ModaScout Privacy Policy
Effective date: 12 September 2026 Last updated: 12 September 2026
This Privacy Policy explains how ModaScout collects, uses, shares, stores, and protects personal information when you use the ModaScout mobile application, its Share-to-App features, notifications, websites or support pages that link to this Policy, and the related backend services (together, the Service).
1. Who we are
ModaScout is a trading name and brand of ModaScout Limited. In this Policy, ModaScout, we, us, and our mean ModaScout Limited.
Legal operator and data controller: ModaScout Limited
Company number: 17397182
Registered office: 11 Khama Road, London, SW17 0EN, United Kingdom
Privacy and support email: mailing@getmodascout.com
Telephone: +44 7412 805807
Website: https://getmodascout.com
Public account-deletion request page: https://getmodascout.com/delete-account
Support page: https://getmodascout.com/support
ModaScout Limited is the controller of the personal information described in this Policy. Some third-party services act as our processors, and some may act as separate controllers for their own activities, as explained below. A director acting as ModaScout's privacy lead monitors privacy requests sent to the address above.
2. The short version
- ModaScout lets you upload or share a clothing photo or screenshot, identify visible garments using artificial intelligence, and search for visually or textually similar products.
- New scans require a separate, explicit choice about third-party AI usage. If you do not consent, you can still access parts of the app, but ModaScout cannot process new scans.
- When you consent and start a scan, the uploaded image is sent to Google Gemini to identify visible clothing. Selected garment crops, descriptions, and search settings are sent through SerpAPI to Google Lens or Google Shopping to find products.
- We store scans, garment crops, search results, account information, preferences, likes, operational diagnostics, and notification information as needed to provide and secure the Service.
- We do not currently use third-party advertising or analytics SDKs in the mobile app. We do not sell personal information or share it for cross-context behavioural advertising.
- If you create a registered account, you may separately opt in to marketing email. Marketing is optional, is not required to use ModaScout, and can be stopped at any time.
- You can withdraw AI consent, turn off notifications, delete individual scans, and request account deletion. Withdrawing AI consent stops new AI processing but does not automatically delete information already processed; deletion is a separate action.
- ModaScout is a fashion discovery tool. Product matches, descriptions, prices, availability, currencies, and retailer information may be incomplete, delayed, or wrong.
3. Information we collect
3.1 Account and session information
ModaScout supports stable guest accounts and registered accounts.
For a registered account, we collect your display name, email address, account identifier, account status, and timestamps associated with account creation or updates. Authentication is provided through Supabase Auth. ModaScout does not need to see or store your plaintext password in its operational database, but Supabase processes authentication credentials and session information for us.
For a guest account, we create a pseudonymous user identifier and session credentials so your scans and Wardrobe can remain associated with the same installation. If you later register or sign in, eligible guest data may be transferred to the registered account and the old guest identity may be deleted or retained briefly as a security tombstone while cleanup completes.
The app stores access and refresh tokens, expiry information, consent state, and limited account details on your device. On iOS, the same information may be stored in the private App Group used by the main app, Share Extension, notification extension, and shared-storage components so those features can act for the correct account.
3.2 AI consent information
We store whether you granted or withdrew consent to third-party AI usage, the disclosure version you were shown, the relevant timestamps, the source of the change, and a pseudonymous subject identifier. We maintain a consent audit so we can enforce your current choice, prevent processing without authority, demonstrate compliance, and investigate disputes.
3.3 Photos, screenshots, shared files, and camera images
When you choose a photo, take a camera photo, or share an image to ModaScout, we process:
- the image content itself, which may include clothing, people, faces, bodies, surroundings, text, retailer interfaces, or other visible information;
- file and upload information such as file type, file size, image dimensions, upload-attempt identifiers, source method, and processing timestamps;
- a private stored copy of the source image; and
- garment crops created from the image.
ModaScout does not request precise device-location permission. During first setup, the app may read the device's locale or region code locally to suggest a Base Country. A photo may nevertheless reveal location or other personal information through its visible content. Do not upload images that you are not entitled to use or that reveal information you do not want processed.
3.4 Clothing analysis and search information
AI analysis may generate or store:
- detected garment labels and categories;
- colour, material, pattern, texture, fit, silhouette, neckline, sleeve, length, visibility, and confidence information;
- crop coordinates and garment crops;
- visible brand marks, visible garment text, retailer or domain clues, and product-search phrases;
- layer and wearer-context attributes used to separate garments in the image;
- suggested retail department information and compatibility terms; and
- technical provider outcomes, warnings, retries, status codes, and processing durations.
ModaScout is not designed to identify people, recognise faces, or create biometric templates. It may analyse visible context about how clothing is worn because that is necessary to distinguish garments and search for products.
When you start a product search, we also process the garments you selected, the search generation and reliability checkpoint, the Base Country, language and country localisation, local-currency preference, your optional Male or Female profile choice, and whether you enabled Show fewer opposite-sex results. These settings are snapshotted for that search so concurrent jobs and retries use the same context.
3.5 Product, retailer, and Wardrobe information
We collect and store product-search results such as product identifiers, titles, brands, merchants, prices, currencies, images, retailer URLs, availability signals, ranking information, match type, source, and the garment to which a result relates.
If you like a product, we store it in your Wardrobe using a stable product identity. We store when it was saved and the product details needed to show it again. ModaScout does not currently process retailer payments, payment-card details, delivery addresses, or your completed purchases. If you visit or buy from a retailer, the retailer processes that interaction under its own terms and privacy policy.
3.6 Preferences and local app state
The app may store your:
- optional sex preference;
- opposite-department results preference;
- Base Country and local-currency preference;
- notification preference and operating-system permission state;
- onboarding and tutorial progress;
- scan labels, recently completed scan identifiers, and share-intent deduplication records; and
- local choices used to avoid repeating confirmations.
Some preferences remain only on your device. Search-related preferences are sent to the backend when needed to run or restore a search. On iOS, relevant account, consent, device, and search-preference values may also be copied to the private App Group so Share-to-App and expanded notification search can work correctly.
3.7 Device, network, diagnostics, and usage information
We create a random installation identifier, called a client device ID, to associate guest sessions, uploads, quotas, notification routing, and Share-to-App reconciliation with the correct installation. It is not an advertising identifier and is not intended to track you across unrelated apps or services.
We may process device platform, app build, operating-system permission state, Expo push token, IP address, request time, API route, connection information, errors, provider call counts, job status, retry state, search and scan limits, latency, estimated provider cost, and security or abuse-prevention signals.
We use first-party operational usage events and daily summaries to operate quotas, monitor reliability, diagnose failed scans or searches, and manage service cost. The current mobile app does not include third-party advertising or behavioural analytics SDKs.
3.8 Notifications
If you enable notifications and the operating system grants permission, we process your Expo push token, platform, environment, installation identifier, notification preference, token status, ticket or receipt identifiers, delivery outcome, and limited notification payload information.
Notifications may say that a scan or search is complete or failed. On supported iOS devices, an expanded scan notification may include garment labels, garment crop references, and capture identifiers so you can choose up to three garments and start a search without opening the main app. Notification previews may be visible on a locked device depending on your operating-system settings.
3.9 Support, complaints, and deletion requests
If you contact us, we collect the information you provide, such as your name, email address, message, attachments, and information needed to investigate the issue. If you request account deletion outside the app, we may collect an email address, verification information, request timestamps, request status, failure details, and records needed to complete and prove the deletion.
3.10 Marketing preferences and email
If you create a registered account and actively select the unticked marketing option, we process your email address, name where available, consent status, the wording and version presented, the time and source of the choice, email topics or preferences, delivery information, and unsubscribe status. Account and security emails are transactional and do not depend on marketing consent.
We use Resend to deliver authentication and operational email and, where you opt in, marketing email. Resend may process recipient details, message content, delivery events, and suppression or unsubscribe records in the United States and through its subprocessors.
4. Where information comes from
We obtain information:
- directly from you when you create an account, change settings, upload or share an image, select garments, like products, request deletion, or contact us;
- automatically from the app, your installation, and our backend when the Service processes a request;
- from your device and operating system, such as permission status, app platform, device region, and push token;
- from Google Gemini, SerpAPI, Google Lens, Google Shopping, retailers, product pages, image hosts, and currency-data services when they return analysis or product information; and
- from Apple, Google, Expo, Supabase, Render, and other infrastructure providers when they return authentication, delivery, hosting, or security information.
5. How and why we use information
5.1 To provide the Service
We use information to create and maintain guest or registered sessions; receive uploads; identify clothing; create garment crops; search for products; localise countries, retailers, and currencies; display results; maintain Wardrobe likes; restore searches; support Share-to-App; and send requested notifications.
Where data-protection law requires a lawful basis, this processing is generally necessary to perform our contract with you or to take steps at your request. Third-party AI processing is additionally gated by the explicit consent choice shown in the app.
5.2 To honour AI consent and privacy choices
We use consent records and audit events to prevent new scans or searches when third-party AI usage is off, to transfer the correct consent state to Share-to-App, and to demonstrate when a choice was made.
Where consent is our lawful basis, you may withdraw it at any time in ME. Withdrawal does not affect processing that was lawful before withdrawal and does not itself delete prior scans, results, or audit records.
5.3 To secure, troubleshoot, and improve reliability
We use operational data to authenticate requests, prevent one installation receiving another installation's results, reconcile ambiguous uploads, prevent duplicate captures and duplicate notifications, enforce rate and usage limits, recover jobs after worker restarts, detect abuse, investigate security incidents, and improve reliability.
Where applicable, we rely on our legitimate interests in operating a secure, dependable, cost-controlled Service, provided those interests are not overridden by your rights. We minimise diagnostics and restrict access according to job role and operational need.
5.4 To comply with law and protect rights
We may use or preserve information to comply with legal obligations, enforce our Terms and Conditions, respond to lawful requests, establish or defend legal claims, protect users or the public, and document account deletion or consent history.
5.5 To send marketing you requested
We send marketing email only where you have actively opted in or another lawful permission applies. Consent is optional and is not bundled with account creation, AI consent, or use of the Service. You can withdraw it through the marketing preference control in ME, through the unsubscribe link in each marketing email, or by contacting us. Withdrawal does not affect transactional messages that are necessary to administer or secure your account.
6. When we share information
We share personal information only as needed for the purposes described in this Policy.
6.1 Google Gemini
After you grant third-party AI consent and start a scan, ModaScout sends the uploaded image and an analysis prompt to Google Gemini. Gemini returns structured clothing-analysis information. The image may contain more than the selected garment because the full photo is used to detect visible items.
6.2 SerpAPI, Google Lens, and Google Shopping
For each garment you choose to search, ModaScout may provide SerpAPI with a selected garment crop through a time-limited signed URL, a garment description or search query, language and country parameters, and other search settings. SerpAPI obtains results from Google Lens and, only in the existing emergency fallback case, Google Shopping. Those services return product and retailer information.
The current search design normally uses two concurrent Lens routes per garment and permits at most one emergency Shopping call, for a maximum of three SerpAPI calls per garment. This operational limit does not change the categories of information shared.
6.3 Supabase
Supabase provides authentication, PostgreSQL database services, and private object storage. It stores account records, consent state, scans, garment crops, search and product data, Wardrobe items, notification records, quotas, diagnostics, and deletion state. Source and crop images are held in a private bucket and read through backend-authorised or time-limited signed URLs.
6.4 Render
Render hosts the ModaScout API and worker processes. It processes API traffic, network information, job state, provider calls, logs, and the information needed to run the backend.
6.5 Expo, Apple, and Google notification services
If notifications are enabled, ModaScout sends the push token and notification payload through Expo's push service and the relevant Apple Push Notification service or Firebase Cloud Messaging infrastructure. Apple and Google also process app-store, device, crash, purchase, and platform information under their own terms where applicable.
6.6 Retailers, product sites, and image hosts
ModaScout may retrieve publicly available product information, retailer metadata, and product images to validate and present results. When you open a retailer link, your browser or retailer app connects directly to that retailer. The retailer may receive your IP address, device or browser information, referral information, and any information you provide to it. ModaScout is not responsible for the retailer's independent processing.
6.7 Other service providers and professional advisers
Resend provides transactional email and our opt-in marketing-email service. ExchangeRate-API provides currency-reference data; we do not need to send it your account, photos, garment crops, or Wardrobe data. We may also use security, backup, customer-support, legal, accounting, or audit suppliers. They may process only the information reasonably necessary for their service and must protect it under contract and applicable law.
6.8 Legal, safety, and business events
We may disclose information when reasonably necessary to comply with law, respond to lawful process, protect rights or safety, investigate fraud or abuse, or establish or defend claims. If the Service or its operator is involved in a merger, financing, reorganisation, acquisition, or asset transfer, information may be disclosed under confidentiality and transferred subject to applicable law and notice requirements.
7. No sale or behavioural advertising
ModaScout does not currently sell or rent personal information. The current mobile app does not include third-party advertising SDKs, and we do not share personal information for cross-context behavioural advertising or targeted advertising based on activity across unrelated services.
Marketing email is based on your direct choice to hear from ModaScout; it is not behavioural advertising and does not involve selling your personal information.
If this changes, we will update this Policy and provide any notice, consent, or opt-out required by law before the new use begins.
8. Automated processing and AI limitations
ModaScout uses automated systems to detect clothing, create search descriptions, rank and filter product results, localise retailer links, recover product images, enforce usage limits, and route notifications. These systems can make mistakes, including missing a garment, choosing an imperfect crop, returning an irrelevant item, or displaying stale or incomplete retailer information.
The automated processing is intended to help you discover clothing products. It is not used to make decisions that produce legal or similarly significant effects about you. You can choose a different photo, select different garments, retry a search, change preferences, delete a scan, withdraw AI consent, or stop using the Service.
9. International data transfers
ModaScout Limited is established in the United Kingdom. Our production database and private image storage are hosted through Supabase in the United States, currently in the us-east-1 region; our production API and workers are hosted by Render in Virginia, United States. Google, SerpAPI, Expo, Apple, Resend and their subprocessors may also process information in the United States, the United Kingdom, the European Economic Area, and other countries. Data-protection laws in those countries may differ from those where you live.
Where data-protection law restricts an international transfer, a valid transfer mechanism must be in place. Depending on the recipient and applicable law, this may involve an adequacy decision or regulation, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, or an applicable recognised data-privacy framework, together with any necessary additional safeguards. Contact mailing@getmodascout.com to request information about the safeguards applicable to your data or a copy, subject to necessary redactions.
ModaScout’s public-launch scope includes the European Union and European Economic Area. Before enabling the Service in those markets, we will complete the required territorial, representative, transfer, and notice arrangements. Including a market in our launch plans does not mean those arrangements have already been completed.
10. How long we keep information
We keep personal information only for as long as reasonably necessary for the purposes described here, including to provide the Service, honour choices, secure the platform, comply with law, resolve disputes, and complete deletion.
Our retention schedule is as follows:
- Registered accounts and profiles: kept until you delete the account or we lawfully close it, subject to the limited records below and periodic reviews of whether continued retention remains necessary.
- Inactive guest accounts: scheduled for deletion after 12 months without activity, subject to reasonable notice or technical safeguards where appropriate. Guest data may be lost earlier if its credentials can no longer be linked to you.
- Scans, source images, garment crops, cached product images, analysis, and results: kept until you delete the scan or relevant account. Deleting a scan triggers deletion of its private image objects and operational data. A short-lived technical tombstone may remain for approximately 24 hours to reconcile uploads already in flight and verify cleanup.
- Wardrobe items: kept until you unlike or remove the product or delete the relevant account.
- Notification delivery records: completed outbox records are deleted after 30 days. Active tokens and preferences remain until disabled, revoked, replaced, or the account is deleted.
- Local app and App Group data: kept until it is overwritten, cleared by the app, removed through account or share cleanup, or removed when you delete the app or its data. Uninstalling the app does not by itself guarantee deletion of server-side guest or account data.
- Consent and account-deletion audit records: limited records are kept for six years after account deletion or completion of the relevant request so we can demonstrate the instruction, prevent data resurrection, meet legal obligations, and resolve claims.
- Identifiable security, provider, and technical diagnostic records: normally kept for 90 days. We may retain a specific record longer where necessary to investigate an incident, prevent fraud or abuse, or establish or defend a legal claim.
- Aggregated operational and usage summaries: kept for up to 24 months. We minimise or remove identifiers where they are no longer needed.
- Support correspondence: normally kept for 24 months after the matter is closed, or longer where reasonably necessary for an unresolved dispute, complaint, legal duty, or claim.
- Marketing consent and suppression records: kept while marketing consent is active and afterwards for as long as necessary to honour an unsubscribe, demonstrate the consent history, and meet legal obligations. We retain the minimum suppression information needed to avoid contacting someone who opted out.
- Database backups: Supabase Pro daily database backups are retained for up to seven days. Those database backups contain database records and object metadata, but do not contain the actual files stored in the private capture-images Storage bucket. We have not configured a separate backup or replication system for those Storage objects.
- Provider-held copies: may remain for the provider's documented processing or deletion cycle. For paid Gemini services, Google states that submitted content is not used to improve its products, but may temporarily log prompts and responses for abuse monitoring unless Zero Data Retention has been approved. ModaScout does not currently claim Zero Data Retention approval.
- Legal holds: where reasonably necessary to comply with law or establish, exercise, or defend claims, we may preserve the minimum relevant information until that need ends.
If a deletion cannot complete immediately, ModaScout marks the data and account for deletion, prevents new scans or searches for that identity where appropriate, and retries the cleanup.
We retain only the minimum information needed to record and finish that request. Information may remain temporarily in protected backups but is not restored for ordinary use after a valid deletion request.
11. Your choices and controls
11.1 Third-party AI usage
You can grant or withdraw third-party AI consent in ME. If it is off, ModaScout will not start new scans that require Gemini, SerpAPI, Google Lens, or Google Shopping. Turning it off does not delete completed scans or reverse provider processing that already occurred.
11.2 Photos and camera
You choose whether to use the photo library, camera, iOS Share Extension, or Android share target. You can change camera or photo permissions in system settings. ModaScout does not scan your whole library; it processes images you select, capture, or share to it.
11.3 Notifications
You can turn ModaScout notifications off in ME and control operating-system permission in system settings. Notification previews and lock-screen visibility are controlled by your device settings.
11.4 Country, currency, and result preferences
You can change Base Country, local-currency preference, optional sex preference, and the opposite-department results preference in ME. Changes apply to later searches and do not retroactively alter an already snapshotted search.
11.5 Scan and account deletion
You can delete individual scans in the app. Registered users can request account deletion in the account controls. After a registered account is deleted, the app may create a fresh guest session so the app can continue to open; that new guest session is separate from the deleted account.
Deleting the app from your device does not automatically submit a server-side account-deletion request. If you cannot access the app, use https://getmodascout.com/delete-account. We normally verify an external request through the registered email address or authenticated account and request additional evidence only where reasonably necessary.
11.6 Marketing email
When creating a registered account, you can decide whether to receive marketing email through a separate unticked choice. You may later withdraw through ME, an unsubscribe link in any marketing message, or by contacting us. Withdrawing from marketing does not disable essential authentication, security, deletion, or support messages.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- ask whether we process your personal information and obtain a copy;
- correct inaccurate or incomplete information;
- request deletion;
- restrict or object to certain processing;
- receive certain information in a portable format;
- withdraw consent at any time where processing is based on consent;
- object to direct marketing and withdraw any marketing consent at any time;
- opt out of sale, sharing, or targeted advertising where applicable, although ModaScout does not currently conduct those activities; and
- complain to a data-protection authority.
To exercise a right, use https://getmodascout.com/support or contact mailing@getmodascout.com. We normally verify a request through your authenticated account or control of the registered email address. We request additional identification only where it is reasonably necessary and proportionate. We normally respond within one month; where applicable law permits more time for a complex or multiple request, we will explain the extension within the initial period. We will not discriminate against you for exercising a legally protected right.
In the United Kingdom, you may complain through the Information Commissioner's Office complaint service. If you are in the EU/EEA and the GDPR applies to our processing, you may complain to a supervisory authority, including in the country where you habitually live or work, or where you believe an infringement occurred. The European Data Protection Board lists these authorities. In other regions, you may contact your local privacy regulator. We would appreciate the opportunity to address your concern first, but you do not have to contact us before using a regulator where the law gives you that right.
12.1 Privacy complaints
To make a privacy complaint, contact our privacy lead using Section 17 and describe what happened and the resolution you seek. We will acknowledge the complaint, investigate it fairly, and normally provide a substantive response within 30 days. If we need more time, we will explain why and provide an updated timeframe. You may also complain to the regulator that has jurisdiction where you live.
12.2 Additional United States disclosures
Where an applicable US state privacy law covers ModaScout, categories processed may include identifiers; account and customer-record information; internet or network activity; photos and other sensory information; product interests and Wardrobe activity; approximate country or region; and inferences or preferences used to provide search results. We use and disclose these categories for the business and service purposes described in this Policy.
We do not knowingly sell these categories or share them for cross-context behavioural advertising. We do not use sensitive personal information to infer characteristics for unrelated purposes. Applicable state law may give you rights to know, access, correct, delete, or obtain a portable copy and to appeal a denied request.
If we deny a privacy request and the law where you live provides an appeal right, reply to the decision or submit an appeal through our support page with the subject Privacy appeal. We will review the appeal separately where required and explain any available regulator contact.
13. Children
ModaScout is an adult service. You must be at least 18 years old to create or use a guest or registered account, upload or share an image, or otherwise use the Service. ModaScout is not directed to children, and we do not knowingly collect personal information from anyone under 18.
If we learn that someone under 18 has used ModaScout or submitted personal information, we will restrict the account and take reasonable steps to delete the information, subject to any minimal record needed for safety, legal compliance, and preventing repeated underage access. A parent or guardian may contact mailing@getmodascout.com or use our support page to report suspected underage use.
14. Security
ModaScout uses technical and organisational measures designed to protect personal information. Current safeguards include authenticated API access, server-side secrets, private object storage, row-level and runtime database controls, time-limited signed image URLs, encrypted network transport, per-user ownership checks, per-installation notification routing, bounded upload and image validation, durable deletion records, and restricted administrative diagnostics.
No security measure is perfect. You are responsible for protecting your device, account credentials, email account, and any screenshots you save or share. Tell us promptly if you believe your account or information has been compromised.
15. Third-party services and links
Retailers, product sites, Apple, Google, and other third parties have their own privacy notices and terms. This Policy does not govern their independent processing. Review a retailer's terms, privacy policy, returns policy, product information, and payment security before making a purchase.
16. Changes to this Policy
We may update this Policy when the Service, providers, law, or data practices change. We will change the Last updated date and provide additional notice when required. If a change materially affects processing based on consent, we will request a new choice where the law or app-store rules require it.
17. Contact us
Questions, complaints, privacy requests, and deletion requests may be submitted through https://getmodascout.com/support, by email to mailing@getmodascout.com, or by post to ModaScout Limited, 11 Khama Road, London, SW17 0EN, United Kingdom. Account-deletion requests may also be submitted at https://getmodascout.com/delete-account. Telephone: +44 7412 805807.