Legal

Privacy.

Last updated: 1 September 2026

Fibe is an AI styling app made for the Gulf, launching first in the UAE. This page explains what data we collect, why we collect it, and the choices you have. It is written to be readable, not lawyered. If anything is unclear, email hello@fibeapp.com.

What we collect

How we use it

Photos and biometric data

Your photos are treated as sensitive personal data under UAE Federal Decree-Law 45/2021. We:

Face data

Fibe needs to see your face to do its job: your colour season is read from your skin, hair and eye colouring, and outfit images are generated so they look like you rather than a stock model. Because "face data" is a term App Store review and several privacy laws treat specifically, here is exactly what happens to it.

Cross-border data transfer

Some processing (AI vision, image generation) is performed by providers based outside the UAE. Before your photos are sent for AI processing the app asks your permission in a dedicated prompt that names what is sent and who receives it, and nothing is transferred unless you agree. Continuing past the welcome screen accepts these Terms and this Policy generally; it is not treated as permission for that transfer. We sign data processing agreements with every external provider and apply contractual safeguards equivalent to UAE PDPL standards.

Analytics and session replay

To understand how people use our website and app — which screens are confusing, where people get stuck, what they tap — we use Microsoft Clarity, a product-analytics tool that builds aggregate heatmaps and replays of interaction sessions. Clarity captures behavioural signals only: pages and screens viewed, clicks and taps, scrolls, pointer or touch movement, device and browser type, and an approximate location derived from your IP address. It does this using first-party cookies and similar storage.

It is configured to protect your content. Clarity masks sensitive content on your device, before anything leaves it — masked content is never uploaded to Microsoft. It does not capture what you type. In our mobile app, every image of you is masked: the photos you upload, the colour portrait and character sheet we build from them, and every outfit image we generate for you. When you open your phone's photo library or camera to add a photo, recording stops entirely while that screen is open. What Clarity does record is the rest of the interface — the catalog items, prices and buttons you tap — because that is what shows us which screens are confusing. We use Clarity to improve the product, never to identify you personally.

Microsoft processes this data as an independent data controller under the Microsoft Privacy Statement, and stores it on Microsoft Azure. We do not sell this data. You can opt out of Clarity across every site that uses it via the Digital Advertising Alliance opt-out (choose Microsoft), and Clarity honours the Global Privacy Control browser signal.

We also use PostHog, a product-analytics platform, on our website and in the app. PostHog receives the product events we define (for example: an account was created, an outfit was generated or saved, a store link was opened, a purchase was completed), screen and page views, feature-flag evaluations that decide which product experience you see, your survey answers when you choose to respond, and device and app-version information. These events are tied to your Fibe account ID so we can understand usage across sessions — but never to your reference photos.

PostHog also records replays of app sessions so we can watch how features are used and fix what's confusing. In these recordings, anything you type is masked on your device (never uploaded), system photo pickers are masked, and every image of you is masked — your reference photos, your colour portrait, and the outfit images we generate of you. A recording shows the app's screens and taps, never your likeness or your keyboard input. General product imagery and app content are visible in recordings.

PostHog Inc. processes this data on our behalf as a data processor under the PostHog Privacy Policy, stored in the United States — covered by the cross-border transfer consent described above. We use it to improve the product, never to identify you to third parties, and we do not sell it. To have your analytics data deleted, delete your account or contact us — see "Your rights" below.

Advertising measurement

When we advertise Fibe, we need to know which ads actually bring people to the app. To measure that, our mobile app includes Meta's app measurement SDK and shares a limited set of app events with Meta Platforms: app installs and opens, when you view a product, when you complete setup, and purchases (including the amount and currency).

These events are tied to an anonymous, install-scoped identifier generated by Meta — not to your name, your email, your reference photos, or the outfit images we generate for you. On iOS, the app presents Apple's "Allow tracking" prompt once, early in setup. If you allow it, Meta also receives your device advertising identifier (IDFA), which lets it link your Fibe activity to the ad that brought you here and measure our campaigns person-by-person. If you decline — or dismiss the prompt — no IDFA is collected, Meta cannot link your Fibe activity to your activity in other companies' apps, and measurement falls back to Apple's privacy-preserving SKAdNetwork and Meta's aggregated measurement. The app works identically either way, and you can change your answer at any time in iOS Settings → Privacy & Security → Tracking.

Purchase events are sent to Meta from our payments provider's servers rather than from your device. Meta processes this data as an independent controller under the Meta Privacy Policy, outside the UAE. You can limit ad personalisation in your Meta account settings, and iOS Settings → Privacy & Security → Tracking lets you refuse app tracking device-wide.

Our website (fibeapp.com) also uses the Meta Pixel for the same purpose: it records that the page was viewed and that a download button was clicked, using a cookie set by Meta in your browser. It does not see anything you type and there is nothing to type on the page — no account, no photos, no personal content exists on the website. Meta processes pixel data as an independent controller under the same policy linked above; you can limit how Meta uses it in your Meta ad settings, or block the pixel entirely with a content blocker.

Your rights

You can at any time:

To exercise any of these rights, email privacy@fibeapp.com.

Retention

We keep your account data while your account is active. After you delete your account, we retain the minimum required for legal and accounting reasons (usually 30 days for backup expiry, longer where law requires).

Children

Fibe is not intended for users under 18. We do not knowingly collect data from minors.

Changes to this policy

We will email you and update the "Last updated" date if we change this policy materially.

Contact

Privacy questions: privacy@fibeapp.com
General: hello@fibeapp.com