Privacy Policy
Last Updated: 2025-04-02
Welcome to digiMirror ("digiMirror," "We," "Us," "Our"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, website, and related services (collectively, the "Service").
Please read this Privacy Policy carefully. By accessing or using the Service, you agree to the terms of this Privacy Policy and our Terms of Service. If you do not agree with the terms of this Privacy Policy, please do not access or use the "Service".
1. Information We Collect
We collect information about you in various ways when you use our Service:
(a) Information You Provide Directly:
- Account Information: When you register for an account, we collect your email address (which requires verification), chosen username, and password (stored in a hashed format).
- Uploaded Images (User Content): When you use the core image generation feature, you upload images (e.g., of a person and clothing). These images are processed by the Service but, as detailed below, are generally not stored permanently on Our servers.
(b) Information Collected Automatically:
- Technical Data for Free Trial Abuse Prevention (Fingerprinting - With Consent): For users accessing the Free Trial feature without being logged in, and only after you provide explicit consent (e.g., via a checkbox presented before starting the trial), we collect certain technical information from your browser and device to create a unique identifier ("fingerprint"). This may include data points such as your IP address, browser user-agent string, timezone, data derived from techniques like canvas fingerprinting, etc. This data is collected SOLELY for the purpose of preventing abuse of the Free Trial offer (e.g., limiting users to the intended number of free uses) and is retained only for 24 hours.
- Usage Data & Server Logs (via Cloudflare): Like most websites, our hosting provider (Cloudflare) automatically collects standard log information when you access the Service. This may include your IP address, browser type, operating system, access times, pages viewed, and referring website addresses. Cloudflare provides us with aggregated analytics based on this data. We may also track your session information when you are logged in.
- Cookies and Similar Technologies: We and our third-party partners (like Cloudflare) use cookies and similar tracking technologies (like web beacons or local storage) to operate and improve the Service, understand usage, manage sessions, and potentially serve advertisements. See Section 6 for more details.
- Information collected by Advertising Partners (Google AdSense): When you use our Service, our advertising partner, Google, may use cookies and similar technologies (like web beacons) to collect information about your device, browsing activity, and interactions with ads displayed on our Service. This may include IP addresses, cookie identifiers, device identifiers, geographic location (at the city level), and website usage data.
(c) Analized fashion data:
When you use our virtual try-on service, our primary goal is to provide you with the best experience. To do this, and to understand broader fashion trends, we collect certain anonymous information related solely to the clothing items analyzed and general interaction patterns. We are committed to protecting your privacy and do not collect or store personally identifiable information (PII) such as your name, email address, precise location, or unique device identifiers through this specific process. Our focus is strictly on the clothing, not the individual user. When you provide a clothing image for virtual try-on, our AI system analyzes the image of the clothing item itself to understand its characteristics. The types of anonymous information we collect include:
- AI-Detected Clothing Attributes: Such as the item's general category, dominant color(s), patterns, etc.
- Temporary Session Information: To understand which items are tried on together within a single, active usage session, we use a temporary, random session identifier. This identifier is generated by your browser or app instance, exists only for the duration of your active session, and is not linked to any personal account or persistent identifier. It is automatically discarded when your session ends.
- General Location: We collect the country associated with the request (e.g., 'USA', 'Germany') to understand regional trends. This is derived from the incoming request data provided by network infrastructure and is not precise location information.
- Timestamps: We record the time of interactions to analyze trends over time.
(d) Information from Third Parties:
- Payment Information (via PayPal): When you purchase Credits, the transaction is processed by PayPal. We receive confirmation data from PayPal, such as the transaction or Order ID and the amount paid, to update your Credit balance. We do not collect or store your full financial information like credit card numbers or PayPal account details directly.
(e) Generated Images (Output):
The images generated by the Service based on your User Content are returned to you. As detailed below, these are generally not stored permanently on Our servers.
2. How We Use Your Information
We use the information we collect for various purposes, including:
- To provide, operate, maintain, and improve the Service.
- To process your User Content (images) through the third-party AI Provider to generate the requested output images.
- To create and manage your account and authenticate users.
- To process payments for Credits via PayPal and manage your Credit balance.
- To prevent abuse of the Free Trial offer (using consented fingerprinting data).
- To understand which types of clothing, styles, colors, and features are popular helping us improve the virtual try-on experience, potentially refine our AI models, and understand how users interact with different types of garments.
- To identify broader fashion trends by aggregating data from many anonymous interactions.
- To help broader our fashion ecosystem and understand consumer interests based on anonymized, collective behavior within our app.
- To monitor and analyze usage and trends to improve user experience (using aggregated data from Cloudflare).
- To maintain the security and integrity of the Service (using server logs and technical data).
- To communicate with you, including sending transactional emails (e.g., email verification, purchase confirmations, password resets).
- To comply with legal obligations.
- To display advertisements through third-party partners like Google AdSense, which may include personalized advertising based on your activity (unless you opt-out).
3. Legal Basis for Processing (for GDPR and similar regimes)
We process your personal data based on the following legal grounds:
- Performance of a Contract: Processing your account information, User Content (images), payment information (via PayPal), and delivering Generated Content is necessary to provide the Service you requested under our Terms of Service.
- Consent: We rely on your explicit consent to collect and process technical data (fingerprinting) for Free Trial abuse prevention. We also rely on your consent (implied by your action of uploading and confirmed by agreeing to our Terms) to process your uploaded images for generation. Where required by law (e.g., for certain cookies), we will obtain your consent.
- Legitimate Interests: We process server log data and usage analytics (via Cloudflare) for our legitimate interests in maintaining security, preventing fraud, analyzing usage, and improving the Service, provided these interests are not overridden by your data protection rights.
- Legal Obligation: We may process certain data (like transaction records) to comply with applicable laws and regulations.
4. How We Share Your Information
We do not sell your personal information. We may share information we collect in the following circumstances:
- With the Third-Party AI Provider: We transmit your uploaded User Content (images) to our third-party AI provider solely for the purpose of generating the output image you requested. Their processing is subject to their own terms and privacy policies. This provider is a globally recognized company, but we are not responsible for their data handling practices.
- With Payment Processors (PayPal): We share transaction information with PayPal as necessary to process your Credit purchases.
- With Service Providers (Cloudflare): We use Cloudflare for hosting, security, content delivery, and basic analytics. Cloudflare processes data (like IP addresses, usage logs) on our behalf according to their terms and privacy policy.
- With Advertising Partners (Google): We use Google AdSense to display ads on our Service. Google uses cookies (including the DoubleClick cookie) to collect data and serve ads based on your prior visits to our Service and other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our sites and/or other sites on the Internet. The information collected may be shared with Google as described in their privacy policy.
- With third parties fashion businesses:We may generate reports or provide insights based only on anonymized, aggregated trend data to third parties, such as clothing platforms or advertisers. This information is always aggregated and cannot be used to identify any individual user.
- For Legal Reasons: We may disclose your information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.
5. Data Retention
We retain your information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Account Information: Retained while your account is active. You can delete your account via settings. Some data may be retained after deletion for a limited period as required for legal, tax, or accounting purposes.
- Uploaded & Generated Images: We do not permanently store your uploaded User Content or the Generated Content on our servers. Processing is transient. Images may be temporarily stored in your browser's local storage (
IndexedDB
) during your active session, which you control. - Fingerprinting Data: Retained only for 24 hours from collection, solely for Free Trial abuse prevention.
- Transaction Data (Order IDs, Amounts): Retained as necessary for accounting, support, and legal compliance (potentially for several years).
- Server Logs (Cloudflare): Retained according to Cloudflare's standard practices or for a limited period necessary for security and analysis.
6. Cookies, Analytics, and Tracking Technologies
We use cookies (small text files stored on your device) and similar technologies (like IndexedDB
for local image storage, potentially web beacons):
- Necessary Cookies: Essential for the Service to function (e.g., session management, login authentication, Cloudflare security cookies).
- Analytics Cookies (Cloudflare): To understand how users interact with the Service on an aggregated basis.
- AdSense: We partner with Google AdSense to display advertisements on our Service. Google, as a third-party vendor, uses cookies to serve ads on our Service. This includes the use of the DoubleClick cookie, which enables Google and its partners to serve ads based on your visits to this site and/or other sites on the Internet.
- Opt-Out Information (Required by Google): You may opt out of personalized advertising by visiting Google's Ads Settings. Alternatively, you can opt out of a third-party vendor's use of cookies for personalized advertising by visiting www.aboutads.info/choices/.
- Google's Policies: For more information on how Google collects and uses data when you use our Service, please review Google's Privacy & Terms page.
- Address Consent: In jurisdictions where consent is required for the use of cookies (like the European Economic Area and the UK), we will obtain your consent before non-essential cookies, including those used for personalized advertising by Google AdSense, are placed on your device. You can manage your cookie preferences through [Your Cookie Consent Tool Mechanism - e.g., "the cookie banner presented upon your first visit" or "the 'Cookie Settings' link in the footer"].
- Fingerprinting (Consent-Based): As described in Section 1(b), we use technical data collection requiring your consent for Free Trial abuse prevention. This is separate from standard cookies but is a form of device identification.
7. Data Security
We implement reasonable administrative, technical, and physical security measures designed to protect your information from unauthorized access, use, alteration, or disclosure. We use HTTPS for secure communication. However, please be aware that no security measures are perfect or impenetrable, and we cannot guarantee the absolute security of your data.
8. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your own, including the United States and other locations where our servers (via Cloudflare), the third-party AI provider's servers, or PayPal's servers are located. These countries may have data protection laws that are different from the laws of your country. We rely on appropriate safeguards (such as Standard Contractual Clauses where applicable under GDPR) for such transfers where required by law. By using the Service, you consent to the transfer of your information to these countries.
9. Your Privacy Rights
Depending on your location (e.g., if you are in the EEA/UK or California), you may have certain rights regarding your personal data:
- Right to Access: You may request access to the personal information we hold about you.
- Right to Rectification: You may request correction of inaccurate personal information.
- Right to Erasure (Deletion): You may request deletion of your personal information, subject to certain exceptions. You can delete your account and associated data directly via your account settings.
- Right to Restrict Processing: You may request that we restrict the processing of your personal information under certain conditions.
- Right to Data Portability: You may request a copy of your data in a machine-readable format under certain conditions.
- Right to Object: You may object to processing based on legitimate interests under certain conditions.
- Right to Withdraw Consent: Where processing is based on consent (like fingerprinting), you can withdraw your consent at any time (though this won't affect past processing).
To exercise these rights (other than account deletion via settings), please contact us at [email protected]. We will respond to your request in accordance with applicable laws. You may also have the right to lodge a complaint with your local data protection supervisory authority.
Remember, you can opt-out of personalized advertising via the Google Ads Settings link provided in the Cookies section.
10. Children's Privacy
The Service is not intended for or directed at children under the age of 13 (or a higher age threshold if required by applicable law, such as 16 in the EEA or 18 for certain features/purchases as per our Terms of Service). We do not knowingly collect personal information from children under this age limit. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information.
11. Third-Party Links and Services
The Service may contain links to third-party websites or services (like PayPal or Google) that are not operated by us. This Privacy Policy does not apply to third-party practices, and we are not responsible for their content or privacy policies. We encourage you to review the privacy policies of any third-party service you interact with.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We may also provide notice through the Service or via email for significant changes. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
[email protected]
Make sure to also review our Terms of Service.