Privacy Policy – Magic Mirror
Effective Date: 01/01/2026
Operated by: GeniusMetaverse (email: geniusmetaverse@gmail.com)
At Magic Mirror, we value your privacy. This Privacy Policy explains how your personal data is collected, used, shared, stored, and protected when you use our mobile application Magic Mirror. By continuing to use the App, you agree to this Policy. Please read it carefully.
1. Data We Collect
When using the App, we may collect the following categories of personal data:
- Photos and Images: Photos uploaded by you (including facial and body images), used solely to generate virtual bridal try-on visuals.
- User Interaction Data: In-app actions (selected styles, package purchases, ad views, usage time, trial counts).
- Device and Technical Information: Device model, operating system version, app version, IP address, language preference, advertising ID (IDFA/GAID), crash reports, and performance data.
- Payment Information: Purchases processed via Apple App Store or Google Play (we do not store payment details; only metadata such as transaction IDs).
- Contact Information: Email or message content provided when requesting support.
2. How Data Is Collected
- Directly from you: When you upload photos or interact with the App.
- Automatically: Device information and analytics (via Firebase Analytics or similar tools).
- From third parties: Payment metadata from Apple/Google, ad interaction data from AdMob.
3. Purposes and Legal Bases
Your data is processed for the following purposes:
- Generating virtual try-on images – Contractual necessity.
- Improving performance, fixing errors, analytics – Legitimate interest.
- Displaying and rewarding ads – Consent.
- Meeting legal obligations (tax, audits) – Legal requirement.
- Providing support and communication – Legitimate interest.
4. Photos and AI Processing
- Uploaded photos are processed only temporarily for image generation.
- Photos are automatically deleted after processing and removed from the system within 7 days at the latest.
- Photos are not shared with third parties. Processing occurs via Google Cloud/Vertex AI, which complies with KVKK/GDPR.
- Generated images are for personal use only; commercial use is prohibited.
- If photos contain sensitive data (biometric, health, etc.), uploading them constitutes your explicit consent to their processing.
5. Data Sharing and Transfers
- Your data is not shared with third parties for marketing purposes.
- Limited sharing occurs with technical service providers (Google Cloud, Firebase, RevenueCat).
- International transfers: Data may be processed on Google servers in the United States. Such transfers are safeguarded under GDPR using Standard Contractual Clauses and other approved mechanisms.
- Data may be disclosed if legally required (e.g., court order, regulatory request).
6. Data Retention
- Photos: Deleted within 7 days after processing.
- Usage/analytics data: Retained up to 24 months (longer if anonymized).
- Payment metadata: Retained for 10 years (tax compliance).
- Support requests: Retained for 1 year after resolution.
7. Data Security
We implement industry-standard technical and administrative measures (encryption, access control, regular security testing). However, it is important to note that no internet transmission is entirely risk-free.
8. User Rights (KVKK Article 11 & GDPR Articles 15–22)
You have the following rights:
- Access and obtain information about your personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion or anonymization of your data (“right to be forgotten”).
- Object to or request restriction of processing.
- Exercise data portability (receive your data in a structured format).
- Object to automated decisions (if applicable in AI processing).
To exercise your rights, contact us at geniusmetaverse@gmail.com. Identity verification may be required.
9. Children’s Privacy
The App is intended for users aged 16 and above. We do not knowingly collect data from children under 16. If such data is identified, it will be deleted immediately.
10. Cookies and Similar Technologies
The App uses Firebase Analytics and AdMob, which collect device information through cookie-like technologies. You can manage these preferences via your device settings or the in-app preferences menu.
11. Changes to This Policy
This Policy may be updated from time to time. Significant changes will be communicated via in-app notifications, email, or App updates. Continued use of the App after changes means you accept the updated Policy.
12. Contact
For questions, rights requests, or complaints:
Email: geniusmetaverse@gmail.com
This Policy has been prepared in compliance with KVKK (Law No. 6698), GDPR, and relevant international standards. It is provided for informational purposes and does not constitute legal advice. Professional legal consultation is recommended if needed.