Security & data handling
Built to reduce
unnecessary exposure.
Security is a set of controls and limits, not a promise that risk is zero. This page describes the safeguards implemented by Private Try-On and the boundaries that still depend on external providers and your own device.
Encrypted connection
The public service is delivered over HTTPS so information is encrypted in transit between a supported browser and the site. HTTPS does not control what an external AI provider does after receiving a generation request.
Session protection
Authentication sessions use server-validated, HttpOnly cookies. Production cookies are marked Secure and use a restrictive SameSite policy. State-changing administrative actions require a CSRF token and an allowed request origin. These controls reduce common browser-based attacks but do not replace safe passwords, sign-out on shared devices or account monitoring.
Bounded uploads
Image requests accept defined fields and supported formats, reject mixed or unexpected request contracts and enforce request-size limits. These checks limit accidental or abusive input; they do not prove that an uploaded image is truthful, authorised or free of harmful content.
Temporary media references
When the configured generation flow needs a public image reference, the application can hold it in memory behind a random, short-lived token with expiry, entry and total-size limits. Expired or explicitly disposed entries are removed from that application store. The app does not publish customer images in a searchable gallery.
External AI provider boundary
Your selected inputs and generation instructions are transmitted to the configured AI provider. That provider operates outside this application's temporary media store and may apply its own retention, safety and training terms. Private Try-On cannot currently guarantee provider-side immediate deletion or no-training treatment for every configured provider. See privacy and AI processing before submitting sensitive material.
Account and payment records
Account identifiers, allowance balances, subscriptions, payment references and audit records may be retained to operate access, purchases, cancellation and reconciliation. Private Try-On does not collect your PayPal password or card number; payment credentials are handled on PayPal's service when checkout is available.
Responsible use
Use only images you own or have permission to use. Avoid sensitive, intimate or identifying images that are unnecessary for a style preview. Sign out on shared devices and remove downloaded results from devices you do not control.
Reporting a concern
If you are evaluating a merchant pilot, include the security or data-handling question in the private store preview request. Do not include passwords, payment credentials or sensitive photographs in the message. We will verify the issue before asking for additional evidence.
Last updated: 13 September 2026.
Read the privacy explanation →