EFFECTIVE SEPTEMBER 30, 2026

Privacy policy

VirtualTryOn processes the images you submit to create the result you request. For signed-in users, the input images and selected settings are saved privately with the generated result so we can show task history and help with support requests. Site administrators can review those task inputs and outputs. Generated results stay in your private account library until you delete them. If you choose to share a result, its image and share page become accessible to anyone with the link. Deleting the result disables that public link.

What we process

When you sign in, we store your provider's stable account identifier, verified email address, display name, avatar URL, linked sign-in methods, and a hashed session token. We also process uploaded images, selected tool options, generation status, request identifier, latency, Stripe customer and subscription identifiers, plan status, and credit usage. We do not place image bytes, cookies, payment-card details, or provider credentials in ordinary application logs.

Sign-in and essential cookie

You can sign in with a verified email code, Google, Facebook, or Discord. We request only basic profile and email information and do not retain OAuth access tokens. The public studio sets a secure, HttpOnly, same-site cookie for up to 30 days; the database stores only its cryptographic hash. This keeps generated results private to your account. Signing out invalidates that session.

Why we process it

We use this information only to provide the requested image workflow, administer subscriptions and monthly credits, enforce safety, troubleshoot failures, and protect the service from abuse.

Website analytics

We use Google Analytics 4 to understand visits and how people use our website. It uses analytics cookies and similar technologies to measure page views, traffic sources, device and browser information, and interactions such as scrolling and link clicks. Google processes this usage data to provide analytics reports. We do not send uploaded images, generated images, email addresses, or payment details to Google Analytics. You can block analytics cookies in your browser or use Google's Analytics opt-out browser add-on. Learn more about how Google uses data from sites that use its services.

Retention and deletion

Generated images and signed-in task inputs are retained in private storage until you delete the generated image or request account deletion. Deleting a generated image also removes its saved input files and settings; task status and billing records may remain. Inputs from failed signed-in tasks remain available to administrators for troubleshooting until you request account deletion. Guest uploads are not saved after the request finishes. Results created under our previous 24-hour retention policy may already have expired and cannot be restored. Account, linked-provider, billing, and credit records remain as needed to operate the account and meet legal or accounting obligations.

Account data deletion

To request deletion of your account and linked Google, Facebook, or Discord data, follow our data deletion instructions. We verify account ownership before processing requests.

Your responsibility

Do not upload an image unless you have the right to use it and permission from each identifiable person. Avoid sensitive documents, minors, or intimate imagery.

Service providers

Our configured AI provider processes image inputs and outputs to provide the model response under its applicable data terms. Stripe processes checkout, payment methods, invoices, and subscription management; VirtualTryOn does not store full payment-card details. Contact us if you need help with deletion or privacy questions.