Privacy Policy

Outfitly: AI Outfit Try On
Effective and last updated: July 28, 2026

TL;DR

Outfitly lets you create virtual outfit images without an account. When you request a generation, the person photo, garment photo, and generation settings you choose are sent to our AI service after you consent. Google ML Kit first checks for a person on your device. The App also uses Google AdMob for ads, Firebase Remote Config for feature settings, and Google Play Billing for optional consumable credits. We do not integrate a separate analytics, crash-reporting, messaging, or attribution SDK.

1. Who we are

This Policy explains how EXO Studio (“EXO Studio,” “we,” “us,” or “our”), Hanoi, Vietnam, processes information when you use the Android application Outfitly: AI Outfit Try On (the “App”), package com.exo.outfitly. EXO Studio is responsible for the App and acts as the controller of personal data where applicable law uses that term.

The App does not provide account creation or sign-in. We do not ask you to create a profile or provide a name, phone number, or postal address to use the App.

2. Information we process

CategoryWhat it includesHow it is used
Photos and generation inputs The person photo you select or capture, the garment photo you select, garment category, number of poses, and quality setting. Prepared on your device and transmitted only when you agree to the AI disclosure and request a try-on.
AI result data A generated result image or result URL, image format, dimensions, and a request identifier returned by the service. Displays the result, lets you save it, and helps identify a request if you choose to report a problem.
Local preferences Language, onboarding progress, style-survey choices, AI-consent choice, gallery favorite identifiers, credit balance, generation count, and SHA-256 hashes of processed purchase tokens. Operates the App, remembers choices, prevents duplicate credit grants, and controls ad frequency.
Advertising and consent data Google may process the Android advertising ID where available and permitted, IP address, device/app information, consent signals, ad requests, ad impressions, and interactions. Loads, limits, personalizes where permitted, measures, secures, and reports banner, native, interstitial, app-open, and rewarded ads.
Remote configuration data App-instance and configuration-request metadata processed by Firebase Remote Config. Retrieves settings for ads, credits, ad placement identifiers, reward amounts, and feature availability.
Purchase data Google Play product identifier, purchase state, quantity, purchase token, and related billing responses. The App stores only a one-way hash of a processed token locally. Offers and grants consumable generation credits and prevents the same purchase from being credited twice.
Support communications Your email address and message if you contact us. A report you choose to compose may include request ID, category, pose count, and result URL. Responds to feedback, support requests, privacy requests, and generation reports.

We do not receive your full payment-card details; Google Play processes payment. The App does not request contacts or precise-location permission. It uses face detection only to check whether a selected image contains a person; it does not identify who the person is or create a face-recognition profile.

3. On-device and cloud processing

On your device

The App uses Google ML Kit pose detection, image labeling, and face detection to check whether a selected image contains a person. This check runs against the local image before generation. The App also resizes the selected images to a maximum dimension of 1280 pixels and corrects image orientation in local cache.

Preferences and credits are kept in Android app storage. Generated results are held in memory for display and are saved to the device gallery only when you choose Save. Photos that you explicitly save remain in your gallery until you delete them.

Sent for AI generation

After you select “Agree & continue” and request a generation, the App sends the person image, garment image, garment category, pose count, quality setting, application identifier, and authenticated request metadata to EXO Studio's try-on API hosted at a Modal endpoint. The in-App disclosure identifies OpenAI as the AI provider. The service returns the generated result and request metadata.

The App does not upload your whole photo library. It transmits only the specific person and garment images you choose for a generation.

4. Purposes and legal bases

PurposeTypical legal basis where required
Provide the AI try-on you requestYour affirmative consent for photo transmission and performance of the requested service.
Operate local preferences, credits, favorites, and generation history countersPerformance of the service and our legitimate interest in providing a reliable App.
Show and measure ads, including rewarded adsConsent where required; otherwise our legitimate interest in funding and securing the App, subject to your rights.
Process optional Google Play purchasesPerformance of the purchase contract and compliance with legal obligations.
Prevent duplicate credit grants, fraud, abuse, and security incidentsOur legitimate interests in protecting users, the App, and our services.
Respond to support and privacy requestsOur legitimate interests and compliance with legal obligations.

5. Service providers

Verified integrations in the App include:

These providers process information under their own terms and privacy policies. Their processing may include service diagnostics, security, fraud prevention, and compliance activities.

6. Sharing, sale, and targeted ads

We disclose information to service providers only for the functions described above, when you direct us to do so, to protect rights and safety, or when required by law. We do not sell your photos or personal information for money.

AdMob's use of device identifiers and ad activity for personalized or targeted advertising may be treated as “sharing,” “sale,” or targeted advertising under some US state laws. Where required, Google's consent message lets you make applicable choices before ads are requested. You can also reset or delete your advertising ID through Android settings and contact us to exercise an applicable opt-out right.

If ownership of the App or relevant business assets changes, information may be transferred as part of that transaction subject to this Policy and applicable law.

7. Retention

8. Security

We use safeguards appropriate to the nature of the information, including Android app sandboxing, HTTPS service endpoints, restricted API requests, local hashing of processed purchase tokens, and limited transmission of selected images. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

9. Device permissions

You can deny or revoke optional permissions in Android settings. Some features, such as taking a new photo, will not work without the relevant permission.

10. Children's privacy

The App is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If local law requires a higher age for independent consent, a parent or guardian should supervise use. If you believe a child has provided personal information, contact us so we can review and take appropriate action.

11. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data; withdraw consent; opt out of targeted advertising, sale, or sharing; and lodge a complaint with a data-protection authority. We will not discriminate against you for exercising applicable rights.

Because the App has no account, include enough detail for us to locate relevant server or support records, such as a request ID or the email address you used to contact us. Do not send a copy of your photo unless we specifically request it for verification. You can clear local App data in Android settings, uninstall the App, delete saved gallery images, and manage the advertising ID in Android settings.

To submit a request, email exostudio.feedback@gmail.com. We may need to verify the request and may retain information where law permits or requires it.

12. International transfers

EXO Studio is based in Vietnam. Our providers may process information in Vietnam, the United States, and other countries where they operate. Those countries may have different data-protection laws. Where required, we and our providers use legally recognized transfer mechanisms and safeguards.

13. Changes to this Policy

We may update this Policy to reflect changes to the App, providers, law, or our practices. We will update the date at the top and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.

14. Contact us

EXO Studio
Hanoi, Vietnam
Email: exostudio.feedback@gmail.com