Effective date: June 11, 2026
ShopAI ("we", "our") is a Chrome extension that lets you virtually try on clothing you find while shopping online and get AI styling advice. This policy explains what data ShopAI handles and where it goes.
Account information. When you create an account (email/password or Google sign-in), we store your email address and authentication identifiers with our authentication provider (Supabase). We use this only to operate your account, sync your saved looks, and enforce fair-usage limits.
Photos you provide. Try-on requires the photos you choose to upload (for example a full-body portrait). Photos are sent over HTTPS to our backend, which forwards them to Google's Gemini API to generate the try-on image. Your photos are processed to fulfill each generation request; the source photos you upload are stored locally in your browser (IndexedDB), not on our servers.
Product imagery. When you stage a garment from a shopping page, the product image and basic product details (name, page URL, price text) are processed to run the try-on and to ground stylist answers.
Saved looks. If you save a look to your wardrobe, the generated image and look details are stored locally in your browser and, when cloud sync is enabled for your account, in our database and object storage so your wardrobe follows your account.
Usage records. We record per-account counts of generation requests (timestamps and feature used) to enforce daily limits and control abuse.
Stylist conversations. Messages you send to the AI stylist, and the session context needed to answer them (your staged items, saved-look titles, preferences), are processed by our backend and Google's Gemini API. Session history is stored server-side so conversations stay coherent.
Local data (photos, looks, settings) can be removed by clearing the extension's data or uninstalling it. To delete your account and all server-side data (account record, synced wardrobe, usage and session history), contact us at the support address below; deletion completes within 30 days.
All transport uses HTTPS. Backend requests require authenticated, short-lived tokens. Secrets are never embedded in the extension.
We will update this page when the policy changes and update the effective date above.