Privacy notice · effective 1 September 2026
How StyleIrisT uses your information
CodeMagician Ltd is the controller of personal information used to operate StyleIrisT. This notice explains what we collect, why we use it, who receives it, how long it is kept and the choices and rights available to you.
Controller and contact
The controller is CodeMagician Ltd (company number 17363646), registered in England and Wales, with its registered office at C/O Site & Field Services, 9 Freeman Way, North Seaton Industrial Estate, Ashington, Northumberland, United Kingdom, NE63 0YB. For privacy questions or to exercise a data-protection right, email account@codemagician.co.uk. You do not need to use any particular wording.
Age
The initial public service is intended only for people aged 18 or over, and account creation asks you to confirm this. StyleIrisT is not currently designed as a service for children. Do not upload images of anyone under 18. A future decision to admit 16- or 17-year-olds would require a separate privacy and age-appropriate-design review before the age rule changes.
Information you give us
This can include your name, email address, password in protected hashed form, account-security settings, invitation and waitlist information, wardrobe and reference photographs, garment details, written Style requests, routines, optional weather descriptions, outfit feedback, saved outfits, worn and laundry records, support messages and account-deletion requests. We do not ask for full card details.
Information created when you use StyleIrisT
We create account identifiers, legal-version and age-confirmation records, device-session information, security and support audit records, credit balances and history, AI operation and cost records, generated outfit suggestions and previews, and limited technical logs needed to diagnose, secure and operate the service. Original photograph metadata is removed when an accepted image is cleaned and resized for storage.
Payment and provider information
When purchases are enabled, Apple, Google or the web payment processor sends us limited transaction information such as the provider, product, amount, currency, transaction identifier, state and a pseudonymous account token. We use it to grant credits, prevent duplicate fulfilment, reconcile refunds and keep accounting records. Payment providers process card or store-account details under their own privacy notices.
Why we use information and our lawful bases
We use account and wardrobe information because it is necessary to provide the service and perform our contract with you. We use limited records for security, fraud and abuse prevention, reliable operation, support, capacity and cost control, and service improvement where this is necessary for our legitimate interests and does not override your rights. We use transaction and accounting information to perform the purchase contract and meet legal obligations. We use waitlist and invitation details to take steps you request before an account contract. Waitlist verification, invitation and admission messages are operational service messages, not promotional marketing; any future marketing email would require a separate optional choice and an unsubscribe route. Optional device location is used only when you ask for current weather and to fulfil that request; the operating-system permission can be refused or withdrawn.
Photographs and sensitive information
We use photographs to provide the garment, styling and preview features you request. We do not use facial recognition, identify you from your face, create a biometric identity, or infer health, ethnicity, religion or other sensitive traits. Avoid placing sensitive personal information in prompts or support messages. Only upload your own photograph or a photograph you have permission to use.
OpenAI processing
For AI features, selected cleaned wardrobe or reference photographs and the relevant request context are sent securely from the StyleIrisT server to OpenAI. Current requests disable application-state storage where the endpoint supports it. Under OpenAI's API data controls, API content is not used to train OpenAI models unless the customer opts in; CodeMagician Ltd does not opt in. OpenAI may retain content in abuse-monitoring logs for up to 30 days by default, with limited longer retention for safety or legal reasons. Image inputs may be screened for child-safety and abuse prevention.
Optional current weather
If you choose Use weather where I am, your device asks before sharing a location. The server rounds coordinates to roughly an 11 km area and sends that approximate location to Apple Weather through WeatherKit to obtain current conditions. Apple says location is used only to provide the forecast, is not associated with personally identifying information and is not tracked between requests. Coordinates are not stored in the StyleIrisT database or sent to OpenAI. The readable weather summary is kept with the Style request so a retry uses the same context. You can instead type weather information yourself.
Who receives information
We disclose only what is needed to contracted providers that help run the service: DigitalOcean for hosting infrastructure, OpenAI for requested AI processing, Twilio SendGrid for account and service email, Apple Weather through WeatherKit for optional weather, and Apple, Google or Stripe for the relevant payment channel when enabled. Professional advisers, regulators, courts or law-enforcement bodies may receive limited information where the law requires it or it is necessary to establish or defend legal rights. We do not sell personal information and do not use third-party advertising trackers.
International transfers
Some providers may process information outside the United Kingdom. Where UK personal information is transferred internationally, we use the transfer mechanism required for that provider and destination, such as UK adequacy regulations or approved contractual safeguards, and assess additional protections where required. Provider locations and safeguards are reviewed as part of the service's data-flow and supplier review.
Cookies, device storage and public caching
The browser service uses strictly necessary authentication, security and anti-forgery cookies. A session-storage flag remembers dismissal of the install suggestion only for that browser session. The service worker caches a fixed list of public StyleIrisT files such as styles, scripts and icons; it does not cache signed-in pages, private photographs or API responses. The native apps use protected device storage for renewable sign-in tokens and clear private caches on confirmed sign-out. See the Cookie and device storage notice for more detail.
How long information is kept
Unfinished wardrobe uploads expire after 24 hours. Failed or interrupted styling requests expire after 90 days. An unverified waitlist link expires after 24 hours; the associated waitlist record remains while controlled admission operates or until you ask us to remove it. Delivered or finally failed email content is removed promptly and completed outbox records are deleted after 30 days. Account content normally remains until you delete it or close the account. Security, support and transaction records are kept only as long as needed for their purpose; accounting and tax records may be retained for up to six years after the relevant period where the law requires it. Retention is reviewed when providers or legal requirements change.
Deletion and backups
Account deletion removes your live account, photographs, wardrobe, styling history, previews, usage records, invitations and email records. Billing transactions and support audit entries that must remain are disconnected from the account and use a one-way deleted-user reference. Encrypted rotating disaster-recovery backups are not used as a live archive and age out under the backup schedule, currently 30 daily, 8 weekly and 6 monthly snapshots. If a backup is restored, deletion records and normal cleanup processes must be reapplied.
Your rights
Depending on the circumstances, you may ask for access to your personal information, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting earlier lawful use. Signed-in members can correct or remove much of their content, download a private copy, and delete the account. We may need to verify identity before completing a request and will explain if an exemption applies.
Automated processing
AI generates classifications, styling suggestions and illustrative images, but StyleIrisT does not make solely automated decisions that produce legal or similarly significant effects about you. Credit debits follow the published successful-outcome rules. Support can investigate failed work, purchases and account decisions.
Security
We use encrypted network connections, server-side provider credentials, protected password hashing, optional multi-factor authentication, owner-scoped data access, private media storage, rate limits, audit records and encrypted off-site backups. No internet service can promise absolute security, so contact us promptly if you suspect misuse of your account.
Complaints and changes
Please email account@codemagician.co.uk if you have a privacy concern. You may also complain to the UK Information Commissioner's Office at ico.org.uk or by using its published contact routes. We may update this notice when the product, providers or law change. The page shows its effective date, and material changes will be brought to existing members' attention and recorded as a new version.
See also the cookie and device storage notice and account deletion instructions.