Privacy Policy: How we handle data across the platform and website

Clear information on what we collect, how we use it, how long we keep it, and how customers stay in control.

Effective Date: July 21, 2026

The F* Word, Inc. ("The F* Word," "we," "our," or "us") is a California corporation that provides AI-powered fashion workflow software, websites, applications, APIs, integrations, embedded widgets, and related services.

This Privacy Policy explains what personal data we collect, where it comes from, why and on what legal basis we process it, who receives it, how long we retain it, how we obtain and record consent, how you can change your preferences, and how you can request access, correction, or deletion.

This Privacy Policy applies to our websites, including thefword.ai, our applications, APIs, integrations, widgets, customer support, sales activities, and other services that link to this Privacy Policy, collectively, the "Services."

Who Is Responsible for Your Data

The F* Word, Inc. is the controller or business responsible for personal data collected through our public website, direct account relationships, marketing, billing, and product-led growth activities.

Where we process personal data solely on behalf of an enterprise customer and according to that customer’s instructions, we act as a processor or service provider. Those activities may also be governed by a Data Processing Addendum and the applicable customer agreement.

The F* Word, Inc. 1461 Acton Crescent Berkeley, CA 94702-1918 United States

Privacy contact: support@thefword.ai

EEA and UK Representatives

EEA representative: [INSERT APPOINTED EEA REPRESENTATIVE LEGAL NAME, POSTAL ADDRESS, AND EMAIL]

UK representative: [INSERT APPOINTED UK REPRESENTATIVE LEGAL NAME, POSTAL ADDRESS, AND EMAIL]

EEA and UK users may contact The F* Word directly or contact the applicable representative.

How to Request Deletion of Your Data

You may request deletion of your personal data or account at any time.

Email support@thefword.ai with the subject line “Data Deletion Request.” Include the email address associated with your account, the login method you used, and a brief description of the data or account you want deleted.

You may also use an account-deletion function within the Services if one is available.

We may ask you to verify your identity before completing the request. We will delete personal data that we are required to delete, subject to limited legal exceptions, including fraud prevention, security, tax, accounting, dispute resolution, and legal recordkeeping requirements.

More detailed instructions appear under “Data Deletion Requests” below.

Personal Data We Collect

The personal data we collect depends on how you interact with us.

Account and login information

  • email address
  • username
  • password in encrypted or hashed form, where applicable
  • authentication tokens
  • provider-specific login identifiers
  • login history
  • account and workspace identifiers
  • account status and preferences

When you use a third-party login provider, we receive only the information needed to authenticate you, such as your email address and limited technical authentication data. Beyond that email and authentication data, we do not request names, friend lists, contacts, private messages, social posts, unrelated photos, advertising profiles, or other unrelated account content from third-party login providers.

Profile and business information

  • name
  • company or brand name
  • job title
  • business email address
  • business phone number
  • country or region
  • team membership and role
  • information you provide during onboarding, sales, contracting, or support

Subscription and transaction information

  • selected plan
  • trial and subscription status
  • credits or usage allowance
  • transaction and invoice records
  • payment status
  • renewal and cancellation information
  • billing contact details

Payment card information is generally processed by our payment providers. We do not need to store complete payment-card numbers.

Product content

  • prompts and instructions
  • fashion briefs
  • moodboards
  • sketches and garment images
  • photographs
  • design files
  • tech packs
  • measurements and specifications
  • uploaded documents
  • generated images and outputs
  • feedback and annotations

User Content may contain personal data if you or another user includes personal data in an upload, prompt, image, document, or other submission.

Usage, device, and technical information

  • IP address
  • browser and device type
  • operating system
  • device and session identifiers
  • approximate location inferred from IP address
  • pages and features used
  • clicks and navigation events
  • referral source
  • timestamps
  • error and crash information
  • security, authentication, and audit logs
  • API activity and product telemetry

We do not intentionally collect precise location unless a feature clearly requires it and we provide an appropriate notice.

Communications and support information

  • support requests
  • emails and messages
  • survey responses
  • demo and sales requests
  • feedback
  • complaint and rights-request records
  • information provided during customer research or training

Marketing and preference information

  • marketing subscription choices
  • cookie and tracking preferences
  • consent and withdrawal records
  • email delivery, open, and click information where permitted
  • campaign source and referral information

Sensitive personal data

We do not intentionally request government identifiers, financial account credentials, medical information, biometric identifiers, precise geolocation, or other sensitive personal data unless a specific feature or legal requirement clearly requires it.

Images uploaded by users may depict identifiable individuals. Users are responsible for having the rights, permissions, and notices required to upload and process those images.

Third-Party Integrated Apps and Embedded Widgets

Different rules apply depending on whether you log in to The F* Word or use a limited integrated-app or widget experience.

Login integrations

When you use Facebook Login, Meta Login, or another authentication provider, we may receive your email address, a provider-specific account or authentication identifier, and an authentication token or similar technical information needed to complete login.

We use this information to authenticate you, connect the login to your The F* Word account, maintain security, and provide the Services.

Beyond the email address and limited authentication data required for login, we do not request or collect unrelated content from the login provider, such as names not needed for the login flow, friend lists, contacts, social posts, private messages, unrelated photos, advertising profiles, or other account activity.

Limited widgets and integrated-app experiences

For certain third-party integrated apps or embedded widgets that do not require a The F* Word login, we do not request names, email addresses, social-account details, contacts, or other direct identifiers from the third-party app.

Generated images may be stored as needed to generate and return the image in the widget response, operate the requested function, maintain service reliability, prevent misuse, and investigate technical errors.

If you separately create or access a The F* Word account, the account information you submit is processed under the other sections of this Privacy Policy.

Sources of Personal Data

  • directly from you
  • from your use of the website and Services
  • from your employer or organization when it creates or administers your workspace
  • from login and authentication providers
  • from payment and billing providers
  • from integrations you authorize
  • from service providers acting on our behalf
  • from business partners and referral sources
  • from public business sources where permitted by law

We do not obtain personal data from third-party integrated apps beyond the limited email, authentication, or functionality information described in this Privacy Policy.

Why We Process Personal Data and Our Legal Bases

For EEA and UK users, the table below identifies our primary legal basis for each activity. More than one basis may apply where appropriate.

Processing activityPurposePrimary legal basis
Account creation and loginCreate, authenticate, and administer your accountPerformance of a contract
Product and feature deliveryGenerate outputs, store work, manage workflows, and provide requested functionsPerformance of a contract
Subscription and billingProcess payments, credits, subscriptions, renewals, invoices, and cancellationsPerformance of a contract; legal obligation
Customer supportRespond to requests, diagnose problems, and manage the customer relationshipPerformance of a contract; legitimate interests
Security and fraud preventionProtect accounts, detect misuse, investigate incidents, and enforce our TermsLegitimate interests; legal obligation where applicable
Essential service analyticsMaintain availability, diagnose failures, and measure core service performanceLegitimate interests
Non-essential website analyticsMeasure visitors and website engagement through non-essential technologiesConsent where required
Personalization technologiesRemember preferences and personalize non-essential experiencesConsent where required
Advertising and cross-site trackingDeliver or measure targeted advertising, if introducedConsent and required opt-out rights
Transactional communicationsSend login, billing, security, support, and service messagesPerformance of a contract; legitimate interests
Marketing communicationsSend product news, offers, and promotional contentConsent, or legitimate interests where law permits
Free-tier model improvementImprove internal models using eligible free-tier content where clearly disclosedConsent where required
Paid-user model trainingTrain models using paid-user content only after a separate written opt-inConsent
Product research and feedbackUnderstand product needs and improve usabilityLegitimate interests; consent where required
Legal and compliance activitiesMaintain records and respond to lawful requestsLegal obligation; legitimate interests
Business sale or restructuringEvaluate or complete a merger, financing, acquisition, or asset saleLegitimate interests; legal obligation
Consent recordsProve and administer consent, preferences, and withdrawalsLegal obligation; legitimate interests

We do not use consent where processing is necessary to provide a service you requested. Accepting the Terms and acknowledging this Privacy Policy are separate from consenting to optional processing.

How We Obtain, Record, and Manage Consent

We use consent only when you have a real choice.

Signup records

When you create an account, we may ask you to agree to the Terms of Use, acknowledge that you have read this Privacy Policy, and make separate choices about optional processing.

Agreeing to the Terms creates the contractual relationship. Acknowledging the Privacy Policy confirms that the privacy notice was presented. Neither action, by itself, constitutes consent to optional cookies, marketing, or model training.

Optional consent requests are presented separately and are not preselected.

Consent records

When you provide, deny, change, or withdraw consent, we may record:

  • your account identifier, email address, or a pseudonymous consent identifier
  • the date and time in UTC
  • the consent purpose and category
  • the choice you made
  • how and where the choice was made
  • the version of the consent notice, Privacy Policy, or interface shown
  • the applicable website, application, or signup flow
  • your country, region, or language where relevant
  • later changes or withdrawal of consent

These records allow us to demonstrate what choice was made and which notice was presented at that time.

Withdrawal and preference changes

You may withdraw consent at any time without affecting processing that occurred lawfully before withdrawal.

Depending on the consent, you may withdraw by opening Cookie Settings on our website, changing settings in your account or privacy dashboard, using the unsubscribe link in a marketing email, emailing support@thefword.ai, or withdrawing model-training consent through the applicable product control or support request.

Withdrawing consent will not prevent us from processing data that remains necessary to provide an active account, meet a legal obligation, protect the Services, or maintain a minimal suppression or consent record.

We make withdrawal reasonably as easy as giving consent.

Renewing consent

We may request consent again when the purpose changes materially, new categories of data or recipients are introduced, a consent record is no longer reliable, applicable law or regulatory guidance requires renewal, or a reasonable refresh period has passed.

Cookies and Consent Management Platform

We use a Consent Management Platform, or CMP, to manage website cookies and similar technologies where required.

Strictly necessary technologies

Strictly necessary technologies support website and app security, login and authentication, session management, load balancing, fraud prevention, remembering privacy choices, payment, and checkout functions.

These technologies may operate without consent where applicable law permits because the requested service cannot function properly without them.

Optional technologies

Optional technologies may include analytics, performance measurement, personalization, marketing, advertising, and cross-site or cross-context tracking.

For users in the EEA and UK, optional technologies remain disabled until the user provides affirmative consent through the CMP.

The CMP provides controls to accept optional technologies, reject optional technologies, select categories, review vendors and purposes, and change or withdraw choices later.

A persistent Cookie Settings link remains available on the website.

The CMP may store a pseudonymous consent identifier and the consent-record information described above. The cookie notice or CMP interface provides more specific information about the technologies, providers, purposes, and durations currently in use.

AI and Model Improvement

Free-tier users

We may use eligible free-tier prompts, uploads, outputs, feedback, and related content to develop, evaluate, test, or improve our internal models only where this has been clearly disclosed and the required legal basis has been established.

Where consent is required, we request a separate, specific opt-in and record that choice. Declining or withdrawing optional model-training consent does not affect processing completed lawfully before withdrawal.

Paid users and brands

We do not use private content from paid plans, brands, businesses, agencies, studios, teams, or enterprise customers to train, fine-tune, or improve AI or machine-learning models unless the customer provides a separate, express written opt-in.

This restriction covers private prompts, uploads, designs, images, tech packs, documents, outputs, customer data, and workspace data.

We may use service telemetry, security information, performance data, and aggregated or deidentified statistics to operate, secure, and improve the Services, provided that this activity does not use paid customer content for model training.

Third-party models and providers

Where third-party AI infrastructure is used to deliver a requested function, we require contractual and technical protections appropriate to the service. We do not authorize third-party providers to use paid customer content to train their general models unless the customer expressly agrees in writing.

California Sale and Sharing Disclosure

We do not sell personal information for money.

Based on our current practices, we do not share personal information for cross-context behavioral advertising as those terms are defined under California law.

We do not disclose personal information to third parties for their independent direct-marketing purposes.

If our practices change, we will update this Privacy Policy, provide the required notice, and provide any required Do Not Sell or Share My Personal Information control before the new practice begins.

How We Disclose Personal Data

  • Microsoft Azure and other cloud, hosting, storage, and infrastructure providers
  • authentication and identity providers
  • payment, invoicing, and accounting providers
  • email and transactional communication providers
  • analytics and product-performance providers
  • security, logging, monitoring, and fraud-prevention providers
  • customer support and CRM providers
  • AI infrastructure or processing providers used to deliver requested features
  • integration partners you authorize
  • professional advisers, auditors, insurers, and legal counsel
  • regulators, courts, law enforcement, and government authorities
  • prospective purchasers, investors, lenders, and advisers in a corporate transaction

Service providers are permitted to process personal data only for contracted purposes and subject to appropriate confidentiality, data-protection, and security obligations.

Where we act as a processor for an enterprise customer, our Data Processing Addendum governs our use of subprocessors and applicable notice or objection procedures.

Our current subprocessor list is available at: [INSERT PUBLIC SUBPROCESSOR LIST URL]

International Transfers and Data Residency

The F* Word is based in the United States. Personal data may be processed in the United States and in other countries where our service providers operate.

We use Microsoft Azure and other providers to host and process parts of the Services. Our confirmed primary Azure region or regions for EEA and UK personal data are: [INSERT CONFIRMED AZURE REGION OR REGIONS].

Unless an Order Form or Data Processing Addendum expressly commits to a specific region, we do not represent that personal data will remain exclusively within the EEA, UK, or another jurisdiction.

Where personal data is transferred from the EEA to a recipient outside the EEA that is not covered by an adequacy decision, we use an approved transfer mechanism, which may include the European Commission’s Standard Contractual Clauses.

For transfers from the UK, we use an approved UK transfer mechanism, such as the UK International Data Transfer Addendum or International Data Transfer Agreement, where required.

Where necessary, we also conduct transfer-risk assessments and adopt supplementary safeguards.

Information about contractual data residency for enterprise customers may be included in the applicable Order Form, security documentation, or Data Processing Addendum.

Retention Periods

We retain personal data only for as long as reasonably necessary for the disclosed purpose, including legal, accounting, security, and dispute-resolution requirements.

Data categoryTypical retention period
Account and profile informationWhile the account is active, then up to 6 years after closure where required for legal claims or contractual records
Login and authentication recordsWhile the account is active, then normally up to 24 months, subject to security and legal needs
User Content and saved outputsWhile needed to provide the Service, then deleted or deidentified according to account settings, contract terms, and backup cycles
Deleted account content in backupsNormally removed or overwritten within 90 days, unless legal preservation is required
Generated images from limited third-party widgetsLong enough to return and support the widget response, normally no more than 30 days unless saved to an account or a longer period is required for security or law
Product telemetry and analyticsNormally up to 24 months
Security, audit, and anti-fraud logsNormally up to 24 months, or longer for an active investigation
Support requests and communicationsUp to 3 years after the request or relationship ends
Sales and business-contact recordsUp to 3 years after the last meaningful interaction, unless a longer contractual relationship exists
Marketing recordsUntil consent is withdrawn or you opt out, then a minimal suppression record may be retained
Cookie and consent recordsUp to 6 years after the recorded choice, withdrawal, or end of the relationship
Billing, transaction, tax, and accounting recordsUp to 7 years, or longer where required by law
Contracts and enterprise recordsDuring the relationship, then up to 6 years or the applicable legal limitation period
Rights-request and deletion recordsUp to 6 years after completion
Deidentified and aggregated informationMay be retained longer where it cannot reasonably be used to identify an individual

Actual retention may be shorter or longer where required by law, an enterprise contract, security needs, litigation hold, or a valid deletion request.

Children and Age Requirements

The Services are not directed to children under 13. We do not knowingly permit children under 13 to create accounts or submit personal data.

For users in the EEA and UK, we do not knowingly permit users under 16 to create an account unless a lower digital-consent age applies under local law and we have implemented a legally valid parental or guardian authorization process.

We may require users to confirm their age and country during signup, restrict EEA and UK account creation to users aged 16 or older, request parental or guardian authorization where legally permitted and operationally supported, and suspend or delete an account where the age requirement has not been met.

If you believe a child has provided personal data without appropriate authorization, email support@thefword.ai with the subject line “Child Privacy Request.” We will investigate and delete the data where required.

Your Privacy Rights

California rights

  • know the categories and specific pieces of personal information collected
  • know the sources, purposes, and categories of recipients
  • request deletion
  • request correction
  • receive certain information in a portable format
  • opt out of sale or sharing, if applicable
  • limit certain uses of sensitive personal information, if applicable
  • use an authorized agent
  • receive equal service and pricing when exercising privacy rights

EEA and UK rights

  • access personal data
  • correct inaccurate personal data
  • request deletion
  • restrict processing
  • object to processing based on legitimate interests
  • object to direct marketing
  • receive portable data
  • withdraw consent
  • complain to a supervisory authority
  • receive information about applicable international-transfer safeguards

These rights may be subject to legal conditions and exceptions.

How to Exercise Your Rights

Submit a request by emailing support@thefword.ai with one of the following subject lines:

  • Privacy Access Request
  • Correction Request
  • Data Deletion Request
  • Consent Withdrawal
  • Marketing Opt-Out
  • Cookie Privacy Request

Include your full request, the email associated with your account if applicable, the relevant product, integration, or widget, and enough information for us to locate the applicable record.

We may verify your identity and authority before fulfilling a request. We use verification information only to process and document the request.

We respond within the period required by applicable law. Where legally permitted, we may extend the response period and will explain the reason.

Data Deletion Requests

You may request deletion at any time.

Account deletion

Email support@thefword.ai with the subject line “Data Deletion Request” and include your account email.

We delete or deidentify the account and associated personal data unless retention is required for security and fraud prevention, tax and accounting, legal claims or disputes, compliance records, enforcement of our agreements, or another lawful exception.

Facebook Login, Meta Login, or another connected login

Include the email associated with your The F* Word account, the login provider used, and the approximate date the account was connected if known.

Removing The F* Word from a third-party platform stops the connection but may not delete data already held by The F* Word. A direct deletion request is still required for data held by us.

Integrated apps and widgets

For a limited widget or integrated-app experience, include the app or widget name, the approximate date and time of use, any request or response identifier available, and a description of the generated image or content.

Where the experience did not collect an identifier, we may be unable to connect a particular image to a specific individual without enough information to locate it.

What happens next

We may confirm receipt, request identity verification, locate relevant records, delete or deidentify eligible data, direct service providers to delete eligible data, confirm completion, and explain any data we must retain and the reason.

We may retain a minimal record showing that the deletion request was completed.

Security

We use reasonable administrative, technical, and organizational measures designed to protect personal data, including access control, authentication, encryption, monitoring and logging, vulnerability management, employee and contractor access controls, vendor management, incident response, backup, and recovery.

No system is completely secure. You are responsible for protecting your login credentials and maintaining appropriate copies of important User Content.

Automated Processing

The Services use AI and automated systems to generate fashion-related content and workflow outputs.

We do not use these systems to make decisions that produce legal or similarly significant effects concerning individuals, such as employment, credit, housing, insurance, or access to essential services.

If this practice changes, we will provide any notices and controls required by applicable law.

Complaints

You may first contact us at support@thefword.ai.

EEA users may also complain to the data-protection authority in their country of residence, work, or the alleged infringement. UK users may complain to the UK Information Commissioner’s Office. California residents may contact the California Privacy Protection Agency or the California Attorney General where applicable.

Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the Services, legal requirements, vendors, or data practices.

When we make changes, we update the Effective Date, publish the updated version, provide additional notice where required, and request new consent if a change requires consent.

We retain version records so we can determine which notice and consent request applied at a particular time.

Contact Us

The F* Word, Inc. 1461 Acton Crescent Berkeley, CA 94702-1918 United States

Email: support@thefword.ai

EEA and UK representatives will be published when they are appointed