Privacy Policy

Aglaia — AI Virtual Try-On for Shopify · Last updated: September 13, 2026 (email capture added)

Aglaia (“Aglaia”, “we”, “us”) provides an AI virtual try-on app that merchants install on their Shopify store. A shopper uploads a photo of themselves on a product page and the app generates a preview of that shopper wearing the merchant’s product.

This policy explains what we collect, why, how long we keep it, and how to have it deleted. It applies to merchants who install Aglaia and to shoppers who use the try-on feature on a merchant’s storefront.

Roles. For shopper photos and try-on images, the merchant operating the store is the data controller and Aglaia acts as a processor on that merchant’s behalf. For merchant account, billing, and support data, Aglaia is the controller.

1. Information we collect

From merchants

From shoppers

What we do not collect. Aglaia does not require shoppers to create an account and does not link try-ons to a Shopify customer record — we do not store shopper names, emails, addresses, order history, or payment information. We do not run facial recognition, build face templates, or attempt to identify anyone from an uploaded photo. We do not sell personal information and we do not share it for cross-context behavioural advertising.

2. How AI processing works

To create a preview, the shopper’s photo and the merchant’s product images are sent to Google’s Gemini image models via the Google Gemini API. A lightweight vision check first confirms the photo is usable for apparel try-on (for example, that it is not a face-only crop); the image model then produces the try-on result, which is returned to the storefront and stored so it can be shown again to the shopper and in the merchant’s admin.

Photos and generated images are used only to produce and display that try-on result. They are not used to train Aglaia’s or any third party’s AI models, and they are not sold or shared for advertising.

AI-generated previews are approximations of fit and appearance, not exact representations of the product on the shopper.

3. Why we process this information

Where GDPR/UK GDPR applies, our legal bases are consent (shopper photos, collected by the merchant through the in-app consent notice), contract (providing the app to merchants), and legitimate interests (security, abuse prevention, service improvement).

4. Retention and deletion

Shopper photos and generated images are stored in private, access-controlled object storage and are automatically deleted by a scheduled purge job.

DataRetention
Shopper photo and generated try-on imageDeleted automatically after the merchant’s configured retention window — 24 hours by default, adjustable by the merchant in the app’s Settings.
A try-on a merchant has flagged as a bad result for supportHeld past the normal window so we can investigate, then deleted once the issue is resolved.
Try-on record without images (status, product, timestamps, counts)Kept for the merchant’s analytics for as long as the app is installed.
A shopper email captured by a merchant’s email captureNot covered by the photo retention window above. Kept until the merchant deletes it, the shopper asks for it to be erased, or the app is uninstalled and the store’s data is purged. Merchants can delete any individual address from the app’s Leads screen.
Merchant account, settings, and session dataKept while the app is installed. Sessions are deleted on uninstall; the remaining store data is erased when Shopify sends the shop/redact request (about 48 hours after uninstall).

We support Shopify’s mandatory privacy webhooks — customers/data_request, customers/redact, and shop/redact. Try-ons themselves are never linked to a Shopify customer record, so there is nothing customer-identified to report or erase from them. Where a merchant has captured an email, customers/redact deletes that address from our database and customers/data_request compiles what we hold for it. shop/redact deletes the store’s records entirely, including every captured address.

5. Who we share information with

We share information only with the service providers needed to run the app, and only for that purpose:

We may also disclose information where required by law, to enforce our terms, or to protect the rights and safety of users. If Aglaia is involved in a merger or acquisition, data may transfer as part of that transaction, subject to this policy.

Email addresses and marketing consent

An email a shopper gives on a store’s try-on belongs to that merchant — they are the data controller for it and Aglaia only processes it on their behalf. Marketing consent is single opt-in: the box is unticked by default, we record the exact wording shown at the moment it was ticked, and an address that was never opted in is never added to the merchant’s Shopify customers. Unsubscribing is handled through the merchant’s own Shopify or email tooling, not through Aglaia. We never sell these addresses and never share them with anyone besides the merchant who collected them.

6. International transfers

Our providers operate in the United States and other regions, so information may be processed outside your country. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. Security

Data is encrypted in transit (TLS). Images are stored in a private bucket that is not publicly listable and is served only through an authenticated application route. Access tokens and credentials are held as environment secrets, and access to production data is limited to personnel who need it. No system is perfectly secure, but we work to protect your data and will notify affected merchants of a breach as required by law.

8. Children

Aglaia is not directed to children. Shoppers should not upload photos of anyone under 16 (or the minimum age in their jurisdiction). If we learn we have received such a photo, we will delete it.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to withdraw consent, to object to or restrict processing, and to be free from discrimination for exercising these rights.

We respond to verified requests within the timeframes required by applicable law (generally 30 days). EU/UK users may also complain to their local data protection authority.

10. Changes to this policy

We may update this policy as the app evolves. The “Last updated” date above will change, and we will notify merchants in-app of material changes.

11. Contact

Questions, data requests, or privacy concerns: futurelabsin.