Privacy Notice

Effective 30 June 2026
Abuse / takedown contact
abuse@tryreflecta.app

1. Introduction

This Privacy Notice explains how REFLECTA LABS SOFTWARE TRADING L.L.C (“Reflecta”, “we”, “us”, “our”) collects, uses, stores, discloses, transfers and otherwise processes Personal Data when you access or use Reflecta’s website, iOS mobile application, software, Account, Workspace, AI-powered creative generation tools, image generation tools, image editing tools, asset libraries, billing features, support channels and related services (together, the “Services”).

Reflecta is an AI-powered creative generation platform with private user workspaces. The Services allow users to upload or select visual assets, create and manage workspaces, use platform-provided materials, and generate visual Outputs using AI-powered tools. User Content is processed within the user’s own Account or Workspace. Reflecta does not operate a public social network, public feed or public in-app user-to-user content platform.

This Privacy Notice applies to both the Reflecta website and the Reflecta iOS application.

This Privacy Notice should be read together with:

By “Personal Data” we mean information relating to an identified or identifiable natural person, or information otherwise treated as personal information, personal data or personally identifiable information under applicable data protection laws.

This Privacy Notice does not apply to third-party websites, App Marketplaces, payment processors or services that are not controlled by Reflecta, except where this Privacy Notice expressly states otherwise.

2. Controller Details

For the purposes of applicable data protection laws, the controller of your Personal Data is:

Controller
REFLECTA LABS SOFTWARE TRADING L.L.C
Legal form
Limited Liability Company - Single Owner (LLC - SO)
Commercial Licence No.
1606456
Commercial Register No.
2819318
DCCI Membership No.
674950
Licensed activity
Computer Systems & Communication Equipment Software Trading
Licensed / registered address
Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates
Official licence email / legal contact
legal@tryreflecta.app
Abuse / takedown contact
abuse@tryreflecta.app

3. Definitions

Capitalised terms used in this Privacy Notice have the meanings below, unless the context requires otherwise.

Account
means a user account registered with Reflecta.
AI Features
means AI-powered generation, editing, styling and transformation tools made available through the Services, including tools that generate fashion, product, editorial, marketing-style or other visual Outputs using User Assets, Platform Assets, prompts, styles, products, collections, settings and other inputs.
AI Infrastructure Provider
means a third-party provider used by Reflecta to process inputs, prompts, images, generation parameters or other data to provide AI-powered functionality.
App Marketplace
means Apple App Store or any other digital marketplace through which the Services may be distributed from time to time.
Apple IAP
means Apple In-App Purchase and related Apple payment infrastructure used for purchases made inside the iOS application.
Assets
means User Assets and Platform Assets collectively.
Content
means User Content, prompts, Assets and Outputs collectively, unless the context requires otherwise.
Credits
means credits, tokens, allowances or similar digital units that may be used within the Services to access or redeem eligible AI Features, generation requests, exports or other digital functionality.
Output or Outputs
means images or other content generated, edited or transformed by the Services based on User Assets, Platform Assets, prompts or other inputs.
Paid Services
means subscriptions, Credits, premium features, paid digital functionality, credit packs, enhanced Outputs, high-resolution exports, business plans or other paid offerings made available through the Services.
Person / Model Asset
means an image or reference representing a human person, model, persona, likeness or identifiable individual that is uploaded, selected or used as a visual reference in the Services. A Person / Model Asset is not an AI model.
Personal Data
means information relating to an identified or identifiable natural person, or information otherwise treated as personal information, personal data or personally identifiable information under applicable data protection law.
Platform Asset
means any asset, template, style, scene, product, collection, sample prompt, preset, reference material, model image, setting or other content made available by Reflecta within the Services.
Reflecta Content
means the Services and all software, AI systems, workflows, interfaces, designs, text, graphics, images, examples, templates, Platform Assets, styles, scenes, products, collections, presets, documentation, trademarks, trade names, service marks, logos, slogans and other content made available by Reflecta.
Services
means the Reflecta platform, including the Reflecta website, iOS mobile application, software, AI Features, account workspaces, content libraries, billing features, support channels and related services.
Subscription
means a recurring paid plan that provides access to specified Paid Services for a subscription period, subject to the Reflecta Terms of Use and any disclosures presented at purchase.
User Asset
means any image, product photograph, person/model reference, setting or scene reference, text, prompt, tag, description, collection, product reference or other material uploaded, created, selected, stored or submitted by you through the Services.
User Content
means any User Asset, prompt, photo, image, text, metadata, tag, description, communication, report or other material that you upload, submit, transmit, create, select or otherwise provide to the Services.
Workspace
means an account environment, workspace, organization profile or team space associated with an individual user or business user for managing subscriptions, Credits, Assets, Outputs and related settings.

4. Age Restriction

The Services are intended only for users who are at least 18 years old and have reached the age of majority in their jurisdiction of residence.

You must not create an Account, upload Assets, generate Outputs, purchase Paid Services, use AI Features or otherwise use the Services if you are under 18 or have not reached the age of majority in your jurisdiction.

We do not knowingly collect Personal Data from children or minors. If we become aware that we have collected Personal Data from a person who is not eligible to use the Services, we will take reasonable steps to delete such data and close the relevant Account.

You must not upload images of minors. You must never upload, generate, request, store, share or attempt to generate sexual, exploitative, harmful, abusive, age-inappropriate or unlawful content involving minors.

5. Summary of Our Privacy Position

Reflecta’s privacy approach is based on the following principles:

  • We process your data to provide, operate, secure and support the Services.
  • We process uploaded images as visual assets and reference inputs for AI generation.
  • We do not provide a facial recognition service.
  • We do not use uploaded images to identify you, authenticate you, verify your identity, compare you with other users, search for you or create a facial recognition database.
  • We do not create or store biometric templates, face IDs, liveness profiles or identity verification records.
  • We do not use your uploaded images or generated Outputs to train Reflecta’s general AI models unless you explicitly opt in to a separate programme.
  • We do not sell your Personal Data.
  • We do not share your uploaded images, generated Outputs or Account data with third parties for their own marketing purposes.
  • We do not use advertising cookies, behavioural tracking cookies, third-party marketing pixels or analytics cookies at launch.
  • We use service providers only where necessary to operate, host, secure, support, bill for and provide the Services.

6. Personal Data We Collect

We collect Personal Data directly from you, automatically when you use the Services, and from service providers such as App Marketplaces, payment processors and authentication providers.

The categories of Personal Data we collect depend on how you use the Services.

6.1 Account and Login Data

We collect and process Account and login data, which may include:

  • name, if provided;
  • email address;
  • Account ID;
  • password hash;
  • authentication tokens;
  • session identifiers;
  • email verification codes;
  • password reset codes;
  • login status;
  • device/browser session information;
  • IP address where captured for session, infrastructure or security purposes.

We do not store your password in plain text. Passwords are stored in hashed form.

We use this data to create and manage your Account, authenticate you, keep you logged in, verify your email address, reset your password, protect the Services and prevent unauthorised access.

6.2 Workspace and Organization Data

The Services use a Workspace or organization structure. Depending on how you register and use the Services, we may collect and process:

  • Workspace name;
  • organization name;
  • role or access level within a Workspace;
  • Subscription tier;
  • Credits balance;
  • internal organization ID;
  • Stripe customer ID, where payment is made through the website;
  • Apple subscription or transaction identifiers, where payment is made through the iOS application.

An individual user may also have an automatically created Workspace or organization for technical account-management purposes. Providing an organization name may indicate business use of the Services.

6.3 Uploaded Assets and User Content

When you use the Services, you may upload, submit, select or create Content. This may include:

  • photos and images;
  • product images;
  • Person / Model Assets;
  • setting, background or scene images;
  • prompts;
  • style selections;
  • product, setting, model or collection selections;
  • tags;
  • titles;
  • descriptions;
  • metadata associated with uploaded or generated Content;
  • generated Outputs.

We refer to materials uploaded or submitted by you as User Content or User Assets. Assets may be categorised within the Services as Product, Person / Model, Setting or other asset types.

6.4 Platform Assets and Platform-Provided Materials

The Services may include Platform Assets, such as Discover materials, styles, products, collections, model images, settings, presets, templates or other creative references.

When you interact with Platform Assets, we may process metadata about your selection and use of those Platform Assets to provide the requested functionality and manage your Workspace or library.

6.5 Image Processing Data

When you upload images or use AI Features, we process images and related technical information to provide the requested Output. This may include:

  • uploaded image files;
  • generated image files;
  • image metadata;
  • prompts and generation parameters;
  • text descriptions generated from images for interface and asset-management purposes;
  • technical information required to generate, store, display, retrieve or delete images;
  • safety-filtering signals;
  • temporary processing data transmitted to AI Infrastructure Providers.

Reflecta does not use this processing to identify you as a person, verify your identity or compare you to other users.

6.6 Payments, Subscriptions and Credits

If you purchase a Subscription, Credits or other Paid Services, we may collect and process:

  • Subscription status;
  • payment channel;
  • Subscription tier;
  • renewal status;
  • purchase confirmation;
  • receipt metadata;
  • Credits issued, used or expired;
  • transaction timestamps;
  • Stripe customer ID for web purchases;
  • Apple transaction or subscription identifiers for iOS purchases.

We do not store full payment card numbers. Card and payment details are processed by Apple, Stripe or another payment provider, depending on the payment channel.

6.7 Support, Legal, Abuse and Communications Data

If you contact us, report an issue, submit an abuse or takedown complaint, make a privacy request, appeal an enforcement decision or communicate with us, we may collect:

  • your email address;
  • your name, if provided;
  • message content;
  • support request details;
  • complaint or report details;
  • appeal details;
  • attachments you provide;
  • internal support or review notes;
  • status of the request;
  • dates and times of communications.

6.8 Technical Logs and Security Data

When you use the Services, we and our service providers may process limited technical data, including:

  • request metadata;
  • timestamps;
  • API request status;
  • response times;
  • error codes;
  • session information;
  • IP address where captured for login, security, infrastructure or crash-reporting purposes;
  • device type;
  • browser type;
  • operating system;
  • app version;
  • crash logs;
  • stack traces.

Technical logs do not intentionally include uploaded images, generated Outputs or prompts.

6.9 Crash Reports

We use crash-reporting and error-monitoring tools to detect and fix errors. Crash reports may include:

  • app version;
  • operating system version;
  • device type;
  • stack trace;
  • error details;
  • time of crash;
  • IP address if automatically collected by the crash-reporting provider.

Crash reports are not intended to contain uploaded images, prompts or generated Outputs.

6.10 Data from Third Parties

We may receive limited Personal Data from third parties, including:

  • Apple, where you use the iOS application or make an Apple IAP purchase;
  • Stripe, where you purchase through the website;
  • authentication providers, where third-party sign-in is supported;
  • AI Infrastructure Providers, where processing status or technical data is returned;
  • support, security, email or infrastructure service providers.

7. What We Do Not Collect or Do Not Do

At launch, based on the current technical implementation:

  • We do not use Google Analytics, Mixpanel, PostHog, Segment, Hotjar, Plausible, Vercel Analytics or similar product analytics tools.
  • We do not use advertising cookies.
  • We do not use third-party marketing pixels.
  • We do not use behavioural profiling cookies.
  • We do not use Apple IDFA or other advertising identifiers for tracking.
  • We do not sell Personal Data.
  • We do not share Personal Data for third-party advertising or marketing.
  • We do not use uploaded images or generated Outputs for Reflecta marketing unless you separately consent or provide them to us for that purpose.
  • We do not create or store biometric templates.
  • We do not perform facial recognition, identity verification, liveness detection or face matching.
  • We do not use uploaded images to train Reflecta’s general AI models by default.

If we introduce any analytics, advertising, marketing cookies or materially different processing in the future, we will update this Privacy Notice and, where required, request consent.

8. How We Process Images and AI Inputs

8.1 Image Upload and Storage

When you upload an image, the file is stored in our file storage environment. Related metadata, such as file reference, title, description, tag, asset type and Workspace relationship, is stored in our database.

Uploaded images may include product images, Person / Model Assets, setting images or other visual references selected by you.

8.2 Image Description and Metadata

The Services may automatically generate text descriptions, names or metadata for uploaded Assets. This is used to help display, organise and use Assets in the interface.

This process does not identify who a person is. It may describe visual characteristics of an image for creative and operational purposes.

8.3 AI Generation

When you request generation of an Output, the relevant images, prompts, settings, style selections and generation parameters may be transmitted to an AI Infrastructure Provider for processing.

AI Infrastructure Providers process these materials to generate the requested Output or to apply safety filtering. Reflecta does not use AI Infrastructure Providers as long-term storage for your uploaded Assets or generated Outputs.

8.4 Output Delivery and Storage

Generated Outputs are stored in your library or Workspace so that you can view, manage, download or delete them.

Other users cannot view your uploaded Assets or generated Outputs through the Services unless you choose to share them outside the Services or unless a future sharing feature is introduced and you use it.

8.5 No Facial Recognition or Biometric Identification

Reflecta does not operate a facial recognition service.

We do not use uploaded images or image-derived data to:

  • identify you;
  • authenticate you;
  • verify your identity;
  • compare you with other users;
  • search for you;
  • detect whether two images depict the same person;
  • create a face ID;
  • create a biometric template;
  • create a liveness profile;
  • build a facial recognition database.

We process images as visual assets and reference inputs for creative generation, asset management, safety controls, service operation and support.

8.6 Images May Reveal Sensitive Information

Images may reveal information such as racial or ethnic origin, religious dress, health indicators or other sensitive characteristics. We do not ask you to provide sensitive information, but such information may be visible in images you choose to upload.

Where applicable law treats such information as sensitive or special category data, we rely on your explicit upload action and, where required, your explicit consent to process the image for the specific purpose of providing the requested Services.

You should not upload images containing sensitive information if you do not want such information processed for the purposes described in this Privacy Notice.

8.7 Images of Other People

You must not upload images of another person unless you have all necessary rights, consents and permissions to do so. This is particularly important where an image depicts a person, a professional model, an employee, a customer, an influencer, a celebrity, a public figure or any other identifiable individual.

You must not upload images of minors.

Your responsibilities for uploaded content are also set out in the Reflecta Terms of Use and the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy.

9. Legal Bases for Processing

Where GDPR, UK GDPR or similar laws apply, we rely on one or more lawful bases for processing Personal Data.

PurposeData UsedLegal Basis
Create and manage Accountsemail, password hash, Account ID, login dataperformance of contract; legitimate interests
Authenticate users and maintain sessionssession tokens, login data, device/browser dataperformance of contract; legitimate interests
Create and manage Workspacesorganization name, Workspace ID, role, Subscription tierperformance of contract; legitimate interests
Provide AI Features and generationuploaded images, prompts, style selections, generation settings, Outputsperformance of contract; consent / explicit consent where required
Store Assets and Outputs in user libraryuploaded Assets, generated Outputs, metadataperformance of contract
Process payments and SubscriptionsSubscription status, transaction metadata, Stripe/Apple IDsperformance of contract; legal obligation; legitimate interests
Manage CreditsCredits balance, credit transactions, internal organization IDperformance of contract; legitimate interests
Provide supportemail, message content, support historyperformance of contract; legitimate interests
Handle abuse, takedown and legal complaintsreported content, complaint data, Account datalegitimate interests; legal obligation
Maintain securitysession data, request metadata, limited logslegitimate interests; legal obligation
Detect and fix errorscrash reports, stack traces, device/app datalegitimate interests
Comply with lawAccount, billing, support and legal recordslegal obligation; legitimate interests
Defend legal claimsrelevant Account, billing, Content and support recordslegitimate interests; legal claims
Optional marketingemail and preferencesconsent, where required
Optional AI improvement programmedata covered by the specific opt-inconsent / explicit consent, where required

Where we rely on legitimate interests, we balance our interests against your rights, freedoms and reasonable expectations.

10. Specific Image Processing Consent

Before you upload or process images through the Services, we may ask you to confirm a specific consent statement such as:

“I understand that my uploaded images, prompts and related technical image information will be processed by Reflecta and its service providers to generate AI outputs, operate the Services, apply safety controls and comply with the Privacy Notice. I understand that I can delete my uploaded images and generated outputs as described in the Privacy Notice.”

This consent is intended to be specific to image processing and AI generation. It does not permit Reflecta to sell your images, use them for third-party marketing, or train Reflecta’s general AI models unless you separately opt in.

11. No General AI Training by Default

We do not use your uploaded images, prompts or generated Outputs to train Reflecta’s general AI models or create separate AI products made available to other users unless you explicitly opt in to a separate improvement or training programme.

If such a programme is introduced, we will provide a separate explanation and obtain your consent where required. You may withdraw such opt-in with prospective effect.

Withdrawal of consent may not affect processing already completed before withdrawal, including model-improvement steps that cannot reasonably be reversed, but it will stop further use of your data for that optional programme.

Third-party AI Infrastructure Providers may process data in accordance with their own terms, privacy policies, data processing commitments and technical safeguards. We seek to use providers and configurations that process user inputs and Outputs for the purpose of providing the requested Services and not for unrelated third-party marketing.

12. Service Providers and Third-Party Recipients

We disclose Personal Data only where necessary for the purposes described in this Privacy Notice.

We do not sell your Personal Data. We do not share your uploaded images, generated Outputs or Account data with third parties for their own marketing purposes.

12.1 Current Categories of Recipients

Recipient CategoryPurposeData Involved
Database hosting providerAccount data, Workspace data, Subscription metadata, prompts, metadataemail, password hash, Workspace data, metadata, prompts
File storage providerstorage of uploaded Assets and generated Outputsuploaded images, generated images
Cloud infrastructure providerwebsite, API, routing, security, request handlingrequest metadata, technical data, transmitted Content
AI Infrastructure ProviderAI generation and safety filteringimages, prompts, generation parameters, Outputs
Crash-reporting providererror detection and debuggingcrash reports, device/app data, stack traces
Payment processor for website purchasesweb payments and Subscriptionspayment and Subscription metadata
Apple App Store / Apple IAPiOS app distribution, in-app purchases, Subscription managementApple transaction and Subscription data
Email and support toolssupport, privacy requests, abuse reports, takedown communicationsemail, message content, attachments
Professional adviserslegal, accounting, audit, insurancerelevant records where necessary
Authorities and regulatorslegal compliancedata required by law
Corporate transaction partiesmerger, acquisition, financing, reorganisation or sale of assetslimited business records subject to confidentiality

12.2 Current Technical Providers

Subject to change as the Services develop, the current technical infrastructure includes:

  • Neon – PostgreSQL database hosting, currently in London, United Kingdom.
  • Cloudflare R2 – file storage for uploaded Assets and generated Outputs, currently in Eastern Europe region.
  • Cloudflare Workers – application server / API execution environment; data is processed in transit and not stored permanently in the worker environment.
  • Replicate – AI Infrastructure Provider used to process images, prompts and generation requests; processing may occur outside the United Kingdom, European Economic Area or United Arab Emirates.
  • Sentry – crash reporting and error monitoring, with processing that may occur in the United States.
  • Stripe – website payment processing and Subscription management.
  • Apple – iOS app distribution, Apple account services and Apple IAP.
  • abuse@tryreflecta.app / support@tryreflecta.app – support, privacy requests, abuse and takedown communications.

We may update the provider list from time to time. Where required by applicable law, we will make an updated subprocessor or service-provider list available through the Services or upon request.

12.3 App Marketplaces and Payment Providers as Independent Controllers

Apple, Stripe and other payment or App Marketplace providers may process certain data as independent controllers or independent businesses under their own terms and privacy policies.

Your payment details, Apple ID, Stripe account interactions and App Marketplace transactions may be governed by their own policies and settings.

13. Cookies and Similar Technologies

We use only limited cookies and similar technologies required for core functionality, authentication, Account security and session continuity.

Our use of cookies, local storage, secure app storage and similar technologies is described in the Reflecta Cookie and Similar Technologies Notice.

At launch, we do not use:

  • advertising cookies;
  • behavioural tracking cookies;
  • third-party marketing pixels;
  • analytics cookies;
  • social media tracking widgets;
  • Google Analytics;
  • Meta Pixel;
  • Google Ads tags;
  • Hotjar or similar session-recording tools.

If we introduce non-essential cookies or tracking technologies in the future, we will update the Cookie and Similar Technologies Notice and, where required, request consent before using them.

14. Communications

We may send you service-related communications, including:

  • Account verification emails;
  • password reset emails;
  • Subscription notices;
  • purchase confirmations;
  • security alerts;
  • support responses;
  • abuse, takedown or appeal communications;
  • legal or policy notices.

These communications are necessary for the Services and cannot generally be opted out of while you maintain an Account.

We do not use your uploaded images or generated Outputs for marketing purposes. We will send marketing communications only where permitted by law and, where required, only with your consent. You may opt out of marketing communications at any time.

15. Data Security

We use reasonable technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

  • encryption in transit;
  • encryption at rest where supported by our infrastructure providers;
  • password hashing;
  • HTTP-only session cookies;
  • access controls;
  • role-based internal access;
  • API access checks;
  • Workspace-level access restrictions;
  • secure cloud infrastructure;
  • vendor due diligence;
  • limited administrative access;
  • crash and error monitoring;
  • abuse and Account enforcement procedures.

Access to uploaded Assets and generated Outputs is restricted to the authorised user or Workspace. The Services do not provide a public catalogue of user-uploaded Assets or generated Outputs. Files are accessed through authenticated requests and Workspace-level checks.

No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your Account credentials and for notifying us promptly if you suspect unauthorised access.

16. Data Retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Notice, unless a longer period is required or permitted by law.

The following table summarises our retention approach.

Data CategoryRetention Period
Account datauntil you delete your Account or request deletion, subject to lawful exceptions
Password reset and email verification codesapproximately 10 minutes or until expiry
Session datauntil session expiry or logout, subject to security needs
Workspace / organization datauntil Account or Workspace deletion, subject to lawful exceptions
Uploaded Assetsuntil you delete the Asset or delete your Account
Generated Outputsuntil you delete the Output or delete your Account
Prompts, descriptions, tags and metadatauntil related Asset / Output deletion or Account deletion
AI Infrastructure Provider processing datatransmitted for processing; provider retention is governed by applicable provider terms and contractual safeguards
Cloudflare technical logsup to 72 hours, unless required for security investigation
Sentry crash reportsup to 90 days
Support recordsup to 3 years after last interaction, unless longer retention is required for dispute, legal, safety or compliance reasons
Billing, tax and accounting recordsnormally up to 7 years or such other period required by applicable law
Credit transaction recordsretained for accounting, reconciliation, fraud prevention, dispute and legal purposes; after Account deletion, retained in de-identified or pseudonymised form where possible
Abuse, takedown and legal complaint recordsfor as long as necessary to investigate, enforce policies, prevent repeat abuse and defend legal claims
Backupsdeleted or overwritten in accordance with backup cycles, normally within 30–90 days, unless legal hold or security investigation applies

We apply a unified retention approach designed to meet high data-protection standards across jurisdictions. We do not currently assign different retention periods based on the country from which a user uploads Content.

17. Account Deletion and Content Deletion

You may delete individual uploaded Assets and generated Outputs through the Services where the relevant functionality is available.

You may delete your Account through the Account deletion functionality or by contacting us at privacy@tryreflecta.app.

Deleting the app from your device does not delete your Account. To delete your Account, you must use the Account deletion function or contact us.

Deleting the app from your device also does not cancel a Subscription processed by Apple, Stripe or another payment provider. You must cancel any active Subscription through the applicable subscription management process.

When you delete your Account, we delete or de-identify:

  • your Account record;
  • your email address;
  • your name, if provided;
  • your Workspace / organization record, where applicable;
  • uploaded Assets;
  • generated Outputs;
  • prompts and Content metadata;
  • sessions;
  • verification and reset codes;
  • directly identifying support Account links, where applicable.

Certain limited records may remain after Account deletion where necessary for tax, accounting, fraud prevention, dispute resolution, legal compliance, safety or security reasons.

For example:

  • billing and Credit transaction records may remain linked to an internal organization ID and transaction numbers, without your email address or name;
  • support tickets may be de-identified by removing your email and name while retaining the message history for support quality, dispute and legal purposes;
  • Cloudflare technical logs may remain for up to 72 hours;
  • Sentry crash reports may remain for up to 90 days;
  • Stripe, Apple and other payment providers may retain payment and transaction records under their own policies.

After Account deletion, remaining internal records are no longer linked to directly identifying Account details such as your email address or name, except where retention is required by law, tax, accounting, dispute, security, fraud prevention or legal reasons.

18. Cross-Border Data Transfers

Because the Services are provided globally and rely on international technical infrastructure, your Personal Data may be transferred to, stored in or processed in countries other than your country of residence.

These transfers may include:

  • email address;
  • password hash and authentication data;
  • organization or Workspace name;
  • uploaded images;
  • generated images;
  • prompts;
  • descriptions, tags and metadata;
  • Subscription and payment metadata;
  • support communications;
  • abuse, takedown and appeal communications;
  • technical logs;
  • crash reports;
  • legal complaint records.

Current processing locations include:

  • United Arab Emirates – Reflecta’s place of establishment and corporate administration;
  • United Kingdom – database hosting;
  • Eastern Europe region – file storage for uploaded Assets and generated Outputs;
  • United States – crash reporting and certain service-provider processing;
  • other locations – AI infrastructure, payment processing and cloud routing may involve processing outside your country of residence.

Where applicable law restricts international transfers, we use appropriate transfer mechanisms, which may include:

  • adequacy decisions;
  • standard contractual clauses;
  • the UK International Data Transfer Agreement or UK Addendum;
  • data processing agreements;
  • contractual confidentiality and security obligations;
  • technical and organisational safeguards;
  • transfer risk assessments where required;
  • derogations permitted by law, including where the transfer is necessary to perform the contract with you.

We do not transfer uploaded images, generated Outputs or Account data to third parties for their own marketing purposes.

19. Your Privacy Rights

Depending on your jurisdiction, you may have rights in relation to your Personal Data, including:

  • the right to access your Personal Data;
  • the right to receive a copy of your Personal Data;
  • the right to correct inaccurate Personal Data;
  • the right to delete Personal Data;
  • the right to restrict processing;
  • the right to object to processing;
  • the right to data portability;
  • the right to withdraw consent where processing is based on consent;
  • the right to appeal certain privacy decisions, where applicable;
  • the right to lodge a complaint with a supervisory authority.

These rights may be subject to legal limitations and exceptions.

19.1 How to Exercise Rights

You may submit a privacy request by:

  • using in-app tools, where available;
  • emailing privacy@tryreflecta.app with the subject line “Privacy Rights Request”;
  • writing to Reflecta at Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates, Attn: Privacy.

We may ask you to provide information necessary to verify your identity and protect your Account against fraudulent or unauthorised requests.

19.2 Response Timing

Where GDPR or UK GDPR applies, we generally respond to valid privacy requests within one month, subject to lawful extensions.

Where U.S. state privacy laws or other local laws apply, we respond within the time required by applicable law.

19.3 Withdrawal of Consent

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.

If you withdraw consent necessary to provide image generation or other core features, certain features may no longer be available.

20. EEA, UK and Swiss Users

If you are located in the European Economic Area, United Kingdom or Switzerland, you may have additional rights under applicable data protection laws.

You may lodge a complaint with your local data protection authority. We encourage you to contact us first so that we can try to resolve your concern.

EU Representative
To be inserted if appointed or required before EEA launch
UK Representative
To be inserted if appointed or required before UK launch
Data Protection Officer
To be inserted if appointed or required

If Reflecta is not established in the EEA or the United Kingdom and offers Services to users there, Reflecta will assess whether an EU and/or UK representative is required under applicable law.

21. U.S. State Privacy Disclosures

This Section applies to residents of U.S. states that provide privacy rights under applicable state privacy laws.

21.1 Categories of Personal Information Collected

We may collect the following categories of personal information:

  • identifiers, such as name, email address, Account ID, IP address and internal identifiers;
  • commercial information, such as Subscription status, purchase history and Credit transactions;
  • internet or electronic network activity information, such as session data, request metadata and technical logs;
  • visual information, such as uploaded images and generated Outputs;
  • professional or business information, such as organization name where provided;
  • inferences or metadata used for Asset organisation and service functionality;
  • sensitive personal information where uploaded images reveal sensitive characteristics.

21.2 Purposes

We use this information for the purposes described in this Privacy Notice, including providing the Services, generating Outputs, managing Accounts, processing payments, providing support, protecting security, enforcing policies and complying with law.

21.3 Sale, Sharing and Targeted Advertising

We do not sell Personal Data.

At launch, we do not share Personal Data for cross-context behavioural advertising or targeted advertising.

We do not use cookies or similar technologies for advertising, behavioural profiling or third-party marketing.

If this changes, we will update this Privacy Notice and provide required opt-out mechanisms.

21.4 Sensitive Personal Information

We do not use sensitive personal information for the purpose of inferring characteristics about you for advertising or profiling. Images may reveal sensitive information, but we process such images to provide the Services you request.

21.5 U.S. Privacy Rights

Depending on your state of residence, you may have rights to:

  • know what personal information we collect;
  • access personal information;
  • correct inaccurate information;
  • delete information;
  • obtain a portable copy of information;
  • opt out of sale, sharing or targeted advertising, where applicable;
  • limit certain uses of sensitive personal information, where applicable;
  • appeal our decision on a rights request.

You may exercise these rights by contacting privacy@tryreflecta.app.

We will not discriminate against you for exercising privacy rights.

22. UAE and MENA Privacy Position

Reflecta is established in Dubai, United Arab Emirates. Where UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data or similar regional data protection laws apply, we process Personal Data for the purposes described in this Privacy Notice and apply appropriate technical and organisational safeguards.

Where required, we rely on consent, contract performance, legal obligation, legitimate business purposes or other lawful bases available under applicable law.

Cross-border transfers are made for the purposes of hosting, storage, AI processing, payment processing, support, security and operation of the Services, subject to safeguards described in this Privacy Notice.

23. Legal Requests, Safety and Rights Complaints

We may access, preserve or disclose Personal Data where reasonably necessary to:

  • comply with law, regulation, legal process or governmental request;
  • enforce the Reflecta Terms of Use and the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy;
  • investigate security incidents;
  • detect, prevent or address fraud or abuse;
  • protect the rights, property or safety of Reflecta, users or others;
  • respond to intellectual property, privacy, likeness, abuse or takedown complaints;
  • review appeals or counter-notices;
  • establish, exercise or defend legal claims.

24. Business Transfers

If Reflecta is involved in a merger, acquisition, financing, restructuring, sale of assets, insolvency process or similar transaction, Personal Data may be disclosed to advisers, potential transaction parties and successor entities, subject to appropriate confidentiality protections.

Where required by law, we will provide notice of such transfer and any choices available to you.

25. Third-Party Links and Services

The Services may contain links to third-party websites, App Marketplaces, payment processors or services. This Privacy Notice does not apply to the privacy practices of third parties that are not controlled by Reflecta.

You should review the privacy policies of Apple, Stripe, Replicate and other third-party services that may be relevant to your use of the Services.

26. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our Services, technology, providers, legal requirements or business practices.

When we update this Privacy Notice, we will revise the “Last updated” date. Where required by law, we will provide additional notice or request consent.

Your continued use of the Services after an updated Privacy Notice becomes effective means that you acknowledge the updated Privacy Notice, subject to your mandatory legal rights.

27. Contact Details

Controller
REFLECTA LABS SOFTWARE TRADING L.L.C
Legal form
Limited Liability Company - Single Owner (LLC - SO)
Commercial Licence No.
1606456
Commercial Register No.
2819318
DCCI Membership No.
674950
Licensed activity
Computer Systems & Communication Equipment Software Trading
Licensed / registered address
Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates
Official licence email / legal contact
legal@tryreflecta.app
Abuse / takedown contact
abuse@tryreflecta.app
Data Protection Officer
To be inserted if appointed or required
EU Representative
To be inserted if appointed or required
UK Representative
To be inserted if appointed or required

Annex A – Processing Matrix

ActivityData TypesPurposeRecipientsLegal BasisRetention
Account creation and loginname, email, password hash, Account ID, session data, OTP codescreate Account, authenticate user, secure accessdatabase hosting, cloud infrastructurecontract; legitimate interestsAccount life; OTP approx. 10 minutes; sessions until expiry
Workspace / organization managementorganization name, Workspace ID, role, tier, Creditsprovide Workspace functionality and Subscription accessdatabase hosting, cloud infrastructurecontract; legitimate interestsuntil Account / Workspace deletion
Uploading Assetsuploaded images, metadata, tags, descriptionsstore and display Assets, prepare for generationfile storage, database hosting, cloud infrastructurecontract; consent where requireduntil user deletes Asset or Account
AI generationuploaded images, prompts, style selections, generation settingsgenerate requested Outputs and apply safety controlsAI Infrastructure Provider, cloud infrastructurecontract; consent / explicit consent where requiredstored by Reflecta until deletion; provider processing subject to provider commitments
Output librarygenerated Outputs, metadatadisplay, manage and download Outputsfile storage, database hostingcontractuntil user deletes Output or Account
Payments and SubscriptionsSubscription status, receipt metadata, Stripe/Apple IDs, Creditsbilling, Subscription access, reconciliation, fraud preventionApple, Stripe, database hostingcontract; legal obligation; legitimate interestsnormally up to 7 years or as required by law
Supportemail, message content, attachments, support notesrespond to requests, resolve issuessupport tools, database hostingcontract; legitimate interestsup to 3 years or longer if required
Abuse and takedownreport details, complained-of Content, Account detailsinvestigate complaints, enforce policiessupport tools, legal advisers, authorities where requiredlegitimate interests; legal obligationas necessary for enforcement, repeat abuse and legal claims
Technical logsrequest metadata, timestamps, status, limited IP/session datadebugging, security, service operationCloudflare, cloud infrastructurelegitimate interestsup to 72 hours unless security investigation applies
Crash reportsstack traces, app version, OS, device type, IP if captureddetect and fix errorsSentrylegitimate interestsup to 90 days
Legal compliancerelevant Account, transaction, support and Content recordscomply with law and defend claimslegal advisers, authoritieslegal obligation; legitimate interestsas required by law or legal claim needs

Annex B – Retention Schedule

Data TypeDefault RetentionUser ControlNotes
Account datauntil Account deletiondelete Accountlawful exceptions may apply
Password hashuntil Account deletiondelete Accountnot stored in plain text
OTP / verification codesapprox. 10 minutesnot applicableautomatically expire
Sessionsuntil expiry/logoutlogout / Account deletionmay be retained briefly for security
Organization / Workspace datauntil Account / Workspace deletiondelete Account / Workspacebilling exceptions may apply
Uploaded Assetsuntil Asset deletion / Account deletiondelete in appbackup/legal hold exceptions may apply
Generated Outputsuntil Output deletion / Account deletiondelete in appbackup/legal hold exceptions may apply
Prompts and metadatauntil related Content / Account deletiondelete Content / Accountmay be retained if part of abuse/legal record
Credit transactionsaccounting/legal periodlimitedafter Account deletion, retained without email/name where possible
Stripe / Apple transaction referencesnormally up to 7 yearslimitedtax/accounting/dispute retention
Support messagesup to 3 yearsrequest deletionmay be retained longer for disputes/legal compliance
Cloudflare technical logsup to 72 hourslimitedno intentional Content storage
Sentry crash reportsup to 90 dayslimitedno intentional Content storage
Backupsnormally 30–90 dayslimitedsubject to backup cycles and legal holds
Abuse / takedown recordsas necessarylimitedrepeat abuse, legal claims and safety

Annex C – Cookie and Similar Technologies Summary

Reflecta uses only limited technologies required for login, Account security, session continuity and basic interface functionality.

At launch, Reflecta does not use advertising cookies, analytics cookies, behavioural tracking cookies, third-party marketing pixels or social media tracking widgets.

Detailed information is available in the Reflecta Cookie and Similar Technologies Notice.

Annex D – Service Provider and Subprocessor Summary

ProviderFunctionData CategoriesRegion / Location
NeonPostgreSQL database hostingAccount, Workspace, Subscription metadata, prompts, metadataLondon, United Kingdom
Cloudflare R2file storageuploaded Assets, generated OutputsEastern Europe region
Cloudflare Workersapplication/API processing, routing, securityrequest data, transmitted Content, technical metadataCloudflare network
ReplicateAI infrastructure and model processingimages, prompts, generation parameters, Outputsmay include processing outside UK/EEA/UAE
Sentrycrash and error monitoringcrash reports, stack traces, device/app data, IP if capturedUnited States / provider infrastructure
Stripewebsite payments and Subscriptionspayment metadata, Subscription data, customer IDStripe infrastructure
AppleiOS app distribution and Apple IAPApple transaction and Subscription dataApple infrastructure
abuse@tryreflecta.app / support@tryreflecta.appsupport and communicationsemail, message content, attachmentsGoogle infrastructure, UAE

This list may be updated from time to time.

Annex E – Image Processing Notice for In-App Display

Reflecta uses uploaded images and prompts to generate AI-powered creative Outputs. Your images may be stored in your Workspace, transmitted to service providers for AI processing, used to create descriptions or metadata, and stored as generated Outputs in your library.

Reflecta does not use your images to identify you, verify your identity, compare you with other users or create a facial recognition database.

By uploading an image, you confirm that you have the necessary rights and consents to upload and process that image, including where the image depicts another person.

You must not upload images of minors.

You may delete uploaded images and generated Outputs through the Services or request Account deletion as described in the Privacy Notice.

Annex F – Privacy Notice at Collection

We collect the following Personal Data when you use Reflecta:

  • Account information, such as email address, password hash and Account ID;
  • Workspace information, such as organization name, Subscription tier and Credits;
  • uploaded images and related metadata;
  • prompts, style selections and generation settings;
  • generated Outputs;
  • payment and Subscription metadata;
  • support communications;
  • abuse, takedown and legal complaint communications;
  • limited technical logs and crash reports.

We use this information to provide, operate, secure and support the Services, generate Outputs you request, manage Subscriptions and Credits, respond to support and legal requests, prevent abuse, comply with law and maintain service reliability.

We do not sell Personal Data. We do not use uploaded images or generated Outputs for third-party marketing. We do not use advertising cookies or analytics cookies at launch.

More details are available in the full Privacy Notice.