Legal
Privacy Policy
Last updated: 2026-09-15
TryPrimero is a service of IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen’s Road Central, Central, Hong Kong (business registration number 77297048) ("we", the data controller). We run the website tryprimero.com, the TryPrimero iOS app and the TryPrimero Telegram bot. This policy covers all three, and it is specific about the website because the website now processes photos itself rather than sending you elsewhere.
The short version: your photo is used to make your try-on and for nothing else. It is not sold, not used for advertising, not used to train AI models, and never sent to our analytics provider.
1. Photos you upload
When you use the try-on – signed in or not – the photo goes from your browser to our servers over TLS, and from there to our AI image provider, fal.ai, which hosts it and runs the image model that produces your result. Both the photo you sent and the image that comes back are stored on fal.ai storage under an unguessable URL.
Before anything is processed, every uploaded photo passes an automatic safety check. A photo that fails is refused and never reaches the image model.
We do not use your photos to train models, we do not publish them, and we do not give them to anyone other than the AI provider that generates your result. Our analytics (section 6) never receives them: we exclude the upload areas and result images from it and we do not record sessions.
| What | Where it is kept | How long |
|---|---|---|
| Anonymous website try-on (the free one) | Our database: the tool used, the status and the result URL. No photo bytes. | Deleted after 30 days by an automatic daily sweep |
| Signed-in try-on | Your history on your account | Until you delete it or delete your account |
| Photo and result files | fal.ai storage, under an unguessable URL | Per the provider’s retention; we do not republish them and the link is not indexable |
2. Your account
Signing in is handled by Firebase Authentication (Google LLC) – the same account as the iOS app, which is why your balance is the same everywhere. We receive a user identifier, your email address and, if the provider supplies one, your display name.
In our database, against that identifier, we store your try-on balance, your purchases and your generation history. If analytics is on in your browser, signing in also links the analytics collected on that browser, including your earlier visits, to your account id (section 6). Your email address is never sent to analytics.
If you sign in with Apple and choose to hide your email, we only ever see the relay address Apple gives us.
3. Emails we send
If you ask for a sign-in code, we send one email with a 6-digit code through Resend (Plus Five Five, Inc.), our email provider. If the address has no account yet, entering the code creates one. We store your address, a keyed hash of the code (never the code itself), how many wrong codes were entered, and the provider’s message id so we can tell "we never sent it" apart from "we sent it and it did not arrive". A code expires after 10 minutes, works once and stops working after 5 wrong attempts. When the iOS app launches, it will use the same codes for the same account.
If you created your account on the website, have not bought anything (on the site or in the app) and have not unsubscribed, we send one more email at least 24 hours after sign-up: a short note that your try-on is saved in your account, with a link to the try-on packs. It is sent once per account and never repeated. It has an unsubscribe link and a one-click unsubscribe header for mail clients, and its links carry campaign tags (utm parameters) with no personal identifier so we can measure whether it was useful. Unsubscribing stops this email only; sign-in codes keep working. Accounts created in the iOS app never receive it.
Click tracking and open tracking are switched off. Every link in our emails points at tryprimero.com and nowhere else.
Spent and expired token rows are deleted after 7 days.
4. Payments
Card payments are processed by Stripe on Stripe’s own checkout page. We never see, receive or store your card details. What comes back to us is the checkout session id, the amount, the currency and which pack you bought – enough to credit your account and answer a billing question.
Purchases made in the iOS app are processed by Apple, and purchases in the Telegram bot by Telegram. The same applies: we do not see payment credentials.
5. Cookies, device identifiers and limits
The free try-on has to be limited to one per device, and the sign-in form has to be protected from being used to send mail to strangers. Both need to recognise a device without knowing who you are. We do that with a small first-party device id, a coarse browser fingerprint (screen size, timezone, language, platform) and your IP address – and the last two are stored only as salted, one-way hashes, never as readable values.
Cloudflare Turnstile may show you a quick "are you human" check before your first action. A pass gives you a signed 45-minute token so you are not asked again.
If analytics is on (section 6), PostHog’s code, served from our site, stores a separate random analytics id, a session id and the campaign details of your visits in a first-party cookie and in browser storage whose names start with ph_. That id is not the device id above, and the two are never combined. Your analytics choice itself is kept for 12 months in the tp_consent cookie, with its time and a random consent id.
A few other values stay in your browser only: tp_cc (for the tab session, the country our CDN reports, used only to choose which consent rules apply), tp_pending_job (which finished try-on is waiting for you to sign in), tp_claim and tp_unsub (for the tab session, so a purchase or an unsubscribe completes if you reload the page), and tp_analytics / tp_analytics_s (analytics only, removed when analytics is off).
The full list of cookies and identifiers, with purpose and lifetime, is in the Cookie Policy. You can refuse analytics with Cookie settings, and block or delete cookies in your browser settings; blocking our own cookies means you cannot stay signed in.
6. Analytics
We use PostHog (PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA) for product analytics. PostHog acts as our processor, and the data is stored in PostHog’s EU Cloud in Frankfurt, Germany. Requests normally go through our own domain, otherwise directly to PostHog’s EU servers. We do not use Google Analytics, advertising pixels or cross-site trackers.
If you are in the EEA, the UK, Switzerland, Turkey or Quebec, or we cannot tell where you are, analytics stays off until you accept it in the cookie banner. Everywhere else it is on by default and you can turn it off at any time. If your browser sends a Global Privacy Control signal, we treat it as an opt-out and analytics stays off on that browser unless you turn it on yourself. You can change your choice at any time with (also in the footer of every page). Refusing or turning analytics off does not change how the site works.
When analytics is on, PostHog receives:
- the pages you view and the page you came from, including campaign parameters and ad click ids in the address (such as utm_source or gclid);
- your device type, browser, operating system, screen size and language;
- a coarse location (such as country and city) derived from your IP address, which is then discarded;
- clicks and form submissions, including the text of the button or link you click, but not what you type into fields;
- rage clicks (repeated clicks) and dead clicks (clicks that do nothing);
- heatmaps of where people click and how far they scroll;
- page performance (how fast pages load and respond);
- error messages and technical details (stack traces) when something breaks on a page;
- the steps of the try-on, sign-in and checkout, such as that a photo was added (its file type and size, never the photo), a result was generated, a pack was chosen or a purchase was completed;
- your analytics choice, with its time and a random consent id, when you accept analytics;
- after you sign in, your account id, your try-on balance and whether a free try-on is still available.
PostHog does not receive your email address, your photos or results, or what you type, and we do not record sessions.
We use this to understand how the site is used, fix errors and slow pages, improve the try-on, and measure which pages, campaigns and ads bring people who sign up or buy. We do not sell it, we do not share it for cross-context behavioural advertising, and we do not use it to make decisions about you.
Analytics events are kept for up to 7 years and then deleted. On request we delete the analytics profile linked to your account together with its events (section 9).
Separately, the site sends a small event to our own server when you use the try-on or press a button that leaves the site. It carries only the event name (such as upload, result, locked, unlock, paywall_view or click_bot), the page and the language, and our server writes it to its log, not to a database. It follows the same analytics choice: when analytics is off, it is not sent.
The site is served by Cloudflare, which processes ordinary request metadata (IP address, user agent, timestamps) to deliver pages, block attacks and produce aggregate traffic counts. Cloudflare acts as our processor.
7. Legal bases
In the EEA, the UK and Switzerland (and, for analytics, also in Turkey and Quebec) we rely on:
- Performance of a contract: generating your try-on, keeping your balance, delivering what you bought, and sending sign-in codes.
- Legitimate interests: preventing abuse of the free try-on and of the sign-in form, keeping the service secure and available, and sending the one reminder email described in section 3 (you can unsubscribe at any time). We limit this with salted hashing and short retention windows.
- Legal obligation: keeping transaction records where tax or accounting law requires it.
- Consent: for analytics cookies and similar storage (section 6). You can withdraw it at any time with Cookie settings. Withdrawing does not affect processing that happened before, and refusing has no effect on the service.
Elsewhere, the service itself rests on the contract with you and on legal obligations as above. For analytics:
- Brazil: legitimate interest (LGPD art. 7, IX), with the opt-out described in section 6.
- South Korea: a legitimate interest that clearly outweighs your rights (PIPA art. 15(1)(6)), limited to the items in section 6, with the refusal method described there.
- Mexico: your tacit consent once this privacy notice is available to you, which you can revoke at any time with Cookie settings or by email.
- Japan: we use personal information only for the purposes of use published in this policy (APPI art. 21).
- United States, Hong Kong and other countries: this notice, with the opt-out described in section 6.
8. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, correct it, have it deleted, restrict or object to processing, receive it in a portable form, withdraw consent at any time, and complain to a data protection supervisory authority, in particular where you live or work.
Wherever you are, you can turn analytics off at any time with , and we honour a Global Privacy Control signal as an opt-out. Clearing this site’s cookies and data also removes the analytics id, but it removes your choice too, so the banner may appear again.
In Japan you can ask us to disclose, correct, stop using or delete the personal data we hold about you. In South Korea you can ask to access, correct or delete your personal information, ask us to suspend processing, and withdraw consent; the remedies available to you are listed in section 13.
Notice at collection (California). These are the categories of personal information we collect, where they come from, why we use them and how long we keep them:
| Category | What and from where | Why | How long |
|---|---|---|---|
| Identifiers | Account id, email address and display name (from you and your sign-in provider); device id and random analytics ids (from your browser); IP address (from your connection) | Providing your account, preventing abuse, analytics | Account data until you delete your account; analytics up to 7 years; hashed limiter values 3 days; sign-in token records 7 days |
| Internet or other electronic network activity | Pages viewed, referrers, clicks, heatmaps, errors, performance and try-on, sign-in and checkout steps (from your browser, when analytics is on) | Improving the site, fixing errors, measuring ads and campaigns | Analytics up to 7 years |
| Approximate geolocation | Country and city derived from your IP address | Choosing which consent rules apply, analytics | Country for the tab session; analytics up to 7 years |
| Commercial information | Packs bought, amount, currency and checkout session id (from you and Stripe) | Delivering purchases, answering billing questions, bookkeeping, measuring which ads lead to purchases | As long as tax or accounting law requires; analytics up to 7 years |
| Visual information | The photos you upload and the images generated from them (from you) | Generating your try-on | As in section 1 |
We do not sell any of these categories or share them for cross-context behavioural advertising, and we never have. We do not use sensitive personal information to infer characteristics about you. If you are in California, you have the right to know what we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information. Exercising any right will never get you a worse service.
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. The automatic safety check in section 1 only decides whether a photo can be processed; if it refuses a photo, you can use another one.
To exercise any of these rights, write to [email protected] from the address on your account. We answer within 30 days.
9. Deleting your account
Email [email protected] and we delete your account record, your balance, your generation history and your purchase records, except where we are legally required to keep a transaction record, and we delete the analytics profile linked to your account together with its events. Anonymous website try-ons are already deleted automatically after 30 days, and analytics never linked to an account is deleted when its retention period ends.
Deleting your account deletes it everywhere – site, app and bot are one account.
10. International transfers
Our processors are PostHog, Inc. (USA; analytics data stored in Germany), fal (Features & Labels Inc., USA and other countries), Google LLC (Firebase Authentication, USA), Plus Five Five, Inc. (Resend, USA), Stripe (for our account, Stripe Payments Europe, Limited, Ireland; Stripe also processes data in the USA and other countries) and Cloudflare, Inc. (USA, with a worldwide network). Transfers of data from the EEA, the UK and Switzerland rely on the EU-US Data Privacy Framework and its UK and Swiss extensions where the provider is certified, and on the Standard Contractual Clauses in each provider’s data processing terms.
For users in Japan: all of these processors are businesses in foreign countries. We entrust personal data to them under contracts that require them to take measures equivalent to those required under the APPI (art. 28(1)), and we take the measures needed to make sure they keep doing so. On request, we tell you the country concerned, its system for protecting personal information and the measures the recipient takes (art. 28(3)).
For users in South Korea (PIPA art. 28-8): we transfer personal information overseas as follows. The transfers to fal, Google, Resend, Stripe and Cloudflare are needed to provide the service and are disclosed in this policy. The transfer to PostHog is for analytics only, and you can refuse it at any time with Cookie settings without any effect on the service.
| Recipient (contact) | Country | Items | Purpose | When and how | Retention | How to refuse |
|---|---|---|---|---|---|---|
| PostHog, Inc. ([email protected]) | USA; data stored in Germany | Random analytics ids, pages and clicks, device and browser data, approximate location, try-on, sign-in and checkout steps, account id, try-on balance and free try-on availability after sign-in | Usage analytics and ad measurement | Continuously over the network while you use the site with analytics on | up to 7 years | Turn analytics off with Cookie settings; the site keeps working |
| fal, Features & Labels Inc. ([email protected]) | USA and other countries | Uploaded photos and generated images | Generating try-ons | Over the network when you use the try-on | As in section 1 | Do not use the try-on; you cannot use that feature |
| Google LLC, Firebase Authentication (Firebase Support contact form) | USA | Account id, email address, display name, sign-in data | Sign-in | Over the network when you sign in | Until you delete your account | Do not sign in; you cannot use an account |
| Plus Five Five, Inc., Resend ([email protected]) | USA | Email address and email content, including sign-in codes | Sending sign-in and service emails | Over the network when an email is sent | Per the provider’s retention | Do not ask for a sign-in code, or unsubscribe from the reminder; you cannot use that feature |
| Stripe Payments Europe, Limited ([email protected]) | Ireland, USA and other countries where Stripe operates | Payment details you enter on Stripe, email address, amount, pack bought | Processing payments | Over the network when you go to the Stripe payment page | Per Stripe’s retention and the law | Do not buy on the website; you cannot use that feature |
| Cloudflare, Inc. ([email protected]) | USA; worldwide network | IP address, request and browser data, human-check data | Delivering the site, security checks | Over the network on every visit | Per Cloudflare’s retention | Cannot be refused separately; the site cannot be delivered without it |
Processing we entrust to others (PIPA art. 26):
- PostHog, Inc.: usage analytics
- Cloudflare, Inc.: delivering the site and security checks
- Google LLC (Firebase): sign-in
- fal (Features & Labels Inc.): image generation and storage of photos and results
- Stripe: payment processing
- Plus Five Five, Inc. (Resend): sending emails
11. Children
TryPrimero is not for children. You must be at least 13, and at least 16 where your country sets that as the age of digital consent. In South Korea you must be at least 14 years old. We do not knowingly process a child’s photo; if you believe we have one, write to us and we will delete it.
12. Security
Everything travels over TLS. Sign-in codes and link tokens are stored only as one-way hashes. On our servers, your IP address, the browser fingerprint and the device id used for limits are kept only as salted one-way hashes. Analytics ids are random values, not derived from any of those; PostHog uses your IP address only to derive a coarse location and then discards it. Sessions are held in an httpOnly cookie that JavaScript cannot read. No system is perfect, but the design assumes a breach and stores as little as it can get away with.
Understanding the external environment: our processors are based in, or store data in, the United States, Ireland and Germany, and some of them (Stripe, fal and Cloudflare’s network) also process data in other countries. We have checked the personal-information protection systems of those countries before using these processors.
13. Changes and contact
If this policy changes materially we update the date at the top and, where the change affects you, say so on the site.
The data controller is IT Nest Limited, Office 3906, 39/F, The Center, 99 Queen’s Road Central, Central, Hong Kong (business registration number 77297048). Questions, requests, or a data protection issue: [email protected].
Privacy contact (for Korea, the department responsible for privacy and complaints): IT Nest Limited, privacy team, [email protected].
When a retention period ends, or when you ask us to delete data and no law requires us to keep it, we destroy it without delay: electronic records are deleted so they cannot be restored, and any printed records are shredded. Data we must keep by law, such as transaction records, is kept separately from other data, only for the period the law requires, and used for nothing else.
If you are in South Korea and need help with an infringement of your privacy rights, you can also contact:
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division: 1301, www.spo.go.kr
- Korean National Police Agency (cybercrime reports): 182, ecrm.police.go.kr