This Privacy Policy explains how Shirtly processes information when you use the Shirtly mobile application and related support pages.
Information we process
- Account: user ID, email, display name, avatar URL, authentication provider, and session information.
- Design and AI content: uploaded photos and artwork, prompts, editable design layers, generated artwork, mockups, virtual try-on source/result images, output reports, and generation identifiers.
- Credits and purchases: credit balance and ledger, app-store product and transaction identifiers, validation status, and rewarded-ad verification references.
- Device and usage: optional Firebase Analytics events, advertising consent, non-personalized ad requests, and camera or photo selections initiated by you.
- Support: email, selected topic, message, deletion request, and processing status.
Why we use it
We process information to authenticate accounts; save and render designs; provide Gemini-powered AI generation, background removal, mockups, and try-on; manage credits; prevent abuse; answer support and privacy requests; secure and improve the service; and meet legal obligations.
Processors and sharing
Shirtly uses Supabase for authentication, database, Edge Functions, and Storage; Google Gemini for AI processing; Google AdMob and UMP for Android advertising and consent; Firebase Analytics for Android usage analytics; and Apple and Google for distribution and purchase validation. We do not sell personal information.
Consent and choices
Usage analytics is enabled by default on Android to help improve product reliability and features. It does not include prompts, images, email addresses, or Shirtly user IDs. You can disable or re-enable it at any time under Profile → Privacy choices. Ad requests are non-personalized and are not made until Google UMP permits them. Shirtly does not request App Tracking Transparency permission in this release.
Retention
- Account and user-owned content remains while the account is active and is removed through account deletion, subject to limited legal or security retention.
- Temporary failed AI objects under designated prefixes are removed after 7 days.
- Purchase and credit-ledger records may be retained for up to 7 years where accounting, fraud, or store-dispute obligations require it.
- Support and verified deletion requests may be retained for up to 24 months after closure.
Security and international processing
Data is encrypted in transit using HTTPS. Access is limited through authentication, row-level security, server-only credentials, and purpose-based operational access. Providers may process data in other countries under their safeguards.
Your rights
Depending on your location, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Delete directly under Profile → Delete account, use the public deletion page, or submit a support request.
Children
Shirtly is not directed to children under 13. Users must meet the minimum digital-consent age applicable in their country.
Contact
Contact Shirtly through the public support form.
Effective and last updated: 16 July 2026
