Privacy Policy

Effective April 17, 2026 · Last updated: July 18, 2026

This policy describes how the Fitwear app (the "Service", "we", hosted at fitwear.app) collects, uses and protects your data. By using the app, you agree to this policy.

1.What we collect

Account data:

Content you upload:

Technical data:

2.How we use it

3.Who we share with

We share only de-identified images with external AI providers for processing:

All AI providers commit not to use your data for training their models (per their API Terms of Service for commercial customers). Data deletion request to providers is processed automatically when you delete your account (see § 7).

We do not sell your data to third parties and do not use it for advertising.

4.Where data is stored

Data is stored on servers located in the European Union. Database backups are created daily and kept for 7 days. Uploaded images live on the server filesystem and are accessed via HTTPS (most operations require authorization).

5.How long we keep data

6.Security

7.Your rights

Under applicable law (including GDPR), you can:

We respond within 30 days.

8.Children

The Service is not intended for users under 18. We do not knowingly collect data from minors. If you discover a minor is using the Service, please write to privacy@fitwear.app and we will remove the account.

9.Changes

For material changes, we will update the "Effective" date and notify active users via the app or email. Continued use after changes means you accept the new version.

10.Data Controller

For the purposes of GDPR (EU 2016/679), UK-GDPR, and equivalent data-protection laws worldwide, the Data Controller is:

Private Entrepreneur "Matvei Popchenko", Republic of Armenia
Taxpayer Registration Number (TIN): 20313581
State registration number: 286.1587934 (registered June 08, 2026, State Register of Juridical Persons, Ministry of Justice of the Republic of Armenia)
Registered address: 26a Movses Khorenatsi str., office 201, Kentron, Yerevan 0010, Republic of Armenia
Email: privacy@fitwear.app

EU representative (GDPR Art. 27): [to be appointed via Prighter / DataRep / equivalent after registration].

Legal basis for processing (GDPR Art. 6): consent (Art. 6(1)(a)) for biometric data and AI processing; contract performance (Art. 6(1)(b)) for service delivery; legitimate interest (Art. 6(1)(f)) for fraud prevention and service security.

Biometric and face data (GDPR Art. 9): photos of your face and body used for virtual try-on are processed only with your explicit consent obtained in-app. You can withdraw consent at any time from the app (Profile → AI Consent), which will trigger deletion of derived biometric features.

Face data — collection, use, sharing, and retention: the only face data we collect is the photos you voluntarily upload as body scans, which may include your face. We do not create faceprints, facial-geometry templates, or any facial-recognition identifiers, and we do not use face data to identify, track, or match users. Face data is used solely to render virtual try-on images and to crop/prepare your scan for that purpose. It is shared only with the image-generation providers listed in § 3 (fal.ai, BytePlus, WaveSpeed) for the immediate processing task; per their commercial API terms they do not retain inputs beyond the inference request and do not use them for model training. Face data is stored on our servers in the European Union (see § 4) for as long as you keep the scan in your account: deleting a scan, withdrawing consent, or deleting the account permanently removes the photos and all derived images within 30 days (see § 5 and § 7).

Automated decision-making (GDPR Art. 22): AI-generated try-on images and style recommendations are produced by machine-learning models. These are creative/decorative outputs and do not produce legal or similarly significant effects. You can disable AI features at any time without losing access to your data.

International transfers (GDPR Art. 44-49): photos and prompts may be transferred to AI providers in the US (OpenAI, fal.ai, WaveSpeed), UK (Google Gemini, Anthropic), and Singapore (BytePlus). We rely on Standard Contractual Clauses (SCCs) or equivalent safeguards published by each provider. Providers process data only as instructed and do not retain inputs beyond the immediate inference task (per their public data-use policies).

11.California Privacy Rights (CCPA / CPRA)

California residents have the right to:

To exercise these rights, email privacy@fitwear.app with subject "California Privacy Request". We will respond within 45 days. Authorized agents may submit requests with verifiable authorization. Categories of personal information collected match Section 1 above (Cal. Civ. Code §1798.140(o)).

12.Contact

Privacy: privacy@fitwear.app
Support: support@fitwear.app
Legal: legal@fitwear.app