1. Who is responsible
Samuel Kubinec is the controller of personal data processed for the Styvi service unless a feature clearly identifies another controller. Our public contact for privacy, support, child-safety, rights and legal requests is samuel.kubinec@icloud.com.
Styvi is currently presented as a pre-release project operated by Samuel Kubinec as an individual. No registered company, sole-trader details, company or tax identifier, register entry, or separate public business address has been supplied for Styvi. This disclosure is factual, not a statement that a public commercial launch without the legally required operator details is permitted. Those details and the operator's business and tax status must be completed before a commercial public launch.
Apple, Google, external retailers and other third-party services may act as separate controllers for information they collect directly under their own terms. This Policy does not replace their notices.
- Samuel Kubinec
- Status: individual pre-release developer; no company or sole-trader registration has been supplied for Styvi
- Country used for this notice: Slovakia
- Separate public business or service address: not established or supplied
- Company or registration ID: none supplied
- Tax or VAT ID: none supplied; Styvi is not represented as VAT-registered
- Register and registration number: none supplied
- Email: samuel.kubinec@icloud.com
- Phone: +421951818608
- Consumer and e-commerce supervision: Slovak Trade Inspection, Central Inspectorate, Bajkalská 21/A, P. O. BOX 29, 827 99 Bratislava, Slovakia
- Data-protection supervision: Office for Personal Data Protection of the Slovak Republic, Galvaniho 7/B, 821 04 Bratislava, Slovakia
2. Information we process
| Category | Examples | Source |
|---|---|---|
| Account and profile | Email address, authentication provider and identifiers, username, display name, biography, avatar, cover, links, account status, settings, declared age band and security preferences. | You, Apple or Google sign-in services, and account-security systems. |
| Content and communications | Posts, photos, videos, audio, captions, comments, replies, Snips, messages, voice notes, GIF selections, polls, Outfit Studio projects, wardrobe items, drafts and other material you create or send. Uploaded files can also contain an original filename and metadata embedded by your device. | You and people who communicate or collaborate with you. |
| Body, size and fit preferences | Clothing measurements, sizes, brand-specific sizes and fit preferences previously stored in wardrobe fit-passport features. Legacy records can remain even while the feature is unavailable. | You and your use of wardrobe tools. |
| Social and recommendation activity | Follows, friends, likes, saves, shares, views, watch or dwell activity, searches, feed position, recommendation feedback, product-link interactions and feature use. | Your use of Styvi. |
| Location | Precise or approximate device location when you actively use a location feature, location-sharing timestamps, selected places, city or region, location permission state, and GPS coordinates, capture time or device information embedded in an uploaded file. Current website uploads do not strip all embedded metadata. | Your device, an uploaded file, Apple MapKit, Google Maps or a place you select. |
| AI and search | Text or spoken prompts and transcripts, images selected for analysis or editing, style choices, generated results, safety signals, feedback, search terms and request metadata. | You, on-device processing, and the online feature you request. |
| Purchases and entitlements | Store product and transaction identifiers, subscription or entitlement state, coin and AI-credit balances, storage allocation, gifts, refund or revocation status and receipt-delivery records. Styvi does not receive your full payment-card number. | Apple App Store, Google Play and your use of purchased features. |
| Safety, support and legal | Reports, blocks, mutes, restrictions, moderation results, appeals, support conversations, attachments, admin notes, legal notices, data requests and evidence needed to investigate them. | You, other users, automated safety systems, support staff and lawful third parties. |
| Device, network and security | Styvi user ID, app installation or device identifiers, push token, device label, app and OS version, session records, IP address or a derived rate-limit signal, request logs, integrity or attestation results, errors, diagnostics and security or network events. | Your device, browser, Cloudflare, Supabase, Apple and Google platform services. |
| Website and Studio | Portal sessions, waitlist choices, Snip uploads, site-access attempts, theme and onboarding preferences, Studio content, uploaded website assets, publish history and owner audit information. | Your browser and, for owner tools, the authenticated Studio owner. |
3. Device permissions and on-device work
Depending on the feature you choose, Styvi may ask for camera, microphone, photo or media library, notifications, location, speech, biometric or device authentication, Siri or shortcuts, and related platform permissions. A permission is requested for the feature shown at that moment. You can refuse or change it in system settings, but that feature may stop working.
Some visual analysis, safety checks, subject segmentation, translation and other processing may happen on the device through Apple or Google frameworks. Information that stays only on your device is not collected by Styvi. If a result or selected file is sent to our backend, that transmitted information is covered by this Policy.
The audited app does not currently upload your address-book contacts. Discovery settings referring to contacts do not by themselves grant Contacts access. We will update the product notice and this Policy before any contact upload is introduced.
4. Why we process data and our legal bases
We do not treat a device permission as blanket consent for unrelated processing. Where we rely on consent, you may withdraw it prospectively without affecting earlier lawful processing. Where we rely on legitimate interests, you may object and we will assess your circumstances and our compelling grounds.
| Purpose | Typical legal basis in the EEA |
|---|---|
| Create accounts, authenticate sessions, deliver profiles, content, messages, location sharing, exports, waitlists and requested features. | Performance of our contract with you; steps you request before entering that contract. |
| Personalize Explore, search, recommendations, creator suggestions and feature order. | Performance of the service and our legitimate interest in making Styvi relevant, balanced against your rights and available controls. |
| Run requested AI generation, editing, analysis or search understanding. | Performance of the requested feature; consent where required for a particular input or permission. |
| Process purchases, entitlements, refunds, receipts, credits, coins and storage. | Performance of the purchase contract and compliance with accounting, tax, consumer and platform obligations. |
| Moderate content, investigate reports, prevent fraud and abuse, secure accounts, rate-limit requests and keep evidence. | Our legitimate interests and those of users in a safe, authentic and secure service; compliance with legal obligations; protection of vital interests in an emergency. |
| Send push, email, social, purchase, safety and service notices. | Performance of the service, legitimate interests for essential notices, and consent for optional communications where required. |
| Debug, maintain, measure and improve reliability and accessibility. | Our legitimate interest in operating and improving Styvi with proportionate data; consent if a law requires it. |
| Respond to legal requests, enforce rights and resolve disputes. | Legal obligation, legitimate interests and establishment, exercise or defence of legal claims. |
5. Who can see what you share
- Public profiles and public posts can be seen by other users and, where public sharing is enabled, by people outside Styvi.
- Audience-limited posts and Snips are delivered according to the audience selected when you share them.
- Messages and live-location information are intended for conversation participants. Recipients can still screenshot, record, copy or redistribute what they receive.
- Drafts and private account information are not presented as public content, but authorized systems and staff may process them when needed to provide the feature, investigate a report, secure Styvi or comply with law.
- Removing content from public view does not necessarily erase copies already saved or lawfully retained by another person.
6. Service providers and other recipients
We disclose only the information reasonably needed for the relevant service. The exact data a provider receives depends on the feature you use.
| Recipient | Role |
|---|---|
| Supabase and its infrastructure providers | Authentication, PostgreSQL database, storage, realtime delivery and Edge Functions. Styvi's primary Supabase project is currently deployed in the Central EU (Frankfurt) region, while edge processing and subprocessors may operate elsewhere. |
| Cloudflare | Website and portal delivery, Workers, traffic security, operational observability, R2 website assets, Durable Object site content and request processing. Cloudflare may process IP address, routing, request, security and network-diagnostic data at its network edge. The website R2 bucket is configured for EU jurisdiction, but that does not make all Cloudflare processing EU-only. |
| Apple | Sign in with Apple, App Store and StoreKit, push notifications, App Attest, declared age range, Speech, MapKit and other platform services used on iOS. |
| Google Play sign-in or credentials where used, Play Billing, Play Integrity, Age Signals, Firebase Cloud Messaging and Installations, Google Maps, ML Kit, Gemini API and Custom Search. | |
| Brave Search | Product and image search requests created from the search or outfit context you ask Styvi to process. |
| Resend | Transactional email delivery, including supported purchase receipts and service communications. |
| GIPHY and media hosts | Delivery of a GIF or other external media you select or view; the media host receives normal network-request information. |
| Frankfurter and external retailers or websites | Currency conversion and links or product results. When you open an external site, that operator receives standard browser request information and applies its own policy. |
| Authorities, advisers and affected parties | Only where reasonably necessary for law, safety, rights protection, fraud investigation, a transaction involving the service, or with your direction. |
7. International transfers
Some providers and their subprocessors process information outside Slovakia or the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses and supplementary measures, or another lawful mechanism. A provider's infrastructure, support and security processing may still be global even when primary storage is in the EEA.
You may contact us for information about the safeguards relevant to a transfer. We do not describe Styvi as EU-only because that would not accurately reflect all edge, platform, AI, search and support services.
8. AI processing
When you intentionally use an online AI feature, Styvi may send the prompt, selected image or other input, limited account or entitlement context, and safety metadata through our backend to Google Gemini. The response and request record may be stored in Styvi to deliver the result, account for credits, investigate abuse or show your history where the feature provides one.
The audited backend uses direct Gemini generateContent requests, including inline image inputs where needed. It does not currently call the Gemini File API, Interactions API, Google Search or Maps grounding, or explicit context caching. The production project must remain associated with active billing so that it qualifies as a Paid Service in the EEA.
Styvi has not yet verified that the production Gemini project is associated with an active Cloud Billing account. Google's current terms allow API clients in the EEA, Switzerland and the United Kingdom only through Paid Services. Gemini must therefore remain unavailable for a public production launch in those territories until active billing is verified.
Because the production billing configuration is unverified, Styvi does not claim the Paid Services data-use terms for live production traffic. No sensitive, confidential or personal information should be submitted to an unpaid Gemini service; public EEA production use remains blocked until billing and the applicable data-processing terms are verified.
Do not submit confidential information, special-category data or another person's content unless you have a lawful reason and permission. AI output can be inaccurate, biased, incomplete or unexpected and is not professional advice.
9. Ranking, personalization and moderation
Styvi uses signals such as follows, interactions, freshness, watch or dwell activity, saves, feedback, safety status and account settings to rank or recommend content. Automated image and text systems may label, block, reduce visibility of or route content for review. Human review may be used for reports, appeals and significant enforcement where operationally available or legally required.
These systems can be wrong. You can use available feedback, report and appeal controls or contact us. Styvi does not use automated decisions to determine eligibility for employment, credit, housing, insurance or another comparable high-impact service.
10. Cookies and browser storage
Styvi uses strictly necessary first-party cookies and browser storage to provide the website, authenticate accounts and protect sign-in. Under section 109(8) of Slovak Act No. 452/2021 Coll., consent is not requested for storage whose sole purpose is communication transmission or that is strictly necessary to provide an information-society service you expressly request.
Optional preference storage is off until you choose “Allow optional cookies”. Choosing “Use necessary only” does not limit sign-in, MFA, passkeys, magic links, Device Approval or other account-security controls. Styvi currently uses no advertising cookies, cross-site tracking cookies or browser analytics cookies.
| Cookie or storage | Category | Purpose | Duration | Protection and scope |
|---|---|---|---|---|
| __Host-styvi_site_access | Strictly necessary | Remembers a successful entry through the private website gate. | 24 hours. | First-party, Secure, HTTP-only, SameSite=Lax, Path=/, host-only. |
| __Host-styvi_web_access | Strictly necessary | Holds the short-lived access token for the authenticated Styvi session. | The active session lifetime, normally about one hour and never configured below 60 seconds. | First-party, Secure, HTTP-only, SameSite=Lax, Path=/, host-only. |
| __Host-styvi_web_refresh | Strictly necessary | Renews the authenticated session without exposing the refresh token to browser scripts. | Up to 30 days, or earlier when you sign out, clear site data or the session is revoked. | First-party, Secure, HTTP-only, SameSite=Lax, Path=/, host-only. |
| __Host-styvi_web_pending_access and __Host-styvi_web_pending_refresh | Strictly necessary | Hold the restricted pending session while additional identity verification is completed. | The current server deadline: initially about 5 minutes and, after at most two explicit presence confirmations, never more than 15 minutes from the start. | First-party, Secure, HTTP-only, SameSite=Lax, Path=/, host-only. |
| __Host-styvi_web_mfa_factor and __Host-styvi_web_mfa_challenge | Strictly necessary | Bind an MFA verification attempt to the selected factor and challenge. | No longer than the current pending sign-in deadline; the provider challenge can expire sooner. | First-party, Secure, HTTP-only, SameSite=Lax, Path=/, host-only. |
| __Host-styvi_web_magic_pkce and __Host-styvi_web_magic_state | Strictly necessary when requested | Protect a magic-link sign-in with PKCE and bind its callback to the browser that requested it. | 10 minutes. | First-party, Secure, HTTP-only, SameSite=Lax, Path=/, host-only. |
| __Host-styvi_web_passkey_challenge | Strictly necessary when requested | Binds a passkey response to the short-lived WebAuthn challenge issued to this browser. | Between 1 and 300 seconds. | First-party, Secure, HTTP-only, SameSite=Strict, Path=/, host-only. |
| __Host-styvi_login_browser_id and __Host-styvi_login_browser_secret | Strictly necessary for account security | Bind the browser to secured web sessions, risk checks and Device Approval without exposing the browser secret to JavaScript. | 365 days, or earlier when cleared or replaced. | First-party, Secure, HTTP-only, SameSite=Strict, Path=/, host-only. |
| __Host-styvi_cookie_consent | Strictly necessary preference record | Stores only policy version v2 and whether you selected all cookies or necessary cookies, so Styvi can respect your choice. It contains no user or advertising identifier. | 180 days, or earlier when you change the choice or clear site data. | First-party, Secure, SameSite=Strict, Path=/, host-only. Readable by the same-origin consent control so it can apply your choice before optional storage is accessed. |
| styvi-onboarding-complete | Strictly necessary requested state | Remembers that you completed the web onboarding you requested, preventing a repeated onboarding redirect after sign-in. | Until you clear site data or the website replaces it. | First-party localStorage. It is not sent automatically with HTTP requests. |
| styvi-theme | Optional preference | Remembers the light or dark appearance you selected. Without consent, the current appearance can still be changed but is not stored for a later visit. | Until consent is withdrawn, site data is cleared or the preference is replaced. | First-party localStorage. Access is blocked unless optional cookies are allowed. |
| styvi-last-404-screenshot-id | Optional visual preference | Avoids showing the same rotating 404 artwork twice in a row. | The browser-tab session, or earlier when consent is withdrawn. | First-party sessionStorage. Access is blocked unless optional cookies are allowed. |
The older cookie names styvi_web_access, styvi_web_refresh, styvi_web_pending_access, styvi_web_pending_refresh, styvi_web_mfa_factor and styvi_web_mfa_challenge are not active storage. The server only sends deletion instructions for them during authentication cleanup.
Cloudflare operational observability and security request processing occur on the server and are not browser analytics cookies. WebAuthn passkey credentials are managed by your browser or operating system rather than stored by Styvi as cookies.
Use the persistent “Cookie settings” control at the bottom of the website to change or withdraw your choice at any time. Withdrawal is prospective and immediately deletes Styvi's optional local and session-storage keys where browser access permits. If Styvi introduces optional analytics, advertising or another storage purpose, this notice and the consent choices must be updated before that purpose is activated.
11. How long we keep information
We keep personal data only for the period needed for the purpose described above, then delete, de-identify or securely isolate it unless law or a legal hold requires longer retention. Because several records are linked, deletion can occur in stages across active databases, storage, queues and protected backups.
- Account, profile and user content: generally while the account or content remains active, then through the deletion process. Some purchase, safety, audit or AI-usage records can remain where required or can be retained after the account identifier is removed.
- Snips and other time-limited media: expiry removes the item from ordinary viewing, but does not currently guarantee immediate deletion of the database record or stored media. Safety, report, legal and backup needs can extend retention.
- Messages and location: ordinary message records remain for the conversation lifecycle and are not represented as end-to-end encrypted. Opt-in live friend-location payloads are encrypted for intended participants and delivered through a private realtime channel rather than intentionally written to the main location database.
- Search, recommendation and feature activity: for as long as needed to personalize, secure and improve the service, with reset or deletion controls where available.
- Purchase, entitlement, refund and receipt records: for the account lifecycle and longer where accounting, tax, fraud, platform or consumer law requires.
- Reports, enforcement, security and audit records: for the time reasonably needed to investigate, prevent repeat abuse, defend decisions and meet legal duties.
- Support and legal requests: through resolution and an appropriate limitation or record-keeping period.
- Data exports: the signed download link expires after seven days. Expiry of that link is not the same as immediate deletion of the protected export object, which follows the backend storage lifecycle.
- Website Studio: publication history and soft-deleted website media are currently retained without a fixed deletion deadline. Removing an asset from the current page does not by itself erase historical copies.
The current service does not have one universal fixed period for every record. Where a period is not stated, we use criteria including account status, feature lifecycle, sensitivity, user expectations, legal limitation periods, fraud and safety risk, storage integrity and whether information can be de-identified. Contact us for the current period applicable to a specific record.
12. Your choices and rights
Send a request to samuel.kubinec@icloud.com. We may need proportionate information to verify your identity and protect the account. Under the GDPR we normally respond within one month, subject to permitted extensions for complex or numerous requests.
Submitting an account-deletion request starts Styvi's backend deletion workflow. Certain records may instead be retained or de-identified for purchases, fraud prevention, moderation, security, legal claims or another lawful reason, and independently copied or re-shared content may require a separate rights request. If the in-app workflow fails, contact us so the request can be handled manually. Removing the app does not delete the account, and deleting a Styvi account does not automatically cancel an Apple or Google subscription.
- Access personal data and obtain information about its processing.
- Correct inaccurate or incomplete information.
- Request deletion, subject to lawful exceptions.
- Restrict processing or object to processing based on legitimate interests.
- Receive portable data where the GDPR conditions apply.
- Withdraw consent prospectively where consent is the legal basis.
- Use profile, privacy, notification, personalization, block, mute, restrict, export and deletion controls that are available in Styvi.
- Complain to the Úrad na ochranu osobných údajov Slovenskej republiky or another competent supervisory authority.
13. Children and teenagers
You must be at least 18 to create or use a Styvi account. A higher age may apply in a country or to a particular feature. Styvi is not an Apple Kids Category app and is not designed for children below the applicable minimum age.
Slovak law requires parental authorization where consent is used for an information-society service offered to a child under 16. Styvi does not treat a written age statement or restricted-mode label as a substitute for legally valid authorization.
Google's current Gemini API terms prohibit an API client that is directed to or likely accessed by people under 18. While Styvi includes Gemini, the service therefore requires users to be 18 or older. If Styvi later serves minors, Gemini must first be removed or replaced and the age design and this Policy must be updated.
A parent or guardian who believes a child is using Styvi contrary to these rules should contact samuel.kubinec@icloud.com. We may restrict the account, request proportionate age information, or delete data where required.
14. Security and incidents
Styvi uses measures such as encrypted transport, authentication and MFA controls, scoped storage, platform attestation or integrity checks where configured, server-side purchase verification, rate limits, access controls and audit records. Live friend-location payloads are designed to be encrypted for intended participants; ordinary messages and the service as a whole are not described as end-to-end encrypted.
No service is perfectly secure. Protect your credentials, use device security, and report suspected compromise. We will assess personal-data incidents and notify affected people or authorities where law requires it.
15. Changes and contact
We may update this Policy when the service, vendors or law changes. We will change the effective date and provide additional notice for material changes where required. Earlier versions should be retained for accountability.
Questions, requests and complaints can be sent to samuel.kubinec@icloud.com. Use a clear subject such as “Privacy request”, “Child safety”, “Account deletion” or “Security”.
- Samuel Kubinec
- Status: individual pre-release developer; no company or sole-trader registration has been supplied for Styvi
- Country used for this notice: Slovakia
- Separate public business or service address: not established or supplied
- Company or registration ID: none supplied
- Tax or VAT ID: none supplied; Styvi is not represented as VAT-registered
- Register and registration number: none supplied
- Email: samuel.kubinec@icloud.com
- Phone: +421951818608
- Consumer and e-commerce supervision: Slovak Trade Inspection, Central Inspectorate, Bajkalská 21/A, P. O. BOX 29, 827 99 Bratislava, Slovakia
- Data-protection supervision: Office for Personal Data Protection of the Slovak Republic, Galvaniho 7/B, 821 04 Bratislava, Slovakia