Privacy Policy
Effective 27 September 2026
Who is the controller
chiqo.fit is a digital wardrobe, outfit, and AI virtual try-on service. The data controller is the operator of chiqo.fit: Denis Kotenko pr Računarsko programiranje Razrabotchik Novi Sad, Trg Republike 20/1/2, Novi Sad, Serbia.
Privacy questions and requests: denis@chiqo.fit. General support: denis@chiqo.fit.
What we collect
- Account data: email address, Firebase user id, account timestamps, wallet balance, and payment provider order ids when applicable.
- Wardrobe data: item photos, attributes, links, and AI autofill results you save.
- Avatar and try-on data: face or body reference photos you upload and AI-generated try-on or outfit images produced for you.
- Outfit data: photos you upload, generated cover images, item references, and publication status.
- Social profile data (if you use social features): public handle, display name, bio, profile photo, follow/block relationships, and age attestation metadata (version, timestamp, eligibility flag).
- Social content: posts you publish, comments, likes, notifications, and content reports you submit (including optional details and a snapshot of the reported content).
- Preferences stored on your device: locale, theme, fitting-queue ids, try-on composer state, and the debug API environment switch in first-party
localStorage. - Technical data: authentication tokens, request logs, and security-related metadata processed by our hosting providers.
- We do not require a postal address to use the free wardrobe features.
Why we use it
We process personal data to provide and secure the service, run AI analysis and virtual try-on, operate optional social features, process prepaid wallet credits, enforce our Terms and Community Guidelines, respond to reports, and comply with law.
Legal bases (EEA/UK)
- Contract — to create and maintain your account, store your wardrobe, deliver AI features you request, and process prepaid credits.
- Legitimate interests — to keep the service secure, prevent abuse, improve reliability, and moderate reported content, balanced against your rights.
- Consent — where required for optional processing (for example, if we add non-essential analytics or marketing cookies in the future).
- Legal obligation — where we must retain or disclose information to comply with applicable law.
Processors and service providers
- Google Firebase Auth — sign-in and identity (email / Google account).
- Hetzner — API and web app hosting.
- Cloudflare R2 — object storage for photos and generated images.
- FastSpring (Merchant of Record) — test checkout and, once live payments are enabled, payment processing, tax, receipts, refunds, and payment disputes for credit top-ups.
- OpenRouter — LLM gateway for item analysis and outfit text. Item photos and attributes may be sent to this processor.
- Replicate — image operations such as background removal, upscaling, and try-on / outfit image generation. Photos and face images may be sent to this processor.
International transfers
Some processors are located outside the EEA, including in the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms approved under applicable law.
AI processing
When you use AI features, photos and related attributes may be transmitted to OpenRouter and Replicate to analyze items and generate try-on or outfit images. Outputs may be stored on Cloudflare R2 and linked to your account.
We do not represent that third-party AI providers will never use submitted content for their own model improvement. Do not upload sensitive images you do not want processed by these providers.
Social features and public content
If you enable social features, information you choose to make public — such as your handle, display name, bio, profile photo, and published posts — can be viewed by other signed-in users in feeds and on your public profile page.
Public Discover and Following surfaces show outfit and item imagery attached to posts. They do not display other users' private photoreal body try-on renders. Your own body try-on results remain visible to you in your account unless you separately choose to publish permitted outfit imagery.
Social features require that you attest you meet the minimum age stated in our Terms (currently 16). We store the attestation version and your response.
Retention
We keep account and wardrobe data until you delete your account or ask us to delete data we control. Individual wardrobe items and outfits are removed when you delete them or when your account is deleted.
Payment providers may retain purchase and tax records where required after we erase app data we control.
Your rights
If you are in the EEA, UK, or Switzerland you may have rights to access, delete, rectify, restrict, object to, and port personal data, and to withdraw consent where processing is consent-based.
California and other US state residents may have rights to know, delete, and correct personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.
Export and deletion
Signed-in users can export account metadata via GET /v1/me/export (JSON; no raw photo bytes). To delete the account and app data we control, use DELETE /v1/me?confirm=delete while signed in, or email denis@chiqo.fit. Firebase Auth deletion may require an active session.
We will respond to verified requests without undue delay and within time limits required by applicable law.
Children
chiqo.fit is not directed at children under 13, and we do not knowingly collect personal data from them.
Social features (public handle, publishing, comments, follows) are available only to users who attest they are at least 16. If you believe a child has provided personal data, contact denis@chiqo.fit.
Cookies and local storage
Firebase Auth uses strictly necessary session storage for sign-in. First-party localStorage stores functional preferences (locale, theme, fitting queue, try-on composer, debug API env). We do not set advertising pixels or sell data from cookies.
When you use checkout, FastSpring may set cookies on its own checkout domain after redirect.
Content reports and moderation
If you report content, we process your report, the reason you select, optional details, and a snapshot of the reported content so operators can review it under our notice-and-action process described in the Terms and Community Guidelines.
Contact
Privacy requests and controller questions: denis@chiqo.fit. Support: denis@chiqo.fit.
chiqo.fit · How it works · Digital wardrobe · Virtual try-on · Pricing · Privacy · Terms · Community · Refunds