Privacy Policy - Radiant Harmony
Last updated: July 16, 2026
1. Introduction
Welcome to Radiant Harmony, currently marketed in app stores as Radiant Harmony StyleUp. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our mobile application, website, and associated services.
Radiant Harmony is the controller of the personal data described in this Privacy Policy. You can contact us or exercise your privacy rights using the contact details in Section 13.
2. Information We Collect
2.1 Personal Information
We may collect the following types of personal information:
- Email address
- Profile information from third-party social media services (if you choose to connect these)
- User-generated content, such as photos you upload for analysis or styling features
- Style selections and prompts you choose to provide for styling features, such as occasion, style vibe, accessories, and optional free-text instructions
- Optional body measurements you choose to provide for style analysis and personalization features, such as height, weight, shoe size, shoulder width, waist measurement, and bone structure
- Device, app, and online identifier information, such as device model, operating system and app version, AppsFlyer install ID, IDFV on iOS, App Set ID on Android, and, only when enhanced campaign measurement is effective, available advertising identifiers
- Network and technical information, such as IP address, IP-derived approximate location, user agent, timestamps, and diagnostic metadata
- Product usage and interaction events when you consent to product analytics
- Install, referrer, and campaign attribution information
- Purchase and subscription information, such as product, receipt, entitlement, trial, renewal, cancellation, and refund status
2.2 Photo and Image Data
Our app uses photos and images for seasonal color analysis, body type analysis, essence analysis, and styling features such as AI-generated outfit ideas. Here's how we handle your image data:
- On-device preparation: When you upload a photo or take a new one within the app, the image may be resized or converted on your device before upload.
- Secure transmission: Image data is transmitted to our servers over HTTPS.
- Server and AI processing: Our backend prepares image data and sends it to the relevant AI provider for analysis, styling recommendations, or outfit generation.
- Temporary cloud storage: Uploaded images may be stored temporarily in secure cloud storage during processing. For Styler, generated outfit images are also stored temporarily so they can be returned to your device.
- Saved copies: If you choose to save an analysis or outfit in the app, the saved copy is stored locally on your device.
We use industry-standard security measures to protect image data during transmission and processing. Access to systems that handle image data is strictly limited and controlled.
2.3 AI-Processed Data
We use third-party artificial intelligence models to analyze your photos, interpret optional measurements and style selections, generate personalized style insights, and create AI-generated outfit previews. Depending on the feature, this may include image-derived attributes, optional measurements, style preferences, and optional free-text prompts. Third-party provider handling is described in Section 6.
2.4 Measurements Data
Our app also offers optional body measurements to improve style analysis and personalization features, including body type analysis, essence analysis, style profile features, and similar styling experiences within the app. These measurements are stored locally on your device as part of your style profile unless you edit or delete them. When you use a feature that relies on measurements, only the measurement fields relevant to that feature and that you provided are securely transmitted to our backend and AI service provider for the sole purpose of generating or improving the requested analysis or recommendations. Our analysis backend is designed to use these measurements during processing and not to intentionally store the measurement values in our analysis databases or object storage after processing. Limited operational logs may retain technical metadata, such as which measurement fields were included, for monitoring and troubleshooting. If we materially change how measurements are used, we will update this Privacy Policy.
3. How We Use Your Information
We use your personal information for the following purposes:
- To provide and maintain our Service
- To personalize your experience and deliver tailored style insights, recommendations, and outfit ideas
- To improve our app and develop new features
- To communicate with you about our Service
- To provide customer support
- To process payments for in-app purchases
- To send you email notifications about app updates and new features, if you've opted in
- To generate and improve style analysis, personalization, and recommendation features using optional measurements you choose to provide
- To understand product usage and improve the app when you consent to product analytics
- To measure which campaigns lead to installs and validated subscriptions through limited install measurement, and to perform enhanced campaign measurement when you consent
- To diagnose crashes, errors, and reliability issues
- To comply with legal obligations
- To protect our website from spam and abuse using Google reCAPTCHA v3
3.1 Email Communications
If you opt-in to receive email notifications, we will use your email address to send you information about our services, including app launch notifications and updates. You can manage your email preferences or opt-out at any time through your account settings or by using the unsubscribe link in our emails.
Marketing email and notification consent is separate from product analytics, limited install measurement, and enhanced campaign measurement. Marketing consent is optional, off by default, and is not required to use the app.
4. Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. Specifically:
- Account information: Retained while your account is active and then only as long as needed to complete deletion, maintain limited backups, protect the service, resolve disputes, and meet legal obligations.
- Product analytics data: Retained only for as long as needed to understand product use, improve the service, maintain security, and honor privacy requests, according to our approved production retention settings.
- Attribution and subscription data: Retained only for as long as needed to measure campaign performance, validate and administer subscriptions, resolve disputes or fraud, meet accounting and legal obligations, and honor privacy requests. Retention is also subject to our approved processor settings and contractual deletion procedures.
- Crash and diagnostic data: Retained only for as long as needed to investigate and resolve reliability or security issues, according to our approved production retention settings.
- Photos, uploaded images, and generated outfit images: Used during processing and may be stored temporarily in secure cloud storage so we can complete the requested feature and deliver the result to your device. If you choose to save an analysis or outfit, the saved copy is stored locally on your device.
- Optional measurements: Stored locally on your device until you update or delete them. When transmitted for style analysis, personalization, or recommendation features that use measurements, they are used during real-time processing and are not intentionally stored in our analysis databases or object storage after processing, although limited operational logs may retain technical metadata for a short period.
You can delete your account and associated personal data directly from the app settings. For detailed instructions, please visit our Account Deletion Instructions. Alternatively, you can contact us at: support[at]radiantharmonyai[dot]com for assistance with data deletion.
4.1 Third-Party Data Retention
Our processors retain personal data for the period configured or instructed by us, subject to limited backup, security, dispute-resolution, and legal retention requirements. We set and review retention by considering the purpose of the processing, the sensitivity of the data, the time needed to investigate issues and honor rights requests, and applicable contractual and legal obligations. Contact us if you want information about, access to, or deletion of processor-held data associated with you.
5. Privacy-Aware Analytics System
In the mobile app, product analytics and enhanced campaign measurement are separate, optional choices and remain off until you choose them. Limited install measurement is a distinct baseline purpose that starts at app startup for every installation, before the two optional onboarding choices. It is not an in-app choice and cannot be disabled in Settings. Core app functionality is not conditioned on granting either optional consent. Website analytics is a separate choice managed through the website's cookie banner.
5.1 Product Analytics (PostHog)
Mobile App Product Analytics
Product analytics is off until you expressly consent. When enabled, PostHog receives a fixed set of app and onboarding interactions, feature-use events, paywall and purchase-flow events, app version, build, platform, environment, user tier, trial state, and event-specific properties. For signed-in users, we use the Cognito subject ID as the analytics identifier.
We do not send PostHog your name, email address, photos, image paths, prompts, measurements, analysis results, authentication tokens, raw error messages, or client-side purchase revenue. Automatic screen and touch capture, automatic lifecycle events, session replay, and PostHog performance and error capture are disabled in the app. Network information, including IP address and IP-derived approximate location, may still be processed depending on our production PostHog project settings.
You can withdraw product analytics consent at any time in the app's privacy settings. This stops future product events and resets the local PostHog identity. It does not automatically erase historical events; you can contact us to exercise access or deletion rights.
Website Analytics
Website analytics is off unless you accept analytics through the website's cookie banner. When enabled, PostHog receives page-view events and interactions with selected website calls to action, including the page path, page language, the name and placement of the selected call to action, and its destination. PostHog may also process a browser analytics identifier and standard technical and network information, such as browser and device information, IP address, and potentially IP-derived approximate location.
The website does not use PostHog to identify you with your Radiant Harmony account, name, or email address. Automatic interaction capture, automatic page-view and page-leave capture, session replay, heatmaps, and performance capture are disabled; the website sends only the page views and selected call-to-action events described above. Your website analytics choice and PostHog browser state are stored in your browser's local storage. You can withdraw website analytics consent by clearing the site's stored data and choosing "Reject" when the cookie banner is shown again. This stops future website analytics but does not automatically erase historical events; you can contact us to exercise access or deletion rights.
5.2 Limited Install Measurement (AppsFlyer and RevenueCat)
Limited install measurement starts when the app starts so we can connect an install or campaign source to validated trials, subscriptions, renewals, and other configured subscription lifecycle events. We rely on our legitimate interest in evaluating paid acquisition, avoiding materially wasteful advertising spend, and supporting the service. This purpose is separate from product analytics and is not used to personalize app features or build cross-app advertising profiles.
In limited mode, the app does not send AppsFlyer the Radiant Harmony account identifier and disables collection of IDFA, GAID, OAID, and Amazon Advertising ID. Limited mode is not anonymous. AppsFlyer creates a per-install AppsFlyer ID and may process IP address and IP-derived approximate location, user agent, timestamps, install, referrer and campaign information, standard device/app/OS metadata, and platform identifiers such as IDFV on iOS or App Set ID on Android where available.
We send the AppsFlyer ID to RevenueCat. RevenueCat then sends configured, server-validated subscription lifecycle and revenue events to AppsFlyer so those events can be attributed to an install or campaign. The mobile client does not send purchase revenue events directly to AppsFlyer. In limited mode, the app blocks advertising-partner sharing through both AppsFlyer and RevenueCat.
Limited install measurement is not an in-app choice and has no Settings toggle or stored consent or objection preference. To exercise applicable access, deletion, restriction, or objection rights concerning this processing, contact us using Section 13. We will authenticate the request and use the relevant backend or processor workflow to handle AppsFlyer records and RevenueCat attribution attributes.
5.3 Enhanced Campaign Measurement (AppsFlyer and RevenueCat)
Enhanced campaign measurement is off until you expressly consent. When effective, it may additionally use available advertising identifiers, link attribution to your Cognito subject ID as the AppsFlyer Customer User ID, allow sharing with dashboard-approved campaign partners, and ask RevenueCat to collect applicable device identifiers for attribution. Names, email addresses, photos, prompts, measurements, and analysis results are not supplied for attribution.
On iOS, enhanced campaign measurement becomes effective only when App Tracking Transparency permission is authorized. If permission is denied or restricted, measurement remains limited. You may withdraw enhanced consent in the app's privacy settings. This disables future advertising-identifier collection, clears the AppsFlyer Customer User ID, restores partner-sharing restrictions, and returns measurement to limited mode. Withdrawing enhanced consent does not disable limited install measurement.
Advertising-Network and Campaign Partners
At the time this version of the Privacy Policy was published, no advertising-network or campaign partner was active in AppsFlyer. AppsFlyer and RevenueCat processed attribution and subscription data for us as service providers, but no advertising network received user-level attribution, event, or subscription data through an AppsFlyer partner integration.
We may activate advertising-network or campaign partners from time to time to attribute installs or events, measure and optimize campaigns, prevent advertising fraud, and produce campaign reporting. Partner sharing will remain blocked in limited mode. Where enhanced campaign measurement is effective, an activated partner may receive only the data configured for that integration, such as advertising, device, AppsFlyer, or campaign-specific identifiers; install, app-launch, re-engagement, and specifically mapped in-app events; campaign, referrer, timestamp, and standard device, app, or operating-system information; country or approximate location derived from network information; and, only when specifically mapped, subscription or revenue events and the AppsFlyer Customer User ID.
We do not provide campaign partners with your email address, photos, prompts, measurements, analysis results, full payment details, or other data outside the purposes and categories described above. Depending on its role and how it uses permitted data, a campaign partner may act as our service provider or as an independent controller under its own privacy policy. We may add or change campaign partners without updating this Privacy Policy where the processing remains within this description and the applicable consent controls. We will update this Privacy Policy and applicable app-store disclosures before materially changing the purposes, data categories, or controls described here where required. Activating a campaign partner does not place third-party advertisements inside the Radiant Harmony app.
5.4 Historical Data and Your Choices
Product analytics, enhanced campaign measurement, marketing communications, and baseline limited install measurement are separate purposes. Product analytics, enhanced measurement, and marketing communications have optional controls; limited install measurement does not. Withdrawing an optional choice stops the corresponding future optional collection but does not disable baseline measurement or by itself erase records already held by our processors. Some RevenueCat attribution and device attributes cannot be changed from the mobile client after they are first stored. Contact us using Section 13 so we can authenticate and process an applicable access, restriction, objection, or deletion request through the relevant backend and processor tools.
6. Sharing Your Information
6.1 Overview of Third-Party Services
We partner with several third-party services to provide our app's functionality. Each service receives only the minimum necessary data to perform its specific function:
For transparency, this section describes data transmitted to service providers as well as data that may be disclosed to independent third parties. A transfer to a service provider that processes data only for us and under our instructions is different from disclosure to an advertising-network partner for that partner's own campaign-measurement or optimization activities. At the time this version was published, no advertising-network partner was active in AppsFlyer. The future-partner rules in Section 5.3 apply if we activate one later.
Authentication Services (AWS Cognito)
- Data shared:
- Email address
- Authentication tokens
- Device identifiers
- Purpose: To manage user accounts and secure access to the app
- Data retention: For the life of the account and then only as long as needed to complete deletion, maintain limited backups, protect the service, and meet legal obligations
- Privacy policy: AWS Privacy Notice
Email Service Provider (SMTP2GO)
- Data shared:
- Email address
- Email subject lines
- Email content (for transactional emails like verification codes)
- Email headers
- Purpose: To deliver transactional emails (account verification, password resets) and potential future marketing communications
- Data handling:
- Emails are transmitted using TLS encryption
- Email headers and basic information are stored with encryption at rest using AES-256
- Full email content is not stored by default unless email archiving is enabled
- Data retention: Delivery records and message metadata are retained only as long as needed to deliver and troubleshoot messages, handle suppression and unsubscribe requests, maintain security, and meet legal obligations
- Privacy policy: SMTP2GO Privacy Policy
AI Processing (Google)
- Data shared:
- Language selection
- Processed image data
- Style selections and optional free-text prompts used for styling features
- Optional body measurements for style analysis and personalization features, when you choose to provide them
- Purpose: To provide AI-powered style analysis, personalized styling recommendations, and AI-generated outfit images
- Data handling:
- Optional measurements are shared only when you request a feature that uses them for analysis or recommendations
- Data is processed in accordance with Google's Data Processing Addendum
- Prompts and responses are logged for a limited time only for detecting violations of the Prohibited Use Policy
- No data is used to improve Google's products
- Data retention: Limited period for compliance monitoring
- Privacy policy: Google Privacy Policy
AI Processing (Anthropic)
- Data shared:
- Language selection
- Processed image data
- Purpose: To provide premium seasonal color analysis
- Data handling:
- Inputs and outputs are retained only as long as needed to provide the requested feature and for any applicable safety, abuse-prevention, security, or legal requirements under our production terms
- Data may be retained longer if flagged for policy or legal review
- Data retention: Based on the processing purpose and our approved production provider terms and settings
- Privacy policy: Anthropic Privacy Policy
Social Login Providers
- Google Sign-In
- Data shared: Email address and basic profile information
- Purpose: To enable Google account login
- Privacy policy: Google Privacy Policy
- Facebook Login
- Data shared: Email address and basic profile information
- Purpose: To enable Facebook account login
- Privacy policy: Meta Privacy Policy
Google reCAPTCHA v3
- Data shared:
- Hardware and software information
- Device information
- Date and duration of visits
- Mouse movements and touches
- Browser language
- IP address
- Purpose: To protect our website from spam and abuse
- Data handling: Automated background verification of user interactions
- Privacy policy: Google Privacy Policy
- Terms of Service: Google Terms of Service
Product Analytics (PostHog)
- Data shared:
- Cognito subject ID for signed-in, consented users
- Fixed, allowlisted product interaction events and event-specific properties
- App version, build, platform, environment, user tier, and trial state
- On the website after consent: page views, selected call-to-action interactions, page path and language, and the call-to-action name, placement, and destination
- Network information, including IP address and potentially IP-derived approximate location, depending on the production project configuration
- Purpose: To understand product use and improve the app and website after you consent to the applicable analytics
- Data handling:
- The app does not send names or email addresses, whether hashed or unhashed
- Photos, prompts, measurements, analysis results, authentication tokens, raw errors, and client-side purchase revenue are excluded
- Automatic screen/touch capture, automatic lifecycle events, session replay, and PostHog performance/error capture are disabled
- The mobile app uses PostHog's EU ingestion endpoint in production
- You can grant or withdraw product analytics consent at any time in the app's privacy settings
- Website analytics loads only after you accept it through the website's cookie banner; automatic interaction capture, page-view capture, page-leave capture, session replay, heatmaps, and performance capture are disabled
- Legal basis: Consent
- Data retention: Only as long as needed for product analysis, service improvement, security, and privacy-request handling under our approved production settings
- Privacy policy: PostHog Privacy Policy
Install Attribution and Campaign Measurement (AppsFlyer)
- Data shared:
- AppsFlyer per-install ID
- IDFV on iOS and App Set ID on Android where available
- IP address and IP-derived approximate location, user agent, timestamps, and standard device/app/OS metadata
- Install, referrer, and campaign metadata
- Configured subscription lifecycle and revenue events sent by RevenueCat server-to-server
- Available advertising identifiers and Cognito subject ID only when enhanced campaign measurement is effective
- Purpose: To connect campaign sources to installs and validated subscription outcomes and evaluate acquisition effectiveness
- Data handling:
- Limited mode begins by default and does not use the Radiant Harmony account ID, IDFA, GAID, OAID, or Amazon Advertising ID
- Limited mode remains linkable at the installation level and must not be understood as anonymous
- Advertising-partner sharing is blocked in limited mode
- Enhanced mode is based on consent and may add advertising identifiers, Cognito subject ID linkage, and sharing with approved campaign partners; on iOS it is effective only after ATT authorization
- No advertising-network partner was active at the time this version was published; partners may be activated for the purposes, data categories, and consent controls described in Section 5.3
- Limited measurement has no in-app Settings control; privacy-rights requests are handled through the authenticated contact and processor workflow described in Sections 5.4, 7.3, and 13
- You can withdraw enhanced consent in the app's privacy settings; measurement then returns to limited mode
- Legal basis: Legitimate interests for limited install measurement; consent for enhanced campaign measurement
- Data retention: Only as long as needed to measure campaign performance, investigate attribution issues, honor privacy requests, and meet contractual or legal obligations under our approved production settings
- Privacy information: AppsFlyer Privacy Policy and AppsFlyer Data Processing Addendum
Subscription Operations and Attribution (RevenueCat)
- Data shared:
- Cognito subject ID as the RevenueCat App User ID
- App, store, and product identifiers
- Purchase receipts and subscription, entitlement, trial, renewal, cancellation, and refund status
- SDK, device, and network technical metadata
- AppsFlyer ID when limited or enhanced attribution is active
- Additional device and advertising identifiers only when collection is explicitly requested after enhanced campaign measurement becomes effective
- Purpose: To display subscription offerings, process and restore purchases, validate entitlements, administer subscription lifecycle events, and support server-to-server attribution
- Data handling:
- Apple App Store or Google Play processes payment credentials; neither Radiant Harmony nor RevenueCat receives your full card details
- Automatic attribution-network device identifier collection is disabled in the app's RevenueCat configuration
- The AppsFlyer ID is synchronized for limited or enhanced attribution, and configured subscription lifecycle and revenue events are sent from RevenueCat to AppsFlyer server-to-server
- Some attribution and device attributes cannot be changed by the mobile client after first storage; historical access or deletion must use our authenticated processor workflow
- Legal basis: Performance of our contract with you and applicable legal obligations for subscription operations; the attribution basis described above for attribution data
- Data retention: Only as long as needed to provide and verify subscriptions, maintain financial and entitlement records, resolve disputes or fraud, honor privacy requests, and meet contractual or legal obligations
- Privacy information: RevenueCat Privacy Policy and RevenueCat Data Processing Addendum
Error Monitoring Service (Sentry)
- Data shared:
- Error details and stack traces
- Device type and operating system version
- App version
- Crash identifiers
- Navigation and manually added network or WebSocket breadcrumbs
- Possible user agent, inferred IP address, request URL and query string, and console or breadcrumb context
- Data handling:
- The app sets
sendDefaultPiito false and does not explicitly identify the signed-in user to Sentry - Depending on the production project and relay configuration, Sentry may still infer an IP address and receive enabled request, URL, query-string, console, or breadcrumb context
- Session replay, screenshots, performance traces, automatic performance tracing, and automatic session tracking are disabled in app code
- Data is used solely for identifying and fixing technical issues
- Error reports are automatically collected when crashes or errors occur
- The app sets
- Legal basis: Our legitimate interest in maintaining a reliable and secure service and, where applicable, performance of our contract with you
- Data retention: Only as long as needed to investigate and resolve reliability or security issues and honor privacy requests under our approved production settings
- Privacy policy: Sentry Privacy Policy
6.2 Data Sharing Principles
- We share only the minimum necessary data required for each service to function
- All data sharing is conducted over encrypted connections
- We regularly review our third-party partnerships to ensure compliance with our privacy standards
- We do not sell your personal information to third parties
- We do not allow advertising-network partner sharing in limited install measurement
- If an advertising-network partner is activated, sharing is limited to effective enhanced campaign measurement and the approved data and event mappings described in Section 5.3
6.3 Legal Requirements
We may disclose your information if required by law, in response to legal processes, or to protect our rights and the rights of others. In such cases, we will:
- Notify users when possible (unless legally prohibited)
- Limit the data shared to what is legally required
- Review all legal requests for validity
6.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice in our app of any change in ownership or uses of your personal information.
6.5 Payment Processing
We use RevenueCat to manage in-app purchases, subscriptions, and entitlements. When you make a purchase:
- Your payment information is processed securely through Google Play or Apple App Store
- We do not store your payment details directly
- Purchase history and subscription status are managed through RevenueCat
- You can manage your subscriptions through your device's settings or the respective app store
7. Your Privacy Rights
7.1 GDPR Rights (for EEA users)
Under the General Data Protection Regulation (GDPR), users in the European Economic Area have the following rights:
- Right to access your personal data
- Right to rectify inaccurate personal data
- Right to erase your personal data
- Right to restrict processing of your personal data
- Right to data portability
- Right to object to processing of your personal data
- Right to withdraw consent at any time
7.2 California Privacy Rights (CPRA)
California residents have additional rights under the California Privacy Rights Act (CPRA), including:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale or sharing of personal information
- Right to non-discrimination for exercising CPRA rights
7.3 Exercising Your Rights
To exercise any of these rights, please contact us at: support[at]radiantharmonyai[dot]com We will respond to your request within 30 days.
For requests involving limited install measurement or attribution records, please provide enough information for us to authenticate your request and identify the relevant installation or account records. We will use our backend and the applicable AppsFlyer or RevenueCat processor tools to handle valid access, restriction, objection, or deletion requests. Changing an optional analytics or enhanced-measurement setting does not itself delete historical attribution records.
7.4 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data infringes on data protection laws. For users in the European Union, you can find a list of supervisory authorities here.
8. Legal Bases for Processing
We process your personal data on the following legal bases:
- Consent: For product analytics, enhanced campaign measurement, and optional marketing communications. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
- Contract: To create and secure your account, provide requested analyses and styling features, process and restore purchases, validate entitlements, provide support, and otherwise deliver the service you request.
- Legitimate Interests: For limited install measurement, preventing materially wasteful advertising spend, maintaining and improving service reliability and security, preventing abuse, and understanding service performance where those interests are not overridden by your rights and freedoms. You may object to processing based on legitimate interests.
- Legal Obligation: To comply with applicable laws and regulations.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication measures
- Employee training on data protection and security
While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
10. Children's Privacy
Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe we may have collected information about a child, please contact us immediately.
11. International Data Transfers
Some service providers and their subprocessors, including AppsFlyer, RevenueCat, PostHog, Sentry, AWS, our email provider, and our AI providers, may process personal data in countries other than the country where you live. These providers process data for us under applicable contracts and data-processing terms.
Where personal data is transferred outside the European Economic Area, United Kingdom, or another jurisdiction that restricts international transfers, we use an applicable lawful transfer mechanism, such as an adequacy decision or approved Standard Contractual Clauses, together with supplementary safeguards where required. You may contact us for more information about safeguards relevant to your personal data.
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide a more prominent notice, which may include an email notification to users who have opted in to communications.
We encourage you to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
13. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Data controller: Radiant Harmony
- Email: support[at]radiantharmonyai[dot]com
14. Cookie Policy
Our application and website use cookies and similar technologies. For detailed information about the types of cookies we use, how we use them, and how you can manage your preferences, please see our separate Cookie Policy.
15. Local Storage
15.1 Website Local Storage
Our website uses local storage, a web storage technology built into your browser, to remember your language preference and cookie-banner choice. If you accept website analytics, PostHog also uses local storage to maintain browser analytics state and begins receiving website analytics events and associated technical information as described in Section 5.1.
You can clear these records through your browser's site-data settings. Clearing them removes your saved language and consent choices and causes the cookie banner to be shown again. Clearing local storage stops use of the locally stored analytics state but does not automatically delete historical events already held by PostHog; contact us if you wish to exercise applicable access or deletion rights.
15.2 Mobile App Local Storage
Our mobile application uses device storage, including AsyncStorage, to keep preferences, versioned product-analytics and enhanced-measurement consent records, usage state, and user-selected saved analysis or outfit results. Limited install measurement has no stored consent or objection preference.
These local records remain on your device unless a feature requires synchronization or transmission as described in this Privacy Policy. In particular, photos, optional measurements, style selections, prompts, and other feature inputs are transmitted when you request cloud analysis or generation. Product analytics events and attribution identifiers are transmitted only according to the separate controls described in Section 5. You can remove local data by using available in-app deletion controls, clearing app data, or uninstalling the app, but doing so does not automatically delete records already held by our servers or processors.
16. Version History
July 16, 2026: Analytics, attribution, diagnostics, and storage update:
- Replaced the former two-tier analytics description with separate product analytics, enhanced campaign measurement, and limited install measurement purposes
- Documented automatic limited AppsFlyer measurement for every installation, its legitimate-interest basis, data categories, lack of an in-app toggle, and privacy-rights request process
- Clarified consent-based PostHog product analytics and enhanced AppsFlyer campaign measurement, including iOS ATT dependency
- Expanded RevenueCat subscription and server-to-server attribution disclosures and explained historical deletion limits
- Corrected Sentry diagnostic-data and IP-address disclosures
- Removed disclosures for advertising and analytics services that are not part of the current mobile runtime
- Added website PostHog analytics and browser local-storage disclosures and updated mobile local-storage and processor-retention descriptions
- Recorded that no advertising-network partner was active in AppsFlyer when this version was published and disclosed the purposes, data categories, and controls that apply if campaign partners are activated later
- Confirmed that limited-mode partner sharing remains blocked and that email addresses, photos, prompts, measurements, analysis results, and full payment details are excluded
March 15, 2026: Style-focused privacy policy update:
- Updated the policy to reflect Radiant Harmony's broader style-focused product positioning, including current app store branding as Radiant Harmony StyleUp
- Expanded data collection disclosures to cover style selections, optional prompts, and optional measurements
- Updated image and AI processing sections to cover seasonal, body type, essence, and Styler features
- Clarified temporary cloud storage for uploaded images and Styler-generated outfit images during processing
- Refined third-party AI provider descriptions to better match current analysis and styling workflows
July 17, 2025: Analytics and marketing measurement update:
- Added AppsFlyer as Mobile Measurement Partner for install attribution and marketing campaigns
- Documented the analytics and attribution model used at that time; this model was superseded by the July 16, 2026 update
- Added details about RevenueCat Server-to-Server integration for revenue tracking
- Enhanced privacy controls with immediate opt-out capabilities
April 2, 2025: Payment processing update:
- Added detailed RevenueCat information for in-app purchases and subscriptions
- Added specific subscription information requirements
- Updated payment processing section with more detailed information
March 7, 2025: Email service provider update:
- Added SMTP2GO as email service provider
- Specified EU data location for GDPR compliance
- Added detailed information about email data handling
February 15, 2025: AI processing and third-party services update:
- Added detailed information about Google AI data processing
- Updated Anthropic AI data retention policies
- Added detailed information about PostHog
- Added detailed information about Sentry
- Improved transparency on third-party data processing
December 31, 2024: Major restructuring of privacy policy:
- Removed in-app purchases section (to be added when feature launches)
- Removed automated decision-making and profiling section (not applicable to current app functionality)
- Consolidated all third-party service information into Section 5 (previously 6)
- Added comprehensive details about data sharing with each service provider
- Added detailed information about reCAPTCHA v3 data handling
- Improved clarity on advertising opt-out procedures
- Updated local storage section to accurately reflect app's data storage practices
- Simplified cookie policy section to avoid duplication
- Removed redundant cookie choices section
- Reorganized document structure
September 21, 2024: Cookie consent and language preferences update:
- Updated to include information about the cookie consent banner
- Added user choices regarding cookies
- Clarified the use of local storage for language preferences
- Removed language preference from cookie policy
September 12, 2024: Google reCAPTCHA update:
- Updated to include information about Google reCAPTCHA v3 usage
- Added details about data collection and processing
September 06, 2024: Feature and compliance update:
- Added sections on in-app purchases
- Added legal bases for processing
- Added automated decision-making
- Expanded information on email communications
- Enhanced user rights section
September 05, 2024: Major revision:
- Complete rewrite for user-friendliness
- Enhanced compliance with current regulations
- Improved document structure and clarity
August 20, 2024: Initial release
17. Language
This Privacy Policy has been prepared in English. Translations into other languages are provided for convenience only. In the event of any conflict or discrepancy between the English version and a translated version, the English version shall prevail.
The authoritative English version of this Privacy Policy can be found at: https://www.radiantharmonyai.com/en/privacy-policy/