Privacy Notice
- Privacy contact
- privacy@tryreflecta.app
- Support contact
- support@tryreflecta.app
- Abuse / takedown contact
- abuse@tryreflecta.app
- Legal contact
- legal@tryreflecta.app
1. Introduction
This Privacy Notice explains how REFLECTA LABS SOFTWARE TRADING L.L.C (“Reflecta”, “we”, “us”, “our”) collects, uses, stores, discloses, transfers and otherwise processes Personal Data when you access or use Reflecta’s website, iOS mobile application, software, Account, Workspace, AI-powered creative generation tools, image generation tools, image editing tools, asset libraries, billing features, support channels and related services (together, the “Services”).
Reflecta is an AI-powered creative generation platform with private user workspaces. The Services allow users to upload or select visual assets, create and manage workspaces, use platform-provided materials, and generate visual Outputs using AI-powered tools. User Content is processed within the user’s own Account or Workspace. Reflecta does not operate a public social network, public feed or public in-app user-to-user content platform.
This Privacy Notice applies to both the Reflecta website and the Reflecta iOS application.
This Privacy Notice should be read together with:
- Reflecta Terms of Use;
- Reflecta European Terms of Use, where applicable;
- Reflecta Cookie and Similar Technologies Notice;
- Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy;
- any other notice presented to you at the time of using a specific Service, feature, Workspace, subscription, credit pack, purchase or enterprise arrangement.
By “Personal Data” we mean information relating to an identified or identifiable natural person, or information otherwise treated as personal information, personal data or personally identifiable information under applicable data protection laws.
This Privacy Notice does not apply to third-party websites, App Marketplaces, payment processors or services that are not controlled by Reflecta, except where this Privacy Notice expressly states otherwise.
2. Controller Details
For the purposes of applicable data protection laws, the controller of your Personal Data is:
- Controller
- REFLECTA LABS SOFTWARE TRADING L.L.C
- Legal form
- Limited Liability Company - Single Owner (LLC - SO)
- Commercial Licence No.
- 1606456
- Commercial Register No.
- 2819318
- DCCI Membership No.
- 674950
- Licensed activity
- Computer Systems & Communication Equipment Software Trading
- Licensed / registered address
- Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates
- Official licence email / legal contact
- legal@tryreflecta.app
- Phone
- +971 58 5520042
- Privacy contact
- privacy@tryreflecta.app
- Support contact
- support@tryreflecta.app
- Abuse / takedown contact
- abuse@tryreflecta.app
- Legal contact
- legal@tryreflecta.app
3. Definitions
Capitalised terms used in this Privacy Notice have the meanings below, unless the context requires otherwise.
- “Account”
- means a user account registered with Reflecta.
- “AI Features”
- means AI-powered generation, editing, styling and transformation tools made available through the Services, including tools that generate fashion, product, editorial, marketing-style or other visual Outputs using User Assets, Platform Assets, prompts, styles, products, collections, settings and other inputs.
- “AI Infrastructure Provider”
- means a third-party provider used by Reflecta to process inputs, prompts, images, generation parameters or other data to provide AI-powered functionality.
- “App Marketplace”
- means Apple App Store or any other digital marketplace through which the Services may be distributed from time to time.
- “Apple IAP”
- means Apple In-App Purchase and related Apple payment infrastructure used for purchases made inside the iOS application.
- “Assets”
- means User Assets and Platform Assets collectively.
- “Content”
- means User Content, prompts, Assets and Outputs collectively, unless the context requires otherwise.
- “Credits”
- means credits, tokens, allowances or similar digital units that may be used within the Services to access or redeem eligible AI Features, generation requests, exports or other digital functionality.
- “Output or Outputs”
- means images or other content generated, edited or transformed by the Services based on User Assets, Platform Assets, prompts or other inputs.
- “Paid Services”
- means subscriptions, Credits, premium features, paid digital functionality, credit packs, enhanced Outputs, high-resolution exports, business plans or other paid offerings made available through the Services.
- “Person / Model Asset”
- means an image or reference representing a human person, model, persona, likeness or identifiable individual that is uploaded, selected or used as a visual reference in the Services. A Person / Model Asset is not an AI model.
- “Personal Data”
- means information relating to an identified or identifiable natural person, or information otherwise treated as personal information, personal data or personally identifiable information under applicable data protection law.
- “Platform Asset”
- means any asset, template, style, scene, product, collection, sample prompt, preset, reference material, model image, setting or other content made available by Reflecta within the Services.
- “Reflecta Content”
- means the Services and all software, AI systems, workflows, interfaces, designs, text, graphics, images, examples, templates, Platform Assets, styles, scenes, products, collections, presets, documentation, trademarks, trade names, service marks, logos, slogans and other content made available by Reflecta.
- “Services”
- means the Reflecta platform, including the Reflecta website, iOS mobile application, software, AI Features, account workspaces, content libraries, billing features, support channels and related services.
- “Subscription”
- means a recurring paid plan that provides access to specified Paid Services for a subscription period, subject to the Reflecta Terms of Use and any disclosures presented at purchase.
- “User Asset”
- means any image, product photograph, person/model reference, setting or scene reference, text, prompt, tag, description, collection, product reference or other material uploaded, created, selected, stored or submitted by you through the Services.
- “User Content”
- means any User Asset, prompt, photo, image, text, metadata, tag, description, communication, report or other material that you upload, submit, transmit, create, select or otherwise provide to the Services.
- “Workspace”
- means an account environment, workspace, organization profile or team space associated with an individual user or business user for managing subscriptions, Credits, Assets, Outputs and related settings.
4. Age Restriction
The Services are intended only for users who are at least 18 years old and have reached the age of majority in their jurisdiction of residence.
You must not create an Account, upload Assets, generate Outputs, purchase Paid Services, use AI Features or otherwise use the Services if you are under 18 or have not reached the age of majority in your jurisdiction.
We do not knowingly collect Personal Data from children or minors. If we become aware that we have collected Personal Data from a person who is not eligible to use the Services, we will take reasonable steps to delete such data and close the relevant Account.
You must not upload images of minors. You must never upload, generate, request, store, share or attempt to generate sexual, exploitative, harmful, abusive, age-inappropriate or unlawful content involving minors.
5. Summary of Our Privacy Position
Reflecta’s privacy approach is based on the following principles:
- We process your data to provide, operate, secure and support the Services.
- We process uploaded images as visual assets and reference inputs for AI generation.
- We do not provide a facial recognition service.
- We do not use uploaded images to identify you, authenticate you, verify your identity, compare you with other users, search for you or create a facial recognition database.
- We do not create or store biometric templates, face IDs, liveness profiles or identity verification records.
- We do not use your uploaded images or generated Outputs to train Reflecta’s general AI models unless you explicitly opt in to a separate programme.
- We do not sell your Personal Data.
- We do not share your uploaded images, generated Outputs or Account data with third parties for their own marketing purposes.
- We do not use advertising cookies, behavioural tracking cookies, third-party marketing pixels or analytics cookies at launch.
- We use service providers only where necessary to operate, host, secure, support, bill for and provide the Services.
6. Personal Data We Collect
We collect Personal Data directly from you, automatically when you use the Services, and from service providers such as App Marketplaces, payment processors and authentication providers.
The categories of Personal Data we collect depend on how you use the Services.
6.1 Account and Login Data
We collect and process Account and login data, which may include:
- name, if provided;
- email address;
- Account ID;
- password hash;
- authentication tokens;
- session identifiers;
- email verification codes;
- password reset codes;
- login status;
- device/browser session information;
- IP address where captured for session, infrastructure or security purposes.
We do not store your password in plain text. Passwords are stored in hashed form.
We use this data to create and manage your Account, authenticate you, keep you logged in, verify your email address, reset your password, protect the Services and prevent unauthorised access.
6.2 Workspace and Organization Data
The Services use a Workspace or organization structure. Depending on how you register and use the Services, we may collect and process:
- Workspace name;
- organization name;
- role or access level within a Workspace;
- Subscription tier;
- Credits balance;
- internal organization ID;
- Stripe customer ID, where payment is made through the website;
- Apple subscription or transaction identifiers, where payment is made through the iOS application.
An individual user may also have an automatically created Workspace or organization for technical account-management purposes. Providing an organization name may indicate business use of the Services.
6.3 Uploaded Assets and User Content
When you use the Services, you may upload, submit, select or create Content. This may include:
- photos and images;
- product images;
- Person / Model Assets;
- setting, background or scene images;
- prompts;
- style selections;
- product, setting, model or collection selections;
- tags;
- titles;
- descriptions;
- metadata associated with uploaded or generated Content;
- generated Outputs.
We refer to materials uploaded or submitted by you as User Content or User Assets. Assets may be categorised within the Services as Product, Person / Model, Setting or other asset types.
6.4 Platform Assets and Platform-Provided Materials
The Services may include Platform Assets, such as Discover materials, styles, products, collections, model images, settings, presets, templates or other creative references.
When you interact with Platform Assets, we may process metadata about your selection and use of those Platform Assets to provide the requested functionality and manage your Workspace or library.
6.5 Image Processing Data
When you upload images or use AI Features, we process images and related technical information to provide the requested Output. This may include:
- uploaded image files;
- generated image files;
- image metadata;
- prompts and generation parameters;
- text descriptions generated from images for interface and asset-management purposes;
- technical information required to generate, store, display, retrieve or delete images;
- safety-filtering signals;
- temporary processing data transmitted to AI Infrastructure Providers.
Reflecta does not use this processing to identify you as a person, verify your identity or compare you to other users.
6.6 Payments, Subscriptions and Credits
If you purchase a Subscription, Credits or other Paid Services, we may collect and process:
- Subscription status;
- payment channel;
- Subscription tier;
- renewal status;
- purchase confirmation;
- receipt metadata;
- Credits issued, used or expired;
- transaction timestamps;
- Stripe customer ID for web purchases;
- Apple transaction or subscription identifiers for iOS purchases.
We do not store full payment card numbers. Card and payment details are processed by Apple, Stripe or another payment provider, depending on the payment channel.
6.7 Support, Legal, Abuse and Communications Data
If you contact us, report an issue, submit an abuse or takedown complaint, make a privacy request, appeal an enforcement decision or communicate with us, we may collect:
- your email address;
- your name, if provided;
- message content;
- support request details;
- complaint or report details;
- appeal details;
- attachments you provide;
- internal support or review notes;
- status of the request;
- dates and times of communications.
6.8 Technical Logs and Security Data
When you use the Services, we and our service providers may process limited technical data, including:
- request metadata;
- timestamps;
- API request status;
- response times;
- error codes;
- session information;
- IP address where captured for login, security, infrastructure or crash-reporting purposes;
- device type;
- browser type;
- operating system;
- app version;
- crash logs;
- stack traces.
Technical logs do not intentionally include uploaded images, generated Outputs or prompts.
6.9 Crash Reports
We use crash-reporting and error-monitoring tools to detect and fix errors. Crash reports may include:
- app version;
- operating system version;
- device type;
- stack trace;
- error details;
- time of crash;
- IP address if automatically collected by the crash-reporting provider.
Crash reports are not intended to contain uploaded images, prompts or generated Outputs.
6.10 Data from Third Parties
We may receive limited Personal Data from third parties, including:
- Apple, where you use the iOS application or make an Apple IAP purchase;
- Stripe, where you purchase through the website;
- authentication providers, where third-party sign-in is supported;
- AI Infrastructure Providers, where processing status or technical data is returned;
- support, security, email or infrastructure service providers.
7. What We Do Not Collect or Do Not Do
At launch, based on the current technical implementation:
- We do not use Google Analytics, Mixpanel, PostHog, Segment, Hotjar, Plausible, Vercel Analytics or similar product analytics tools.
- We do not use advertising cookies.
- We do not use third-party marketing pixels.
- We do not use behavioural profiling cookies.
- We do not use Apple IDFA or other advertising identifiers for tracking.
- We do not sell Personal Data.
- We do not share Personal Data for third-party advertising or marketing.
- We do not use uploaded images or generated Outputs for Reflecta marketing unless you separately consent or provide them to us for that purpose.
- We do not create or store biometric templates.
- We do not perform facial recognition, identity verification, liveness detection or face matching.
- We do not use uploaded images to train Reflecta’s general AI models by default.
If we introduce any analytics, advertising, marketing cookies or materially different processing in the future, we will update this Privacy Notice and, where required, request consent.
8. How We Process Images and AI Inputs
8.1 Image Upload and Storage
When you upload an image, the file is stored in our file storage environment. Related metadata, such as file reference, title, description, tag, asset type and Workspace relationship, is stored in our database.
Uploaded images may include product images, Person / Model Assets, setting images or other visual references selected by you.
8.2 Image Description and Metadata
The Services may automatically generate text descriptions, names or metadata for uploaded Assets. This is used to help display, organise and use Assets in the interface.
This process does not identify who a person is. It may describe visual characteristics of an image for creative and operational purposes.
8.3 AI Generation
When you request generation of an Output, the relevant images, prompts, settings, style selections and generation parameters may be transmitted to an AI Infrastructure Provider for processing.
AI Infrastructure Providers process these materials to generate the requested Output or to apply safety filtering. Reflecta does not use AI Infrastructure Providers as long-term storage for your uploaded Assets or generated Outputs.
8.4 Output Delivery and Storage
Generated Outputs are stored in your library or Workspace so that you can view, manage, download or delete them.
Other users cannot view your uploaded Assets or generated Outputs through the Services unless you choose to share them outside the Services or unless a future sharing feature is introduced and you use it.
8.5 No Facial Recognition or Biometric Identification
Reflecta does not operate a facial recognition service.
We do not use uploaded images or image-derived data to:
- identify you;
- authenticate you;
- verify your identity;
- compare you with other users;
- search for you;
- detect whether two images depict the same person;
- create a face ID;
- create a biometric template;
- create a liveness profile;
- build a facial recognition database.
We process images as visual assets and reference inputs for creative generation, asset management, safety controls, service operation and support.
8.6 Images May Reveal Sensitive Information
Images may reveal information such as racial or ethnic origin, religious dress, health indicators or other sensitive characteristics. We do not ask you to provide sensitive information, but such information may be visible in images you choose to upload.
Where applicable law treats such information as sensitive or special category data, we rely on your explicit upload action and, where required, your explicit consent to process the image for the specific purpose of providing the requested Services.
You should not upload images containing sensitive information if you do not want such information processed for the purposes described in this Privacy Notice.
8.7 Images of Other People
You must not upload images of another person unless you have all necessary rights, consents and permissions to do so. This is particularly important where an image depicts a person, a professional model, an employee, a customer, an influencer, a celebrity, a public figure or any other identifiable individual.
You must not upload images of minors.
Your responsibilities for uploaded content are also set out in the Reflecta Terms of Use and the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy.
9. Legal Bases for Processing
Where GDPR, UK GDPR or similar laws apply, we rely on one or more lawful bases for processing Personal Data.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Create and manage Accounts | email, password hash, Account ID, login data | performance of contract; legitimate interests |
| Authenticate users and maintain sessions | session tokens, login data, device/browser data | performance of contract; legitimate interests |
| Create and manage Workspaces | organization name, Workspace ID, role, Subscription tier | performance of contract; legitimate interests |
| Provide AI Features and generation | uploaded images, prompts, style selections, generation settings, Outputs | performance of contract; consent / explicit consent where required |
| Store Assets and Outputs in user library | uploaded Assets, generated Outputs, metadata | performance of contract |
| Process payments and Subscriptions | Subscription status, transaction metadata, Stripe/Apple IDs | performance of contract; legal obligation; legitimate interests |
| Manage Credits | Credits balance, credit transactions, internal organization ID | performance of contract; legitimate interests |
| Provide support | email, message content, support history | performance of contract; legitimate interests |
| Handle abuse, takedown and legal complaints | reported content, complaint data, Account data | legitimate interests; legal obligation |
| Maintain security | session data, request metadata, limited logs | legitimate interests; legal obligation |
| Detect and fix errors | crash reports, stack traces, device/app data | legitimate interests |
| Comply with law | Account, billing, support and legal records | legal obligation; legitimate interests |
| Defend legal claims | relevant Account, billing, Content and support records | legitimate interests; legal claims |
| Optional marketing | email and preferences | consent, where required |
| Optional AI improvement programme | data covered by the specific opt-in | consent / explicit consent, where required |
Where we rely on legitimate interests, we balance our interests against your rights, freedoms and reasonable expectations.
10. Specific Image Processing Consent
Before you upload or process images through the Services, we may ask you to confirm a specific consent statement such as:
“I understand that my uploaded images, prompts and related technical image information will be processed by Reflecta and its service providers to generate AI outputs, operate the Services, apply safety controls and comply with the Privacy Notice. I understand that I can delete my uploaded images and generated outputs as described in the Privacy Notice.”
This consent is intended to be specific to image processing and AI generation. It does not permit Reflecta to sell your images, use them for third-party marketing, or train Reflecta’s general AI models unless you separately opt in.
11. No General AI Training by Default
We do not use your uploaded images, prompts or generated Outputs to train Reflecta’s general AI models or create separate AI products made available to other users unless you explicitly opt in to a separate improvement or training programme.
If such a programme is introduced, we will provide a separate explanation and obtain your consent where required. You may withdraw such opt-in with prospective effect.
Withdrawal of consent may not affect processing already completed before withdrawal, including model-improvement steps that cannot reasonably be reversed, but it will stop further use of your data for that optional programme.
Third-party AI Infrastructure Providers may process data in accordance with their own terms, privacy policies, data processing commitments and technical safeguards. We seek to use providers and configurations that process user inputs and Outputs for the purpose of providing the requested Services and not for unrelated third-party marketing.
12. Service Providers and Third-Party Recipients
We disclose Personal Data only where necessary for the purposes described in this Privacy Notice.
We do not sell your Personal Data. We do not share your uploaded images, generated Outputs or Account data with third parties for their own marketing purposes.
12.1 Current Categories of Recipients
| Recipient Category | Purpose | Data Involved |
|---|---|---|
| Database hosting provider | Account data, Workspace data, Subscription metadata, prompts, metadata | email, password hash, Workspace data, metadata, prompts |
| File storage provider | storage of uploaded Assets and generated Outputs | uploaded images, generated images |
| Cloud infrastructure provider | website, API, routing, security, request handling | request metadata, technical data, transmitted Content |
| AI Infrastructure Provider | AI generation and safety filtering | images, prompts, generation parameters, Outputs |
| Crash-reporting provider | error detection and debugging | crash reports, device/app data, stack traces |
| Payment processor for website purchases | web payments and Subscriptions | payment and Subscription metadata |
| Apple App Store / Apple IAP | iOS app distribution, in-app purchases, Subscription management | Apple transaction and Subscription data |
| Email and support tools | support, privacy requests, abuse reports, takedown communications | email, message content, attachments |
| Professional advisers | legal, accounting, audit, insurance | relevant records where necessary |
| Authorities and regulators | legal compliance | data required by law |
| Corporate transaction parties | merger, acquisition, financing, reorganisation or sale of assets | limited business records subject to confidentiality |
12.2 Current Technical Providers
Subject to change as the Services develop, the current technical infrastructure includes:
- Neon – PostgreSQL database hosting, currently in London, United Kingdom.
- Cloudflare R2 – file storage for uploaded Assets and generated Outputs, currently in Eastern Europe region.
- Cloudflare Workers – application server / API execution environment; data is processed in transit and not stored permanently in the worker environment.
- Replicate – AI Infrastructure Provider used to process images, prompts and generation requests; processing may occur outside the United Kingdom, European Economic Area or United Arab Emirates.
- Sentry – crash reporting and error monitoring, with processing that may occur in the United States.
- Stripe – website payment processing and Subscription management.
- Apple – iOS app distribution, Apple account services and Apple IAP.
- abuse@tryreflecta.app / support@tryreflecta.app – support, privacy requests, abuse and takedown communications.
We may update the provider list from time to time. Where required by applicable law, we will make an updated subprocessor or service-provider list available through the Services or upon request.
12.3 App Marketplaces and Payment Providers as Independent Controllers
Apple, Stripe and other payment or App Marketplace providers may process certain data as independent controllers or independent businesses under their own terms and privacy policies.
Your payment details, Apple ID, Stripe account interactions and App Marketplace transactions may be governed by their own policies and settings.
13. Cookies and Similar Technologies
We use only limited cookies and similar technologies required for core functionality, authentication, Account security and session continuity.
Our use of cookies, local storage, secure app storage and similar technologies is described in the Reflecta Cookie and Similar Technologies Notice.
At launch, we do not use:
- advertising cookies;
- behavioural tracking cookies;
- third-party marketing pixels;
- analytics cookies;
- social media tracking widgets;
- Google Analytics;
- Meta Pixel;
- Google Ads tags;
- Hotjar or similar session-recording tools.
If we introduce non-essential cookies or tracking technologies in the future, we will update the Cookie and Similar Technologies Notice and, where required, request consent before using them.
14. Communications
We may send you service-related communications, including:
- Account verification emails;
- password reset emails;
- Subscription notices;
- purchase confirmations;
- security alerts;
- support responses;
- abuse, takedown or appeal communications;
- legal or policy notices.
These communications are necessary for the Services and cannot generally be opted out of while you maintain an Account.
We do not use your uploaded images or generated Outputs for marketing purposes. We will send marketing communications only where permitted by law and, where required, only with your consent. You may opt out of marketing communications at any time.
15. Data Security
We use reasonable technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures may include:
- encryption in transit;
- encryption at rest where supported by our infrastructure providers;
- password hashing;
- HTTP-only session cookies;
- access controls;
- role-based internal access;
- API access checks;
- Workspace-level access restrictions;
- secure cloud infrastructure;
- vendor due diligence;
- limited administrative access;
- crash and error monitoring;
- abuse and Account enforcement procedures.
Access to uploaded Assets and generated Outputs is restricted to the authorised user or Workspace. The Services do not provide a public catalogue of user-uploaded Assets or generated Outputs. Files are accessed through authenticated requests and Workspace-level checks.
No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your Account credentials and for notifying us promptly if you suspect unauthorised access.
16. Data Retention
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Notice, unless a longer period is required or permitted by law.
The following table summarises our retention approach.
| Data Category | Retention Period |
|---|---|
| Account data | until you delete your Account or request deletion, subject to lawful exceptions |
| Password reset and email verification codes | approximately 10 minutes or until expiry |
| Session data | until session expiry or logout, subject to security needs |
| Workspace / organization data | until Account or Workspace deletion, subject to lawful exceptions |
| Uploaded Assets | until you delete the Asset or delete your Account |
| Generated Outputs | until you delete the Output or delete your Account |
| Prompts, descriptions, tags and metadata | until related Asset / Output deletion or Account deletion |
| AI Infrastructure Provider processing data | transmitted for processing; provider retention is governed by applicable provider terms and contractual safeguards |
| Cloudflare technical logs | up to 72 hours, unless required for security investigation |
| Sentry crash reports | up to 90 days |
| Support records | up to 3 years after last interaction, unless longer retention is required for dispute, legal, safety or compliance reasons |
| Billing, tax and accounting records | normally up to 7 years or such other period required by applicable law |
| Credit transaction records | retained for accounting, reconciliation, fraud prevention, dispute and legal purposes; after Account deletion, retained in de-identified or pseudonymised form where possible |
| Abuse, takedown and legal complaint records | for as long as necessary to investigate, enforce policies, prevent repeat abuse and defend legal claims |
| Backups | deleted or overwritten in accordance with backup cycles, normally within 30–90 days, unless legal hold or security investigation applies |
We apply a unified retention approach designed to meet high data-protection standards across jurisdictions. We do not currently assign different retention periods based on the country from which a user uploads Content.
17. Account Deletion and Content Deletion
You may delete individual uploaded Assets and generated Outputs through the Services where the relevant functionality is available.
You may delete your Account through the Account deletion functionality or by contacting us at privacy@tryreflecta.app.
Deleting the app from your device does not delete your Account. To delete your Account, you must use the Account deletion function or contact us.
Deleting the app from your device also does not cancel a Subscription processed by Apple, Stripe or another payment provider. You must cancel any active Subscription through the applicable subscription management process.
When you delete your Account, we delete or de-identify:
- your Account record;
- your email address;
- your name, if provided;
- your Workspace / organization record, where applicable;
- uploaded Assets;
- generated Outputs;
- prompts and Content metadata;
- sessions;
- verification and reset codes;
- directly identifying support Account links, where applicable.
Certain limited records may remain after Account deletion where necessary for tax, accounting, fraud prevention, dispute resolution, legal compliance, safety or security reasons.
For example:
- billing and Credit transaction records may remain linked to an internal organization ID and transaction numbers, without your email address or name;
- support tickets may be de-identified by removing your email and name while retaining the message history for support quality, dispute and legal purposes;
- Cloudflare technical logs may remain for up to 72 hours;
- Sentry crash reports may remain for up to 90 days;
- Stripe, Apple and other payment providers may retain payment and transaction records under their own policies.
After Account deletion, remaining internal records are no longer linked to directly identifying Account details such as your email address or name, except where retention is required by law, tax, accounting, dispute, security, fraud prevention or legal reasons.
18. Cross-Border Data Transfers
Because the Services are provided globally and rely on international technical infrastructure, your Personal Data may be transferred to, stored in or processed in countries other than your country of residence.
These transfers may include:
- email address;
- password hash and authentication data;
- organization or Workspace name;
- uploaded images;
- generated images;
- prompts;
- descriptions, tags and metadata;
- Subscription and payment metadata;
- support communications;
- abuse, takedown and appeal communications;
- technical logs;
- crash reports;
- legal complaint records.
Current processing locations include:
- United Arab Emirates – Reflecta’s place of establishment and corporate administration;
- United Kingdom – database hosting;
- Eastern Europe region – file storage for uploaded Assets and generated Outputs;
- United States – crash reporting and certain service-provider processing;
- other locations – AI infrastructure, payment processing and cloud routing may involve processing outside your country of residence.
Where applicable law restricts international transfers, we use appropriate transfer mechanisms, which may include:
- adequacy decisions;
- standard contractual clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- data processing agreements;
- contractual confidentiality and security obligations;
- technical and organisational safeguards;
- transfer risk assessments where required;
- derogations permitted by law, including where the transfer is necessary to perform the contract with you.
We do not transfer uploaded images, generated Outputs or Account data to third parties for their own marketing purposes.
19. Your Privacy Rights
Depending on your jurisdiction, you may have rights in relation to your Personal Data, including:
- the right to access your Personal Data;
- the right to receive a copy of your Personal Data;
- the right to correct inaccurate Personal Data;
- the right to delete Personal Data;
- the right to restrict processing;
- the right to object to processing;
- the right to data portability;
- the right to withdraw consent where processing is based on consent;
- the right to appeal certain privacy decisions, where applicable;
- the right to lodge a complaint with a supervisory authority.
These rights may be subject to legal limitations and exceptions.
19.1 How to Exercise Rights
You may submit a privacy request by:
- using in-app tools, where available;
- emailing privacy@tryreflecta.app with the subject line “Privacy Rights Request”;
- writing to Reflecta at Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates, Attn: Privacy.
We may ask you to provide information necessary to verify your identity and protect your Account against fraudulent or unauthorised requests.
19.2 Response Timing
Where GDPR or UK GDPR applies, we generally respond to valid privacy requests within one month, subject to lawful extensions.
Where U.S. state privacy laws or other local laws apply, we respond within the time required by applicable law.
19.3 Withdrawal of Consent
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.
If you withdraw consent necessary to provide image generation or other core features, certain features may no longer be available.
20. EEA, UK and Swiss Users
If you are located in the European Economic Area, United Kingdom or Switzerland, you may have additional rights under applicable data protection laws.
You may lodge a complaint with your local data protection authority. We encourage you to contact us first so that we can try to resolve your concern.
- EU Representative
- To be inserted if appointed or required before EEA launch
- UK Representative
- To be inserted if appointed or required before UK launch
- Data Protection Officer
- To be inserted if appointed or required
If Reflecta is not established in the EEA or the United Kingdom and offers Services to users there, Reflecta will assess whether an EU and/or UK representative is required under applicable law.
21. U.S. State Privacy Disclosures
This Section applies to residents of U.S. states that provide privacy rights under applicable state privacy laws.
21.1 Categories of Personal Information Collected
We may collect the following categories of personal information:
- identifiers, such as name, email address, Account ID, IP address and internal identifiers;
- commercial information, such as Subscription status, purchase history and Credit transactions;
- internet or electronic network activity information, such as session data, request metadata and technical logs;
- visual information, such as uploaded images and generated Outputs;
- professional or business information, such as organization name where provided;
- inferences or metadata used for Asset organisation and service functionality;
- sensitive personal information where uploaded images reveal sensitive characteristics.
21.2 Purposes
We use this information for the purposes described in this Privacy Notice, including providing the Services, generating Outputs, managing Accounts, processing payments, providing support, protecting security, enforcing policies and complying with law.
21.3 Sale, Sharing and Targeted Advertising
We do not sell Personal Data.
At launch, we do not share Personal Data for cross-context behavioural advertising or targeted advertising.
We do not use cookies or similar technologies for advertising, behavioural profiling or third-party marketing.
If this changes, we will update this Privacy Notice and provide required opt-out mechanisms.
21.4 Sensitive Personal Information
We do not use sensitive personal information for the purpose of inferring characteristics about you for advertising or profiling. Images may reveal sensitive information, but we process such images to provide the Services you request.
21.5 U.S. Privacy Rights
Depending on your state of residence, you may have rights to:
- know what personal information we collect;
- access personal information;
- correct inaccurate information;
- delete information;
- obtain a portable copy of information;
- opt out of sale, sharing or targeted advertising, where applicable;
- limit certain uses of sensitive personal information, where applicable;
- appeal our decision on a rights request.
You may exercise these rights by contacting privacy@tryreflecta.app.
We will not discriminate against you for exercising privacy rights.
22. UAE and MENA Privacy Position
Reflecta is established in Dubai, United Arab Emirates. Where UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data or similar regional data protection laws apply, we process Personal Data for the purposes described in this Privacy Notice and apply appropriate technical and organisational safeguards.
Where required, we rely on consent, contract performance, legal obligation, legitimate business purposes or other lawful bases available under applicable law.
Cross-border transfers are made for the purposes of hosting, storage, AI processing, payment processing, support, security and operation of the Services, subject to safeguards described in this Privacy Notice.
23. Legal Requests, Safety and Rights Complaints
We may access, preserve or disclose Personal Data where reasonably necessary to:
- comply with law, regulation, legal process or governmental request;
- enforce the Reflecta Terms of Use and the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy;
- investigate security incidents;
- detect, prevent or address fraud or abuse;
- protect the rights, property or safety of Reflecta, users or others;
- respond to intellectual property, privacy, likeness, abuse or takedown complaints;
- review appeals or counter-notices;
- establish, exercise or defend legal claims.
24. Business Transfers
If Reflecta is involved in a merger, acquisition, financing, restructuring, sale of assets, insolvency process or similar transaction, Personal Data may be disclosed to advisers, potential transaction parties and successor entities, subject to appropriate confidentiality protections.
Where required by law, we will provide notice of such transfer and any choices available to you.
25. Third-Party Links and Services
The Services may contain links to third-party websites, App Marketplaces, payment processors or services. This Privacy Notice does not apply to the privacy practices of third parties that are not controlled by Reflecta.
You should review the privacy policies of Apple, Stripe, Replicate and other third-party services that may be relevant to your use of the Services.
26. Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our Services, technology, providers, legal requirements or business practices.
When we update this Privacy Notice, we will revise the “Last updated” date. Where required by law, we will provide additional notice or request consent.
Your continued use of the Services after an updated Privacy Notice becomes effective means that you acknowledge the updated Privacy Notice, subject to your mandatory legal rights.
27. Contact Details
- Controller
- REFLECTA LABS SOFTWARE TRADING L.L.C
- Legal form
- Limited Liability Company - Single Owner (LLC - SO)
- Commercial Licence No.
- 1606456
- Commercial Register No.
- 2819318
- DCCI Membership No.
- 674950
- Licensed activity
- Computer Systems & Communication Equipment Software Trading
- Licensed / registered address
- Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates
- Official licence email / legal contact
- legal@tryreflecta.app
- Phone
- +971 58 5520042
- Privacy contact
- privacy@tryreflecta.app
- Support contact
- support@tryreflecta.app
- Abuse / takedown contact
- abuse@tryreflecta.app
- Legal contact
- legal@tryreflecta.app
- Data Protection Officer
- To be inserted if appointed or required
- EU Representative
- To be inserted if appointed or required
- UK Representative
- To be inserted if appointed or required
Annex A – Processing Matrix
| Activity | Data Types | Purpose | Recipients | Legal Basis | Retention |
|---|---|---|---|---|---|
| Account creation and login | name, email, password hash, Account ID, session data, OTP codes | create Account, authenticate user, secure access | database hosting, cloud infrastructure | contract; legitimate interests | Account life; OTP approx. 10 minutes; sessions until expiry |
| Workspace / organization management | organization name, Workspace ID, role, tier, Credits | provide Workspace functionality and Subscription access | database hosting, cloud infrastructure | contract; legitimate interests | until Account / Workspace deletion |
| Uploading Assets | uploaded images, metadata, tags, descriptions | store and display Assets, prepare for generation | file storage, database hosting, cloud infrastructure | contract; consent where required | until user deletes Asset or Account |
| AI generation | uploaded images, prompts, style selections, generation settings | generate requested Outputs and apply safety controls | AI Infrastructure Provider, cloud infrastructure | contract; consent / explicit consent where required | stored by Reflecta until deletion; provider processing subject to provider commitments |
| Output library | generated Outputs, metadata | display, manage and download Outputs | file storage, database hosting | contract | until user deletes Output or Account |
| Payments and Subscriptions | Subscription status, receipt metadata, Stripe/Apple IDs, Credits | billing, Subscription access, reconciliation, fraud prevention | Apple, Stripe, database hosting | contract; legal obligation; legitimate interests | normally up to 7 years or as required by law |
| Support | email, message content, attachments, support notes | respond to requests, resolve issues | support tools, database hosting | contract; legitimate interests | up to 3 years or longer if required |
| Abuse and takedown | report details, complained-of Content, Account details | investigate complaints, enforce policies | support tools, legal advisers, authorities where required | legitimate interests; legal obligation | as necessary for enforcement, repeat abuse and legal claims |
| Technical logs | request metadata, timestamps, status, limited IP/session data | debugging, security, service operation | Cloudflare, cloud infrastructure | legitimate interests | up to 72 hours unless security investigation applies |
| Crash reports | stack traces, app version, OS, device type, IP if captured | detect and fix errors | Sentry | legitimate interests | up to 90 days |
| Legal compliance | relevant Account, transaction, support and Content records | comply with law and defend claims | legal advisers, authorities | legal obligation; legitimate interests | as required by law or legal claim needs |
Annex B – Retention Schedule
| Data Type | Default Retention | User Control | Notes |
|---|---|---|---|
| Account data | until Account deletion | delete Account | lawful exceptions may apply |
| Password hash | until Account deletion | delete Account | not stored in plain text |
| OTP / verification codes | approx. 10 minutes | not applicable | automatically expire |
| Sessions | until expiry/logout | logout / Account deletion | may be retained briefly for security |
| Organization / Workspace data | until Account / Workspace deletion | delete Account / Workspace | billing exceptions may apply |
| Uploaded Assets | until Asset deletion / Account deletion | delete in app | backup/legal hold exceptions may apply |
| Generated Outputs | until Output deletion / Account deletion | delete in app | backup/legal hold exceptions may apply |
| Prompts and metadata | until related Content / Account deletion | delete Content / Account | may be retained if part of abuse/legal record |
| Credit transactions | accounting/legal period | limited | after Account deletion, retained without email/name where possible |
| Stripe / Apple transaction references | normally up to 7 years | limited | tax/accounting/dispute retention |
| Support messages | up to 3 years | request deletion | may be retained longer for disputes/legal compliance |
| Cloudflare technical logs | up to 72 hours | limited | no intentional Content storage |
| Sentry crash reports | up to 90 days | limited | no intentional Content storage |
| Backups | normally 30–90 days | limited | subject to backup cycles and legal holds |
| Abuse / takedown records | as necessary | limited | repeat abuse, legal claims and safety |
Annex C – Cookie and Similar Technologies Summary
Reflecta uses only limited technologies required for login, Account security, session continuity and basic interface functionality.
At launch, Reflecta does not use advertising cookies, analytics cookies, behavioural tracking cookies, third-party marketing pixels or social media tracking widgets.
Detailed information is available in the Reflecta Cookie and Similar Technologies Notice.
Annex D – Service Provider and Subprocessor Summary
| Provider | Function | Data Categories | Region / Location |
|---|---|---|---|
| Neon | PostgreSQL database hosting | Account, Workspace, Subscription metadata, prompts, metadata | London, United Kingdom |
| Cloudflare R2 | file storage | uploaded Assets, generated Outputs | Eastern Europe region |
| Cloudflare Workers | application/API processing, routing, security | request data, transmitted Content, technical metadata | Cloudflare network |
| Replicate | AI infrastructure and model processing | images, prompts, generation parameters, Outputs | may include processing outside UK/EEA/UAE |
| Sentry | crash and error monitoring | crash reports, stack traces, device/app data, IP if captured | United States / provider infrastructure |
| Stripe | website payments and Subscriptions | payment metadata, Subscription data, customer ID | Stripe infrastructure |
| Apple | iOS app distribution and Apple IAP | Apple transaction and Subscription data | Apple infrastructure |
| abuse@tryreflecta.app / support@tryreflecta.app | support and communications | email, message content, attachments | Google infrastructure, UAE |
This list may be updated from time to time.
Annex E – Image Processing Notice for In-App Display
Reflecta uses uploaded images and prompts to generate AI-powered creative Outputs. Your images may be stored in your Workspace, transmitted to service providers for AI processing, used to create descriptions or metadata, and stored as generated Outputs in your library.
Reflecta does not use your images to identify you, verify your identity, compare you with other users or create a facial recognition database.
By uploading an image, you confirm that you have the necessary rights and consents to upload and process that image, including where the image depicts another person.
You must not upload images of minors.
You may delete uploaded images and generated Outputs through the Services or request Account deletion as described in the Privacy Notice.
Annex F – Privacy Notice at Collection
We collect the following Personal Data when you use Reflecta:
- Account information, such as email address, password hash and Account ID;
- Workspace information, such as organization name, Subscription tier and Credits;
- uploaded images and related metadata;
- prompts, style selections and generation settings;
- generated Outputs;
- payment and Subscription metadata;
- support communications;
- abuse, takedown and legal complaint communications;
- limited technical logs and crash reports.
We use this information to provide, operate, secure and support the Services, generate Outputs you request, manage Subscriptions and Credits, respond to support and legal requests, prevent abuse, comply with law and maintain service reliability.
We do not sell Personal Data. We do not use uploaded images or generated Outputs for third-party marketing. We do not use advertising cookies or analytics cookies at launch.
More details are available in the full Privacy Notice.