Effective August 7, 2026 · Last updated September 14, 2026
Your permission before AI processing
We ask for your explicit permission in the app before sending personal data to the AI providers named in the disclosure. Photo ownership permission, accepting our terms, or reading this policy does not grant AI processing permission. We record the disclosure version and your choice on your account. Declining leaves non-AI features available.
What is sent to AI providers
The photos you select (including visible faces and any crops), your prompts and refinement notes, styling choices such as presentation and region, generated images and image analysis, and an internal account identifier for abuse prevention.
How and why AI data is collected
We collect images you intentionally choose using the photo picker or camera and text and styling preferences you enter or select. We derive image observations and generated results while fulfilling your request. Anthropic, or Anthropic/Google through OpenRouter, analyzes photos and creates styling directions, Style DNA, garment analysis and look sheets. OpenAI checks safety and creates or refines fashion images and model figures.
Third-party protection
We require providers receiving personal data to provide the same or equal protection required by this policy: limited-purpose processing, confidentiality, appropriate security, restricted access and applicable deletion and transfer safeguards. Anthropic handles text and image analysis; OpenRouter routes fallback analysis to Anthropic or Google. OpenAI continues to handle image generation and moderation, and analysis for accounts that have only accepted the earlier OpenAI-only disclosure. Processing is subject to the applicable provider terms and data-processing protections. Provider details: https://privacy.claude.com/ ; https://openrouter.ai/privacy ; https://ai.google.dev/gemini-api/terms ; https://openai.com/policies/data-processing-addendum/
Provider retention and training
We use commercial API services and request providers that do not collect OpenRouter requests for training. Provider abuse-monitoring and legal retention rules still apply; this is not a promise of zero retention. See our privacy policy for provider details. Fashy does not opt your content into model training and disables optional Responses API storage. Retention depends on the provider, feature and applicable safety or legal requirements. See https://developers.openai.com/api/docs/guides/your-data
Withdraw AI permission
Choose Not now to continue without AI. You can withdraw permission in Settings → AI data sharing. This stops new AI requests; work you already requested may finish and data already sent cannot be recalled. To delete source photos, concepts or your account, use the separate deletion controls. Contact [email protected] about data already processed or applicable access and deletion rights.
Who we are
Fashy is an AI fashion concept, social discovery, and curated-designer service operated by Nyza Creations LLC (“Fashy,” “we,” “us”), a Washington limited liability company. Postal address: 3850 Kitsap Wy, Ste 104 PMB 1247, Bremerton, WA 98312, USA. This policy covers fashy.ai and the Fashy iOS and Android apps. For privacy requests write to [email protected]; for anything else, [email protected].
Information we collect
- Account details such as name, username, email address, sign-in provider identifiers, profile information, and support communications.
- Photos you upload, the prompts and style selections you provide, AI concepts produced for you, closet content, posts, comments, likes, reports, and account blocks.
- Designer applications, portfolios, quote briefs, messages, measurements you choose to provide, shipping details, production updates, and dispute information.
- Transaction and entitlement records. Payment card details are processed by Stripe, Apple, or Google and are not stored by Fashy.
- Technical data such as IP address, device and app information, logs, security events, approximate location derived from network data, and cookie or analytics data where allowed.
How we use information
- Provide authentication, private media, AI generation, credits, feeds, closets, designer matching, quotes, orders, shipping updates, support, and account controls.
- Run safety checks, prevent fraud and abuse, investigate reports, enforce our terms, secure the service, and meet legal obligations.
- Send transactional messages and, only where permitted, product communications you can opt out of.
- Improve reliability and product quality using minimized or aggregated information. We do not claim ownership of your source photos, we do not sell them, and we do not use them to train public AI models.
AI processing and service providers
After you accept the current AI disclosure, your selected photos and instructions are sent to Anthropic (Claude) for text and image analysis, with Anthropic or Google through OpenRouter as fallbacks. OpenAI handles image generation and moderation. Older OpenAI-only consent continues to use OpenAI until you accept the updated disclosure. Hosting, storage, email, analytics, authentication, fraud prevention, payments, and delivery providers process information under their own terms and our service arrangements. Do not upload an image unless you have the right and consent to use it.
- Anthropic for text and image analysis; OpenRouter as a routing service to Anthropic and Google when needed. We request routes that prohibit provider data collection for training. Provider security, abuse-monitoring and legal retention rules still apply.
- OpenAI for AI image generation and safety processing, and the older-consent text/analysis path.
- OVHcloud for application hosting and Google Cloud Storage for private media storage and delivery. Cloudinary is used only to manage deletion of legacy media where present.
- Stripe for web payments and physical-goods checkout; Apple and Google for in-app digital purchases.
- Nyza Mail, our own email platform operated by Nyza Creations LLC, which uses Amazon Web Services (SES) to deliver outbound email and Cloudflare Email Routing to receive support email.
Visibility and retention
Source photos and generations are private by default. A generated concept becomes public only when you explicitly publish it. When you publish, you may also choose to show the source photo the concept was made from; that choice is off unless you turn it on, the photo passes our safety checks first, and removing it from the post, unpublishing, or deleting the photo, the concept or your account stops it being shown right away. Public posts may be copied or shared by others before deletion. We retain data while your account is active and as needed for the service, fraud prevention, disputes, tax, accounting, and legal obligations. Deleted media may remain briefly in backups before scheduled expiry.
Your choices and rights
- Delete individual photos or concepts, unpublish content, block users, or request full account deletion.
- Access, correct, export, restrict, or object to eligible processing, depending on your location.
- Withdraw optional consent without affecting processing already performed.
- Appeal a moderation decision by contacting support.
Children and sensitive data
Fashy is not directed to children under 13, or the higher minimum age required where you live. Do not upload sexualized images of minors. Measurements and photos can be sensitive; provide only what is necessary and never post private measurements publicly.
Security, transfers, and changes
We use access controls, authenticated private media, encryption in transit, and operational safeguards, but no system is perfectly secure. Information may be processed in countries other than yours with applicable transfer safeguards. We will post material policy changes and provide notice where required.
Regional rights and how to exercise them
- European Economic Area, United Kingdom and Switzerland: you may access, rectify, erase, restrict, port, or object to processing of your personal data, and may lodge a complaint with your supervisory authority. Our legal bases are contract (providing the service you asked for), legitimate interests (security, fraud prevention, product improvement), consent (third-party AI processing and optional communications), and legal obligation.
- California and other U.S. states: you may request access to, deletion of, or correction of your personal information and will not be discriminated against for doing so. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of.
- Every request: email [email protected] from the account address, or use the in-app deletion controls, which act immediately. We may ask for reasonable verification, respond within the period the applicable law sets, and you may use an authorised agent where the law allows.