Privacy Policy
Your photos are processed to make the try-on you asked for, kept in the EU, deleted on a schedule you control, and never used to train AI models.
Version privacy-2026-09-12Effective 12 September 2026
This document is an engineering draft pending review by counsel. It describes what the service actually does today and is written to be accurate, but it is not yet legal advice or a final agreement.
Who we are
kasually is a virtual try-on service: you upload a photo of yourself and a garment, and we generate an image of you wearing it. We are the data controller for the personal data described here — we decide why and how it is processed.
For anything in this document, including data-rights requests, write to privacy@kasually.me. A named privacy owner monitors that address.
What we collect and why
We collect only what the service needs. There are no free-text profile fields that invite information about other people, and we ask for no data we do not use.
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Email, display name, sign-in identifier | Run your account | Contract | Life of account, then purged within 30 days |
| Photos you upload and results we generate | Produce the try-on you asked for | Contract | Your setting — 90 days by default |
| Job records (status, tier, timings, errors) | Deliver results, support, reliability | Contract and legitimate interest | 24 months, then stripped of identifiers |
| Credit ledger and payment records | Billing and tax | Contract and legal obligation | 10 years, pseudonymised after account deletion |
| Consent records | Prove what you agreed to and when | Legal obligation | Life of account plus 5 years |
| Safety screening outcome | Keep minors and explicit content off the platform | Legitimate interest | With the image |
| Browser notification registration | Tell you a try-on finished | Consent | Until you turn notifications off, sign out, or after 90 days without activity |
| Notification delivery records | Avoid duplicate alerts and retry delivery | Consent | Up to 7 days after a try-on finishes |
| Operational logs | Security and debugging | Legitimate interest | 30 days |
Logs never contain photos, emails or tokens — only pseudonymous identifiers (a user ID, a job ID, a trace ID). Location metadata is removed from every photo the moment it arrives: uploads are decoded and re-encoded on our servers, which strips EXIF, including GPS coordinates, before anything is stored.
What happens to your photos
This is the part that matters most, so it is spelled out in full.
- They are screened before anything else. Every upload passes automated safety screening that rejects explicit imagery and photos that appear to show a minor. Our screening runs first; the AI provider’s own filters are a second layer, not the first.
- They are sent to an AI provider to generate the result. That is the service. The providers we use are listed in section 5.
- They are never used to train AI models. We contract for no-training and zero-retention terms with every generation provider, so the provider keeps nothing after returning your image.
- They are never sold, rented or shared for advertising.
- They are deleted on a clock you control. See section 4.
- They are only reachable through expiring signed links. No image in our storage is publicly addressable. A result becomes visible to anyone else only if you deliberately create a share link, which expires after 7 days.
Generated images carry a provenance marker identifying them as AI-generated. Delivered, downloaded, and shared results carry a visible kasually.me watermark.
How long we keep things, and how deletion works
Photos and results are deleted automatically 90 days after upload by default. You can set that anywhere from 1 to 365 days in privacy settings. Expiry is enforced by a scheduled job that hard-deletes the stored file, with a storage lifecycle rule behind it as a backstop.
Deleting your account starts a 7-day grace period during which you can cancel. After it elapses, we erase your photos, results, job history, notification tokens and profile, and ask our identity and payment providers to delete or redact their copies.
Two things deliberately survive that erasure, because the law requires us to keep them: the credit ledger and payment records are retained for tax purposes for 10 years. They are pseudonymised — your identifier is replaced with a meaningless token, and your email and name are erased — so what remains cannot be traced back to you by us or anyone else.
Database backups are kept for at most 35 days, and erased data ages out of them naturally. We record every erasure in an internal journal and re-apply it after any backup restore, so restoring a backup can never bring an erased account back.
Who else processes your data
We use a small number of vendors, each under a data-processing agreement. They act on our instructions and may not use your data for their own purposes.
| Vendor | What they do | What they see |
|---|---|---|
| Google Cloud | Hosting, database, storage, queues | Everything, at rest in EU regions |
| Google Vertex AI (Gemini) | Image generation — the default route | The two photos for that job, EU endpoints |
| OpenAI | Image generation, higher quality tier | The two photos for that job |
| FASHN | Image generation, dedicated try-on model | The two photos for that job |
| Stripe | Payments | Your email and payment details — we never see card numbers |
| Firebase (Google) | Sign-in and push notifications | Email, sign-in identifier, device token |
| Email delivery provider | Transactional email | Your email address |
We may also disclose data where we are legally compelled to, or to establish or defend legal claims. If our business is ever transferred, this policy travels with the data and you will be told before anything changes.
Where your data lives
Storage and the default generation route are in the European Union. This is enforced in code, not just in policy: each AI provider carries a residency attribute, and a job from an EU user is only allowed to reach a provider marked as EU-resident unless that provider has been individually approved after a documented transfer assessment.
Some processing does happen outside the EU — sign-in and push notifications, some email delivery, and the higher quality tier where an EU-resident option is not contracted. Those transfers rely on the European Commission’s Standard Contractual Clauses together with a transfer impact assessment and technical safeguards.
Your rights
Under the GDPR you can exercise all of the following free of charge. Most of them are self-serve in privacy settings and take effect immediately rather than in 30 days.
- Access and portability. Export everything we hold — profile, jobs, ledger, consents and every image — as a zip file, delivered by an expiring link.
- Erasure. Delete your account, with the 7-day cancellation window described above.
- Rectification. Correct your profile details.
- Restriction. Ask us to pause processing while a dispute is open. This suspends new generations and all marketing.
- Objection. Object to processing based on legitimate interest, and withdraw any consent at any time — withdrawing is exactly as easy as granting, in the same place.
We answer requests within 30 days and normally far sooner. If you are unhappy with how we handle one, you can complain to your local data protection supervisory authority.
Automated safety screening can reject an upload, which is not a decision with legal or similarly significant effect. Any permanent account suspension is reviewed by a person before it takes effect, and you can appeal it.
If you appear in someone else’s photo
Our Terms require uploaders to be the person pictured or to have that person’s permission. Uploaders accept this obligation when agreeing to the Terms, then confirm it applies when they choose to use each photo. We record that action against the image, alongside the applicable policy version; we do not ask for a separate checkbox for each upload.
If you appear in a photo someone uploaded and you want it erased, you do not need an account and you do not need to explain yourself. Use the subject request form or write to privacy@kasually.me. You can also report a shared result from the page it is shared on.
Age
kasually is for adults aged 18 and over, which is stricter than the law requires — we chose it because the service is built around photographs of people. We ask for your year of birth at signup, and our safety screening independently rejects photos that appear to show a minor regardless of who uploaded them.
How we protect it
Data is encrypted in transit and at rest. Media is reachable only through short-lived signed links. Access to production data is least-privilege, with no standing human access and audited break-glass procedures. Uploads are re-validated server-side before being stored. We keep a rehearsed breach runbook: if a breach ever puts your rights at risk we notify the supervisory authority within 72 hours of becoming aware, and you directly where the risk to you is high.
Changes to this policy
Each revision of this document has a version string, shown at the top of this page and recorded against your acceptance. If we make a material change we will ask you to review and accept the new version before you continue using the service, rather than quietly swapping the text.