1. Introduction
GT Atlas LLC ("Company," "we," "us") operates the Snapics.ai website and platform. We are committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding that data. It applies to all users of the Snapics.ai platform, including the website, application, and APIs.
By using Snapics.ai, you consent to the practices described in this policy. If you do not agree, please do not use the Service.
2. Data Controller
The data controller responsible for your personal data is GT Atlas LLC, operating under the brand name Snapics.ai. For any data-related inquiries, contact our Data Protection team at privacy@snapics.ai.
3. Information We Collect
3.1 Account Information
When you create an account, we collect:
- Email address — for authentication, communication, and account recovery.
- Display name — optional, for personalization.
- Profile picture — provided via your authentication provider (Clerk/Google/GitHub).
Authentication is handled by Clerk. We do not store passwords directly.
3.2 Payment Information
All payment processing is handled by Stripe. We never store, see, or have access to your full credit card number, CVV, or banking details. Stripe provides us with:
- Billing name and email.
- Last four digits of the card (for receipt display).
- Transaction IDs and subscription status.
- Country of the payment method (for tax purposes).
3.3 Uploaded Images
When you use the Service, you upload images for AI processing. These images are:
- Stored securely on Cloudflare R2 (encrypted at rest).
- Transmitted to AI processing providers (FAL.ai, Replicate, Google Gemini) solely for the purpose of generating your virtual try-on results.
- Never used to train, fine-tune, or improve AI models.
- Never shared with third parties for marketing, advertising, or any purpose other than service delivery.
3.4 Usage Data
We automatically collect:
- Pages visited, features used, and actions taken within the app.
- Device type, browser type, operating system, and screen resolution.
- IP address (for security, rate limiting, and approximate geolocation).
- Referring URL and session duration.
This data is collected via essential cookies and, with your consent, analytics cookies. See our Cookie Policy for details.
3.5 Support Communications
If you contact us via email or an in-app support channel, we retain the correspondence (including any attachments) to resolve your inquiry and improve our support quality.
4. How We Use Your Information
We use personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the Service (image processing, storage) | Performance of contract |
| Processing payments and managing subscriptions | Performance of contract |
| Sending transactional emails (receipts, account alerts) | Performance of contract |
| Security, fraud prevention, and abuse detection | Legitimate interest |
| Product analytics and service improvement | Legitimate interest / Consent |
| Marketing communications (opt-in only) | Consent |
5. Image Data — How We Handle Your Images
Key Commitment: We take the security and privacy of your images extremely seriously. You retain full ownership of all images you upload and all processed outputs. We do not use your images to train, fine-tune, or benchmark any AI model. Period.
- Ownership: You retain full ownership of all images you upload and all processed outputs.
- No AI Training: We do not use your images to train, fine-tune, or benchmark any AI model. Period.
- Encryption: Images are encrypted at rest on Cloudflare R2 and in transit via TLS/HTTPS.
- Access Control: Only your authenticated account can access your images. Presigned URLs with short expiry times are used for secure delivery.
- AI Provider Transmission: When you submit a processing job, your image is securely transmitted to the selected AI provider (FAL.ai, Replicate, or Google). These providers process the image in memory and return the result. We do not control the provider's internal data handling but select providers with strong privacy commitments.
- Deletion: When you delete an image from your account, both the original upload and all processed versions are permanently deleted from our storage within 24 hours. Upon account deletion, all images are removed within 30 days.
6. Marketplace & Affiliate Data
Snapics.ai operates a fashion marketplace with affiliate links to external retailers. In connection with this marketplace, we collect and process the following data:
- Product browsing data: We record which products and categories you view on our marketplace to improve recommendations and user experience.
- Affiliate click data: When you click a "Buy Now" button, we log the click (product ID, timestamp, and page source). We do not receive your purchase details, payment information, or order history from the retailer.
- Virtual try-on data: When you use the AI virtual try-on feature, your uploaded photos are processed by our AI partners (FAL.ai, Replicate) to generate try-on results. Photos are processed in real-time and are not permanently stored by our AI providers.
- Cookies from affiliate networks: When you click through to a retailer, their affiliate tracking system may place cookies on your device. These cookies are governed by the retailer's own privacy and cookie policies. See our Cookie Policy for details.
6. Third-Party Services & Data Processors
We share personal data only with the following categories of service providers, each acting as a data processor under our instruction:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication & identity | Email, name, OAuth tokens |
| Stripe | Payment processing | Billing info, transaction data |
| Cloudflare R2 | Image storage | Uploaded & processed images |
| FAL.ai | AI virtual try-on | Images (for try-on generation only) |
| Replicate | AI virtual try-on | Images (for try-on generation only) |
| Google (Gemini) | AI virtual try-on | Images (for try-on generation only) |
| Amazon Associates | Affiliate tracking | Click data (anonymized) |
| Awin | Affiliate tracking | Click data (anonymized) |
We do not sell, rent, or trade your personal data to any third party for marketing, advertising, or data brokerage purposes.
7. Data Retention
- Account data: Retained for the lifetime of your account plus 30 days after deletion.
- Images: Retained until you delete them or close your account. Permanently purged within 30 days of account closure.
- Payment records: Retained for 7 years to comply with tax and accounting regulations.
- Server logs: Automatically rotated and deleted after 90 days.
- Support correspondence: Retained for 2 years after the last interaction.
8. International Data Transfers
GT Atlas LLC operates Snapics.ai globally. Your data may be processed in the United States and other countries where our service providers operate. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) with our processors.
- Adequacy decisions by the European Commission where applicable.
- The EU-US Data Privacy Framework (where certified).
9. Data Security
We implement industry-standard security measures to protect your data, including:
- TLS 1.3 encryption for all data in transit.
- AES-256 encryption at rest for stored images (Cloudflare R2).
- Access control via authenticated sessions with short-lived tokens.
- Presigned URLs with time-limited expiry for image delivery.
- Rate limiting and abuse detection on all API endpoints.
- Regular security reviews and dependency audits.
While we take every reasonable precaution, no system is 100% secure. If you discover a vulnerability, please report it responsibly to security@snapics.ai.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
10.1 All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and all associated data.
- Data Portability: Request your data in a structured, machine-readable format.
10.2 EEA/UK Residents (GDPR)
- Right to Object: Object to processing based on legitimate interest.
- Right to Restrict Processing: Request limitation of processing in certain circumstances.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time (without affecting prior processing).
- Right to Complain: Lodge a complaint with your local Data Protection Authority.
10.3 California Residents (CCPA)
- Right to know what personal information is collected and how it is used.
- Right to delete personal information.
- Right to opt out of the "sale" of personal information (we do not sell personal data).
- Right to non-discrimination for exercising your privacy rights.
To exercise any of these rights, contact us at privacy@snapics.ai. We will respond within 30 days (or sooner where required by law).
11. Children's Privacy
Snapics.ai is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, contact us at privacy@snapics.ai.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or an in-app notification at least 30 days before the new policy takes effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
13. Contact Information
For any privacy-related questions, data requests, or concerns, contact the Snapics.ai team:
- Business Entity: GT Atlas LLC
- Data Protection: privacy@snapics.ai
- General Support: support@snapics.ai
- Security: security@snapics.ai