This policy describes how the Fitwear app (the "Service", "we", hosted at
fitwear.app) collects, uses and protects
your data. By using the app, you agree to this policy.
1.What we collect
Account data:
- email and password (stored as a bcrypt hash, cannot be recovered);
- display name.
Content you upload:
- your body scan photos for virtual try-on;
- clothing photos you add to your wardrobe;
- generated try-on results;
- feedback (👍/👎) and saved capsule outfits.
Technical data:
- IP address, device type, app version, request timestamps;
- Apple Push Notifications device token (if you allowed notifications);
- error logs and performance metrics.
2.How we use it
- generate virtual try-ons from your photos;
- store your try-ons and capsules so you can revisit them;
- personalize outfit recommendations based on your feedback;
- send push notifications when a try-on is ready (with your consent);
- protect the service: block disallowed content (NSFW), prevent abuse (rate limit + risk score);
- analyze aggregate stats to improve model quality.
3.Who we share with
We share only de-identified images with external AI providers for processing:
- BytePlus (Byte Capital, ByteDance) — primary virtual try-on provider
(Seedream 4.5 model), plus clothing classification and content checks.
Sent: URLs of your body scan and clothing photos. Personal data (email, name) is not sent.
Images are not used for model training.
See byteplus.com/legal/privacy-policy.
- fal.ai (fal Ltd, on Google Cloud infrastructure) — fallback virtual try-on
provider and content vision checks (Birefnet, nano-banana).
Sent: URLs of your body scan and clothing photos. Personal data (email, name) is not sent.
Images are not used for model training.
See fal.ai/privacy.
- Google Gemini (Google LLC) — outfit compatibility analysis for capsule curation
(gemini-2.5-flash model) and pre-flight style scoring. Only clothing metadata (category, color,
type) is sent — no photos. Per Google AI policy, data is not used for training.
See ai.google.dev/gemini-api/terms.
- Anthropic Claude (Anthropic PBC) — advanced stylist advice for PRO+ tier
(Claude Sonnet model). Wardrobe metadata and preferences sent; no photos.
See anthropic.com/privacy.
- OpenAI (OpenAI Inc) — fallback classifier and AI stylist (GPT-4o-mini model).
Clothing metadata and preferences sent; photos only when necessary for classification
(no email/name in metadata).
See openai.com/policies/privacy-policy.
- WaveSpeed AI — fallback virtual try-on provider.
Body scan URL and clothing photo URLs sent.
See wavespeed.ai/privacy.
- Apple Push Notifications service — to deliver push notifications (device token + notification text only).
All AI providers commit not to use your data for training their models (per their API Terms of Service for commercial customers).
Data deletion request to providers is processed automatically when you delete your account (see § 7).
We do not sell your data to third parties and do not use it for advertising.
4.Where data is stored
Data is stored on servers located in the European Union.
Database backups are created daily and kept for 7 days.
Uploaded images live on the server filesystem and are accessed via HTTPS (most operations require authorization).
5.How long we keep data
- account and related data — for as long as you use the app;
- after account deletion (see § 7) — data is removed within 30 days, except as required by law;
- security event log (NSFW blocks, rate-limit events, access audit) — kept in the database for up to 12 months, then deleted automatically.
6.Security
- HTTPS (TLS 1.2/1.3) for all client-server connections;
- JWT auth tokens, bcrypt-hashed passwords;
- strict content moderation: prompt guard + vision check on input and output images;
- anti-abuse: rate limiting and automatic risk-scoring;
- safety journal accessible only to administrators.
7.Your rights
Under applicable law (including GDPR), you can:
- request a copy of your data;
- correct inaccurate data via the app settings;
- delete your account and related data — directly in the app (Profile → Delete Account) or by writing to privacy@fitwear.app;
- withdraw consent (this triggers account deletion);
- file a complaint with your supervisory authority.
We respond within 30 days.
8.Children
The Service is not intended for users under 18. We do not knowingly collect data from minors.
If you discover a minor is using the Service, please write to
privacy@fitwear.app and we will remove the account.
9.Changes
For material changes, we will update the "Effective" date and notify active users via the app or email.
Continued use after changes means you accept the new version.
10.Data Controller
For the purposes of GDPR (EU 2016/679), UK-GDPR, and equivalent
data-protection laws worldwide, the Data Controller is:
Private Entrepreneur "Matvei Popchenko", Republic of Armenia
Taxpayer Registration Number (TIN): 20313581
State registration number: 286.1587934 (registered June 08, 2026, State Register
of Juridical Persons, Ministry of Justice of the Republic of Armenia)
Registered address: 26a Movses Khorenatsi str., office 201, Kentron,
Yerevan 0010, Republic of Armenia
Email:
privacy@fitwear.app
EU representative (GDPR Art. 27): [to be appointed via Prighter / DataRep / equivalent
after registration].
Legal basis for processing (GDPR Art. 6): consent (Art. 6(1)(a)) for biometric
data and AI processing; contract performance (Art. 6(1)(b)) for service delivery;
legitimate interest (Art. 6(1)(f)) for fraud prevention and service security.
Biometric and face data (GDPR Art. 9): photos of your face and body used for
virtual try-on are processed only with your explicit consent obtained in-app. You can
withdraw consent at any time from the app (Profile → AI Consent), which will trigger
deletion of derived biometric features.
Face data — collection, use, sharing, and retention: the only face data
we collect is the photos you voluntarily upload as body scans, which may include your face.
We do not create faceprints, facial-geometry templates, or any facial-recognition
identifiers, and we do not use face data to identify, track, or match users. Face data is used
solely to render virtual try-on images and to crop/prepare your scan for that purpose. It is
shared only with the image-generation providers listed in § 3 (fal.ai, BytePlus, WaveSpeed)
for the immediate processing task; per their commercial API terms they do not retain inputs
beyond the inference request and do not use them for model training. Face data is stored on
our servers in the European Union (see § 4) for as long as you keep the scan in your account:
deleting a scan, withdrawing consent, or deleting the account permanently removes the photos
and all derived images within 30 days (see § 5 and § 7).
Automated decision-making (GDPR Art. 22): AI-generated try-on images
and style recommendations are produced by machine-learning models. These are
creative/decorative outputs and do not produce legal or similarly significant effects.
You can disable AI features at any time without losing access to your data.
International transfers (GDPR Art. 44-49): photos and prompts may be
transferred to AI providers in the US (OpenAI, fal.ai, WaveSpeed), UK (Google Gemini,
Anthropic), and Singapore (BytePlus). We rely on Standard Contractual Clauses (SCCs)
or equivalent safeguards published by each provider. Providers process data only as
instructed and do not retain inputs beyond the immediate inference task (per their
public data-use policies).
11.California Privacy Rights (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and sell;
- Delete personal information we have collected;
- Correct inaccurate personal information;
- Opt out of "sale" or "sharing" of personal information for
cross-context behavioral advertising — we do not sell or share personal
information for advertising purposes;
- Limit use of sensitive personal information (biometric data,
precise geolocation) — exercised via in-app AI Consent withdraw;
- Non-discrimination — we will not deny service or change pricing
because you exercise these rights.
To exercise these rights, email privacy@fitwear.app
with subject "California Privacy Request". We will respond within 45 days.
Authorized agents may submit requests with verifiable authorization. Categories of
personal information collected match Section 1 above (Cal. Civ. Code §1798.140(o)).
12.Contact
Privacy: privacy@fitwear.app
Support: support@fitwear.app
Legal: legal@fitwear.app