kasually
Sign in

Privacy Policy

Your photos are processed to make the try-on you asked for, kept in the EU, deleted on a schedule you control, and never used to train AI models.

Version privacy-2026-09-12·Effective 12 September 2026

This document is an engineering draft pending review by counsel. It describes what the service actually does today and is written to be accurate, but it is not yet legal advice or a final agreement.

Contents

  1. 01Who we are
  2. 02What we collect and why
  3. 03What happens to your photos
  4. 04How long we keep things, and how deletion works
  5. 05Who else processes your data
  6. 06Where your data lives
  7. 07Your rights
  8. 08If you appear in someone else’s photo
  9. 09Cookies and analytics
  10. 10Age
  11. 11How we protect it
  12. 12Changes to this policy

01Who we are

kasually is a virtual try-on service: you upload a photo of yourself and a garment, and we generate an image of you wearing it. We are the data controller for the personal data described here — we decide why and how it is processed.

For anything in this document, including data-rights requests, write to privacy@kasually.me. A named privacy owner monitors that address.

02What we collect and why

We collect only what the service needs. There are no free-text profile fields that invite information about other people, and we ask for no data we do not use.

DataWhyLegal basisKept for
Email, display name, sign-in identifierRun your accountContractLife of account, then purged within 30 days
Photos you upload and results we generateProduce the try-on you asked forContractYour setting — 90 days by default
Job records (status, tier, timings, errors)Deliver results, support, reliabilityContract and legitimate interest24 months, then stripped of identifiers
Credit ledger and payment recordsBilling and taxContract and legal obligation10 years, pseudonymised after account deletion
Consent recordsProve what you agreed to and whenLegal obligationLife of account plus 5 years
Safety screening outcomeKeep minors and explicit content off the platformLegitimate interestWith the image
Browser notification registrationTell you a try-on finishedConsentUntil you turn notifications off, sign out, or after 90 days without activity
Notification delivery recordsAvoid duplicate alerts and retry deliveryConsentUp to 7 days after a try-on finishes
Operational logsSecurity and debuggingLegitimate interest30 days

Logs never contain photos, emails or tokens — only pseudonymous identifiers (a user ID, a job ID, a trace ID). Location metadata is removed from every photo the moment it arrives: uploads are decoded and re-encoded on our servers, which strips EXIF, including GPS coordinates, before anything is stored.

03What happens to your photos

This is the part that matters most, so it is spelled out in full.

  • They are screened before anything else. Every upload passes automated safety screening that rejects explicit imagery and photos that appear to show a minor. Our screening runs first; the AI provider’s own filters are a second layer, not the first.
  • They are sent to an AI provider to generate the result. That is the service. The providers we use are listed in section 5.
  • They are never used to train AI models. We contract for no-training and zero-retention terms with every generation provider, so the provider keeps nothing after returning your image.
  • They are never sold, rented or shared for advertising.
  • They are deleted on a clock you control. See section 4.
  • They are only reachable through expiring signed links. No image in our storage is publicly addressable. A result becomes visible to anyone else only if you deliberately create a share link, which expires after 7 days.

Generated images carry a provenance marker identifying them as AI-generated. Delivered, downloaded, and shared results carry a visible kasually.me watermark.

04How long we keep things, and how deletion works

Photos and results are deleted automatically 90 days after upload by default. You can set that anywhere from 1 to 365 days in privacy settings. Expiry is enforced by a scheduled job that hard-deletes the stored file, with a storage lifecycle rule behind it as a backstop.

Deleting your account starts a 7-day grace period during which you can cancel. After it elapses, we erase your photos, results, job history, notification tokens and profile, and ask our identity and payment providers to delete or redact their copies.

Two things deliberately survive that erasure, because the law requires us to keep them: the credit ledger and payment records are retained for tax purposes for 10 years. They are pseudonymised — your identifier is replaced with a meaningless token, and your email and name are erased — so what remains cannot be traced back to you by us or anyone else.

Database backups are kept for at most 35 days, and erased data ages out of them naturally. We record every erasure in an internal journal and re-apply it after any backup restore, so restoring a backup can never bring an erased account back.

05Who else processes your data

We use a small number of vendors, each under a data-processing agreement. They act on our instructions and may not use your data for their own purposes.

VendorWhat they doWhat they see
Google CloudHosting, database, storage, queuesEverything, at rest in EU regions
Google Vertex AI (Gemini)Image generation — the default routeThe two photos for that job, EU endpoints
OpenAIImage generation, higher quality tierThe two photos for that job
FASHNImage generation, dedicated try-on modelThe two photos for that job
StripePaymentsYour email and payment details — we never see card numbers
Firebase (Google)Sign-in and push notificationsEmail, sign-in identifier, device token
Email delivery providerTransactional emailYour email address

We may also disclose data where we are legally compelled to, or to establish or defend legal claims. If our business is ever transferred, this policy travels with the data and you will be told before anything changes.

06Where your data lives

Storage and the default generation route are in the European Union. This is enforced in code, not just in policy: each AI provider carries a residency attribute, and a job from an EU user is only allowed to reach a provider marked as EU-resident unless that provider has been individually approved after a documented transfer assessment.

Some processing does happen outside the EU — sign-in and push notifications, some email delivery, and the higher quality tier where an EU-resident option is not contracted. Those transfers rely on the European Commission’s Standard Contractual Clauses together with a transfer impact assessment and technical safeguards.

07Your rights

Under the GDPR you can exercise all of the following free of charge. Most of them are self-serve in privacy settings and take effect immediately rather than in 30 days.

  • Access and portability. Export everything we hold — profile, jobs, ledger, consents and every image — as a zip file, delivered by an expiring link.
  • Erasure. Delete your account, with the 7-day cancellation window described above.
  • Rectification. Correct your profile details.
  • Restriction. Ask us to pause processing while a dispute is open. This suspends new generations and all marketing.
  • Objection. Object to processing based on legitimate interest, and withdraw any consent at any time — withdrawing is exactly as easy as granting, in the same place.

We answer requests within 30 days and normally far sooner. If you are unhappy with how we handle one, you can complain to your local data protection supervisory authority.

Automated safety screening can reject an upload, which is not a decision with legal or similarly significant effect. Any permanent account suspension is reviewed by a person before it takes effect, and you can appeal it.

08If you appear in someone else’s photo

Our Terms require uploaders to be the person pictured or to have that person’s permission. Uploaders accept this obligation when agreeing to the Terms, then confirm it applies when they choose to use each photo. We record that action against the image, alongside the applicable policy version; we do not ask for a separate checkbox for each upload.

If you appear in a photo someone uploaded and you want it erased, you do not need an account and you do not need to explain yourself. Use the subject request form or write to privacy@kasually.me. You can also report a shared result from the page it is shared on.

09Cookies and analytics

We set no advertising cookies and run no cross-site trackers. Storage in your browser is limited to what signing in requires.

Product analytics are privacy-preserving and load only after you consent to them; if you do not, they never run. Declining costs you nothing.

10Age

kasually is for adults aged 18 and over, which is stricter than the law requires — we chose it because the service is built around photographs of people. We ask for your year of birth at signup, and our safety screening independently rejects photos that appear to show a minor regardless of who uploaded them.

11How we protect it

Data is encrypted in transit and at rest. Media is reachable only through short-lived signed links. Access to production data is least-privilege, with no standing human access and audited break-glass procedures. Uploads are re-validated server-side before being stored. We keep a rehearsed breach runbook: if a breach ever puts your rights at risk we notify the supervisory authority within 72 hours of becoming aware, and you directly where the risk to you is high.

12Changes to this policy

Each revision of this document has a version string, shown at the top of this page and recorded against your acceptance. If we make a material change we will ask you to review and accept the new version before you continue using the service, rather than quietly swapping the text.

Questions about this document, or want to exercise a data right? Privacy settings handles export, deletion and consent yourself. If you are not a kasually user but appear in someone’s photo, use the subject request form.

kasuallyFor brandsTermsPrivacy