Privacy Policy
Trendo Privacy Policy
Effective date: 24 June 2026 | Last updated: 24 June 2026
This Privacy Policy explains how Clover AI Tech FZCO ("Clover AI Tech", "the Company", "we", "us" or "our") collects, uses, shares, and protects personal data when you use the Trendo mobile application (the "App", bundle id com.trendo.trendoapp) on iOS and Android, and any related websites, features, and services that link to this policy (together, the "Service").
Trendo is operated under our "Clover & Fox" brand. This Privacy Policy should be read together with our Terms of Service, which govern your use of the Service. If you do not agree with this Privacy Policy, please do not use the Service.
Your privacy choices at a glance: you can delete your account and data at any time (Section 11); control location, try-on, and marketing consents (Sections 4, 5, and 13); exercise your GDPR/UK rights (Section 13); and exercise US state rights, including opting out of any "sale" or "share," in Section 15.
1. Who we are (Data Controller) and how to contact us
For the purposes of the EU and UK General Data Protection Regulation (GDPR/UK GDPR) and other data-protection laws, the data controller responsible for your personal data is:
- Clover AI Tech FZCO
- A free-zone company established in Dubai, United Arab Emirates
- Brand / website: Clover & Fox — cloverandfox.com
- Contact for privacy matters: info@cloverandfox.com
EU/UK representative: If we are required to appoint a representative under Article 27 GDPR / UK GDPR, their name and contact details will be published here and are available on request at info@cloverandfox.com.
We have not appointed a statutory Data Protection Officer where one is not legally required; you can reach our privacy contact at the email above. If you are in the EU/EEA or the UK and have a concern we have not resolved, you also have the right to contact your local data-protection authority (see Section 14).
2. Scope and key definitions
This policy applies to personal data we process about: (a) account holders (adults aged 18 or over) who use Trendo; and (b) child profiles created and managed by an account holder who is the child's parent or legal guardian (see Section 12, Children).
- "Personal data" means any information relating to an identified or identifiable individual.
- "Processing" means any operation performed on personal data (collecting, storing, using, sharing, deleting, etc.).
- "User content" means content you provide or upload, such as wardrobe photos, outfit images, try-on photos, and (in future) posts, comments, and likes.
- "Child profile" means a profile an adult account holder creates within their own account to organize the style of a child in their care. The child does not have their own account or login.
- "Service provider" / "processor" means a third party that processes personal data on our behalf and under our instructions.
3. The personal data we collect
We collect the categories of data below. Some you provide directly; some is generated automatically as you use the App; and some comes from third parties (such as sign-in providers and payment platforms).
3.1 Information you provide
- Account and profile data: name or nickname, email address, password (stored in hashed form), and authentication identifiers. We use your email to send a verification code at signup to confirm the address is genuine and deter automated abuse. If you sign in with Google or Apple, we receive your name, email, and a unique user ID from that provider.
- Style and preference data: gender, age, body type, skin/eye/hair attributes, chosen aesthetics, themes, and style preferences you select to personalize recommendations.
- Wardrobe photos and user content: photographs of your clothing and accessories that you upload, the AI-generated cut-outs derived from them, the outfits you build, and items you save.
- Try-on / face and body photos (current or future feature): if you use virtual try-on, a photo of yourself that you upload so that AI can generate images of you wearing garments. We treat face and body imagery as sensitive and process it only with your explicit consent (see Sections 4, 5, and 5a).
- Community content (future feature): if and when social features launch, posts, captions, comments, likes, and follows you create.
- Referral and promotional data (where offered): if you participate in a referral program, the contact details you provide for yourself and any person you refer.
- Communications: messages, feedback, and support requests you send to us.
3.2 Information collected automatically
- Location data: with your permission, your approximate and/or precise device location, used to provide local weather that informs styling recommendations. You can change location permissions in your device settings at any time. (Precise geolocation is treated as sensitive personal information under some US state laws — see Section 15.)
- Usage and interaction data: how you use the App — screens viewed, features used, in-app search history, items you tap, and (for shopping) outbound clicks on merchant and affiliate links, including the brand, item, price, shop, category, and position of the item tapped. Outbound-click tracking is subject to your applicable consent settings.
- Behavioral / "taste profile" data: inferences we derive from your activity and preferences to build a personalized style and recommendation profile (this is profiling for personalization; see your rights in Section 13).
- Device and technical data: device model, operating system, app version, language, time zone, device and other identifiers, advertising identifiers (subject to your permission), and IP address.
- Diagnostics: crash logs, error reports, performance data, and other diagnostic information.
3.3 Information from third parties
- Sign-in providers (Google, Apple): basic profile and authentication data as described above.
- Payment / app-store platforms (Apple, Google): your subscription status and purchase history. We do not receive or store your full payment-card details — these are handled by Apple and Google.
- Attribution / analytics partners (e.g., AppsFlyer): information about how you found and installed the App and how you interact with it, subject to your tracking choices.
3.4 Child-profile data
Where an account holder creates a child profile, the data in that profile may include the child's name or nickname, age, gender, body type, chosen themes/style preferences, and any wardrobe images the parent uploads. This data is provided by, and processed under the consent and control of, the parent or guardian (see Section 12).
4. How and why we use your data — and our legal bases
Under the GDPR we must have a lawful basis for each use of your data. The list below sets out what we do and the legal basis we rely on.
- Create and manage your account; authenticate sign-in; verify your email at signup. Legal basis: performance of a contract and legitimate interests in preventing fraud and bot signups.
- Provide the core Service — AI styling feedback and scores, wardrobe recognition and cut-outs, outfit recommendations and creation, calendar planning, and the inspiration feed. Legal basis: performance of a contract.
- Personalize the Service — build and apply your taste profile, tailor recommendations and the inspiration feed to your preferences. Legal basis: performance of a contract and our legitimate interests in providing a relevant, useful product; where required, consent. You may object to personalization profiling based on our legitimate interests (see Section 13).
- Provide virtual try-on using a photo of you. Legal basis: your explicit consent (given the sensitive nature of face/body imagery); you can withdraw consent at any time by deleting the relevant images or your account.
- Provide local weather-based suggestions using location. Legal basis: your consent (device location permission).
- Process subscriptions and purchases (Trendo Pro), validate receipts, and prevent abuse of free trials. Legal basis: performance of a contract and legitimate interests in preventing fraud.
- Operate shopping and affiliate links, including measuring outbound clicks and closed-loop affiliate attribution. Legal basis: legitimate interests in operating and funding the Service; where required for tracking/identifiers, consent.
- Operate referral and promotional programs (where offered) — process your and the referred person's contact details to run the program and credit referrals. Legal basis: performance of a contract and legitimate interests; you must only refer people who are happy to be contacted.
- Operate social/community features (where offered) — display the content and profile information you choose to share with other users. Legal basis: performance of a contract, and your consent for content you choose to make public; you control what you share and can delete it.
- Develop, train, and improve our AI models, recommendations, and features. We train and improve our models using usage data and, for ordinary (non-sensitive) user content, in de-identified or aggregated form, or with your consent where required. We do not use virtual try-on face/body images, or child-profile data, to train our AI models. Legal basis: our legitimate interests in improving and securing the Service, or consent where the law requires. EEA/UK users may object to legitimate-interests-based training (see Section 13).
- Maintain security, prevent fraud and abuse (including bots and trial abuse), and protect the Service and our users. Legal basis: legitimate interests and legal obligation.
- Diagnose crashes, debug, and improve reliability and performance. Legal basis: legitimate interests.
- Communicate with you — service messages, security and transactional notices. Legal basis: performance of a contract and legitimate interests.
- Send marketing, referral, and promotional communications. For email marketing to EEA/UK recipients, we send messages only with your consent (or under the limited "soft opt-in" for existing customers regarding our own similar products); every marketing message includes an unsubscribe link. Elsewhere we may rely on consent or legitimate interests; you can opt out at any time.
- Comply with legal obligations and enforce our Terms, including responding to lawful requests and exercising or defending legal claims. Legal basis: legal obligation and legitimate interests.
- Effect a corporate transaction (merger, acquisition, financing, or asset sale). Legal basis: legitimate interests (see Section 7.4).
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to such processing as described in Section 13.
5. Special category / sensitive data
Photographs of your face or body that you upload for virtual try-on are sensitive (special category) data because they can reveal characteristics about you. We process such images only where you have given your explicit consent (GDPR Art. 9(2)(a)) and solely to provide the feature you requested. We do not use them for advertising, we do not use them to train our AI models, and we do not sell them. You can withdraw consent at any time by deleting the images or your account (see Sections 11 and 13).
5a. Biometric information (US states)
If and to the extent any face or body image you provide for virtual try-on is processed in a way that captures a "biometric identifier" or "biometric information" under laws such as the Illinois Biometric Information Privacy Act (BIPA) or comparable Texas or Washington laws, the following apply: (i) we collect and use it only with your prior consent and solely to generate the try-on images you request and to operate and improve that feature; (ii) we and our processors do not sell, lease, trade, or otherwise profit from your biometric data; (iii) we retain such data only as long as needed to provide the feature and in any event destroy it when the purpose for collecting it is satisfied or within 3 years of your last interaction with the feature, whichever occurs first, after which it is permanently deleted; and (iv) you may withdraw consent and delete the images at any time. Our virtual try-on is intended to generate images and not to create a facial-recognition template; where any biometric identifier is nonetheless involved, your consent under Section 7.2 of the Terms is intended to serve as a written release to the extent permitted by applicable law for its collection, storage, and use.
6. AI and automated processing
Trendo is an AI-powered product. To deliver its features, your content and inputs may be processed by us and by trusted AI service providers acting as our processors:
- OpenAI — language and image processing for styling insights, recognition, and content generation.
- Google (Gemini) — AI processing for styling and content features.
- fal.ai (FAL) — AI image generation, including garment cut-outs and (for future try-on) generating images of you wearing garments.
We send these providers only the data needed to perform the requested task (for example, an image URL and structured prompt). We do not permit them to use your personal data for their own independent purposes, and we contract for appropriate safeguards.
Some imagery we display as inspiration content depicts AI-generated, synthetic people who are not real individuals. This imagery is produced by our own AI generation pipeline from generic prompts. It is not generated from your photos, and your try-on or profile images are never used to create public inspiration content. AI-generated inspiration images are labelled as such within the app.
Automated processing. Our AI produces styling feedback, scores, recommendations, generated images, and inspiration content for personalization, information, and entertainment only. We do not use solely-automated processing to make decisions that produce legal effects concerning you or similarly significantly affect you, except limited automated checks to prevent fraud, abuse, and bots and to secure the Service (for example, verifying your email at signup and detecting trial abuse); where such a check restricts your access, you may contact us to request human review. AI outputs may be imperfect or inaccurate; see our Terms for the applicable disclaimers.
As noted in Section 4, we may use usage data and de-identified or aggregated user content to develop, train, and refine our AI models and recommendations; any model or learning derived from this processing is retained even after you delete your account or content, because it no longer identifies you. We do not use try-on face/body images or child-profile data for model training.
7. How we share your data
We do not sell your personal data for money. We may "share" or "sell" limited identifiers as those terms are broadly defined under certain US state laws (for example, for analytics and attribution), and we offer you the right to opt out (see Section 15). We share personal data only as described below.
7.1 Service providers / processors
We share data with vendors that process it on our behalf, under contract and our instructions, including:
- Cloud hosting, storage, and databases: Amazon Web Services (AWS), with primary hosting currently in the EU (region eu-west-1); we may use other AWS regions as the Service evolves.
- AI providers: OpenAI; Google (Gemini); fal.ai (FAL).
- Attribution and analytics: AppsFlyer (see Section 9).
- Crash reporting and logging: Sentry; Better Stack.
- Payments and sign-in: Apple; Google.
- Weather: a third-party weather API (location used to return a local forecast).
7.2 Affiliate networks and merchants
When you tap a shopping link, you may be taken to a third-party merchant's site or app. Some links are affiliate links that earn us a commission. To attribute clicks and purchases, limited information (such as a click identifier) may be shared with affiliate networks and merchants — for example, CJ (Commission Junction), AliExpress, and other networks or merchants we add over time. These third parties are independent controllers of any data you provide to them, and their own privacy policies apply. See Section 8 of our Terms regarding affiliate disclosures.
7.3 Legal, safety, and compliance
We may disclose personal data where we believe in good faith it is necessary to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of the Company, our users, or the public.
7.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your personal data may be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy or notify you of any material change.
7.5 With your direction (social features — future)
If you choose to use community/sharing features, content you post and your associated profile information will be visible to other users as you direct. Do not post content you do not wish to share.
8. International data transfers
We operate internationally. Because the Company is established in the United Arab Emirates (which does not have an EU adequacy decision), and because some of our providers operate elsewhere, your personal data may be processed in, or transferred to, countries other than your own — including the UAE, the European Union (where our primary hosting is located, AWS eu-west-1), and the United States (where certain AI, analytics, and infrastructure providers operate).
Where we make EEA, UK, or other transfer-restricted personal data available to our UAE establishment or to providers in countries without an adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA where applicable), adequacy decisions where they exist, or other lawful transfer mechanisms, together with supplementary measures where needed. You may request more information about these safeguards, or a copy where available, using the contact details in Section 1.
9. Cookies, SDKs, advertising identifiers, and tracking (ATT)
The App uses software development kits (SDKs) and similar technologies, in addition to any cookies used on our websites. In particular, our attribution and analytics partner AppsFlyer may use device and advertising identifiers to measure installs, attribute marketing, and understand usage.
EEA/UK consent. For users in the EEA/UK, where required by law we obtain your consent before storing or accessing non-essential identifiers on your device for analytics or attribution (for example, the AppsFlyer SDK), separately from the Apple ATT prompt; you may withdraw this consent in your device settings or by contacting us.
Apple App Tracking Transparency (ATT): on iOS, before any tracking that uses identifiers across apps and websites owned by other companies, we present Apple's ATT prompt. If you do not grant permission, we do not use the relevant identifiers to track you across other companies' apps and websites. On Android and in your device settings you can reset or limit your advertising identifier at any time.
On our website at cloverandfox.com, we honor the Global Privacy Control (GPC) signal as an opt-out of "sale"/"share" where required by law, and any cookies are described in a separate cookie notice on that site.
10. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, including:
- Account and profile data, wardrobe photos, and user content: for as long as your account is active. When you delete specific content, we delete it from active systems; when you delete your account, we delete or de-identify your personal data within a reasonable period, subject to the exceptions below.
- Try-on / face and body images: retained only as needed to provide the feature and then deleted or de-identified; you can delete them sooner at any time.
- Child-profile data: retained only as long as the parent keeps the child profile, and deleted promptly when the parent deletes the profile or the account. We keep child-profile data to the minimum necessary to provide the styling features.
- Transaction and subscription records: retained as required for accounting, tax, audit, and fraud-prevention purposes.
- Diagnostics and logs: retained for limited periods for security and reliability.
We may retain de-identified or aggregated data, and models or learnings derived from your data that no longer identify you, for analytics and product improvement. We may also retain limited data where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
11. Account and content deletion
You can delete your account and associated data at any time:
- In the App: Settings > Delete profile.
- On the web: https://www.cloverandfox.com/delete-your-account/.
- By email: contact info@cloverandfox.com.
You can delete a child profile and all of its data on its own, without deleting your account, in Settings; this removes the child's data from active systems. Deleting the parent's account removes the parent's data and any child profiles within it. Some residual data may persist in backups for a limited period before being overwritten, and we may retain limited records where the law allows or requires.
12. Children
Trendo is intended for adults aged 18 and over. Children may not create their own accounts or use the Service independently.
We recognize that a parent or legal guardian may wish to use Trendo to organize the style of a child in their care. To support this, an adult account holder may create one or more child profiles within their own account. By creating a child profile and entering a child's information, the account holder:
- confirms that they are the parent or legal guardian of the child (or otherwise have the authority to provide the child's data); and
- provides consent, as the holder of parental responsibility, to our processing of the child's data for the purposes in this policy, and attests to their authority to do so. The lawful bases are the account holder's consent (GDPR Art. 6(1)(a), with Art. 9(2)(a) explicit consent for any sensitive elements such as images), with Art. 8 GDPR cited as the rule governing the validity of that consent. The child remains a data subject whose rights are exercisable through the parent.
Where applicable law requires a particular method of verifiable parental consent (for example, under US COPPA for a child under 13), we obtain that consent through the mechanism we make available before processing the child's data for that purpose, and we rely on the account holder's attestation of parental authority. We keep a record of the consent obtained.
The child-profile data we process may include the child's name or nickname, age, gender, body type, chosen themes/style preferences, and any wardrobe images the parent uploads. We use this data only to provide the styling features within the parent's account. We minimize child-profile data and will not require you to provide more child information than is reasonably necessary to use the styling features. Where a child's image must be processed by an AI provider to perform a feature the parent requested, we send only what is necessary and require the provider to act as our processor and not to use the data for its own purposes. We do not use child-profile data for advertising or to build advertising or marketing profiles, do not disclose it to advertising or attribution partners, do not use it to train our AI models, and do not sell or "share" it.
As the parent or guardian, you may at any time review the personal information in the child profile, refuse to permit its further collection or use, and delete it on its own (in Settings) or by contacting info@cloverandfox.com — without having to delete your own account. If you believe a child's data has been provided to us without proper authority, please contact us and we will delete it.
13. Your privacy rights (GDPR / UK)
If you are in the EEA, the UK, or another region that grants these rights, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing, including processing based on our legitimate interests, profiling for personalization, AI-model-training based on legitimate interests, and any direct marketing;
- Data portability — receive certain data in a portable format;
- Withdraw consent at any time, where we rely on consent (this does not affect prior processing);
- Lodge a complaint with your local supervisory authority.
Withdrawing an optional consent (for example, location or virtual try-on) stops the related feature but does not affect your continued use of the rest of the Service. To exercise these rights, use the in-app and web deletion options above or email info@cloverandfox.com. We will respond within the time limits required by law (generally within one month under the GDPR). We may need to verify your identity before acting on a request, and we will not discriminate against you for exercising your rights.
Where the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), or the data-protection regime of the relevant UAE free zone, applies, we process personal data in accordance with it, and you may exercise the rights it provides by contacting us at the email above.
14. Supervisory authority
EEA and UK users have the right to lodge a complaint with their national data-protection authority if they believe our processing infringes applicable law. We would, however, appreciate the chance to address your concerns first — please contact us at info@cloverandfox.com.
15. U.S. state privacy rights (California / CCPA and similar laws)
This section applies to residents of California and other U.S. states with comprehensive privacy laws. In the past 12 months we have collected the categories of personal information described in Section 3, including: identifiers (name, email, user and device IDs); commercial information (purchase history); internet/network activity (app interactions, in-app search history, outbound clicks); geolocation (approximate and precise); audio/visual information (photos you upload); inferences (your taste/style profile); and sensitive personal information (precise geolocation and, for try-on, face/body images, used only to provide the features you request). We collect this from you, automatically, and from the third parties named in Section 3.3.
We retain each category of personal information for the periods described in Section 10 (Data Retention) or, where no fixed period applies, for as long as needed for the purpose collected and to meet legal obligations. We disclose the categories above to our service providers and processors for the business purposes described in Sections 4 and 7 (operating, securing, and improving the Service; payments; analytics; AI processing).
Sensitive personal information. We use sensitive personal information (precise geolocation; try-on face/body images) only to provide the features you request and for purposes that are exempt under applicable law (such as Cal. Civ. Code §1798.121(d)), and not to infer characteristics about you for advertising. Because of this, no separate "Limit the Use of My Sensitive Personal Information" link is required; you may nonetheless stop this processing by disabling the feature, revoking permissions, or deleting the relevant data. Precise geolocation is used solely to return local weather and is not shared with AppsFlyer or any advertising or attribution partner.
"Sale"/"share" and your opt-out. We do not sell your personal information for money. However, some U.S. state laws define a "sale" or "share" broadly to include disclosing identifiers to advertising and attribution partners for cross-context behavioral advertising or measurement, and our use of AppsFlyer and advertising identifiers could be considered a "sale" or "share" under those definitions. You may opt out: on iOS, decline the App Tracking Transparency prompt; on Android and other devices, limit or reset your advertising identifier in your device settings; on our website, we honor the Global Privacy Control (GPC) signal where required by law; and you may email info@cloverandfox.com with the subject "Do Not Sell or Share My Personal Information." We do not knowingly sell or share the personal information of consumers under 16, and child-profile data is never sold, shared, or disclosed to advertising or attribution partners. If a user indicates they are under 16, we do not sell or share their personal information.
Subject to applicable law, U.S. state residents have the right to know/access, delete, and correct their personal information, to opt out of sale/share and of targeted advertising, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. To exercise them, use the deletion options in Section 11 or email us. You may use an authorized agent, and we will verify requests as required. If we deny a request, you may appeal by replying to our decision.
Notice of financial incentive: if we later launch a referral or rewards program that offers a price or service difference in exchange for personal information, we will provide any "notice of financial incentive" required by applicable US state law at that time.
16. Security
We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls, hashed passwords, and hosting with a reputable cloud provider. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If a personal-data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected users, without undue delay and in accordance with applicable law. Please keep your account credentials confidential and notify us promptly of any suspected unauthorized use.
17. Third-party links and services
The Service contains links to third-party websites, merchants, and services (including shopping and affiliate links) that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Please review their policies before providing them with personal data.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where required by law, provide additional notice (for example, in the App or by email). Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy, except where additional consent is required.
19. Contact us
If you have questions, requests, or complaints about this Privacy Policy or our handling of your personal data, contact:
- Clover AI Tech FZCO (Clover & Fox)
- Email: info@cloverandfox.com
- Website: cloverandfox.com
- Account deletion: https://www.cloverandfox.com/delete-your-account/
This Privacy Policy works together with our Terms of Service.