CAPSULEKIT — Legal / 02

Privacy Policy

Last updated: 9 September 2026

01. Controller

The controller responsible for the processing of personal data on this website is:

Nikolai Efimov
Winsstraße 59
10405 Berlin, Germany
Email: hello@capsulekit.app


02. Data we collect

We collect the following categories of personal data in the course of providing our styling service:

  • Contact data — name and email address provided during intake or account creation.
  • Intake responses — lifestyle, occasion, and style preference answers you provide during the brief. These may include information about physical measurements and body characteristics. We process these solely to deliver the styling service and do not sell or share them with third parties beyond the processors listed in section 05.
  • Photographs — client photos uploaded voluntarily for the AI virtual try-on feature. See section 03 for full details.
  • What was paid — a single amount, typed in by your stylist after money has changed hands elsewhere, so the studio has a record of what was settled. There is no checkout on this site and no payment provider behind it: no card number, no bank detail and no transaction reference ever reaches us, because nothing here ever asks for one.
  • Usage data — presentation views and interaction timestamps, used to detect abuse and improve the service.
  • Enquiries about a piece for sale — when someone holding the link to a piece a client is passing on leaves a way to be reached (a handle, an email or a phone number) and an optional message. It is shown only to the client selling that piece, is never published, is not used to contact the enquirer for anything else, and is deleted with the listing.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) for intake and project data; Art. 6(1)(a) GDPR (consent) for photographs used in AI try-on (see section 03); Art. 6(1)(b) GDPR for an enquiry about a piece for sale, which is the step the enquirer takes to be contacted about it.


03. Photos & AI try-on

As part of the styling service, we offer an optional AI-powered virtual try-on feature. This feature is strictly opt-in and requires your explicit written confirmation before any photo is transmitted.

AI try-on processing: To generate try-on visualisations, your photos are transmitted to FASHN (fashn.ai), a third-party AI image processing provider. Under FASHN's terms of service, uploaded content is not used for AI model training, marketing, or promotional purposes, and any third-party AI subprocessors engaged by FASHN process data transiently, solely to fulfil the generation request. All inputs and outputs submitted via the FASHN API are automatically deleted within 72 hours; only anonymised request logs are retained.

AI wardrobe analysis: When you (or your stylist) upload wardrobe photos, those photos are transmitted to OpenAI (openai.com) to recognise the garments and to generate clean garment images (cut-outs and studio photo preparation). Wardrobe photos can include you or parts of your home. Under OpenAI's API terms, content submitted via the API is not used to train OpenAI's models; API data may be retained for up to 30 days for abuse monitoring and is then deleted.

Result: a synthetic, AI-generated image. The output is a visualisation only and does not represent a guarantee of fit, colour accuracy, or product availability. This feature uses AI-generated content within the meaning of EU AI Act Art. 50.

International transfers: FASHN operates under the laws of England and Wales. Where personal data is processed outside the EU/EEA, transfers rely on an adequacy decision (e.g. for the United Kingdom) or Standard Contractual Clauses pursuant to Art. 46 GDPR.

Legal basis: Art. 6(1)(a) GDPR — your explicit consent, given when you upload your photos for a styling project. You may withdraw consent at any time with effect for the future; this does not affect the lawfulness of prior processing. To withdraw, contact us at the address in section 01.

Deletion: your original photos and all generated images are deleted from our systems within 12 months of project completion, or within 14 days of your request (see section 07).


04. Where your photos live, and who can open them

Your photographs — the ones you upload, and the AI images generated from them — are held in private storage with no public address. They are served only through an authenticated route that checks, on every single request, that the person asking is you or a stylist you currently work with. Removing a stylist's access removes their access to your pictures at the same moment.

There is one deliberate exception, and it is worth understanding. When your stylist publishes an edition, it becomes a web page reachable by its own long, unguessable link — so that you can open it without an account and show it to whoever you like. Anyone holding that link can see the edition, including the photographs of you inside it. That is what makes it shareable, and it is why the link should be treated as private.

The link can be withdrawn. Ask us or your stylist to revoke it and the page stops opening for everyone, immediately — including anyone you sent it to earlier. A link may also be given an expiry date when it is created.

Legal basis: Art. 6(1)(b) GDPR — performance of the service you commissioned, of which the published edition is the deliverable.


05. Processors & sub-processors

We use the following processors under Data Processing Agreements:

  • Vercel Inc. (USA) — website hosting and serverless functions. Transfers outside the EU/EEA are made under SCCs. Vercel DPA accepted in dashboard.
  • Supabase Inc. — database and authentication. Data is hosted in the EU (Frankfurt / AWS eu-central-1). Supabase standard DPA accepted in dashboard.
  • FASHN LTD — AI try-on processing. See section 03. All inputs and outputs automatically deleted within 72 hours. Processing is governed by FASHN's public Data Processing Addendum, which forms part of the agreement and incorporates the EU Standard Contractual Clauses and a published sub-processor list.
  • OpenAI, L.L.C. (USA) — AI photo analysis (wardrobe item recognition) and image processing (garment cut-outs, studio photo preparation). See section 03. API content is not used for model training; API data may be retained up to 30 days for abuse monitoring, then deleted. Transfers outside the EU/EEA are made under SCCs.
  • WaveSpeedAI PTE. LTD. (Singapore) — AI video generation (Higgsfield models). Would receive the look image, which may show the client, to animate it into a short runway clip. We do not generate videos for clients, and no client data has been sent to this provider. We will not begin until a data processing agreement and a valid transfer mechanism are in place: Singapore is not covered by an EU adequacy decision, and this provider currently publishes neither an Art. 28 addendum nor Standard Contractual Clauses. Any testing we do meanwhile uses our own photographs, not yours.
  • Features & Labels, Inc. (fal.ai) (USA) — background removal (Bria RMBG), used when a studio photo is prepared and when a garment is cut out of its photograph. Receives the photograph being processed, which for a studio photo shows the client. This replaced Kaleido AI GmbH (remove.bg, Austria) in September 2026, when that service announced its closure; the change moves this processing from the EU/EEA to the USA, and transfers are made under the provider’s Data Processing Addendum.
  • Zyte Group Ltd (Ireland) and Jina AI GmbH (Germany) — reading a shop page when a product link is imported and the shop refuses an ordinary request. They receive the shop link and nothing else: no name, no account, no photograph, and no indication of who pasted it. They are used only for importing a product from a public web page.
  • Resend Inc. (USA) — transactional email delivery (intake confirmations, presentation share links). Transfers outside the EU/EEA are made under SCCs. Resend DPA accepted in dashboard.

Vercel also provides Web Analytics and Speed Insights for this website: aggregate page views and page-loading measurements. They set no cookies, store nothing on your device, and build no profile — no identifier follows you between visits or between sites. What is recorded is the page address, the referring page, the country, and the browser and device class.

Page addresses are redacted before they leave this site: share links, invitation links and every identifier inside a URL are replaced with a placeholder, so a report says that an edition was opened without saying which one or whose. No advertising or profiling scripts are loaded on any page.


06. Retention periods

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.

  • Intake responses and project data — retained for the duration of the project and a reasonable period thereafter for service quality and legal compliance purposes, then deleted.
  • Client photos and generated try-on images — retained for the duration of the active project; deleted within 12 months of project completion, or within 14 days of your request at any time.
  • Payment records — retained for 10 years in accordance with § 147 AO (German fiscal retention obligation).
  • Account / authentication data — retained until you request account deletion.
  • FASHN processing artefacts — automatically deleted by FASHN within 72 hours of processing (see section 03).

07. Your rights

Under the GDPR you have the following rights regarding your personal data:

  • Access (Art. 15) — obtain a copy of data we hold about you.
  • Rectification (Art. 16) — correct inaccurate data.
  • Erasure (Art. 17) — request deletion of your data.
  • Restriction (Art. 18) — limit how we process your data.
  • Portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)) — withdraw consent for photo/AI processing at any time without affecting prior processing.

To exercise any of these rights, contact us at hello@capsulekit.app. We will respond within one month (Art. 12(3) GDPR).

You also have the right to lodge a complaint with the competent supervisory authority. For Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin (datenschutz-berlin.de).


08. Cookies

This website uses only technically necessary cookies — session tokens required for authenticated areas of the service. No tracking or advertising cookies are set on any page, and no cookie consent banner is displayed.

The analytics described in section 05 are cookieless: they set no cookie and write nothing to your device’s storage, which is why no consent banner appears for them. If anything that stores data on your device is added later, this section and a consent mechanism will be updated before activation.


09. Changes to this policy

We may update this policy when our processing activities change. Material changes will be communicated to active clients by email. The “last updated” date at the top of this page reflects the most recent revision.