Privacy Policy
Last updated: EFFECTIVE_DATE
LEGAL_ENTITY (LEGAL_ADDRESS) is the controller for the personal data described here. The short version: the extension was built so that the interesting things — your photos, your looks, the garments, what you typed, and which shop you were on — never reach us at all.
What never leaves your browser
The following are stored only in your browser's local extension storage, on your own device. They are not uploaded to us, not synced across your devices, and not backed up by us:
- The photographs of yourself that you add.
- The looks the Service generates for you.
- The garment images you select from web pages.
- The extra instructions you type.
- The addresses of the pages you were browsing.
Deleting them in the extension, or uninstalling it, deletes them. We have no copy to delete.
What we do collect
| Install identifier | A random value created when you install the extension. It is not derived from you, your device or your browser — it is not a fingerprint. It is what your credit balance belongs to. |
| Credit balance and ledger | How many credits the install has, and a record of each movement — grants, spends, refunds and purchases. A balance cannot work without being stored. |
| Usage events | That a look was generated, whether it succeeded, and the extension version. Failures are recorded as one of a handful of fixed categories, never as error text, because an error message can quote the request back. This is optional — see below. |
| Purchase record | What was bought, for how much, and the email address you gave Paddle at checkout. The email is stored for one reason: so that a buyer who loses their install identifier can be given their credits back. |
There is no account, so we hold no name, no password and no profile. We never receive your card details.
Turning usage collection off
The usage events are a switch in the extension's Settings, on by default. Turning it off stops them and changes nothing else about how the Service works. The credit balance keeps syncing when it is off — that is an account balance rather than analytics, and the Service cannot function without it.
Why we are allowed to hold it
- Performance of a contract — the install identifier, the balance and the purchase record. Without them we cannot give you what you paid for.
- Legitimate interests — usage events, to know whether the product works and how much it is used, kept deliberately content-free and switchable.
- Legal obligation — transaction records we are required to keep for tax and accounting.
Who else processes it
- Supabase — database and hosting for the balance, the ledger and the usage events. Hosted in the EU.
- Paddle.com Market Ltd — our merchant of record. Paddle takes the payment, holds your billing details and email, issues the receipt, and handles tax. Paddle is a controller in its own right for that data; its privacy notice applies to it.
- Cloudflare — serves this website.
- An image generation provider — receives the photograph and the garment images for the moment it takes to produce a look, together with the instruction text. It does not receive your install identifier, your email or anything identifying you or the shop you were browsing. Generated images and inputs are not used to train models.
Where your images go during a generation
This is the one moment your photograph leaves your machine. To produce a look, the photograph you selected and the garment images are sent to the image generation provider, a look comes back, and it is stored in your browser. We do not keep a copy, and nothing about which page you were on travels with it.
How long we keep things
- Balance, ledger and install record: for as long as the install exists, because the balance is the reason they exist.
- Usage events: 24 months.
- Purchase records including the checkout email: as long as tax and accounting law requires, typically 6–10 years depending on jurisdiction.
Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive it in a portable form. Write to SUPPORT_EMAIL and we will act on it.
A practical note: because we deliberately do not know who you are, the install identifier is usually the only handle we have on your data. To act on a request we will normally need that identifier — the extension shows it in Settings — or the email address from your Paddle receipt. If you have neither, we may genuinely be unable to find any data relating to you, which is a consequence of the design rather than an evasion.
If you are in the EU or UK you also have the right to complain to your local data protection authority.
Children
The Service is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. Do not use the Service to generate images of a minor.
Changes
If this policy changes, the date at the top changes with it. Changes that materially affect what we collect will be announced in the extension before they take effect.
Contact
LEGAL_ENTITY, LEGAL_ADDRESS — SUPPORT_EMAIL.