Effective 30 May 2026 · Last updated 7 August 2026 · Version 1.15 (MVP 1)
Privacy policy
What personal information we collect, how we use it, who we share it with, and your rights under the Australian Privacy Principles and the New Zealand Information Privacy Principles.
1. Introduction
The Lookahead ("we," "us," or "our") is a mobile application that helps you plan your weekly outfits and manage your wardrobe. We are committed to protecting your personal information and respecting your privacy.
This Privacy Policy explains what information we collect when you use The Lookahead, how we use it, who we share it with, and the rights you have over your information. It applies to your use of The Lookahead mobile and web application at thelookahead.app and the waitlist landing page at join.thelookahead.app (together, the "Service").
The Lookahead is operated by Kirsten Tindel-Davidson trading as THE LOOKAHEAD APP (ABN 75 241 681 935), a registered business name held with the Australian Securities and Investments Commission. We are based in Australia and bound by the Australian Privacy Principles ("APPs") set out in the Privacy Act 1988 (Cth).
By creating an account or using the Service, you confirm that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
2. Scope and geographic coverage
The Lookahead is operated from Australia and is offered to users in Australia and New Zealand. We handle your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and, for our New Zealand users, the Information Privacy Principles (IPPs) under the New Zealand Privacy Act 2020. Where those regimes differ, we apply the protections applicable to you based on where you are located.
We are not currently targeting users in the European Union, the United Kingdom, California, or other jurisdictions outside Australia and New Zealand. Before we open the Service to users in those jurisdictions, we will update this Privacy Policy to address the additional rights and obligations that apply under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and any other relevant laws. If you access the Service from outside Australia and New Zealand, please note that your information will be handled in accordance with this policy.
The Service is intended for adults only. The Lookahead is not directed to, and we do not knowingly collect personal information from, anyone under 18 years of age. If we become aware that we have collected personal information from a minor, we will delete it promptly.
3. Information we collect
We only collect personal information that we reasonably need to provide and improve the Service. We collect the following categories:
3.1 Information you provide directly
Account information: your name, email address, and authentication identifier when you create an account using Sign in with Apple, Sign in with Google, or another supported sign-in method.
Profile and style preferences: information you choose to enter, such as your style direction and how you prefer to set up your wardrobe, used to personalise outfit suggestions.
Wardrobe content: photos, descriptions, tags, and metadata for the clothing items you add to your wardrobe. Photos are re-encoded on your device before upload, which removes embedded EXIF metadata — including GPS location and camera device identifiers — so that data is never transmitted to or stored by us (see Section 3.4).
Communications: messages, feedback, and support requests you send us.
3.2 Information collected automatically
Usage data: how you interact with features of the Service, such as screens visited, actions taken, error events, and approximate time of use. This is used to operate, secure, and improve the Service. Where this involves optional product analytics (which features you tap) or performance monitoring (how quickly screens render and network requests to our backend complete), we send it only via Google Analytics for Firebase and Firebase Performance Monitoring, and only after you have opted in (a small number of one-time sign-up events may be held locally on your device beforehand and are sent only if you opt in — see Section 7.1); both are off by default, share the same consent and Settings toggle, carry no personal information or wardrobe content, use no advertising identifiers, and can be turned off at any time in Settings (see Section 7.1 and Section 8.1).
Device and technical data: device model, operating system version, app version, language settings, crash diagnostics (processed by Sentry — see Section 7.1), and a non-identifying device identifier used for security and abuse prevention.
Approximate location: for security and fraud prevention we derive a coarse location from your IP address. Separately, for the optional weather feature, we request your device location through your browser's standard location-permission prompt; the reading is rounded on your device to approximately one-kilometre precision before anything is sent, so your precise coordinates never leave your device, and we store and use only that rounded approximation. You can decline the prompt, in which case the weather feature is simply not personalised to your location and everything else continues to work.
3.3 Information from connected services
Some features of the Service rely on third-party providers. When you choose to enable these features, we receive limited information from them:
Sign in with Apple: a unique identifier and the email address (real or relay) that Apple provides for authentication.
Sign in with Google and Gmail (read-only receipts, optional): when you sign in with Google or connect your Gmail account, our request includes the OpenID Connect (openid) scope and — for the Gmail receipts feature — the gmail.readonly scope. Google's consent screen shows you both. From the openid scope we receive a stable Google account identifier (the OpenID sub claim) and the basic profile information shown on Google's consent screen; we store the sub so we can immediately act on security signals Google sends us (for example, when you revoke our access from your Google Account, Google notifies us and we use the sub to identify and erase the matching local credentials). The Gmail receipts feature works as follows: when you tap "Import receipts" in Settings, we ask Gmail for messages in two ways: those it has classified under its smart category:purchases label, and those sent from a defined allowlist of known retailer domains (which catches order confirmations that the purchases category has not tagged) — each within a recent time window (90 days by default). For each candidate message, we read the subject line, sender address, and decoded body text, and send those fields to our AI sub-processor Anthropic (see §5) for line-item extraction. Anthropic returns structured items — brand, item name, category, price, currency, and purchase date — which we save to your wardrobe. We do not store the original message content; only the extracted item fields plus a list of Gmail message IDs already processed (used to avoid re-processing the same receipt on a later sweep). When Anthropic also identifies a per-item product image, our backend (not your device) fetches the image from the retailer's URL over HTTPS and saves a copy under our own Firebase Storage bucket; the wardrobe view displays the copy stored with us rather than fetching directly from the retailer. The retailer's original URL is validated against an SSRF guard (HTTPS only, public IPs only, 5 MiB cap, MIME-magic verification) before the fetch, and a copy is only retained when validation succeeds. We only fetch messages matching one of these two criteria — Gmail's purchases category, or a known retailer sender domain; other emails in your inbox are never fetched. We do not send email on your behalf, and you can disconnect Google at any time from your device account settings or in-app settings. New Zealand users: because the item details above are collected from your retailer emails rather than entered by you directly, this notice is provided in accordance with Information Privacy Principle 3A of the New Zealand Privacy Act 2020.
Weather information: weather data for the morning outfit card is sourced from the Australian Bureau of Meteorology (BOM). To provide it, when the weather feature is enabled we ask for your device location through your browser (you can decline). Your device rounds the reading to approximately one kilometre before anything is sent — your precise coordinates never leave your device — and we use the rounded value in two ways, both proxied through our backend so neither provider ever sees your IP address: (a) we reverse-geocode the rounded coordinates to a country using OpenStreetMap's Nominatim service, so we can select the correct regional forecast provider (see §7.1); and (b) we request the forecast from the provider for your country — the Bureau of Meteorology for Australia, or Apple WeatherKit for New Zealand — for that approximate location. We send no name, email, or account identifier to either provider, and we store only the rounded coordinates and the resulting country — not your precise location. No user identity is transmitted to the weather provider or to Nominatim.
3.4 What we do not collect
We do not collect government identifiers (such as Tax File Numbers or Medicare numbers).
We do not collect health information or biometric identifiers.
We do not knowingly collect information from children under 18.
We do not use third-party advertising trackers or marketing pixels in the mobile app.
We do not collect or store the location (GPS) or device metadata embedded in your wardrobe photos. Photos are re-encoded on your device before upload to strip this EXIF metadata, so it never reaches our servers.
4. How we use your information
We use your personal information for the following purposes:
To provide the core Service, including authentication, generating outfit suggestions, managing your wardrobe, and synchronising your data across devices.
To personalise your experience based on the preferences and wardrobe items you provide.
To process payments and manage subscriptions for users on a paid tier (if and when paid features are activated).
To communicate with you about your account, service updates, security notices, and support enquiries.
To diagnose and fix bugs, monitor performance, and protect the Service against abuse, fraud, and unauthorised access.
To understand how the Service is used at an aggregate level so we can improve features and user experience.
To comply with our legal obligations and enforce our terms.
We do not sell your personal information. We do not share your personal information with third parties for their own advertising or marketing purposes.
5. Artificial intelligence and automated processing
The Lookahead uses artificial intelligence ("AI") to generate outfit suggestions and other features. To do this, we send the minimum information required to our AI sub-processor, Anthropic, PBC ("Anthropic"), and Anthropic processes the request and returns a response that we present to you in the app. The categories of information we send vary by feature:
Outfit suggestions: relevant wardrobe item descriptions, your stated preferences, and contextual information like weather or occasion.
Gmail receipt import (optional, opt-in via §3.3): for each Gmail message classified by Google under the category:purchases smart label within the time window you requested, we send the subject line, sender address, and decoded body text so Anthropic can extract structured line items (brand, item name, category, price, currency, purchase date). The full message content is not stored on our side; only the extracted item fields and the Gmail message ID are persisted, the latter solely to avoid re-processing the same receipt on a later sweep.
Our use of Anthropic is governed by Anthropic's Commercial Terms of Service and Data Processing Addendum, under which:
We are the data controller and Anthropic is our processor.
Anthropic does not sell or share your information, does not use it to train its general-purpose AI models, and does not combine it with data received from other sources.
Anthropic also retains the output of a content-safety classifier run on each request, which they use to enforce their Usage Policy. Anthropic's published terms govern how that output is handled.
Anthropic only processes your information to provide the AI service to us, on our documented instructions.
Anthropic operates on a default 30-day retention window for API inputs and outputs on our current plan tier. They are additionally required to delete or return your information within 30 days of the end of our agreement, subject only to legal-retention or trust-and-safety exceptions (including the content-safety classifier output described above).
Free and beta users of The Lookahead are subject to a monthly AI usage allowance, which is disclosed during onboarding. We track usage of this allowance for the purpose of fair use and conversion to paid tiers; we do not use it for any other purpose.
AI-generated outfit suggestions are recommendations only and do not constitute professional styling, medical, or other advice. You remain in control of which suggestions you accept or modify.
6. How and where we store your information
6.1 Storage location
Your account data and wardrobe content are stored using Google Firebase services in Google Cloud's Australian region (australia-southeast1). Certain sub-processors process limited data in the United States: AI request data by Anthropic, payment data by Stripe, application error and crash diagnostics by Sentry, and — where you opt in — product analytics by Google Analytics (see §7.1).
When personal information is transferred outside Australia, we take reasonable steps to ensure that the recipient handles it consistently with the Australian Privacy Principles, including by relying on the contractual data-protection commitments offered by these providers. For our US-based sub-processors, those commitments include Standard Contractual Clauses incorporated in each provider's Data Processing Addendum.
New Zealand users (IPP 12). Some of the service providers who process your information on our behalf are located outside New Zealand (primarily in the United States — see Section 7.1). Before disclosing your personal information to an overseas service provider, we rely on binding contractual data-protection commitments (including the Standard Contractual Clauses in each provider's Data Processing Addendum) that we believe, on reasonable grounds, require the recipient to protect your information with safeguards comparable to those under the New Zealand Privacy Act 2020, consistent with Information Privacy Principle 12.
6.2 Security
We use industry-standard measures to protect your personal information, including:
Encryption of data in transit using TLS 1.2 or higher.
Encryption of data at rest using AES-256 or equivalent industry-standard algorithms.
Role-based access controls and the principle of least privilege for any administrative access.
Multi-factor authentication for administrative access to systems holding personal information.
Regular security reviews of our infrastructure and dependencies.
Our key sub-processors maintain independently audited information-security programs (for example, SOC 2 reports for Anthropic and Google Cloud, and SOC 2 Type 2 plus ISO 27001 for Sentry), and are contractually required to notify us of any security incident affecting your data without undue delay so that we can fulfil our notification obligations to you and to regulators. Independently audited reports for our key sub-processors are available on request, or directly via the providers' trust portals — for example, Anthropic at trust.anthropic.com, Google Cloud at cloud.google.com/security/compliance, and Sentry at sentry.io/trust.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affects your personal information, we will notify you and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). For New Zealand users, where a privacy breach is likely to cause serious harm we will notify you and the New Zealand Office of the Privacy Commissioner as required by the Privacy Act 2020.
6.3 Data retention
We retain personal information for only as long as it is needed for the purposes described in this Privacy Policy:
Account and wardrobe data: kept until you delete your account, after which it is deleted from our active systems within 30 days. Backup copies are overwritten on our standard backup rotation cycle (typically within a further 30 days).
AI request data: processed by our AI sub-processor (Anthropic) to deliver the AI feature, and not used by Anthropic to train its general-purpose AI models. On our current plan tier, Anthropic operates on a default 30-day retention window for API inputs and outputs, plus a permanent content-safety classifier output retained under their Usage Policy (see §5). Anthropic is contractually required to return or delete personal information within 30 days of the end of our agreement, subject to limited legal-retention and trust-and-safety exceptions. For Anthropic's current operational retention practices for API data, please refer to Anthropic's published policies at anthropic.com/legal.
Error and crash diagnostics: error events sent to Sentry are retained for 30 days (Sentry Developer-tier default) and then deleted.
Product-analytics data: where you have opted in, anonymous feature-usage events collected via Google Analytics for Firebase are retained for 2 months and then deleted. Withdrawing consent in Settings, or deleting your account, resets the analytics identifier on your device so subsequent data cannot be tied to the prior one.
Usage and diagnostic logs: retained for up to 12 months for security, troubleshooting, and service-improvement purposes, then deleted or anonymised.
Communications and support records: retained for up to 24 months from the last interaction, so we can follow up on issues and refer to prior context.
Records required by law: where Australian law requires us to retain certain records (for example, financial or tax records relating to paid subscriptions), we will retain them for the period required by that law.
7. Who we share your information with
We do not sell your personal information. We share it only in the limited circumstances below.
7.1 Service providers (sub-processors)
We use carefully selected third-party providers to operate the Service. They process personal information on our behalf and only for the purposes we instruct. Our current sub-processors are:
Anthropic, PBC (United States) — large language model and AI processing for outfit suggestions and other AI features. Inputs and outputs are subject to Anthropic's default 30-day API retention plus a permanent content-safety classifier output (see §5).
Google LLC (United States, including Firebase and Google OAuth) — authentication (Sign in with Google), database, file storage, push notifications, and (with your consent) read-only access to your Gmail for retail receipts. When you sign in with Google or connect Gmail, we receive your stable Google account identifier (the OpenID sub claim) and act on revocation signals Google may send us to keep your account and our local credentials in sync (see §3.3).
Apple Inc. (United States) — Sign in with Apple authentication, App Store distribution, and (where applicable) in-app purchase processing.
Cloudflare, Inc. (United States) — DNS, content delivery, edge caching, and security protection for our website and APIs.
Stripe, Inc. (United States) — payment processing for web subscriptions. When you subscribe on the web, Stripe receives your email address and payment details at its hosted checkout, and we store a Stripe customer identifier linked to your account. We do not receive or store your full card number — card data is handled directly by Stripe under its PCI-DSS-compliant environment. Our use of Stripe is governed by Stripe's Data Processing Agreement, which incorporates Standard Contractual Clauses as the cross-border transfer mechanism we rely on for APP 8 and IPP 12.
Google LLC (United States) — Google Analytics for Firebase — optional, opt-in product analytics. When you have consented, we record anonymous feature-usage events (for example, which outfit actions you tap) to understand how the Service is used and improve it. It is off by default and we send nothing to Google until you allow it; you can withdraw at any time in Settings. Because we ask for your analytics choice only after you finish setting up, a small number of one-time events that happen during sign-up (such as account creation) are held locally on your device while your choice is pending — nothing is transmitted before you opt in. If you opt in, those locally-held events are sent then; if you decline, they are discarded and never sent. This on-device store is limited in size and age, is cleared automatically, and holds no email, name, account identifier, or wardrobe content. We do not send your email, display name, account identifier, or wardrobe content, and we set no custom user identifier. It is configured without advertising identifiers (no IDFA/AdID collection) and without Google advertising features, Google signals, or cross-app/cross-site tracking, so it is not used for advertising. Advertising-related consent signals (ad storage, ad user data, ad personalisation) are permanently denied. Data is stored in the United States and retained for 2 months. Our use of Google's services is governed by the Google Data Processing Addendum, which incorporates Standard Contractual Clauses as the cross-border transfer mechanism we rely on for APP 8.
Google LLC (United States) — Firebase Performance Monitoring — optional, opt-in performance diagnostics. When you have consented to product analytics, the app also records anonymous performance traces — app start-up and screen-render timings, and the duration, size, and response code of network requests to our own backend — via Firebase Performance Monitoring, to find and fix slow or failing paths. It is off by default and collects nothing until you opt in; it shares the same analytics consent and the same Settings toggle. It carries no personal information, wardrobe content, or advertising identifiers, and we set no custom user identifier — traces are tied only to a non-identifying app-instance identifier that is reset when you withdraw consent or delete your account. Data is stored in the United States and governed by the Google Data Processing Addendum, which incorporates Standard Contractual Clauses as the cross-border transfer mechanism we rely on for APP 8.
Functional Software, Inc. trading as Sentry (United States) — application error tracking, crash diagnostics, and performance monitoring. Our Sentry organisation is configured with the United States as the data-storage region. Sentry receives anonymous session identifiers, error type and stack trace, app version, environment tag, device and operating system version, and the type of network error encountered. For a sampled subset of sessions we also send anonymous performance-trace data — screen and route names and the timing of page loads and in-app navigations — so we can identify slow or failing operations; this contains no wardrobe content and no user-identifying data. We do not send your email, display name, IP address, account identifier, wardrobe content, or any other user-identifying data to Sentry; outgoing events are filtered for authentication headers and any incidental secrets before transport. Error and performance events are retained for 30 days (Sentry Developer-tier default) and then deleted. Our use of Sentry is governed by Sentry's Data Processing Addendum (currently v5.1.0), which incorporates Standard Contractual Clauses as the cross-border transfer mechanism we rely on for APP 8. Sentry's own sub-processors are published at sentry.io/legal/subprocessors.
Weather information for the morning outfit card is sourced from the Australian Bureau of Meteorology (BOM) for Australian home locations, and from Apple WeatherKit for New Zealand home locations and for trip destinations. All weather requests are proxied through our backend, so the provider sees only our server's IP address — not yours. We send only an approximate location (rounded to roughly one kilometre) and receive a forecast. No user identity is transmitted to the provider. BOM data is a public-domain government data source, not a personal-data processor; Apple WeatherKit is operated by Apple Inc. (United States), already listed as a sub-processor above, under its published terms. Attribution to the source provider (the Bureau of Meteorology, or "Apple Weather") is shown in the morning card. Additional regional weather providers will be added to this list before the Service opens to users in other regions.
Country lookup for the weather feature uses Nominatim, the geocoding service operated by the OpenStreetMap Foundation (United Kingdom) on the public, open OpenStreetMap database. When the weather feature is enabled, our backend sends the rounded (~1 km) coordinates to Nominatim to determine your country, so we can choose the correct regional forecast provider. The request is proxied through our backend, so Nominatim receives only the approximate coordinates and our server's IP address — never your IP, email, name, or account identifier. OpenStreetMap and the public Nominatim service are open-data resources rather than a commercial personal-data processor; our use is governed by the OpenStreetMap Foundation's published usage terms. If we move to a self-hosted or commercial geocoding arrangement, we will update this section before doing so.
Any future sub-processors will be disclosed here before they are used.
7.2 Legal and safety disclosures
We may disclose personal information where we are required or permitted by law, including:
to comply with a court order, subpoena, lawful request from a regulator, or other legal process;
to protect the safety, rights, or property of you, us, or others;
to investigate or prevent fraud, abuse, or violations of our terms;
in connection with a sale, merger, restructuring, or transfer of part or all of the business, in which case we will require the recipient to honour this Privacy Policy or notify you so you can make choices about your information.
8. Cookies and tracking technologies
8.1 Mobile app
The Lookahead mobile app does not use third-party advertising cookies, marketing pixels, or cross-site tracking technologies. We use only the local storage and authentication tokens necessary to keep you signed in and to operate core features. With your consent, the app also collects anonymous product-analytics events via Google Analytics for Firebase and anonymous performance traces via Firebase Performance Monitoring (see Section 7.1); these are off by default, opt-in, share the same consent and Settings toggle, and can be turned off at any time in Settings. It is configured without advertising identifiers and is never used for advertising or to track you across other apps or websites.
8.2 Waitlist landing page
Our public waitlist landing page at join.thelookahead.app may use a small number of essential and analytics cookies, including those provided by Cloudflare for security, performance, and aggregate traffic analytics. These cookies do not identify individual users and are not used for advertising. If we add additional analytics or marketing cookies in future, we will update this section and provide an appropriate cookie notice and consent mechanism on the site.
You can control cookies through your browser settings, including blocking or deleting cookies. Disabling essential cookies may affect site functionality.
9. Your privacy rights
Under the Australian Privacy Principles, you have the following rights in relation to the personal information we hold about you:
Access: request a copy of the personal information we hold about you.
Correction: ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
Deletion: delete your account at any time from within the app at Settings → Delete account. This permanently removes your account, wardrobe, preferences, and associated data within 30 days, subject only to information we are legally required to retain.
Withdraw consent: where we rely on your consent (for example, Gmail receipt access), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
Anonymity or pseudonymity: you may interact with us anonymously or under a pseudonym where it is lawful and practicable to do so. Some features (such as personalised outfit suggestions) cannot reasonably be provided without identifying you as an account holder.
Complain: you have the right to make a complaint about how we have handled your personal information (see Section 11).
To exercise any of these rights, contact us using the details in Section 12. We may need to verify your identity before acting on your request and will respond within a reasonable timeframe (generally within 30 days).
10. International users
The Service is offered to users in Australia and New Zealand. If you choose to access the Service from outside Australia and New Zealand, you do so on your own initiative and you acknowledge that your personal information will be processed in Australia and in the countries where our sub-processors operate (including the United States), under the protections described in this Privacy Policy.
We will update this Privacy Policy with additional disclosures and rights before opening the Service to general users in the European Union, the United Kingdom, California, or other jurisdictions with specific privacy laws.
11. Complaints
If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact us first using the details in Section 12. We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, and you are in Australia, you may make a complaint to the Office of the Australian Information Commissioner (OAIC):
Trading name: Kirsten Tindel-Davidson trading as THE LOOKAHEAD APP, ABN 75 241 681 935
Country: Australia
We aim to respond to all privacy enquiries within 5 business days and to resolve formal requests within 30 days.
13. Changes to this privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the addition of new features or sub-processors. When we make material changes, we will:
update the "Last updated" date at the top of this policy;
notify you in-app and/or by email before the changes take effect; and
where required by law, ask for your renewed consent.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after the changes take effect indicates your acceptance of the updated policy.