Contents
On this page

Privacy Policy

How TryOn AI collects, uses, and protects your information.

Effective July 17, 2026 Last updated July 17, 2026 Controller Dhruvisha Jagani

This Privacy Policy explains how Dhruvisha Jagani (“we,” “us,” or “our”), the operator of the TryOn AI mobile application (the “App”), collects, uses, discloses, transfers, and protects your information. It applies to users worldwide, including the EEA, UK, California and other U.S. states, India, Brazil, and Canada. By using the App you acknowledge you have read and understood this Policy.

Your photos

Source photos are uploaded only temporarily for the try-on and deleted right after generation.

AI processing

Try-ons are generated by third-party AI (Google Gemini, ModelsLab) acting as our processors.

No biometrics

Face detection runs on your device only. We never store a faceprint or identify you by face.

Your control

Access, correct, or delete your data anytime — including in-app account deletion.

1 Who we are

The data controller responsible for your personal information is:

Dhruvisha Jagani
Surat, Gujarat, India
Email: support@nextwaveinfotech.com

We have not appointed a separate EEA/UK representative or Data Protection Officer; for all privacy matters, contact us using the details in the Contact section.

2 Information we collect

2.1 Information you provide

  • Account information. Email, display name, and (for email sign-up) a password managed by our authentication provider. If you sign in with Google or Apple, we receive your name and email from that provider. With Apple’s “Hide My Email,” we receive a private relay email.
  • Guest use. You may also use the App as a guest without registering. We then create an anonymous account identifier for you and collect the device and usage data described in this Policy, without an email address. Guest accounts and their data can be deleted in the App just like registered accounts (see Section 13).
  • Profile information. Optional name, phone number, and profile photo.
  • Photos & images. The full-body photo of yourself and the outfit images you upload or select to generate a try-on. See Section 3.
  • Purchases. Processed by the Apple App Store or Google Play and our purchase provider (RevenueCat). We receive purchase and entitlement records, but not your full card number.
  • Communications. Information you provide when contacting support or exercising a right.

2.2 Information collected automatically

  • Device & identifiers. A device/OS identifier (a system build identifier on Android / iOS identifierForVendor), device model, OS version, app version, language, and a user ID.
  • Usage & analytics. Events such as screens viewed, taps, and try-ons, via Mixpanel. We also associate your user ID, name, and email address with your analytics profile and record purchase amounts in Mixpanel to understand feature usage and revenue. Analytics only runs according to your consent choices (see Section 9).
  • Advertising identifiers. Where ads appear, Google AdMob and Meta Audience Network may access your advertising ID to serve and measure ads.
  • Approximate location. No precise GPS. Partners may infer city/region-level location from your IP address.
  • Local storage. Some data is stored on your device (e.g., saved-photo path, a local cache of results, preference flags).

2.3 Information from third parties

  • Sign-in providers (Google, Apple) — identity details as above.
  • App stores & purchase provider (Apple, Google, RevenueCat) — purchase validation and subscription status.

3 Your photos & AI processing

Generating a try-on requires processing the images you provide — the most sensitive processing we perform:

  • What we process. The photo of you and the outfit image you upload or select.
  • On-device validation. Your photo is first checked on your device to confirm it contains a person (see Section 4).
  • Transfer to AI processors. To create the try-on, your photo and the outfit image are transmitted to third-party AI services — ModelsLab and/or Google (Gemini API) — which process them to produce the result, acting as our processors/sub-processors.
  • Temporary storage. Your source images are uploaded to our cloud storage (Google Firebase) only temporarily and are deleted automatically once the try-on is generated. If an interruption (for example, a lost connection) prevents immediate deletion, any remaining source uploads are removed when you delete your account. We do not use your raw source photos for any other purpose.
  • Generated results. Generated try-on images are stored in our cloud storage (Google Firebase) so we can deliver and re-display them to you. A result appears in your Creations gallery only if you save it; deleting a saved creation also deletes the stored image file, and all generated images are removed when you delete your account. Results you download are saved to your device gallery.
  • Processor-side handling. ModelsLab and Google may temporarily retain transmitted images to provide and secure their services; their handling is governed by their own privacy policies (linked in Section 8).
  • No training without consent. We do not use your photos to train our own facial- recognition models.

Please upload only photos of yourself or images you have the right to use. Do not upload photos of other people without consent, or unlawful, infringing, or explicit content.

4 Face detection & biometrics

The App uses Google ML Kit to run on-device face/person detection solely to verify that an uploaded photo contains a human before it is used for a try-on. Importantly:

  • Detection runs locally on your device and is not transmitted to us for that purpose.
  • We do not create, store, or use a faceprint, face geometry, or any biometric identifier to identify you.
  • We do not use face data for authentication, surveillance, or recognition, and never sell or share biometric information.

This section addresses biometric-privacy laws such as the Illinois Biometric Information Privacy Act (BIPA) and comparable statutes.

5 How we use your information

PurposeExamples
Provide the core serviceAuthenticate you, generate try-ons, change backgrounds, save/share results, manage credits.
Account & supportMaintain your account, respond to requests, prevent fraud/abuse.
PaymentsProcess purchases and manage subscriptions/entitlements.
CommunicationsSend push notifications you enabled and important service notices.
Analytics & improvementUnderstand feature usage and improve reliability and UX.
AdvertisingShow and measure ads, including rewarded ads where applicable.
Legal & safetyComply with law, enforce terms, and protect users and our rights.

Abuse prevention

To prevent abuse of one-time free credits (e.g., deleting and re-creating accounts), we store a one-way, irreversible cryptographic hash (SHA-256) derived from your email, sign-in provider identifier, or device identifier. It cannot be reversed to recover your email and is retained even after account deletion solely for fraud prevention.

7 How we share information

We do not sell your personal information for money. We share information only as follows:

  • Service providers / sub-processors processing data on our behalf under contract (see Section 8).
  • AI processors that generate your try-on results (ModelsLab, Google Gemini).
  • Advertising partners for showing and measuring ads. Under some laws (e.g., California CPRA) this may be “sharing” for cross-context behavioral advertising; you can opt out (see Section 12).
  • Legal, safety & corporate transactions — to comply with law, protect rights and safety, or in a merger, acquisition, or asset sale.

8 Third-party services

The App integrates the following services, each processing data under its own privacy policy:

ProviderPurposePolicy
Google FirebaseAccounts, database, image storage, configurationLink
Google (Gemini API)AI try-on image generationLink
ModelsLabAI try-on image generationLink
Google Sign-InAuthenticationLink
Apple (Sign in with Apple)AuthenticationLink
MixpanelProduct analyticsLink
OneSignalPush notificationsLink
Google AdMobAdvertisingLink
Meta Audience NetworkAdvertising (mediation)Link
RevenueCatIn-app purchases / subscriptionsLink

9 Advertising & analytics

The App may show ads served through Google AdMob with Meta Audience Network mediation, and uses Mixpanel for analytics. Depending on your consent and settings, ads may be personalized using your advertising identifier and related signals.

  • iOS: Control tracking via Settings → Privacy & Security → Tracking (App Tracking Transparency).
  • Android: Reset/delete your advertising ID and opt out of personalization in Settings → Google → Ads.
  • Where required (for example in the EEA/UK), we display a consent form powered by Google’s User Messaging Platform when you first open the App; ads and analytics then run only according to your choices there.
  • Withdraw consent in the App: where these consent rules apply, you can review or withdraw your consent for personalized ads at any time via Settings → Manage Ad Consent, which reopens the consent options form. Withdrawing consent also stops analytics tracking.

10 International data transfers

We and our providers may process your information in countries other than your own, including the United States, which may not offer the same level of protection as your jurisdiction. Where we transfer personal data out of the EEA, UK, or other restricted regions, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision. You may request a copy of the relevant safeguards using the contact details below.

11 Data retention

DataRetention
Account & profile dataUntil you delete your account, plus any period required by law.
Raw uploaded source photosDeleted automatically after the try-on is generated; any upload orphaned by an interruption is removed on account deletion.
Generated result imagesStored to deliver and re-display results; removed when you delete your account.
Saved result images (Creations)Until you delete them in the App or delete your account.
Analytics & usage dataA limited period consistent with our provider’s settings.
Abuse-prevention hash (SHA-256)Retained after deletion solely to prevent free-credit abuse.
Purchase recordsAs required for tax, accounting, and audit obligations.

12 Your privacy rights

Depending on where you live, you may have some or all of these rights:

  • Access — request a copy of the personal data we hold about you.
  • Correction — correct inaccurate or incomplete data.
  • Deletion — request deletion of your data.
  • Portability — receive your data in a portable format.
  • Objection / restriction — object to or restrict certain processing.
  • Withdraw consent — where processing is based on consent.
  • Opt out of “sale” or “sharing” and targeted advertising, and limit use of sensitive personal information (U.S. state laws).
  • Non-discrimination — we won’t discriminate against you for exercising rights.
  • Complaint — lodge a complaint with your local data-protection authority.

To exercise any right, contact support@nextwaveinfotech.com. We will verify your request and respond within the timeframe required by law. You may use an authorized agent where permitted.

13 Account & data deletion

You can delete your account and associated data directly in the App: Settings → Delete Account (guest accounts included). This permanently removes your account profile, your saved try-on results and uploaded images, your remaining credits, and your preferences, and signs you out. For full steps and a breakdown of what is deleted and retained, see our Account Deletion page. You may also email support@nextwaveinfotech.com to request deletion. Certain limited data may be retained where required by law or for fraud prevention (see Section 11).

14 U.S. state & California disclosures

This section supplements the Policy for residents of California (CCPA/CPRA) and similar U.S. state laws (Virginia, Colorado, Connecticut, Utah, Texas). We do not sell your personal information for money. In the preceding 12 months, we may have collected these categories:

CategoryCollected“Shared” for ads
Identifiers (name, email, device/user ID, IP)YesYes
Commercial information (purchases, credits)YesNo
Internet/network activity (app usage, analytics)YesYes
Approximate geolocation (from IP)YesYes
Visual information (photos you upload)YesNo
Sensitive personal information (credentials; photos)YesNo

California residents may exercise the rights in Section 12, including opting out of “sharing” for cross-context behavioral advertising. To opt out, email support@nextwaveinfotech.com, and use your device’s advertising controls described in Section 9. We use and disclose sensitive personal information (your photos and sign-in credentials) only to provide the service you request, not to infer characteristics about you. We do not knowingly sell or share the personal information of consumers under 16.

15 EEA / UK disclosures

If you are in the EEA or UK, our legal bases are in Section 6 and your rights in Section 12. You have the right to lodge a complaint with your supervisory authority. Where we require a photo for AI processing, we rely on your explicit consent, which you may withdraw at any time by ceasing to upload photos and/or deleting your account.

16 Children’s privacy

The App is not directed to children. You must be at least 13 years old (or the minimum age of digital consent in your country — e.g., 16 in some EEA states) to use the App. We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided us personal information, contact us and we will delete it.

17 Data security

We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and reputable cloud infrastructure (Google Firebase). No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please keep your login credentials confidential.

18 Changes to this Policy

We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date and may be highlighted within the App or by other reasonable means. Your continued use of the App after changes take effect constitutes acceptance of the revised Policy.

19 Contact us

For any privacy questions or to exercise your rights, contact us:

Get in touch

Controller
Dhruvisha Jagani
Address
Surat, Gujarat, India
Grievance Officer (India DPDP Act, 2023)
Dhruvisha Jagani

We have not appointed an EEA/UK representative under GDPR Art. 27; EEA/UK users can contact the controller directly at support@nextwaveinfotech.com with any privacy request.