligation under Article 10 of Turkey's Personal Data Protection Law No. 6698 ("KVKK"). For users located in the European Union, the rights available under the General Data Protection Regulation ("GDPR") are separately set out in this policy.

1. Identity of the data controller

The data controller for your personal data is İbrahim Mestav, the individual developer and operator of the App (Türkiye). For questions or requests, you can reach us at destek@styloom.app.

2. What data we collect

Your selfie (face data). We treat the selfie photo you capture or select as face data because it contains your face. It is processed only to generate a hairstyle/color/beard try-on or to produce a color analysis/hair report. It is permanently deleted from our servers instantly upon a successful generation, and in every case within 24 hours at the latest. The photo you use on the Studio screen stays only on your own device until you replace or delete it. This is so the app can remember your photo; we cannot access that device copy.

On-device camera guidance. During camera capture, Google ML Kit face detection runs on the device only to provide framing guidance. It may calculate a single-frame bounding box, yaw/pitch/roll angles, and eyes-open probability. This temporary geometry is not transmitted, persisted, used for recognition or authentication, or sent to any third party; it is discarded with the next frame.

Biometric identifiers: never. A face template, embedding, or any other biometric derivative is never extracted or stored.

Anonymous usage analytics. Collected only with your consent; you can withdraw it at any time from the Permissions and consents screen in the app. Your photos and face analysis never enter any analytics tool.

Device identifier. A device record is kept to prevent the free trial allowance from being claimed repeatedly on the same device. Even if you delete your account, this record continues to be kept with its link to your identity severed. This is to prevent abuse, not to track you.

Purchase data. Your subscription and credit purchases are processed via the App Store/Google Play and RevenueCat; your card details never reach us.

Crash/diagnostic data. If the app errors out, we receive diagnostic information via Sentry; screenshot and session-replay features are disabled.

3. Why we process your data

We process your personal data only for the following purposes:

4. Data transfers, including abroad

We use the following service providers to run the app; each is subject to its own privacy policy:

Equal protection for face data. We share a selfie with fal.ai and Google Gemini only to perform the AI operation the user requested. We require each recipient that receives face data to provide protections equal to or stronger than those described in this policy: purpose limitation, confidentiality and access controls, no advertising or unrelated profiling, no use to train or improve unrelated products, and deletion/retention limits consistent with this policy. We do not share face data with a recipient unless its applicable terms or agreement provides those protections.

These service providers' servers are located abroad (primarily in the United States); this transfer of data abroad falls under Article 9 of the KVKK. By using the app and uploading your photo, you give your explicit consent to this transfer; you may withdraw that consent at any time by discontinuing use of the app and deleting your account via Profile → "Delete account and data."

5. Collection method and legal basis

All data is collected electronically and automatically through the mobile app. The legal basis for processing is necessity for the performance of the service for selfie processing and purchase data, and your explicit consent for transfers abroad and for the optional analytics/report features.

6. Retention and deletion schedule

We don't leave how long we keep things vague:

DataRetention period
Source selfie (server)Permanently deleted instantly once processing completes, within 24 hours at the latest in every case
Generated image (server)Deleted immediately after delivery to/saving on your device; automatically deleted within 24 hours at the latest if not delivered
Studio selfie (your device)Kept only until you replace or delete it in Studio; deleting the app or using account deletion also removes the app's local selfie copy
Saved results (your device)Kept only in the app's local history; delete an individual result from History, or delete the app/account to remove the local history
Camera guidance geometry (device)Discarded with the next camera frame; never persisted or transmitted
Face template / biometric derivativeNever created
Analytics dataAnonymous/pseudonymous; associated server data is permanently deleted upon an account-deletion request
Device identifier (abuse prevention)Kept with its identity link severed after account deletion

7. Your rights as a data subject (KVKK Art. 11)

Under Article 11 of the KVKK, you have the right to:

8. How to exercise your rights

Right to delete. Using Profile → "Delete account and data" in a single step permanently deletes all server data linked to your account; this action cannot be undone.

Withdrawing face-data consent. At any time, open Profile → Permissions and consents and turn off Hairstyle generation and/or Color Analysis & Hair Report. Turning either switch off stops the corresponding selfie from being sent to our AI processors; the app asks for consent again before a later request for that operation. Turning off consent does not delete a selfie that is already on the device, so delete or replace the Studio photo separately if you want to remove that local copy.

Deleting face data. Delete the current Studio selfie by replacing or deleting it in Studio. Delete a saved generated image from History using its delete control; a copy saved separately to the device photo gallery is controlled by the device owner and is not affected by deleting an in-app history item. Profile → "Delete account and data" deletes the account's server data and clears the app's local selfie, local history, consent state, and cached generated files. Server-side source selfies and generated outputs are deleted according to the schedule in Section 6, including the 24-hour safety-net limit.

Withdrawing analytics consent. You can also turn off analytics sharing at any time from Profile → Permissions and consents; your photos are never included in analytics.

Other requests. You can submit requests regarding the rights above by writing to destek@styloom.app; depending on the nature of the request, we respond within 30 days at the latest and in the manner prescribed by the KVKK.

AI disclosure. All images in the app are generated with AI; this is stated clearly on the onboarding and result screens as well.

9. Additional information for EU (GDPR) users

If you are located in the European Union, in addition to the rights above you also have the right to object to the processing of your data under the GDPR and to lodge a complaint with the competent data protection authority in your country. The legal bases for processing and the retention periods are the same as set out in the sections above.

10. Children's privacy. Styloom is not directed at children and does not knowingly collect data from children.

11. Changes to this policy

We may update this policy from time to time. When a material change occurs, we will notify you from within the app; the current version is always available on this page.

12. Contact

You can write to destek@styloom.app with any questions about this policy.