Attira Privacy Policy
Last updated: September 6, 2026
Attira ("Attira", "we", "us") is an AI-powered wardrobe, styling-assistant and virtual try-on application operated by Abdul Afreen, a sole proprietor based in Eluru, Andhra Pradesh, India. Attira answers questions about the clothes you already own — styling an occasion, planning a week or a trip, judging a potential purchase, and generating try-on previews. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. It applies to the Attira web application at [https://tryattire.com] and the Attira mobile applications.
If you do not agree with this policy, please do not use Attira.
Contact: support@tryattira.com
1. Data we collect
1.1 Account information (you provide it)
| Data | Why we collect it |
|---|---|
| Name | To identify you in the app |
| Email address | Sign-in, email verification (one-time codes), password reset |
| Password | Sign-in (stored as a salted hash, never in plain text) |
| Gender | To filter the clothing catalog and select appropriate model avatars |
1.2 Photos and images (you provide them)
- Clothing photos. Photos you upload of garments. Our AI detects and extracts individual clothing items from them to build your digital wardrobe.
- Full-body ("persona") photos. An optional photo of yourself used to generate virtual try-on images. This photo shows your face and body. See Section 3 for how we handle it. You can instead choose a stock Attira model avatar, in which case no photo of you is used for try-on.
- Photos you attach to a conversation. You can send a photo to the styling assistant mid-conversation — a garment you are asking about, a shelf of your wardrobe, or what you currently have on so the assistant can review the outfit. A photo of what you are wearing may show your face and body, and when it does we treat it exactly as we treat a persona photo (see Section 3). Attachments are uploaded to our image storage and linked to the conversation you sent them in.
- Generated outfit images. AI-generated images of outfits, which may depict your likeness if you uploaded a persona photo.
1.3 Content you create in the app
- Chat messages you exchange with the styling assistant, and the conversation history needed to keep context.
- Calendar events you add (title, date/time, optional description) so we can suggest outfits for upcoming occasions.
- Trip plans. When you ask the assistant to plan a trip, the destination, travel dates and trip context you give it, plus the day-by-day packing plan it produces. A destination and a set of dates can reveal where you will be and when, so we keep them with your conversation and delete them with it.
- Shopping questions and buy lists. The garment you asked us to evaluate, the ranked buy list we produced, and which gaps in your wardrobe it was scored against. We do not sell clothing, take a commission, or pass these to any retailer or advertiser.
- Saved looks and wardrobe metadata (item categories, colors, descriptions, usage).
- App preferences (settings you choose, such as your default try-on model, and onboarding style preferences — style vibe, fit preference, and employment/lifestyle context — used to bias outfit suggestions when you haven't stated a preference in a given conversation).
- Wear history. When you tap "Wearing this" on a generated outfit, we log which wardrobe items you confirmed wearing and the date, so we can avoid suggesting the same pieces again too soon. This is only recorded when you explicitly confirm it — never just because a look was generated or previewed.
1.4 Collected automatically
-
Authentication tokens and session data, stored in your browser's local storage and cookies, used solely to keep you signed in.
-
Device location (optional). We use your device's coordinates for two things, and only ever at the moment you ask for something that needs them:
- Weather. To suggest weather-appropriate outfits. We ask for this permission once per device — if you deny it, we don't ask again. Your coordinates are cached on your own device (browser local storage, or the app's local storage) so we don't have to ask repeatedly; they are sent to our backend only at the moment you request an outfit, used to fetch current weather, and are not stored in our application database. If location permission is denied or unavailable, we approximate your location from your IP address instead (see Section 4) — again, only for that request, not stored.
- Finding stores near you. When you ask the assistant where to buy something, we ask your device for its position at that moment and send the coordinates to our backend, which looks up nearby clothing shops in OpenStreetMap (see Section 4). We do not ask you to type a city, and we do not store the coordinates or the list of shops we returned. If you refuse, the assistant asks you for an area instead, and the feature still works.
Location is never collected in the background, and never while the app is closed. Tapping a shop in the results opens your phone's or browser's maps application (Google Maps) with that shop's name or coordinates — at that point you have left Attira and Google's own privacy policy applies.
-
Push notification token (optional). If you allow notifications on the mobile app, your device generates a push token (issued through Expo, and ultimately Apple's or Google's push service). We store that token against your account so we can send you notifications — for example, that your look for tomorrow's event is ready. The token identifies a device, not you personally, and is not used for advertising or shared with anyone besides the push providers in Section 4. Turn notifications off in your device settings and we stop sending them.
-
Device context sent with a request. Each request to the styling assistant carries your device's time zone and locale, so "tomorrow morning" and date formats mean what you expect. These travel with the request and are not stored as a profile.
-
Standard server logs (IP address, timestamps, requested endpoints) for security and debugging. These are generated by our hosting provider's ingress and captured via Azure Monitor into a Log Analytics workspace, retained for 30 days and then deleted. We do not store IP addresses in our application database.
We do not use third-party analytics, advertising SDKs, or cross-site tracking. We do not sell your personal information, and we have not done so in the preceding 12 months.
2. How we use your data
- Provide the core service: detect clothing in your photos, build your wardrobe, generate outfit recommendations and try-on images.
- Answer your questions about your own wardrobe — style an occasion, plan a week or a trip, review an outfit you photographed, tell you what a potential purchase would actually unlock, and find shops nearby when something is worth buying.
- Send you the notifications you asked for, if you turned them on.
- Authenticate you and secure your account (email verification codes, password reset).
- Send transactional emails only (verification codes, password resets). We do not send marketing email unless you separately opt in.
- Maintain, debug, and secure the service.
We do not use your photos, likeness, or content to train AI models, and we do not permit our AI providers to do so (see Section 4). Our agreements with Azure OpenAI and Google confirm that customer data sent to their APIs is not used to train their AI models.
3. Face and body data (please read)
Two things you can send us may contain your face and body imagery: a persona photo, and a photo you attach to a conversation showing what you have on. Both are handled the same way, with extra care:
- What it's used for: exclusively to answer the request you made with it — to generate a virtual try-on image, or to let the assistant review the outfit you photographed. It is never used for face recognition, identification, profiling, or advertising.
- Consent: we ask for your explicit consent before your first persona photo upload, and you can use a stock model avatar instead at any time. A conversation attachment is only ever sent because you chose that photo and sent that message.
- Where it's stored: encrypted at rest in our cloud storage (Microsoft Azure Blob Storage). Images are served through short-lived, signed URLs.
- Who processes it: the AI providers listed in Section 4, only at the moment a try-on image is generated, under contracts that prohibit them from retaining or training on it.
- How long we keep it: until you replace it, delete it, or delete your account. When you delete your account, your persona photo and all other images are deleted immediately and permanently from our storage as part of the deletion request.
We do not extract or store biometric templates (e.g., faceprints or other biometric identifiers) from your photos.
4. Who we share data with (subprocessors)
We share data only with the service providers needed to run Attira:
| Provider | Purpose | Data shared |
|---|---|---|
| Microsoft Azure (Blob Storage) | Cloud storage of images | All uploaded and generated images |
| Microsoft Azure (Database) | Database hosting for application data | Account info, wardrobe metadata, calendar events, conversations, saved looks, settings |
| Microsoft Azure OpenAI Service | Clothing detection/description, styling assistant, image generation | Clothing photos, chat messages, persona photo (during generation) |
| Google (Gemini API) | Try-on image generation | Persona photo, garment images, outfit prompts (during generation) |
| Resend (Resend, Inc.) | Transactional email delivery (verification codes, password resets) | Your email address, verification/reset codes |
| Microsoft Azure (Container Apps + Azure Monitor / Log Analytics) | Hosting the backend application and storing server logs | Standard web request data (IP address, headers, requested endpoints) |
| Vercel (Vercel Inc.) | Hosting the web frontend | Standard web request data (IP address, headers) |
| Open-Meteo | Current weather lookup, to suggest weather-appropriate outfits | Approximate device coordinates (latitude/longitude), for that request only |
| ipapi.co | Approximate location by IP address, only when device location is denied or unavailable | Your IP address, for that request only |
| OpenStreetMap (Overpass API) | Finding clothing shops near you when you ask where to buy something | Approximate coordinates or the area you named, for that request only — never your account, identity, or wardrobe |
| Expo (650 Industries, Inc.) | Delivering push notifications to your device | Your device's push token and the notification's content |
| Apple (APNs) and Google (FCM) | The operating-system push services Expo delivers through | Your device's push token and the notification's content |
| Paddle.com Market Ltd | Merchant of record for paid plans — payment processing, invoicing, tax | Your name, email, billing/payment details, and subscription status. We never see or store your full card details |
These providers act as our processors and may not use your data for their own purposes — with the exception of Paddle, which acts as merchant of record and is an independent controller of the payment data it collects, under its own privacy policy. We do not share your data with advertisers, data brokers, or social networks.
Links out of Attira. When you tap a shop in the nearby-stores results, we open Google Maps with that shop's name or coordinates. That is a link, not a data transfer from us: we send Google no information about you, your account, or your wardrobe. Once the map opens you are on Google's service, under Google's privacy policy.
We may also disclose data if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to data collected under it).
5. Data retention
| Data | Retained until |
|---|---|
| Account information | Account deletion |
| Persona photos | You replace/delete them, or account deletion |
| Wardrobe photos and extracted items | You delete the item, or account deletion |
| Generated outfits and saved looks | You delete them, or account deletion |
| Chat history, conversation attachments, trip plans and buy lists | You delete the conversation, or account deletion |
| Calendar events | You delete them, or account deletion |
| Push notification token | You turn notifications off, or account deletion |
| Wear-history logs (worn outfits) | Account deletion (no per-entry deletion in the app yet) |
| Server logs (incl. IP address) | 30 days, then automatically deleted |
| Device location cached on your device | Until you clear your browser's or the app's local storage (does not leave your device) |
| Coordinates sent to find nearby shops | Not retained — used for that request and discarded |
When you delete your account, your account record and all associated data — wardrobe uploads, calendar events, settings, conversations, saved looks, and every image in storage — are deleted immediately and permanently from our production systems as part of the deletion request. Residual copies may persist only transiently in our cloud provider's automated infrastructure backups, which are overwritten on the provider's standard backup cycle.
6. Your rights and choices
You can, at any time:
- Access and export your data — contact us at support@tryattira.com.
- Correct your account details in Settings.
- Delete individual photos, wardrobe items, looks, events, and conversations in the app.
- Delete your account and all associated data — in Settings → Danger zone → Delete account, or by emailing support@tryattira.com from your registered email address. You can also request deletion without reinstalling the app at [https://tryattire.com/delete-account].
- Withdraw consent for persona-photo processing by deleting your persona photo and switching to a stock model avatar.
- Turn off notifications at any time in your device settings. You can also ask us to delete the stored push token at support@tryattira.com.
- Revoke location permission at any time in your browser or device settings. Clearing your browser's local storage also removes the cached location on that device; we'll simply ask again (or fall back to IP-based location) on your next visit.
Depending on where you live, you may have additional statutory rights:
- EEA/UK (GDPR/UK GDPR): rights of access, rectification, erasure, restriction, portability, and objection; the right to withdraw consent at any time; and the right to lodge a complaint with your supervisory authority. Our legal bases are: performance of contract (providing the service), consent (persona-photo/face-data processing — Article 9(2)(a)), and legitimate interests (security, debugging). [IF EEA/UK USERS IN SCOPE: name your EU/UK representative here if required.]
- California (CCPA/CPRA): rights to know, delete, correct, and to opt out of sale/sharing. We do not sell or share personal information as defined by the CPRA. Precise geolocation is Sensitive Personal Information under the CPRA; we collect it solely to determine local weather so we can suggest weather-appropriate clothing — a use reasonably necessary and proportionate to provide the feature you requested, not sold, shared, used for advertising, or repurposed for anything else.
- India (DPDP Act 2023): rights to access, correction, erasure, and grievance redressal. Contact us at support@tryattira.com.
- Illinois, Texas, Washington (biometric/health data laws): we do not create biometric identifiers from your photos. Where these laws apply to face imagery, our consent, retention, and deletion practices are described in Sections 3 and 5.
We respond to verified requests within the timeframe required by applicable law (generally 30–45 days).
7. International data transfers
Our infrastructure spans more than one region:
- Application database (Microsoft Azure) — hosted in West US (United States).
- Backend application and server logs (Azure Container Apps + Azure Monitor) — hosted in East US (United States).
- Image storage (Azure Blob Storage) — hosted in East US (United States).
If you use Attira from another region, your data is transferred to and processed in the regions above. For transfers out of the EEA/UK we rely on Standard Contractual Clauses and, for US providers, the EU-U.S. Data Privacy Framework where the provider is certified.
8. Security
- All traffic is encrypted in transit (TLS/HTTPS).
- Images and data are encrypted at rest by our cloud providers.
- Passwords are stored as salted hashes.
- Image URLs are short-lived signed links, not public URLs.
- Access to production data is restricted to personnel who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and regulators as required by law.
9. Children
Attira is not directed to children under 13 (or under 16 for users in the EEA), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact support@tryattira.com and we will delete it.
10. AI-generated content and recommendations
Try-on images are AI-generated previews. They are for personal styling use and may not accurately represent garment fit, color, or appearance.
The same applies to everything else the assistant produces — outfit suggestions, week and trip plans, wardrobe gap analysis, and buy-or-skip advice. These are suggestions generated from the wardrobe data we hold, not professional, financial, or purchasing advice, and they can be wrong. Nearby-shop results come from OpenStreetMap, a public database maintained by volunteers; opening hours, stock, and whether a shop still exists are outside our knowledge. Check before you travel.
You can report problematic generated content in the app or at support@tryattira.com.
11. Changes to this policy
What changed on September 6, 2026
This version covers the styling assistant released in this update. In summary: photos you attach to a conversation are described in Sections 1.2 and 3 and are treated as face/body data when they show you; device location now has a second, separately-asked purpose — finding shops near you (Section 1.4); push notification tokens are collected if you allow notifications (Section 1.4); trip plans and shopping buy lists are named as content we store (Section 1.3); and OpenStreetMap, Expo, Apple/Google push and Paddle are added to the subprocessor table (Section 4). The application database is hosted on Microsoft Azure in West US (replacing Supabase). Nothing about training, selling, or tracking has changed: we still do none of them.
We will post any changes here and update the "Last updated" date. For material changes (especially to how we handle photos or face data), we will notify you in the app or by email before the change takes effect.
12. Contact us
Abdul Afreen (sole proprietor) Eluru, Andhra Pradesh, India Email: support@tryattira.com
All privacy requests, questions, and grievances (including from EEA/UK and India users) go to support@tryattira.com.