New in Figr — Live Try-On, a world first ever. Click to view ->
Privacy Policy
Privacy Policy
Last updated: 18 June 2026
This Privacy Policy explains how Enly AI Inc ("Figr", "we", "us", "our"), a Delaware C-corporation based in the United States, collects, uses, and protects your personal data when you use the Figr try-on and fit experience embedded in a partner brand's online store (the "Service").
Figr provides a pre-purchase visualization and fit layer for fashion brands: you can try products on a personal avatar and get size recommendations before you buy. This policy is written for shoppers: the people who create an account, upload photos, and receive try-ons and sizing through Figr.
Note on roles. When you shop on a brand's website, that brand decides to offer Figr and is a joint or independent controller for some of your data, while Figr acts as controller for the avatar, try-on, and sizing data described below. Please also read the brand's own privacy notice.
1. Who we are and how to contact us
Controller: Enly AI Inc, 131 Continental Drive, Suite 305, Newark, DE 19713, United States.
Privacy contact: privacy@figr.so
EU representative (GDPR Art. 27): Simon Solbas, contact privacy@figr.so
UK representative: None appointed; contact privacy@figr.so
If you are in the EU/EEA you may lodge a complaint with your local supervisory authority (in France, the CNIL, cnil.fr). If you are in the UK, you may complain to the Information Commissioner's Office (ico.org.uk).
2. The data we collect
We collect only what we need to create your avatar, show you try-ons, and recommend sizes.
You provide directly:
Account data: your email address (we use a one-time code to sign you in; we do not store a password).
Profile / fit data: gender, age range, height, weight, and body-type descriptors (e.g. torso and abdomen build).
Photos: the face photo and body photo you upload to generate your avatar and estimate measurements.
Generated when you use the Service:
Avatars, portraits, and try-on images and videos created from your photos and profile.
Estimated body measurements (e.g. chest, waist, hips, inseam) derived from your body photo and height.
Try-on and size-recommendation history linked to your account.
Collected automatically:
Usage and device data: product events, the store you used Figr in, SDK version, environment, and basic technical/diagnostic data via our analytics (PostHog) and error monitoring (Sentry). We configure these to avoid collecting unnecessary personal identifiers.
We do not ask for or process payment card details. Purchases happen on the brand's store, not within Figr.
3. Sensitive data and your explicit consent
Your photographs and the body measurements we derive from them can reveal information about your physical appearance and body. Where this data is treated as a special category of personal data under the GDPR/UK GDPR (Article 9), we process it only with your explicit consent, which you give through an opt-in checkbox shown before you upload any photo.
We do not use your photos for facial-recognition identification, and we do not use your data or photos to train AI models. You can withdraw your consent at any time by deleting your data or your account (see Section 8), which stops further processing.
4. Why we use your data and our legal bases
Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
Create your account and sign you in | Performance of a contract | |
Generate your avatar and try-on images/videos | Photos, profile data | Explicit consent (Art. 9) + contract |
Estimate measurements and recommend sizes | Body photo, height/weight, body type | Explicit consent (Art. 9) + contract |
Save your try-on and sizing history | Generated content, account ID | Performance of a contract |
Measure, secure, debug, and improve the Service | Usage, device, error data | Legitimate interests |
Detect and prevent misuse, fraud, and unsafe content | Images, usage data | Legitimate interests / legal obligation |
Send service or marketing messages (where applicable) | Consent or legitimate interests (you can opt out) |
Where we rely on legitimate interests, we have balanced them against your rights; contact us for details of that assessment.
5. How your data is processed by AI
To create avatars and try-ons, your photos and profile data are sent to and processed by our AI systems and trusted AI infrastructure providers (see Section 6). Generation is automated, but it does not produce legal or similarly significant effects about you. It produces images and a suggested size, which you remain free to accept or ignore. Our sizing service processes your body photo in memory to estimate measurements and does not retain the photo itself.
6. Who we share data with (subprocessors)
We do not sell your personal data. We share it only with service providers ("subprocessors") that help us run the Service, under contracts that require them to protect it:
The brand/store where you used Figr, for your try-on, sizing, and shopping experience.
Cloud & infrastructure: Cloudflare (storage, media streaming, application hosting), Fly.io and Google Cloud (AI service hosting), Supabase (authentication and database).
AI processing: Google (Gemini models, Vertex AI) for image generation and embeddings; FAL.AI for image upscaling (configured so outputs expire within ~1 hour and inputs/outputs are not stored).
Analytics & monitoring: PostHog (product analytics), Sentry (error monitoring).
Commerce & messaging: Shopify (product data), Klaviyo and Resend (email).
A current list of subprocessors is available on request at privacy@figr.so. We may also disclose data where required by law or to protect our rights and users' safety.
7. International transfers
We are based in the United States, and some of our subprocessors process data in the United States and other countries. When we process the personal data of shoppers in the EEA or UK, those transfers outside the EEA/UK rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or an adequacy decision where one applies. You can request a copy of the relevant safeguards.
8. How long we keep your data and how to delete it
We keep your account, profile, photos, and generated content for as long as your account is active. We do not impose a fixed expiry: your data is retained until you delete it or close your account. You can:
Export your data: request a machine-readable (JSON) copy of your account, profile, and generated content.
Delete your account: this permanently erases your authentication record, stored photos and assets, try-on videos, and triggers deletion requests to our email provider.
We action data-rights requests within 30 days. Some limited data may be retained where required for legal, security, or fraud-prevention reasons, and backups are purged within 30 days [TO CONFIRM: verify the actual backup purge window].
9. Your rights
Under the GDPR and UK GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). Where decisions are automated, you can ask for human review. To exercise any right, email privacy@figr.so or use the in-product export/delete tools. We will not discriminate against you for exercising your rights.
10. Security
We protect your data with measures including encryption in transit, access controls and least-privilege provisioning, tenant isolation (your data is never shared across brands or used to train models), monitoring, and a documented incident-management program. We are in the observation period for SOC 2 Type II. No system is perfectly secure, but we work to protect your data and will notify you and regulators of breaches where the law requires.
11. Children
The Service is not directed to children. You must be at least 18 years old to use Figr. We do not knowingly collect data from children; if you believe a child has used the Service, contact privacy@figr.so and we will delete the data.
12. Changes to this policy
We may update this policy as the Service evolves. We will post the new version with an updated "Last updated" date and, for material changes, provide additional notice. Continued use after changes take effect means you accept the updated policy.
This document is a grounded draft based on Figr's actual data flows and aligned with GDPR/UK GDPR expectations. It is not legal advice; have it reviewed by qualified counsel before publishing. One item remains flagged for internal confirmation: the backup purge window in Section 8.
