VAELIS.AI VAELIS
VAELIS · PRIVACY

Privacy Policy

Effective 5 August 2026  ·  Version 2.1

This policy explains what data the Vaelis mobile app processes, why, who it is shared with, and what rights you have. It is written to meet the Turkish Personal Data Protection Law (KVKK, No. 6698) and the EU General Data Protection Regulation (GDPR).

01Data controller

Eren Yalçın — Türkiye
Contact: eren@yalcin.ai

Vaelis is operated by an independent developer. All data protection requests go to this address.

02What stays on your device

The following run entirely on your device. No data leaves it for these operations:

  • Photo classification, human and body-pose detection, visual fingerprints (Apple Vision).
  • Garment visual similarity (an on-device CoreML model).
  • Deciding which photos in your library are outfits.
  • Converting calendar event titles into a category.
  • The background-removal cache and your photo files.
  • Your session key, stored in the iOS Keychain.

03Data we process

a. Account data

Email address; a secure derivation of your password (PBKDF2-HMAC-SHA256 — we never store plaintext); your name (optional); if you use Sign in with Apple, the identifier and refresh token Apple issues; account creation and last-seen timestamps. Purpose: creating your account and managing sessions.  Legal basis: performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5/2-c).

Using Vaelis requires an account. Anonymous use has been removed; backing your data up to the cloud and getting it back on a new device depends on it.

b. User content

Photos you upload; wardrobe pieces and their details (name, category, colour, brand, size); saved outfits; journal entries and notes; plans and occasions; your wishlist. Purpose: providing the service and syncing across your devices.  Legal basis: performance of a contract.

c. Style profile

Gender preference; your declared skin, hair and jewellery tones; your silhouette answers; preferred archetypes; colour season; pieces you avoid. Purpose: shaping recommendations around you.  Legal basis: performance of a contract.

You declare this information yourself. Vaelis does not measure your body and performs no biometric identification.

d. AI outputs

Generated analyses, outfit suggestions, verdicts, chat replies, periodic summaries and edited product images, together with the prompt version that produced them. Purpose: showing your history and monitoring quality.  Legal basis: performance of a contract and legitimate interest (service quality).

e. Interaction history

Which suggestion you picked, which you passed, what you marked as worn; style preferences inferred from your chats (for example “dislikes slim legs”). Purpose: improving the accuracy of recommendations over time.  Legal basis: performance of a contract.

f. Usage analytics

Events such as screen opens, feature usage and purchase-funnel steps. These events are sent to our analytics provider PostHog together with your user identifier and your email address. Our analytics are not pseudonymous; they are linked to your account. Purpose: measuring which parts of the product actually work.  Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — you may object at any time.

We do not use advertising identifiers and we do not track you across apps.

g. Crash and error data

Crash location, device model, iOS version, app version, user identifier and a small sample of performance measurements. Your email address is never sent to the crash provider. Purpose: diagnosing failures.  Legal basis: legitimate interest (keeping the service working).

h. Subscription status

Subscription state and transaction identifier (original_transaction_id) from Apple, your plan and its expiry. Purpose: verifying premium access.  Legal basis: performance of a contract.

We never see your payment details (card, billing address); payment is handled entirely by Apple.

04How the AI works

To produce analyses, outfit suggestions, verdicts, chat replies and summaries, we process your photos and text context through OpenAI (United States).

  • We ask for separate consent before your first photo is sent. If you decline, no photo is sent and you can keep using the rest of the app.
  • Data sent through the API is not used to train OpenAI’s models. OpenAI may retain it for a limited period for abuse monitoring.
  • Turning product photos into studio-style images uses the same provider’s image generation model.
  • The context the AI sees consists of your wardrobe, style profile, a weather summary, your plan for the day and your past choices. Your location coordinates, calendar titles and email address are not part of it.

05Search and shopping

When you search for products, your query text is sent through our search provider Serper (United States) to Google search results. Results are cached for up to six hours.

Photo search works as follows: your photo is temporarily written to our server and made reachable for a short time through an unguessable random link (so the search provider can fetch it), then deleted as soon as the search completes. The link is never published or indexed and expires within seconds. Using this feature is optional.

When you follow a product link, that retailer’s own privacy policy applies.

06Location and weather

To tailor suggestions to the weather, we use your approximate location (medium accuracy) if you allow it.

  • Your coordinates are never sent to Vaelis servers. Your device (and the home-screen widget) queries the Open-Meteo weather service directly.
  • Our server only receives a summary such as “12°, partly cloudy” and which hemisphere you are in, used to determine the season.
  • If you decline the permission, the app works without location.

07Calendar

If you allow it, we read only — never write — your calendar events for today and the next three days.

Event titles never leave your device. Each title is reduced on-device to a single category (for example work, dinner, sport) and only that category is sent to our server. You can revoke the permission at any time in iOS Settings.

08Notifications

Morning and evening reminders are local notifications scheduled on your device. We use no remote push infrastructure, so no data is sent to our server for notifications.

09Share links

When you share a card, its content is stored on our server and a publicly accessible link is generated. Anyone who knows the link can view it. Links expire automatically after 90 days. Sharing is entirely your choice.

10Personalisation and profiling

Your choices, feedback and preferences inferred from chat are used to shape your recommendations. This constitutes profiling.

This processing does not produce automated decisions with legal or similarly significant effects for you; it only determines which outfit is suggested. If you wish to object to personalisation, write to us.

11Third-party processors

ProviderWhat is sentLocationPolicy
OpenAIPhotos, style context, chat textUSAopenai.com/policies
CloudflareAll server data (database, photo storage, infrastructure)Global edgecloudflare.com/privacypolicy
SerperSearch queries; temporary image link for photo searchUSAserper.dev
ResendEmail address (verification, password reset)USAresend.com/legal
PostHogEvent records, user identifier, email addressEUposthog.com/privacy
SentryCrash records, user identifierEU (Germany)sentry.io/privacy
Open-MeteoApproximate coordinates (sent directly by your device)EU (Germany)open-meteo.com/en/terms
AppleSubscriptions and purchases; Sign in with AppleApple infrastructureapple.com/legal/privacy

These providers process data only on our behalf and on our instructions. None of them sells your data or uses it for advertising.

12International transfers

As the table shows, some data is transferred outside Türkiye and the EU, in particular to the United States.

Your photos and AI processing rely on your explicit consent. The consent screen shown before your first photo is sent names the services it goes to and the country. If you decline, your photo is not sent and you can keep using the rest of the app. You can withdraw consent at any time from Profile → Account — withdrawal does not undo processing already carried out.

Account, sync and subscription data rely on performance of the contract; we cannot provide the service without these transfers.

In our relationship with providers, the data processing terms and European Commission Standard Contractual Clauses they offer apply.

13Retention

DataRetention
Your wardrobe, outfits, journal, wishlistUntil you delete your account
Your verdict history (LOOK / VERDICT)Most recent 500 records
Your chat historyMost recent 200 conversations
Outfit-of-the-day recordsMost recent 730 days
Session key90 days
Share link90 days
Search result cacheUp to 6 hours
Temporary image used for photo searchDeleted as soon as the search completes
Usage analyticsUp to 12 months
Crash recordsUp to 90 days

The three rows above carry a count cap: the oldest records beyond the cap fall off the cloud. The copy on the device you use is untouched; when you move to a new device, only the records within the cap come down. The rest of your content has no such cap.

When you request deletion, data is removed from production systems immediately. Our database infrastructure keeps disaster-recovery backups allowing point-in-time restore for up to 30 days, so residual traces in backups age out within that window.

14Security

  • All traffic is encrypted with TLS.
  • Passwords are derived with PBKDF2-HMAC-SHA256 using a random salt and 100,000 iterations; plaintext passwords are never stored.
  • Photos are held in object storage and every request is authorisation-checked against the requesting user.
  • The session key is stored in the iOS Keychain on your device.

No system can guarantee absolute security. In the event of a breach we will notify the Turkish Data Protection Authority and affected users without undue delay and within 72 hours at the latest.

15Deleting your account and data

In the app: open Profile → Account and choose Delete account.

Once confirmed, your account, wardrobe, outfits, journal, plans, chats, style profile, interaction history, wishlist, share links and all photos on the server are deleted; your session is revoked; local copies on your device are wiped. This cannot be undone.

The same principle applies to individual deletions: when you delete an outfit or a wardrobe item, its photo is removed from the cloud as well.

16Your rights

Under KVKK Art. 11 and the GDPR you may:

  • Learn whether your personal data is processed and request information about it,
  • Learn whether it has been used for its stated purpose,
  • Have inaccurate or incomplete data corrected,
  • Request erasure or destruction,
  • Object to processing and withdraw your consent,
  • Request a copy of your data in a structured format (portability),
  • Request restriction of processing,
  • Claim compensation for damages you suffer.

Send your request to eren@yalcin.ai; we respond within 30 days at the latest. If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (kvkk.gov.tr) or to the supervisory authority of your EU member state.

17Children

Vaelis is not intended for anyone under 16 and we do not knowingly collect their data. If you believe someone under 16 has uploaded data, write to eren@yalcin.ai and we will delete the account and the data.

18Changes to this policy

When we update this policy we change the effective date and notify you in the app. Where a change broadens the scope of processing, we ask for your consent as well. Earlier versions are available on request.

19Contact

eren@yalcin.ai