Privacy
How Vendeuse collects and processes your personal data.
Vendeuse is a brand operated by BrightifAI AG, Oberneuhofstrasse 3, 6340 Baar, Switzerland (company number UID CHE-166.984.707). BrightifAI AG is the data controller for the processing described in this notice.
This notice covers every side of Vendeuse:
- the website at vendeuse.com, including the support form,
- the Vendeuse iOS app — your private AI stylist, who knows your wardrobe, your life, and your taste, and
- the Vendeuse web app at app.vendeuse.com — the same stylist in your browser.
Because we are based in Switzerland and serve people across Switzerland, the EU, and beyond, we process your data under both the Swiss Federal Act on Data Protection (FADP / revDSG) and the EU General Data Protection Regulation (GDPR).
As a controller established outside the EU/EEA that offers a service to people there, we have appointed an EU representative under GDPR Art. 27, whom EU/EEA users may contact directly: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria.
You can reach us about anything in this notice at contact@vendeuse.com. For privacy matters specifically, you can also write to dpo@brightif.ai.
On the website (support form)
- The details you send through the support form at vendeuse.com/support: your email address, the subject and message you write, and your name if you choose to give one.
- Basic technical information sent by your browser (IP address, request time, user agent), via our hosting provider’s standard request logs.
We don’t set any cookies on the website, run analytics, or load third-party advertising scripts on the site.
In the app
To be your vendeuse, the app needs to know you. We collect:
- Account details — your email address, and the short one-time codes we email you when you sign in by email. Vendeuse is passwordless: there is no password to create, send, or store.
- How you sign in — you can sign in with Apple, with Google, or by email code. If you choose Apple or Google, we receive a verified sign-in token, your email address, and your name the first time you sign in. With Sign in with Apple you can hide your email, in which case we only ever see a private relay address (an @privaterelay.appleid.com alias). These providers don’t receive any of your wardrobe, photos, measurements, or conversations — only what’s needed to confirm it’s you. If you delete your account, we ask Apple to revoke your Sign in with Apple link.
- Your profile — the display name you choose and, if you add one, an avatar photo.
- Your body — the measurements you enter (such as bust, waist, hips, and shoe size), your date of birth, and any free-text notes you write about your body or fit.
- Reference photos — full-body and fit photos you upload so your vendeuse knows what you look like.
- Your conversations — the messages you send your vendeuse, any photos you attach to them, and (if you use it) your search terms. Voice input is transcribed entirely on your device — see “why we process it” below.
- Your wardrobe — the pieces and outfits you save, their favorite / owned / wished status, and the product pages you share to the app from a retailer (the page’s web address and a cleaned-up copy of the page, so we can read the item’s details).
- Your journal — events you add (such as their title, place, dress code, and dates) and any photos in an event’s gallery.
- What your vendeuse learns — to give you better advice, your vendeuse keeps working notes about your taste, fit, and preferences inferred from your conversations. These notes can include sensitive observations about your appearance or self-image. You can clear them at any time with “forget me.”
- Your purchases — if you take out a subscription or buy credits, we keep a record of what you bought and your current subscription status. The payment itself is handled by Apple through the App Store — we never see or store your card details.
- Technical data — the access tokens that keep you signed in (stored securely in your device’s Keychain in the iOS app, and in your browser’s local storage on your device in the web app), and the standard request information any internet service receives, such as your IP address.
A note on photo metadata. When you upload a photo, we strip its embedded metadata — such as the capture date and any GPS location your camera may have saved — before storing it, so that location and device details aren’t kept or shared.
What you may not upload. Vendeuse is a styling service. You must not upload intimate, sexually explicit, or nude photos — of yourself or of anyone else. Reference and fit photos should show you clothed, the way you would show a stylist. Uploading such content breaches our Terms and falls outside the processing described in this notice; if we become aware of it, we may delete the content and may suspend or close the account.
We ask for camera and microphone access only so you can take photos and dictate messages, and we use the system photo picker to let you choose existing photos — the picker hands us only the photo you select and grants no access to your wider library. The app sets no cookies of its own, contains no analytics or tracking SDK, and doesn’t use Apple’s App Tracking Transparency, because we don’t track you. The web app never asks for camera or microphone permission at all — you choose photos with your browser’s file picker.
On the website, we process the details you send through the support form to receive, understand, and respond to your request, to follow up with you about it, and to send you a short automatic email confirming we’ve received your message.
In the app, we process your data to give you the service: to create and secure your account, to let your vendeuse understand your body, taste, wardrobe, and plans, to generate styling advice, to read product pages you share, and to keep your closet and journal in sync. If you buy a subscription or credits, we also process your purchase and subscription status to provide and manage it.
We rely on the following legal bases under the GDPR (Art. 6) and the equivalent grounds under the Swiss FADP:
- Performance of a contract (GDPR Art. 6(1)(b)) — most app processing (running your account, your conversations, your wardrobe and journal, and the styling advice itself) is necessary to provide the service you asked for.
- Handling your requests (GDPR Art. 6(1)(b) and (f)) — when you contact us through the support form, we use your details to receive, answer, and follow up on your request. Where you’re an app user, this supports the contract between us; otherwise we rely on our legitimate interest in responding to people who write to us.
- Legitimate interests (GDPR Art. 6(1)(f)) — keeping our systems secure, preventing fraud and abuse, and monitoring for errors so the app works reliably.
- Legal obligation (GDPR Art. 6(1)(c)) — meeting our data-security, record-keeping, and similar duties.
Sensitive personal data. Some of what you give us — your body measurements, your date of birth, the photos of yourself you upload, your free-text body notes, and the appearance-related notes your vendeuse keeps — is treated as sensitive personal data under the FADP (Art. 5(c)) and may be special-category data under GDPR Art. 9. We process it solely to provide the styling service, and we rely on your explicit consent (GDPR Art. 9(2)(a); FADP Art. 6(7)/Art. 30), which you give by choosing to enter this information. You can withdraw it at any time by deleting the data, using “forget me,” or deleting your account.
A note on the AI and profiling. To answer you, your vendeuse builds a profile of your taste, body, and plans — this is profiling under GDPR Art. 4(4). It produces styling recommendations only; it doesn’t make automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Art. 22 / FADP Art. 21. To generate her replies, your vendeuse sends the relevant context — your chat messages, the wardrobe and journal details in play, your body measurements when needed, the appearance notes she keeps, and the photos relevant to your request — to an AI language-model provider (see “who else sees it”). When you ask her to create a try-on image of you wearing pieces from your wardrobe, she sends a small set of your reference photos — and any photo of yourself you include in that request — along with your body measurements and the pieces’ images and descriptions to an AI image-generation provider, which renders the picture; the generated image is stored with your account like any other photo, and you can delete it at any time. When she looks something up on the web for you, she sends the search query to a search provider, and — when she needs to read a specific page — sends that page’s web address to a page-reading service that fetches it on our behalf (both EU-established providers). Your voice, when you dictate, is transcribed on your device by Apple’s on-device speech engine; the audio never leaves your phone — only the resulting text becomes a normal message if you choose to send it.
We don’t sell your data, and we don’t share it for anyone else’s advertising. We use a small set of trusted providers, each only for what’s listed below. Where a provider processes data outside Switzerland and the EU/EEA, see “international transfers.”
On the website
- Resend (Plus Five Five, Inc. d/b/a Resend, USA) — delivers the emails behind our support form: it sends your message to our support inbox and sends you the automatic acknowledgement. It therefore processes your email address, your name (if you gave one), and the contents of your message. resend.com/legal/privacy-policy
- Vercel (Vercel, Inc., USA) — hosts this website. vercel.com/legal/privacy-policy
In the app
- Microsoft Azure (Microsoft) — runs our application servers and the database that holds essentially all of your account data: your profile, body measurements, notes, conversations, wardrobe, and journal. Data is hosted in Azure’s Switzerland region. We host on Azure but don’t use Azure’s own AI services. Microsoft data protection addendum
- Microsoft Azure Communication Services (Microsoft) — sends your account emails, so it receives your email address, your display name, and the email’s contents, including verification and sign-in codes.
- Sign in with Apple & Sign in with Google (Apple Inc., USA; Google LLC, USA) — if you use one of these to sign in, the provider confirms your identity and passes us a verified sign-in token, your email (a private relay address, if you hide it with Apple), and your name on first sign-in. They receive nothing else of yours — no photos, measurements, wardrobe, or conversations. (Apple and Google also appear below for unrelated features — Google as a backup image model, Apple for on-device speech; those roles are separate.)
- Anthropic(Anthropic PBC, USA) — by default, the AI provider that powers your vendeuse. It receives the chat and styling context described in “why we process it,” including the relevant photos, to generate her replies. Anthropic doesn’t use the data we send it to train its models. anthropic.com/legal/privacy
- OpenAI(OpenAI, L.L.C., USA) — two roles. As a conversation AI provider, it serves some accounts and acts as an automatic fallback if Anthropic is unavailable, receiving the same styling context as Anthropic would. And when you ask your vendeuse to create a try-on image of you, OpenAI’s image model generates it — for that request it receives a small set of your reference photos (and any photo of yourself you include in that request), your body measurements, the images and descriptions of the pieces being rendered, and (if the image is set at one of your events) an event photo. These are sent only to generate that image. OpenAI doesn’t use data sent through its API to train its models. openai.com/policies/privacy-policy
- Google(Google LLC, USA) — the backup image model for try-on images (Gemini). If OpenAI declines or fails to generate a try-on image you asked for, the same request — your selected reference photos (and any photo of yourself you include), body measurements, piece images and descriptions, and any event photo — is sent to Google instead. We use Google’s paid API tier, under which Google commits not to use your data to train its models. Generated images carry Google’s invisible SynthID watermark identifying them as AI-generated. business.safety.google/privacy
- Linkup (Linkup SAS, France) — powers your vendeuse’s web search. It receives only the search query she composes (which can include details you mentioned, such as a place or an event). It does not receive your photos, measurements, or any of your wardrobe or journal content, and it doesn’t use your queries to train its models. Linkup is established in the EU (France) and processes and stores data within the EU. linkup.so/privacy
- Zyte (Zyte Group Ltd., Ireland) — fetches web pages on our behalf: both retailer product pages when you (or your vendeuse) add a piece by link, and pages your vendeuse needs to read to answer you. It receives only the page’s web address — none of your photos, measurements, wardrobe, or journal data. zyte.com/privacy-policy
- Cloudflare R2 (Cloudflare, Inc.) — the private object store for the photos you upload in the app (reference, chat, event, and avatar images), served to you through short-lived signed links. Storage is in Cloudflare’s EU jurisdiction. cloudflare.com/privacypolicy
- Sentry (Functional Software, Inc., USA) — error monitoring for our backend and for the web app, so we can find and fix problems. We scrub error reports before they’re sent: request bodies are dropped and fields that could carry your message contents, photos, or measurement values are filtered out. Web-app crash reports go to Sentry’s EU-hosted infrastructure, session replay is disabled, and reports carry no message or photo content. The iOS app itself still contains no crash-reporting or analytics SDK. sentry.io/privacy
- RevenueCat (RevenueCat, Inc., USA) — manages your subscriptions and credit purchases. It receives a record of your purchases and subscription status, tied to a pseudonymous account identifier — not your email, name, photos, or any of your wardrobe or conversation data. The payment itself is processed by Apple, not RevenueCat. revenuecat.com/privacy
- Apple (on-device) — speech-to-text for voice input runs on your iPhone using Apple’s on-device engine; your audio isn’t sent to Apple or to us. On first use the engine may download a language model from Apple. apple.com/legal/privacy
When it’s relevant to your request, the photos your vendeuse sends the active AI provider aren’t limited to the one you attach to a message — she can also draw on the photos you’ve stored in the app and the product images from pages you’ve shared, so she can describe and reason about them. These are sent only to generate your response.
We may also disclose data to our professional advisors, auditors, or to authorities where we’re legally required to, and to a successor in the event of a business reorganization or sale.
Two things to be clear about: the app contains no third-party analytics, crash-reporting, or advertising SDK of its own. And when the app shows you product images, your device fetches them directly from the retailer’s own image servers (for example Zalando or Mytheresa) without sending them your account details — but, as with any image you load on the web, this reveals your device’s IP address and which images you’re viewing to those image servers.
We take the security of your data seriously, especially because it includes sensitive information about your body and photos of you.
- Data is encrypted in transit (TLS) between your device, our servers, and our providers, and at rest on our hosting.
- Your sign-in tokens are stored in your iPhone’s Keychain, not in ordinary app storage. In the web app they live in your browser’s local storage, isolated to app.vendeuse.com and guarded by a strict Content Security Policy that bans third-party scripts.
- Your uploaded photos live in a private object store and are served only through short-lived signed links, never from a public URL.
- We apply access controls and least-privilege to who and what can reach your data, and host it in Switzerland and the EU.
No system is perfectly secure, but if a data breach occurs that’s likely to result in a risk to you, we’ll notify the Swiss FDPIC and the relevant EU supervisory authority, and affected users, as the FADP (Art. 24) and GDPR (Art. 33–34) require.
Your stored data lives in Switzerland (on Azure) and in the EU (your uploaded photos, in Cloudflare R2’s EU jurisdiction).
Some of our providers — including our AI, subscription-management, sign-in, error-monitoring, email, and website-hosting providers — are based in, or process data in, the United States. (Our search and page-reading providers, by contrast, are in the EU.) Where we transfer your data outside Switzerland and the EU/EEA, we rely on appropriate safeguards under FADP Art. 16–17 and GDPR Art. 44–46, such as the EU Standard Contractual Clauses (with the Swiss addendum where Swiss data is involved) and, where a provider is certified, the EU–US and Swiss–US Data Privacy Framework. You can ask us for more detail on, or a copy of, the safeguards in place for any specific transfer.
Support messages. We keep the messages you send us through the support form, and our replies, for as long as we need them to deal with your request and for a reasonable period afterwards in case you follow up. We then delete them from active systems, and any copies in backups are removed as those backups rotate.
App data. We keep your account data for as long as your account is open. You can remove things yourself at any time — you can clear your chat, ask your vendeuse to “forget” what she has learned about you (which erases those working notes), or delete your whole account from the app. When you delete your account, we erase your data — including your photos in object storage — from our active systems within 30 days, and any copies in isolated backups are removed as those backups rotate, within a further 90 days.
We may keep limited information for longer where we have to — for example to meet a legal obligation, or to establish or defend a legal claim.
Under the GDPR and the Swiss FADP, and depending on where you live, you have the right to:
- Access the personal data we hold about you, and information about it.
- Correct data that’s inaccurate or incomplete.
- Delete your data.
- Restrict or object to certain processing — and you can object to direct marketing at any time.
- Withdraw any consent you’ve given, at any time.
- Receive a copy of your data in a portable format (GDPR Art. 20; FADP Art. 28).
- Be informed about any automated individual decision-making (GDPR Art. 22; FADP Art. 21). As explained in “why we process it,” your vendeuse profiles you to give advice but makes no such decisions.
Where to complain. If you’re in Switzerland, you may file a report with the Federal Data Protection and Information Commissioner (FDPIC), and you may separately bring a civil claim before the Swiss courts (Art. 32 revDSG). If you’re in the EU/EEA, you can lodge a complaint with a supervisory authority — in the country of your habitual residence, your place of work, or the place of the alleged infringement.
To exercise any of these rights, email us at contact@vendeuse.com, our privacy contact at dpo@brightif.ai, or (if you’re in the EU/EEA) our Art. 27 representative named in “who we are.” Exercising your rights is free; we may charge a reasonable fee only where the law allows it for clearly excessive or repeated requests.
Website. The website sets no cookies at all — none for functionality, analytics, or advertising. Because we set no cookies, the site needs no cookie banner.
App. The Vendeuse app doesn’t use cookies, doesn’t contain any analytics or tracking technology, and doesn’t use Apple’s App Tracking Transparency, because we don’t track you across other apps or websites.
Web app. The web app at app.vendeuse.com sets no cookies either — it keeps you signed in with tokens in your browser’s local storage, which stays on your device and is not a tracking technology, and it contains no analytics. If you install it to your home screen, your browser caches the app’s own files on your device so it starts faster — never your personal data.
Vendeuse is not intended for children. Because the service processes sensitive body data and personal photos of you, you must be at least 16 years old to use the app. During onboarding we ask for your date of birth and don’t let you continue with a date that shows you’re under 16. We don’t knowingly collect personal data from anyone under that age; if you believe a child has given us their data, contact us at contact@vendeuse.com and we’ll delete it.
We may update this notice from time to time — for example when we add a feature or change a provider. The “last updated” date at the bottom of this page reflects the most recent version. For significant changes, we’ll notify you in advance — in the app or by email — before they take effect, and where a change affects processing that relies on your consent we’ll ask for fresh consent.
Last updated July 7, 2026.