Privacy Policy: How we handle data across the platform and website
Effective Date: July 21, 2026
The F* Word, Inc. ("The F* Word," "we," "our," or "us") is a California corporation that provides AI-powered fashion workflow software, websites, applications, APIs, integrations, embedded widgets, and related services.
This Privacy Policy explains what personal data we collect, where it comes from, why and on what legal basis we process it, who receives it, how long we retain it, how we obtain and record consent, how you can change your preferences, and how you can request access, correction, or deletion.
This Privacy Policy applies to our websites, including thefword.ai, our applications, APIs, integrations, widgets, customer support, sales activities, and other services that link to this Privacy Policy, collectively, the "Services."
Who Is Responsible for Your Data
The F* Word, Inc. is the controller or business responsible for personal data collected through our public website, direct account relationships, marketing, billing, and product-led growth activities.
Where we process personal data solely on behalf of an enterprise customer and according to that customer’s instructions, we act as a processor or service provider. Those activities may also be governed by a Data Processing Addendum and the applicable customer agreement.
The F* Word, Inc. 1461 Acton Crescent Berkeley, CA 94702-1918 United States
Privacy contact: support@thefword.ai
EEA and UK Representatives
EEA representative: [INSERT APPOINTED EEA REPRESENTATIVE LEGAL NAME, POSTAL ADDRESS, AND EMAIL]
UK representative: [INSERT APPOINTED UK REPRESENTATIVE LEGAL NAME, POSTAL ADDRESS, AND EMAIL]
EEA and UK users may contact The F* Word directly or contact the applicable representative.
How to Request Deletion of Your Data
You may request deletion of your personal data or account at any time.
Email support@thefword.ai with the subject line “Data Deletion Request.” Include the email address associated with your account, the login method you used, and a brief description of the data or account you want deleted.
You may also use an account-deletion function within the Services if one is available.
We may ask you to verify your identity before completing the request. We will delete personal data that we are required to delete, subject to limited legal exceptions, including fraud prevention, security, tax, accounting, dispute resolution, and legal recordkeeping requirements.
More detailed instructions appear under “Data Deletion Requests” below.
Personal Data We Collect
The personal data we collect depends on how you interact with us.
Account and login information
- email address
- username
- password in encrypted or hashed form, where applicable
- authentication tokens
- provider-specific login identifiers
- login history
- account and workspace identifiers
- account status and preferences
When you use a third-party login provider, we receive only the information needed to authenticate you, such as your email address and limited technical authentication data. Beyond that email and authentication data, we do not request names, friend lists, contacts, private messages, social posts, unrelated photos, advertising profiles, or other unrelated account content from third-party login providers.
Profile and business information
- name
- company or brand name
- job title
- business email address
- business phone number
- country or region
- team membership and role
- information you provide during onboarding, sales, contracting, or support
Subscription and transaction information
- selected plan
- trial and subscription status
- credits or usage allowance
- transaction and invoice records
- payment status
- renewal and cancellation information
- billing contact details
Payment card information is generally processed by our payment providers. We do not need to store complete payment-card numbers.
Product content
- prompts and instructions
- fashion briefs
- moodboards
- sketches and garment images
- photographs
- design files
- tech packs
- measurements and specifications
- uploaded documents
- generated images and outputs
- feedback and annotations
User Content may contain personal data if you or another user includes personal data in an upload, prompt, image, document, or other submission.
Usage, device, and technical information
- IP address
- browser and device type
- operating system
- device and session identifiers
- approximate location inferred from IP address
- pages and features used
- clicks and navigation events
- referral source
- timestamps
- error and crash information
- security, authentication, and audit logs
- API activity and product telemetry
We do not intentionally collect precise location unless a feature clearly requires it and we provide an appropriate notice.
Communications and support information
- support requests
- emails and messages
- survey responses
- demo and sales requests
- feedback
- complaint and rights-request records
- information provided during customer research or training
Marketing and preference information
- marketing subscription choices
- cookie and tracking preferences
- consent and withdrawal records
- email delivery, open, and click information where permitted
- campaign source and referral information
Sensitive personal data
We do not intentionally request government identifiers, financial account credentials, medical information, biometric identifiers, precise geolocation, or other sensitive personal data unless a specific feature or legal requirement clearly requires it.
Images uploaded by users may depict identifiable individuals. Users are responsible for having the rights, permissions, and notices required to upload and process those images.
Third-Party Integrated Apps and Embedded Widgets
Different rules apply depending on whether you log in to The F* Word or use a limited integrated-app or widget experience.
Login integrations
When you use Facebook Login, Meta Login, or another authentication provider, we may receive your email address, a provider-specific account or authentication identifier, and an authentication token or similar technical information needed to complete login.
We use this information to authenticate you, connect the login to your The F* Word account, maintain security, and provide the Services.
Beyond the email address and limited authentication data required for login, we do not request or collect unrelated content from the login provider, such as names not needed for the login flow, friend lists, contacts, social posts, private messages, unrelated photos, advertising profiles, or other account activity.
Limited widgets and integrated-app experiences
For certain third-party integrated apps or embedded widgets that do not require a The F* Word login, we do not request names, email addresses, social-account details, contacts, or other direct identifiers from the third-party app.
Generated images may be stored as needed to generate and return the image in the widget response, operate the requested function, maintain service reliability, prevent misuse, and investigate technical errors.
If you separately create or access a The F* Word account, the account information you submit is processed under the other sections of this Privacy Policy.
Sources of Personal Data
- directly from you
- from your use of the website and Services
- from your employer or organization when it creates or administers your workspace
- from login and authentication providers
- from payment and billing providers
- from integrations you authorize
- from service providers acting on our behalf
- from business partners and referral sources
- from public business sources where permitted by law
We do not obtain personal data from third-party integrated apps beyond the limited email, authentication, or functionality information described in this Privacy Policy.
Why We Process Personal Data and Our Legal Bases
For EEA and UK users, the table below identifies our primary legal basis for each activity. More than one basis may apply where appropriate.
| Processing activity | Purpose | Primary legal basis |
|---|---|---|
| Account creation and login | Create, authenticate, and administer your account | Performance of a contract |
| Product and feature delivery | Generate outputs, store work, manage workflows, and provide requested functions | Performance of a contract |
| Subscription and billing | Process payments, credits, subscriptions, renewals, invoices, and cancellations | Performance of a contract; legal obligation |
| Customer support | Respond to requests, diagnose problems, and manage the customer relationship | Performance of a contract; legitimate interests |
| Security and fraud prevention | Protect accounts, detect misuse, investigate incidents, and enforce our Terms | Legitimate interests; legal obligation where applicable |
| Essential service analytics | Maintain availability, diagnose failures, and measure core service performance | Legitimate interests |
| Non-essential website analytics | Measure visitors and website engagement through non-essential technologies | Consent where required |
| Personalization technologies | Remember preferences and personalize non-essential experiences | Consent where required |
| Advertising and cross-site tracking | Deliver or measure targeted advertising, if introduced | Consent and required opt-out rights |
| Transactional communications | Send login, billing, security, support, and service messages | Performance of a contract; legitimate interests |
| Marketing communications | Send product news, offers, and promotional content | Consent, or legitimate interests where law permits |
| Free-tier model improvement | Improve internal models using eligible free-tier content where clearly disclosed | Consent where required |
| Paid-user model training | Train models using paid-user content only after a separate written opt-in | Consent |
| Product research and feedback | Understand product needs and improve usability | Legitimate interests; consent where required |
| Legal and compliance activities | Maintain records and respond to lawful requests | Legal obligation; legitimate interests |
| Business sale or restructuring | Evaluate or complete a merger, financing, acquisition, or asset sale | Legitimate interests; legal obligation |
| Consent records | Prove and administer consent, preferences, and withdrawals | Legal obligation; legitimate interests |
We do not use consent where processing is necessary to provide a service you requested. Accepting the Terms and acknowledging this Privacy Policy are separate from consenting to optional processing.
How We Obtain, Record, and Manage Consent
We use consent only when you have a real choice.
Signup records
When you create an account, we may ask you to agree to the Terms of Use, acknowledge that you have read this Privacy Policy, and make separate choices about optional processing.
Agreeing to the Terms creates the contractual relationship. Acknowledging the Privacy Policy confirms that the privacy notice was presented. Neither action, by itself, constitutes consent to optional cookies, marketing, or model training.
Optional consent requests are presented separately and are not preselected.
Consent records
When you provide, deny, change, or withdraw consent, we may record:
- your account identifier, email address, or a pseudonymous consent identifier
- the date and time in UTC
- the consent purpose and category
- the choice you made
- how and where the choice was made
- the version of the consent notice, Privacy Policy, or interface shown
- the applicable website, application, or signup flow
- your country, region, or language where relevant
- later changes or withdrawal of consent
These records allow us to demonstrate what choice was made and which notice was presented at that time.
Withdrawal and preference changes
You may withdraw consent at any time without affecting processing that occurred lawfully before withdrawal.
Depending on the consent, you may withdraw by opening Cookie Settings on our website, changing settings in your account or privacy dashboard, using the unsubscribe link in a marketing email, emailing support@thefword.ai, or withdrawing model-training consent through the applicable product control or support request.
Withdrawing consent will not prevent us from processing data that remains necessary to provide an active account, meet a legal obligation, protect the Services, or maintain a minimal suppression or consent record.
We make withdrawal reasonably as easy as giving consent.
Renewing consent
We may request consent again when the purpose changes materially, new categories of data or recipients are introduced, a consent record is no longer reliable, applicable law or regulatory guidance requires renewal, or a reasonable refresh period has passed.
Cookies and Consent Management Platform
We use a Consent Management Platform, or CMP, to manage website cookies and similar technologies where required.
Strictly necessary technologies
Strictly necessary technologies support website and app security, login and authentication, session management, load balancing, fraud prevention, remembering privacy choices, payment, and checkout functions.
These technologies may operate without consent where applicable law permits because the requested service cannot function properly without them.
Optional technologies
Optional technologies may include analytics, performance measurement, personalization, marketing, advertising, and cross-site or cross-context tracking.
For users in the EEA and UK, optional technologies remain disabled until the user provides affirmative consent through the CMP.
The CMP provides controls to accept optional technologies, reject optional technologies, select categories, review vendors and purposes, and change or withdraw choices later.
A persistent Cookie Settings link remains available on the website.
The CMP may store a pseudonymous consent identifier and the consent-record information described above. The cookie notice or CMP interface provides more specific information about the technologies, providers, purposes, and durations currently in use.
AI and Model Improvement
Free-tier users
We may use eligible free-tier prompts, uploads, outputs, feedback, and related content to develop, evaluate, test, or improve our internal models only where this has been clearly disclosed and the required legal basis has been established.
Where consent is required, we request a separate, specific opt-in and record that choice. Declining or withdrawing optional model-training consent does not affect processing completed lawfully before withdrawal.
Paid users and brands
We do not use private content from paid plans, brands, businesses, agencies, studios, teams, or enterprise customers to train, fine-tune, or improve AI or machine-learning models unless the customer provides a separate, express written opt-in.
This restriction covers private prompts, uploads, designs, images, tech packs, documents, outputs, customer data, and workspace data.
We may use service telemetry, security information, performance data, and aggregated or deidentified statistics to operate, secure, and improve the Services, provided that this activity does not use paid customer content for model training.
Third-party models and providers
Where third-party AI infrastructure is used to deliver a requested function, we require contractual and technical protections appropriate to the service. We do not authorize third-party providers to use paid customer content to train their general models unless the customer expressly agrees in writing.
California Sale and Sharing Disclosure
We do not sell personal information for money.
Based on our current practices, we do not share personal information for cross-context behavioral advertising as those terms are defined under California law.
We do not disclose personal information to third parties for their independent direct-marketing purposes.
If our practices change, we will update this Privacy Policy, provide the required notice, and provide any required Do Not Sell or Share My Personal Information control before the new practice begins.
How We Disclose Personal Data
- Microsoft Azure and other cloud, hosting, storage, and infrastructure providers
- authentication and identity providers
- payment, invoicing, and accounting providers
- email and transactional communication providers
- analytics and product-performance providers
- security, logging, monitoring, and fraud-prevention providers
- customer support and CRM providers
- AI infrastructure or processing providers used to deliver requested features
- integration partners you authorize
- professional advisers, auditors, insurers, and legal counsel
- regulators, courts, law enforcement, and government authorities
- prospective purchasers, investors, lenders, and advisers in a corporate transaction
Service providers are permitted to process personal data only for contracted purposes and subject to appropriate confidentiality, data-protection, and security obligations.
Where we act as a processor for an enterprise customer, our Data Processing Addendum governs our use of subprocessors and applicable notice or objection procedures.
Our current subprocessor list is available at: [INSERT PUBLIC SUBPROCESSOR LIST URL]
International Transfers and Data Residency
The F* Word is based in the United States. Personal data may be processed in the United States and in other countries where our service providers operate.
We use Microsoft Azure and other providers to host and process parts of the Services. Our confirmed primary Azure region or regions for EEA and UK personal data are: [INSERT CONFIRMED AZURE REGION OR REGIONS].
Unless an Order Form or Data Processing Addendum expressly commits to a specific region, we do not represent that personal data will remain exclusively within the EEA, UK, or another jurisdiction.
Where personal data is transferred from the EEA to a recipient outside the EEA that is not covered by an adequacy decision, we use an approved transfer mechanism, which may include the European Commission’s Standard Contractual Clauses.
For transfers from the UK, we use an approved UK transfer mechanism, such as the UK International Data Transfer Addendum or International Data Transfer Agreement, where required.
Where necessary, we also conduct transfer-risk assessments and adopt supplementary safeguards.
Information about contractual data residency for enterprise customers may be included in the applicable Order Form, security documentation, or Data Processing Addendum.
Retention Periods
We retain personal data only for as long as reasonably necessary for the disclosed purpose, including legal, accounting, security, and dispute-resolution requirements.
| Data category | Typical retention period |
|---|---|
| Account and profile information | While the account is active, then up to 6 years after closure where required for legal claims or contractual records |
| Login and authentication records | While the account is active, then normally up to 24 months, subject to security and legal needs |
| User Content and saved outputs | While needed to provide the Service, then deleted or deidentified according to account settings, contract terms, and backup cycles |
| Deleted account content in backups | Normally removed or overwritten within 90 days, unless legal preservation is required |
| Generated images from limited third-party widgets | Long enough to return and support the widget response, normally no more than 30 days unless saved to an account or a longer period is required for security or law |
| Product telemetry and analytics | Normally up to 24 months |
| Security, audit, and anti-fraud logs | Normally up to 24 months, or longer for an active investigation |
| Support requests and communications | Up to 3 years after the request or relationship ends |
| Sales and business-contact records | Up to 3 years after the last meaningful interaction, unless a longer contractual relationship exists |
| Marketing records | Until consent is withdrawn or you opt out, then a minimal suppression record may be retained |
| Cookie and consent records | Up to 6 years after the recorded choice, withdrawal, or end of the relationship |
| Billing, transaction, tax, and accounting records | Up to 7 years, or longer where required by law |
| Contracts and enterprise records | During the relationship, then up to 6 years or the applicable legal limitation period |
| Rights-request and deletion records | Up to 6 years after completion |
| Deidentified and aggregated information | May be retained longer where it cannot reasonably be used to identify an individual |
Actual retention may be shorter or longer where required by law, an enterprise contract, security needs, litigation hold, or a valid deletion request.
Children and Age Requirements
The Services are not directed to children under 13. We do not knowingly permit children under 13 to create accounts or submit personal data.
For users in the EEA and UK, we do not knowingly permit users under 16 to create an account unless a lower digital-consent age applies under local law and we have implemented a legally valid parental or guardian authorization process.
We may require users to confirm their age and country during signup, restrict EEA and UK account creation to users aged 16 or older, request parental or guardian authorization where legally permitted and operationally supported, and suspend or delete an account where the age requirement has not been met.
If you believe a child has provided personal data without appropriate authorization, email support@thefword.ai with the subject line “Child Privacy Request.” We will investigate and delete the data where required.
Your Privacy Rights
California rights
- know the categories and specific pieces of personal information collected
- know the sources, purposes, and categories of recipients
- request deletion
- request correction
- receive certain information in a portable format
- opt out of sale or sharing, if applicable
- limit certain uses of sensitive personal information, if applicable
- use an authorized agent
- receive equal service and pricing when exercising privacy rights
EEA and UK rights
- access personal data
- correct inaccurate personal data
- request deletion
- restrict processing
- object to processing based on legitimate interests
- object to direct marketing
- receive portable data
- withdraw consent
- complain to a supervisory authority
- receive information about applicable international-transfer safeguards
These rights may be subject to legal conditions and exceptions.
How to Exercise Your Rights
Submit a request by emailing support@thefword.ai with one of the following subject lines:
- Privacy Access Request
- Correction Request
- Data Deletion Request
- Consent Withdrawal
- Marketing Opt-Out
- Cookie Privacy Request
Include your full request, the email associated with your account if applicable, the relevant product, integration, or widget, and enough information for us to locate the applicable record.
We may verify your identity and authority before fulfilling a request. We use verification information only to process and document the request.
We respond within the period required by applicable law. Where legally permitted, we may extend the response period and will explain the reason.
Data Deletion Requests
You may request deletion at any time.
Account deletion
Email support@thefword.ai with the subject line “Data Deletion Request” and include your account email.
We delete or deidentify the account and associated personal data unless retention is required for security and fraud prevention, tax and accounting, legal claims or disputes, compliance records, enforcement of our agreements, or another lawful exception.
Facebook Login, Meta Login, or another connected login
Include the email associated with your The F* Word account, the login provider used, and the approximate date the account was connected if known.
Removing The F* Word from a third-party platform stops the connection but may not delete data already held by The F* Word. A direct deletion request is still required for data held by us.
Integrated apps and widgets
For a limited widget or integrated-app experience, include the app or widget name, the approximate date and time of use, any request or response identifier available, and a description of the generated image or content.
Where the experience did not collect an identifier, we may be unable to connect a particular image to a specific individual without enough information to locate it.
What happens next
We may confirm receipt, request identity verification, locate relevant records, delete or deidentify eligible data, direct service providers to delete eligible data, confirm completion, and explain any data we must retain and the reason.
We may retain a minimal record showing that the deletion request was completed.
Security
We use reasonable administrative, technical, and organizational measures designed to protect personal data, including access control, authentication, encryption, monitoring and logging, vulnerability management, employee and contractor access controls, vendor management, incident response, backup, and recovery.
No system is completely secure. You are responsible for protecting your login credentials and maintaining appropriate copies of important User Content.
Automated Processing
The Services use AI and automated systems to generate fashion-related content and workflow outputs.
We do not use these systems to make decisions that produce legal or similarly significant effects concerning individuals, such as employment, credit, housing, insurance, or access to essential services.
If this practice changes, we will provide any notices and controls required by applicable law.
Complaints
You may first contact us at support@thefword.ai.
EEA users may also complain to the data-protection authority in their country of residence, work, or the alleged infringement. UK users may complain to the UK Information Commissioner’s Office. California residents may contact the California Privacy Protection Agency or the California Attorney General where applicable.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the Services, legal requirements, vendors, or data practices.
When we make changes, we update the Effective Date, publish the updated version, provide additional notice where required, and request new consent if a change requires consent.
We retain version records so we can determine which notice and consent request applied at a particular time.
Contact Us
The F* Word, Inc. 1461 Acton Crescent Berkeley, CA 94702-1918 United States
Email: support@thefword.ai
EEA and UK representatives will be published when they are appointed
