Legal
Privacy.
Last updated: 1 September 2026
Fibe is an AI styling app made for the Gulf, launching first in the UAE. This page explains what data we collect, why we collect it, and the choices you have. It is written to be readable, not lawyered. If anything is unclear, email hello@fibeapp.com.
What we collect
- Account information — name, email, city, language, date of birth.
- Photos — the few reference photos you upload, used to analyse your colours and to generate personalised outfit images of you.
- Style preferences — aesthetics, occasions, coverage preferences, sizes.
- Activity — outfits viewed, saved, generated, and items clicked through to retailers.
- Device and diagnostic data — app version, OS, error logs. No advertising identifiers.
- Website and app usage — how you move through our website and app (pages and screens viewed, clicks, taps, scrolls), captured through privacy-masked analytics. See "Analytics and session replay" below.
How we use it
- To generate personalised outfit images and recommendations.
- To detect your colour palette and styling preferences from your photos.
- To improve outfit quality and product matching over time.
- To process affiliate link click-throughs to partner retailers (we earn commission on purchases).
- To send you account-related communication. We do not sell your data.
Photos and biometric data
Your photos are treated as sensitive personal data under UAE Federal Decree-Law 45/2021. We:
- Encrypt every photo at rest (AES-256-GCM) using a key unique to your account — not even our own admin tools can open them.
- Store photos in a region with appropriate data protection. Cross-border transfers are made only with your explicit consent.
- Share your photos with exactly one category of third party: the AI processors strictly necessary to analyse your colouring and generate your outfit images — OpenRouter, which routes the request to Google’s Gemini models. No one else receives them. Your photos are not used to train general AI models, and are never sold.
- Delete your photos and all derived data on request — see "Your rights" below.
Face data
Fibe needs to see your face to do its job: your colour season is read from your skin, hair and eye colouring, and outfit images are generated so they look like you rather than a stock model. Because "face data" is a term App Store review and several privacy laws treat specifically, here is exactly what happens to it.
- What we collect. The photographs you choose to upload, which contain your face and body. From them we derive and store: a colour profile (season, undertone and a small set of hex values sampled from your skin, hair, eyes and lips), an approximate body shape, and a generated "character sheet" — a set of reference renders of you used to keep your appearance consistent across outfit images. We do not compute or store a faceprint, face template, face geometry or any other biometric identifier capable of uniquely identifying you, and we do not perform face recognition, face matching or face search of any kind.
- How it is used. Only to produce your own colour analysis and your own outfit images. It is never used for advertising, never used to identify you, and never used to train general-purpose AI models.
- Who it is shared with. Photographs and the derived reference renders are sent to OpenRouter, which routes them to Google’s Gemini models for analysis and image generation. These are the only third parties that receive them. Both are bound by data-processing terms that require protections equivalent to those in this policy, and neither is permitted to use your images to train their models or for their own purposes. We do not sell, rent or otherwise disclose face data to anyone else.
- Where it is stored. Encrypted at rest (AES-256-GCM) in Cloudflare R2 under a key unique to your account, held in our key-management service. Our own staff and admin tools cannot decrypt it. Processing by the AI providers above occurs outside the UAE — see "Cross-border data transfer".
- How long it is retained. Your photographs and everything derived from them are kept only while your account is active, so that we can keep generating outfits that look like you. Generated outfit images are pruned on a rolling retention schedule. You can delete your photographs and all derived data at any time from Settings → Privacy and data, and deleting your account removes them within 30 days.
- Your permission. Before any photograph is sent for AI processing, the app shows a prompt naming what is sent, who receives it, why, and how long it is kept, and the transfer happens only if you agree. Declining leaves your photographs on your device.
Cross-border data transfer
Some processing (AI vision, image generation) is performed by providers based outside the UAE. Before your photos are sent for AI processing the app asks your permission in a dedicated prompt that names what is sent and who receives it, and nothing is transferred unless you agree. Continuing past the welcome screen accepts these Terms and this Policy generally; it is not treated as permission for that transfer. We sign data processing agreements with every external provider and apply contractual safeguards equivalent to UAE PDPL standards.
Analytics and session replay
To understand how people use our website and app — which screens are confusing, where people get stuck, what they tap — we use Microsoft Clarity, a product-analytics tool that builds aggregate heatmaps and replays of interaction sessions. Clarity captures behavioural signals only: pages and screens viewed, clicks and taps, scrolls, pointer or touch movement, device and browser type, and an approximate location derived from your IP address. It does this using first-party cookies and similar storage.
It is configured to protect your content. Clarity masks sensitive content on your device, before anything leaves it — masked content is never uploaded to Microsoft. It does not capture what you type. In our mobile app, every image of you is masked: the photos you upload, the colour portrait and character sheet we build from them, and every outfit image we generate for you. When you open your phone's photo library or camera to add a photo, recording stops entirely while that screen is open. What Clarity does record is the rest of the interface — the catalog items, prices and buttons you tap — because that is what shows us which screens are confusing. We use Clarity to improve the product, never to identify you personally.
Microsoft processes this data as an independent data controller under the Microsoft Privacy Statement, and stores it on Microsoft Azure. We do not sell this data. You can opt out of Clarity across every site that uses it via the Digital Advertising Alliance opt-out (choose Microsoft), and Clarity honours the Global Privacy Control browser signal.
We also use PostHog, a product-analytics platform, on our website and in the app. PostHog receives the product events we define (for example: an account was created, an outfit was generated or saved, a store link was opened, a purchase was completed), screen and page views, feature-flag evaluations that decide which product experience you see, your survey answers when you choose to respond, and device and app-version information. These events are tied to your Fibe account ID so we can understand usage across sessions — but never to your reference photos.
PostHog also records replays of app sessions so we can watch how features are used and fix what's confusing. In these recordings, anything you type is masked on your device (never uploaded), system photo pickers are masked, and every image of you is masked — your reference photos, your colour portrait, and the outfit images we generate of you. A recording shows the app's screens and taps, never your likeness or your keyboard input. General product imagery and app content are visible in recordings.
PostHog Inc. processes this data on our behalf as a data processor under the PostHog Privacy Policy, stored in the United States — covered by the cross-border transfer consent described above. We use it to improve the product, never to identify you to third parties, and we do not sell it. To have your analytics data deleted, delete your account or contact us — see "Your rights" below.
Advertising measurement
When we advertise Fibe, we need to know which ads actually bring people to the app. To measure that, our mobile app includes Meta's app measurement SDK and shares a limited set of app events with Meta Platforms: app installs and opens, when you view a product, when you complete setup, and purchases (including the amount and currency).
These events are tied to an anonymous, install-scoped identifier generated by Meta — not to your name, your email, your reference photos, or the outfit images we generate for you. On iOS, the app presents Apple's "Allow tracking" prompt once, early in setup. If you allow it, Meta also receives your device advertising identifier (IDFA), which lets it link your Fibe activity to the ad that brought you here and measure our campaigns person-by-person. If you decline — or dismiss the prompt — no IDFA is collected, Meta cannot link your Fibe activity to your activity in other companies' apps, and measurement falls back to Apple's privacy-preserving SKAdNetwork and Meta's aggregated measurement. The app works identically either way, and you can change your answer at any time in iOS Settings → Privacy & Security → Tracking.
Purchase events are sent to Meta from our payments provider's servers rather than from your device. Meta processes this data as an independent controller under the Meta Privacy Policy, outside the UAE. You can limit ad personalisation in your Meta account settings, and iOS Settings → Privacy & Security → Tracking lets you refuse app tracking device-wide.
Our website (fibeapp.com) also uses the Meta Pixel for the same purpose: it records that the page was viewed and that a download button was clicked, using a cookie set by Meta in your browser. It does not see anything you type and there is nothing to type on the page — no account, no photos, no personal content exists on the website. Meta processes pixel data as an independent controller under the same policy linked above; you can limit how Meta uses it in your Meta ad settings, or block the pixel entirely with a content blocker.
Your rights
You can at any time:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data, including your encrypted photos and every generated outfit image (we crypto-shred the encryption key, making the data permanently unreadable).
- Withdraw consent for biometric processing or cross-border transfer — though some features will become unavailable as a result.
- Object to processing and lodge a complaint with the UAE Data Office.
To exercise any of these rights, email privacy@fibeapp.com.
Retention
We keep your account data while your account is active. After you delete your account, we retain the minimum required for legal and accounting reasons (usually 30 days for backup expiry, longer where law requires).
Children
Fibe is not intended for users under 18. We do not knowingly collect data from minors.
Changes to this policy
We will email you and update the "Last updated" date if we change this policy materially.
Contact
Privacy questions: privacy@fibeapp.com
General: hello@fibeapp.com