Privacy

What we collect, and why.

Short version: your photo generates a try-on preview and nothing else. Here's the full, specific version — what we collect, how long we keep it, who it's shared with, and how to get it back.

This page describes what Modelly actually does, based on how the product is built today. It's written to be accurate and complete, but it isn't a substitute for professional legal advice — if you need that for your own compliance purposes, get a lawyer to review it rather than relying on this page alone.

Account data

Creating an account means we store your name, email address, and a bcrypt-hashed password — we never store or log your password in plain text. If you sign in with Google instead, we receive your Google account ID and the name and email on your Google profile.

Photos you upload

A photo you upload is used only to generate the try-on or outfit result you asked for. The original uploaded photo is always deleted immediately once that job finishes — whether it succeeded or failed. We don't keep a copy, and we don't use it to train any AI model unless you give separate, explicit opt-in consent for that.

Generated results and saved looks

A generated result is temporary by default — if you don't save it, it's automatically deleted within roughly 24–48 hours. Saving a result as a "look" is what makes it durable: from that point it's stored with a label and timestamps, tied to your account, until you delete it or delete your account.

Onboarding survey

When you sign up, we may ask a short, optional, skippable survey — how you heard about Modelly, whether you're here for personal or business use, and a 0–10 recommend score. None of it is required to use the product.

Reviews

Submitting a review doesn't require an account — anyone can submit a name, star rating, and quote, and it's rate-limited to prevent abuse. Reviews are only shown publicly once approved.

Newsletter and forms

Signing up for the newsletter stores your email address, nothing else. The demo, contact, and FAQ support forms store your name and email plus whatever else that particular form asks for — business or store name, website, role, phone number, plan interest, or free-text notes — depending on which one you fill out.

Security and technical data, collected automatically

  • Your IP address is used for rate-limiting and to lock out repeated failed sign-in attempts.
  • If your password is changed, we send a security email that includes your device/browser (parsed from your User-Agent) and a best-effort approximate location derived from your IP through a third-party lookup — so you can tell whether a password change was really you. That lookup is used only for this one email, and if it fails, the email just says "Location unavailable" instead of guessing.
  • A session cookie (httpOnly — not readable by JavaScript) and a CSRF token cookie are set so the site works and your session is protected. Neither is a tracking or advertising cookie. Sessions expire after 120 minutes of inactivity.
  • We keep basic page-view analytics — which pages get visited — stored on our own servers. It isn't tied to advertising and isn't sold or shared with ad networks.
  • We're in the process of adding Google Analytics, to understand traffic and usage patterns at a larger scale than our own basic page-view count covers. We're configuring it with Google's ad-personalization/Signals features turned off, so it stays an analytics tool rather than an advertising one — but it does set its own cookie and send visit data to Google, which is why it's called out here separately rather than folded into "what we don't do" below.

Admin and error logs

Internally, we keep an audit log of admin actions (who did what, for accountability) and a capped log of unexpected technical errors, kept for 30 days. These are operational and security records — they aren't used to build a profile of you or for anything beyond keeping the service reliable and secure.

What we don't do

No advertising cookies, no third-party ad trackers, no selling personal data, and no training AI on your photos without your separate, explicit opt-in. Google Analytics (above) is configured as analytics only, with ad-personalization features off — we're not treating it as an exception to this, but we're naming it explicitly rather than letting "no third-party ad trackers" imply we use nothing from Google at all.

Who your data is shared with, and why

  • Resend sends transactional email on our behalf — OTP codes, password-change alerts, welcome emails, lead confirmations. It receives the recipient's email address and the content of that message.
  • Google sees your account info if you choose "Continue with Google" (a standard OAuth handshake, and we receive back the basic profile info described above), and separately receives visit data through Google Analytics, configured with ad-personalization off.
  • A third-party IP-geolocation lookup receives the IP address of whoever just changed a password, for that single security-email purpose, and nothing else.
  • Our infrastructure runs on Hostinger, with a separate service on Railway handling the AI generation step specifically.
  • Once fully live, the AI provider that generates your try-on or outfit image will receive the photo you upload for that single purpose. As of today, that call is still a stub in our backend and isn't wired to a live provider yet — we're noting this as accurate future-state, not something already happening.
  • Once payments launch, a payment processor will handle billing on our behalf — see our terms for how billing works. We don't store raw card details ourselves.

How long we keep things

  • Uploaded photos — deleted immediately after each job finishes.
  • Unsaved generated results — roughly 24–48 hours.
  • Saved looks and account data — until you delete them or your account.
  • Error logs — 30 days.
  • Sessions — 120 minutes of inactivity.

Your rights

You can exercise these directly, or by emailing us — no need to explain why.

  • Access and portability. Download a copy of your data any time from your account using "Download your data."
  • Rectification. Edit your name or email directly on the same account page.
  • Erasure. Deleting your account is real — your uploaded photos and saved looks are genuinely purged. To be precise about it, though: the account record itself is soft-deleted rather than instantly wiped from our database, so we can keep the minimum internal record-keeping a small business needs. It's not usable, not visible to you or anyone else, and it isn't "everything is instantly and completely gone" in the most literal sense — we'd rather say that plainly than round it up.
  • Objection, restriction, and withdrawing consent. Email us at privacy@modelly.fit and we'll act on it.
  • Complaints. You also have the right to lodge a complaint with your local data protection supervisory authority — which one depends on where you live, so we won't guess it for you here.

Questions or deletion requests

Email privacy@modelly.fit for privacy questions or to request deletion of your data. See our terms for how the product and billing work.