Privacy Policy
Last updated: September 2, 2026
Decantech (“we”, “us”, or “our”), a company registered in France, operates the Outfitap mobile application (the “App”) and the website at outfitap.com (the “Website”). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App and Website (collectively, the “Service”).
We are committed to protecting your privacy and processing your data in compliance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and applicable French data protection law (Loi Informatique et Libertés). Decantech acts as the data controller for the personal data described in this policy.
1. Photos You Upload
Your photos are pass-through only. When you upload a photo for virtual try-on:
- Photos are transmitted over encrypted connections (TLS) and processed in real-time. They exist on our servers in memory only during processing (approximately 30–120 seconds) and are permanently discarded from our servers immediately after.
- For successful try-ons, photos are never stored on our own servers, databases, file systems, or any persistent storage.
- If a photo is blocked by content moderation (e.g. for containing nudity, swimwear, or lingerie), it may be retained in memory for up to 7 days for debugging and moderation review purposes, after which it is permanently deleted. These retained images are not used for any other purpose.
- To generate your try-on result, photos are sent to Google's Generative AI service (Gemini API). As required by Google's terms, we disclose the following:
- Google may temporarily retain submitted images for a limited period to detect abuse and enforce its policies, after which they are automatically deleted.
- Because Decantech is based in the European Economic Area, Google's paid-service data terms apply: Google does not use your photos to train or improve its AI models.
- Google may have human reviewers read and annotate API inputs and outputs to enforce its policies. Google states that it disconnects this data from your API key and account before review.
- This data may be processed in any country where Google maintains facilities.
- Photos are never used by us for AI model training, analytics, marketing, or any purpose other than generating your virtual try-on result and performing content moderation (see Section 4).
- Profile photos you add to the App are stored locally on your device only. We never upload or access them unless you initiate a try-on.
2. Information We Collect
2.1 Device Identifier
When you first open the App, we generate a random, anonymous device identifier (UUID). This identifier is used solely to:
- Manage your try-on credit balance and subscription status
- Apply rate limits and prevent abuse of the Service
- Verify the integrity of the App on your device (see Section 4)
This identifier cannot be used to personally identify you and is not linked to your name, email, phone number, or any other personally identifiable information.
2.2 Website Account and Anti-Abuse Data
Website sign-in uses your email address. To prevent repeated use of a promotional welcome-credit grant, we also generate a random first-party browser identifier and process your IP address. We store keyed hashes of the normalized email, browser identifier, and IP address with the welcome-credit claim; we do not collect a high-entropy browser fingerprint. These controls never reduce or block purchased credits.
2.3 Subscription and Purchase Data
Subscriptions and credit pack purchases are processed and billed entirely by the Apple App Store or Google Play Store. We do not collect, process, or store any payment information (credit card numbers, billing addresses, etc.).
Through our subscription management provider (RevenueCat), we receive and store the following data linked to your anonymous device identifier:
- Subscription status (active, expired, or cancelled)
- Subscription product identifier and expiration date
- Renewal status
- Credit balance (free, period, and purchased credits)
- Credit pack purchase events (for crediting your account)
2.4 Usage Analytics
We use PostHog (hosted in the European Union) to collect anonymous usage analytics to improve the App. Events tracked include:
- Onboarding completion steps
- Try-on actions (started, completed, failed - no photo content is included)
- Feature usage (profile creation, history viewing, sharing results)
- Paywall impressions and subscription selections
- App lifecycle events (opened, backgrounded)
- Error events (for debugging purposes)
All analytics events are linked to your anonymous device identifier only. We do not track your location, contacts, browsing history, or any personal information through analytics.
2.5 Crash Reports
We use Firebase Crashlytics (a Google service) to collect crash reports and error logs. This data includes:
- Device model, operating system version, and app version
- Stack traces and error messages when the App crashes
- Anonymous crash identifiers
Crash reports do not contain your photos, personal information, or usage content.
2.6 Device Integrity Data
To protect the Service from abuse and ensure requests originate from a legitimate copy of the App, we use:
- Apple App Attest (iOS) - verifies the authenticity of the App on your device. We store a public key and counter value linked to your device identifier.
- Google Play Integrity API (Android) - verifies that the App has not been tampered with. Integrity tokens are validated server-side and are not stored.
3. Legal Basis for Processing (GDPR)
We process your data on the following legal grounds:
- Contract performance (Article 6(1)(b) GDPR): Processing your photos for virtual try-on, managing your subscription and credit balance, and operating the Service as described in our Terms of Service.
- Legitimate interest (Article 6(1)(f) GDPR): Collecting anonymous analytics to improve the App, performing crash reporting to ensure stability, applying rate limits and device attestation to prevent abuse, and ensuring the security and integrity of the Service.
4. Third-Party Services
We use the following third-party services to operate the Service and may offer optional content hosted by third parties. Each service processes data according to its function:
- Google Generative AI (Gemini API) - Our virtual try-on AI and content moderation use Google's Gemini API. Photos are transmitted securely and processed by Google's AI models. Google may temporarily retain submitted data for a limited period to detect abuse and enforce its policies. Under the EEA terms, Google does not use this data for AI model training. Google human reviewers may review API inputs and outputs for policy enforcement (data is de-identified before review). Content moderation uses Google Generative AI to automatically reject inappropriate uploads. See Section 1 for full details. Data location: global (any Google facility).
- RevenueCat - Subscription and purchase management. Processes anonymous purchase events linked to your device identifier. Data location: United States.
- PostHog - Anonymous product analytics. Data location: European Union.
- Firebase Crashlytics (Google) - Crash reporting and error monitoring. Data location: United States.
- Cloudflare Turnstile (when enabled) - Automated abuse prevention for Website welcome-credit claims. Cloudflare may process limited browser and network data required to validate the security challenge.
- Apple App Store / Google Play Store - App distribution and in-app purchase processing. Governed by their respective privacy policies.
- Instagram, Pinterest, and TikTok - Some blog articles may include posts hosted by these platforms. When an article contains one of these posts, the embed loads automatically and your browser connects directly to that platform. The platform may receive technical data such as your IP address, browser information, and referring page, and may use cookies or similar trackers under its own policy. For a Pinterest Share link, our server may also contact Pinterest to resolve the public link while building the article. A direct link to the original post is shown below each embed. See the providers' respective privacy policies: Instagram, Pinterest, and TikTok.
5. International Data Transfers
Some of our sub-processors (Google, RevenueCat, Firebase Crashlytics) process data outside the European Economic Area, including in the United States and other countries where they maintain facilities. These transfers are safeguarded by:
- The EU–U.S. Data Privacy Framework (where the provider is certified), or
- Standard Contractual Clauses (SCCs) approved by the European Commission
PostHog analytics data is processed and stored within the European Union. When a blog article contains an embedded social-media post, that provider may process technical data outside the European Economic Area under the safeguards described in its privacy policy.
6. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- All data in transit is encrypted using TLS (Transport Layer Security)
- Photo processing occurs in secure, isolated server environments with no persistent storage
- Device attestation validates the integrity of every request
- Rate limiting protects against abuse
- Webhook idempotency ensures purchases and credits are processed exactly once
- Local data on your device is stored using encrypted storage (MMKV)
7. Data Retention
- Photos (our servers): Not retained. Discarded from server memory immediately after processing (within 30–120 seconds).
- Photos (Google): Google may temporarily retain images submitted to the Gemini API for a limited period for abuse detection and policy enforcement, after which they are automatically deleted. Retention periods are governed by Google's Gemini API Terms.
- Device identifier and subscription data: Retained in our database as long as you use the Service. Automatically purged after 12 months of inactivity.
- Analytics data (PostHog): Retained for up to 12 months, then automatically deleted.
- Crash reports (Firebase Crashlytics): Retained for up to 90 days.
- Purchased credits: Retained indefinitely until used or until your device record is purged due to inactivity.
- Website welcome-credit claims: Retained only as long as reasonably necessary for fraud prevention, abuse investigations, and legal compliance.
- Local data on your device: Stored until you uninstall the App or manually clear the data.
8. Your Rights (GDPR)
Under the GDPR, as a data subject in the European Economic Area, you have the following rights:
- Right of access - Request a copy of the personal data we hold about you.
- Right to rectification - Request correction of inaccurate or incomplete data.
- Right to erasure - Request deletion of your data (“right to be forgotten”).
- Right to restriction - Request that we limit how we process your data.
- Right to data portability - Receive your data in a structured, machine-readable format.
- Right to object - Object to processing based on legitimate interest, including analytics.
- Right to lodge a complaint - File a complaint with the French data protection authority (CNIL) at www.cnil.fr or with any supervisory authority in your EU member state.
Since we store minimal data and no photos, most of these rights are automatically satisfied by our architecture. To exercise any of these rights, contact us at support@outfitap.com. We will respond within 30 days.
9. Children's Privacy
The App is not directed at children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at support@outfitap.com and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of any material changes by updating the “Last updated” date at the top of this page. For significant changes, we may also provide notice within the App. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or have a data protection concern, please contact us:
- Email: support@outfitap.com
- Company: Decantech, France
You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), France's data protection authority, or with your local supervisory authority.
Our Privacy Commitment
- ✓Your photos are never stored on our servers - discarded immediately after processing
- ✓Photos are never used for AI training (EEA terms apply)
- ✓No personal data collection - only an anonymous device ID
- ✓Profile data stored locally on your device only
- ✓Analytics hosted in the EU (PostHog)
- ✓GDPR compliant