Privacy Policy
Last updated · June 2026
This policy describes what Attyr collects, why, and what you can do about it. In short: we collect what we need to style you well, we don't sell your data, and you can export or delete everything at any time.
What we collect
- Account: email + password hash (bcrypt; we never see the raw password).
- Style profile: your onboarding answers, aesthetic, colour preferences, sizing references.
- Photos: images you upload for try-on, and images of garments you add to your closet.
- Wardrobe: items, wear logs, prices, brands, cost-per-wear, perceptual hashes of photos for duplicate detection.
- Collections: wishlist items, moodboards and pins, outfit plans, packing lists, shared-look tokens, feed posts you publish.
- Activity: saves, favourites, shopping intents, affiliate clicks, credit ledger entries, analytics events.
- Derived signals: taste-vector embeddings of your saved items so recommendations stay relevant.
- Device basics: request timestamps, rough region for currency formatting, browser local storage for your session token.
How we use it
- Generate try-on images and stylist commentary.
- Personalise recommendations via a derived taste signal.
- Operate the credit system and affiliate commerce.
- Improve the service — aggregated, non-identifying usage patterns only.
Who we share with
We use third-party providers for specific capabilities: FASHN (virtual try-on), Kling (motion generation), Cartesia (voice), OpenAI / DeepSeek / Anthropic (language models), Cohere / Voyage (embeddings, when configured), remove.bg / rembg (image cleanup, when configured), Cuelinks (affiliate links in India), Stripe / Razorpay (payments), Sentry (error monitoring with personal identifiers scrubbed). Your photos are sent to the relevant provider only when you trigger an action that needs them. Providers apply their own retention policies; Attyr does not sell your data to anyone.
When content is public
Most of Attyr is private to you. Two surfaces are not:
- Share links: when you generate a share link for a saved look, anyone with the token can view a stripped- down version (image + commentary only; no owner identity). You can revoke the link at any time.
- Community feed: if you publish a look to the feed, the image and caption appear to every signed-in member. We remove owner identity from public feed responses. You can delete or un-publish your post at any time from the Mine tab.
Biometric data (try-on & avatar)
Attyr's try-on and avatar features create images of you from a photo. To place clothing realistically, the photo is analyzed to map your facial and body geometry — a “biometric identifier” under Illinois' Biometric Information Privacy Act (BIPA), Texas' CUBI, and similar laws. We handle it with these commitments:
- What we collect: the photo you provide for try-on or avatar, and the facial and body geometry derived from it to render your result.
- Why: only to generate the try-on and avatar images you request. We never use it to identify you, for advertising, or to train AI models, and we never sell, lease, or trade it.
- Who processes it: Attyr and our AI image provider, OpenAI, which receives the photo solely to generate your image and does not retain it to train its models. Motion clips additionally use Kling.
- How it's stored: your try-on portrait stays on your device and is transmitted to the AI provider only for each render. If you set up an avatar, the selfie, full-body, and sizing photos you provide are stored on our servers so your avatar persists across devices — secured in transit and at rest.
- Consent: we obtain your explicit written consent before the first time we process your biometric data.
- Age: the face features are limited to users 18 and older; we confirm your date of birth first and do not knowingly collect biometric data from anyone under 18.
- Your control: you can withdraw consent and delete your biometric data anytime in Settings → Account, and deleting your account erases it immediately.
Retention & destruction. We permanently destroy your biometric identifiers and information when the purpose for collecting them has been satisfied, when you delete them or your account, or within 3 years of your last interaction with Attyr — whichever occurs first. For Texas users, within one year of the purpose expiring. We store and transmit this data using reasonable security measures at least as protective as those we use for other confidential information.
How long we keep it
We keep account data while your account is active. When you delete your account, we remove your profile, wardrobe items, wear logs, feedback events, credit ledger, shopping intents, wishlist, moodboards and pins, outfit plans, packing lists, share tokens, feed posts, and photo references. Aggregated non-identifying metrics (e.g. weekly trend snapshots) and provider-held copies of images are retained per their policies.
Cookies and local storage
Attyr uses browser local storage to keep your session token and a small amount of cached profile data so the app opens quickly. We don't set advertising cookies and we don't track you across the web.
Your rights
You can delete your account and every related row directly in the app from Settings → Account → Delete account, which removes your data immediately. You can also email privacy@attyr.app to request deletion or a JSON export of everything we store. For jurisdiction-specific rights (GDPR, CCPA, India DPDP), email privacy@attyr.app and we'll handle it within the required timeline.
Children
Security
Changes
Contact
This is a plain-English summary for a consumer fashion app. It doesn't replace jurisdiction-specific disclosures that Attyr's operating entity may publish separately.