Legal
Privacy Policy
Last updated: July 31, 2026
The short version
FitMyMirror Hover lets you virtually try on clothing while you shop. To do that we need your photo and a few body measurements. We use them to render your try-ons — nothing else.
- We do not sell your data.
- We do not show ads or share with advertisers.
- You can delete your photo and measurements at any time.
- Try-ons are private to your account by default.
What we collect
Account
Email address and authentication identifier when you sign in.
Body profile
The photo you upload, plus the measurements you enter (height, weight, chest, waist, hips, shoulder, size, gender, fit preference).
Try-on activity
The product images you try on, the generated result images, and the source page URL — used to cache results and power your saved gallery.
Diagnostics
Standard server logs (IP, user agent, timestamps) for security and debugging. Retained for 30 days.
Biometric data & explicit consent (GDPR Art. 9)
Your uploaded photo is processed as biometric data, a special category of personal data under GDPR Art. 9. We ask for your explicit consent the first time you upload a photo, and again whenever you revoke it from Settings → Privacy. Without consent we cannot render try-ons. You can withdraw consent at any time; doing so deletes the photo from your device cache and stops further AI processing.
How we use it
- Generate try-on images and short scene videos for you.
- Save your lookbook so you can revisit past try-ons.
- Improve reliability and prevent abuse of the service.
AI training — what we never do
User-uploaded images, selfies, body photos, and generated try-ons are never used to train AI models — ours or anyone else's — without your explicit, separate consent.
- We do not train on your photos.
- We send your photo to third-party AI providers only at the moment of rendering a try-on, and only under contracts that forbid them from using your input or the output for model training.
- We do not enroll you in any "improve the model" data-sharing program by default.
- If we ever want to use your photo to fine-tune a model, we will ask for fresh, opt-in consent with a clear description of what would be trained and how to revoke.
Third-party AI providers (sub-processors)
Each provider below is a contractually bound processor under a Data Processing Agreement (DPA). They receive only what is strictly required to fulfil your request, and are forbidden from training on, reusing, or selling your data.
- Google (Gemini API) — try-on image generation, scene videos, measurement estimation. Inputs and outputs are not used to train Google's models when called via the paid API.
- OpenAI (GPT & image models) — outfit reasoning and selected image generation. API inputs/outputs are not used to train OpenAI's models under their API data policy.
- fal.ai — image and video model hosting. Inputs are processed only to return the requested output.
- Lovable Cloud (Supabase) — hosting, database, authentication, encrypted file storage.
- Paddle — Merchant of Record for payments. Never receives your photo or biometric data.
We review providers before integration and remove any whose policies become incompatible with this Privacy Policy. The current list is kept up to date here.
Image storage & security
- All uploads travel over TLS (HTTPS) end-to-end. Files are encrypted at rest by our storage provider.
- Each photo is stored under your user-id folder and is only served via long, unguessable URLs. Other users cannot list your files.
- Database rows holding your photos and try-ons are protected by row-level security — only you (and our server, when you request a try-on) can read them.
- We keep your photos only as long as your account exists or until you delete them — whichever comes first.
- We don't embed your photo in shareable links unless you explicitly use the "Share look" feature.
Data retention
- Photo & measurements: until you delete them or close your account.
- Saved try-ons: until you delete them.
- Generated cache: up to 30 days, then re-generated on demand.
- Logs: 30 days.
Your rights — including deletion
You have the right, at any time and free of charge, to:
- Delete your account — wipes all your data, photos, and storage files (Settings → Account).
- Delete individual photos from your profile or wardrobe.
- Export your data as a JSON download (Settings → Privacy → "Export my data").
- Withdraw consent for biometric processing or cookies (Settings → Privacy, or buttons at the top of this page).
- Access, correct, or restrict processing of your data.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, use Settings or email privacy@fitmymirror.app. We respond within 30 days.
The Chrome extension
The FitMyMirror Hover Chrome extension only activates on the page you are viewing when you hover a clothing image and click Install. It sends the image URL of that product to our service to render your try-on. It does not read passwords, form fields, browsing history, or any page content outside the image you click. The extension uses chrome.storage.local to remember your sign-in and preferences on your own device.
Children and minors
FitMyMirror is not directed to children. The minimum age is 18 in India and in any other country whose law requires verifiable parental consent for under-18s, and 16 elsewhere (or the higher local digital-consent age where one applies). We do not knowingly collect personal data — and in particular do not knowingly process biometric data (photos / faces) — from anyone below that age.
- India (DPDP Act 2023, s.9): processing a child's (under-18) data requires verifiable parental consent. We do not operate that flow, so under-18 accounts are not available in India. We never carry out tracking, behavioural advertising, or targeted advertising directed at children.
- United States: under-13 users are excluded under COPPA; state laws restricting teen data (e.g. sale of data of users under 16) are honoured — we sell no data at all.
- Where required, minors' data requires verified parental consent — we do not offer that flow today, so under-age accounts are not supported.
- If you believe a minor has created an account, contact privacy@fitmymirror.app and we will delete the account and all associated photos without delay.
Legal bases for processing (GDPR Art. 6 & 9)
- Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) — your photo, face and body measurements (biometric / special-category data), and any non-essential cookies.
- Contract (Art. 6(1)(b)) — creating your account, rendering the try-ons you request, subscriptions.
- Legitimate interests (Art. 6(1)(f)) — service security, abuse and fraud prevention, aggregated reliability metrics. We balance these against your rights and you may object at any time.
- Legal obligation (Art. 6(1)(c)) — tax, accounting and lawful requests.
Withdrawing consent is as easy as giving it (Settings → Privacy) and does not affect processing carried out before withdrawal.
Biometric retention & destruction schedule
This is our publicly available written biometric policy, required by laws such as Illinois BIPA, Texas CUBI and Washington's My Health My Data Act.
- Purpose: solely to render the virtual try-ons, scene images, videos and size recommendations you request.
- Term: we retain your photo and derived measurements until you delete them, until your account is closed, or after 24 months of inactivity — whichever happens first — and in no case longer than 3 years after your last interaction.
- Destruction: deletion wipes the database rows and the underlying storage objects; backups age out within 30 days.
- Disclosure: your biometric data is disclosed only to the AI processors listed above, only at the moment of rendering, never sold, leased, traded or profited from.
- No training: your biometric data is never used to train any model.
International data transfers
We are a global service, so your data may be processed outside your country — including in the EEA, the UK, the United States and India. Where we transfer personal data out of the EEA/UK/ Switzerland we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (with the UK Addendum / Swiss annex as applicable), together with transfer-risk assessments and encryption in transit and at rest. Transfers from India comply with s.16 of the DPDP Act (no transfer to a restricted territory). Copies of the relevant safeguards are available on request.
Automated processing
We use AI to generate images and to suggest a clothing size. These outputs are suggestions only — they produce no legal or similarly significant effect on you, and no automated decision-making in the sense of GDPR Art. 22 takes place. You can always ignore a suggestion, correct your measurements, or ask a human to review by emailing us.
India — DPDP Act 2023 (Digital Personal Data Protection)
For users in India we act as a Data Fiduciary and you are the Data Principal. This policy doubles as the notice required by s.5, in plain language, and is available in English; we will provide it in any Eighth Schedule language on request.
- Consent is free, specific, informed, unconditional and unambiguous, taken separately for your photo and for cookies, and is withdrawable at any time in Settings → Privacy with the same ease.
- Your rights: access a summary of your data and processing (s.11), correction, completion, updating and erasure (s.12), grievance redressal (s.13) and nomination of another person to exercise your rights in case of death or incapacity (s.14).
- Grievance Officer: the Privacy Team, FitMyMirror — grievance@fitmymirror.app. We acknowledge within 72 hours and resolve within 30 days. If unsatisfied you may complain to the Data Protection Board of India.
- Erasure on withdrawal: when you withdraw consent or close your account we erase your personal data unless retention is required by law.
- Breach notification: we notify affected Data Principals and the Board without delay, as required.
Your regional rights around the world
We apply one global standard — the strongest applicable protection — to every user. Specific regimes:
- EU / EEA (GDPR) & UK (UK GDPR, DPA 2018): access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to complain to your supervisory authority (or the UK ICO).
- Switzerland (revFADP) and Norway/Iceland/Liechtenstein — equivalent rights; Swiss users may contact the FDPIC.
- United States (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA and successors): know, access, delete, correct, portability, opt out of sale/sharing/targeted advertising, and limit the use of sensitive personal information (your photo and biometric data are sensitive PI). We do not sell or share personal information and we honour Global Privacy Control browser signals automatically. We never discriminate against you for exercising a right.
- Illinois BIPA / Texas CUBI / Washington MHMDA: we obtain a written release before capturing biometric identifiers and publish the retention schedule above.
- Canada (PIPEDA) & Québec (Law 25): access, correction, withdrawal, portability, de-indexing, and the right to complain to the OPC or the Commission d'accès à l'information.
- Brazil (LGPD): confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent; ANPD complaints accepted.
- Australia (Privacy Act / APPs): access and correction; the OAIC handles complaints. Biometric information is sensitive information and is only collected with consent.
- Japan (APPI), South Korea (PIPA), Singapore (PDPA), UAE (PDPL), Saudi Arabia (PDPL), South Africa (POPIA), Nigeria (NDPA), New Zealand (Privacy Act 2020) — equivalent access, correction, deletion and consent-withdrawal rights.
- China (PIPL): the service is not offered to users in mainland China; we do not process facial data of PRC residents.
Exercise any right in Settings → Privacy or by emailing privacy@fitmymirror.app. We verify your identity through your signed-in account, respond free of charge, and never longer than 30 days (45 days in the US where extension applies, 30 days in India). An authorised agent or nominee may act for you with proof of authority.
Security incidents
If a personal-data breach occurs we notify the competent supervisory authority within 72 hours (GDPR Art. 33, UK GDPR, LGPD, POPIA) and the Data Protection Board of India and affected users without delay under the DPDP Act, plus any US state notification requirements that apply. Biometric incidents are always treated as high-risk and communicated to affected users directly.
Data controller & contacts
- Controller / Data Fiduciary: FitMyMirror — privacy@fitmymirror.app
- Data Protection Officer: dpo@fitmymirror.app
- India Grievance Officer: grievance@fitmymirror.app
Changes
If we make material changes we will update the date above and, for significant changes, notify you by email. Where a change affects processing that relies on your consent, we ask for fresh consent before it takes effect.
Payments and Paddle (Merchant of Record)
When you subscribe, our reseller Paddle.com acts as the Merchant of Record. Paddle collects and processes your billing information (name, billing address, payment method, tax data) to take payment, issue invoices, handle tax compliance, and manage refunds and chargebacks. Fit Mirror Now receives subscription status and a Paddle customer ID — we do not see or store your full card details.
Data sharing
We share personal data only with:
- Hosting and infrastructure providers (Lovable Cloud / Supabase) under appropriate data-processing terms.
- Paddle, our Merchant of Record, for payments, subscription management, tax, and invoicing.
- AI model providers used to generate try-on images, limited to what's required to produce the output.
- Professional advisers (legal, accounting) and authorities where required by law.
Contact
Questions? Email privacy@fitmymirror.app.
