Fresh

Fresh — Privacy Policy

Effective date: July 23, 2026

Last updated: July 23, 2026


1. Who we are

Fresh is a men's fashion app that learns your taste and delivers a daily outfit recommendation ("Today's Fit"), lets you save items and outfits, and links you out to retailers to buy. Fresh is operated by Spotlight Crypto LLC (d/b/a Spotlight Labs), located at 224 W 35th St Ste 500 #2645, New York, NY 10001, USA ("Spotlight Labs," "we," "us"), the controller responsible for your personal data under this policy.

The Fresh app is offered in the United States only. It is directed to U.S. users and is not offered in the EU or UK at this time.

Questions about this policy or your data: support@spada.media.

2. Scope

This policy covers the Fresh iOS app and its backend API. It does not cover the third-party retailer websites we link to when you tap "Buy" — those sites have their own privacy policies, and once you leave Fresh you are subject to them.

3. Age requirement (children's policy)

Fresh is intended for users 17 and older (this matches our App Store age rating; see below). We do not knowingly collect personal data from anyone under

  1. If you believe a child under 17 has provided us data, contact

support@spada.media and we will delete it. We do not target children, serve child-directed content, or use the app for behavioral advertising to minors.

4. What data we collect

We practice data minimization: we collect only what the features below need.

4.1 Account & identity

4.2 Style preferences (onboarding quiz + swipes)

Collected to build your taste profile and personalize recommendations:

Note on automated processing: your recommendations are produced by automated systems, including machine-learning models and third-party AI services that label and match catalog imagery (see Sub-processors). This processing ranks and matches products; it does not make legal or similarly significant decisions about you.

4.3 Saved content

4.4 Device & push

4.5 Subscription status

4.6 Usage analytics & diagnostics

4.7 Photos

4.8 Information we do NOT collect

5. How we use your data (purposes)

De-identified and aggregated data. We may create de-identified and aggregated data derived from your activity (for example, combined preference and swipe statistics with all direct identifiers removed). Such data does not identify you and is not personal information. We use and retain it to build, train, and improve our models and the service — including after you delete your account — and we keep it in de-identified form and do not attempt to re-identify you.

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.

6. Your rights

6.1 Everyone

6.2 California (CCPA/CPRA)

California residents have the rights to know/access, delete, correct, and to opt out of sale/sharing (we do neither), plus the right to non-discrimination for exercising these rights. We do not sell or share your personal information, and we do not use or disclose sensitive personal information for purposes requiring an opt-out. Submit requests at support@spada.media.

We verify requests using your signed-in email/account. We respond within the timeframes required by law.

7. Sub-processors and data recipients

We use the following vendors to run Fresh. They process personal data only on our instructions and under data-processing terms. This list is accurate to the current stack.

Sub-processorPurposeData it may process
SupabaseAuth, database, private storageEmail, user ID, preferences, swipes, saved items, push tokens
ResendTransactional email delivery (sign-in codes)Email address, one-time code
Expo (Expo Application Services)Push notification delivery; relays to Apple APNsPush token, device platform
AppleIn-app purchases / payment; push transport (APNs)Subscription/payment (processed by Apple), push token
RevenueCatSubscription management, entitlementsUser ID, subscription/entitlement status, purchase events
ModalServerless GPU compute for catalog ML (embeddings, image processing)Catalog/product data (not tied to user identity)
OpenRouterLLM / image-generation API routing for catalog labeling & outfit imageryCatalog/product text and images (not tied to user identity)
Fly.ioBackend API hosting (United States)All API-transited data in memory/logs
PostHogProduct analyticsEvent data keyed to opaque user/anon ID (no email/PII by design)
SentryCrash & error diagnosticsDiagnostic data tagged with opaque user ID

We will keep a current sub-processor list and update this policy when we add or change a material vendor.

8. Account and data deletion

You can delete your account and all associated personal data at any time:

When you delete your account we remove or irreversibly anonymize your personal data, including account/email, preferences, swipes, saved items, and push tokens. User tables in our database are configured to cascade-delete your rows when your account is removed. We also propagate deletion to sub-processors that hold personal data (e.g. deleting/anonymizing your person in analytics and diagnostics). Some records may be retained where law requires (e.g. transaction/tax records) or in backups until they cycle out; these are access-restricted and deleted on their normal schedule. De-identified and aggregated data derived from your activity that no longer identifies you is retained and is not deleted, as described in Section 5.

9. Data retention

10. Where your data is stored

Fresh is operated from and for the United States. Our backend API runs on Fly.io and our database and storage run on Supabase, both in the United States. Because Fresh is offered only in the U.S., we do not make international personal-data transfers as part of providing the Service.

11. Security

We use industry-standard measures: encryption in transit (HTTPS), Supabase row-level security so a signed-in client can only read/write its own rows, private storage buckets, service-role access restricted to the backend, and passwordless auth (no stored passwords to breach). No system is perfectly secure; we cannot guarantee absolute security.

12. Changes to this policy

We may update this policy. Material changes will be reflected by updating the "Last updated" date and, where appropriate, an in-app or email notice. Continued use after an update means you accept the revised policy.

13. Contact

Spotlight Crypto LLC (d/b/a Spotlight Labs) — Fresh Privacy: support@spada.media Address: 224 W 35th St Ste 500 #2645, New York, NY 10001, USA