← Back|Spottd

Legal

Privacy Policy

Last updated: 12 April 2026

1. Who we are

Spottd (“we”, “us”, “our”) is an AI-powered fashion search service that helps you find clothing and accessories from photos or descriptions. We are the data controller for the personal data described in this policy. Contact us at hello@spottd.app.

2. What data we collect

  • Account data — your name and email address when you create an account.
  • Search data — images you upload, URLs you paste, and text queries you submit.
  • Usage data — search history, saved favourites, and size preferences you store in your profile.
  • Device data — IP address, browser type, and operating system, collected automatically when you use the service.
  • Cookies — small files stored in your browser. See Section 6 for details.

We do not collect payment information — Spottd links to third-party retailers and does not process purchases.

3. How we use your data

  • To provide the search service — analysing images and returning matching products.
  • To personalise results — applying your size and budget preferences.
  • To send transactional emails — account verification, password resets, and (where you opt in) product updates.
  • To improve the service — aggregate, anonymised analytics on how features are used.
  • To comply with legal obligations.

4. Legal basis for processing (GDPR)

If you are in the UK or EU, we rely on the following legal bases:

  • Contract — processing your account data and searches to deliver the service you signed up for.
  • Legitimate interests — detecting abuse, improving reliability, and securing the platform.
  • Consent — analytics cookies and marketing emails (you can withdraw at any time).

5. Third parties we share data with

  • Anthropic — images and text are sent to Claude AI for fashion attribute extraction. Anthropic does not train on API inputs by default. Anthropic Privacy Policy.
  • Resend — transactional email delivery (verification, password reset). Resend Privacy Policy.
  • PostHog — product analytics (only if you accept analytics cookies). PostHog Privacy Policy.
  • Vercel — frontend hosting and edge infrastructure. Vercel Privacy Policy.
  • Railway — backend hosting and database. Railway Privacy Policy.
  • Affiliate networks — when you click a “Shop” link, the retailer and affiliate network may set their own cookies and record the click for commission tracking.

We do not sell your personal data to any third party.

6. Cookies

We use the following categories of cookies:

  • Essential — required for the service to function (session authentication). These cannot be disabled.
  • Analytics — PostHog collects anonymised usage data to help us improve the product. Only set if you click “Accept all” in the cookie banner.

You can change your cookie preference at any time by clearing your browser's local storage for spottd.app, which will show the consent banner again on your next visit.

7. Data retention

  • Account data — retained until you delete your account.
  • Search history — retained for 90 days, then automatically deleted.
  • Email verification and password reset tokens — deleted after use or expiry (24 hours / 1 hour respectively).
  • Server logs — retained for 30 days for security purposes.

8. Your rights

If you are in the UK or EU, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, email us at hello@spottd.app. We will respond within 30 days.

You also have the right to lodge a complaint with your local supervisory authority (in the UK: the ICO).

9. Security

Passwords are hashed with bcrypt and never stored in plaintext. All data in transit is encrypted via HTTPS. We follow industry-standard practices to protect your data, but no system is completely secure — if you believe your account has been compromised, contact us immediately.

10. Children

Spottd is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. We will notify registered users of material changes by email. The “Last updated” date at the top of this page will always reflect the most recent version.

12. Contact

Questions about this policy? Email us at hello@spottd.app.