Privacy Policy
Last updated [EFFECTIVE DATE — PENDING CLOSED-BETA LAUNCH DATE]
Mila is a personal styling application. To style you, it needs to know what you own and what you like. This page says exactly what that means, what leaves our systems, and what we cannot promise.
[LEGAL ENTITY NAME — PENDING COMPANY FORMATION], a [COUNTRY/STATE OF ORGANIZATION — PENDING COMPANY FORMATION] company, operates Mila. This policy covers the app and this website.
Scope. This policy is written for Mila’s initial launch in the United States. It does not attempt to meet the GDPR, the UK GDPR, or other non-U.S. regimes. Compliance work for those jurisdictions is outstanding and must be completed before Mila is offered in them.
1. Who can use Mila
Mila is for people aged 18 or over in the United States. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, write to privacy@ai-mila.com and we will remove it.
2. What Mila collects, and why
| Category | What | Why |
|---|---|---|
| Account | Email address, password (stored hashed by our authentication provider), username, display name, bio, profile photo, date of birth, and country and city if you provide them | To create and secure your account, and to show you to other users |
| Your closet | Photographs of your clothing, and attributes derived from them by AI — colour, material, pattern, cut, how formal a piece is | So Mila can style you from clothes you actually own |
| Style profile | Sizes, sizes you wear by brand, fit preferences per garment, colours you like and avoid, style words, budget band, and body measurements if you choose to type them | To make suggestions and size guidance fit you |
| Styling requests | The text of what you asked for, the occasion and style you chose, and whether the request succeeded | To generate looks, to apply rate limits, and to diagnose failures |
| Generated looks | Outfits Mila produced and the ones you saved | So you can return to them |
| Posts, stories and reels | The photographs and videos you publish, captions, occasion and style tags | To show them to the people you chose to show them to |
| Social activity | Follows, likes, saves, comments | To operate the feed and show counts |
| Messages | The text of your direct messages, and any image or video you send in one | To deliver them to the person you sent them to |
| Voice | A short audio recording, made only while you are recording | To turn speech into text you can edit. See section 4 |
| Reports and blocks | What you reported, which category you chose, who you blocked, and when | To review reports and enforce blocks |
| Error diagnostics | When the app fails: the error and where in the code it happened, the app version, whether you were on Android or iOS, and the time. Tied to your account so we can tell one person’s problem from everyone’s. It never contains your messages, captions, photographs, closet, styling requests or Mila’s replies, and the text is stripped of anything that looks like an address, a link or a credential before it leaves your device | So we can find and fix crashes. Stored in Mila’s own database, sent to no one else, and deleted after 30 days |
3. What Mila does not collect
These are statements about the current implementation, not aspirations:
- No analytics or tracking SDK. Mila contains no analytics, product-telemetry, advertising or crash-reporting SDK. We do not build behavioural profiles and we do not track you across other apps or websites. Mila does record its own errors, in our own database and nowhere else — see “Error diagnostics” in section 2.
- No device location. Mila never asks for or reads your device location. The country and city on your profile are text you type, and you can leave them blank.
- No payment information. No payment method is collected and no payment processor is connected. See section 8.
- No body-photograph analysis. Mila does not analyse photographs of your body and does not infer or store health, weight, body type or similar characteristics. Measurements, if you enter them, are numbers you type.
- No biometric identifiers. Mila does not perform face recognition or generate any biometric identifier or template.
4. Voice, in detail
This is the full path a voice request takes:
- You tap the microphone. Recording starts only then, and the microphone is not used at any other time.
- The recording is held in temporary storage on your own device.
- When you stop, the clip is sent to our server, which forwards it to OpenAI for transcription. It is not saved to our database or file storage at any point.
- The returned text is placed in the request box for you to read, correct or discard before anything else happens.
- The temporary copy on your device is deleted — on success, on cancellation, on failure, on timeout, and if you navigate away.
- If you then send the request, the text is treated exactly like a typed request: it is stored with your styling request, and it goes to Anthropic as part of generating a look.
What we can state: Mila does not retain the audio. Our server holds it only in memory for the duration of the request; nothing writes it to storage, and no log records it.
What we have verified with OpenAI. Mila’s OpenAI organisation is configured so that inputs and outputs are not shared with OpenAI, and data is not shared for evaluation or fine-tuning. Every other voluntary sharing control available in that organisation is switched off. In plain terms: your voice recordings are not used to train or improve OpenAI’s models.
What we cannot tell you yet. Zero Data Retention is not enabled on our organisation, and API call logging is enabled. That means OpenAI may hold the request for some period on its own systems under its API data-usage policy. We are not going to tell you that the audio is deleted immediately, or name a retention period, until we can point to OpenAI’s own current documentation for the exact endpoint we use.
[LEGAL/OPERATIONS DECISION REQUIRED — one endpoint-specific fact outstanding: the retention period OpenAI applies to requests to /v1/audio/transcriptions, and what “API call logging” captures and for how long. Founder-verified organisation Data Controls are recorded above; this is the remaining item and must be sourced from OpenAI’s current documentation or a written commitment, not inferred.]
5. Photographs sent for AI processing
Two kinds of image leave our systems:
- Closet photographs. When you add a garment, its photograph is sent to Anthropic so the garment’s attributes can be read. The photograph is also stored by Mila in a private closet area only you can read.
- Reference photographs. If you ask Mila to recreate a look from a picture, that picture is sent to Anthropic for that request. Mila does not store it.
What Anthropic does with them. Anthropic retains what we send — inputs and outputs — for 30 days under its default organisation retention, and may access that data during those 30 days for safety and security purposes. We have not enabled Zero Data Retention, so this 30-day window applies to every photograph, styling request and profile detail described above.
Not used to improve Anthropic’s models. We have not joined Anthropic’s Development Partner Program or any other voluntary data-sharing or model-improvement programme, and feedback sharing is switched off on our organisation. Retention for safety and security is a different thing from training, and we are not opted in to the latter.
6. Who else processes your information
These are the only third parties that receive personal information, and each processes it only to provide its service to Mila.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Hosting, database, file storage, authentication | All stored data, held in the US East (us-east-1) region |
| Anthropic (Claude) | Generates outfits; reads closet garment photographs | Your styling request text, your closet inventory and its attributes, your style profile including sizes, fit preferences and any measurements you entered, closet garment photographs, and reference photographs you supply. Your name, username and email address are not sent |
| OpenAI (Whisper) | Transcribes voice recordings, and nothing else | The audio clip only. Our organisation has model-training and evaluation sharing switched off; retention is covered in section 4 |
| Railway | Processes uploaded video into a publishable reel | Video files you upload |
[LEGAL DECISION REQUIRED — whether data-processing agreements are in place with each provider. Retention and training positions are now recorded in sections 4, 5 and 7: Anthropic 30 days with no training opt-in, OpenAI training sharing off with its retention period still to be confirmed for the transcription endpoint. What remains here is the contractual layer, not the factual one.]
7. Three different kinds of retention
These are easy to confuse, so they are set out separately. They are not the same thing and they have different answers.
- What Mila stores. Your account, closet, style profile, posts, messages, saved looks and styling request text, kept until you delete them or close your account. Voice recordings and reference photographs are not in this list — Mila does not store either. Section 10 has the detail.
- What our AI providers retain as processors. Separate from Mila’s own storage, and outside our control once sent. Anthropic: 30 days, accessible to Anthropic in that window for safety and security. OpenAI: unverified — see section 4.
- Voluntary model-improvement programmes. Schemes where a customer opts in to let a provider learn from their data. We have joined none of them. Anthropic’s Development Partner Program: not joined, feedback sharing off. OpenAI: inputs/outputs sharing off, evaluation and fine-tuning sharing off.
In short: a provider holding your request for 30 days so it can investigate abuse is not the same as a provider training on it. The first is true of Anthropic; the second is not true of either provider.
8. Sharing, selling and advertising
- We do not sell personal information.
- We do not share personal information for cross-context behavioural advertising.
- We do not serve advertising in Mila and run no advertising SDK.
- We disclose personal information only to the processors in section 6, and where we are required to by law or legal process.
- If Mila is ever involved in a merger, acquisition or sale of assets, information may transfer to the successor; we would tell you before that happened.
Other Mila users see what you choose to publish: your profile, your posts, stories and reels, and your messages to them. Your closet, your style profile, your measurements, your styling requests and your saved looks are private to you and are never shown to another user.
9. Subscriptions and payment
Nothing is for sale in Mila today. No payment method is collected, no charge is made, and no payment processor is connected. Where the app shows a plan choice, that choice is stored as a preference only. If we introduce paid features, this policy will be updated to describe what the payment processor receives before anyone is charged.
10. How long Mila keeps things
- Stories stop being visible 24 hours after posting. Being hidden is not the same as being deleted: the story record and its media file remain in our storage until you delete the story or your account. There is no automatic purge of expired stories today.
- Original uploaded video is swept from staging seven days after processing by our video worker. This is implemented and runs on a schedule; if the worker is not running, the sweep does not happen and the file remains.
- Voice recordings are not retained by Mila at all. Provider-side retention is unverified — see section 4.
- Reference photographs are not stored by Mila. Provider-side retention is unverified — see section 5.
- Styling request text is kept with your request history until you delete your account.
- Reports are kept for moderation review. A report is deleted if the person who made it deletes their account.
- Everything else is kept until you delete it or close your account.
- Backups. Our database provider takes daily backups. Point-in-time recovery is not enabled. Deleted data may persist in a backup for a period after deletion. [LEGAL/OPERATIONS DECISION REQUIRED — the configured backup retention window has not been verified.]
11. Deleting your account
Settings → Account → Delete account. You will be shown what deletion removes and asked to type DELETE to confirm.
Deletion is carried out on our servers and removes your account, your profile, closet, style profile and measurements, styling requests and saved looks, posts, stories and reels, comments, likes, follows, reports you filed, blocks you created, and the files you uploaded across every storage area. Your session ends immediately.
Two things deliberately survive: a conversation you took part in continues to exist for the other person, without your messages — their half of their own thread is not yours to delete; and copies may persist in backups as described above.
You can also delete individual items at any time: a closet garment and its photograph, and your own posts, stories and messages, from where they appear.
12. Security
Data is held by our hosting provider in the United States and encrypted in transit. Access to your rows is enforced in the database itself, not only in the app: every table carries row-level rules so that a request for another person’s data returns nothing, even if it bypasses the app entirely. Closet photographs, message media and uploaded video are held in private storage areas that are not publicly readable. Keys for AI providers are held server-side and are never present in the app.
No system is perfectly secure, and we cannot guarantee absolute security.
13. Your choices and rights
You can see and change your profile and style profile in the app, delete individual content, block and report other users, make your account private, and delete your account entirely.
Depending on where you live in the United States, you may have rights to know what we hold about you, to obtain a copy, to correct it, and to have it deleted. Mila is built so you can exercise the main ones yourself in the app. To make a request in writing, contact privacy@ai-mila.com. We will not discriminate against you for exercising a right.
Because we do not sell personal information or share it for cross-context behavioural advertising, there is nothing to opt out of in that respect.
[LEGAL DECISION REQUIRED — whether Mila meets the applicability thresholds of the California Consumer Privacy Act, and of the Virginia, Colorado, Connecticut, Utah, Texas and other state privacy statutes, and whether dedicated state sections, a “Notice at Collection”, or an authorised-agent process are required.]
14. Where your information is held
In the United States. Our processors may handle data in other regions in the course of providing their services; their own documentation governs that.
15. Changes
We may update this policy. Material changes will be notified in the app and the date above revised.
16. Contact
privacy@ai-mila.com · support@ai-mila.com
[LEGAL ENTITY NAME — PENDING COMPANY FORMATION], [REGISTERED BUSINESS ADDRESS — PENDING COMPANY FORMATION]