Privacy policy
Last updated October 7, 2026
ChangeMyFit (“we”, “us”) makes a browser extension and this website that let you try clothes on a photo of yourself. This policy explains what we collect, why, who helps us process it, and the choices you have. Questions go to hello@changemyfit.com.
What we collect
- Your account. When you sign in with Google we receive your name, email address and profile picture. We never see your Google password.
- Your photo. The photo of yourself you add so we can dress it.
- Items you add. The clothing images you drag in or upload and, when they come from a shop page, that page's link and the product's name and brand.
- Your fits and looks. The fits you build, their names, and the images we generate for you.
- Credits. How many credits and free photos you have. To stop free credits being claimed again with a new account, we also keep a one-way hash of your email address, recording that it has had them.
- Purchases. When you buy credits, a record of each payment: which checkout and payment it was, and how many credits it added. Stripe handles your card details; we never see or store them.
- Technical data. Sign-in session details such as your IP address and browser type, and the logs our hosting providers keep to run and secure the service.
- Usage. What happens in your account, like a look made or failed or credits bought, recorded by a random account ID rather than your name or email. On this website, the pages visited, clicks and errors, with a cookie that recognises a returning visitor, and the rough location (country and city) PostHog works out from your IP address. If you remove the extension, the reason you choose on the page that opens, if you send one.
The extension reads a web page only when you drag something from it into the sidebar, to find that item's image, name and link. It does not track or send us the pages you visit.
How we use it
- To run ChangeMyFit: keep your photo, fits and looks in your account and make the looks you ask for.
- To keep track of your credits and prevent abuse of free credits.
- To keep the service secure, fix problems and improve it.
- To reply when you contact us.
We do not sell your data, use it for advertising, or use your photos to train AI models. Where the GDPR applies, we rely on performing our contract with you to provide the service, and on our legitimate interests to secure it and prevent abuse.
Who processes it for us
- Google, to sign you in.
- Convex, which hosts our database and backend.
- Cloudflare, which stores images (your photo, items and looks).
- OpenAI, which generates your looks. For each look it receives your photo and the item images in that fit. Under OpenAI's API terms this data is not used to train their models and may be kept for up to 30 days to detect abuse.
- Stripe, which takes payments for credits and sends your receipt.
- Vercel, which hosts this website.
- PostHog, in the EU, which shows us how ChangeMyFit is used, from the usage above.
These providers may process data in the United States and other countries. Where required, transfers are covered by safeguards such as the EU Standard Contractual Clauses.
Image links
Your images are stored at long, random web addresses that are not listed or linked anywhere, so the sidebar can show them quickly. Anyone who has the exact address of an image could open it, so don't share those addresses if you want an image kept private.
How long we keep it
We keep your photo, fits and looks for as long as you have an account. An image is deleted when you remove it and nothing else in your account uses it, or if its upload never finished being added to a fit. You can delete your account at any time from the account page. That permanently deletes your photo, items, fits, looks, credits and account. Only the email hash is kept, so free credits can't be claimed twice, the record of each payment, which Stripe keeps too and the law requires for accounting, and the usage PostHog recorded, which names only the random account ID that no longer leads to you. Copies may remain in our providers' backups for a short period before they are overwritten.
Your rights
Depending on where you live, including the EEA, the UK and California, you may have the right to access, correct, export or delete your data, and to object to or restrict how we use it. Email us to exercise any of these; we will reply within 30 days. You can also complain to your local data protection authority. We do not sell or share personal data as those terms are defined under California law.
Children
ChangeMyFit is for people aged 18 and over. We do not knowingly collect data from anyone younger; if you believe we have, contact us and we will delete it.
Security
Data is encrypted in transit, and access to your account requires your Google sign-in. No service is perfectly secure, but we work to protect your data and will tell you about a breach that affects you as the law requires.
Changes
If we change this policy we will update the date above, and tell you in the extension or by email if the change is significant.