TryPrimero
Tools
AI clothes changerVirtual try on clothesClothes on an AI modelAI hairstyle try onBangs simulatorFace shape hairstyle finderHair color try onVirtual makeup try onVirtual nail try on
How it worksPricing
English
English日本語Español한국어
☰
ToolsAI clothes changerVirtual try on clothesClothes on an AI modelAI hairstyle try onBangs simulatorFace shape hairstyle finderHair color try onVirtual makeup try onVirtual nail try onTryPrimeroHow it worksPricingLanguageEnglish日本語Español한국어

Legal

Cookie Policy

Last updated: 2026-09-15

tryprimero.com is operated by IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen’s Road Central, Central, Hong Kong (business registration number 77297048). This page lists every cookie and browser-stored value the site uses, and what your browser sends to other companies while you use it. There are no advertising cookies and no cross-site trackers in the list, because we do not set any.

Everything here exists for one of four reasons: keeping you signed in, keeping the free try-on to one per device and the site safe from abuse, remembering your analytics choice, and analytics that shows us how the site is used and which ads bring customers. Analytics is the only optional one, and in the EEA, the UK, Switzerland, Turkey and Quebec it runs only if you accept.

Cookies we set

NamePurposeLifetime
tp_sessionYour signed-in session. httpOnly, so JavaScript cannot read it, and signed so a forged value is rejected.30 days
tp_authA readable flag that says "someone is signed in", used only so the header does not flicker while the real answer loads. It grants nothing on its own.30 days
tp_didA random device id. Together with a coarse fingerprint it keeps the free try-on to one per device.400 days
tp_humanA signed token issued after you pass the Cloudflare Turnstile check, so you are not asked again during the same visit.45 minutes
tp_consentYour analytics choice (on or off), which banner you gave it under, when you gave it, and a random consent id, so we can respect the choice and show that it was made. It holds nothing about who you are.12 months
ph_phc_rVyQa3QhzN5gdTRxW4t3vKuTqCt6YDKT4in5SBJjopPt_posthogPostHog analytics: a random visitor id, the current session id, the first page and referrer of your first visit (including any campaign parameters in that address), your account id once you sign in, and, if you arrived from a Meta (Facebook or Instagram) ad, that ad’s click id. A small companion cookie with the same name ending in _cpm records which of these values the cookie holds. Set only when analytics is on.365 days

Values stored in your browser (not cookies)

Where a name below starts with ph_phc_…, the full prefix is ph_phc_rVyQa3QhzN5gdTRxW4t3vKuTqCt6YDKT4in5SBJjopPt, the public key of our PostHog project. Values marked "analytics only" exist only while analytics is on and are deleted as soon as it is turned off.

NameStoragePurpose and lifetime
tp_didlocalStorageA copy of the device id, so clearing one of the two does not silently create a new device. Kept until you clear site data.
tp_signed_inlocalStorageMarks that someone signed in on this browser. It is what lets us avoid downloading the ~250 KB sign-in SDK for the majority of visitors, who never sign in. Removed when you sign out.
tp_humanlocalStorageA copy of the Turnstile token, so it also works in browsers that block third-party cookies. Gone when you close the tab.
tp_pending_joblocalStorageWhich finished try-on is waiting for you to sign in, and the address of its blurred preview, so the result is not lost during the sign-in step. Removed once the result is unlocked or can no longer be unlocked.
tp_ccsessionStorageThe country (and region) our CDN reports for your connection, used only to choose which consent rules apply. Gone when you close the tab.
tp_claimsessionStorageFinishes crediting a purchase if you reload the payment confirmation page. Once the purchase is credited it keeps only a "done" note, without the payment reference. Gone when you close the tab.
tp_unsubsessionStorageThe same for the unsubscribe link: a reload can finish the request, and afterwards only the outcome is kept. Gone when you close the tab.
tp_analyticslocalStorageAnalytics only. How many try-ons this browser has started, which account analytics was last linked to, short hashes of completed purchases so none is counted twice, a hash of your balance details so they are sent only when they change, and the pack of a checkout in progress (dropped after 2 hours). Kept until analytics is turned off or you clear site data.
tp_analytics_ssessionStorageAnalytics only. Events waiting to be sent if you leave a page before analytics has loaded, and short hand-offs such as the campaign you arrived with or the quiz you came from. Gone when you close the tab.
ph_phc_…_posthoglocalStorageAnalytics only. PostHog’s copy of the cookie values, plus the properties it attaches to events from this browser, such as your first and latest campaign, page, language and consent version. Related keys starting with the same name (ending in __flags or __surveys) may also be written. Kept until analytics is turned off or you clear site data.
ph_phc_…_posthogsessionStorageAnalytics only. Values that belong to the session in the current tab. Gone when you close the tab.
ph_phc_…_window_idsessionStorageAnalytics only. A random id for this tab, so sessions in different tabs are kept apart. Gone when you close the tab.
ph_phc_…_primary_window_existssessionStorageAnalytics only. Notices when a tab has been duplicated, so the copy gets its own tab id. Removed when the tab closes.
ph_phc_…_session_registered_propertiessessionStorageAnalytics only. The names of properties that apply to the current session only, such as the page the session started on. Gone when you close the tab.
__ph_opt_in_out_phc_…localStorageRemembers that analytics was turned off in this browser, if PostHog had already loaded on the page where you turned it off, so that opt-out is still respected if tp_consent is lost. Kept until you clear site data; turning analytics back on removes it.

Identifiers we derive but do not store in readable form

To keep the free try-on to one per device and to stop the sign-in form being used to email strangers, our servers derive two more identifiers from each request:

  • A hash of your IP address – salted and one-way. We never store the address itself.
  • A hash of a coarse browser fingerprint – screen size, timezone, language, platform. Deliberately imprecise: it is enough to recognise the same device after a cookie wipe, and not enough to identify you across sites.

Both are used for rate limits and abuse prevention only, and the buckets they live in are deleted after 3 days.

Analytics

We use PostHog (PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA) as our processor for analytics. The data is stored in PostHog’s EU Cloud in Frankfurt, Germany. Your browser normally sends it through our own domain, otherwise directly to PostHog’s EU servers. Because PostHog, Inc. is a US company, transfers rely on the EU-US Data Privacy Framework and the European Commission’s Standard Contractual Clauses.

When it runs. In the EEA, the UK, Switzerland, Turkey and Quebec, and whenever we cannot tell where you are, the analytics code is not loaded and no analytics data is stored or sent until you press Accept. Everywhere else analytics is on by default and you can turn it off at any time. Where analytics is on by default, a Global Privacy Control signal from your browser keeps it off in that browser unless you allow it on the notice that tells you so.

What it collects when it runs:

  • The pages you view and where you came from, including campaign parameters and ad click ids in the address.
  • Your device type, browser, screen size and language.
  • A coarse location worked out from your IP address, which PostHog then discards.
  • Clicks and form submissions, including the text of the button or link you click, but not what you type into fields.
  • Rage clicks and dead clicks (repeated clicks, and clicks that do nothing).
  • Heatmaps of where people click and how far they scroll.
  • Page performance (how fast pages load and respond).
  • Error messages and technical details (stack traces).
  • The steps of the try-on, sign-in and checkout, such as a photo added, a result shown or a purchase completed.
  • Your account id once you sign in.

It does not receive your email address, your photos or your results, and it makes no session recordings. When you sign in, earlier analytics from this browser is linked to your account. If you ask for a sign-in link in a browser where analytics is on, the link may carry that browser’s random analytics id; if it does and analytics is also allowed in the browser where you open it, both browsers are linked to your account.

We use it to improve the site, fix errors and see which pages and ads bring customers. Events are kept for up to 7 years. We do not sell this information or share it for cross-context behavioural advertising.

The site also sends a short usage beacon to our own server for some actions, such as a click on an outbound button, an upload, a result or a paywall. It carries the event name, the page and the language, is written to our server logs, and follows the same analytics choice.

Cookies set by others

Cloudflare serves this site and may set its own security cookies (such as __cf_bm and cf_clearance) to tell human traffic from automated traffic and to keep the site available. These are set by Cloudflare, not by us.

PostHog sets no cookies of its own. Its code is part of our site and is served from tryprimero.com, so the ph_ values listed above are stored on our domain, and only while analytics is on.

Stripe sets cookies on its own checkout page, which is where card payments happen. That page is Stripe’s, and so is its cookie policy – we never receive your card details.

Google Fonts serves the typefaces. Firebase (Google) handles sign-in and stores its session data in your browser once you sign in.

Information sent to third parties from your browser

Some features make your browser send information to another company, either directly or, for PostHog, normally through our own domain. The table lists each recipient, what is sent and why.

RecipientInformation sentPurpose
PostHog, Inc. (PostHog)Only under the rules in "Analytics" above: a random visitor id and session id, the pages you view and where you came from (including campaign parameters and ad click ids), device, browser, screen and language, your IP address (used for a coarse location, then discarded), clicks and form submissions (with the text of the button or link, without what you type), rage and dead clicks, click and scroll heatmaps, page performance, error messages and technical details, try-on, sign-in and checkout events, and your account id once you sign in.Improving the site, fixing errors and seeing which pages and ads bring customers.
Cloudflare, Inc. (Cloudflare Turnstile)When the human check runs: your IP address, browser and device characteristics, and signals from the check itself.Telling people from automated traffic, and protecting the free try-on and the sign-in form.
Google LLC (Firebase Authentication)When you sign in or are already signed in: your IP address, browser information, your Google sign-in or the one-time sign-in token, and your account id and email address.Signing you in and keeping you signed in.
Google LLC (Google Fonts)On every page: your IP address, browser information and the address of our site.Delivering the typefaces the site uses.
Features & Labels, Inc. (fal)When your result or its blurred preview is shown: your IP address, browser information and the address of the image.Showing you the image the AI made, which is stored on fal storage.
Stripe Payments Europe, Limited (Stripe)Only when you go to the Stripe payment page: what you enter there (such as card details and email address), your IP address and browser information. Our pages load no Stripe script.Taking your payment.

Only PostHog depends on your analytics choice. The others are needed for the feature you are using: without them the site cannot run the human check, sign you in, show its typefaces, show your result or take a payment. Other requests that stay with our own servers are not listed.

Managing cookies

opens your analytics choice again at any time. The same button is at the bottom of every page.

Turning analytics off stops PostHog and our usage beacon in this browser straight away, and deletes the ph_ cookies, the ph_ stored values, tp_analytics and tp_analytics_s. We keep tp_consent, and __ph_opt_in_out_… where it was written, so your choice is remembered. The site works exactly the same with analytics off. Turning it off does not delete events already sent; to have analytics linked to your account deleted, see the Privacy Policy.

Your choice is kept for 12 months. After that, where we ask before analytics runs, analytics stays off until you accept again. Elsewhere analytics returns to its default: it is on again and the notice is shown, unless your browser sends a Global Privacy Control signal or still holds PostHog’s opt-out record described above, in which case it stays off. To stay opted out, turn analytics off again when you see the notice. If you clear this site’s cookies and storage, the choice is lost and the rules for your region apply as they would to a new visitor.

A Global Privacy Control signal from your browser counts as an opt-out wherever analytics would otherwise be on by default. We do not act on the Do Not Track signal.

Every browser lets you view, block and delete cookies from its settings. Blocking them here has a specific cost: you cannot stay signed in, and clearing the device id does not restore the free try-on, because it is also counted against the hashed IP and fingerprint pair described above. Deleting the ph_ values in your browser also removes the analytics id, but where analytics is on by default a new one is created on your next visit, so use Cookie settings to opt out.

For users in South Korea: automatic collection devices. We install and operate the cookies and similar browser storage listed on this page (automatic collection devices) for the purposes given for each. You can refuse them: turn analytics off in Cookie settings, or set your browser to block or delete cookies (Chrome: Settings → Privacy and security; Safari: Settings → Privacy; Edge: Settings → Cookies and site permissions). Refusing analytics does not affect the service. Refusing the other cookies means you cannot stay signed in, and some features may not work.

How your data is used more broadly is set out in the Privacy Policy. Questions: [email protected].

TryPrimero

AI try-on for outfits, hair, makeup and nails. Your face stays yours.

Try it free in Telegram

First try-on free · Results in seconds · Photos used only for your try-on

All tools

  • AI clothes changer
  • Virtual try on clothes
  • Clothes on an AI model
  • AI hairstyle try on
  • Bangs simulator
  • Face shape hairstyle finder
  • Hair color try on
  • Virtual makeup try on
  • Virtual nail try on

Info

  • How it works
  • Pricing
  • Privacy
  • Cookie Policy
  • Terms
  • Contact
© 2026 IT Nest LimitedEnglish日本語Español한국어

Cookie settings

May we use analytics cookies to improve TryPrimero and measure our ads? The site works the same if you reject.We use analytics cookies to improve TryPrimero and measure our ads. You can opt out at any time.Your browser’s Global Privacy Control is on, so analytics stays off on this browser. Privacy · Cookies

Current choice: analytics on.Current choice: analytics off.