Scope and definitions
This Privacy Policy applies when you visit or use FitPreview, including when you use an anonymous session, create an account, upload images, generate a preview, review saved history, or contact support.
“FitPreview,” “we,” “us,” and “our” refer to the operator of the FitPreview service under that brand name. The service is offered to users worldwide, subject to mandatory rules that apply where a user lives.
In this policy, “uploaded images” means the person photo and garment image you provide. A “generated preview” is the static virtual try-on image produced from those inputs. “Personal data” means information that identifies, relates to, or can reasonably be linked with a person.
FitPreview is built for shopping inspiration. Uploaded images and generated previews may be personal data, even when you use the service without creating a registered account.
FitPreview is only for people who are at least 18 years old. Do not use the service if you are under 18, and do not upload an image that depicts anyone under 18.
Information we collect
We collect the information needed to operate the feature you choose to use. The exact information depends on whether you browse the public site, create an anonymous session, register an account, generate a preview, or contact support.
- Account and session information, such as an internal user identifier, anonymous-session status, email address and verification status when you register, sign-in provider details when you choose a supported provider, session records, and available preview credits.
- Uploaded person photos and garment images, the storage paths associated with them, and the category inferred from a garment image.
- Generated previews and generation records, including status, timestamps, provider task identifiers, and error or retry information needed to complete a request.
- Technical and security information, such as request metadata, device-session identifiers, IP address and user-agent information used for authentication auditing, bot-verification results, and operational error logs. We do not log API keys, signed image URLs, or image contents as debugging data.
- Support information you choose to send through Crisp, including messages and technical information associated with the support session. If you are signed in and explicitly continue with account details, FitPreview also sends only your account name and email address to Crisp so support can identify that conversation. You can instead continue without account details.
- Website usage information from Plausible and Microsoft Clarity is processed only when Cookiebot reports that Statistics consent is available. User-uploaded and generated image surfaces remain marked for masking in Clarity.
How we use information
We use information only for the product, security, support, and measurement purposes described here.
- Create and maintain anonymous or registered access, credits, and saved preview history.
- Validate uploads, classify the garment, generate the requested preview, return the result, and recover or refund a preview credit when generation fails.
- Protect the service from abuse, diagnose failures, maintain reliability, and enforce these Terms and Conditions.
- Respond to support questions and understand problems reported by users.
- Understand aggregate site use through the analytics services described in this policy and use those insights to improve the product.
- FitPreview does not use uploaded images or generated previews to train AI models. This statement applies to FitPreview’s own use and does not make a promise about a service provider’s separate practices under its own terms.
- Send authentication messages and, when enabled and applicable, a one-time welcome service notification.
Storage and service providers
FitPreview uses a limited set of systems and service providers to run the service. They receive information only as needed for their role, under their own terms and privacy practices.
- Better Auth supports anonymous sessions, registered accounts, and authentication flows within the application. Account, session, and product records are stored in Neon Postgres in US West 2 (Oregon).
- Uploaded images and generated previews are stored in private Cloudflare R2 object storage configured with an Eastern Europe location hint. The hint is a best-effort placement preference rather than a guaranteed data-residency boundary. The browser receives time-limited signed URLs instead of storage credentials.
- Right Codes endpoints are used for garment classification and preview generation in the production remote-provider flow, including a Gemini classification model. The provider receives time-limited access to the uploaded images needed to perform the request. Provider-side retention, model-improvement, and training practices are governed by the provider’s own terms and settings.
- Cloudflare Turnstile receives technical request information to verify that protected requests, including preview generation and password recovery, are made by a person rather than an automated system.
- Cookiebot provides the consent banner, regional consent rules, consent record, and cookie-preference controls. Cookiebot processes the website URL, browser language, user agent, and an anonymized IP-based location lookup as needed to provide the configured regional experience and document a consent choice.
- Crisp provides the support chat. Crisp Total Privacy Mode must be enabled in production, and FitPreview also requires Cookiebot Preferences consent, a user click, and confirmation of the support notice before starting chat. A signed-in user who chooses to continue with account details shares only their account name and email address with Crisp; FitPreview does not send an internal user ID, session token, credit balance, History, image, payment, or subscription data.
- Plausible and Microsoft Clarity provide traffic and behavioral analytics only when Cookiebot reports Statistics consent. FitPreview does not send custom signed-in user identifiers to either analytics service. Clarity advertising storage remains denied.
- Configured email services, including SMTP delivery and Resend for an eligible welcome notification, process an email address and message-delivery information when an email is sent.
- CREEM acts as merchant of record for paid subscriptions and processes checkout, payment, billing, tax, receipt, refund, dispute, and customer-portal information needed for that role. FitPreview does not receive or store full payment-card details.
- FitPreview is an independent product and is not affiliated with or endorsed by Google. Third-party AI and infrastructure providers operate independently under their own terms.
International processing
Because FitPreview is available worldwide and uses providers in different regions, information may be processed outside the country where you live, including in the United States, Eastern Europe, and other regions used by the providers described above. Mandatory local rights remain unaffected.
Retention and deletion
FitPreview does not use one fixed retention period for every category of information. We retain account, session, image, generation, support, security, email, and operational records for as long as they are reasonably needed to provide the relevant feature, maintain service integrity, investigate abuse or failures, resolve disputes, and meet applicable obligations.
The criteria used to decide whether information is still needed include whether an account or anonymous session remains active, whether a saved generation remains in History, whether the information is needed to complete or support a request, and whether security, fraud-prevention, backup, record-keeping, or legal needs continue to apply.
When a registered user deletes an individual generation from History, FitPreview hides it from active History immediately and places it in Recently deleted for a limited recovery period. The user can restore it while that option remains available and permanent deletion has not started. When deletion becomes due, FitPreview’s deletion worker asynchronously removes the generated result and deletes reusable person or garment inputs only when no other generation or processing request references them. Once permanent deletion has started, the generation cannot be restored. This control does not delete unrelated account, session, security, email, provider, support, analytics, backup, or legal records.
New application requests stop issuing signed URLs for a deleted generation immediately. A signed image URL issued before deletion may continue to work until it expires, for no longer than five minutes on History and try-on result surfaces. URL expiry does not itself delete the underlying object. Provider-side and backup deletion remain subject to the relevant system’s retention and legal requirements.
To request deletion of other account, person-image, or service data, email support@fitpreview.shop. We may need to verify your identity and may retain limited information where required for security, fraud prevention, legal compliance, dispute resolution, or record keeping.
Your choices
You decide whether to upload images, create a registered account, or start a support conversation. You can stop using the service at any time. The self-service privacy controls currently available are deleting an individual saved generation from History, restoring it while that option remains available, or requesting permanent deletion. Deletion of an entire account remains a separate request handled through support.
You can use the Cookie preferences control in the site footer to review or change the choices available for your region. Where the configured Cookiebot regional rule requires a response, FitPreview keeps Plausible, Microsoft Clarity, and Crisp disabled until the corresponding Statistics or Preferences choice is available.
For other account, image, access, correction, export, deletion, or privacy questions, email support@fitpreview.shop. We accept these requests for review but may need to verify your identity, and the available response may be limited by security, technical feasibility, provider systems, and applicable law.
Security
We use reasonable technical and organizational safeguards designed to protect information, including private object storage, time-limited signed image URLs, server-side credentials, access checks tied to the current user, and masked private image surfaces for Clarity.
No internet service or storage system is completely secure. We cannot guarantee absolute security, uninterrupted availability, or that every attempted intrusion will be prevented.
Changes to this policy
We may update this policy when the product, its providers, data practices, or legal requirements change. We will publish the revised policy on this page and update the date above. Material product changes that affect this policy should be reflected here when those changes become available.
Contact us
Email support@fitpreview.shop or use the FitPreview Contact page and its support chat to ask a privacy question or request review of your data choices. Do not include passwords, storage credentials, or other secrets in a support message.
Contact FitPreview