Skip to content

Privacy policy

Last updated:

Pryzmo is a virtual try-on: a shopper on an online store uploads a photo of themselves and, within seconds, receives an image of themselves wearing that garment, along with a size recommendation. That photo is sensitive personal data, and we treat it as such.

This policy explains what data we process, why, who we share it with, and how long we keep it. It covers pryzmo.ai —including the demo try-on we offer there—, the merchant panel (app.pryzmo.ai), the try-on experience that opens inside stores (try.pryzmo.ai), and the Pryzmo app for Tiendanube/Nuvemshop.

In this document, "Pryzmo" and "we" refer to the controller of the data described here. For any privacy question, or to exercise your rights, write to soporte@pryzmo.ai.

The essentials, in five points

  • The shopper's photo is deleted. It is removed when the try-on session closes or, at the latest, after 24 hours. We do not use it to train models, and we do not sell it to anyone.
  • The generated image is not kept either. It lives exactly as long as the photo and is deleted with it. We record that a try-on happened, not the image.
  • We never publish the photo at an open URL. It travels encrypted and only over authenticated channels, including on its way to the provider that generates the image.
  • The three people involved are treated differently: the shopper trying a garment on, the merchant using the panel, and the visitor browsing pryzmo.ai.
  • pryzmo.ai uses measurement to improve the site and evaluate campaigns. Forms and anything you type are never sent to those tools; the merchant panel and try-on remain outside this tracking.

1. Who this applies to

We process data belonging to three groups of people, and what we do with each is very different:

  • Shoppers: people who use the virtual try-on inside a merchant's online store.
  • Merchants: people who create an account in the Pryzmo panel to install and configure the product on their store.
  • Visitors: people who browse pryzmo.ai, fill in the contact form, book a meeting, or try the site's demo try-on.

When a shopper uses the try-on inside a merchant's store, the store decides to offer the service and Pryzmo operates it. Each party answers for its own part: the merchant for its relationship with the shopper and for its catalog information, Pryzmo for the technical processing described in this policy.

2. Shoppers: the photo and the generated image

What we process

  • The photo you upload. It is the only image of you we receive, and it exists only because you uploaded it.
  • The generated image, produced from that photo and from the merchant's garment image.
  • Size form data, if the merchant has enabled it (height and body type, for example). You enter it yourself, and it is used only to compute that session's recommendation.
  • A random device identifier, generated by us and stored in your browser's local storage. It is not a device fingerprint and we use no fingerprinting libraries: it is a random number you can remove by clearing site data. It exists to limit abusive use of the service.
  • Technical security signals: the store origin, the product, and a network reference derived from the IP address. Before storage, our servers transform the device identifier and network reference into pseudonymous HMAC codes; we do not keep the raw IP or identifier in the anti-abuse ledger.
  • Usage events with no image content: that a try-on started, that it finished, that the result was downloaded, or that the add-to-cart button was tapped, with the date and the product involved.

Purpose and legal basis

The photo is processed with your consent, given when you upload it: the notice is shown before you pick a file, and the upload button implies acceptance. There is a single purpose —generating your image wearing the garment and, where applicable, the size recommendation— and we use it for nothing else. You can withdraw consent by closing the try-on session, which deletes the photo immediately.

Usage events are processed under our legitimate interest in measuring whether the product works and in preventing abuse of the service. They contain neither your photo, nor your result, nor data identifying you.

How long it lasts

  • Photo and generated image: 24 hours at most. They are deleted earlier if you close the try-on session, which is what normally happens. An automated hourly routine removes anything expired, so in practice nothing survives more than 25 hours.
  • Size recommendation: it lives inside the session and is discarded with it.
  • Usage events: kept as aggregate statistics. The associated device identifier is automatically anonymized after 30 days.
  • Anti-abuse records: pseudonymous codes, single-use authorizations, and technical counters are deleted within 48 hours.

How we protect it

  • The photo and the result are stored in a private, encrypted bucket (AES-256 at rest, TLS in transit). They are not publicly accessible.
  • The result is delivered through a signed link that expires after 120 seconds. If that link leaked, it stops working almost immediately.
  • Your browser never talks directly to the image generation provider. Everything goes through Pryzmo's servers, and the photo reaches the provider via an authenticated upload, never a public address.
  • Shopper data is hosted in São Paulo, Brazil.
  • There is a cap of 3 try-ons per session, plus hourly and daily limits for the same device and store. We also use network and concurrency limits so clearing browser storage does not remove every control.

What we do not do

  • We do not use your photo or your generated image to train artificial intelligence models.
  • We do not keep the generated image for metrics, demos, or marketing material.
  • We do not sell or hand over your images to third parties for advertising purposes.
  • We do not ask for your name, email, or phone number to use the try-on.

If we ever wanted to retain images to improve service quality, that would be a separate, optional purpose with its own explicit consent.

Automated content screening

To prevent prohibited uses —sexual content, nudity, or images of minors— the provider that generates the image applies an automated safety filter to both input and output. It is a technical control, always on, that we cannot disable. If the filter rejects an image, generation fails and the try-on shows an error; no other decision is made about you, and the rejected image is not retained.

Every generated image carries a watermark indicating it was created with artificial intelligence.

3. Merchants: account and store

If you create an account in the Pryzmo panel, we process:

  • Identity data: first name, last name, and email. Supabase Auth manages email verification and access credentials. If you choose a password, Pryzmo cannot read or recover it.
  • Optional profile data: job title, phone, and website, if you choose to provide them.
  • Google identity, if you sign in that way: Google and Supabase process authentication and linking by verified email. Pryzmo receives the confirmed identity and necessary profile data, but does not retain long-lived Google credentials.
  • Your store's data, obtained through the authorization you grant when installing the app: store identifier, language and currency, and the catalog information (products, variants, and images) the try-on needs to work.
  • Integration authorization: the credential Tiendanube/Nuvemshop provides to operate your store remains only on our servers, protected with authenticated application-layer encryption and rotatable encryption keys. It is not sent to the browser or to our diagnostic systems.
  • Panel session: technical tokens managed by Supabase Auth and kept in your browser's local storage to maintain access and renew the session.

The legal basis is performance of the service you sign up for. We keep this data while your account is active.

Uninstalling the app from a store deletes that store's data —including garment images and all associated configuration— but your account and your other stores remain. Deleting your account is a separate request you can send us at soporte@pryzmo.ai.

Tiendanube/Nuvemshop may also send us mandatory privacy requests. If it asks us to redact a store, we apply the same complete deletion. If it asks us to redact a customer's data, we delete only the attributions for the order IDs supplied by Tiendanube/Nuvemshop; we do not search for or delete sessions using approximate matches. If it requests access to data, we search only those identifiers and send the report directly to the merchant's verified email. We do not retain the customer name, email, phone number, or identification received in those notifications.

A pending report is encrypted in our email outbox. We delete it as soon as the provider accepts delivery; if it remains blocked or fails permanently, its content is deleted automatically after 30 days.

4. Visitors to pryzmo.ai

Contact form

When you write to us through the form, we process the name, email, store URL, and message you leave, along with attribution data (UTM parameters, the site you came from, and the landing page). The purpose is to reply to you; the legal basis is your prior request for contact.

The box to receive news by email is optional and never pre-checked. We record consent only if you tick it yourself, together with the version of the text you accepted. Submitting the form without ticking it subscribes you to nothing, and booking a meeting neither grants nor revokes that consent.

Meetings

Meetings are booked through Cal.com, which acts as a provider and processes your name, email, and chosen time under its own policy. From its notification we store only a booking identifier, the times, the language, and the attribution; we explicitly discard the notification body, the headers, the notes, the reason for a cancellation, and the video call address.

WhatsApp

If you start a conversation over WhatsApp, that exchange is also governed by Meta's policies, as the operator of the service.

Demo try-on

On pryzmo.ai you can try the virtual fitting room without installing anything: you pick a garment from a fictional store, upload a photo of yourself and see the result. The generation is real and your photo is treated exactly like a shopper's, with the same consent on upload, the same encryption, the same 120-second signed link and the same deletion windows described in section 2. The try-on is not linked to any store or account.

To keep the demo from being abused by automated traffic we use Cloudflare Turnstile and a random device identifier stored in your browser's local storage, together with a network reference derived from your IP address. The last two are stored pseudonymised with HMAC and deleted within 48 hours; they exist only to enforce a per-person, per-day try-on limit.

Retention

  • Contact with no account and no activity: up to 24 months.
  • The commercial message you left us: up to 90 days.
  • Demo try-on photo and result: the windows in section 2 (24 hours at most, usually less).
  • With an account created: the account policy in the previous section applies.

5. Cookies and similar technologies

On pryzmo.ai only, the following technologies are always active so we can understand how the site is used, improve the commercial journey, and measure campaigns:

  • Vercel Web Analytics counts page views and aggregate events without cookies.
  • Vercel Speed Insights measures real page performance (Core Web Vitals) anonymously and without cookies: it records the route, device type, browser, operating system, network speed, and country, without making it possible to reconstruct your browsing.
  • Google Tag Manager loads the approved tags and does not create cookies by itself.
  • Google Analytics 4 measures navigation and conversions. Its _ga and _ga_* cookies may last up to two years unless you delete them. They are configured for the pryzmo.ai host and are therefore not sent to its subdomains.
  • Microsoft Clarity creates interaction metrics, heat maps, and session replays. It may use _clck for up to one year and _clsk for up to one day. Form fields, the contact form, and its confirmation are explicitly masked.
  • Meta Pixel measures campaign performance and may use _fbp and, when you arrive from an ad, _fbc, for up to three months.

Through Pryzmo's integration, these tools receive the sanitized visited path, language, interaction type, technical browser data, and permitted campaign parameters (utm_*, gclid, gbraid, wbraid, and fbclid). Pryzmo does not add names, email addresses, phone numbers, messages, store URLs, submission identifiers, Cal.com content, or credentials to the current URL, events, or their properties. Vercel Web Analytics, Microsoft Clarity, and Meta Pixel may also process the browser's native technical referrer; that value can contain the previous page's path or parameters and Pryzmo cannot rewrite it. A form is recorded as a lead only after our servers confirm it was stored; anything you type travels exclusively to the contact system.

This processing relies on our legitimate interest in measuring and improving pryzmo.ai and evaluating our campaigns. We do not display a consent banner or provide our own control to disable these tools. You can delete or block cookies in your browser; doing so may limit measurement but does not prevent you from using the site or contacting us.

Separately, we use Sentry on pryzmo.ai, app.pryzmo.ai, try.pryzmo.ai, and the API to detect and diagnose failures. We send 100% of errors and a 10% sample of performance traces, including the technical stack, error class, release, random technical trace identifiers, normalized route, HTTP method and status, duration, and browser, operating system, or runtime data. We do not include cookies, users, headers, bodies, URL parameters or full page or request URLs, local variables, messages, photos, tokens, or credentials in events; storage of IP addresses is also disabled. We do not enable Sentry session replay, screenshots, or logs. Events are hosted in the European region and retained for no more than 90 days. This processing relies on our legitimate interest in keeping the service secure and operational.

The virtual try-on uses browser local storage for the random device identifier described in section 2. The merchant panel uses local storage for the technical tokens managed by Supabase Auth.

The functional pryzmo_locale cookie remembers your chosen language for one year. The virtual try-on uses local storage for the random identifier described in section 2, and the merchant panel uses local storage for Supabase Auth tokens. app.pryzmo.ai and try.pryzmo.ai, including sign-in and sign-up screens, do not load Google Analytics, Clarity, Meta Pixel, or the pryzmo.ai measurement container.

The try-on uses Cloudflare Turnstile as a security check before every generation. Cloudflare processes the challenge and technical browser and network signals to distinguish automated traffic; Pryzmo receives a verification token, not an advertising identity, and does not use this control for marketing. See the Turnstile Privacy Addendum for more information.

6. Who we share data with

We do not sell personal data. We share it only with providers that supply a service we need in order to operate, under contract and instructed to process it solely for that purpose:

  • Pruna AI — generates the try-on image. Receives the shopper's photo and the garment image via authenticated upload. It may run the model on its own infrastructure providers.
  • Cloudflare — operates Turnstile to prevent automated abuse of the try-on and processes the technical signals needed to verify the challenge.
  • Supabase — merchant account authentication, sessions, database, and file storage, in our project in the São Paulo region.
  • Fly.io — servers for the API and the merchant panel, in the São Paulo region.
  • Vercel — hosting for the pryzmo.ai site and aggregate, cookieless web and performance analytics.
  • Sentry — technical error and performance diagnostics for the site, dashboard, try-on, and API in the European Union. It receives stacks, release, runtime, and sanitized routes or operations; it does not store IP addresses or derived geolocation, and we discard user, request, message, and free-form URL data before each event is persisted.
  • Google — optional merchant authentication and, on pryzmo.ai only, Tag Manager and Google Analytics 4. For authentication, we receive only the basic data needed to identify and link the account; we do not request access to Gmail, Drive, Calendar, contacts, or files.
  • Microsoft — Microsoft Clarity, on pryzmo.ai only, for interaction and session metrics with forms masked.
  • Meta — campaign measurement through Meta Pixel on pryzmo.ai only, and WhatsApp when you choose to start a conversation.
  • Tiendanube/Nuvemshop — the e-commerce platform where the merchant's store runs and from which we obtain authorized catalog information.
  • Cal.com — meeting scheduling.
  • Resend — transactional email delivery, including authentication messages Supabase sends through our dedicated SMTP and Pryzmo operational notices.

We may also disclose data where a competent authority legally requires it.

International transfers

Shopper data and the main database are hosted in Brazil. Some of the providers listed operate infrastructure outside Argentina and Brazil, mainly in the United States and the European Union. In those cases the transfer relies on the consent you give and on the contractual clauses agreed with each provider.

7. Your rights

You can ask us at any time to:

  • access the personal data we hold about you;
  • correct anything incomplete or out of date;
  • delete it;
  • obtain a copy in a readable format;
  • object to a processing activity or withdraw a consent you gave, without affecting what was done before the withdrawal.

Write to soporte@pryzmo.ai from the address linked to your account, or telling us how we can verify your identity. We respond within 15 calendar days of being able to verify it.

If you are a shopper, note that your photo has probably already been deleted by the time you write: maximum retention is 24 hours.

We process data belonging to people in Argentina and Brazil, and we align our practices with Argentina's Personal Data Protection Act 25.326 and with Brazil's Lei Geral de Proteção de Dados (Law 13.709). If you believe we handled your request poorly, you can complain to the data protection authority in your country —the Agencia de Acceso a la Información Pública in Argentina, the Autoridade Nacional de Proteção de Dados in Brazil.

8. Minors

Pryzmo is not directed at people under 18, who should not use the virtual try-on. We do not ask for the shopper's age, so we cannot verify it; the automated content filter described in section 2 is the technical control we apply.

If you are a parent or guardian and believe a minor in your care uploaded a photo, write to soporte@pryzmo.ai and we will delete it along with the entire associated session. Given the 24-hour retention window, it has most likely been deleted already.

9. Security

We apply encryption in transit and at rest, private file buckets with no public access, authenticated application-layer encryption for integration credentials, and rotatable encryption keys kept as server secrets. Shopper-session bearer values are not stored reversibly: we retain only their SHA-256 hash to verify later requests. We also use sessions managed and revocable through Supabase Auth, data isolation between merchants verified on every request, and the rule that no photo, email address, message, or credential is ever written to our diagnostic systems.

No system is infallible. Should a security incident affect your personal data, we will notify the people affected and the relevant authority as required by applicable law.

10. Changes to this policy

If we change this policy, we will publish the new version on this same page and update the date in the header. When the change is substantial —a new purpose, a new provider, or a longer retention period— we will notify merchants with an active account by email before it takes effect.

11. Contact

For privacy questions, to exercise your rights, or for anything else about this document: soporte@pryzmo.ai.