Effective April 17, 2026 · Last updated: July 18, 2026
This policy describes how the Fitwear app (the "Service", "we", hosted at fitwear.app) collects, uses and protects your data. By using the app, you agree to this policy.
Account data:
Content you upload:
Technical data:
We share only de-identified images with external AI providers for processing:
All AI providers commit not to use your data for training their models (per their API Terms of Service for commercial customers). Data deletion request to providers is processed automatically when you delete your account (see § 7).
We do not sell your data to third parties and do not use it for advertising.
Data is stored on servers located in the European Union. Database backups are created daily and kept for 7 days. Uploaded images live on the server filesystem and are accessed via HTTPS (most operations require authorization).
Under applicable law (including GDPR), you can:
We respond within 30 days.
The Service is not intended for users under 18. We do not knowingly collect data from minors. If you discover a minor is using the Service, please write to privacy@fitwear.app and we will remove the account.
For material changes, we will update the "Effective" date and notify active users via the app or email. Continued use after changes means you accept the new version.
For the purposes of GDPR (EU 2016/679), UK-GDPR, and equivalent data-protection laws worldwide, the Data Controller is:
EU representative (GDPR Art. 27): [to be appointed via Prighter / DataRep / equivalent after registration].
Legal basis for processing (GDPR Art. 6): consent (Art. 6(1)(a)) for biometric data and AI processing; contract performance (Art. 6(1)(b)) for service delivery; legitimate interest (Art. 6(1)(f)) for fraud prevention and service security.
Biometric and face data (GDPR Art. 9): photos of your face and body used for virtual try-on are uploaded to our servers, stored, and shared with our AI providers only with your explicit consent obtained in-app. You can withdraw consent at any time from the app (Profile → AI Consent), which will trigger deletion of derived biometric features.
On-device frame check: before any upload, the app checks on your device — using Apple's on-device Vision framework — whether a person is fully in the frame, so that an unusable photo never leaves your phone. This check runs entirely on your device, returns only a technical result (person in frame, legs cropped, head cropped, no person), creates no faceprint or biometric template, and performs no recognition or matching against anyone. Neither the photo nor any derived image data leaves your device as part of this check.
Face data — collection, use, sharing, and retention: the only face data we collect is the photos you voluntarily upload as body scans, which may include your face. We do not create faceprints, facial-geometry templates, or any facial-recognition identifiers, and we do not use face data to identify, track, or match users. Face data is used solely to render virtual try-on images and to crop/prepare your scan for that purpose. It is shared only with the image-generation providers listed in § 3 (fal.ai, BytePlus, WaveSpeed) for the immediate processing task; per their commercial API terms they do not retain inputs beyond the inference request and do not use them for model training. Face data is stored on our servers in the European Union (see § 4) for as long as you keep the scan in your account: deleting a scan, withdrawing consent, or deleting the account permanently removes the photos and all derived images within 30 days (see § 5 and § 7).
Automated decision-making (GDPR Art. 22): AI-generated try-on images and style recommendations are produced by machine-learning models. These are creative/decorative outputs and do not produce legal or similarly significant effects. You can disable AI features at any time without losing access to your data.
International transfers (GDPR Art. 44-49): photos and prompts may be transferred to AI providers in the US (OpenAI, fal.ai, WaveSpeed), UK (Google Gemini, Anthropic), and Singapore (BytePlus). We rely on Standard Contractual Clauses (SCCs) or equivalent safeguards published by each provider. Providers process data only as instructed and do not retain inputs beyond the immediate inference task (per their public data-use policies).
California residents have the right to:
To exercise these rights, email privacy@fitwear.app with subject "California Privacy Request". We will respond within 45 days. Authorized agents may submit requests with verifiable authorization. Categories of personal information collected match Section 1 above (Cal. Civ. Code §1798.140(o)).
Privacy: privacy@fitwear.app
Support: support@fitwear.app
Legal: legal@fitwear.app