1. Data Controller
The controller of the processing of your personal data is OOTDly (hereinafter, "OOTDly" or "we").
Contact: contact@ootdlyapp.com
We are not required to appoint a Data Protection Officer (DPO) under Art. 37 GDPR.
2. Data We Collect
- Account data: name, username, email, date of birth, profile picture.
- Published content: photos, videos, comments, loops, stories.
- Usage data: interactions, preferences, activity history.
- Financial data: GZL balance, transaction history, campaign earnings.
- Payment data for withdrawals: depending on the chosen method (SEPA, Wise or PayPal), we collect the IBAN, the Wise or PayPal email, as well as the account holder's name and an optional phone number. This data is NOT sent to Stripe; it is processed manually by the OOTDly team from their own Wise / PayPal accounts until the automated integration is complete. Each payment is accompanied by a receipt (image or PDF) that the user can consult in their history. Stripe is used for GZL package purchases (in-app purchases), not for withdrawals.
- Biometric data for virtual Try-On: body photo (
person_image_url) and additional views (body_views_json) that you voluntarily upload to use the virtual garment try-on feature. These images are also processed by Fal.ai (external provider) as detailed in section 5. - KYC data (Know Your Customer): full legal name, document type and number (DNI/NIE/CPF/passport) and residential address. These are only requested when you request a withdrawal from GZL to EUR, in compliance with the legal obligation to identify the beneficiary (Art. 6.1.c GDPR and applicable anti-money-laundering regulations).
- Social handles: Instagram and TikTok usernames that you optionally and manually enter in your profile.
- Direct messages (DMs): the content of private messages between users. They are transmitted encrypted (HTTPS/TLS), but stored without at-rest encryption in our database. OOTDly only accesses them to resolve disputes, investigate abuse or comply with legal obligations.
- Login sessions: IP address, user-agent, platform, app version, date and time of each login. They are kept for security reasons (detection of suspicious access) for a maximum of 90 days.
- Payment receipt: when OOTDly manually processes a withdrawal, a receipt (image or PDF) is uploaded that the user can consult from their transaction history.
- Image rights assignment consent: when you accept a brand campaign, your consent is recorded together with your name, document, address and the date and time of signing. This record has evidential value and, once signed, cannot be modified (it is immutable by design).
- Email verification code: used only during registration.
- Advertising data: device identifiers for Google AdMob and Facebook SDK (only with ATT consent on iOS).
- Approximate location: city and country (as text) when you create a post or a story. It is derived from your GPS coordinates through reverse geocoding via OpenStreetMap. We do not store your GPS coordinates.
- Push notifications: device token to send you relevant notifications via Expo Push.
3. Legal Basis for Processing
- Performance of the contract (Art. 6.1.b): account management, GZL economy, campaigns, withdrawals and payments.
- Consent (Art. 6.1.a): email verification, personalised advertising, access to location, calendar and image processing in Try-On. You can withdraw your consent at any time.
- Legitimate interest (Art. 6.1.f): fraud prevention, platform security, service improvement and access to campaign channels in the event of a dispute.
- Legal obligation (Art. 6.1.c): retention of financial records, KYC identification of the beneficiary in withdrawals, retention of signed consents and compliance with requests from competent authorities.
4. Use of the Data
We use your data to: provide the service, personalise your experience, manage the GZL economy, process payments and withdrawals, display relevant advertising, send transactional notifications, prevent fraud and improve the platform.
5. Third-Party Services and International Transfers
- Stripe (USA): processing of in-app purchases (purchase of GZL packages). Not used for withdrawals. EU Standard Contractual Clauses.
- Wise (United Kingdom / EEA): manual processing of international withdrawals. Subject to Wise's own privacy policies.
- PayPal (Luxembourg / USA): manual processing of withdrawals via personal PayPal. Subject to PayPal's own privacy policies.
- Fal.ai (USA): image processing for the virtual Try-On feature. It receives the user's body photo and the garment image and returns the combined image. The body image may contain biometric data (special category GDPR Art. 9). It requires your express and informed consent before first use, through a separate dialog box that you must accept by ticking the corresponding checkbox. You can withdraw your consent at any time from Settings > Data and Privacy, which disables the feature. EU Standard Contractual Clauses. We do not retain the image after processing: it is deleted immediately from Fal.ai's servers (retention < 24 h).
- Resend (USA): sending of transactional emails (email verification, reminders, moderation alerts). EU Standard Contractual Clauses.
- Google AdMob (USA): rewarded advertising in the app. Requires your ATT consent on iOS.
- Google Sign-In (OAuth): social login. The backend validates the token; we do not store your Google password.
- Apple Sign-In: social login on iOS. We validate the token with Nimbus JOSE JWT; we do not store your Apple password.
- Facebook SDK (Meta) (USA): only for advertising measurement. Subject to your ATT consent on iOS.
- Hetzner Object Storage (Germany, EU): storage of photos, videos and other uploaded files. As it is in the EU, there is no international transfer.
- RevenueCat / Apple / Google: management of in-app purchases.
- Giphy / Pixabay: search for GIFs and images.
- AudD: music recognition in stories. It receives only a short audio fragment (≤ 12 s) and returns metadata of the identified track (title, artist, album). We do not receive or store acoustic fingerprints. The fragment is not retained by AudD after the response. International transfer under the Standard Contractual Clauses (Art. 46 GDPR).
- OpenStreetMap (Nominatim): reverse geocoding (coordinates → city name).
- Expo Push: delivery of push notifications to iOS and Android devices.
International transfers outside the EEA are covered by the Standard Contractual Clauses (Art. 46 GDPR).
We do not sell your data to third parties.
6. Your Rights (GDPR)
- Access (Art. 15): obtain confirmation of whether we process your data.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): request the deletion of your data.
- Restriction (Art. 18): request that we restrict processing.
- Portability (Art. 20): receive your data in a structured format.
- Objection (Art. 21): object to processing based on legitimate interest.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
You can exercise these rights from Settings > Data and Privacy, or at contact@ootdlyapp.com.
You can also lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
7. Data Retention
- Account data and content: until you delete your account (deletion within 30 days).
- Biometric data (body photo for Try-On): deleted immediately when Try-On is disabled or when the account is deleted.
- Financial records: 5 years (legal obligation).
- Payment receipts: 5 years, in parallel with the financial records they document.
- Image rights assignment consents: throughout the term of the consent and 5 additional years after its expiry, to support any subsequent legal audit.
- Security logs and login sessions: maximum 90 days.
- Verification codes: 15 minutes or until used.
8. Security
We implement password encryption (bcrypt), secure session tokens, certificate pinning for the API, and encrypted communications (HTTPS/TLS).
9. Advertising and App Tracking Transparency
On iOS, we request your permission before showing personalised ads through Apple’s ATT system. This consent also controls whether the Facebook SDK can collect advertising data. You can change your preference in Settings > Privacy and Security > Tracking.
10. Messages in Campaign Channels and Direct Messages
Messages in campaign channels, as well as direct messages (DMs) between users, may be reviewed by OOTDly solely to resolve disputes, investigate prohibited conduct or comply with legal obligations (Art. 6.1.b and 6.1.f GDPR). Access is logged and restricted to authorised personnel.
11. Automated Content Validation
Before publishing a photo or a video, the server runs two local ONNX models:
- Person detection: rejects uploads where no person is detected. We do not store biometric data derived from this detection; the model only returns whether there is a person or not.
- NSFW detection: rejects explicit content.
Both models run on the OOTDly server (Hetzner, EU) using local ONNX. The image is not sent to any third party for this validation. Only Fal.ai receives the image when the user explicitly activates the Try-On feature (section 5).
They are technical filters with no legal effects on your account — they do not constitute an automated decision under Art. 22 GDPR.
12. Calendar
If you book a style consultation, we offer to add the event to your device calendar (via expo-calendar). This access is optional and you control it from your operating system settings.
13. Minors and Parental Authorisation in Campaigns
OOTDly is not aimed at children under 14. In accordance with Art. 8 GDPR and Spanish law (LOPDGDD), the minimum age to give consent to the processing of personal data in Spain is 14 years.
We do not intentionally collect data from children under 14. If we detect that a user is under 14, we will delete their account and data immediately.
Participation of minors in paid commercial campaigns: users between 14 and 17 years old can use OOTDly normally, but their participation in paid campaigns requires authorisation from the legal guardian through the following process:
- The brand must have expressly enabled the "Accept minors" flag in its campaign.
- Campaigns with products restricted to adults (alcohol, tobacco, vaping, gambling, adult content) are prohibited from accepting minors, with no possibility of exception.
- When the brand accepts the minor's application, the system requests the legal guardian's contact details and sends them an email with a unique authorisation link valid for 48 hours.
- The guardian opens the link, reads the full document and ticks the confirmation checkboxes. Only then does the system enable the minor for that specific campaign.
- The authorisation is specific to a single campaign. Another campaign requires new authorisation.
- The guardian can revoke the authorisation at any time; uses already made before the revocation remain valid.
Total block on withdrawal of real money for minors: regardless of any parental authorisation, minors under 18 cannot withdraw GZL balance or EUR balance as real money. They can only redeem their balance for gift cards in the platform's catalogue. This limitation is not negotiable and cannot be overridden by guardian authorisation.
14. Signed Documents and Image Rights Assignment
When a creator delivers content for a campaign, they electronically sign an image rights assignment document that authorises the brand to use that content under the agreed terms (duration, territory, modalities).
Features of the document:
- Default duration: 12 months from signing. The brand may agree longer durations (3 years, 5 years or perpetual) that the creator explicitly accepts.
- Limited scope: use is limited to the specific campaign. The brand may NOT transfer the image to third parties or reuse it in other campaigns without new express authorisation.
- Revocability: the document can be revoked by the creator at any time from their "My assigned rights" section. Revocation takes effect from its registration: the brand loses the right of future use, but uses already made before the revocation remain valid.
- Cryptographic integrity: the document includes a SHA-256 seal and is stored in PDF format downloadable by both parties. Once signed, it cannot be modified (it is immutable by design).
- Audit trail: your name, document, address and the date and time of signing are recorded with evidential value.
The use of the creator’s image in harmful, defamatory or offensive contexts, as well as in association with content that violates applicable law, is prohibited.
15. OOTDly as an Intermediary in Commercial Campaigns
OOTDly acts exclusively as an intermediary technology platform that facilitates collaboration between creators and brands. Responsibility for compliance with the advertising, consumer protection and child protection rules applicable in each jurisdiction lies with the contracting brand.
OOTDly is not responsible for the final commercial use that the brand makes of the content outside the platform. OOTDly reserves the right to suspend, reject or terminate any user’s participation in a campaign when necessary to protect the integrity of the platform or the safety of its users.
A creator’s participation in campaigns does not constitute any employment relationship between OOTDly, the creator, the minor (if applicable) or the brand. These are one-off content-creation collaborations.
16. Account and Balance Deletion
You can delete your account at any time from Settings. When you do:
- The GZL balance is deleted and cannot be converted to real money or transferred to another user.
- The EUR campaign balance is retained for 30 days after the deletion request to allow its withdrawal to the previously registered payment method (SEPA / Wise / PayPal). If you have not requested the withdrawal after 30 days, the balance is permanently lost.
- The historical financial transactions (GZL purchases, withdrawals, campaign commissions) are kept for 5 years in accordance with tax obligations (LGT art. 66) even if the account is deleted. These records are anonymised as far as possible.
- The published content (posts, loops, stories) is deleted. Campaign content already delivered to brands with valid image rights remains visible to those brands according to the signed assignment document.
If you want to download your data before deleting the account, you can exercise your right to portability by writing to contact@ootdlyapp.com.
17. Applicability to Users Outside the EEA
Although OOTDly operates under the GDPR (EU) framework, we also respect the equivalent rights for users outside the EEA:
- Brazil (LGPD): Brazilian users have equivalent rights of access, rectification, erasure, portability and objection under Arts. 18-22 of the LGPD.
- United Kingdom (UK GDPR): equivalent application to the GDPR after Brexit.
- Other countries: if your country's local legislation grants rights more protective than those described in this policy, those rights prevail.
You can exercise any of these rights by contacting contact@ootdlyapp.com.
18. Contact and Complaints
For any query or exercise of privacy rights: contact@ootdlyapp.com
If you are not satisfied with our response, you have the right to lodge a complaint with the AEPD: www.aepd.es
19. Changes to this Policy
We will notify you of significant changes at least 15 days in advance. The current version will always be available in the app and on this page.