We take your privacy seriously. Here's exactly what we collect, where it goes, and how to delete it — written in plain language so you actually know what's going on.
LAST UPDATED · 2026-09-11When you sign in with Apple, we receive a stable, anonymized user ID from Apple plus an email address (you may choose Apple's privacy-relay address — that's fine with us).
When you sign in with Google, we receive your Google account email, display name, and profile photo URL. Google handles the authentication — we never see your Google password.
When you continue as a guest, Supabase assigns an anonymous account ID. We do not receive an email address unless you later connect a sign-in method.
Your display name, avatar, optional age, gender identity, height, body-build and language preferences, consent timestamps, and current credit balance are stored in our database when you provide them.
If you add clothing photos to your wardrobe, those photos are uploaded to private Supabase Storage and linked to your account. This lets your wardrobe sync across the iOS app and browser extension. Other users cannot access your wardrobe items.
Each time you tap "Try on", your selected model photo and the clothing photo are sent securely (TLS) to a server function. The function forwards them to the image provider and model you select in the app. Current image models, including Google Gemini models, are accessed through OpenRouter, which routes the request to the selected model's provider, then returns the result image.
We do not retain try-on input photos as stored input images. They are used to generate the result and are not kept as source photos after processing.
If you choose to create an Identity Pack, the reference photos you upload are stored in private Supabase Storage and linked to your account. They are used to keep your appearance consistent in future AI photos. The reusable character asset created from those references is stored privately in the same way.
Identity Pack photos and the character asset are sent to the selected image provider when needed to create the asset or a new AI photo. They remain in your account until you replace them, delete them, or delete your account. Other users cannot access them.
We keep generation status, timestamps, selected options, credit usage, and limited diagnostic details for billing accuracy and debugging. Signed-in users may also keep generated results in their private cloud history; guest results remain in that browser or device unless saved.
When you buy credits, Apple processes the payment. We receive an transaction status that we use to credit your account. RevenueCat may process purchase and entitlement records on our behalf. Apple's terms govern your payment information — we never see your card.
If the app crashes, Apple may share anonymous crash reports with us (only if you opted in to share with developers). We do not use any third-party analytics or advertising SDKs.
OpenRouter and the selected model's provider process the photos and instructions needed for the generation you request. The selected provider may process face-related visual features to preserve identity. We do not use your inputs or outputs to train our own models. Provider processing, retention, abuse monitoring, and training rules are governed by the selected provider's current terms.
See Google's Gemini API terms and privacy policy, and OpenRouter's terms and privacy policy.
TryonMe's image-generation features are for adults aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us so we can delete it.
You may request access to, correction of, or deletion of your data at any time by emailing us. Residents of California (CCPA) and the EU (GDPR) have additional rights including data portability and the right to object to processing.
Questions about privacy? support@appnor.io
Mail: Appnor — Ali Ozkan, Los Angeles, California, USA. Contact via email above.
If we change this policy in a material way we'll notify you in the app and update the "last updated" date above.