Zyah · Privacy
Zyah Privacy Policy
Effective date: 1 June 2026 · Last updated: 12 September 2026
1. Who we are
Zyah is an AI wardrobe-assistant app published by Pinegrass Technologies Private Limited (“Pinegrass”, “we”, “us”), a company incorporated in India under CIN U62011MN2026PTC015607, with its registered office in Imphal East, Manipur, India.
Pinegrass is the data fiduciary for Zyah under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). This policy explains what Zyah collects, why, who it is shared with, and the rights you hold. For company-level practices, see the Pinegrass privacy notice.
2. Data we collect
Account information. Your name and email address, collected when you sign in with Google Sign-In via Firebase Authentication.
Profile data. Gender, age range, height, weight, style personality, occasion preferences, and colour preferences — provided by you during onboarding and used to personalise outfit suggestions.
Wardrobe photos. Images of clothing items you capture or upload to build your digital wardrobe. Analysed by AI to detect category, colour, pattern, and sleeve length.
Selfie / profile photo. An optional photo used only to generate Virtual Try-On images. Processed by AI and stored on Cloudinary; it is deleted when you delete your account.
Outfit logs. Dates, items worn, occasion, and any notes you record to track your wear history.
Shopping list. Items, URLs, prices, and images you save to your in-app shopping list.
Preferences & ratings. Occasions you enter, ratings you give to suggestions, and wear-frequency data used to learn your style over time.
Optional connected data. If you opt in to Gmail order import, an encrypted OAuth refresh token and extracted order item details are processed; email bodies are not retained. If you opt in to anonymous peer aggregation, Zyah stores coarse style and occasion signals and never includes your photos or item names in aggregate results.
Purchases. Product, entitlement, transaction status, and expiry information needed to provide and restore Zyah Pro. Google Play handles payment credentials; Zyah does not receive complete card details.
Location for weather. If you enable weather-aware suggestions, location coordinates are sent to the weather service and the device geocoding service. Android build 15 and later round coordinates to a 0.1-degree grid before these requests. Earlier builds can send the coordinates returned by the device, which may be precise. Zyah does not store these coordinates on its servers. Open-Meteo may retain request logs, including coordinates and IP addresses, for up to 90 days.
Optional voice input. When you tap the microphone and grant permission, your device speech-recognition service converts speech into text. Depending on your device and settings, Apple, Google, or the configured speech provider may process audio on its servers under its own privacy and retention settings. Zyah does not save the audio. Text you submit is processed and retained like typed occasion or styling input. You can use typed input instead.
Optional calendar context. With permission, Zyah reads calendar events on your device to suggest an occasion. Event titles are analysed on the device; raw titles, notes and attendees are not uploaded. When you use a suggested occasion to create an outfit plan, that occasion category and the selected plan date are processed and stored with your plan. Calendar access can be disabled in device settings.
Push notification token. An opaque Expo push token, stored only if you grant notification permission, used solely to deliver reminders you request.
Crash & performance telemetry. Stack traces and request timings sent to Sentry. Personally-identifiable fields are stripped before transmission.
Usage & device data. With your analytics consent, pseudonymous feature-use events, platform, and app version are sent to PostHog. A one-way device fingerprint hash, IP-derived rate-limit counters, and daily feature counts are used to prevent abuse and enforce usage limits.
3. How we use data
We use the data above strictly to:
- authenticate you and let you access your wardrobe across devices;
- build and organise your digital wardrobe, outfit logs, and shopping list;
- generate AI-assisted outfit suggestions, smart recommendations, event-planner outfits, shopping check results, and virtual try-on images using your wardrobe and photos;
- learn your style so suggestions improve over time;
- send wear-frequency insights, care reminders, and nudges — only with your explicit notification consent;
- show local weather for outfit context, only if you grant location permission;
- diagnose crashes and improve app reliability.
- provide, restore, and verify Zyah Pro access and enforce free-tier or paid-tier limits.
We do not sell your data, do not use it for advertising, and do not train any third-party AI model on your photos or personal data.
4. AI processing & third-party processors
To generate outfit analyses, suggestions, and virtual try-on images, Zyah sends relevant content to the following data providers. Our application processors handle data on our behalf; device speech services and direct weather requests are also subject to the provider practices described above. Some are located outside India; by using Zyah you consent to this cross-border transfer under DPDP §16.
- Google Gemini API (United States) — outfit analysis, smart suggest, event planner, shopping check, and virtual try-on. Wardrobe images and your selfie (when you use Try-On) are sent to Gemini only when you invoke these features.
- Firebase Authentication / Google Sign-In (United States) — sign-in and session management only.
- Apple — Sign in with Apple authentication on supported devices.
- Cloudinary (United States) — image storage for wardrobe items, profile photo, and try-on outputs.
- Railway (United States) — application hosting and MySQL database where your account, wardrobe metadata, outfit logs, and shopping list are stored.
- Open-Meteo (European Union) — weather forecasts using the location handling described above. The direct request also exposes your network IP address to the service.
- Device speech provider — optional speech-to-text processing through Apple, Google, or the service configured on your device, as described above.
- Expo Push Service (United States) — delivers push notifications to your device, if you have enabled them.
- Sentry (United States / European Union) — crash and performance telemetry, with PII auto-redacted before transmission.
- PostHog — consent-gated product analytics routed through Pinegrass servers; events do not contain wardrobe photos, item names, or AI prompts.
- RevenueCat — purchase and entitlement management. Google Play processes the payment.
- FASHN AI — virtual try-on processing when that provider is available; Zyah falls back to Google Gemini when necessary.
5. Legal basis & consent
We process your personal data on the basis of your free, specific, informed, and unambiguous consent under DPDP §6. You can withdraw consent at any time — revoke push, location, or camera permissions in your device settings, or delete your account to withdraw all consent. Withdrawal does not affect processing that took place while consent was in force.
Optional features (push notifications, location, camera) each require a separate consent at the point of use.
6. Data retention
We keep your data only as long as your account is active or as required by law:
| Data category | Retention |
|---|---|
| Account profile, wardrobe, logs, shopping list | Until account deletion |
| Profile photo & try-on outputs (Cloudinary) | Until you delete the item or your account |
| Sentry crash & performance telemetry | 90 days |
| Database backup snapshots | 30 days rolling |
| Records required for legal or fraud purposes | As required by law |
When you delete your account, all data tied to your user ID is cascade-deleted from the primary database within 24 hours, and all images you uploaded are removed from Cloudinary within 7 days. Backup snapshots roll over within 30 days.
7. Data security
All data in transit is encrypted using HTTPS/TLS 1.2 or higher. Database and image storage are encrypted at rest. Access to personal data is restricted to authorised personnel who need it to operate the service. We never see your Google password — sign-in is delegated entirely to Firebase/Google.
In the event of a personal-data breach, we will notify affected users and the Data Protection Board of India within 72 hours of becoming aware of it, as required by DPDP §8(6).
8. Your rights under the DPDP Act, 2023
Under the DPDP Act, 2023, you have the right to:
- Access (§11): view all your personal data from within the app.
- Correction & erasure (§12): edit your profile, wardrobe, logs, or shopping list at any time; or delete your account from Profile → Delete Account.
- Withdraw consent (§6): revoke specific permissions in device settings, or delete your account to withdraw all consent.
- Nominate a representative (§14): designate another individual to exercise these rights on your behalf — email the Grievance Officer with the nominee’s name and contact details.
- Grievance redressal (§13): contact our Grievance Officer below. We acknowledge within 48 hours and resolve within 30 days.
- Escalate to the DPB: if your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India under §27 at www.dpb.gov.in.
To exercise any right, email privacy@pinegrass.in with the request type in the subject line.
9. Children's privacy
Zyah is intended for users aged 18 and over. It is not directed at children, and we do not knowingly process personal data from anyone under 18 without verifiable parental consent (DPDP §9). If you believe a minor has signed up without consent, contact the Grievance Officer and we will delete the account.
10. Grievance Officer
Designated under section 8(9) of the DPDP Act, 2023 as the point of contact for grievance redressal on behalf of the Data Fiduciary.
11. Changes to this policy
We may update this policy from time to time. When we make material changes (new third-party processors, new categories of data), we will flag it in-app with a one-time notice and update the “Last updated” date above. The prior version is available on request.
12. Governing law
This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. Disputes relating to this policy shall be subject to the exclusive jurisdiction of the courts at Imphal, Manipur.
13. Contact
For any privacy question or data request relating to Zyah, email privacy@pinegrass.in. General queries: connect@pinegrass.in.