Skip to content
Vesta
HomeTermsPrivacy choices

LEGAL · PRIVACY

Privacy, in plain language.

This policy explains what Vesta processes when you use the AI fitting room, where that information goes, and the choices available to you.

Effective: September 19, 2026Version 1.0Applies to iOS, Android & website
Publisher details required before public releaseReplace the legal entity, public address, and working privacy/support emails in site-config.js. The policy structure is complete, but those details must be real and monitored.
On this page1. Scope & controller2. Data we process3. How we use data4. EU/EEA legal bases5. Sharing6. Retention7. International transfers8. Your rights9. U.S. state rights10. Children11. Security12. Changes13. Contact

At a glance

Vesta needs a person photo and a garment image to generate a virtual try-on. In the current architecture, processing copies and generated images on Vesta’s server are configured to expire after 24 hours. Imported wardrobe items and app preferences are primarily stored on your device. Vesta does not currently use advertising or third-party analytics SDKs.

1. Scope and data controller

This Privacy Policy applies to the Vesta mobile application, the Vesta website, and related support services (together, the “Service”). Vesta is the controller responsible for personal data described here, except where another service acts as an independent controller under its own terms.

Publisher address: Publisher address required before public release.

The current app can be used without creating a Vesta account. If account functionality is introduced, this policy and the in-app notices will be updated before that change applies.

2. Data we process

Category Examples Source
Photos and generated content Person photos, garment photos or screenshots, cropped product images, and virtual try-on results. You, your camera/photo library, or content you intentionally share to Vesta.
Product and wardrobe information Product URLs, retailer, title, garment type, selected image, description, and locally saved wardrobe metadata. You and publicly available metadata from a product page you submit.
Try-on and service data Job ID, selected AI provider, job status, progress, error code, creation time, credit balance, and idempotency identifiers. Generated when you use Vesta.
Purchase information Product identifier, credits purchased, localized price, purchase status, and transaction identifier used for verification. Apple App Store or Google Play. Vesta does not receive your full payment-card details.
Device-local settings AI provider setting in test builds, remaining credits, auto-delete preference, imported products, and app permissions. Your device and choices.
Website technical data Basic request data such as IP address, browser type, and timestamps may be processed by the hosting provider for delivery, reliability, and security. Your browser and hosting infrastructure.

Embedded store browser

When you visit a retailer inside Vesta, the retailer may use cookies or similar technology in that browser session under its own privacy policy. Vesta captures only the viewport when you choose “Add to wardrobe”; it does not automatically read a retailer’s page content or complete purchases for you.

3. How we use data

  • Provide the virtual try-on you request, including image upload, AI processing, results, saving, and sharing.
  • Import a product from a submitted URL or screenshot and organize your wardrobe.
  • Maintain job status, credit balances, purchase verification, error handling, and fraud or abuse prevention.
  • Respond to privacy, support, safety, or legal requests.
  • Protect the Service, diagnose failures, and comply with law.

Vesta does not use person photos to train Vesta models, build advertising profiles, identify you, or infer sensitive traits. If that practice changes, Vesta will provide a separate notice and obtain consent where required before using affected data.

4. EU/EEA legal bases

For people in the European Economic Area or European Union, Vesta relies on the following bases under the GDPR:

  • Contract: to provide try-on, wardrobe, purchase, saving, sharing, and support functions you request.
  • Consent: when you choose to provide a photo or grant camera/photo-library access, and where consent is otherwise required. You can withdraw device permissions at any time.
  • Legitimate interests: to secure the Service, prevent abuse, troubleshoot, and improve reliability, balanced against your rights.
  • Legal obligation: to comply with law, valid government requests, tax, accounting, or consumer-protection duties.

Vesta’s AI output is a visual preview. It is not used to make decisions that produce legal or similarly significant effects about you.

5. When information is shared

Vesta may disclose the minimum necessary information to:

  • AI processing providers: Google Cloud Vertex AI or Replicate, depending on production configuration, to generate the requested try-on.
  • Infrastructure providers: hosting, storage, content delivery, security, and support vendors operating under contract.
  • App stores: Apple and Google for distribution, in-app purchase processing, refund handling, and platform security.
  • Retailers and websites you open: when you deliberately browse or return to a store; their own terms and privacy policies apply.
  • Authorities or transaction parties: when required by law, needed to protect rights and safety, or as part of a merger, financing, acquisition, or sale, subject to appropriate safeguards.

Vesta does not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising in the current version.

6. Retention and deletion

  • Server images: uploaded person photos, uploaded garment images, copied product images, and server-generated result files are configured with a 24-hour time-to-live and are removed by automated cleanup.
  • In-memory job and credit records: the current backend holds these while the service process is running and removes user-linked entries when the deletion endpoint is invoked. Production infrastructure must preserve only what is necessary for purchases, security, and legal obligations.
  • On-device content: imported wardrobe metadata and product images remain until you remove them, clear app data, or uninstall the app. Images you save to your photo library remain under your device controls.
  • Store records: Apple or Google may retain transaction records under their own policies and legal duties.

Backups, security logs, chargeback records, or records required by law may be retained longer, isolated from ordinary use, and deleted or anonymized when no longer needed.

7. International data transfers

Vesta and its providers may process data in countries outside the EEA, including the United States. Where required, Vesta will use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism and apply appropriate technical and organizational safeguards. You may request information about the applicable safeguard.

8. Your privacy rights

Depending on your location, you may ask Vesta to access, correct, delete, restrict, or provide a portable copy of personal data; object to certain processing; withdraw consent; or complain to your local data protection authority. EU/EEA rights are not absolute and may depend on the circumstances.

Because the current app has no account and temporary image URLs are not intended to identify you, include the job ID, approximate date/time, device platform, and any relevant purchase transaction reference when making a request. Do not email the photo itself unless support specifically asks you to.

Visit Privacy Choices for device-level controls and the request channel.

9. U.S. state privacy rights

Residents of California and certain other U.S. states may have rights to know or access categories and specific pieces of personal information, delete, correct, and obtain a portable copy, and to opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling. Vesta does not currently sell personal information or use it for those advertising purposes, so no opt-out signal is necessary for the current version.

Vesta will not discriminate against you for exercising an applicable privacy right. An authorized agent may submit a request where permitted; Vesta may verify both the agent’s authority and your identity. If Vesta denies a request, you may appeal by replying to the decision.

10. Children

Vesta is not directed to children under 13 in the United States, or under the minimum digital-consent age in their country. Do not submit a child’s photo unless you are the parent or legal guardian and the use is lawful. If Vesta learns that a child’s data was collected without required authorization, it will take reasonable steps to delete it.

11. Security

Vesta uses measures designed to protect data, including HTTPS in production, restricted service credentials, private file permissions, upload size and type checks, short image retention, and provider credentials kept on the backend rather than in the mobile app. No system can guarantee absolute security. Please report suspected security issues to support@your-domain.example.

12. Changes to this policy

Vesta may update this policy when features, providers, or legal requirements change. Material changes will be highlighted in the app or on this page before they take effect where required. The effective date and version at the top show the latest revision.

13. Contact

Privacy controller: Vesta
Address: Publisher address required before public release
Privacy requests: privacy@your-domain.example
Support: support@your-domain.example

EEA users may also lodge a complaint with the supervisory authority in their country of residence, work, or the place of the alleged infringement.

Vesta
PrivacyTermsPrivacy choices