*PRIVACY POLICY
what we collect, why, and the controls you hold. version 1.0 — effective july 19, 2026 (under legal review).
WHO WE ARE
ASiLUM magazine ("ASiLUM", "we") operates asilummagazine.com — a fashion discovery magazine with a personal taste engine. Privacy questions and requests: legal@asilummagazine.com.
WHAT WE COLLECT
a pseudonymous device identity. a random identifier in a signed, http-only cookie plus a matching identifier in your browser's local storage. it is not your name and we do not link it to one unless you sign in.
an optional account. signing in uses a magic link, so we hold your email address. signing in moves your existing anonymous taste data under your account, once, with your action.
taste signals. saves, favorites, skips, searches, viewing time, corrections you give Asterisk, and moodboard training words. these build the taste profile that ranks your feed. you can inspect every class of this data in the Asterisk control room.
content you add. moodboard images are analyzed for color inside your browser — only the color summary and the file name reach our servers, never the image itself. wardrobe garment photos are different: with your explicit per-upload consent they are stored in a private bucket, served only through short-lived signed links, and erased — verifiably — when you delete them. body measurements you enter stay in the first-party fit engine; they are never sent to merchants or to any external model.
purchase tickets. if you ask us to track an external purchase, we store what you submitted, with your consent, under the disclaimer shown at the time.
technical records. rate-limit counters (stored as hashes, not identities), search queries for relevance improvement, and the security logs our hosting providers keep to run the site.
WHAT WE DO NOT DO
no advertising. no selling or sharing of personal data for marketing. no third-party analytics or tracking pixels. no cross-site tracking. no inference of sensitive traits, ever. no children's data — the service is not directed to children under 13 and we do not knowingly collect their information. no external AI model receives your personal data: every model integration in this product is switched off, and if one is ever enabled it will be opt-in, disclosed on the surface where it operates, and covered by an updated version of this policy.
WHO PROCESSES DATA FOR US
supabase (database, authentication, and private file storage; hosted in canada) and vercel (site hosting, delivery, and security filtering). both act under our instructions to run the service — no other recipients.
COOKIES
essential cookies only: the signed device-identity cookie described above and the short-lived security cookies our hosting sets when it checks that a visitor is not an abusive bot. there are no advertising or analytics cookies, which is why there is no cookie banner.
YOUR CONTROLS
see it: the Asterisk control room shows what the system holds and lets you export it as JSON. correct it: every recommendation carries correction controls that retrain or exclude. pause it: Asterisk guidance can be switched off; hard filters still apply and your data sits unused. delete it: Settings holds a typed-confirmation delete that removes personalization data, and wardrobe photos erase on demand, storage object first. deleting your data is not conditioned on anything.
RETENTION
taste and content data persist while your profile is active and go when you delete them. security and search records are kept for limited operational periods; the exact schedule is under final review and this policy will state it when fixed. we never keep deleted wardrobe photos — erasure is verified against the storage bucket before the request succeeds.
CHANGES
we will post any material change here with a new version number and effective date. continued use after the effective date means the new version applies.