Privacy Policy
How TryOn AI collects, uses, and protects your information.
This Privacy Policy explains how Dhruvisha Jagani (“we,” “us,” or “our”), the operator of the TryOn AI mobile application (the “App”), collects, uses, discloses, transfers, and protects your information. It applies to users worldwide, including the EEA, UK, California and other U.S. states, India, Brazil, and Canada. By using the App you acknowledge you have read and understood this Policy.
Your photos
Source photos are uploaded only temporarily for the try-on and deleted right after generation.
AI processing
Try-ons are generated by third-party AI (Google Gemini, ModelsLab) acting as our processors.
No biometrics
Face detection runs on your device only. We never store a faceprint or identify you by face.
Your control
Access, correct, or delete your data anytime — including in-app account deletion.
1 Who we are
The data controller responsible for your personal information is:
Dhruvisha Jagani
Surat, Gujarat, India
Email: support@nextwaveinfotech.com
We have not appointed a separate EEA/UK representative or Data Protection Officer; for all privacy matters, contact us using the details in the Contact section.
2 Information we collect
2.1 Information you provide
- Account information. Email, display name, and (for email sign-up) a password managed by our authentication provider. If you sign in with Google or Apple, we receive your name and email from that provider. With Apple’s “Hide My Email,” we receive a private relay email.
- Guest use. You may also use the App as a guest without registering. We then create an anonymous account identifier for you and collect the device and usage data described in this Policy, without an email address. Guest accounts and their data can be deleted in the App just like registered accounts (see Section 13).
- Profile information. Optional name, phone number, and profile photo.
- Photos & images. The full-body photo of yourself and the outfit images you upload or select to generate a try-on. See Section 3.
- Purchases. Processed by the Apple App Store or Google Play and our purchase provider (RevenueCat). We receive purchase and entitlement records, but not your full card number.
- Communications. Information you provide when contacting support or exercising a right.
2.2 Information collected automatically
- Device & identifiers. A device/OS identifier (a system build identifier on Android / iOS
identifierForVendor), device model, OS version, app version, language, and a user ID. - Usage & analytics. Events such as screens viewed, taps, and try-ons, via Mixpanel. We also associate your user ID, name, and email address with your analytics profile and record purchase amounts in Mixpanel to understand feature usage and revenue. Analytics only runs according to your consent choices (see Section 9).
- Advertising identifiers. Where ads appear, Google AdMob and Meta Audience Network may access your advertising ID to serve and measure ads.
- Approximate location. No precise GPS. Partners may infer city/region-level location from your IP address.
- Local storage. Some data is stored on your device (e.g., saved-photo path, a local cache of results, preference flags).
2.3 Information from third parties
- Sign-in providers (Google, Apple) — identity details as above.
- App stores & purchase provider (Apple, Google, RevenueCat) — purchase validation and subscription status.
3 Your photos & AI processing
Generating a try-on requires processing the images you provide — the most sensitive processing we perform:
- What we process. The photo of you and the outfit image you upload or select.
- On-device validation. Your photo is first checked on your device to confirm it contains a person (see Section 4).
- Transfer to AI processors. To create the try-on, your photo and the outfit image are transmitted to third-party AI services — ModelsLab and/or Google (Gemini API) — which process them to produce the result, acting as our processors/sub-processors.
- Temporary storage. Your source images are uploaded to our cloud storage (Google Firebase) only temporarily and are deleted automatically once the try-on is generated. If an interruption (for example, a lost connection) prevents immediate deletion, any remaining source uploads are removed when you delete your account. We do not use your raw source photos for any other purpose.
- Generated results. Generated try-on images are stored in our cloud storage (Google Firebase) so we can deliver and re-display them to you. A result appears in your Creations gallery only if you save it; deleting a saved creation also deletes the stored image file, and all generated images are removed when you delete your account. Results you download are saved to your device gallery.
- Processor-side handling. ModelsLab and Google may temporarily retain transmitted images to provide and secure their services; their handling is governed by their own privacy policies (linked in Section 8).
- No training without consent. We do not use your photos to train our own facial- recognition models.
Please upload only photos of yourself or images you have the right to use. Do not upload photos of other people without consent, or unlawful, infringing, or explicit content.
4 Face detection & biometrics
The App uses Google ML Kit to run on-device face/person detection solely to verify that an uploaded photo contains a human before it is used for a try-on. Importantly:
- Detection runs locally on your device and is not transmitted to us for that purpose.
- We do not create, store, or use a faceprint, face geometry, or any biometric identifier to identify you.
- We do not use face data for authentication, surveillance, or recognition, and never sell or share biometric information.
This section addresses biometric-privacy laws such as the Illinois Biometric Information Privacy Act (BIPA) and comparable statutes.
5 How we use your information
| Purpose | Examples |
|---|---|
| Provide the core service | Authenticate you, generate try-ons, change backgrounds, save/share results, manage credits. |
| Account & support | Maintain your account, respond to requests, prevent fraud/abuse. |
| Payments | Process purchases and manage subscriptions/entitlements. |
| Communications | Send push notifications you enabled and important service notices. |
| Analytics & improvement | Understand feature usage and improve reliability and UX. |
| Advertising | Show and measure ads, including rewarded ads where applicable. |
| Legal & safety | Comply with law, enforce terms, and protect users and our rights. |
Abuse prevention
To prevent abuse of one-time free credits (e.g., deleting and re-creating accounts), we store a one-way, irreversible cryptographic hash (SHA-256) derived from your email, sign-in provider identifier, or device identifier. It cannot be reversed to recover your email and is retained even after account deletion solely for fraud prevention.
6 Legal bases (EEA / UK)
If you are in the EEA or UK, we rely on these legal bases under the GDPR/UK GDPR:
| Basis | Applies to |
|---|---|
| Contract (Art. 6(1)(b)) | Providing the App, generating try-ons, processing purchases. |
| Consent (Art. 6(1)(a)) | Uploading your photo for AI processing, push notifications, personalized ads. Withdrawable anytime. |
| Legitimate interests (Art. 6(1)(f)) | Analytics, security, fraud prevention, and service improvement. |
| Legal obligation (Art. 6(1)(c)) | Complying with applicable laws and lawful requests. |
Where your photo is treated as a special category of data, we rely on your explicit consent (Art. 9(2)(a)).
8 Third-party services
The App integrates the following services, each processing data under its own privacy policy:
| Provider | Purpose | Policy |
|---|---|---|
| Google Firebase | Accounts, database, image storage, configuration | Link |
| Google (Gemini API) | AI try-on image generation | Link |
| ModelsLab | AI try-on image generation | Link |
| Google Sign-In | Authentication | Link |
| Apple (Sign in with Apple) | Authentication | Link |
| Mixpanel | Product analytics | Link |
| OneSignal | Push notifications | Link |
| Google AdMob | Advertising | Link |
| Meta Audience Network | Advertising (mediation) | Link |
| RevenueCat | In-app purchases / subscriptions | Link |
9 Advertising & analytics
The App may show ads served through Google AdMob with Meta Audience Network mediation, and uses Mixpanel for analytics. Depending on your consent and settings, ads may be personalized using your advertising identifier and related signals.
- iOS: Control tracking via Settings → Privacy & Security → Tracking (App Tracking Transparency).
- Android: Reset/delete your advertising ID and opt out of personalization in Settings → Google → Ads.
- Where required (for example in the EEA/UK), we display a consent form powered by Google’s User Messaging Platform when you first open the App; ads and analytics then run only according to your choices there.
- Withdraw consent in the App: where these consent rules apply, you can review or withdraw your consent for personalized ads at any time via Settings → Manage Ad Consent, which reopens the consent options form. Withdrawing consent also stops analytics tracking.
10 International data transfers
We and our providers may process your information in countries other than your own, including the United States, which may not offer the same level of protection as your jurisdiction. Where we transfer personal data out of the EEA, UK, or other restricted regions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. You may request a copy of the relevant safeguards using the contact details below.
11 Data retention
| Data | Retention |
|---|---|
| Account & profile data | Until you delete your account, plus any period required by law. |
| Raw uploaded source photos | Deleted automatically after the try-on is generated; any upload orphaned by an interruption is removed on account deletion. |
| Generated result images | Stored to deliver and re-display results; removed when you delete your account. |
| Saved result images (Creations) | Until you delete them in the App or delete your account. |
| Analytics & usage data | A limited period consistent with our provider’s settings. |
| Abuse-prevention hash (SHA-256) | Retained after deletion solely to prevent free-credit abuse. |
| Purchase records | As required for tax, accounting, and audit obligations. |
12 Your privacy rights
Depending on where you live, you may have some or all of these rights:
- Access — request a copy of the personal data we hold about you.
- Correction — correct inaccurate or incomplete data.
- Deletion — request deletion of your data.
- Portability — receive your data in a portable format.
- Objection / restriction — object to or restrict certain processing.
- Withdraw consent — where processing is based on consent.
- Opt out of “sale” or “sharing” and targeted advertising, and limit use of sensitive personal information (U.S. state laws).
- Non-discrimination — we won’t discriminate against you for exercising rights.
- Complaint — lodge a complaint with your local data-protection authority.
To exercise any right, contact support@nextwaveinfotech.com. We will verify your request and respond within the timeframe required by law. You may use an authorized agent where permitted.
13 Account & data deletion
You can delete your account and associated data directly in the App: Settings → Delete Account (guest accounts included). This permanently removes your account profile, your saved try-on results and uploaded images, your remaining credits, and your preferences, and signs you out. For full steps and a breakdown of what is deleted and retained, see our Account Deletion page. You may also email support@nextwaveinfotech.com to request deletion. Certain limited data may be retained where required by law or for fraud prevention (see Section 11).
14 U.S. state & California disclosures
This section supplements the Policy for residents of California (CCPA/CPRA) and similar U.S. state laws (Virginia, Colorado, Connecticut, Utah, Texas). We do not sell your personal information for money. In the preceding 12 months, we may have collected these categories:
| Category | Collected | “Shared” for ads |
|---|---|---|
| Identifiers (name, email, device/user ID, IP) | Yes | Yes |
| Commercial information (purchases, credits) | Yes | No |
| Internet/network activity (app usage, analytics) | Yes | Yes |
| Approximate geolocation (from IP) | Yes | Yes |
| Visual information (photos you upload) | Yes | No |
| Sensitive personal information (credentials; photos) | Yes | No |
California residents may exercise the rights in Section 12, including opting out of “sharing” for cross-context behavioral advertising. To opt out, email support@nextwaveinfotech.com, and use your device’s advertising controls described in Section 9. We use and disclose sensitive personal information (your photos and sign-in credentials) only to provide the service you request, not to infer characteristics about you. We do not knowingly sell or share the personal information of consumers under 16.
15 EEA / UK disclosures
If you are in the EEA or UK, our legal bases are in Section 6 and your rights in Section 12. You have the right to lodge a complaint with your supervisory authority. Where we require a photo for AI processing, we rely on your explicit consent, which you may withdraw at any time by ceasing to upload photos and/or deleting your account.
16 Children’s privacy
The App is not directed to children. You must be at least 13 years old (or the minimum age of digital consent in your country — e.g., 16 in some EEA states) to use the App. We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided us personal information, contact us and we will delete it.
17 Data security
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and reputable cloud infrastructure (Google Firebase). No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please keep your login credentials confidential.
18 Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date and may be highlighted within the App or by other reasonable means. Your continued use of the App after changes take effect constitutes acceptance of the revised Policy.
19 Contact us
For any privacy questions or to exercise your rights, contact us:
Get in touch
We have not appointed an EEA/UK representative under GDPR Art. 27; EEA/UK users can contact the controller directly at support@nextwaveinfotech.com with any privacy request.