On this page
Your photos
The photos you upload are used to generate your color analysis report and any AI styling images you request. Producing those results requires sending the photos to third-party AI providers that process images on our behalf.
We do not use your photos to train our own models, and we do not sell them. We process them only as described in this policy, including with necessary service providers. Uploaded photos and the images generated from them are stored on secure cloud infrastructure for as long as your account exists, so you can return to your reports.
Your privacy settings let you download the available account-data export. To request account deletion, contact support. We manually verify the request, remove account-linked reports and media, and retain only the minimum payment, refund, dispute, and tax records required by law, without an account link where possible.
Photos you upload for a Complete Report purchase are kept only while that purchase is in progress. If the purchase is not completed, we delete them within a few days.
What we collect
When you use Style Look Lab, we collect:
- Your Google account name, email, and profile picture, which support Google sign-in
- The photos you upload and the report images we generate for you
- Your analysis results, credit balance, and purchase history
- Standard web analytics through Google Analytics, including page views, referrer, device and browser type, and approximate country-level location
- Product-usage insights through Microsoft Clarity, including anonymized session replays and heatmaps of mouse movement, clicks, and scrolling; typed input and sensitive fields are masked
Stripe handles payments on its own checkout pages. Style Look Lab never sees or stores your card number. We do not collect precise location, social media accounts, or biometric identifiers; the BIPA section below explains that distinction.
Cookies
We use cookies that keep you signed in and make the product work, along with analytics cookies from Google Analytics and Microsoft Clarity that help us understand how the site is used.
We do not run advertising or cross-site tracking cookies, and we do not sell the information we collect.
Share attribution cookie
When a visitor opens a public report through a share link, we write one HTTP-only
cookie, sll_attr_share_id, to remember the most recent share-link value they arrived
with.
If that value matches a valid share ID and the visitor later creates an account, the cookie lets us credit the original share link as the source of the signup. The person who shared the report can then see which of their links brought new users in.
- In links generated by Style Look Lab, the value is a 10-character base62 share ID.
Style Look Lab does not add a name, email, location, device fingerprint, or other
personal information to it. Do not put personal information in a manually constructed
sparameter. - It is marked HttpOnly, so browser JavaScript cannot read it; SameSite=Lax, so it does not enable cross-site tracking; and Secure, so it is sent only over HTTPS. Only the Style Look Lab server reads it.
- A valid attribution value is deleted as soon as signup completes. Otherwise, the cookie expires 30 days after it is written.
Visitor counting (anonymous hash)
To estimate how many distinct people opened a share link, the server creates a short anonymous fingerprint at view time.
The algorithm combines the visitor's IP address, browser User-Agent, share-event identifier, and a server-side secret salt. The salt is held only in memory, never written to the database, and never committed to source control. The server hashes that combination with SHA-256 and stores only the first 96 bits, represented by 24 hexadecimal characters.
- What we never store: the raw IP address, raw User-Agent, server-side secret salt, or another raw field that could be traced back to a specific person.
- What we store: only the truncated hash. The server-side secret prevents someone with the stored hash alone from testing possible IP and User-Agent combinations offline.
- How it is scoped: the share-event identifier is part of the hash. The same visitor opening two different share links produces two unrelated values, so this mechanism cannot follow a visitor across share links.
California (CCPA) rights
If you reside in California, you have the right to:
- Know what personal information we hold. Your privacy settings provide an account-data export; for another access or correction request, contact Style Look Lab
- Request deletion of your account and associated data by contacting support; we manually verify the request
- Opt out of any "sale" of your data; Style Look Lab does not sell your data
- Exercise these rights without losing access to other available features
Illinois (BIPA) — biometric data
We do not collect or store biometric identifiers. The AI reads color and proportion from a photo to produce style attributes. It does not generate a facial-geometry template or anything designed to identify you from your face.
See the full Biometric Information Policy for what the system does and does not extract.
EU (GDPR)
Style Look Lab is currently focused on the North American market. EU visitors can use the service. The privacy settings provide an account-data export; contact support to request account deletion; for another access or correction request, contact Style Look Lab. We do not run localized EU marketing.
Changes to this policy
The latest version is always posted on this page. The date at the top shows when the policy was last reviewed, so you can tell when it changes.
Contact
For a question about this policy, a privacy request, or help using the account privacy tools, contact Style Look Lab.