Your privacy is important to us. This Privacy Policy explains how Moire ("we," "us," or "our") collects, uses, discloses, and safeguards your information when you use our AI-powered fashion design platform.
1. Information We Collect
1.1 Information You Provide
We collect information you voluntarily provide when you:
- Create an account: Name, email address, and authentication credentials via our identity provider (Clerk)
- Make a purchase: Billing information processed securely via Stripe (we do not store full payment card details)
- Use our services: Text prompts, style preferences, and design parameters you submit for AI image generation
- Contact us: Information included in support requests, feedback, or other communications
1.2 Information Collected Automatically
When you access our platform, we automatically collect:
- Device information: Browser type, operating system, device identifiers
- Usage data: Pages visited, features used, generation history, interaction patterns
- Log data: IP address, access times, referring URLs, error logs
- Cookies and similar technologies: See our Cookie Policy for details
1.3 Information from Third Parties
We may receive information from:
- Authentication providers: Profile information from social login providers (Google, GitHub) if you choose to authenticate this way
- Payment processors: Transaction confirmation and billing status from Stripe
2. How We Use Your Information
We use the collected information to:
- Provide our services: Process your prompts, generate fashion designs, and deliver results
- Process transactions: Handle payments, manage subscriptions, and provide purchase confirmations
- Improve our platform: Analyze usage patterns, develop new features, and enhance AI model performance
- Communicate with you: Send service updates, respond to inquiries, and provide customer support
- Ensure security: Detect fraud, prevent abuse, and protect our users and platform
- Comply with legal obligations: Meet regulatory requirements and respond to lawful requests
3. AI Processing and Generated Content
3.1 How AI Generation Works
When you submit a prompt, your text is processed by our AI systems, which include:
- Google Gemini 2.5: For image generation based on your prompts
- Our fashion techniques database: Curated fashion techniques and garment construction data used to enhance prompt accuracy
3.2 Prompt and Generation Data
- Your prompts may be used to improve our services and AI models
- Generated images are associated with your account for your access and portfolio features
- We do not sell your prompts or generated content to third parties
- You may request deletion of your generation history at any time
4. Information Sharing and Disclosure
We do not sell your personal information. We may share your information with:
4.1 Service Providers
- Clerk: User authentication and identity management
- Stripe: Payment processing and subscription management
- Google Cloud: AI image generation (Gemini/Imagen)
- Railway: Application hosting and database management
- Cloudflare: CDN, security, and content delivery
- PostHog: Product analytics (privacy-focused)
4.2 Legal Requirements
We may disclose information when required by law or to:
- Comply with legal processes or government requests
- Protect our rights, privacy, safety, or property
- Enforce our Terms of Service
- Investigate potential violations or fraud
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your personal information becomes subject to a different privacy policy.
5. Data Retention
We retain your information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal and regulatory obligations
- Resolve disputes and enforce our agreements
- Support legitimate business purposes
Specific retention periods:
- Account data: Until account deletion plus 30 days for backup purposes
- Generation history: 24 months, or until you request deletion
- Transaction records: 10 years for tax and legal compliance
- Analytics data: Aggregated and anonymized after 26 months
6. Your Privacy Rights
6.1 General Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete information
- Deletion: Request removal of your personal data
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain processing activities
- Withdraw consent: Where processing is based on consent
6.2 European Economic Area (GDPR)
If you are in the EEA, you have additional rights under GDPR:
- Legal basis: We process your data based on contract performance, legitimate interests, consent, or legal obligation
- International transfers: Data may be transferred to the United States; we use standard contractual clauses to protect your data
- Supervisory authority: You may lodge a complaint with your local data protection authority
6.3 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it's used
- Request deletion of your personal information
- Opt-out of the sale or sharing of personal information
- Non-discrimination for exercising your privacy rights
We do not sell personal information as defined by the CCPA.
6.4 Exercising Your Rights
To exercise any privacy rights, contact us at:
- Email: [email protected]
- Response time: Within 30 days (45 days for complex requests)
- Verification: We may need to verify your identity
7. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication via Clerk with multi-factor options
- PCI DSS compliant payment processing via Stripe
- Regular security assessments and monitoring
- Access controls and employee training
While we strive to protect your information, no method of transmission or storage is 100% secure. See our Security page for more details.
8. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at [email protected].
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States. These countries may have different data protection laws. We ensure appropriate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with all service providers
- Compliance with applicable data transfer frameworks
10. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing any personal information.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting the updated policy on this page
- Updating the "Last updated" date
- Sending an email notification for significant changes
Your continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or our data practices:
- Email: [email protected]
- Data Protection Officer: Pomelo Studio Team at [email protected]
- Mailing Address:
Pomelo Studio
10 bis rue Mehul
93500 Pantin
France