Vella Studio

Privacy Policy

Last updated: 21 July 2026 · Effective immediately

This Privacy Policy explains how Vella Studio ("the App", "we", "us", or "our") collects, uses, shares, and protects your personal information. We've written this in plain language because your privacy matters and you deserve to understand what happens with your data.

Quick Navigation

1. The short version

If you read nothing else, read this:

The full details are below.

2. Who runs Vella Studio

Owner and Data Controller

LSA Management (Services) Australia Pty Ltd
24B Andrew Street
Mount Waverley, VIC 3149
Australia

Privacy contact: info@mobisec.lk

LSA Management (Services) Australia Pty Ltd is the legal entity responsible for Vella Studio and is the "data controller" under applicable privacy laws including the Australian Privacy Act 1988, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the various US state privacy laws (CCPA, VCDPA, CPA, CTDPA, UCPA).

3. Data we collect

3.1 Photos and images you upload

When you use Vella Studio's AI features, you choose photos to upload from your device — typically selfies, makeup photos, or inspiration images. These are the most sensitive data we handle.

We treat photos as biometric-adjacent data and apply additional safeguards even where the law does not strictly require it.

3.2 Profile and preference data

You may provide the following information during onboarding or in Settings:

Preference answers are stored primarily on your device. We also create an anonymous guest account on our servers (tied to a device-based identifier) so features like AI processing and subscriptions can work across sessions. Product analytics events may include preference-related funnel signals without your photos.

3.3 Subscription and purchase data

When you start a free trial or subscribe, the transaction is handled by the store you used:

Through RevenueCat we receive:

We do not receive your name, email, payment card, or billing address from Apple or Google. Your payment information stays with the applicable store (or web payment processor, for web purchases).

3.4 Device, usage, and diagnostic data

To make the app work and improve it, we collect:

3.5 Generated content

AI features produce outputs such as: color season analyses, makeup descriptions, after-images of your face with AI-applied makeup, and roast-mode feedback. These outputs are linked to your input photos and stored locally on your device. They are not transmitted to our servers.

3.6 Push notifications token

If you enable notifications, Firebase Cloud Messaging issues an anonymous device token so we can send you reminders, feature announcements, or important updates. You can disable notifications at any time in your device settings (iOS or Android) or in the App where available.

3.7 Data we do not collect (and what we don’t use it for)

4. How we use AI (and which providers)

AI photo sharing disclosure

Vella Studio shares photos you upload with the third-party AI providers listed in this section to perform AI analysis and generate transformed images (relevant to Apple App Store Guideline 5.1.2(i) and Google Play User Data policies). Before any photo is sent to these providers, we ask for your explicit consent within the app. You can review or revoke this consent at any time in Settings → Privacy & AI.

Vella Studio's core features rely on artificial intelligence. We are transparent about exactly which AI providers we use, what data is shared, and why.

4.1 Google (Gemini and image generation models)

Provider: Google LLC, accessed via Google Cloud's AI services and the "Nano Banana Pro" image generation model (Gemini 3 Pro Image)

What we share: The selfies, inspiration photos, and makeup photos you choose to upload. We also share text prompts describing the desired transformation (e.g., "apply soft glam makeup").

Purpose: Generate AI-transformed images of your face with makeup applied; recreate inspiration looks on your features; perform visual analysis of skin tone, eye color, and hair color for color season classification.

How long Google retains data: Per Google's Generative AI APIs Terms of Service, prompts and images submitted via paid API endpoints are not used to train Google's models and are retained only briefly for abuse-detection purposes (typically up to 30 days), then deleted.

Google's Privacy Policy: https://policies.google.com/privacy

Google Cloud's data processing terms: https://cloud.google.com/terms/cloud-privacy-notice

4.2 OpenAI

Provider: OpenAI, L.L.C. (using GPT-5 model family via the OpenAI API)

What we share: Photos you upload (selfies, makeup photos), plus text describing what we want the model to assess.

Purpose: Analyze your photo to assess makeup application; provide feedback through Roast Mode; generate personalized makeup recommendations and shade suggestions; perform certain steps of color season analysis.

How long OpenAI retains data: Per OpenAI's API Data Usage Policy, data submitted via the API is not used to train OpenAI's models. OpenAI retains API inputs and outputs for up to 30 days for abuse and misuse monitoring, then deletes them. Approved Zero Data Retention may apply to certain endpoints.

OpenAI's Privacy Policy: https://openai.com/policies/privacy-policy/

OpenAI's API Data Usage Policy: https://openai.com/policies/api-data-usage-policies/

4.3 Replicate

Provider: Replicate, Inc.

What we share: Photos in transit to AI models hosted on Replicate's infrastructure (specifically Google's Nano Banana Pro and similar models).

Purpose: Replicate is the cloud infrastructure that runs the AI models we use. It does not analyze your data itself; it routes photos to the model and returns the model's output to us.

How long Replicate retains data: Per Replicate's privacy practices, prediction inputs and outputs are retained for up to 1 hour by default to support debugging and reliability, after which they are deleted. We do not opt into longer retention.

Replicate's Privacy Policy: https://replicate.com/privacy

4.4 What we explicitly don't do with your photos

4.5 Your control over AI processing

Before the first time the App sends a photo to any AI provider, we show you a consent screen explaining what will happen. You must tap "I agree, continue" for any AI processing to occur. If you decline, no photos will be sent to AI providers, but you will not be able to use the AI features.

You can revoke this consent at any time by going to Settings → Privacy & AI → Revoke AI permissions. After revocation, no further photos will be sent to AI providers until you grant consent again.

4.6 Automated decision-making

Vella Studio's AI features make automated decisions (e.g., classifying you as a "Soft Autumn" color season, recommending specific makeup shades). These decisions are not legally significant — they are aesthetic recommendations, not credit, employment, insurance, or housing decisions. You can disregard any AI output, request a different result, or stop using the app at any time.

5. How we use your data

We use the data described above only for the following purposes:

We do not use your data for behavioral profiling for marketing unrelated to attributing campaigns you’ve seen nor for any purpose unrelated to providing or improving the App.

6. Third parties we share data with

Beyond the AI providers listed in Section 4, we share limited data with the following service providers as necessary to operate the App:

6.1 Apple Inc. (App Store) and Google LLC (Google Play)

What: Subscription / in-app purchase transactions, store receipt or purchase-token validation, app distribution. Apple or Google may also provide crash or usage diagnostics if you opted into sharing analytics with developers in your device settings.

Apple Privacy Policy: https://www.apple.com/legal/privacy/

Google Privacy Policy: https://policies.google.com/privacy

6.2 RevenueCat, Inc.

What: Subscription state management, receipt / purchase-token validation, anonymous user identifiers tied to your subscription. RevenueCat may collect device identifiers (including advertising IDs where permitted) and is linked to AppsFlyer so subscription events can be attributed to the correct install.

Privacy Policy: https://www.revenuecat.com/privacy/

6.3 Google (Firebase Cloud Messaging)

What: Firebase Cloud Messaging (FCM) delivers push notification tokens/messages between our backend and Apple’s / Google’s push gateways. Notifications are transactional (e.g. reminders, product updates).

Privacy Policy: https://firebase.google.com/support/privacy

6.4 Bugsnag (SmartBear monitoring tools)

What: Crash and error telemetry (logs, stack traces, device/OS/app version identifiers) — not your facial photos.

Privacy Policy: Bugsnag / SmartBear Privacy Policy

6.5 Amplitude Inc.

What: Anonymous product analytics — feature usage, funnel events, session lengths. Photos are not sent to Amplitude.

Privacy Policy: https://amplitude.com/privacy

6.6 AppsFlyer Ltd. (mobile measurement / attribution)

What: AppsFlyer is our mobile measurement partner (MMP). The AppsFlyer SDK collects in-app events — for example installs, sessions, completions, subscriptions, and purchases — plus device and network metadata used for attribution (including AppsFlyer device ID). On iOS, IDFA may be included when you allow App Tracking Transparency. On Android, the Google Advertising ID (GAID) and related signals may be used where permitted. Purchase / subscription events are also relayed via our RevenueCat ↔ AppsFlyer integration so renewals can be attributed without double-firing from the client.

Important: This is not an in-app advertising network and does not show third-party ads inside Vella Studio. AppsFlyer attributes installs to marketing campaigns you may have seen externally (for example on Meta or TikTok) and may share attribution / conversion signals with those advertising partners and with us for ROI reporting.

If you deny tracking on iOS, AppsFlyer continues in limited / aggregated measurement modes consistent with Apple’s rules and AppsFlyer’s documentation. On Android, limiting ad personalization or resetting your Advertising ID in Google settings may reduce identifier-based attribution.

Purpose: Measure installs and ROI from marketing campaigns, attribute conversions, improve media spend efficiency, and support fraud prevention for installs.

Privacy Policy: https://www.appsflyer.com/legal/privacy-policy/

6.7 Sales, brokers, and in-app advertisements

We don’t rent your identifiable profile to brokers. The App remains free of invasive third‑party banners. Partner SDKs described above—including AppsFlyer measurement—receive only the categories of telemetry each policy section lists.

7. Advertising measurement (iOS & Android)

7.1 iOS — App Tracking Transparency (ATT)

Apple requires apps to obtain permission before accessing the Identifier for Advertisers (IDFA) for cross-app measurement. During onboarding we may present an educational pre-prompt explaining why opt‑in matters, followed by Apple's system ATT dialog if tracking is still not determined.

7.2 Android — Advertising ID

On Android, Google Play apps that use the Advertising ID must declare that use. Vella Studio’s Android build includes the Advertising ID permission because AppsFlyer (and RevenueCat device-identifier collection linked for attribution) may read the Google Advertising ID to measure installs and conversions.

7.3 Relationship to store privacy disclosures

Vella Studio’s App Store binaries declare AppsFlyer-related tracking domains in Apple’s privacy manifest (for example att.attr.whappsflyer.com and related AppsFlyer ATT domains) alongside our App Privacy Questionnaire disclosures in App Store Connect. On Google Play, our Data Safety form discloses collection and sharing consistent with this policy, including Advertising ID where applicable.

8. Where data is stored and for how long

8.1 On-device storage (your phone)

Most of your data — photos, generated images, color analysis results, makeup preferences, subscription cache — is stored locally on your device. We do not maintain a full copy of this media on our servers. If you uninstall the App, on-device data is removed with it; use Delete my data (or contact us) to request deletion of anonymous server-side records.

8.2 Backend processing (transient)

When you use an AI feature, your photo passes through our backend infrastructure (hosted on Google Cloud) on its way to the AI provider. The photo is held in memory only as long as needed to forward the request and is not written to persistent storage. We also store an anonymous guest profile needed to operate the service until you delete it.

8.3 AI provider retention

See Section 4 for each provider's specific retention period. In summary: Replicate (~1 hour), OpenAI (up to 30 days), Google (up to 30 days). After these periods, the data is deleted by the provider.

8.4 Analytics, attribution, and crash data

Anonymous analytics (Amplitude), error telemetry (Bugsnag), AppsFlyer measurement events, plus campaign / subscription attribution records are retained per each vendor’s schedules (typically 14–24 months for analytics backends unless deprecated earlier). AppsFlyer aggregates or deletes attribution data pursuant to its retention policies disclosed in AppsFlyer’s documentation.

8.5 Subscription records

Subscription transaction records are retained as required by tax and accounting law (typically 7 years in Australia).

9. Your rights and choices

Depending on where you live, you have rights under the Australian Privacy Act, EU/UK GDPR, CCPA, and other privacy laws. Globally, we offer the following choices to all users:

9.1 Within the App

9.2 By contacting us

You can email info@mobisec.lk to:

We respond within 30 days for most requests. We may need to verify your identity before responding (typically by asking you to send a request from the email tied to your subscription, if applicable).

10. International data transfers

Vella Studio is operated from Australia, but our service providers—including AI partners and US-based measurement / analytics platforms such as AppsFlyer, Amplitude, RevenueCat, and Bugsnag—may process data internationally, primarily in the United States. When you use AI features, your photos are transferred internationally to AI providers as described in Section 4.

For users in the EU, UK, and other jurisdictions with cross-border data restrictions, transfers are protected by:

For users in Australia, transfers comply with Australian Privacy Principle 8 (cross-border disclosure) — we take reasonable steps to ensure overseas recipients handle your data consistent with the Australian Privacy Principles.

11. Region-specific rights

11.1 Australia (Privacy Act 1988 & APPs)

If you are in Australia, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can:

11.2 European Union (GDPR)

If you are in the EU, you have rights under the General Data Protection Regulation (GDPR), including:

Our legal bases for processing include: (a) your consent (including AI uploads and, where required, advertising measurement frameworks such as ATT); (b) performance of a contract (to deliver the subscribed App); (c) our legitimate interests (product improvement, attribution reporting at an aggregate level, fraud prevention).

11.3 United Kingdom (UK GDPR)

UK residents have substantially the same rights as EU residents under the UK GDPR. You may also lodge a complaint with the UK Information Commissioner's Office (ICO).

11.4 California (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

Categories of personal information collected in the past 12 months (examples): Identifiers (guest UUID, AppsFlyer ID, advertiser IDs when permitted); commercial/subscription identifiers (via RevenueCat / App Store / Google Play); internet or electronic network activity (in-app telemetry, AppsFlyer attribution & Amplitude funnel events without photos); coarse geolocation (IP-derived locality); biometric-adjacent photos when you voluntarily run AI workflows; inferred preferences derived from uploads.

We do not knowingly collect personal information from California consumers under 16 without opt-in consent.

11.5 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA)

Residents of these states have rights similar to California consumers:

11.6 Brazil (LGPD)

Brazilian residents have rights under the Lei Geral de Proteção de Dados Pessoais (LGPD), including access, correction, deletion, anonymization, portability, and the right to withdraw consent at any time. International transfers from Brazil are governed by LGPD-compliant mechanisms including standard contractual clauses and your explicit consent.

11.7 Other jurisdictions

If you are in a jurisdiction not specifically listed, you may still have privacy rights under your local law. Please contact us at info@mobisec.lk to exercise them and we will respond consistent with applicable law.

12. Children's privacy

Vella Studio is intended for users aged 17 and older. The App is rated for mature teens / adults on the Apple App Store and Google Play (exact rating labels may vary by store). We do not knowingly collect personal information from children under 13 (or 16 in the EU/UK, or other ages where applicable law sets a higher threshold).

If you are a parent or guardian and believe your child under the relevant age has provided us personal information, please contact us at info@mobisec.lk and we will promptly delete that information.

13. Security

We protect your data using industry-standard security measures, including:

No system is perfectly secure. If we ever experience a data breach affecting your personal information, we will notify you and applicable regulators as required by law (typically within 72 hours under GDPR).

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

If you continue using the App after a change takes effect, you accept the updated policy.

15. Contact us

For any privacy questions, requests, or complaints, please contact:

LSA Management (Services) Australia Pty Ltd
Attn: Privacy Officer
24B Andrew Street
Mount Waverley, VIC 3149
Australia

Email: info@mobisec.lk

We aim to respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority.