The Lookahead
Effective 30 May 2026 · Last updated 4 September 2026 · Version 1.27 (MVP 1)

Privacy policy

What personal information we collect, how we use it, who we share it with, and your rights under the Australian Privacy Principles, the New Zealand Information Privacy Principles, and Singapore's Personal Data Protection Act 2012.

1. Introduction

The Lookahead ("we," "us," or "our") is a mobile application that helps you plan your weekly outfits and manage your wardrobe. We are committed to protecting your personal information and respecting your privacy.

This Privacy Policy explains what information we collect when you use The Lookahead, how we use it, who we share it with, and the rights you have over your information. It applies to your use of The Lookahead mobile and web application at thelookahead.app (the "Service"). Our former landing page at join.thelookahead.app no longer hosts a site: it permanently redirects to thelookahead.app, collects nothing, and sets no cookies of its own.

The Lookahead is operated by Kirsten Tindel-Davidson trading as THE LOOKAHEAD APP (ABN 75 241 681 935), a registered business name held with the Australian Securities and Investments Commission. We are based in Australia and bound by the Australian Privacy Principles ("APPs") set out in the Privacy Act 1988 (Cth).

By creating an account or using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.

2. Scope and geographic coverage

The Lookahead is operated from Australia and is offered to users in Australia, New Zealand, Singapore, France, and the United States. We handle your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth); for our New Zealand users, the Information Privacy Principles (IPPs) under the New Zealand Privacy Act 2020; for our Singapore users, the Personal Data Protection Act 2012 (PDPA); for our French users, the EU General Data Protection Regulation (GDPR) and France's Loi Informatique et Libertés; and for our United States users, any applicable US state privacy law, where one applies to us (see below). Where those regimes differ, we apply the protections applicable to you based on where you are located.

France is, for now, our only market within the European Economic Area — a deliberate, limited exception rather than a general EU launch. If you access the Service from France, or the GDPR otherwise applies to you because we are offering the Service to you in the EU, Sections 6.1, 9, and 11 describe the additional transfer safeguards, rights, and complaint path that apply to you.

United States users. A number of US states have their own comprehensive privacy laws, each with its own applicability thresholds based on factors like revenue or the number of consumers whose information a business handles. We do not currently meet the applicability thresholds of any of them, including California's Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) — among other things, we do not have the revenue the CCPA's threshold requires, we do not buy, sell, or share the personal information of 100,000 or more California consumers or households, and, as stated in Section 4, we do not sell or share your personal information at all. Because that can change as we grow, we will monitor this and update this Privacy Policy — including with state-specific rights and a designated request method — before any such law applies to us.

We are not currently targeting users elsewhere in the European Union or European Economic Area, or the United Kingdom. Before we open the Service to those jurisdictions, we will update this Privacy Policy to address the additional rights and obligations that apply under those laws, including the UK GDPR. If you access the Service from outside Australia, New Zealand, Singapore, France, and the United States, please note that your information will still be handled in accordance with this policy.

The Service is intended for adults only. The Lookahead is not directed to, and we do not knowingly collect personal information from, anyone under 18 years of age. If we become aware that we have collected personal information from a minor, we will delete it promptly.

3. Information we collect

We only collect personal information that we reasonably need to provide and improve the Service. We collect the following categories:

3.1 Information you provide directly

3.2 Information collected automatically

3.3 Information from connected services

Some features of the Service rely on third-party providers. When you choose to enable these features, we receive limited information from them:

3.4 What we do not collect

4. How we use your information

We use your personal information for the following purposes:

We do not sell your personal information. We do not share your personal information with third parties for their own advertising or marketing purposes.

5. Artificial intelligence and automated processing

The Lookahead uses artificial intelligence ("AI") to generate outfit suggestions and other features. To do this, we send the minimum information required to our AI sub-processor, Anthropic, PBC ("Anthropic"), and Anthropic processes the request and returns a response that we present to you in the app. The categories of information we send vary by feature:

Our use of Anthropic is governed by Anthropic's Commercial Terms of Service and Data Processing Addendum, under which:

Anthropic also publishes its current data-handling and retention practices for its API services. For the most up-to-date information, please see Anthropic's Privacy Policy and Data Processing Addendum at anthropic.com/legal.

Free and beta users of The Lookahead are subject to a monthly AI usage allowance, which is disclosed during onboarding. We track usage of this allowance for the purpose of fair use and conversion to paid tiers; we do not use it for any other purpose.

AI-generated outfit suggestions are recommendations only and do not constitute professional styling, medical, or other advice. You remain in control of which suggestions you accept or modify.

6. How and where we store your information

6.1 Storage location

Your account data and wardrobe content are stored using Google Firebase services in Google Cloud's Australian region (australia-southeast1). Certain sub-processors process limited data in the United States: AI request data by Anthropic, payment data by Stripe, application error and crash diagnostics by Sentry, and — where you opt in — product analytics by Google Analytics (see §7.1).

When personal information is transferred outside Australia, we take reasonable steps to ensure that the recipient handles it consistently with the Australian Privacy Principles, including by relying on the contractual data-protection commitments offered by these providers. For our US-based sub-processors, those commitments include Standard Contractual Clauses incorporated in each provider's Data Processing Addendum.

New Zealand users (IPP 12). Some of the service providers who process your information on our behalf are located outside New Zealand (primarily in the United States — see Section 7.1). Before disclosing your personal information to an overseas service provider, we rely on binding contractual data-protection commitments (including the Standard Contractual Clauses in each provider's Data Processing Addendum) that we believe, on reasonable grounds, require the recipient to protect your information with safeguards comparable to those under the New Zealand Privacy Act 2020, consistent with Information Privacy Principle 12.

Singapore users (PDPA Transfer Limitation). Your account and wardrobe data are stored in Australia, and some of the service providers who process your information on our behalf are located outside Singapore (primarily in the United States and Australia — see Section 7.1). Before transferring your personal data outside Singapore, we take reasonable steps to ensure the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the Personal Data Protection Act 2012 — including the Standard Contractual Clauses incorporated in each provider's Data Processing Addendum — consistent with the Transfer Limitation Obligation under the PDPA.

France / European Union users (GDPR Chapter V). Australia does not currently have an adequacy decision from the European Commission under the GDPR. We therefore rely on Standard Contractual Clauses (SCCs) as our transfer safeguard for personal information you provide to us that is processed or stored outside the European Economic Area — including in our own systems in Australia, and in onward transfers to our sub-processors (see Section 7.1), each already governed by SCCs incorporated in that sub-processor's Data Processing Addendum, as described above.

6.2 Security

We use industry-standard measures to protect your personal information, including:

Our key sub-processors maintain independently audited information-security programs (for example, SOC 2 reports for Anthropic and Google Cloud, and SOC 2 Type 2 plus ISO 27001 for Sentry), and are contractually required to notify us of any security incident affecting your data without undue delay so that we can fulfil our notification obligations to you and to regulators. Independently audited reports for our key sub-processors are available on request, or directly via the providers' trust portals — for example, Anthropic at trust.anthropic.com, Google Cloud at cloud.google.com/security/compliance, and Sentry at sentry.io/trust.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affects your personal information, we will notify you and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). For New Zealand users, where a privacy breach is likely to cause serious harm we will notify you and the New Zealand Office of the Privacy Commissioner as required by the Privacy Act 2020. For Singapore users, where a data breach results in, or is likely to result in, significant harm to affected individuals, or is of a significant scale, we will notify the Personal Data Protection Commission (PDPC) and, where required, the affected individuals, in accordance with the Data Breach Notification Obligation under the Personal Data Protection Act 2012. For French and other EU/EEA users, where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the French data protection authority (the CNIL) without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify you directly where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Articles 33 and 34 of the GDPR.

6.3 Data retention

We retain personal information for only as long as it is needed for the purposes described in this Privacy Policy:

7. Who we share your information with

We do not sell your personal information. We share it only in the limited circumstances below.

7.1 Service providers (sub-processors)

We use carefully selected third-party providers to operate the Service. They process personal information on our behalf and only for the purposes we instruct. Our current sub-processors are:

Weather information for the morning outfit card is sourced from the Australian Bureau of Meteorology (BOM) for Australian home locations, and from Apple WeatherKit for New Zealand home locations and for trip destinations. All weather requests are proxied through our backend, so the provider sees only our server's IP address — not yours. We send only an approximate location (rounded to roughly one kilometre) and receive a forecast. No user identity is transmitted to the provider. BOM data is a public-domain government data source, not a personal-data processor; Apple WeatherKit is operated by Apple Inc. (United States), already listed as a sub-processor above, under its published terms. Attribution to the source provider (the Bureau of Meteorology, or "Apple Weather") is shown in the morning card. Additional regional weather providers will be added to this list before the Service opens to users in other regions.

Country lookup for the weather feature uses Nominatim, the geocoding service operated by the OpenStreetMap Foundation (United Kingdom) on the public, open OpenStreetMap database. When the weather feature is enabled, our backend sends the rounded (~1 km) coordinates to Nominatim to determine your country, so we can choose the correct regional forecast provider. The request is proxied through our backend, so Nominatim receives only the approximate coordinates and our server's IP address — never your IP, email, name, or account identifier. OpenStreetMap and the public Nominatim service are open-data resources rather than a commercial personal-data processor; our use is governed by the OpenStreetMap Foundation's published usage terms. If we move to a self-hosted or commercial geocoding arrangement, we will update this section before doing so.

Any future sub-processors will be disclosed here before they are used.

7.2 Legal and safety disclosures

We may disclose personal information where we are required or permitted by law, including:

7.3 Community pool deliveries (courier)

If you use the community pool feature to send an item to, or receive an item from, another member, we disclose the recipient's name and delivery address to our courier partner, Shippit Pty Ltd (Australia), so it can generate a shipping label and arrange delivery. This is the only circumstance in which a delivery address is shared, and the other member in the exchange never sees it — labels are generated on our servers and neither party's app receives the other's address.

Unlike the service providers listed in Section 7.1, Shippit does not act only on our instructions. Under its own terms and privacy policy, Shippit handles delivery information as an independent controller for the purpose of providing the delivery; its terms limit it to using or disclosing that information for a purpose connected with the delivery service, or as required by law. Shippit may process the delivery information using service providers located outside Australia — including in the Philippines, Indonesia, India, Malaysia, Singapore, and the United States — for the purpose of arranging delivery (see Section 6 and Section 10). Shippit's handling of your information is governed by its own privacy policy.

On our side, a delivery address collected for a pool transaction is held only for that transaction: it is never stored on your profile, and it is deleted on delivery or within 14 to 30 days, whichever comes first. We cannot control how long Shippit retains the address it needs to complete the delivery.

7.4 eBay listings (optional resale)

If you connect your own eBay account and choose to list a piece for sale, we send that listing to eBay so it can be published. What we send is the listing itself: the photographs of the item, its title and description, condition, brand, size, colour, the item specifics eBay’s category requires (for example a dress length), the price and currency, and a reference code for the item. The listing is created under your eBay account and is yours — you manage, edit, or end it on eBay.

We do not send eBay your name, your email address, or your home address. A listing needs a shipping origin, and we supply our own business address for that purpose, not yours. Buyers deal with you through eBay under eBay’s own terms; we are not a party to the sale and we do not receive payment information from it.

Unlike the service providers listed in Section 7.1, eBay does not act only on our instructions. eBay operates as an independent controller of the listing and of your eBay account activity, under its own terms and privacy notice, and it is a global business that processes information outside Australia, including in the United States (see Section 6 and Section 10). eBay’s handling of your information is governed by its own user privacy notice.

On our side we store the encrypted access and refresh tokens for the connection, the permission scope you granted, your eBay user ID, and the identifiers of listings created through the Service. Disconnecting eBay in Settings deletes the stored connection. Listings already published stay on eBay, because they are yours — end them on eBay if you no longer want them live.

8. Cookies and tracking technologies

8.1 Mobile app

The Lookahead mobile app does not use third-party advertising cookies, marketing pixels, or cross-site tracking technologies. We use only the local storage and authentication tokens necessary to keep you signed in and to operate core features. With your consent, the app also collects anonymous product-analytics events via Google Analytics for Firebase and anonymous performance traces via Firebase Performance Monitoring (see Section 7.1); these are off by default, opt-in, share the same consent and Settings toggle, and can be turned off at any time in Settings. It is configured without advertising identifiers and is never used for advertising or to track you across other apps or websites.

8.2 Waitlist landing page

We no longer operate a separate landing page. The address join.thelookahead.app now permanently redirects to thelookahead.app; it serves no content, collects nothing, and sets no cookies of its own. If we publish a separate marketing site in future, we will update this section and provide an appropriate cookie notice and consent mechanism on it.

You can control cookies through your browser settings, including blocking or deleting cookies. Disabling essential cookies may affect site functionality.

9. Your privacy rights

Under the Australian Privacy Principles, you have the following rights in relation to the personal information we hold about you:

New Zealand users have comparable access and correction rights under the Information Privacy Principles of the Privacy Act 2020, and Singapore users have comparable access and correction rights under the Personal Data Protection Act 2012.

France / European Union users (GDPR). If the GDPR applies to you, our legal bases for the processing described in Section 4 are: performance of our contract with you (providing the core Service, personalisation, payments, and related account communications); our legitimate interests, balanced against your rights (diagnosing and fixing bugs, protecting the Service against abuse and fraud, understanding aggregate usage to improve the Service, and inviting optional feedback — you may object to processing based on legitimate interests at any time, including to feedback outreach); your consent, which you may withdraw at any time without affecting the lawfulness of prior processing (optional features such as product analytics, performance monitoring, the weather location prompt, and Gmail receipt import); and compliance with our legal obligations. In addition to the rights listed above, you have the right to: request restriction of processing in certain circumstances; receive the personal information you have provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (data portability); and object to processing carried out on the basis of our legitimate interests. As noted in Section 3.1, the soft taste signals we infer from your activity are never used to make a decision about you that has a legal or similarly significant effect, so Article 22 of the GDPR (automated individual decision-making) does not apply to that processing. You also have the right to lodge a complaint with a supervisory authority, including the CNIL (see Section 11).

To exercise any of these rights, contact us using the details in Section 12. We may need to verify your identity before acting on your request and will respond within a reasonable timeframe (generally within 30 days).

10. International users

The Service is offered to users in Australia, New Zealand, Singapore, France, and the United States. If you choose to access the Service from outside those countries, you do so on your own initiative and you acknowledge that your personal information will be processed in Australia and in the countries where our sub-processors operate (including the United States), under the protections described in this Privacy Policy.

France. France is currently our only market within the European Economic Area. If you are located in France, the GDPR applies to our processing of your personal information, and Sections 6.1, 9, and 11 describe the transfer safeguards, rights, and complaint path that apply to you specifically. Under Article 27 of the GDPR, we have designated Noah Hoebeke in France as our representative in the European Union for data protection matters. You may contact them at noahhoebeke7@gmail.com, or contact us directly using the details in Section 12.

United States. As described in Section 2, we do not currently meet the applicability thresholds of the CCPA/CPRA or any other US state privacy law, so no state-specific rights or complaint path apply yet. We will add them here if that changes.

We will update this Privacy Policy with additional disclosures and rights before opening the Service more generally to users in the European Union, the United Kingdom, or other jurisdictions with specific privacy laws.

If you use the community pool feature, your delivery address may additionally be processed by our courier partner Shippit’s service providers located outside Australia — including in the Philippines, Indonesia, India, Malaysia, Singapore, and the United States — for the purpose of arranging delivery (see Section 7.3).

If you use the optional eBay resale feature, the listing you create is processed by eBay outside Australia, including in the United States, for the purpose of publishing and running that listing (see Section 7.4).

11. Complaints

If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact us first using the details in Section 12. We will acknowledge your complaint promptly and aim to resolve it within 30 days.

If you are not satisfied with our response, and you are in Australia, you may make a complaint to the Office of the Australian Information Commissioner (OAIC):

If you are in New Zealand, you may make a complaint to the Office of the Privacy Commissioner (OPC):

If you are in Singapore, you may make a complaint to the Personal Data Protection Commission (PDPC):

If you are in France or another EU/EEA country, you may make a complaint to the Commission Nationale de l'Informatique et des Libertés (CNIL):

12. Contact us

If you have questions about this Privacy Policy, want to exercise your privacy rights, or wish to raise a privacy concern, please contact us:

We aim to respond to all privacy enquiries within 5 business days and to resolve formal requests within 30 days.

13. Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the addition of new features or sub-processors. When we make material changes, we will:

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after the changes take effect indicates your acceptance of the updated policy.