Fresh — Privacy Policy
Effective date: July 23, 2026
Last updated: July 23, 2026
1. Who we are
Fresh is a men's fashion app that learns your taste and delivers a daily outfit recommendation ("Today's Fit"), lets you save items and outfits, and links you out to retailers to buy. Fresh is operated by Spotlight Crypto LLC (d/b/a Spotlight Labs), located at 224 W 35th St Ste 500 #2645, New York, NY 10001, USA ("Spotlight Labs," "we," "us"), the controller responsible for your personal data under this policy.
The Fresh app is offered in the United States only. It is directed to U.S. users and is not offered in the EU or UK at this time.
Questions about this policy or your data: support@spada.media.
2. Scope
This policy covers the Fresh iOS app and its backend API. It does not cover the third-party retailer websites we link to when you tap "Buy" — those sites have their own privacy policies, and once you leave Fresh you are subject to them.
3. Age requirement (children's policy)
Fresh is intended for users 17 and older (this matches our App Store age rating; see below). We do not knowingly collect personal data from anyone under
- If you believe a child under 17 has provided us data, contact
support@spada.media and we will delete it. We do not target children, serve child-directed content, or use the app for behavioral advertising to minors.
4. What data we collect
We practice data minimization: we collect only what the features below need.
4.1 Account & identity
- Email address. Fresh uses passwordless sign-in. You enter your email; we send a 6-digit one-time code (OTP) to verify it. We never set or store a password. Identity is managed by Supabase Auth; your account is a Supabase user record keyed to your email and a random user ID (UUID).
- One-time codes are transient (they expire, and delivery is handled by our email vendor); we do not retain OTP codes after verification.
4.2 Style preferences (onboarding quiz + swipes)
Collected to build your taste profile and personalize recommendations:
- Quiz answers: shopping attitude, style vibe, color palette, fit preference (slim / regular / relaxed), occasions (office, dates, nights out, weekend, events), and budget bands.
- Size information you provide (e.g. shirt, waist, shoe) to refine fit.
- Brand preferences you select.
- "No-go" items you exclude.
- Swipes (like / pass / save) on outfits and products, including an optional dwell time (how long a card was on screen), which sharpens the taste model.
- A derived taste vector and facet affinities (a mathematical summary of the above — not readable text about you).
Note on automated processing: your recommendations are produced by automated systems, including machine-learning models and third-party AI services that label and match catalog imagery (see Sub-processors). This processing ranks and matches products; it does not make legal or similarly significant decisions about you.
4.3 Saved content
- Saved items and saved outfits you bookmark, and the outfits assigned to you each day ("Today's Fit").
4.4 Device & push
- Expo push token — a device identifier issued by Expo/Apple that lets us send the daily "your fit is ready" notification. Stored with your platform (iOS/Android) and tied to your account when you're signed in. You can turn notifications off in iOS Settings; doing so stops the nudges.
4.5 Subscription status
- Fresh offers an auto-renewing subscription. Purchases are handled by Apple and managed through RevenueCat. We receive and store entitlement/ subscription status (e.g. whether "pro" is active, trial state, renewal/ cancellation events) keyed to your user ID. We do not receive or store your full payment card details — Apple processes payment.
4.6 Usage analytics & diagnostics
- Product analytics (PostHog): app events such as screens viewed, onboarding funnel steps, paywall views, reveal opens, saves, and buy-link taps, keyed to an opaque user ID or a pre-login anonymous ID. By design we exclude raw email, one-time codes, tokens, raw search text, and affiliate URLs from analytics.
- Crash & error diagnostics (Sentry): crash reports and error traces, tagged with your opaque user ID (not your email).
- We do not use Apple's advertising identifier (IDFA) and do not track you across other companies' apps or websites for advertising. As configured at launch, Fresh does not present the App Tracking Transparency prompt. If we ever add cross-app advertising or attribution SDKs, we will update this policy and request your permission first.
4.7 Photos
- Fresh does not collect user-uploaded photos. The current version of the app has no photo-upload feature and does not access your photo library.
4.8 Information we do NOT collect
- No passwords. No precise GPS location. No contacts, no photo library scanning, no user-uploaded photos, no health data, no advertising identifiers.
5. How we use your data (purposes)
- Provide the core service: authenticate you, build your taste profile, generate and assign your daily outfit, power search and the swipe deck, and save your items/outfits.
- Notify you: send the daily "fit is ready" push and transactional emails (your sign-in code).
- Manage your subscription: verify entitlements and unlock paid features.
- Improve the product: measure funnel and feature usage (analytics) and fix crashes (diagnostics).
- Train and improve our models: we use the preference signals you generate — swipes (like / pass / save), dwell time, brand and style selections, saved items and outfits, and your derived taste vector — to develop, train, evaluate, and improve Fresh's own recommendation, outfit-matching, and ranking models.
- Security & fraud prevention: verify sign-in, protect accounts and the API.
- Legal compliance: meet tax, accounting, and legal obligations.
De-identified and aggregated data. We may create de-identified and aggregated data derived from your activity (for example, combined preference and swipe statistics with all direct identifiers removed). Such data does not identify you and is not personal information. We use and retain it to build, train, and improve our models and the service — including after you delete your account — and we keep it in de-identified form and do not attempt to re-identify you.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.
6. Your rights
6.1 Everyone
- Access / export your data, correct it, and delete your account (see Section 8).
6.2 California (CCPA/CPRA)
California residents have the rights to know/access, delete, correct, and to opt out of sale/sharing (we do neither), plus the right to non-discrimination for exercising these rights. We do not sell or share your personal information, and we do not use or disclose sensitive personal information for purposes requiring an opt-out. Submit requests at support@spada.media.
We verify requests using your signed-in email/account. We respond within the timeframes required by law.
7. Sub-processors and data recipients
We use the following vendors to run Fresh. They process personal data only on our instructions and under data-processing terms. This list is accurate to the current stack.
| Sub-processor | Purpose | Data it may process |
|---|---|---|
| Supabase | Auth, database, private storage | Email, user ID, preferences, swipes, saved items, push tokens |
| Resend | Transactional email delivery (sign-in codes) | Email address, one-time code |
| Expo (Expo Application Services) | Push notification delivery; relays to Apple APNs | Push token, device platform |
| Apple | In-app purchases / payment; push transport (APNs) | Subscription/payment (processed by Apple), push token |
| RevenueCat | Subscription management, entitlements | User ID, subscription/entitlement status, purchase events |
| Modal | Serverless GPU compute for catalog ML (embeddings, image processing) | Catalog/product data (not tied to user identity) |
| OpenRouter | LLM / image-generation API routing for catalog labeling & outfit imagery | Catalog/product text and images (not tied to user identity) |
| Fly.io | Backend API hosting (United States) | All API-transited data in memory/logs |
| PostHog | Product analytics | Event data keyed to opaque user/anon ID (no email/PII by design) |
| Sentry | Crash & error diagnostics | Diagnostic data tagged with opaque user ID |
We will keep a current sub-processor list and update this policy when we add or change a material vendor.
8. Account and data deletion
You can delete your account and all associated personal data at any time:
- In-app: use Profile → Delete Account, or
- By email: request deletion at support@spada.media.
When you delete your account we remove or irreversibly anonymize your personal data, including account/email, preferences, swipes, saved items, and push tokens. User tables in our database are configured to cascade-delete your rows when your account is removed. We also propagate deletion to sub-processors that hold personal data (e.g. deleting/anonymizing your person in analytics and diagnostics). Some records may be retained where law requires (e.g. transaction/tax records) or in backups until they cycle out; these are access-restricted and deleted on their normal schedule. De-identified and aggregated data derived from your activity that no longer identifies you is retained and is not deleted, as described in Section 5.
9. Data retention
- Account, preferences, saved items, taste profile, push tokens: kept while your account is active; deleted/anonymized on account deletion (Section 8).
- One-time sign-in codes: transient; not retained after use/expiry.
- Analytics/diagnostic logs: retained for up to 12 months.
- Subscription/transaction records: retained as required for tax/accounting.
- Backups: deleted personal data persists in backups only until they expire on their normal rotation.
10. Where your data is stored
Fresh is operated from and for the United States. Our backend API runs on Fly.io and our database and storage run on Supabase, both in the United States. Because Fresh is offered only in the U.S., we do not make international personal-data transfers as part of providing the Service.
11. Security
We use industry-standard measures: encryption in transit (HTTPS), Supabase row-level security so a signed-in client can only read/write its own rows, private storage buckets, service-role access restricted to the backend, and passwordless auth (no stored passwords to breach). No system is perfectly secure; we cannot guarantee absolute security.
12. Changes to this policy
We may update this policy. Material changes will be reflected by updating the "Last updated" date and, where appropriate, an in-app or email notice. Continued use after an update means you accept the revised policy.
13. Contact
Spotlight Crypto LLC (d/b/a Spotlight Labs) — Fresh Privacy: support@spada.media Address: 224 W 35th St Ste 500 #2645, New York, NY 10001, USA