Privacy Policy — Virtual Try-On
Policy version v1 · Effective 18 July 2026
This policy explains what happens to your photo when you use the Fesch virtual try-on on a store. The short version: your photo is used only to render your try-on, it is processed and stored exclusively in the European Union, it is deleted automatically after 72 hours, and it is never used to train AI models.
Who is responsible
The try-on feature is provided by Fesch (the app operator) on behalf of the store you are shopping in. The store (merchant) is the data controller for your personal data; Fesch acts as its data processor under a Data Processing Agreement. You can contact the store directly, or reach Fesch at privacy@fesch.app.
What we process
- Your photo — the picture you upload or take to try a garment on.
- The product image — the garment picture from the store's product page.
- The generated try-on image ("render") — the preview of you wearing the garment.
- An anonymous shopper token — a random identifier created in your browser. It is not linked to your name, email, or any store account, and it does not follow you across other stores.
- A consent record — when you agree to this policy before uploading, we store the anonymous token, the store's domain, the policy version you agreed to, and a timestamp. A hashed (non-reversible) form of your IP address may be stored with this record as proof of consent.
We do not collect your name, email address, or account details, and we do not perform face recognition, biometric identification, or any matching of your photo against other people's photos.
Why we process it
Solely to render your virtual try-on preview. Before generation, an automated check verifies that the photo is usable for try-on (a single clothed adult, suitable framing); photos that fail this check are rejected and never sent to the image-generation provider. The legal basis is your consent, which you give in the widget before your photo leaves your browser.
Where it is processed
The entire photo path runs inside the European Union: storage and hosting on AWS in Frankfurt, Germany (eu-central-1), the automated photo check on Amazon Bedrock restricted to EU regions, database records on Supabase in Frankfurt, and image generation via Black Forest Labs' EU endpoint. The full list of subprocessors is on the DPA & subprocessors page.
How long we keep it
- Photos and renders: deleted automatically after 72 hours. Deletion is enforced by storage lifecycle rules, not a manual process. Photos are encrypted at rest.
- Consent records and pseudonymous try-on records (anonymous token, store domain, product reference, job status) are kept while the store uses the app, as proof of consent and to operate the service. They contain no images. They are deleted when the store uninstalls the app.
Never used to train AI
Your photos and renders are never used to train AI models, not by Fesch and not by our providers on our behalf.
Your choices and rights
- Remove your photo at any time: tap "Remove my photo" in the try-on widget. This immediately deletes your stored photos for that store; any remaining renders expire within the 72-hour window.
- You can withdraw consent at any time the same way; without a stored photo, nothing further is processed.
- Under the GDPR you also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Because we hold no name or contact details about you, exercise these rights via the store you shopped in or via privacy@fesch.app.
Changes to this policy
This policy is versioned (currently v1). If we change it in a way that matters, the version is bumped and you will be asked to consent again before your next try-on.