Privacy Policy
Last updated: September 18, 2026
This Privacy Policy is prepared by İbrahim Mestav ("Styloom", "we", "the Operator"), the individual developer and operator of the Styloom mobile application (the "App"), and is also intended to satisfy the disclosure obligation under Article 10 of Turkey's Personal Data Protection Law No. 6698 ("KVKK"). For users located in the European Union, the rights available under the General Data Protection Regulation ("GDPR") are separately set out in this policy.
1. Identity of the data controller
The data controller for your personal data is İbrahim Mestav, the individual developer and operator of the App (Türkiye). For questions or requests, you can reach us at destek@styloom.app.
2. What data we collect
Your selfie (face data). We treat the selfie photo you capture or select as face data because it contains your face. It is processed only to generate a hairstyle/color/beard try-on or to produce a color analysis/hair report. It is permanently deleted from our servers instantly upon a successful generation, and in every case within 24 hours at the latest. The photo you use on the Studio screen stays only on your own device until you replace or delete it. This is so the app can remember your photo; we cannot access that device copy.
On-device camera guidance. During camera capture, Google ML Kit face detection runs on the device only to provide framing guidance. It may calculate a single-frame bounding box, yaw/pitch/roll angles, and eyes-open probability. This temporary geometry is not transmitted, persisted, used for recognition or authentication, or sent to any third party; it is discarded with the next frame.
Biometric identifiers: never. A face template, embedding, or any other biometric derivative is never extracted or stored.
Anonymous usage analytics. Collected only with your consent; you can withdraw it at any time from the Permissions and consents screen in the app. Your photos and face analysis never enter any analytics tool.
Device identifier. A device record is kept to prevent the free trial allowance from being claimed repeatedly on the same device. Even if you delete your account, this record continues to be kept with its link to your identity severed. This is to prevent abuse, not to track you.
Purchase data. Your subscription and credit purchases are processed via the App Store/Google Play and RevenueCat; your card details never reach us.
Crash/diagnostic data. If the app errors out, we receive diagnostic information via Sentry; screenshot and session-replay features are disabled.
3. Why we process your data
We process your personal data only for the following purposes:
- Generating hairstyle, hair color, and beard try-on images,
- Producing your personal color analysis and hair report,
- Preventing abuse of the free trial allowance,
- Operating subscriptions and purchases,
- Diagnosing errors/crashes and keeping the service reliable,
- Where you have given consent, improving the app through usage analytics.
4. Data transfers, including abroad
We use the following service providers to run the app; each is subject to its own privacy policy:
- Google Firebase: authentication, database, storage, server functions, analytics
- fal.ai + Google Gemini API: image generation/processing (where your selfie is processed)
- RevenueCat: subscription and purchase management
- Sentry: error/crash reporting
- AppsFlyer: app install measurement
Equal protection for face data. We share a selfie with fal.ai and Google Gemini only to perform the AI operation the user requested. We require each recipient that receives face data to provide protections equal to or stronger than those described in this policy: purpose limitation, confidentiality and access controls, no advertising or unrelated profiling, no use to train or improve unrelated products, and deletion/retention limits consistent with this policy. We do not share face data with a recipient unless its applicable terms or agreement provides those protections.
These service providers' servers are located abroad (primarily in the United States); this transfer of data abroad falls under Article 9 of the KVKK. By using the app and uploading your photo, you give your explicit consent to this transfer; you may withdraw that consent at any time by discontinuing use of the app and deleting your account via Profile → "Delete account and data."
5. Collection method and legal basis
All data is collected electronically and automatically through the mobile app. The legal basis for processing is necessity for the performance of the service for selfie processing and purchase data, and your explicit consent for transfers abroad and for the optional analytics/report features.
6. Retention and deletion schedule
We don't leave how long we keep things vague:
| Data | Retention period |
|---|---|
| Source selfie (server) | Permanently deleted instantly once processing completes, within 24 hours at the latest in every case |
| Generated image (server) | Deleted immediately after delivery to/saving on your device; automatically deleted within 24 hours at the latest if not delivered |
| Studio selfie (your device) | Kept only until you replace or delete it in Studio; deleting the app or using account deletion also removes the app's local selfie copy |
| Saved results (your device) | Kept only in the app's local history; delete an individual result from History, or delete the app/account to remove the local history |
| Camera guidance geometry (device) | Discarded with the next camera frame; never persisted or transmitted |
| Face template / biometric derivative | Never created |
| Analytics data | Anonymous/pseudonymous; associated server data is permanently deleted upon an account-deletion request |
| Device identifier (abuse prevention) | Kept with its identity link severed after account deletion |
7. Your rights as a data subject (KVKK Art. 11)
Under Article 11 of the KVKK, you have the right to:
- Learn whether your personal data is being processed,
- Request information about it if it has been processed,
- Learn the purpose of processing and whether it is used in line with that purpose,
- Know the third parties, domestic or abroad, to whom your data is transferred,
- Request correction if it has been processed incompletely or incorrectly,
- Request erasure or destruction under the conditions set out in applicable law,
- Request that correction/erasure requests be notified to third parties to whom the data was transferred,
- Object to a result that is to your detriment arising exclusively from analysis of your data through automated systems,
- Claim compensation for damage suffered due to unlawful processing.
8. How to exercise your rights
Right to delete. Using Profile → "Delete account and data" in a single step permanently deletes all server data linked to your account; this action cannot be undone.
Withdrawing face-data consent. At any time, open Profile → Permissions and consents and turn off Hairstyle generation and/or Color Analysis & Hair Report. Turning either switch off stops the corresponding selfie from being sent to our AI processors; the app asks for consent again before a later request for that operation. Turning off consent does not delete a selfie that is already on the device, so delete or replace the Studio photo separately if you want to remove that local copy.
Deleting face data. Delete the current Studio selfie by replacing or deleting it in Studio. Delete a saved generated image from History using its delete control; a copy saved separately to the device photo gallery is controlled by the device owner and is not affected by deleting an in-app history item. Profile → "Delete account and data" deletes the account's server data and clears the app's local selfie, local history, consent state, and cached generated files. Server-side source selfies and generated outputs are deleted according to the schedule in Section 6, including the 24-hour safety-net limit.
Withdrawing analytics consent. You can also turn off analytics sharing at any time from Profile → Permissions and consents; your photos are never included in analytics.
Other requests. You can submit requests regarding the rights above by writing to destek@styloom.app; depending on the nature of the request, we respond within 30 days at the latest and in the manner prescribed by the KVKK.
AI disclosure. All images in the app are generated with AI; this is stated clearly on the onboarding and result screens as well.
9. Additional information for EU (GDPR) users
If you are located in the European Union, in addition to the rights above you also have the right to object to the processing of your data under the GDPR and to lodge a complaint with the competent data protection authority in your country. The legal bases for processing and the retention periods are the same as set out in the sections above.
10. Children's privacy. Styloom is not directed at children and does not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. When a material change occurs, we will notify you from within the app; the current version is always available on this page.
12. Contact
You can write to destek@styloom.app with any questions about this policy.