Security & data handling

A customer's photo is personal. We treat it that way.

Virtual try-on works from images of a person's hand, neck or ear. That is sensitive by nature, so our defaults lean toward keeping as little as possible, for as short as possible.

What we store

The photo, the render, and not much else.

We collect what a try-on needs and are deliberate about what we keep once it is done.

Try-on images

The hand, neck or ear photo used for a session, plus the resulting render. Used to produce the try-on and, briefly, to let a customer revisit it.

Sizing signals

The measurements or size estimates derived from a session, so a confirmed size can travel with an order.

Try-on activity

Which catalog pieces were tried on, for analytics - kept separate from the identifiable image wherever possible.

Retention & deletion

Photos do not linger by default.

The most sensitive item - the customer image - has the shortest life in our system.

Deleted after the session. Our default is to delete a customer’s try-on photo after the session ends, or after a short revisit window that a retailer configures.
Renders follow the same rule. A generated render is treated with the same care as the source photo and removed on the same schedule.
Analytics without the face. Aggregate try-on activity is retained for insight; it is decoupled from the identifiable image so the two are not held together needlessly.
Deletion on request. A retailer can request deletion of a customer’s data, and we act on it.
Protection & access

Encrypted moving and at rest, with tight access.

Encryption in transit and at rest

Data is encrypted as it travels between the customer, the store and our systems, and encrypted while stored.

Scoped access

Access to customer images is limited to what a task requires, on a need-to-use basis, rather than broadly available.

A clear deletion policy

Photos are removed after a try-on session on a defined schedule - not kept indefinitely on the chance they are useful later.

Transparent by design

A customer can be told plainly what is captured, why, and when it goes - because the answer is short.

Compliance posture

Stated honestly, current status only.

We describe where we actually are, not where we hope to be.

No overclaiming. We do not list certifications or standards we have not met. As our posture matures, this page will say so specifically.
Data-minimisation first. Our controls start from keeping less: the surest protection for a photo is not to retain it once its purpose is served.
Built to support obligations. Deletion, scoped access and encryption are in place to help retailers meet their own duties to their customers.

Have a specific data question?

If you need detail on retention windows or access for your own review, put it to us directly and we will answer plainly.