Privacy Policy
Last updated · 29 August 2026
This policy describes what Attyr collects, why, and what you can do about it. In short: we collect what we need to style you well, we don't sell your data, we don't run advertising trackers, and you can delete everything at any time.
What we collect
- Account: email + password hash (bcrypt; we never see the raw password). If you sign in with Apple or Google, the identity token they issue us.
- Style profile: your onboarding answers, aesthetic, colour preferences, sizing references, date of birth, and optional details you choose to give us such as pronouns, height, occupation, budget, and any style or modesty preferences you set.
- Photos: images you upload for try-on, avatar setup, sizing, hair design, in-store checks, your community profile photo, and images of garments you add to your closet.
- Body measurements: measurements and body-shape values we calculate from your sizing photos or that you enter yourself, and — if you generate one — a 3D body model built from your full-body photo.
- Wardrobe: items, wear logs, prices, brands, cost-per-wear, perceptual hashes of photos for duplicate detection.
- Collections: wishlist items, moodboards and pins, outfit plans, packing lists, trips (destination, dates and any notes you add), shared-look tokens, feed posts you publish.
- Messages: direct messages, crew messages and pro briefs you send inside Attyr, including their text and anything you attach. Message content is stored on our servers in readable form so it can be delivered — it is not end-to-end encrypted. We don't read your messages except when one is reported to us.
- Forwarded email. When you sign up we create a personal forwarding address for you (yourname-xxxx@in.attyr.app) and send it to you in your verification email. If you forward an order confirmation to that address, we receive the whole email — sender, subject and body — and use an AI model to pull out what you bought. We store the extracted items, the retailer and the order date. We never read a mailbox: we hold no access to your email account, and nothing reaches us unless you forward it. Extracted item detail is deleted after 30 days.
- Location. If you allow it, we use your device's location for the weather in your daily edit, for showing shops and services near you, and for answering “near me” questions. We store a deliberately coarse version of the fix — rounded to roughly 11 km, enough to know your city, not your street. You can revoke access in your device settings at any time.
- Voice. If you talk to Atti instead of typing and your device can't transcribe on-device, the audio is uploaded and transcribed. We keep the transcript, not the recording. Atti's spoken replies are generated and cached on our servers.
- Activity: saves, favourites, shopping intents, affiliate clicks, credit ledger entries, and product-usage events recorded against your account. We keep these in our own database and don't send them to any analytics vendor.
- Fitness, if you use gym outfits: the workout types you do and the days you do them.
- Derived signals: taste-vector embeddings of your saved items and looks so recommendations stay relevant.
- Connected accounts: if you connect Pinterest, we store the tokens Pinterest issues us and the aesthetic signals we derive from your boards. Disconnecting deletes the tokens.
- Device basics: request timestamps; your device's locale and region for currency formatting; your IP address, which our servers use to estimate your city when you haven't granted location; a push token issued by Expo, stored with your platform and time zone so we can send you notifications; and a truncated, one-way hash of your IP address recorded alongside any consent you give, as proof of when and where it was given.
How we use it
- Generate try-on images, avatars, hair designs and stylist commentary.
- Personalise recommendations via a derived taste signal.
- Operate the credit system and affiliate commerce.
- Improve the service. A small random sample — about 1 in 100 — of AI requests is kept along with the text sent to the model and the result it returned, including, for image features, the generated image. These samples can be traced back to the account that produced them and may be reviewed by Attyr staff to check quality and catch regressions. We don't use them to train AI models. Email privacy@attyr.app to have your account excluded from sampling.
Who we share with
We use third-party providers for specific capabilities. Your photos and messages are sent to a provider only when you trigger an action that needs them.
- Image generation and analysis: OpenAI (try-on, full-look and avatar rendering, hair renders, image moderation); fal.ai (motion clips via Kling, 3D body-mesh reconstruction, background removal); Replicate (segmenting garments out of your photos, and as a fallback image engine); Google (Gemini); Hugging Face (on-body garment parsing); Modal (matching looks you publish to the community feed); FASHN (retained as a fallback try-on engine).
- Language and vision models: OpenRouter, which brokers our requests to Google (Gemini) and Alibaba (Qwen) models; OpenAI; Anthropic; DeepSeek, whose service is operated from China.
- Voice: OpenAI (transcription), Cartesia (speech).
- Embeddings: OpenAI, and Cohere or Voyage when configured.
- Storage and hosting: Cloudflare (R2, where all your photos and generated images are stored), Render (our backend), Vercel (this website and the partner portal).
- Email: Postmark, which delivers our emails to you and receives the order confirmations you forward.
- Notifications: Expo, which issues your push token and delivers notifications through Apple (APNs) and Google (FCM), and which receives your device's IP address each time the app launches to check for updates.
- Location and weather: Open-Meteo, WeatherAPI.com and ipapi.co, which receive your coordinates or your IP address to return local weather; OpenFreeMap, which serves map tiles and so receives your IP address and the area of the map you're viewing.
- Commerce: SerpAPI and Admitad (product search and catalogue), Cuelinks (affiliate links), Stripe and Razorpay (payments).
- Messaging: Meta, if you contact us through Instagram; Pinterest, if you connect it.
- Diagnostics: Sentry, which receives crash reports, error messages, device model and OS, and a per-install identifier. We don't attach your name or email to a report, and we suppress request bodies, cookies and headers — but we don't currently run a filter over every diagnostic detail attached to one.
Providers apply their own retention policies. Attyr does not sell your data to anyone, and we don't share it with data brokers or advertisers.
When content is public
Most of Attyr is private to you. These surfaces are not:
- Share links: when you generate a share link for a saved look, anyone with the token can view a stripped-down version — image and commentary only, with no name or account attached. You can revoke the link at any time.
- The community feed, profiles, circles and crews: when you publish a look, it appears to every signed-in member with your display name and profile photo attached — this is a social feed, not an anonymous one. Your profile shows your name, photo, published looks, follower counts and the palette and aesthetic tags Atti has derived for you, and anyone signed in can find you by name. In a crew, every other member sees your name and photo. You can delete or un-publish any post at any time.
- Similar-taste suggestions: we may show you members whose wardrobes are stylistically close to yours, and show you to them the same way. They never see your closet or your items — only the name and photo already on your public profile.
- Pro briefs and barber cards: when you send a brief or a hair card to a professional, the images and notes you attach — which may include your original photo as well as the generated result — are viewable by anyone holding that link until you revoke it.
- Image links: your photos and generated images are stored at long, unguessable web addresses. Anyone you give such a link to can open it without signing in, so treat a shared image link as public.
Businesses and Instagram
Attyr onboards boutiques and independent sellers, and Atti can hold that conversation over Instagram. If you message Attyr's Instagram account, we store your Instagram user ID, the text of your messages and any images you send, and we pass that text to our AI language providers so Atti can reply. We keep the conversation so we can pick it up later; email privacy@attyr.app to have it deleted. When a business onboards, we store the contact address they arrived on, the name and email of each team member they invite, the products and photos they submit, and their public storefront details including their Instagram handle, which we show to Attyr shoppers. Businesses see aggregate counts of how their products perform — never the identity of any shopper.
The Attyr browser extension
The extension installs with permission to run on all websites, because we can't know in advance where you shop. On every page you open it reads that page locally, in your browser, to work out whether it's a product or a shopping results page. That local check never leaves your device.
Information reaches our servers in two situations. When you click the Atti button on a product page, we send that page's product details — title, brand, price, category, colours, image and page address — plus any size chart the extension could read, so we can produce a verdict and a size recommendation. Size-chart images are sent to Google (Gemini) to be read into text; the product details go to Google or OpenRouter to write the verdict, and the title and brand go to SerpAPI to look up cheaper listings. When you switch on Atti's Picks for a shopping site, it stays on for that site until you turn it off, and while it's on it runs automatically: as pages load and as you scroll, it sends the product cards it can see to be scored, and records which items it showed you and which you clicked.
We keep, linked to your account, the retailer domains where you used the extension, the products you asked about, and your outbound shopping clicks. On a small number of retailers the extension also requests that retailer's own size-guide page from your browser — that request goes to the retailer, not to us, and carries whatever cookies your browser would normally send them. We don't record your browsing on non-shopping sites, we don't build an advertising profile, and we don't sell or share any of it with advertisers or with the retailers themselves.
Biometric data (try-on, avatar & hair)
Attyr's try-on, avatar and hair features create images of you from a photo. To place clothing or hair realistically, the photo is analyzed to map your facial and body geometry — a “biometric identifier” under Illinois' Biometric Information Privacy Act (BIPA), Texas' CUBI, Colorado's Privacy Act, Washington's My Health My Data Act and similar laws. We handle it with these commitments:
- What we collect: the photos you provide for try-on, avatar, sizing, hair or an in-store check; the facial and body geometry derived from them; the body measurements and 3D body model we calculate from them; and the images we generate of you.
- Why: to generate the images you request, to size you, and to check content safety before rendering. We never use it to identify you, for advertising, or to train AI models, and we never sell, lease or trade it.
- Who processes it: Attyr and the providers below, each of which receives your photo to perform a specific task and none of which is permitted to use it to train their models — OpenAI (try-on, full-look, avatar and hair rendering; safety moderation); fal.ai (motion clips via Kling, 3D body-mesh reconstruction, background removal); Replicate (segmenting garments out of on-body photos); OpenRouter, which brokers requests to Google (Gemini) and Alibaba (Qwen) models for moderation and style analysis; Anthropic (moderation fallback); Hugging Face (on-body garment parsing); Modal (image matching); FASHN when the fallback try-on engine is active; and Cloudflare, which stores the images.
- How it's stored: the portrait you pick for try-on is saved in your device's app storage and uploaded to our servers each time you request a render. The photos you provide for your avatar, sizing, hair design, community profile or an in-store check are stored on our servers, as are the images we generate of you, so they persist across devices — encrypted in transit and at rest. Stored images are reachable through long, unguessable links; anyone holding such a link can view the image until it is deleted.
- Consent: we obtain your explicit written consent before we generate a try-on, avatar or hairstyle image of you.
- Age: these features are limited to users 18 and older; we ask for your date of birth during setup, before any photo feature is available, and we don't knowingly collect biometric data from anyone under 18.
- Your control: you can withdraw consent and delete your biometric data at any time in Settings → Account. Withdrawing permanently removes the generated images from your saved looks, your avatar and hair renders, and your portrait on that device — these cannot be restored. Deleting your account erases it.
Retention & destruction. We permanently destroy your biometric identifiers and information when the purpose for collecting them has been satisfied, when you delete them or your account, or within 3 years of your last interaction with Attyr — whichever occurs first. Where your state sets a shorter period, we apply that period instead; for Texas users that is within one year of the purpose expiring. We store and transmit this data using reasonable security measures at least as protective as those we use for other confidential information.
How long we keep it
We keep account data while your account is active. When you delete your account, we remove your profile, wardrobe items, wear logs, measurements, biometric data and photos, feedback events, credit ledger, shopping intents, wishlist, moodboards and pins, outfit plans, packing lists, trips, share tokens, feed posts, push tokens and connected-account tokens. Messages you sent in direct or crew conversations remain visible to the people you sent them to; email privacy@attyr.app to have those removed as well. Aggregated non-identifying metrics and provider-held copies of images are retained per those providers' policies.
What we store on your device
On the web, we use browser local storage for your session token. In the mobile app, your session token and account email are held in the operating system's secure keystore (iOS Keychain / Android Keystore). Other data is cached in ordinary app storage, which relies on your device's own disk encryption and app sandbox rather than encryption by us: your try-on and hair portraits, your avatar image links and measurements, your chat history with Atti, your last known coordinates, your onboarding answers, and cached wardrobe and outfit content. On iOS we also write your daily outfit's caption and images into a shared container so the home-screen widget can display them. The browser extension stores your session token, email and user ID, and the list of shopping domains where you've switched Atti's Picks on or off. All of it is cleared when you sign out or delete the app.
We set no advertising cookies and use no advertising, attribution or third-party analytics SDKs. We don't track you across apps or across the general web; where the extension does collect information from shopping pages, it is described in “The Attyr browser extension” above.
How to delete your data
In the app: Settings → Account → Delete account. This removes your profile, wardrobe items, wear logs, measurements, biometric data and photos, feedback events, credit ledger, shopping intents, wishlist, moodboards and pins, outfit plans, packing lists, trips, share tokens, feed posts, push tokens and connected-account tokens.
By email: write to privacy@attyr.app from the address on your account and ask us to delete it. We will confirm and complete the deletion within 30 days.
Connected Instagram accounts: if your shop connected an Instagram professional account, disconnecting it in the Attyr Partner Portal (Import → Instagram) deletes the access token and the copy we kept of your profile picture. You can also revoke Attyr from Instagram directly, under Settings → Website permissions → Apps and websites. Deleting your Attyr shop removes the imported products and the stored Instagram handle as well.
Messages you sent in direct or crew conversations stay visible to the people you sent them to; email privacy@attyr.app to have those removed too.
Your rights
You can delete your account and its data directly in the app from Settings → Account → Delete account. You can also email privacy@attyr.app to request deletion or a JSON export of what we store. For jurisdiction-specific rights (GDPR, UK GDPR, CCPA/CPRA, Illinois BIPA, Texas CUBI, Colorado, Washington MHMDA, India DPDP), email privacy@attyr.app and we'll handle it within the required timeline.
Children
Attyr isn't designed for users under 13 and we don't knowingly collect their data. We ask for your date of birth during setup; if you tell us you're under 13 we stop setup, and if we learn we hold a child's data we delete the account and everything in it. The try-on, avatar and hair features are limited to users 18 and older.
Security
Passwords are hashed with bcrypt. Sessions use signed JWTs that expire after 30 days and renew while you stay active; signing out clears the token on your device. Backend data is stored in an access-controlled database, and media in access-controlled object storage. No system is perfect — please report suspected issues to security@attyr.app.
Changes
We'll announce material changes in-app and update the date at the top of this page. Continued use after an update means you accept the revised policy.
Contact
privacy@attyr.app for anything related to this policy.
This is a plain-English summary for a consumer fashion app. It doesn't replace jurisdiction-specific disclosures that Attyr's operating entity may publish separately.