Privacy Policy
This Privacy Policy explains how Nirvana AI Technologies Ltd (“we”, “us”, “our”) collects, uses, and shares personal information when you use Arenci: our website at https://www.arenci.app and the Arenci mobile applications we make available (together, the “Services”).
Effective date: 1 September 2026
1. Who we are and what this covers
Arenci is operated by Nirvana AI Technologies Ltd, a private limited company registered in England and Wales under company number 17219459.
Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
We are the controller of personal data described in this policy, unless we say otherwise. For privacy questions or requests, contact us at aryan@arenci.app.
This policy covers:
- The Arenci website and mobile apps we operate.
- Personal data we collect when you create an account, search, save or track items, or contact us.
- Legacy order records from purchases made while Arenci previously offered in-app checkout. Arenci no longer offers checkout for physical goods, but we remain the controller of those records.
This policy does not cover:
- Merchant websites or apps you open when you leave Arenci to view or buy a product on the merchant's own site (those destinations have their own privacy practices).
Our Terms of Service explain the rules for using Arenci. Please read both documents.
2. Personal data we collect
We collect personal data relating to you as described below. Please do not put sensitive personal details (such as health information or government ID numbers) into search queries, photos, or profile fields unless you intend us to process them for the Services.
2.1 Information you provide
- Account data: name, email address, username, bio, profile photo, and sign-in details when you create or update an account, including through a platform sign-in provider.
- Style and shopping profile: shopping department preferences (for example women, men, or all), size information, favourite brands, brands to avoid, budget cues, and style notes you save.
- User content: text search queries, photos or screenshots you upload for visual search, saved items (“Finds”), tracked items and their settings, and feedback such as “more like this” or “not this”.
- Legacy order data: if you bought through Arenci while in-app checkout was available, the items and sizes ordered, delivery and contact details, totals, shipping, tax, fulfilment, tracking, cancellation, return, and refund information.
- Communications: messages you send us (for example support or feedback), including your contact details and message content.
For legacy orders, we did not receive your full payment card number. Card details were processed through our payment provider's hosted checkout; we received payment status, amount, and limited payment details needed for refunds and fraud prevention.
2.2 Information collected automatically
- Device and usage data: device type, operating system, app version, language, approximate region derived from IP address, screens and features you use, and related server log data needed to run and secure the Services.
- Identifiers: app installation or device identifiers (including Apple's IDFV), push notification tokens, and similar technical IDs.
- Analytics events: product analytics (for example feature use and app lifecycle events) that may be linked to your account when you are signed in.
- Advertising data (free service only): when the Google Mobile Ads software is allowed to request ads, Google and its ad technology partners may collect an IP address and approximate location, app- or device-scoped identifiers, ads shown, ad views, clicks and video interactions, and SDK performance and diagnostic data to deliver, measure, secure, and limit the frequency of ads. Arenci does not request Apple's App Tracking Transparency permission and does not access the IDFA.
- In-app browser activity: when you open a merchant's site inside Arenci rather than leaving the app, we record the website's domain name, how long the session lasted, how many pages you moved through, and whether the address looked like a checkout page. We use this to understand whether outbound links are useful. We do not read the contents of merchant pages, do not inject any code into them, and do not record what you typed, saw, or bought there.
- Referral and link data: your personal referral link, link and click identifiers, link-open timestamps, the relationship between the referring and invited accounts, referral eligibility and status, reward history, and an app-install identifier that we convert to a keyed hash for fraud prevention.
- Referral link-event data: when a referral or shared link is opened, our link provider may record the destination, referring page, approximate location derived from IP address, device type, browser, operating system, and IP address. We use this for link attribution, analytics, security, and referral fraud prevention.
On first launch after installing the app, Arenci may read the clipboard solely to look for an Arenci link that the referral page copied at your request. Only a matching Arenci link is used for attribution and sent to our link provider. We do not store or transmit unrelated clipboard contents. If there is no exact link, Arenci does not award a referral based only on an IP-address match.
2.3 Information from third parties
- Sign-in providers: limited profile data from the platform provider you choose when you sign in that way.
- App stores and billing platforms: subscription status, product identifiers, and renewal or entitlement information when you subscribe to Arenci Plus through the platform store. We do not receive or store your full payment card number.
- Legacy commerce records: for purchases made while in-app checkout was available, Shopify provided the resulting order, payment status, fulfilment, tracking, and refund information.
- Advertising providers (free service only): ad consent status and ad-delivery, interaction, measurement, and diagnostic information from Google Mobile Ads and participating ad technology partners.
- Referral and attribution providers: link, click, device, conversion, and subscription-event information from the service providers, including AppsFlyer, that help us measure app installs, validate referrals, and apply rewards.
- Catalog and merchant sources: product listing metadata (title, price, images, shop, product URL, and similar fields) used to show search and tracking results.
2.4 Personalisation memory
To make results more relevant, we may store preference signals built from your activity, including:
- Saves and taste feedback.
- Short memory snippets about what you tend to like or avoid.
- Style patterns such as preferred brands, colours, or fits.
You can edit or remove some of this information in the app where controls are available.
2.5 What we do not aim to collect
- Medical records.
- Biometric identity templates.
- Precise GPS tracking for advertising.
Photos you upload are processed to extract fashion attributes (for example category, colour, or material) so we can search for similar items, not to identify you as a person.
3. How we use personal data
We use personal data to:
- Provide, operate, and maintain Arenci, including text and photo search, personalised discovery, Finds, style profile, sharing, and tracking.
- Create and manage your account and preferences.
- Personalise results and recommendations using your profile, history, and feedback.
- Process and manage Arenci Plus subscriptions and entitlements.
- Administer and support legacy in-app orders and keep the accounting and tax records the law requires.
- Fund the free service by serving, measuring, frequency-limiting, and protecting ads. We do not use your search queries, visual-search photos, Finds, tracked items, or style profile for ad targeting.
- Operate the referral programme, attribute an invited account to the correct referrer, check eligibility, prevent self-referrals and other misuse, and provide or extend Plus rewards.
- Send transactional messages and service notices, and, where allowed, product updates or marketing (you can opt out of marketing).
- Send push notifications you enable (for example price and stock alerts or important service messages).
- Measure performance, debug issues, prevent fraud or abuse, and keep the Services secure.
- Improve the Services, including ranking quality and product features, using aggregated or de-identified insights where practical.
- Comply with law, enforce our Terms of Service, and protect the rights, safety, and property of users and Nirvana AI Technologies Ltd.
3.1 AI and automated processing
Arenci uses automated systems and cloud AI models to power the product. Those systems may:
- Interpret search queries and shopping intent.
- Analyse visual search images for fashion attributes and generate search cues.
- Rank or re-rank product candidates for relevance.
- Help consolidate long-term style preferences from your activity.
Relevant inputs (such as queries, image content for visual search, and selected profile or preference context) may be processed by our cloud infrastructure to deliver the feature you requested. Much of that core infrastructure and AI processing runs in the United States (including facilities in the US East region). We use this processing to operate and personalise Arenci. We do not sell your private inputs as a standalone data product, and we do not use them to train third-party foundation models for their general public products.
We use cloud infrastructure and specialist search providers to perform this processing. The providers that receive private search input are identified below.
- What is processed: the words you type into search, any photo you choose to search with, and the size and brand preferences saved on your style profile.
- Core AI processing: Amazon Web Services, Inc.(“AWS”), which hosts and runs Arenci's generative and vision models through Amazon Bedrock as part of our backend infrastructure.
- Garment segmentation: a visual-search photo may be sent to Roboflow, which hosts the segmentation model used to identify selectable garment outlines. If this step is unavailable, Arenci falls back to manual selection.
- Visual product retrieval: for a Lens search, a temporary copy of the photo, or the selected crop, is made available by URL to SerpApi, which submits it to Google Lens to return visual product matches. Any text you add to that Lens search may accompany the image. The temporary retrieval copy is deleted after the request.
- What we do not send to the ad system: your account name or email, search query, visual-search photo, Finds, tracked items, and style profile are not provided to Google Mobile Ads for ad targeting.
AWS acts strictly as our data processor: it is bound by a data processing agreement, processes this data solely on our documented instructions to deliver the feature you requested, and may not use it for any purpose of its own, as described in section 5. Under the Amazon Bedrock terms that apply to us, AWS does not use inputs or outputs to train Amazon or third-party models. We send visual-search input to Roboflow, SerpApi, and Google for the purpose of providing the segmentation and Lens features you request; their processing is also subject to their applicable service and privacy terms. This processing is necessary to provide the search and personalisation features you ask for, and we rely on contract as the legal basis for it (see section 4).
AI outputs can be incomplete or incorrect. Product titles, prices, availability, and matches may be wrong or out of date. Always check details on the merchant site before you buy.
4. Legal bases (UK / EEA)
Where UK GDPR or EU GDPR applies, we rely on one or more of the following bases:
- Contract: to provide the Services you request (account, search, Finds, tracking for Plus subscribers, and related features) and to support any legacy order placed with us.
- Legitimate interests: to secure, improve, and understand the Services, prevent abuse, and develop product quality, balanced against your rights.
- Consent: where required (for example camera or photo library access, push notifications, advertising and related device storage, and certain marketing or non-essential cookies on the website).
- Legal obligation: when we must retain or disclose information to comply with law, including keeping accounting and tax records for orders.
5. How we share information
We share personal data only as needed to run Arenci and as described below. We name the providers that process private search input in section 3.1. For other supporting functions we describe the categories of provider rather than publishing a list of every vendor we use.
- Search and AI processing: Amazon Web Services, Inc., our cloud infrastructure provider, runs our models on Amazon Bedrock. Roboflow receives a visual-search photo when hosted garment segmentation is used. For Lens searches, SerpApi and Google Lens receive the temporary input described in section 3.1 to return matching products.
- Legacy order providers: Shopify, the payment provider, and the relevant fulfilment supplier retain or receive legacy order information where needed to support, refund, fulfil, or legally retain an order placed while in-app checkout was available.
- Advertising (free service only): Google Mobile Ads and the ad technology partners identified in the advertising privacy form may receive the advertising data described in section 2.2. Depending on your location and choice, Google may serve personalised, non-personalised, or limited ads. Their own privacy terms also apply; see the Google Privacy Policy. Arenci does not request or show ads while a Plus entitlement is active, does not request access to the IDFA, and does not provide the private shopping data listed in section 3.1 to the ad system.
- Other service providers: trusted companies that process data on our instructions for functions such as authentication, hosting, storage, databases, subscription entitlement management, transactional email, push delivery, analytics, short links, and product catalog retrieval. They may only use the data to provide services to us.
- Platform stores and sign-in providers: to process subscriptions or provide the account sign-in method you choose, under their own terms for those services.
- Merchants and shopping destinations: when you leave Arenci to open a product page or buy on a merchant’s own site, that destination’s own privacy policy applies and we are not the seller. We may earn a commission on some referrals through affiliate programmes.
- Professional advisers and authorities: where needed for legal, security, auditing, or regulatory reasons.
- Business transfers: in connection with a merger, acquisition, financing, or asset sale, subject to appropriate safeguards.
Every third party that receives personal data from Arenci, including analytics providers, AI processors, sign-in providers, advertising partners, and software development kits embedded in the app, must provide the same or equal protection of your data as required by this Privacy Policy and applicable law. Providers acting on our instructions are contractually limited to the services we ask them to perform and must apply appropriate security. Where a provider acts under its own terms for a platform or advertising service, those terms and its privacy policy also govern its processing.
For the referral programme, our link-attribution provider processes link clicks and opens and associates them with referral signup and subscription-conversion events. We provide opaque identifiers rather than raw Arenci names or email addresses. Our subscription-management provider processes store subscription and entitlement events used to confirm trial starts and apply eligible rewards. We keep our own referral ledger linking the referring and invited Arenci account identifiers, but we do not reveal the invited customer's name or email address to the referrer.
We do not sell your personal information. We do not provide your account profile, private search input, Finds, or tracked items to advertisers for targeting. Where required, the advertising privacy form provides choices about personalised advertising and related data sharing.
6. Where data is processed (including the United States)
We are based in the United Kingdom. Personal data is processed in more than one country:
- United Kingdom: where we operate as a company and manage the business.
- United States: a substantial part of our core product infrastructure, including hosting, storage, and the Amazon Web Services AI processing used for search and personalisation, runs in the United States (including the AWS US East region).
- Other countries: visual-search, advertising, attribution, analytics, subscription, and other service providers may process data in the European Economic Area or other locations where they operate. Legacy order providers may retain order data on their global infrastructure.
Where required, we use appropriate safeguards for transfers outside the UK / EEA, such as the UK International Data Transfer Agreement or European Commission standard contractual clauses, together with supplementary measures where appropriate.
7. Retention
We keep personal data only as long as needed for the purposes above, including to provide the Services, resolve disputes, and meet legal requirements. Typical patterns:
- Account, profile, Finds, tracked items, and personalisation memory: kept while your account is active, and until you delete specific items or we complete an account deletion request.
- Visual search images: stored privately to process your search and are typically removed from our storage within about 7 days.
- Legacy order records: what you bought, when, for how much, where it was sent, and any refund — retained for at least six years after the end of the accounting period they fall in, because UK tax and company law requires us to keep them. This is the one category we cannot delete on request; see section 8.
- Subscription and entitlement records: retained as needed for billing support, fraud prevention, and legal or accounting obligations.
- Referral records: an unclaimed referral link is recognised for up to 30 days. Referral attribution, eligibility, reward, and anti-fraud records may be kept while the relevant account is active and for as long as reasonably needed afterwards to provide rewards, prevent duplicate claims, resolve disputes, and meet legal or accounting obligations.
- Security and server logs: retained for a limited period for reliability and security, then deleted or aggregated.
- Analytics: retained according to our analytics configuration and operational needs.
- Advertising data: Arenci retains ad interaction and revenue events according to its analytics configuration; Google and its ad technology partners apply their own retention periods to data they process.
After an account deletion request, we aim to delete or de-identify personal data within a reasonable period (typically within 30 days), except where we must retain information for legal, security, dispute, or financial reasons — most commonly the order records described above.
8. Your rights and choices
Depending on your location, you may have rights to:
- Access your personal data.
- Correct inaccurate personal data.
- Delete personal data.
- Export or receive a copy of personal data (portability).
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent (this does not affect processing already carried out lawfully).
You can exercise many controls in the app, including:
- Editing your profile and style preferences.
- Unsaving Finds and deleting tracked items.
- Removing or adjusting personalisation memory items where those controls are available.
- Managing push notification permissions in your device settings.
- Turning product analytics off under Privacy & Data in the app.
- Reviewing or changing advertising privacy choices under Privacy & Data when Google requires that option to be available.
- Continuing without an unclaimed referral, which clears the pending referral from the app.
- Managing or cancelling Arenci Plus in your platform subscription settings.
One limit is worth stating plainly: deleting your account does not delete your order records. We are required to keep those for at least six years (see section 7), so a deletion request will remove your profile, preferences, Finds, tracked items, and history, but the record of what you bought stays until that period expires. We separate it from your account where we can.
To request access, export, correction, or full account deletion, email aryan@arenci.app from the email address associated with your account, or see our Account deletion page. We may need to verify your identity before fulfilling a request.
You may also lodge a complaint with your local data protection authority. In the UK, that is the Information Commissioner’s Office (ICO).
9. Children
Arenci is designed for users aged 16 and over. It is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from someone under 16, contact us and we will take appropriate steps, including deletion where required.
10. Security
We use technical and organisational measures designed to protect personal data against loss, misuse, and unauthorised access. No method of transmission or storage is completely secure. Please protect your devices and account access methods, and notify us promptly if you suspect unauthorised use of your account.
11. Cookies and similar technologies
Our website may use essential cookies and similar technologies needed to operate the site, and may use analytics tools to understand traffic. The mobile apps use software components for authentication, analytics, push notifications, subscriptions, link attribution, and, for free users, advertising. You can control some analytics, advertising, and notification choices through the app, browser, or device settings.
For free users, the Google Mobile Ads software may use device storage or similar technology for ad delivery, frequency control, measurement, and fraud prevention where allowed. In the UK, EEA, Switzerland, and other places where a choice is required, Arenci asks Google for the applicable privacy form before requesting ads. Arenci does not request or show ads while a Plus entitlement is active.
Referral and shared links use a link-attribution service to record link events and connect a valid click with a later app open, signup, or subscription event. On supported mobile devices, the referral installation page can copy the exact Arenci link to the clipboard when you choose the copy option. The app reads that link on first launch so it can restore the invitation after installation.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Where changes are material, we may also provide additional notice (for example in the app or by email) where required by law. Continued use of the Services after changes take effect means you accept the updated policy where permitted by law.
13. Contact
Nirvana AI Technologies Ltd
Company No. 17219459
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Email: aryan@arenci.app
See also our Terms of Service, Shipping and Returns, and Account deletion page.