Effective date: 01.07.2026
Last updated: 06.07.2026
This Privacy Policy explains how FULL FUTURE LTD (“Company”, “we”, “us” or “our”) collects, uses, discloses, protects and otherwise processes personal data in connection with the LOOOK.AI Mirror platform, local application, administrative dashboard, websites, subscriptions, support services and related AI, AR, virtual try-on, virtual mirror, camera, photo, video and interactive experiences.
LOOOK AI Mirror is a platform that enables business customers to activate and run AI, AR and other interactive visual experiences on customer-controlled devices, screens, mirrors, kiosks or similar equipment. The platform may process a live camera, photo or video stream in order to apply the selected experience and return the transformed or augmented image to the screen.
This Privacy Policy is intended for:
- our business customers and their authorised users;
- people who interact with a LOOOK AI Mirror experience at a customer location, event, store, showroom, exhibition, website or other deployment environment;
- visitors to our website or people who contact us.
We may make this Privacy Policy available by QR code, link, notice screen or other appropriate method so that users can review it on their own device.
If you do not want your image, video stream or related information to be processed, please do not stand in front of, activate or use a LOOOK AI Mirror experience.
1. Who We Are
The data controller for personal data processed for our own purposes is:
FULL FUTURE LTD
Registered address: C/O Fdca-Office 2 Bennet’s House, 21 Leyton Road, Harpenden, England, AL5 2HU
Registration number: 15861125
Email: dima@ex.comloook.ai
Data protection contact / DPO: dima@ex.comloook.ai
Where we process personal data on behalf of a business customer, that customer is generally responsible for determining the purposes and means of the relevant processing, including where and how the LOOOK.AI Mirror experience is deployed, which experience is activated, what notice is provided at the location and whether additional consents are required.
2. Our Role and Our Customer’s Role
LOOOK.AI Mirror is typically provided as a B2B platform.
Depending on the context, we may act in different roles:
2.1 We act as a processor or service provider
We may process personal data on behalf of our business customer when we process a live camera stream, image, video, output, email address or other information solely to provide the specific LOOOK.AI Mirror experience selected and deployed by that customer.
In this case, the customer is generally the controller or business, and we act as processor, service provider or equivalent role under applicable privacy laws.
2.2 We act as a controller or business
We act as controller or business when we process personal data for our own purposes, including:
- customer account management;
- subscription activation and administration;
- licensing, billing and invoicing;
- platform security;
- technical logs;
- product analytics;
- service improvement;
- aggregated or de-identified audience analytics;
- compliance with legal obligations;
- responding to direct requests sent to us.
2.3 Customers remain responsible for their deployment
Our business customers are responsible for ensuring that each deployment of LOOOK.AI Mirror is lawful, transparent and appropriate for the specific location and audience. This may include providing visible notices, obtaining any required consent, avoiding unlawful use cases, complying with laws on children’s data, biometrics, advertising, consumer protection, employment, education, health and surveillance, and ensuring that any experience they upload or commission is lawful.
3. What LOOOK.AI Mirror Does
LOOOK.AI Mirror may be used to run experiences such as:
- AR filters, masks, overlays and effects;
- virtual try-on experiences;
- virtual mirror experiences;
- AI-generated or AI-transformed image or video experiences;
- branded interactive experiences;
- live event or retail experiences;
- photo, video or email-sharing experiences;
- customer-created or third-party experiences integrated into the platform.
The exact processing depends on the experience selected by the customer.
In a typical live experience, a camera or similar device captures a live image or video stream. The LOOOK.AI Mirror platform or local application processes that stream in real time, applies the selected effect or experience, and returns the processed image or video to the screen. Unless the experience specifically requires recording, saving or sending a photo or video, we do not intentionally store the live video stream or facial images on our servers.
4. Personal Data We May Process
The categories of personal data we process depend on how you interact with LOOOK.AI Mirror.
4.1 Customer account and subscription data
For business customers and authorised users, we may process:
- name;
- business email address;
- phone number;
- company name;
- job title;
- login credentials;
- billing details;
- subscription details;
- licence period;
- payment status;
- customer support communications;
- administrative dashboard activity.
We use this data to create and manage accounts, activate subscriptions, administer access, provide support, process payments, maintain security and comply with legal obligations.
4.2 Device, installation and licence data
When a customer installs or uses the local LOOOK.AI Mirror application, we may process:
- licence key;
- activation status;
- device or installation identifier;
- application version;
- configuration settings;
- customer location or venue information, if provided by the customer;
- network and diagnostic logs;
- crash reports;
- performance data;
- timestamps of activation and use.
This information is used to activate and operate the platform, prevent misuse, troubleshoot errors, maintain security and ensure that the customer’s subscription functions correctly.
This data normally relates to the customer’s device or installation, not to a visitor’s personal device.
4.3 Live camera, photo or video stream
When a person uses or activates a LOOOK.AI Mirror experience, the relevant device may capture a live image, photo or video stream.
Depending on the experience, we may process:
- live video frames;
- facial image or body image visible to the camera;
- pose, movement or positioning data;
- facial landmarks or similar technical signals required to apply an effect;
- image or video content submitted to the experience;
- generated or transformed output shown on the screen.
We use this data to provide the selected experience in real time.
Unless clearly stated otherwise for a specific experience, we do not intentionally store live camera streams, raw facial images or face templates on our servers after the real-time experience has been delivered.
4.4 Optional photo, video or email-sharing features
Some experiences may allow a user to request that a photo, video, recording, generated image or other output be sent to them by email or another method.
If you choose to use such a feature, we may process:
- your email address;
- the photo, video, recording or output you requested;
- delivery status;
- timestamp;
- related technical logs.
We use this data only to send the output requested by the user, confirm or complete delivery, handle failed delivery attempts, maintain limited delivery/security logs and comply with legal obligations.
We do not use the photo, video, recording or output requested by the user to identify the user, verify the user’s identity, create a faceprint or facial recognition template, compare the user against any database, train AI models, or analyse the user’s biometric identity.
Unless a different retention period is clearly disclosed for a specific experience, we delete the email address and associated output from our active systems within 1–2 days after delivery or attempted delivery, subject to limited technical backups, security logs and legal obligations.
4.5 Usage analytics, optional audience analytics and aggregated insights
LOOOK.AI Mirror generates basic usage analytics about how a deployment is used. Basic usage analytics may include:
- number of sessions;
- number of interactions;
- duration of interaction;
- selected experience or filter;
- time and date of use;
- venue, region or customer location;
- device or installation identifier;
- engagement statistics by experience, campaign, location or time period.
In addition, some deployments may include an optional audience analytics module if enabled by the business customer and if permitted by applicable law. Depending on the customer’s configuration, applicable law, notices and consents, optional audience analytics may include broad audience segments or visible appearance-based attributes, such as estimated age range, apparent gender presentation, skin tone category, hair colour, eye colour or other disclosed attributes configured for that deployment.
We do not use these analytics to identify a specific person. We do not intentionally create or store faceprints, facial recognition templates or biometric identifiers for the purpose of identifying or verifying a person.
Optional audience analytics are enabled only where legally permitted, where the relevant customer has requested or configured the feature, and where the required notices, consents, DPIA or similar assessments and safeguards are in place. In some jurisdictions or deployment contexts, certain audience analytics features may be disabled or unavailable.
Where optional audience analytics are enabled for a customer deployment, the customer is generally responsible for determining the purpose and legal basis for that analytics feature, providing appropriate notices, obtaining required consents and ensuring that the feature is lawful for the relevant location, audience and use case. In such cases, we generally act as processor or service provider, unless we separately determine the purposes and means of processing for our own aggregated or de-identified analytics.
Customer-enabled audience analytics
Where optional audience analytics or visible appearance-based analytics are enabled at the request of a business customer, the customer is generally responsible for determining whether to enable that feature, the purpose of the feature, the applicable legal basis, the required notices and consents, and whether a DPIA, biometric notice or other assessment is required.
We do not enable sensitive audience analytics for a customer deployment unless the customer has requested or configured the relevant feature and the deployment is subject to appropriate contractual, technical and legal safeguards.
We do not use customer-enabled audience analytics to identify individual users, and we do not use such data for our own independent purposes except in aggregated or de-identified form where permitted by applicable law and our agreement with the customer.
4.6 Website, cookies and online identifiers
When you visit our website or online dashboard, we may process:
- IP address;
- browser type;
- device type;
- operating system;
- pages viewed;
- referral URL;
- cookies and similar technologies;
- session logs;
- approximate location derived from IP address;
- analytics and security data.
We use this information to operate the website, maintain security, remember preferences, analyse performance and improve our services.
Where required by law, we ask for consent before placing non-essential cookies.
4.7 Communications and support data
If you contact us, we may process:
- name;
- email address;
- company details;
- message content;
- attachments;
- support tickets;
- call or meeting notes;
- feedback.
We use this data to respond to you, provide support, resolve issues, improve our services and maintain business records.
5. How We Use Personal Data
We may use personal data for the following purposes:
5.1 To provide the LOOOK.AI Mirror platform
This includes:
- activating customer subscriptions;
- enabling the local application;
- running selected AI, AR or virtual mirror experiences;
- processing live streams in real time;
- applying filters, masks, effects, overlays or transformations;
- displaying the output on the screen;
- sending user-requested outputs by email;
- maintaining customer access.
5.2 To administer customer accounts and subscriptions
This includes:
- account creation;
- user authentication;
- dashboard administration;
- licence and subscription management;
- billing and invoicing;
- contract management;
- customer communications.
5.3 To provide support and maintain security
This includes:
- troubleshooting;
- bug fixing;
- technical diagnostics;
- crash reporting;
- platform monitoring;
- fraud prevention;
- misuse prevention;
- security incident response.
5.4 To improve and develop our services
This includes:
- analysing platform performance;
- understanding which experiences are used most often;
- improving user experience;
- testing and developing new features;
- improving AI, AR and rendering quality;
- developing aggregated or de-identified insights;
- conducting internal research and product development.
Where possible, we use aggregated, de-identified or anonymised data for these purposes.
5.5 To provide audience analytics and business insights
Where enabled and lawful, we may use analytics data to:
- measure engagement with experiences;
- compare performance across experiences, campaigns or locations;
- recommend better-suited experiences to customers;
- generate aggregated or de-identified reports;
- provide benchmark or targeting insights to customers.
We do not use these analytics to make decisions that produce legal or similarly significant effects on individual users.
5.6 To comply with legal obligations and protect rights
This includes:
- tax and accounting compliance;
- responding to lawful requests;
- enforcing agreements;
- protecting our rights, customers and users;
- preventing fraud, misuse or security incidents;
- establishing, exercising or defending legal claims.
6. Legal Bases for Processing
Where the GDPR, UK GDPR or similar laws apply, we rely on one or more of the following legal bases:
- performance of a contract, where processing is necessary to provide our services to customers or administer subscriptions;
- legitimate interests, where processing is necessary for security, support, service improvement, analytics, fraud prevention and business operations, provided those interests are not overridden by individual rights;
- consent, where required for live camera processing, non-essential cookies, marketing communications, optional email-sharing features, or certain customer deployments;
- explicit consent, where required for special category data or sensitive biometric-related processing;
- legal obligation, where processing is necessary to comply with applicable law;
- legal claims, where processing is necessary to establish, exercise or defend legal claims.
Where we act as a processor for a customer, the customer is responsible for identifying the applicable legal basis and obtaining any required consent.
7. Facial Images, Biometric Data and Sensitive Inferences
LOOOK.AI Mirror may need to detect or track face, body, pose, movement or other visual features in order to apply AR or AI effects. This may involve technical processing of visual characteristics in real time.
Unless expressly stated otherwise for a specific feature:
- we do not use facial images to identify who you are;
- we do not verify your identity;
- we do not create permanent faceprints;
- we do not store facial recognition templates;
- we do not compare your face against a database of known people;
- we do not intentionally store live facial images on our servers after the real-time experience ends.
Some jurisdictions may treat certain visual processing, face geometry, facial landmarks, biometric identifiers, biometric data or sensitive inferences as specially regulated information. Where such laws apply, we and/or the customer will implement additional safeguards, which may include visible notice, consent, feature limitations, retention limits and contractual restrictions.
We do not deploy AI systems in jurisdictions where prohibited to categorise individuals based on biometric data in order to deduce or infer race, ethnic origin, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
8. De-identified, Aggregated and Anonymous Data
We may create and use aggregated, de-identified or anonymised data from platform usage and experience interactions.
This may include statistics such as:
- total number of sessions;
- average session duration;
- most-used experiences;
- engagement by venue, time period or campaign;
- aggregated audience segments;
- performance benchmarks.
Where aggregated audience segments include optional demographic or appearance-based attributes, such as estimated age range, apparent gender presentation or skin tone category, such insights are generated only where the relevant feature is enabled, legally permitted and subject to appropriate notices, consents and safeguards. We do not use aggregated or de-identified data to re-identify individuals and do not permit customers or partners to do so.
9. Third-Party Technologies and Service Providers
LOOOK.AI Mirror may integrate or use third-party technologies, SDKs, APIs and service providers. Depending on the experience and configuration, these may include the following.
9.1 Snap Camera Kit
Some LOOOK.AI Mirror experiences may use Snap Camera Kit, Snap’s AR SDK, and AR experiences known as Lenses. Snap Camera Kit may enable AR effects, face effects, body effects, world effects, overlays and similar features.
Where Snap Camera Kit is used, Snap may process certain information in accordance with its own terms and privacy policy. Some users may be required to accept Snap’s terms and acknowledge Snap’s privacy policy before using Camera Kit Lenses.
The host application or customer deployment may be responsible for requesting access to camera, microphone, media library, location or similar device permissions where required.
If a user declines Snap’s required terms or consent prompt, Snap Lenses may not function, although other LOOOK.AI Mirror functionality may remain available.
9.2 Decart AI models and API services
Some LOOOK.AI Mirror experiences may use Decart AI models, APIs or related services to process images, videos, live streams or prompts and generate transformed output.
Where Decart-powered functionality is used, relevant input and output may be processed by Decart as our processor or sub-processor, subject to applicable contractual and data protection terms.
9.3 Nano Banana AI models and API services
Some LOOOK.AI Mirror experiences may use Nano Banana AI models, APIs or related services to process images, videos, live streams, prompts or other inputs and generate transformed or augmented output.
Where Nano Banana-powered functionality is used, relevant input and output may be processed by Nano Banana as our processor, sub-processor or independent third-party provider, depending on the applicable integration, configuration and contractual terms.
We use such third-party AI providers only as necessary to provide the selected experience, generate the requested output, maintain security and comply with applicable law and contractual obligations.
9.4 Other service providers
We may also use service providers for:
- cloud hosting;
- storage;
- content delivery;
- email delivery;
- customer support;
- analytics;
- payment processing;
- security monitoring;
- error logging;
- software development and maintenance;
- professional services.
We require service providers to process personal data only as permitted by contract and applicable law.
10. How We Share Personal Data
We may share personal data with:
- our business customers, where necessary to provide the relevant deployment or reports;
- service providers and sub-processors;
- third-party SDK/API providers used in the selected experience;
- payment processors;
- hosting and infrastructure providers;
- analytics and security providers;
- professional advisers, such as lawyers, auditors and accountants;
- regulators, courts, law enforcement or public authorities where required by law;
- parties involved in a merger, acquisition, investment, financing, reorganisation or sale of assets.
We may share aggregated or de-identified audience insights with customers or partners for business, benchmarking, product development, advertising, campaign optimisation or experience recommendation purposes.
We do not sell raw live video streams, raw facial images or faceprints.
11. International Transfers
We may process and transfer personal data in countries other than the country where you are located. These countries may have different data protection laws.
Where required, we use appropriate safeguards for international transfers, such as:
- adequacy decisions;
- Standard Contractual Clauses;
- UK International Data Transfer Addendum;
- Data Privacy Framework participation, where applicable;
- contractual, technical and organisational safeguards.
12. Data Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Typical retention periods are:
| Data category | Typical retention |
| Live camera/video stream | Processed in real time and not intentionally stored on our servers unless the specific experience requires saving |
| Optional emailed photo/video/output | Usually deleted from active systems within 1–2 days after delivery or attempted delivery |
| Email address used to send an output | Usually deleted from active systems within 1–2 days after delivery or attempted delivery |
| Customer account and subscription records | For the duration of the customer relationship and as needed for legal, tax, accounting and contractual purposes |
| Billing and invoice data | As required by tax and accounting laws |
| Technical logs and security data | For a limited period necessary for security, troubleshooting and compliance |
| Support communications | For as long as needed to handle the request and maintain business records |
| Aggregated or de-identified analytics | May be retained for longer because they are not intended to identify an individual |
Backups may retain data for a limited additional period before deletion in accordance with our backup lifecycle.
13. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include:
- access controls;
- authentication;
- encryption in transit;
- secure hosting;
- logging and monitoring;
- separation of customer environments where appropriate;
- employee and contractor confidentiality obligations;
- incident response procedures;
- data minimisation;
- retention controls.
For higher-risk deployments, including deployments involving optional audience analytics, biometric-related processing, children, public spaces or large-scale use, we may apply additional safeguards such as deployment-specific configuration controls, customer approvals, DPIA support, enhanced notices, consent flows, shorter retention periods, restricted access, audit logging and feature disabling in jurisdictions where the feature is not legally permitted.
No system is completely secure. We cannot guarantee absolute security.
14. Your Privacy Rights
Depending on your location and applicable law, you may have rights to:
- request access to personal data;
- request correction;
- request deletion;
- restrict processing;
- object to processing;
- withdraw consent;
- request portability;
- opt out of certain processing;
- object to profiling;
- appeal a refusal of a privacy request;
- lodge a complaint with a data protection authority.
To exercise your rights, contact us at: dima@ex.comloook.ai
If your request relates to a LOOOK.AI Mirror deployment operated by one of our business customers, we may direct you to that customer or work with that customer to respond.
15. How Rights Work When We Do Not Identify Users
In many LOOOK.AI Mirror experiences, users are not registered, and we do not store their name, face, faceprint, device identifier or other direct identifier.
This means that if you only interacted with a live experience and did not provide an email address or other contact details, we may not be able to identify which data relates to you, because the live stream was not stored and analytics may have been aggregated or de-identified.
When submitting a request, please provide enough information to help us assess it, such as:
- date and approximate time of interaction;
- customer or venue name;
- location;
- experience used;
- email address used to receive an output, if any;
- any reference number or message you received.
We will not require you to provide more personal data than reasonably necessary to verify and process your request.
16. Marketing Communications
We may send marketing communications to business contacts where permitted by law. You may opt out at any time by using the unsubscribe link or contacting us.
We do not use live facial images or live video streams to send direct marketing to individual visitors.
17. Children
LOOOK.AI Mirror is not intended for use by children unless the relevant customer deployment is specifically configured and legally approved for that audience.
Business customers must not deploy LOOOK.AI Mirror in a child-directed context, school, children’s event, children’s product environment or similar setting unless they have entered into appropriate terms with us and implemented all required notices, parental consents and safeguards.
In the United States, services directed to children under 13, or services with actual knowledge that personal information is collected from children under 13, may require verifiable parental consent and other protections.
Where Snap Camera Kit is used for users under 13 in the United States, additional Snap requirements may apply.
If you believe a child has provided personal data without required consent, please contact us.
18. Automated Processing and Profiling
LOOOK.AI Mirror uses automated technologies to apply AI, AR, visual effects, transformations and analytics.
We do not use LOOOK.AI Mirror to make decisions about individuals that produce legal or similarly significant effects, such as decisions about employment, credit, insurance, housing, healthcare, education, eligibility for public services or access to essential services.
Audience analytics are intended to produce aggregated or de-identified business insights, not to make decisions about a specific person.
19. Customer-Uploaded or Customer-Selected Experiences
Customers may use their own filters, AR experiences, creative assets, prompts, AI workflows, campaigns or content through LOOOK.AI Mirror.
Customers are responsible for ensuring that their own experiences, content and instructions comply with applicable law and do not unlawfully collect, infer, store, display, share or discriminate based on personal data or sensitive characteristics.
We may refuse, suspend or remove experiences that we believe create legal, privacy, security, safety or reputational risks.
20. Links and Third-Party Services
Our services may contain links or integrations with third-party services. Third-party services may process personal data under their own terms and privacy policies.
We encourage you to review the privacy policies of relevant third-party providers, including Snap, Decart and any other third-party technology provider identified in the applicable experience or customer deployment.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may notify customers through the platform, by email or by posting an updated version.
The updated version will be effective from the date stated at the top of the policy.
22. Contact Us
For questions, requests or complaints, contact:
FULL FUTURE LTD
Registered address: C/O Fdca-Office 2 Bennet’s House, 21 Leyton Road, Harpenden, England, AL5 2HU
Registration number: 15861125
Email: dima@ex.comloook.ai
Data protection contact / DPO: dima@ex.comloook.ai
EEA and UK Privacy Supplement
This section applies to individuals located in the European Economic Area, the United Kingdom and Switzerland, where applicable.
1. Controller, Processor and Customer Deployments
For customer account data, subscription data, service analytics, security data and our own business operations, we are the controller.
For live experience processing carried out solely on behalf of a business customer, we generally act as processor, and the customer acts as controller.
For aggregated or de-identified audience analytics that we determine and use for our own product improvement, benchmarking or business insight purposes, we may act as controller.
2. Legal Bases
We rely on the following legal bases:
| Processing activity | Legal basis |
| Customer account creation and subscription management | Contract |
| Billing, invoicing and tax records | Legal obligation |
| Customer support | Contract or legitimate interests |
| Platform security and fraud prevention | Legitimate interests |
| Live experience processing | Customer’s legal basis where we act as processor; consent or legitimate interests where we act as controller, depending on deployment and applicable law |
| Optional email delivery of user-requested output | Consent or performance of requested service |
| Non-essential cookies | Consent |
| Product analytics and service improvement | Legitimate interests, or consent where required |
| Aggregated or de-identified audience insights | Legitimate interests, consent where required, and only after appropriate safeguards |
| Special category data or sensitive biometric-related processing | Explicit consent or another applicable Article 9 condition, where legally available |
3. Special Category Data and Biometric Data
We do not intentionally identify or verify individuals by face.
However, some visual processing may involve facial landmarks, body tracking, pose estimation or similar technical features. Depending on the configuration and applicable law, this may be treated as biometric data or special category data.
Where special category data is processed, we will only do so where a valid Article 9 condition applies.
We do not deploy AI systems in the EEA to categorise individuals based on biometric data in order to deduce or infer race, ethnic origin, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
4. DPIA and High-Risk Processing
Certain deployments of LOOOK.AI Mirror may require a Data Protection Impact Assessment, especially where they involve:
- systematic monitoring of a publicly accessible area;
- large-scale processing of visual data;
- biometric-related processing;
- sensitive attribute analytics;
- children or vulnerable individuals;
- new AI technologies;
- profiling or audience segmentation.
Where we act as processor, the customer is responsible for determining whether a DPIA is required, and we will provide reasonable assistance as required by our data processing agreement.
5. Individual Rights
You may have the right to:
- access your personal data;
- rectify inaccurate data;
- erase data;
- restrict processing;
- object to processing based on legitimate interests;
- withdraw consent;
- data portability;
- lodge a complaint with a supervisory authority.
You may contact us at dima@ex.comloook.ai.
You may also contact your local supervisory authority. In the UK, this is the Information Commissioner’s Office. In the EEA, this is usually the supervisory authority in your country of residence, work or alleged infringement.
6. International Transfers
Where personal data is transferred outside the EEA, UK or Switzerland, we use appropriate transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful safeguards.
U.S. State Privacy Supplement
This section applies to residents of U.S. states with applicable consumer privacy laws, including California and other states where such laws apply.
1. Categories of Personal Information Collected
Depending on your interaction with us, we may collect the following categories of personal information:
| Category | Examples | Sources | Purposes |
| Identifiers | Name, business email, phone number, account login, email used for output delivery | You, customer, platform | Account management, support, delivery, communications |
| Commercial information | Subscription details, billing records, payment status | Customer, payment provider | Billing, contract administration |
| Internet or network activity | IP address, dashboard logs, website activity, device logs | Platform, website | Security, analytics, troubleshooting |
| Audio, electronic, visual or similar information | Live image/video stream, photo, generated output | Camera/device, user interaction | Provide the selected experience |
| Inferences | Engagement statistics, broad audience segments, usage patterns | Platform analytics | Aggregated insights, product improvement, experience recommendations |
| Sensitive personal information, where enabled and lawful | Biometric-related data, precise location if enabled, sensitive audience categories if legally permitted | Camera/device, customer deployment | Only for disclosed and legally permitted purposes |
| Professional or employment-related information | Job title, company role | Customer users | Account administration and B2B communications |
2. Categories Disclosed for Business Purposes
We may disclose personal information to:
- service providers;
- processors;
- business customers;
- cloud providers;
- email providers;
- analytics providers;
- security providers;
- payment processors;
- third-party SDK/API providers;
- professional advisers;
- regulators or public authorities.
3. Sale or Sharing of Personal Information
We do not sell raw live video streams, raw facial images, faceprints or email addresses collected solely to deliver a requested output.
We may provide customers or partners with aggregated or de-identified audience analytics and business insights. These are not intended to identify any individual.
If we ever sell or share personal information as defined by applicable U.S. state privacy laws, including for cross-context behavioural advertising, we will update this Privacy Policy and provide any required opt-out mechanism, such as a “Do Not Sell or Share My Personal Information” link.
4. Sensitive Personal Information
We use sensitive personal information only as necessary to provide the requested service, maintain security, comply with law, or for other purposes permitted by applicable law.
Where required, we obtain consent before processing sensitive personal information.
California residents may have the right to limit certain uses and disclosures of sensitive personal information.
5. U.S. Privacy Rights
Depending on your state, you may have rights to:
- know or confirm whether we process your personal information;
- access personal information;
- delete personal information;
- correct inaccurate personal information;
- obtain a portable copy of personal information;
- opt out of sale;
- opt out of sharing for cross-context behavioural advertising;
- opt out of targeted advertising;
- opt out of certain profiling;
- limit the use of sensitive personal information;
- appeal a decision on your request.
To exercise rights, contact dima@ex.comloook.ai.
We may need to verify your request. If we cannot reasonably identify you because we did not store identifiable data, we may be unable to fulfil certain requests.
6. Non-Discrimination
We will not discriminate against you for exercising your privacy rights.
7. Authorized Agents
Where permitted by law, you may use an authorized agent to submit a request. We may require proof of authorization and verification of identity.
8. Appeals
If we deny your privacy request and applicable law gives you a right to appeal, you may appeal by contacting dima@ex.comloook.ai and including “Privacy Appeal” in the subject line.
9. Biometric Privacy Notice
Unless expressly stated for a specific feature, we do not create, store or use face geometry, faceprints, voiceprints, iris scans, fingerprints or other biometric identifiers to identify or verify individuals.
If a feature involving biometric identifiers is enabled in a jurisdiction that requires a biometric notice, consent or retention policy, we and/or the customer will provide the required notice and consent before the feature is used.
We do not sell, lease or trade biometric identifiers.
Any biometric-related data, if collected, will be retained only for the period necessary for the disclosed purpose or as otherwise required by law.
Short Notice for QR Code / Device Signage
LOOOK.AI Mirror Privacy Notice
This mirror uses a camera to run an AI/AR visual experience. When you stand in front of or activate the mirror, your live image/video may be processed in real time to apply the selected effect and show the result on the screen.
Unless the experience clearly says otherwise, we do not store your live video stream or facial image on our servers.
Some experiences may let you send a photo or output to your email. If you choose this, we use your email only to send the requested output and usually delete it within 1–2 days.
Some deployments may collect aggregated or de-identified analytics, such as number of sessions, duration of use and experience performance. These analytics are not intended to identify you.
Some experiences may use third-party technologies, including Snap Camera Kit or AI model providers.
If you do not want your image to be processed, please do not use the mirror.

