Privacy Policy
This policy describes how FitCheck handles information for the current women's formal / wedding-guest dress beta.
Last updated: August 26, 2026
What FitCheck is
FitCheck is a beta shopping assistant that helps you find dresses that fit your measurements, style preferences, and shopping intent. You can browse recommendations without creating a traditional account or password.
Information you provide directly
You may choose to enter:
- Body measurements used for size guidance
- Color season
- Style preferences ("Your Style")
- Shop My Values preferences
- Product or keyword search intent
- Optional feedback through FitCheck's feedback forms
- Optional photos for Virtual Try On (processed for that feature only)
These fields are optional for browsing. Skipping personalization does not block basic recommendations; sizing guidance may be omitted when measurements are missing.
Durable shopper identity
FitCheck creates a random, high-entropy shopper identity so your profile can persist across visits in the same browser. This identity is FitCheck-generated. FitCheck does not use device fingerprinting, IP address identity, or hidden cross-site tracking to create shopper identity.
An ownership credential is stored in your browser and sent to FitCheck servers only as needed to load or update your durable profile. Analytics/session identifiers used for product metrics or Try On limits are separate from this shopper identity.
Where profile data is stored
Profile details may be stored in your browser for immediate use and on FitCheck's servers (via our database provider) as the durable copy for Personal Shopper foundation features. Uploaded Try On photos and generated Try On images are not treated as part of your durable shopper profile payload.
Optional Gmail / shopping history
Connecting Gmail is optional. FitCheck does not require Gmail to use the product. You may skip email connection at any time.
If you choose Connect Gmail, FitCheck requests read-only Gmail access (gmail.readonly). FitCheck does not request permission to send, delete, or modify your email, and does not access Google Contacts, Calendar, or Drive for this feature.
FitCheck uses Gmail access specifically to discover fashion-commerce emails (such as order, shipping, delivery, return, refund, cancellation, or exchange messages) and to create structured shopping- history records associated with your FitCheck shopper identity.
Extracted shopping-history fields may include, when present in the email:
- Retailer / merchant
- Transaction type (for example purchase, return, refund)
- Order identifiers and dates
- Product names, sizes, colors, quantities, and prices when reliably parsed
- Source message identifiers needed for deduplication and audit
FitCheck does not intend to keep a full archive of your mailbox. Email content is processed to extract shopping facts; unnecessary raw message bodies are not retained as a general email store.
OAuth access and refresh tokens are encrypted and stored server-side. Those tokens are not exposed to the browser, localStorage, sessionStorage, client API responses, or analytics events.
A purchase is evidence, not preference. Imported shopping history does not automatically mean you liked an item, kept it, or that it fit correctly. In the current product phase, shopping history is not used to change Similar Styles, Recommended For You, sizing logic, or recommendation ranking.
Google user data — Limited Use
FitCheck's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, for Gmail data obtained through Google OAuth:
- We use Gmail data to provide and improve the user-facing shopping- history import feature you requested
- We do not use Gmail data for serving advertisements
- We do not sell Gmail data
- We do not use Gmail data for purposes unrelated to the shopping- history feature described in this policy
- We do not transfer Gmail data to third parties except to trusted processors that help operate FitCheck (such as our database host), and only as needed to provide the feature
- Human review of Gmail-derived content, if any, is limited to security, abuse prevention, compliance, or with your permission / when needed to support a request you make
Disconnect and deletion (shopping history)
You can disconnect Gmail from FitCheck. Disconnecting revokes or deletes stored OAuth credentials when possible and stops future sync. By default, previously imported shopping-history records may remain so you can still review them; FitCheck also provides a way to disconnect and delete imported history, and to remove individual incorrect records.
Other processing and third-party services
FitCheck currently relies on service providers to operate the product, including:
- Hosting / delivery (for example Vercel) for the website and APIs
- Database / storage (Supabase) for durable shopper, catalog, Try On job, and shopping- history data
- Google for optional Gmail OAuth and Gmail API access you authorize
- FASHN for optional Virtual Try On image generation
- Analytics (Vercel Analytics and, when configured, Google Analytics) for product usage metrics — not for reading Gmail contents
- Retailer websites when you follow product links (their own privacy policies apply on those sites)
Some "Shop now" links may use retailer or affiliate URLs configured in the catalog. FitCheck does not control how retailers process data after you leave FitCheck.
Security practices
FitCheck uses practical safeguards appropriate for a beta, including server-side handling of secrets, encrypted storage of Gmail OAuth tokens, shopper ownership checks on personal APIs, and restricted database access patterns. No method of transmission or storage is completely secure. We do not claim certifications (such as SOC 2) beyond what is actually implemented.
Retention
We retain profile and shopping-history data while your durable shopper record exists and the data remains useful for the features you use, or until you delete it through available product controls. Ephemeral OAuth connection state expires quickly. Try On artifacts follow the feature's storage and job lifecycle. Aggregated or de-identified product analytics may be retained longer.
Your choices
- Skip measurements and personalization
- Skip or disconnect Gmail
- Review, correct, or remove imported shopping-history records
- Clear browser site data (creates a new local identity; prior server data is not reachable without your credential)
- Contact us about access or deletion requests we cannot complete in-product yet
Children
FitCheck is intended for adults shopping for themselves. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Policy changes
We may update this policy as the beta evolves. The "Last updated" date above will change when we do. Continued use after an update means you should review the revised policy.
Contact
Questions about privacy or this policy: use Share Feedback on FitCheck, or the support contact listed on the beta page when available.
See also our Terms of Service.