Privacy

What happens to the images you upload to FitPreview

A person photo can be sensitive. Here is the practical path your images take when you request a preview, plus the controls and limits worth knowing.

July 13, 2026 · 5 min read

All guides
AI-generated illustration about uploaded image privacyAI-generated illustration
Editorial illustration for this guide; it is not an uploaded customer photo or a try-on result.
01

Your images support one preview flow

FitPreview needs one person photo and one garment image to generate a static try-on preview. The application stores uploaded images in private object storage and uses time-limited signed links when an authorized service needs to read them.

In the production remote-provider flow, the garment image is used to identify a broad garment category and both inputs are made available to the generation provider for the requested result. The completed result is downloaded, checked, and stored back in FitPreview’s private storage before it is shown to you.

02

Anonymous access does not mean no data

You can begin without registering, but FitPreview still creates an anonymous session and an internal profile so it can enforce credits, associate uploads with the current user, and protect private reads. “Anonymous” describes the account flow; it does not mean the service receives no technical or image data.

If you register, saved history can remain associated with your profile. Account and session records are separate from the image files themselves.

03

Deleting history has a specific scope

Registered users can delete an individual saved generation from History. FitPreview hides it from active History immediately and keeps it in Recently deleted for a limited recovery period, where it can be restored while that option remains available and permanent deletion has not started. Permanent cleanup runs asynchronously, and the generation cannot be restored after that cleanup starts.

Reusable person and garment images are deleted only when no other generation or processing request references them. New History and try-on requests stop issuing signed URLs for a deleted result immediately, but a signed image URL issued earlier may remain usable for no longer than five minutes. This control does not delete unrelated account, security, support, analytics, email, provider, or backup records. Use the Contact page to request deletion of an entire account or ask about other deletion options.

04

Support and analytics are separate

If you allow Preferences and confirm the support notice, Crisp processes the message and associated technical session information. A signed-in user may choose to share only their account name and email for conversation identification. Do not paste passwords, API keys, or storage links into a message.

FitPreview loads Plausible and Microsoft Clarity only when Cookiebot reports Statistics consent. Person photos, garment images, and generated results are marked as masked image surfaces for Clarity, but you should still read the Privacy Policy for the complete current disclosure.

05

Make an informed upload choice

Use a photo only when you have the right and permission to upload it. Crop unnecessary people, documents, locations, or background details, and avoid submitting an image if you are not comfortable with the processing needed to create a preview.

The Privacy Policy is the controlling source for current providers, purposes, retention limits, security measures, and contact options. This guide is a practical overview, not a replacement for that policy.

Keep reading

Related guides

Ready to explore the outfit idea?

Create a static preview with your own images.

Create a free preview

FitPreview support