Tryft Privacy Policy
Effective 23 August 2026. NomadLink SRL, Str. Ciric nr. 34, bl. X3, Iași 700334, Romania, is the data controller. Contact: admin@nomadlink.tech.
Tryft works by keeping a photograph of a person and rendering clothes onto it. Usually that is a photograph of you; the app also lets you add another adult who has agreed to it. Those photographs are the most sensitive thing here, so this policy leads with them and says what happens in plain terms.
The short version
- We keep the photographs you save — your own, and any other adult you have added with their agreement — in private storage. They are not public and have no shareable URL.
- No location data ever reaches us, because your phone re-encodes the photograph before it is uploaded. The image is decoded to pixels and written out as a new JPEG, so there is no camera or location metadata left to remove.
- A saved photograph is sent to Google's Gemini models for two things, and only these two: to generate each render, and once, when you save it, to check whether there is a person in it. We use the paid tier only, under which Google does not use your content to train its models.
- Nothing you upload is used to train any AI model— not ours, not anyone's.
- Deleting is immediate and it is yours to do. Removing a photo, a person, a Look or your whole account destroys the files then and there, not on a schedule.
- Renders have no deletion timer. They go when you delete the Look they are in, and when you delete your account. Home lists every Look that holds a render, saved or not, so any of them can be deleted. One you have reported we keep as the record of your report until you delete your account.
- The cut-out and recoloured copies we make from a garment photo have no deletion timer. They are kept while your Look needs them — see section 5.
- We never delete an account for being inactive. Your data stays until you delete it.
- You can delete everything, at any time, from Settings, or on this website without installing the app.
1. What we collect
Photographs of people
One photograph per person you save, which you take or choose. Everything else in the app depends on them. Most accounts hold one, of the account holder; the app also lets you add another adult who has agreed to it, and section 2 sets out what that rests on.
Before it leaves your device, the app decodes the image to raw pixels and re-encodes it from scratch as a new JPEG, then downscales it. We do not filter the metadata out — there is none to filter, because a re-encoded image carries nothing from the original file. What we receive has no GPS coordinates, no camera serial number and no capture timestamp. Exactly one piece of the original is read, and only so it can be applied and thrown away: the orientation flag, which is baked into the pixels so a photo taken sideways is not uploaded sideways.
We say this precisely because the usual phrasing — “we strip EXIF” — describes a weaker guarantee. Removing named tags is a list, and a list is wrong the moment a phone manufacturer writes a tag that is not on it. Re-encoding cannot miss one.
It is stored in a privatebucket in our database provider's storage, in Ireland (AWS eu-west-1). There is no public path. When the app needs to display it, it requests a signed link that expires shortly after being issued.
If you replace a photograph, the new one is stored as a new version rather than overwriting the old, so that a render already in progress finishes against the photo it started with. Section 5 says what happens to the superseded version.
Garment photographs
Photos of clothes you add — from your camera, your photo library, or shared from another app such as a marketplace listing. Stored privately, the same way, and kept, with no deletion timer: each one goes into your garment library so you can put it in another Look later. One goes when you delete it there, and when you delete your account.
To let you change a garment's colour we make two further copies from that photo: a cut-out of the garment on its own, and that cut-out in the colour you chose. Neither has a deletion timer. They are kept while your Look uses them, and deleted when you clear the colour, when you delete the Look, and when you delete your account. If you replace a garment, the copies made from the photo you replaced stop being used straight away and are deleted when you delete your account. Keeping these copies is what makes every colour after the first one free, and it is why a Look you saved still renders after the original photo it was built from has gone.
Generated images
The renders. Stored privately and shown only to you. They have no deletion timer. A render is kept while the Look it belongs to exists: it is removed when you delete that Look, and when you delete your account. A Look you have not saved does not appear on your Home screen and has no delete control of its own, so the renders in it stay until you delete your account. A render you have reported is kept as the record of what you reported, until you delete your account — deleting the Look it is in does not remove it.
Account
Tryft requires an account before it does anything. You sign in with an email address or with Google when you first open the app, and we store that email address. There is no guest mode and no anonymous session — the app cannot be used without signing in.
That is a deliberate trade and it is worth saying why, because it costs you a step at the door. An account is what makes your Looks, your credits and your photograph survive a reinstall or a change of phone. It is also what makes every body photograph on our systems belong to somebody who can prove it is theirs and ask us to destroy it — which an anonymous account, by construction, cannot.
Purchases
Credit purchases go through Google Play and our purchase provider, RevenueCat. We never see your card details. We receive confirmation that a purchase happened, so we can add the credits, and we keep a ledger of credit changes for your account so the balance is auditable and refunds work.
Usage and diagnostics
We record product events — a render started, a Look saved, the paywall shown — to understand whether the app works. We record crash reports so we can fix crashes.
No photograph, no image path, no signed link, no email address and no authentication token is ever included in an analytics event or a crash report.
What we do not collect
No location. No contacts. No advertising identifier. No browsing history. No microphone. No health data. We do not use tracking cookies, and we do not sell anything to anyone.
2. Why we are allowed to hold this
Where GDPR or a similar law applies:
| Data | Basis |
|---|---|
| Photographs and renders | Explicit consent, given when a photo is added after seeing the disclosure. Where the person in the photograph is not the account holder, the account holder confirms under the Terms that they are an adult and agreed to it |
| Your account and email address | Necessary to perform the contract — the app cannot function without an account |
| Purchases and the credit ledger | Necessary to perform the contract, and to meet accounting obligations |
| Crash reports | Legitimate interest in a working app |
| Product analytics | Legitimate interest in understanding whether the app works |
A photograph of a person is biometric-adjacent and treated as sensitive. We ask for one only after telling you, in the app and not just here, what happens to it. You can withdraw consent at any time by removing a photo or deleting your account. Removing a photo deletes it from your account and from your phone, and leaves that person on the account so you can add a new photo for them later. Other people's photos are unaffected and the app keeps using them; the app asks for a new one only once none are left. Images already rendered stay: each one goes when you delete the Look it is in, and when you delete your account. Home lists every Look holding a render, whether or not you saved it, so any of them can be deleted.
3. Who else processes it
| Who | What they do | What they get |
|---|---|---|
| Supabase | Database, storage, authentication | Your photos, renders, Looks, account row |
| Google (Gemini API) | Generates each render, and checks a newly saved photo for a person | The photograph the render is for and the garment photos, at the moment of a render; that photograph alone, once, when you save it |
| Google Play | Billing | Purchase transactions. We never receive card details |
| Google Play Integrity | Confirms the app is genuine and running on a real device, so free credits cannot be farmed by scripted installs | A device attestation token. No photographs, no email |
| RevenueCat | Purchase validation and entitlements | Your account identifier and purchase events. No photographs |
| Amplitude | Product analytics | Anonymous events. No photographs, no email, no identifiers beyond the account id |
| Sentry | Crash reporting | Crash traces. No photographs, no personal data |
They act on our instructions and may not use your data for their own purposes.
On training, specifically.Renders are generated through Google's Gemini API on the paid tier, and the person check described below runs on the same paid tier. Under Google's terms for that tier, content submitted is not used to improve Google's models. This is the only tier the app ever calls, for either purpose, and it is the reason we can make this promise in writing. We do not train any model of our own on anything.
On crash reports, specifically. Sentry offers a session-replay feature that records the screen as the user sees it. It is deliberately excluded from the app: the screen, in this app, is a photograph of your body. No screenshot and no screen recording is ever captured or sent. This is a choice we made rather than a default we inherited, which is why it is written down.
The person check. When you save a photo, it is sent once to a Google vision model which answers a single question — how many people are visible — and returns one word. It is not asked to describe anyone, their body, their age or their appearance, and it does not. The answer is used to warn you if the photo looks unlikely to render well; it never blocks you from saving the photo, and you can always keep the photo you chose. The check runs at most a small number of times per day per account.
4. Where it is stored, and transfers
Data is stored in Ireland (AWS eu-west-1). Rendering is performed by Google and may be processed outside that region. Where data leaves the UK or EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
5. How long we keep it
The design here is deliberate and it is worth stating before the table: with one exception, nothing expires on a timer. Your data goes when you delete it. That is a stronger guarantee than a retention window, not a weaker one — it means there is no schedule you have to wait for and no window you have to trust us to honour.
| What | How long |
|---|---|
| Body photos | Each one until you replace or remove it, or delete your account — all three of which delete it there and then |
| Superseded versions of a body photo | The one exception. When you replace a photo, the old version is kept until no render still refers to it, and is then collected by a clean-up job. That job is not on a schedule, so we will not promise you a window it runs within. If you want a superseded version gone now, remove the photo or delete your account and it goes with everything else, immediately |
| Garment photos | No timer. Every garment you add is kept in your garment library so you can put it in another Look later. One goes when you delete it there, or when you delete your account |
| Cut-out and recoloured copies of a garment photo | No timer. Until you clear the colour, delete the Look, or delete the account. If you replace the garment, the copies from the old photo go when you delete the account |
| Renders | No timer. Until you delete the Look they are in, or delete your account. Home lists every Look holding a render, saved or not, so any of them can be deleted |
| A render you have reported | Kept as the record of what you reported, until you delete your account — deleting the Look it is in does not remove it. Keeping that render also keeps the version of the body photo it was made from while the Look it belongs to is saved; once that Look, the photo, or the account is deleted, the photo version is removed as normal |
| Credit ledger | Kept while the account exists, then as required for accounting |
| Analytics events | Aggregated product data, no photographs |
We do not delete accounts for inactivity. There is no dormancy rule, no warning email and no expiry. Your data stays until you delete it.
6. Your rights
Access · correction · deletion · restriction · objection · portability · withdrawal of consent · complaint to a data protection authority.
You can complain to the supervisory authority where you live. Because we are established in Romania, our lead supervisory authority is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).
Deletion is built into the app rather than being a request you have to make:
- In the app: Settings → delete everything. It names exactly what is destroyed, warns you that unspent credits do not survive, and confirms only once storage is genuinely clear.
- Without the app: nomadlink.tech/tryft/delete-account.
- Just one person's photo:People → that person's card → Remove this photo. That person stays on the account, and your Looks and credits stay.
- A whole person:People → that person's card → Delete. Their photograph and their name go, so nothing new can ever be made on them again. Looks you made on them keep the pictures already made, and you can point those Looks at someone else.
- If the photograph is of you and someone else uploaded it: email admin@nomadlink.tech. You do not need an account, and we will remove the photograph and the images generated from it.
For anything else, email admin@nomadlink.tech. We respond within 30 days.
7. Security
Encrypted in transit. Private storage buckets with per-user access rules enforced by the database, so one account cannot read another's rows or files. Images are served over short-lived signed links, never public URLs. Our provider API keys are held server-side and never shipped inside the app.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as the law requires.
8. Children
Tryft is 18+. We do not knowingly collect data from anyone under 18. If we learn we have, we delete the account and its photographs. Our image provider also independently refuses images that appear to show a minor.
9. Changes
We will post changes here and, if they are material, tell you in the app before they take effect.
10. Contact
admin@nomadlink.tech · NomadLink SRL, Str. Ciric nr. 34, bl. X3, Iași 700334, Romania · Terms of Service (nomadlink.tech/tryft/terms)