Legal
Privacy Policy
Last updated: 2026-07-28
TryPrimero is a service of IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen’s Road Central, Central, Hong Kong (business registration number 77297048) ("we", the data controller). We run the website tryprimero.com, the TryPrimero iOS app and the TryPrimero Telegram bot. This policy covers all three, and it is specific about the website because the website now processes photos itself rather than sending you elsewhere.
The short version: your photo is used to make your try-on and for nothing else. It is not sold, not used for advertising, and not used to train AI models.
1. Photos you upload
When you use the try-on — signed in or not — the photo goes from your browser to our servers over TLS, and from there to our AI image provider, fal.ai, which hosts it and runs the image model that produces your result. Both the photo you sent and the image that comes back are stored on fal.ai storage under an unguessable URL.
Before anything is processed, every uploaded photo passes an automatic safety check. A photo that fails is refused and never reaches the image model.
We do not use your photos to train models, we do not publish them, and we do not give them to anyone other than the AI provider that generates your result.
| What | Where it is kept | How long |
|---|---|---|
| Anonymous website try-on (the free one) | Our database: the tool used, the status and the result URL. No photo bytes. | Deleted after 30 days by an automatic daily sweep |
| Signed-in try-on | Your history on your account | Until you delete it or delete your account |
| Photo and result files | fal.ai storage, under an unguessable URL | Per the provider’s retention; we do not republish them and the link is not indexable |
2. Your account
Signing in is handled by Firebase Authentication (Google LLC) — the same account as the iOS app, which is why your balance is the same everywhere. We receive a user identifier, your email address and, if the provider supplies one, your display name.
Against that identifier we store your try-on balance, your purchases and your generation history. Nothing else.
If you sign in with Apple and choose to hide your email, we only ever see the relay address Apple gives us.
3. Sign-in emails
If you ask for a sign-in link, we send exactly one email through Resend, our email provider. We store your address, a one-way hash of the link token (never the token itself), and the provider’s message id so we can tell "we never sent it" apart from "we sent it and it did not arrive".
Click tracking and open tracking are switched off. Every link in the email points at tryprimero.com and nowhere else. A sign-in link expires after one hour and works once.
Spent and expired token rows are deleted after 7 days.
4. Payments
Card payments are processed by Stripe on Stripe’s own checkout page. We never see, receive or store your card details. What comes back to us is the checkout session id, the amount, the currency and which pack you bought — enough to credit your account and answer a billing question.
Purchases made in the iOS app are processed by Apple, and purchases in the Telegram bot by Telegram. The same applies: we do not see payment credentials.
5. Cookies, device identifiers and limits
The free try-on has to be limited to one per device, and the sign-in form has to be protected from being used to send mail to strangers. Both need to recognise a device without knowing who you are. We do that with a small first-party device id, a coarse browser fingerprint (screen size, timezone, language, platform) and your IP address — and the last two are stored only as salted, one-way hashes, never as readable values.
Cloudflare Turnstile may show you a quick "are you human" check before your first action. A pass gives you a signed 45-minute token so you are not asked again.
The full list of cookies and identifiers, with purpose and lifetime, is in the Cookie Policy.
6. Analytics
We do not use Google Analytics, advertising pixels or cross-site trackers.
The site sends an anonymous click beacon when you press an outbound button (to the app or to Telegram). It carries the event name, the page and the language — no identifier, nothing that can be tied back to you — and is written to our server log, not to a database.
The site is served by Cloudflare, which processes ordinary request metadata (IP address, user agent, timestamps) to deliver pages, block attacks and produce aggregate traffic counts. Cloudflare acts as our processor.
7. Legal bases (EEA / UK)
- Performance of a contract — generating your try-on, keeping your balance, delivering what you bought.
- Legitimate interests — preventing abuse of the free tier and of the sign-in form, keeping the service available, understanding aggregate traffic. We limit this with hashing and short retention.
- Legal obligation — keeping transaction records where tax or accounting law requires it.
- Consent — where it is required for something optional; you can withdraw it at any time.
8. Your rights
If you are in the EEA or the UK, you have the right to access your data, correct it, have it deleted, restrict or object to processing, receive it in a portable form, and complain to your data protection authority.
If you are in California, you have the right to know what we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information — we do not sell or share personal information, and we never have. Exercising any right will never get you a worse service.
To exercise any of these, write to [email protected] from the address on your account. We answer within 30 days.
9. Deleting your account
Email [email protected] and we delete your account record, your balance, your generation history and your purchase records, except where we are legally required to keep a transaction record. Anonymous website try-ons are already deleted automatically after 30 days.
Deleting your account deletes it everywhere — site, app and bot are one account.
10. International transfers
Our processors (Google, fal.ai, Stripe, Resend, Cloudflare) operate infrastructure outside your country, including in the United States. Transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent mechanism offered by each provider.
11. Children
TryPrimero is not for children. You must be at least 13, and at least 16 where your country sets that as the age of digital consent. We do not knowingly process a child’s photo; if you believe we have one, write to us and we will delete it.
12. Security
Everything travels over TLS. Sign-in tokens are stored as one-way hashes. Device and IP identifiers are salted and hashed. Sessions are held in an httpOnly cookie that JavaScript cannot read. No system is perfect, but the design assumes a breach and stores as little as it can get away with.
13. Changes and contact
If this policy changes materially we update the date at the top and, where the change affects you, say so on the site.
The data controller is IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen’s Road Central, Central, Hong Kong (business registration number 77297048). Questions, requests, or a data protection issue: [email protected].