Trust & Data

A shopper's photo is not a casual thing to ask for.

Every OmnyFit render starts with a real photo of a real person. This page exists because that deserves a plain-language answer, not a buried clause in a 40-page terms document. If anything here conflicts with the linked legal documents, the legal documents govern — this page is the plain-English summary, not a substitute.

What we store

The photo, the render, and nothing else by default

[Placeholder — confirm and publish the exact retention behavior: is the uploaded photo stored at all, or processed in-memory and discarded after the render completes? State it precisely here, since "we don't store your photo" and "we store it for 24 hours then delete it" are very different claims and the difference matters to shoppers and to regulators.]

How long

A defined retention window, not "indefinitely"

[Placeholder — state the actual retention period for session data, render outputs, and any analytics derived from them. If retention differs between the shopper-facing widget and merchant dashboard exports, say so explicitly.]

Model training

Whether shopper photos train our models

[Placeholder — this is the single most-asked question about any photo-upload AI tool. State plainly whether uploaded shopper photos are ever used to train or fine-tune models, and if opt-out or opt-in consent applies.]

Deletion

A real way to delete it

[Placeholder — the actual mechanism: does a shopper have a delete button in the widget, does the merchant control deletion, or is there a support email? Name it here.]

01 — Consent & compliance

Built with biometric-data rules in mind, not around them.

Photo-based fit rendering can touch biometric-data regulation depending on jurisdiction — Illinois' BIPA and the EU's GDPR treat certain photo-derived data as a special category. [Placeholder — have counsel confirm whether OmnyFit's specific processing (garment overlay vs. biometric identification) falls under these rules, and state the conclusion here rather than leaving it ambiguous.]

Explicit consent at upload

[Placeholder — describe the actual consent flow shown to a shopper before their photo is used.]

Merchant obligations

[Placeholder — what a merchant needs to disclose in their own privacy policy to use OmnyFit legally in their jurisdiction.]

Data Processing Addendum

For enterprise and white label partners, a signed DPA is available. See the Data Processing Addendum.

02 — Security

Encryption, access control, and status.

Encryption in transit and at rest

[Placeholder — confirm TLS version and at-rest encryption standard.]

Access control

[Placeholder — who inside OmnyFit can access raw shopper photos, and under what conditions.]

Compliance certifications

[Placeholder — SOC 2 or similar, once obtained. Don't claim a certification the company doesn't yet hold — state "in progress" if that's accurate.]

Questions about how we handle data?

Talk to us directly — this is one topic worth a real conversation, not just a policy page.