Privacy
How Vendeuse collects and processes your personal data.
Vendeuse is a brand operated by BrightifAI AG, Oberneuhofstrasse 3, 6340 Baar, Switzerland (company number UID CHE-166.984.707). BrightifAI AG is the data controller for the processing described in this notice.
This notice covers every side of Vendeuse:
- the website at vendeuse.com, including the support form,
- the Vendeuse iOS app, and
- the Vendeuse web app at app.vendeuse.com — the same service in your browser.
Because we are based in Switzerland and serve people across Switzerland, the EU, and beyond, we process your data under both the Swiss Federal Act on Data Protection (FADP / revDSG) and the EU General Data Protection Regulation (GDPR).
As a controller established outside the EU/EEA that offers a service to people there, we have appointed an EU representative under GDPR Art. 27, whom EU/EEA users may contact directly: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria.
You can reach us about anything in this notice at contact@vendeuse.com. For privacy matters specifically, you can also write to dpo@brightif.ai.
On the website (support form)
- The details you send through the support form at vendeuse.com/support: your email address, the subject and message you write, and your name if you choose to give one.
- Basic technical information sent by your browser (IP address, request time, user agent), via our hosting provider’s standard request logs.
We don’t set any cookies on the website, run analytics, or load third-party advertising scripts on the site.
In the app
To provide the service, the app collects:
- Account details — your email address, and the short one-time codes we email you when you sign in by email. Vendeuse is passwordless: there is no password to create, send, or store.
- How you sign in — you can sign in with Apple, with Google, or by email code. If you choose Apple or Google, we receive a verified sign-in token, your email address, and your name the first time you sign in. With Sign in with Apple you can hide your email, in which case we only ever see a private relay address (an @privaterelay.appleid.com alias). These providers don’t receive any of your wardrobe, photos, measurements, or conversations — only what’s needed to confirm it’s you. If you delete your account, we ask Apple to revoke your Sign in with Apple link.
- Your profile — the display name you choose and, if you add one, an avatar photo.
- Your body — the measurements you enter (such as bust, waist, hips, and shoe size), your date of birth, and any free-text notes you write about your body or fit.
- Reference photos — full-body and fit photos you upload, used as references for styling advice and try-on images.
- Your conversations — the messages you send your vendeuse, any photos you attach to them, and (if you use it) your search terms. Voice input is transcribed entirely on your device — see “why we process it” below.
- Your wardrobe — the pieces and outfits you save, their favorite / owned / wished status, and the product pages you share to the app from a retailer (the page’s web address and a cleaned-up copy of the page, so we can read the item’s details).
- Your journal — events you add (such as their title, place, dress code, and dates) and any photos in an event’s gallery.
- What your vendeuse learns — working notes about your taste, fit, and preferences, inferred from your conversations and used to improve the advice you get. These notes can include sensitive observations about your appearance or self-image. You can clear them at any time with “forget me.”
- Which suggestions you follow — where your vendeuse suggests a piece you could buy, you open the shop’s page from that suggestion and you have agreed to the tracked link: a record that the visit came from us and, if a purchase follows, the details of that purchase — such as its value and the commission due to us — which we receive from the affiliate network, not from you. Without that agreement the link is untracked and none of this is collected. See “commercial recommendations.”
- Your purchases — if you take out a subscription or buy credits, we keep a record of what you bought and your current subscription status. The payment itself is handled by Apple through the App Store, or — if you subscribe in the web app — by our payment provider; either way, we never see or store your card details.
- Technical data — the access tokens that keep you signed in (stored securely in your device’s Keychain in the iOS app, and in your browser’s local storage on your device in the web app), and the standard request information any internet service receives, such as your IP address.
A note on photo metadata. When you upload a photo, we strip its embedded metadata — such as the capture date and any GPS location your camera may have saved — before storing it, so that location and device details aren’t kept or shared.
What you may not upload. Vendeuse is a styling service. You must not upload intimate, sexually explicit, or nude photos — of yourself or of anyone else. Reference and fit photos should show you clothed, the way you would show a stylist. Uploading such content breaches our Terms and falls outside the processing described in this notice; if we become aware of it, we may delete the content and may suspend or close the account.
We ask for camera and microphone access only so you can take photos and dictate messages, and we use the system photo picker to let you choose existing photos — the picker hands us only the photo you select and grants no access to your wider library. The app sets no cookies of its own and contains no analytics or advertising SDK of its own.
If you open a shop’s page from a suggestion and you have agreed to the tracked link, the affiliate network described in “commercial recommendations” is told the visit came from us so that a purchase can be credited to us. The web app never asks for camera or microphone permission at all — you choose photos with your browser’s file picker.
On the website, we process the details you send through the support form to receive, understand, and respond to your request, to follow up with you about it, and to send you a short automatic email confirming we’ve received your message.
In the app, we process your data to give you the service: to create and secure your account, to build the picture of your body, taste, wardrobe, and plans that the advice is based on, to generate styling advice, to read product pages you share, and to keep your closet and journal in sync. Where pieces you could buy are suggested, we also process your data to choose and order those suggestions and, if you follow one of those links, to have a resulting purchase credited to us — see “commercial recommendations.” If you buy a subscription or credits, we also process your purchase and subscription status to provide and manage it.
We rely on the following legal bases under the GDPR (Art. 6) and the equivalent grounds under the Swiss FADP:
- Performance of a contract (GDPR Art. 6(1)(b)) — most app processing (running your account, your conversations, your wardrobe and journal, and the styling advice itself) is necessary to provide the service you asked for.
- Your consent (GDPR Art. 6(1)(a); FADP Art. 6(7)(b)) — where we ask you for it separately: to tailor the pieces your vendeuse suggests you could buy to what the service has learned about you, and to use a tracked link so a shop can credit a purchase to us. You can withdraw either consent at any time, and suggestions still work if you decline both — see “commercial recommendations.”
- Handling your requests (GDPR Art. 6(1)(b) and (f)) — when you contact us through the support form, we use your details to receive, answer, and follow up on your request. Where you’re an app user, this supports the contract between us; otherwise we rely on our legitimate interest in responding to people who write to us.
- Legitimate interests (GDPR Art. 6(1)(f)) — keeping our systems secure, preventing fraud and abuse, and monitoring for errors so the app works reliably; showing you pieces you could buy where you have not asked for those suggestions to be tailored to you; and checking and settling the commission a shop owes us on a purchase you make after following one of those links. You can object to the last two at any time — see “your rights.”
- Legal obligation (GDPR Art. 6(1)(c)) — meeting our data-security, record-keeping, and similar duties.
Sensitive personal data. Some of what you give us — your body measurements, your date of birth, the photos of yourself you upload, your free-text body notes, and the appearance-related notes kept about you — is treated as sensitive personal data under the FADP (Art. 5(c)) and may be special-category data under GDPR Art. 9. We process it to provide the styling service. We rely on your explicit consent (GDPR Art. 9(2)(a); FADP Art. 6(7)/Art. 30), which you give by choosing to enter this information. You can withdraw it at any time by deleting the data, using “forget me,” or deleting your account.
A note on the AI and profiling. To answer you, the service builds a profile of your taste, body, and plans — this is profiling under GDPR Art. 4(4). It produces styling advice, and — where you have consented — it also shapes which pieces are suggested to you and the order they appear in. What is taken into account, and what never is, is set out on the “how your vendeuse chooses” page, which you can also open from any set of suggestions. If you don’t consent to that, pieces you could buy are still suggested — they are simply chosen from what you asked for, not from what the service has learned about you. It doesn’t make automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Art. 22 / FADP Art. 21.
What is sent to an AI provider. To generate replies, your vendeuse sends the relevant context — your chat messages, the wardrobe and journal details in play, your body measurements when needed, the appearance notes kept about you, and the photos relevant to your request — to an AI language-model provider (see “who else sees it”).
When you ask for a try-on image of yourself wearing pieces from your wardrobe, a small set of your reference photos — and any photo of yourself you include in that request — goes to an AI image-generation provider, along with your body measurements and the pieces’ images and descriptions. The generated image is stored with your account like any other photo, and you can delete it at any time.
For a web look-up, the search query — plus your country and language, so that the shops found are ones you can actually buy from — goes to a search provider in the United States. Where a specific page has to be read, that page’s web address goes to an EU page-reading service that fetches it on our behalf.
Your voice, when you dictate, is transcribed on your device by Apple’s on-device speech engine. The audio never leaves your phone — only the resulting text becomes a normal message, if you choose to send it.
We don’t sell your data. Where your vendeuse suggests pieces you could buy, those suggestions are commercial and a shop may pay us a commission — that arrangement, and the network behind it, is described in “commercial recommendations” below; apart from it, we don’t share your data for anyone else’s advertising.
We use a small set of trusted providers, each only for the purpose listed below, each under a data-processing agreement that binds it to our instructions. Where a provider processes data outside Switzerland and the EU/EEA, see “international transfers.” We name the providers whose identity matters to a decision you are making — the ones you sign in with, the ones that pay for or take payment from you, and the ones that receive photographs of you. For the rest we describe the role and the country, which is what determines your rights and your risk. If you would like the current list by name, write to us at contact@vendeuse.com and we will send it.
On the website
- An email delivery provider (USA) — delivers the emails behind our support form: it sends your message to our support inbox and sends you the automatic acknowledgement. It therefore processes your email address, your name (if you gave one), and the contents of your message.
- A website hosting provider (USA) — hosts this website. It processes your IP address and the technical request data any web server receives; this site sets no cookies and loads no analytics.
In the app
- A cloud hosting provider (data hosted in Switzerland) — runs our application servers and the database that holds essentially all of your account data: your profile, body measurements, notes, conversations, wardrobe, and journal. We host with it but do not use any of its AI services.
- An email delivery provider (data hosted in Switzerland) — sends your account emails, so it receives your email address, your display name, and the email’s contents, including verification and sign-in codes.
- Sign in with Apple & Sign in with Google (Apple Inc., USA; Google LLC, USA) — if you use one of these to sign in, the provider confirms your identity and passes us a verified sign-in token, your email (a private relay address, if you hide it with Apple), and your name on first sign-in. They receive nothing else of yours — no photos, measurements, wardrobe, or conversations. (Both companies also appear below in unrelated roles — Google as one of the try-on image models, Apple for on-device speech; those roles are separate.)
- OpenAI (OpenAI, L.L.C., USA) — the conversation AI provider that powers your vendeuse. It receives the chat and styling context described in “why we process it,” including the relevant photos, to generate replies. It does not use data sent through its API to train its models. openai.com/policies/privacy-policy
- A second conversation AI provider (USA) — used only automatically, and only when the provider above is unavailable, so that your vendeuse still answers you. When it is used it receives the same context, including the relevant photos. It does not use that data to train its models.
- OpenAI and Google (OpenAI, L.L.C., USA; Google LLC, USA) — the AI image models that generate try-on images. When you ask your vendeuse to create one, the request goes to one of them and, if it does not produce an image, to the other. That request contains a small set of your reference photos (and any photo of yourself you include in it), your body measurements, the images and descriptions of the pieces being rendered, and — if the image is set at one of your events — an event photo. These are sent only to generate that image, and neither provider uses them to train its models. Generated images carry an invisible watermark identifying them as AI-generated. business.safety.google/privacy
- A web-search provider (USA) — powers your vendeuse’s web search. It receives the search query composed for you (which can include details you mentioned, such as a place or an event) and, so that results are relevant where you actually shop, your country and language setting — the two-letter country code and language from your profile, nothing more precise. It does not receive your photos, measurements, or any of your wardrobe or journal content. It has confirmed to us in writing that query logs are used only for debugging and billing, are never used to train models, and are never passed to any third party, because it runs its own search index rather than drawing on another provider’s. A record of queries is kept for up to 90 days. The provider is in the United States; we rely on Standard Contractual Clauses for this transfer (see “international transfers”).
- A page-reading provider (Ireland, EU) — fetches web pages on our behalf: both retailer product pages when you (or your vendeuse) add a piece by link, and pages your vendeuse needs to read to answer you. It receives only the page’s web address — none of your photos, measurements, wardrobe, or journal data.
- An object-storage provider (storage in the EU) — the private store for the photos you upload in the app (reference, chat, event, and avatar images), served to you through short-lived signed links.
- An error-monitoring provider (USA; web-app reports on EU-hosted infrastructure) — so we can find and fix problems. We scrub error reports before they are sent: request bodies are dropped and fields that could carry your message contents, photos, or measurement values are filtered out. Session replay is disabled and reports carry no message or photo content. The iOS app itself contains no crash-reporting or analytics SDK.
- A subscription-management provider (USA) — manages your subscriptions and credit purchases. It receives a record of your purchases and subscription status, tied to a pseudonymous account identifier — not your email, name, photos, or any of your wardrobe or conversation data. For purchases made in the iOS app the payment itself is processed by Apple, not by this provider.
- Stripe (Stripe, Inc., USA) — takes payment for subscriptions and credits you buy in the web app, rather than through the App Store. It receives what it needs to charge you: your email address, the amount and currency, and the payment details you enter, which go to Stripe and never to us. It receives none of your photos, measurements, wardrobe, journal, or conversations. stripe.com/privacy
- Apple (on-device) — speech-to-text for voice input runs on your iPhone using Apple’s on-device engine; your audio isn’t sent to Apple or to us. On first use the engine may download a language model from Apple. apple.com/legal/privacy
When it’s relevant to your request, the photos sent to the active AI provider aren’t limited to the one you attach to a message — they can also include the photos you’ve stored in the app and the product images from pages you’ve shared, so that those can be described and reasoned about. These are sent only to generate your response.
We may also disclose data to our professional advisors, auditors, or to authorities where we’re legally required to, and to a successor in the event of a business reorganization or sale.
Two things to be clear about: the app contains no third-party analytics, crash-reporting, or advertising SDK of its own. The commercial suggestions described below work through links — nothing measures you inside the app, and the affiliate network’s measurement runs only when you choose to follow one, and only if you have agreed to it; see “commercial recommendations.” And when the app shows you product images, your device fetches them directly from the retailer’s own image servers without sending them your account details — but, as with any image you load on the web, this reveals your device’s IP address and which images you’re viewing to those image servers.
Your vendeuse can suggest pieces you could actually buy, from shops we work with through an affiliate network. Those suggestions are commercial: if you buy something after following one of those links, the shop may pay us a commission. What a shop pays us never affects what is recommended to you, or the order it is recommended in. What is taken into account is set out on the “how your vendeuse chooses” page, which you can open from any set of suggestions.
Awin (Awin AG, Berlin, Germany) — the affiliate network that connects us to those shops. When you open a shop’s page from one of those suggestions, the link runs through Awin, which is told that the visit came from us and stores and reads what it needs on your device or in your browser so that a later purchase can be credited to us. It reports the visit, and any purchase that follows, back to us. It receives none of your photos, measurements, wardrobe, journal, or conversations. The shop you go on to visit is an independent controller for what happens on its own site, under its own privacy notice. awin.com/privacy
We and Awin are joint controllers for that click-and-purchase step (GDPR Art. 26): we decide to place the link and what it recommends, and Awin runs the measurement that credits a purchase. The essence of our arrangement is that we answer your requests about the data we hold and Awin answers requests about the data it holds, and that we inform you about this click-and-purchase step through this notice while Awin informs you through its own, linked above.
You don’t have to work out which of us to approach: bring any request or complaint to either of us, and we will pass it on and tell you who is dealing with it. Whatever the arrangement says between us, you can exercise your rights against either of us. Ours are described in “your rights.”
You decide, in two separate steps. We ask you separately for permission to tailor these suggestions to what your vendeuse has learned about you, and for permission to use the tracked link that lets a shop credit a purchase to us. We ask on a card in the app or the web app, at the point it becomes relevant — not as part of signing up, and never as an answer taken in conversation. Neither is pre-ticked, and you can say yes to one and no to the other:
- Yes to both — suggestions are tailored to what the service has learned about you, and a shop can credit a purchase to us.
- Tailoring only — suggestions are tailored, and the link to the shop is untracked; we earn nothing.
- Tracked link only — suggestions are chosen from what you asked for rather than from what the service has learned about you, and a shop can credit a purchase to us.
- No to both — your vendeuse still advises you and still shows you pieces to buy; they are chosen from what you asked for, the link to the shop is untracked, and we earn nothing.
You can withdraw either consent at any time in Settings, in the app or the web app, or by telling your vendeuse to stop; withdrawing is as easy as agreeing.
You can object at any time to commercial suggestions and to the profiling behind them. This is a separate right from the two consents above, and it is absolute: where you object to processing for direct marketing, we stop (GDPR Art. 21(2)). There is a switch for it in Settings, kept separate from those consents, and you can also simply tell your vendeuse to stop. See “your rights.”
We take the security of your data seriously, especially because it includes sensitive information about your body and photos of you.
- Data is encrypted in transit (TLS) between your device, our servers, and our providers, and at rest on our hosting.
- Your sign-in tokens are stored in your iPhone’s Keychain, not in ordinary app storage. In the web app they live in your browser’s local storage, isolated to app.vendeuse.com and guarded by a strict Content Security Policy that bans third-party scripts.
- Your uploaded photos live in a private object store and are served only through short-lived signed links, never from a public URL.
- We apply access controls and least-privilege to who and what can reach your data, and host it in Switzerland and the EU.
No system is perfectly secure, but if a data breach occurs that’s likely to result in a risk to you, we’ll notify the Swiss FDPIC and the relevant EU supervisory authority, and affected users, as the FADP (Art. 24) and GDPR (Art. 33–34) require.
Your stored data lives in Switzerland (your account data, with our cloud hosting provider) and in the EU (your uploaded photos, in our object-storage provider’s EU jurisdiction).
Some of our providers — including our AI, web-search, subscription-management, payment, sign-in, error-monitoring, email, and website-hosting providers — are based in, or process data in, the United States. (Our page-reading provider, by contrast, is in the EU, and the affiliate network described in “commercial recommendations” is in the EU or the United Kingdom; where it is in the United Kingdom, we rely on the adequacy decisions covering that country rather than on separate safeguards.) Data also travels the other way: what the affiliate network reports back to us reaches Switzerland, which the EU recognises as providing an adequate level of protection (GDPR Art. 45).
Where we transfer your data outside Switzerland and the EU/EEA, we rely on appropriate safeguards under FADP Art. 16–17 and GDPR Art. 44–46, such as the EU Standard Contractual Clauses (with the Swiss addendum where Swiss data is involved) and, where a provider is certified, the EU–US and Swiss–US Data Privacy Framework. You can ask us for more detail on, or a copy of, the safeguards in place for any specific transfer.
Support messages. We keep the messages you send us through the support form, and our replies, for as long as we need them to deal with your request and for a reasonable period afterwards in case you follow up. We then delete them from active systems, and any copies in backups are removed as those backups rotate.
App data. We keep your account data for as long as your account is open. You can remove things yourself at any time — you can clear your chat, use “forget me” to erase what the service has learned about you (which erases those working notes), or delete your whole account from the app. When you delete your account, we erase your data — including your photos in object storage — from our active systems within 30 days, and any copies in isolated backups are removed as those backups rotate, within a further 90 days.
Commercial and consent records. Where you follow one of your vendeuse’s commercial suggestions, we keep the record of that visit and of any purchase a shop reports for as long as we need it to check and settle the commission, and until the period for either side to raise a claim about that settlement has run out.
Where an entry forms part of our accounting records, we keep it for the statutory retention period for business records — ten years under Swiss law (Art. 958f of the Swiss Code of Obligations).
Where processing rests on your consent, we keep the record of that consent — and of what you were shown when you gave it — for as long as the consent lasts and for three years afterwards, so that we can show it was validly given.
We may keep limited information for longer where we have to — for example to meet a legal obligation, or to establish or defend a legal claim.
Under the GDPR and the Swiss FADP, and depending on where you live, you have the right to:
- Access the personal data we hold about you, and information about it.
- Correct data that’s inaccurate or incomplete.
- Delete your data.
- Restrict or object to certain processing.
- Withdraw any consent you’ve given, at any time.
- Receive a copy of your data in a portable format (GDPR Art. 20; FADP Art. 28).
- Be informed about any automated individual decision-making (GDPR Art. 22; FADP Art. 21). As explained in “why we process it,” the service profiles you to give advice and to choose what is suggested to you, but makes no such decisions.
Your right to object to direct marketing, separately stated. You can object at any time, and free of charge, to our processing of your data for direct marketing — and once you do, we stop. That includes the commercial suggestions your vendeuse makes and the profiling carried out for them (GDPR Art. 21(2) and (3); FADP Art. 30(2)(b)). There is a switch for it in Settings, in the app or the web app, kept separate from the two consents described in “commercial recommendations,” and you can also simply tell your vendeuse to stop. Where we rely on legitimate interests for anything else, you can object to that too and we will stop unless we have compelling grounds to continue (GDPR Art. 21(1)).
Where to complain. If you’re in Switzerland, you may file a report with the Federal Data Protection and Information Commissioner (FDPIC), and you may separately bring a civil claim before the Swiss courts (Art. 32 revDSG). If you’re in the EU/EEA, you can lodge a complaint with a supervisory authority — in the country of your habitual residence, your place of work, or the place of the alleged infringement.
To exercise any of these rights, email us at contact@vendeuse.com, our privacy contact at dpo@brightif.ai, or (if you’re in the EU/EEA) our Art. 27 representative named in “who we are.” Exercising your rights is free; we may charge a reasonable fee only where the law allows it for clearly excessive or repeated requests.
Website. The website sets no cookies at all — none for functionality, analytics, or advertising. Because we set no cookies, the site needs no cookie banner.
App. The Vendeuse app sets no cookies and contains no analytics or tracking technology of its own. If you open a shop’s page from a commercial suggestion, and you have agreed to the tracked link, the affiliate network described in “commercial recommendations” stores and reads an identifier on your device so that a purchase can be credited to us; it is kept only for the network’s attribution window and then expires. If you haven’t agreed, the link to the shop carries no identifier. Nothing else about your use of the app is tracked.
Web app. The web app at app.vendeuse.com sets no cookies of its own — it keeps you signed in with tokens in your browser’s local storage, which stays on your device and is not a tracking technology, and it contains no analytics.
The one exception is the tracked link above: if you have agreed to it, following a commercial suggestion lets the affiliate network store and read an identifier in your browser, which is why we ask you first (§ 25 Abs. 1 TDDDG); it too is kept only for the network’s attribution window and then expires. If you install the app to your home screen, your browser caches the app’s own files on your device so it starts faster — never your personal data.
Vendeuse is not intended for children. Because the service processes sensitive body data and personal photos of you, you must be at least 16 years old to use the app. Date of birth is optional; if you give us one that shows you’re under 16, we reject it. We don’t knowingly collect personal data from anyone under that age; if you believe a child has given us their data, contact us at contact@vendeuse.com and we’ll delete it.
We may update this notice from time to time — for example when we add a feature or change a provider. The “last updated” date at the bottom of this page reflects the most recent version. For significant changes, we’ll notify you in advance — in the app or by email — before they take effect, and where a change affects processing that relies on your consent we’ll ask for fresh consent.
Last updated August 27, 2026.