← Back to WeartyAI

Privacy & Cookies Policy

Last updated: 26 April 2026 · Version: 2.0

This policy explains what personal data WeartyAI collects, why we collect it, how long we keep it and what rights you have. It is written for users in the United Kingdom and the European Economic Area, and is designed to comply with the UK GDPR, the EU GDPR (Regulation 2016/679), the UK Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

1. Who is the data controller

The data controller is WeartyAI, operating under sole-trader registration in the United Kingdom. Contact: weartyai@gmail.com. We do not have a Data Protection Officer (DPO) — none is required for our scale — but the contact email above reaches the person responsible for privacy decisions.

2. What personal data we collect

CategoryExamplesSource
Account identityEmail address, hashed password, display name, avatar URL (if you sign in with Google)You, or Google OAuth
Usage dataPhotos you upload to be analysed, the resulting AI outputs, your credit balance, transaction historyYou
Payment dataStripe customer ID, last-4 of card, country, billing email; we do not store card numbersStripe
Technical dataIP address, device type, browser, app version, error logsAutomatic, on each request
CommunicationsEmails you send to support; transactional emails we send you (login link, receipts)You / us

3. Why we collect it (purposes & legal basis)

Under UK GDPR every processing activity needs a lawful basis. Ours:

What we doWhyLegal basis (UK GDPR)
Create & maintain your accountYou asked us to provide the serviceArticle 6(1)(b) — contract
Process your photos through AI models (valuation, product shot, model shoot, animation)You asked for the resultArticle 6(1)(b) — contract
Charge you / refund creditsTo take payment for credits you boughtArticle 6(1)(b) — contract
Send transactional emails (magic link, payment receipt, refund)So you can use the serviceArticle 6(1)(b) — contract
Keep error logs & usage statsDetect bugs, prevent fraud, plan capacityArticle 6(1)(f) — legitimate interest
Comply with tax / VAT / anti-money-laundering rulesUK law requires itArticle 6(1)(c) — legal obligation
Send marketing emails (only if you opt in)Tell you about new featuresArticle 6(1)(a) — your consent (opt-in)
Use optional analytics cookiesSee which features are usedArticle 6(1)(a) — your consent (cookie banner)

4. Who we share it with (sub-processors)

To run WeartyAI we use a handful of carefully chosen vendors. Each is a data processor acting on our instructions under a written agreement (DPA). We do not sell your personal data and we do not share it with advertisers.

VendorWhat it does for usWhere data is processed
SupabaseStores your account & transaction data, runs authEU (Frankfurt)
RailwayHosts our backend APIUSA (Oregon) with EU SCCs in place
VercelHosts our websiteGlobal edge network with EU SCCs
StripeTakes card payments, sends receiptsUK + Ireland
fal.aiRuns the image / video AI models that analyse your uploaded photosUSA with EU SCCs in place
AnthropicRuns Claude models that read your photo to write product descriptionsUSA with EU SCCs in place
ResendSends our transactional emailsUSA with EU SCCs in place
GoogleSign-in with Google (OAuth) only — we receive your email + nameUSA with EU SCCs in place

A current list of sub-processors is maintained at the address above and may change with notice.

5. International transfers

Some of our sub-processors are based in the United States. When data leaves the UK / EEA, it is protected by the European Commission's Standard Contractual Clauses (SCCs) as incorporated into UK law, plus, where available, certification under the UK Extension to the EU-US Data Privacy Framework. Your data is encrypted in transit (TLS 1.3) and at rest.

6. How long we keep it

DataRetention
Account record (email, password hash, settings)While your account is open + 30 days after deletion
Photos you uploadCached at our AI providers for the duration of generation, then deleted within 24 hours. Generated outputs are stored on your account until you delete them.
Credit transactions7 years (UK HMRC requirement)
Stripe payment recordsHeld by Stripe under their own retention rules; we keep transaction IDs for 7 years
Server access logs30 days
Marketing email opt-insUntil you unsubscribe

7. Cookies & similar technologies

A "cookie" is a small text file your browser stores on your device. We use the minimum needed and ask your permission before setting anything optional, as required by PECR §6.

Strictly necessary (always on)

Optional — analytics (off unless you accept)

If you accept analytics in our cookie banner, we may, in future, set anonymous measurement cookies (e.g. Vercel Analytics). At the time of writing we do not load any analytics scripts. If we add some, we will only do so after you opt in via the cookie banner.

Optional — marketing (off unless you accept)

We do not currently use marketing cookies (no Google Ads, no Meta Pixel, no TikTok Pixel). If we ever add these, they will require your consent first.

Changing your mind

You can change your cookie choices any time using the "Cookie preferences" link in our website footer. Your choice is reset if you clear your browser storage.

8. Your rights

Under UK GDPR / EU GDPR you have the following rights. To exercise any of them, email weartyai@gmail.com from the address you registered with — we will respond within 30 days, free of charge.

9. Children's privacy

WeartyAI is for users aged 18 and over. We do not knowingly collect data from children under 18. If you believe a child has created an account, email us and we will delete it.

10. Security

We use TLS 1.3 for all traffic, hash passwords with bcrypt (via Supabase auth), store JWTs in HttpOnly cookies, and run our backend on Railway with private networking. Photos are processed in-memory and not written to long-term storage. Despite our efforts no system is 100% secure — if we discover a personal data breach that risks your rights, we will notify the ICO within 72 hours and you without undue delay, as required by Article 33 / 34 UK GDPR.

11. Changes to this policy

We may update this policy when our practices or the law changes. Material changes are emailed to registered users at least 14 days in advance. The current version number and date are at the top of the page. Old versions are kept on request.

12. Contact & complaints

Questions, requests, complaints: weartyai@gmail.com.

If you are not satisfied with our response, you have the right to complain to a data protection regulator: