Attira Privacy Policy

    Last updated: June 12, 2026

    Attira ("Attira", "we", "us") is an AI-powered wardrobe and virtual try-on application operated by Abdul Afreen, a sole proprietor based in Eluru, Andhra Pradesh, India. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. It applies to the Attira web application at [https://tryattire.com] and the Attira mobile applications.

    If you do not agree with this policy, please do not use Attira.

    Contact: support@tryattire.com


    1. Data we collect

    1.1 Account information (you provide it)

    DataWhy we collect it
    NameTo identify you in the app
    Email addressSign-in, email verification (one-time codes), password reset
    PasswordSign-in (stored as a salted hash, never in plain text)
    GenderTo filter the clothing catalog and select appropriate model avatars

    1.2 Photos and images (you provide them)

    • Clothing photos. Photos you upload of garments. Our AI detects and extracts individual clothing items from them to build your digital wardrobe.
    • Full-body ("persona") photos. An optional photo of yourself used to generate virtual try-on images. This photo shows your face and body. See Section 3 for how we handle it. You can instead choose a stock Attira model avatar, in which case no photo of you is used for try-on.
    • Generated outfit images. AI-generated images of outfits, which may depict your likeness if you uploaded a persona photo.

    1.3 Content you create in the app

    • Chat messages you exchange with the styling assistant, and the conversation history needed to keep context.
    • Calendar events you add (title, date/time, optional description) so we can suggest outfits for upcoming occasions.
    • Saved looks and wardrobe metadata (item categories, colors, descriptions, usage).
    • App preferences (settings you choose, such as your default try-on model).

    1.4 Collected automatically

    • Authentication tokens and session data, stored in your browser's local storage and cookies, used solely to keep you signed in.
    • Standard server logs (IP address, timestamps, requested endpoints) for security and debugging. These are generated by our hosting provider's ingress and captured via Azure Monitor into a Log Analytics workspace, retained for 30 days and then deleted. We do not store IP addresses in our application database.

    We do not use third-party analytics, advertising SDKs, or cross-site tracking. We do not sell your personal information, and we have not done so in the preceding 12 months.


    2. How we use your data

    • Provide the core service: detect clothing in your photos, build your wardrobe, generate outfit recommendations and try-on images.
    • Authenticate you and secure your account (email verification codes, password reset).
    • Send transactional emails only (verification codes, password resets). We do not send marketing email unless you separately opt in.
    • Maintain, debug, and secure the service.

    We do not use your photos, likeness, or content to train AI models, and we do not permit our AI providers to do so (see Section 4). Our agreements with Azure OpenAI and Google confirm that customer data sent to their APIs is not used to train their AI models.


    3. Face and body data (please read)

    If you upload a persona photo, it contains your face and body imagery. We treat it with extra care:

    • What it's used for: exclusively to generate virtual try-on images you request. It is never used for face recognition, identification, profiling, or advertising.
    • Consent: we ask for your explicit consent before your first persona photo upload, and you can use a stock model avatar instead at any time.
    • Where it's stored: encrypted at rest in our cloud storage (Microsoft Azure Blob Storage). Images are served through short-lived, signed URLs.
    • Who processes it: the AI providers listed in Section 4, only at the moment a try-on image is generated, under contracts that prohibit them from retaining or training on it.
    • How long we keep it: until you replace it, delete it, or delete your account. When you delete your account, your persona photo and all other images are deleted immediately and permanently from our storage as part of the deletion request.

    We do not extract or store biometric templates (e.g., faceprints or other biometric identifiers) from your photos.


    4. Who we share data with (subprocessors)

    We share data only with the service providers needed to run Attira:

    ProviderPurposeData shared
    Microsoft Azure (Blob Storage)Cloud storage of imagesAll uploaded and generated images
    Supabase (Supabase Inc.)Database hosting for application dataAccount info, wardrobe metadata, calendar events, conversations, saved looks, settings
    Microsoft Azure OpenAI ServiceClothing detection/description, styling assistant, image generationClothing photos, chat messages, persona photo (during generation)
    Google (Gemini API)Try-on image generationPersona photo, garment images, outfit prompts (during generation)
    Resend (Resend, Inc.)Transactional email delivery (verification codes, password resets)Your email address, verification/reset codes
    Microsoft Azure (Container Apps + Azure Monitor / Log Analytics)Hosting the backend application and storing server logsStandard web request data (IP address, headers, requested endpoints)
    Vercel (Vercel Inc.)Hosting the web frontendStandard web request data (IP address, headers)

    These providers act as our processors and may not use your data for their own purposes. We do not share your data with advertisers, data brokers, or social networks.

    We may also disclose data if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to data collected under it).


    5. Data retention

    DataRetained until
    Account informationAccount deletion
    Persona photosYou replace/delete them, or account deletion
    Wardrobe photos and extracted itemsYou delete the item, or account deletion
    Generated outfits and saved looksYou delete them, or account deletion
    Chat history and calendar eventsYou delete them, or account deletion
    Server logs (incl. IP address)30 days, then automatically deleted

    When you delete your account, your account record and all associated data — wardrobe uploads, calendar events, settings, conversations, saved looks, and every image in storage — are deleted immediately and permanently from our production systems as part of the deletion request. Residual copies may persist only transiently in our cloud provider's automated infrastructure backups, which are overwritten on the provider's standard backup cycle.


    6. Your rights and choices

    You can, at any time:

    • Access and export your data — contact us at support@tryattire.com.
    • Correct your account details in Settings.
    • Delete individual photos, wardrobe items, looks, events, and conversations in the app.
    • Delete your account and all associated data — in Settings → Danger zone → Delete account, or by emailing support@tryattire.com from your registered email address. You can also request deletion without reinstalling the app at [https://tryattire.com/delete-account].
    • Withdraw consent for persona-photo processing by deleting your persona photo and switching to a stock model avatar.

    Depending on where you live, you may have additional statutory rights:

    • EEA/UK (GDPR/UK GDPR): rights of access, rectification, erasure, restriction, portability, and objection; the right to withdraw consent at any time; and the right to lodge a complaint with your supervisory authority. Our legal bases are: performance of contract (providing the service), consent (persona-photo/face-data processing — Article 9(2)(a)), and legitimate interests (security, debugging). [IF EEA/UK USERS IN SCOPE: name your EU/UK representative here if required.]
    • California (CCPA/CPRA): rights to know, delete, correct, and to opt out of sale/sharing. We do not sell or share personal information as defined by the CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
    • India (DPDP Act 2023): rights to access, correction, erasure, and grievance redressal. Contact us at support@tryattire.com.
    • Illinois, Texas, Washington (biometric/health data laws): we do not create biometric identifiers from your photos. Where these laws apply to face imagery, our consent, retention, and deletion practices are described in Sections 3 and 5.

    We respond to verified requests within the timeframe required by applicable law (generally 30–45 days).


    7. International data transfers

    Our infrastructure spans more than one region:

    • Application database (Supabase) — hosted in South Asia (Mumbai, India).
    • Backend application and server logs (Azure Container Apps + Azure Monitor) — hosted in East US (United States).
    • Image storage (Azure Blob Storage) — hosted in East US (United States).

    If you use Attira from another region, your data is transferred to and processed in the regions above. For transfers out of the EEA/UK we rely on Standard Contractual Clauses and, for US providers, the EU-U.S. Data Privacy Framework where the provider is certified.


    8. Security

    • All traffic is encrypted in transit (TLS/HTTPS).
    • Images and data are encrypted at rest by our cloud providers.
    • Passwords are stored as salted hashes.
    • Image URLs are short-lived signed links, not public URLs.
    • Access to production data is restricted to personnel who need it.

    No system is perfectly secure. If a breach affects your personal data, we will notify you and regulators as required by law.


    9. Children

    Attira is not directed to children under 13 (or under 16 for users in the EEA), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact support@tryattire.com and we will delete it.


    10. AI-generated content

    Try-on images are AI-generated previews. They are for personal styling use and may not accurately represent garment fit, color, or appearance. You can report problematic generated content in the app or at support@tryattire.com.


    11. Changes to this policy

    We will post any changes here and update the "Last updated" date. For material changes (especially to how we handle photos or face data), we will notify you in the app or by email before the change takes effect.


    12. Contact us

    Abdul Afreen (sole proprietor) Eluru, Andhra Pradesh, India Email: support@tryattire.com

    All privacy requests, questions, and grievances (including from EEA/UK and India users) go to support@tryattire.com.