fitcheck.
Legal

Privacy Policy

Effective date: 7 May 2026

Last updated: 7 May 2026

Publisher: FitCheck — operated by Anth Casauria

Contact: support@myfitcheck.app

This Privacy Policy describes how FitCheck (the "app") collects, uses, and shares your personal information. By creating an account or using the app you agree to this policy.

1. Quick summary

2. Data we collect

CategoryDataPurposeRetention
AccountEmail; salted/hashed password held by Supabase AuthSign-in and account recoveryUntil account deletion
ProfileDisplay name, optional handle/bio, credit balanceCore app functionalityUntil account deletion
PhotosBase photos of yourself; outfit photos you capture or pick; receipt images forwarded to email importInputs to the AI try-on pipeline. Stored privately in your per-user folder.Until you delete them, or up to 30 days after account deletion
Generated imagesAI-generated try-on resultsDisplay and personal use; optionally posted to community feed at your choiceUntil you delete the look or post; up to 30 days after account deletion
Outfit linksURLs you paste and retailer metadata extracted (title, price, image, materials)"Shop the Look" recommendations and price alertsUntil you delete the saved item
Community contentPosts, comments, likes, reports you fileRun the community feed; honour App Store / Play UGC moderation requirementsUntil you delete the content or your account
Usage eventsIn-app events (screens viewed, try-on started/completed, feature taps)Product analytics, debugging24 months; aggregated after 90 days
Crash dataStack traces, device model, OS version. Image data, JWTs, and emails are scrubbed before send.Diagnose crashes via Sentry90 days
Device identifier (push token)Expo push token, only if you opt into notificationsDeliver in-app notificationsUntil token rotation, opt-out, or account deletion
PurchasesRevenueCat customer record + receipt metadataVerify token-pack purchasesUntil account deletion (we then call the RevenueCat delete-customer API)

We do not collect: precise location, contacts, microphone audio, health data, government identifiers, full payment card numbers, or other sensitive financial data. We do not sell personal information.

3. Third-party processors and AI providers

Photos and certain text are processed by the following third parties strictly to deliver the features you request:

ProviderPurposeData sentProvider policy
SupabaseHosting (database, auth, storage, edge functions)Account, photos, all app datasupabase.com/privacy
Anthropic (Claude)Garment analysis + safety verificationThe clothing image you uploaded; pose-analysis text derived from your base photoanthropic.com/legal/privacy
Google (Gemini image generation)Generates the final try-on imageYour base photo + the structured garment specpolicies.google.com/privacy
OpenAI (GPT-4o)Moderation of base photos and posts; AI outfit suggestions; product classificationThe image being moderated, or the wardrobe summary used for daily suggestionsopenai.com/privacy
Brave Search"Shop the look" product discoveryText queries derived from analysis (not your photos)brave.com/help/privacy
RevenueCatPurchase state of recordApp user id, purchase receiptsrevenuecat.com/privacy
SentryCrash reportingScrubbed stack traces (no images, JWTs, or emails)sentry.io/privacy

Photos sent to AI providers are processed under those providers' commercial API terms in effect at the time we send them. As of the effective date of this policy, Anthropic, Google, and OpenAI commit not to use API content to train their public models.

4. How try-on photos are processed

  1. Your base photo and outfit image are uploaded to your private Supabase Storage folder. Storage is gated by row-level security so only you can read those bytes.
  2. Our edge functions send the images to Anthropic (analysis + safety) and Google (image generation). Each call uses TLS.
  3. The generated image is uploaded back to your private folder. The app reads it via short-lived (24-hour) signed URLs.
  4. You can delete any photo, generated result, or your entire account at any time from Settings → Privacy & Data.

5. Sharing & disclosure

We share personal data only as follows:

We do not sell personal information and we do not share it with advertisers.

6. Legal bases (GDPR / UK GDPR)

You can withdraw consent at any time without affecting prior processing.

7. Your rights

You have the right to access, correct, export, restrict, or delete your personal data, and to lodge a complaint with a supervisory authority.

In the app:

For any other request, email support@myfitcheck.app. We aim to respond within 30 days.

8. Data transfers

Our database and storage are hosted in Supabase (Northeast Asia / Tokyo region). AI providers may process your images in their own regions (primarily the United States). Cross-border transfers rely on the standard contractual clauses or the providers' equivalent transfer mechanisms.

9. Security

10. Children

FitCheck is not directed to children under 13 (or the local digital-consent age, whichever is higher). We do not knowingly collect personal data from children. The base photo moderation pipeline rejects images that appear to depict minors. If you believe a child has submitted personal data, contact support@myfitcheck.app and we will delete it promptly.

11. Cookies and tracking

The mobile app does not use web cookies. We do not use App Tracking Transparency permission and do not perform cross-app tracking. Sentry sets a session identifier within the app only for grouping crash reports; it expires when you close the app.

12. Changes to this policy

We will post any changes here, update the "Last updated" date, and for material changes we will surface an in-app notice. Your continued use of the app after a change indicates acceptance of the updated policy.

13. Contact

support@myfitcheck.app — for any privacy questions, deletion requests, or to report a violation.