Fitox

Privacy Policy

Last updated: August 14, 2026

1. Who we are

Fitox is an AI virtual try-on platform that lets you see how clothing looks on a personalized model of yourself. Fitox is operated by FITOX LTD., which is the data controller responsible for your personal data. This policy explains what information we collect, how we use it, the legal bases we rely on, and the choices and rights you have. It applies to the Fitox app at fitox.app and the Fitox API. By creating an account, you agree to this policy.

2. Information we collect

You give us:

  • Account details — your email address and a password (stored only as a secure hash; we never store your plaintext password).
  • Body measurements — height, chest, waist, hips, weight, and optionally bra size and shoe size, plus your gender and fit preference. These are used to fit garments and calculate fit scores.
  • Photos — the front, side, and/or face photos you upload during onboarding, used solely to generate your base model (see Section 5).
  • Garment photos — any clothing image you upload to try on.

You may also give us:

  • Messages to the AI stylist — anything you type in the stylist chat. Your message, together with relevant profile details (such as your body shape, colour palette and size), is sent to Google's Gemini models to produce a reply (see Section 5). We keep only the most recent part of a conversation, and you can clear it at any time.
  • Style quiz answers — the choices you make in the taste check, used to learn what you like.

We generate or collect automatically:

  • Your base model and try-on results — the images our AI produces from your photos and the garments you try on.
  • Usage data — try-on history, credit balance and usage, saved outfits, cart contents, and basic technical logs (IP address, request time, device/browser) used for security and to operate the service.
  • Product analytics — only if you agree. Which screens you open, which products and outfits you are shown and tap, searches you run, and items you add to a cart or outfit. This is collected by us, on our own servers, and is never shared with any advertising or analytics company. It is tied to a random device identifier stored in your browser. We ask before any of this starts, nothing is stored until you say yes, and you can change your mind at any time — see Section 11.

If you browse before creating an account: you can use much of Fitox signed out, and while you do, the activity above is recorded against that random device identifier rather than a name. If you later create an account on the same device, we link that earlier activity to your account so your likes, measurements, cart and quiz answers carry over rather than being lost. If you would rather that did not happen, clear your browser storage before signing up.

3. How we use your information

  • To create and operate your account and generate your base model and try-on images.
  • To calculate fit scores and size recommendations from your measurements.
  • To track credit usage and prevent abuse or fraud.
  • To send you essential account emails (verification, password reset). We do not send marketing email without your consent.
  • To maintain security, debug problems, and improve the service.

4. Legal bases for processing

Where data-protection law (such as the EU/UK GDPR or Jordan's Personal Data Protection Law) requires a legal basis, we rely on:

  • Performance of a contract — to provide the service you sign up for: your account, base model, try-ons, fit scores, and credits.
  • Your consent — for processing your photos and the biometric/likeness data derived from them (Section 5). You can withdraw this consent at any time by regenerating or deleting your base model, or by deleting your account.
  • Legitimate interests — to secure the service, prevent fraud and abuse, and improve how Fitox works, balanced against your rights.
  • Legal obligation — to keep limited records where the law requires it.

5. Your photos, AI processing, and biometric data

Your photos — and the personalized model we generate from them — are the most sensitive information you share with us. Your face photo and your base model can qualify as biometric or special-category data under some laws, so we process them only with your explicit consent, given when you upload your photos, and we treat them accordingly:

  • Uploaded onboarding photos are stored privately (not publicly accessible) and are used only to generate your base model.
  • After your base model is created, the original front/side/face photos are deleted from our storage. We keep your generated base model so you can try on clothes without re-uploading.
  • To generate images, your base model and the garment image are sent to Google's Gemini AI models. We use Gemini on a paid Google Cloud plan, and under Google's terms for paid services your images and the results are not used to train or improve Google's models, and are not reviewed by people. Google may hold them briefly to detect abuse of its service, after which they are discarded. Fitox itself trains no models on your data.
  • Your base model and try-on results are visible only to you, are never sold, never shared for advertising, and never used to train our or anyone else's AI models.
  • The same Gemini models, on the same paid plan and the same terms, power our other AI features: the AI stylist chat (your messages and relevant profile details), colour analysis and the colour reveal, beauty shots, and the descriptions we generate for products.
  • You can withdraw your consent at any time by regenerating or removing your base model, or by deleting your account — which erases your base model and try-on images (see Sections 8 and 10).

6. How we share information

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are used under California law). We disclose it only to:

  • Service providers (sub-processors) that run Fitox on our behalf: Supabase (database), Cloudinary (image storage), Google (Gemini AI), Resend (email), Railway (API hosting), and Cloudflare (app hosting). Each processes data only to provide their service to us, under contract.
  • Stores — when you place an order, the order details you choose to send (items, sizes, colors, quantities) are shared with that store via WhatsApp so they can fulfill it. We do not share your photos or measurements with stores.
  • Legal reasons — if required by law or to protect the rights and safety of our users and Fitox.

7. International data transfers

Fitox operates from Jordan and uses providers with servers in different regions (for example, Singapore, Japan, and the United States). This means your information may be transferred to and processed in countries other than your own. Where we transfer data from the EU, UK, or another region that restricts international transfers, we rely on an appropriate safeguard — such as the European Commission's Standard Contractual Clauses or an adequacy decision — so your data keeps a comparable level of protection. You can ask us for details using the contact below.

8. Data retention

  • Original onboarding photos: deleted as soon as your base model is generated from them. If you upload a photo and never generate a model, we delete it automatically after a short period rather than keeping it indefinitely.
  • Base model, try-on results, measurements, and account data: kept while your account is active. You can delete your base model or an individual try-on result yourself at any time, without closing your account.
  • Product analytics and error logs: kept for a limited period and then deleted automatically.
  • When you delete your account, we delete your personal data and images. Two deliberate exceptions: analytics records are stripped of anything identifying you rather than removed, so historical totals stay accurate; and if an email to you ever permanently bounced or you marked our mail as spam, we keep that address on a suppression list so we do not email you again — deleting it would undo your own opt-out.
  • We may also retain limited records where the law requires it.

9. Security

We protect your data with industry-standard measures: encrypted connections (HTTPS), hashed passwords, private storage for personal photos, access controls, and rate limiting. No system is perfectly secure, but we work to keep your information safe and to promptly address any issues.

10. Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal data:

  • Access and portability — get a copy of the personal data we hold about you, as a machine-readable JSON file you can keep or take elsewhere. Ask us and we will send it.
  • Correction — fix inaccurate data (you can edit your measurements and profile in the app anytime).
  • Deletion — delete your base model, delete any individual try-on result, or delete your account entirely, which removes your personal data and images. The first two you can do yourself in the app, without closing your account.
  • Restriction and objection — ask us to limit or stop certain processing.
  • Withdraw consent — withdraw your consent to biometric/photo processing at any time by deleting your base model (Section 5).
  • No sale or sharing — because we do not sell or share your data for advertising, there is nothing to opt out of, but you can confirm this with us.
  • Non-discrimination — we will not treat you differently for exercising any of these rights.

To exercise any of these rights, contact us at privacy@fitox.co. If you are in the EU, UK, or another region with a data-protection authority, you also have the right to lodge a complaint with your local regulator.

11. Cookies and local storage

We set one essential, secure cookie to keep you signed in (an httpOnly refresh-token cookie). We do not use advertising or cross-site tracking cookies, and we do not sell or share your data with ad networks.

Other things are stored on your device, all of which you can clear at any time in your browser settings:

  • Local storage — your cart, saved outfits and measurements, kept so the app works smoothly between visits. These are your own data for features you asked for, so we don't ask permission to keep them. Signing out clears the entries that identify you.
  • The analytics identifier — your choice. The random device identifier in Section 2 is the one thing here that isn't needed to run the service, so we ask first. We show a short prompt on your first visit; until you choose Allow, no identifier is created and no analytics are collected. Choosing No thanks keeps it that way.
  • Changing your mind — open Fitting Room → Product analytics and switch it off (or on) whenever you like. Switching it off also deletes the identifier, so any future browsing can't be connected to what came before. Withdrawing is exactly as easy as agreeing.
  • Google Sign-In — if you choose “Continue with Google”, Google sets its own cookies on its domain as part of signing you in. Those are Google's, governed by Google's privacy policy, and we cannot read them.

12. Children

Fitox is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service evolves. We will post the new version here with an updated date, and for significant changes we will notify you in the app or by email.

14. Contact us

Questions about privacy or your data, or to exercise your rights? Email privacy@fitox.co, or write to us at FITOX LTD., Amman, Jordan 11831.

This policy is provided in plain language to describe how Fitox handles your data. It is not legal advice.