Privacy Policy
Effective date: 2026-08-29 Version: 2.0 (see Section 20 for version history)
At a Glance
| Question | Answer |
|---|---|
| Who is this for? | Adults only. You must be 18 or older. We check at sign-up and enforce it on our servers. |
| What is the product? | Anthroutfit scans your body with your iPhone's LiDAR sensor and turns it into measurements and a 3D avatar, so you can see how clothes would fit you. |
| Do you photograph me? | No. The app never captures a camera photograph or video. It records depth — distance measurements — plus a body-outline mask and joint positions. There is no picture of you anywhere in our system. |
| Do you store my date of birth? | No. We use it once to check you are 18, then discard it. We keep only the answer, not the birthday. |
| Do you sell my information? | Never. Not to anyone, in any form, at any price. |
| Do you give body data to insurers, employers, or data brokers? | Never. |
| Do you use advertising or analytics trackers? | No advertising trackers, ever, and no cookies. The app contains no analytics, advertising, or crash-reporting SDK. The website counts visits with a cookieless tool that stores nothing on your device and cannot follow you to other sites. |
| Can I delete everything? | Yes. Deleting your account stops your sign-in immediately and erases your data — including our backup copies — within 30 days. |
| Can I withdraw consent for body scanning? | Yes, at any time. That one is immediate and permanent: your scans, meshes, and measurements are erased straight away, not after a grace period. |
This table is a summary for convenience. The full policy below governs.
1. Who We Are & What This Policy Covers
Adam Tran, doing business as Anthroutfit ("Anthroutfit," "we," "us," "our"), is a sole proprietor, 4739 Irvin Square, Alexandria, VA 22312, United States. For data protection purposes we are the controller of the personal information described in this Policy, except where Section 16 says otherwise.
This Policy covers:
- Our website, where you can read about the product and join the waitlist; and
- The Anthroutfit iOS app, which captures depth data of your body to generate a 3D avatar and clothing-fit measurements (the "App").
It applies to anyone who visits the website, uses the App, or otherwise interacts with us. It does not cover third-party services we link to but do not operate — including Apple's App Store, which is governed by Apple's own privacy policy.
Our service is for adults. You must be 18 years of age or older to create an account or use the App. See Section 17.
Defined terms. "Personal information" (or "personal data") means information that identifies, relates to, or could reasonably be linked with you or your household. "Body Scan Data" means the depth captures recorded during a scan, the 3D body mesh derived from them, the body measurements derived from the mesh, and your generated avatar. "Process" means any operation performed on personal information.
2. Information We Collect
2.1 Information you provide directly
| Category | Examples | When |
|---|---|---|
| Account information | Email address, display name, password (stored only as a salted PBKDF2 hash — never in readable form) | When you register |
| Age attestation | Your confirmation that you are 18 or older. Your date of birth is used once to compute this and is then discarded — we do not store it | At sign-up |
| Consent records | The fact, timestamp, exact document version, IP address, and browser/app identifier for each consent you give. For waitlist sign-ups we also store the country the IP address resolves to and the path of the page the sign-up came from — evidence that the sign-up was genuine and that we were authorized to email you | When you consent |
| Profile details | Height, weight, foot length, gender, and any notes you enter, for the person being scanned | When you set up a profile |
| Support communications | Messages you send us and anything you choose to include | When you contact us |
| Website form submissions | Waitlist form: your email address. Support form: your name, email, subject topic, and message | When you submit a form on our website. Submissions go to infrastructure we operate (Section 3), not to a third-party form service |
| Unsubscribe records | If you unsubscribe, we keep a suppression record of your email address — specifically so that we do not mail you again | When you unsubscribe |
2.2 Information captured with your express consent
| Category | Examples | When |
|---|---|---|
| Raw scan captures | Per-frame depth maps (distance measurements), sensor confidence maps, a body-outline mask separating you from the room, and estimated skeleton joint positions | Only during a scan you start, and only after you accept the Biometric Data Consent Notice |
| Derived Body Scan Data | Your 3D body mesh, body measurements (waist, hips, chest, inseam and similar), your avatar | Generated on our servers from your raw captures |
| Capture context | Camera position and orientation during the scan, floor height, device model, iOS version, app version, capture date | Recorded alongside each scan so we can diagnose failed scans |
We never capture a photograph or video of you. The App does not read your camera's colour image, and no such image is transmitted, stored, or derivable from what we hold. What the sensor records is distance. This is a deliberate design decision, not merely a current practice.
The App cannot scan in the background. Scanning requires the camera permission you grant in iOS, which you may revoke at any time in iOS Settings — scanning stops working, and nothing else about your account changes.
2.3 Information collected automatically
| Category | Examples | Source |
|---|---|---|
| Server logs | IP address, request timestamps, request path, account identifier, response status | Our servers |
| Diagnostic files | Upload diagnostics and iOS performance/crash reports | Written to your device only. These stay on your phone; we do not collect or receive them |
We do not collect precise geolocation. We do not access your photo library, contacts, microphone, or health data (HealthKit). The App contains no analytics, advertising, attribution, or crash-reporting SDK of any kind.
2.4 Information from third parties
We currently receive no personal information about you from third parties. Anthroutfit does not process payments today; if that changes, this Policy will be updated before any payment feature ships.
2.5 California statutory categories
For California residents, this table maps our collection to the categories in Cal. Civ. Code §1798.140, and serves as our Notice at Collection.
| CPRA category | Do we collect it? | Examples |
|---|---|---|
| Identifiers | Yes | Email, IP address, account and profile identifiers |
| Customer records (§1798.80(e)) | Yes | Account information, profile details |
| Protected classifications | Gender, if you enter it; age only as an over/under-18 flag | Profile details, age attestation |
| Commercial information | No | — |
| Biometric information | We collect Body Scan Data and treat it as biometric-level information regardless of its technical classification | Mesh, measurements, depth captures (see Section 4) |
| Internet or network activity | Yes | Server logs |
| Geolocation data | No precise geolocation | Coarse region may be inferable from an IP address in logs; country is recorded for waitlist sign-ups |
| Sensory data | Yes — depth and body-outline data only, never photographs | Depth maps, confidence maps, body mask, skeleton joints |
| Professional or employment information | No | — |
| Education information | No | — |
| Inferences | Yes, narrowly | Clothing-fit and sizing estimates derived from your measurements |
| Sensitive personal information | Yes — Body Scan Data, treated as sensitive | See Sections 4 and 13 |
We collect each category for the purposes in Section 5, retain it per Section 8, and do not sell or share any category (Section 6).
3. Where Your Data Lives
A scan works like this: capture happens on your iPhone → the capture archive is uploaded to our backend → our fitting software derives your mesh and measurements → results are stored with your account and shown to you.
Concretely, your information is held in these places:
| What | Where |
|---|---|
| Account, profile, measurements, consent records | A managed PostgreSQL database hosted on Amazon Web Services infrastructure in the United States (us-east-2) |
| Your raw capture archive | Object storage operated by us on our own hardware |
| Your delivered avatar, preview image, and measurements file | Cloudflare R2 object storage, so your device can download them quickly |
| Website waitlist and support-form submissions | Cloudflare Workers KV |
| Server logs | Our backend servers |
| Website visit counts (cookieless, no device storage) | Umami, operated by Umami Software, Inc. |
The website itself is served by a Cloudflare Worker we operate, and form submissions are posted to that Worker and stored in Cloudflare Workers KV. No third-party form-handling service sits in that path. We do not use Netlify.
4. Body Scan & Biometric Data — Our Commitments
Body Scan Data receives our highest level of protection. This section supplements our Biometric Data Consent Notice, which we present and require you to accept before your first scan.
- Consent first, always. No scan is captured or processed until you have given express, informed, written consent through that notice. Our servers enforce this: until you have attested to being 18 and accepted the current Privacy Policy, Terms of Service, and Biometric Data Consent Notice, the scanning parts of the service refuse to operate for your account. We keep a record of each consent — account, document type, exact version, timestamp, IP address, and browser or app identifier — and those records are append-only: a new consent adds a row, it never overwrites the old one, so what you agreed to remains provable.
- Purpose limitation. We process Body Scan Data for exactly one purpose: generating your avatar and measurements so you can assess clothing fit. No other purpose. We do not use your Body Scan Data to train or improve models. Any new purpose would require fresh, separate consent, and this Policy would be updated first.
- Never sold, leased, traded, or otherwise profited from. Not to anyone, not in any form, not at any price.
- Never disclosed to insurers, employers, advertisers, or data brokers. We do not participate in any data marketplace.
- No identification or surveillance use. We do not use Body Scan Data to identify you or anyone else, to verify identity, or to track individuals. It exists to measure fit.
- No photographs. See Section 2.2. The system has no colour image of you to disclose, lose, or be compelled to produce.
- Withdrawal is immediate and permanent. If you withdraw your biometric consent, we erase the scans, meshes, and measurements for that profile straight away — not after a grace period. This is deliberately stricter than account deletion (Section 8): the account grace period exists so you can undo a mistake, and withdrawing consent to process your body data is not a mistake.
5. How We Use Your Information
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Deliver the core service: process your scan, generate your avatar and measurements, store your results | Body Scan Data, account information | Explicit consent (Art. 9(2)(a) standard applied) and contract (Art. 6(1)(b)) |
| Create and manage your account; authenticate you | Account information | Contract |
| Verify you are old enough to use the service | Age attestation | Legal obligation / contract |
| Record and prove that consent was given | Consent records | Legal obligation (Art. 6(1)(c)) and legitimate interests |
| Respond to support requests | Support communications, account information | Contract |
| Keep the service secure: throttle password guessing, detect abuse, diagnose failures | Server logs, account identifiers | Legitimate interests (Art. 6(1)(f)) — securing a service that handles sensitive data. You may object (Section 12); we apply access limits as a safeguard. |
| Tell you when the product opens in your area, if you asked us to | Waitlist email address | Consent |
| Answer a message you send our support inbox | Support form submission | Steps prior to a contract (Art. 6(1)(b)) / legitimate interests |
| Send service notices (security, terms changes, deletion confirmations) | Account information | Contract / legal obligation |
| Comply with legal obligations (tax, accounting, lawful requests) | The minimum category required | Legal obligation (Art. 6(1)(c)) |
What we never do: sell personal information; share it for cross-context behavioral advertising; use Body Scan Data for advertising or ad targeting of any kind; use it to train models; disclose it to insurers or employers; or use it to make decisions with legal or similarly significant effects about you (see Section 15).
6. How We Share Information
We share personal information only as follows, and in every case the recipient is contractually barred from using it for their own purposes:
- Service providers ("processors"). Vendors that perform work on our behalf: Cloudflare (website hosting, waitlist and support form storage, delivery of your avatar and measurement files), Neon (managed PostgreSQL, running on Amazon Web Services in the United States), and Apple (App distribution). Processors may access only the data needed for their function. We maintain no other processors today; this list will be updated before any new one is engaged.
- Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction — but the commitments in this Policy travel with the data and bind the successor, and we will notify you before your personal information becomes subject to a different privacy policy. The Body Scan Data commitments in Section 4 survive any such transaction.
- Legal compulsion. If we receive a subpoena, court order, warrant, or equivalent valid legal process, we disclose the minimum required. We review every request for validity and scope, we challenge overbroad requests where reasonably possible, and we notify you before disclosure unless legally prohibited from doing so.
- Protection of rights and safety. Where strictly necessary to prevent fraud against us, enforce our Terms, or protect the safety of a person — again limited to the minimum necessary.
- Aggregated or de-identified data. We may use and share aggregated statistics (for example, "median scan processing time") that cannot reasonably be linked to any person, and we never attempt to re-identify them.
We do not sell personal information and have not sold it in the preceding 12 months. We do not "share" personal information for cross-context behavioral advertising and have not done so in the preceding 12 months. (These sentences use the CCPA/CPRA statutory meanings of "sell" and "share.")
7. Cookies & Website Tracking
Our website sets no cookies at all — no advertising cookies, no analytics cookies, no third-party trackers. Nothing is written to your device: no cookie, no local storage, no session storage, no identifier of any kind. You can verify that yourself in your browser's developer tools.
We do count visits. We use Umami, a privacy-first analytics tool, to see how many people reach the site, which pages they read, and which link or campaign sent them. It records the page, the referring site, the browser and operating system in broad terms, and the country. Because Umami stores nothing on your device, it cannot recognise you on a later visit the way a cookie would, and it cannot follow you to any other website.
To avoid counting one person's visit several times within a day, Umami derives a temporary identifier by hashing details of the request together with a secret value that is rotated on a schedule. That identifier is not stored on your device, is not usable outside our own statistics, and stops matching you once the value rotates. Umami's own documentation describes the mechanism in full.
What Umami never receives: Body Scan Data, measurements, your email address, or the contents of any form you submit. When you join the waitlist we record that a signup happened, and which campaign it came from, so we can tell which message worked. We do not send who signed up.
No cookie banner, and that is not an oversight. The consent rules that require one apply to storing or reading information on your device. We do neither, so there is nothing to ask you to accept. The undertaking made in earlier versions of this Policy stands unchanged: if we ever add analytics or marketing cookies, we will deploy a consent mechanism first and update this section before those cookies are set.
We run no advertising, remarketing, or cross-site tracking of any kind, and we do not use Google Analytics, Meta Pixel, or any comparable product.
Form submissions are delivered by Cloudflare to a Worker we operate and stored in Cloudflare Workers KV; no third-party form-handling service sits in that path.
We honor opt-out preference signals, including Global Privacy Control (GPC) and Do Not Track (DNT). A DNT signal switches our visit counting off entirely, in every region, whether or not local law compels it. Because we set no cookies, sell nothing, and share nothing for cross-context behavioral advertising, there is little else for such a signal to switch off; we honor it regardless.
8. Retention & Deletion
We keep personal information no longer than needed for the purposes above, then delete it.
How to delete your data
- Delete your account. Request account deletion in the App or by emailing help@anthroutfit.com. The effect is immediate in the ways that matter: your sign-in stops working at once, and existing sessions cannot be renewed. Your data is then held for a 30-day grace period so you can ask us to restore it, after which it is permanently erased automatically — account, profiles, scans, meshes, measurements, and the copies in our object storage and on Cloudflare R2. If you take no action, you need do nothing further; erasure happens on its own.
- Delete a single scan. Deleting a scan removes its raw capture archive, its derived files, and its stored copies.
- Withdraw biometric consent. This erases that profile's scans, meshes, and measurements immediately and permanently, with no grace period (Section 4).
- Waitlist. To be removed from the waitlist, use the unsubscribe link in any email we send, or email help@anthroutfit.com. Unsubscribing suppresses further email; ask us and we will delete the record itself.
One honest limitation: an access credential already issued to your device remains technically valid until it expires, up to 24 hours. Sign-in and session renewal are blocked immediately on deletion, so the practical window is short, but we would rather state it than imply an instantaneous cut-off we do not deliver.
Retention periods
| Category | Retention period |
|---|---|
| Raw scan captures (depth, confidence, body mask, joints) | Until you delete the scan or your account, then erased with it. We do not currently run a shorter automatic expiry, and we will not claim one until it exists. |
| 3D mesh, measurements, avatar | Until you delete your account or withdraw biometric consent |
| Account and profile information | Life of the account; permanently erased 30 days after you delete it |
| Consent records | Retained while the account exists, as evidence that processing was authorized, and erased with the account |
| Deletion audit records | Retained after erasure as proof the deletion happened, with the link to your identity removed |
| Support communications | [2] years after the ticket closes |
| Waitlist sign-ups | Until you unsubscribe or ask us to delete the record |
| Waitlist consent evidence (IP, country, page path) | Held with the waitlist entry and erased with it |
| Unsubscribe suppression records | Kept indefinitely by design — the record exists so we do not mail you again, and deleting it would defeat that. Ask us and we will remove it, accepting that a future sign-up would then be possible |
| Server logs | Retained for operational and security purposes and not currently subject to an automatic expiry window. We are implementing one, and will state the period here when it is real. |
Where a legal hold, dispute, or regulatory obligation requires longer retention of a specific record, we retain only that record, only for the duration of the obligation, and only for that purpose.
9. Security
We protect personal information with safeguards proportionate to its sensitivity, and Body Scan Data is treated as our most sensitive class. Current measures include:
- Passwords are stored only as PBKDF2-HMAC-SHA256 hashes with 600,000 iterations and a random per-account salt. We never store, log, or transmit your password, and cannot recover it.
- Encryption in transit (TLS 1.2 or higher) for traffic between your device and our service, and between our service and our cloud processors.
- Access controls limiting production access to personnel who operate the processing pipeline.
- Brute-force protection: repeated failed sign-ins are throttled per account and per network address.
- Authorization checks on every endpoint that returns personal data, so one account cannot read another's measurements, scans, or profiles.
- An audited deletion path, so an erasure request is recorded and provable.
We are candid about the current limits: we do not yet offer multi-factor authentication, we do not yet apply application-layer encryption to individual database fields beyond password hashing, and we do not yet have a formally documented and rehearsed incident-response plan. These are on our roadmap and we will update this section as each lands rather than describe them before they exist.
No system is completely secure and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulators as applicable law requires, without undue delay, and tell you what happened, what data was involved, and what we are doing about it.
10. International Data Transfers
We are based in the United States and process data there; our database runs in the United States (Amazon Web Services, us-east-2). Cloudflare operates a global edge network, so website requests and delivered files may be routed through Cloudflare infrastructure outside the United States.
If you use our services from outside the U.S., your information is transferred to and processed in the U.S. Where GDPR or UK GDPR applies to a transfer, we rely on the European Commission's Standard Contractual Clauses (2021/914) with our processors, supplemented by the UK International Data Transfer Addendum for UK transfers, and on additional safeguards. You may request a copy of the relevant safeguards via the contact in Section 19.
11. Your Rights — Everyone
Regardless of where you live, we extend these baseline controls to every user:
- Access what we hold about you and get a copy;
- Correct inaccurate information;
- Delete your account and data (Section 8), or email help@anthroutfit.com;
- Withdraw any consent — biometric processing, marketing — as easily as you gave it;
- Complain to us and get a substantive answer.
We never discriminate against you — in price, quality, or availability of the service — for exercising a privacy right.
To request a copy of your data, email help@anthroutfit.com. We fulfil access and portability requests manually today; we will say so here for as long as that remains true rather than imply a self-service export that does not exist.
12. Your Rights — EU, EEA & UK (GDPR)
If you are in the EU, EEA, or UK, you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection — including to any legitimate-interests processing (Art. 21), and withdrawal of consent at any time without affecting prior processing (Art. 7(3)). We respond within one month, extendable by two further months for complex requests (we will tell you if so, within the first month, with reasons).
You also have the right to lodge a complaint with your local supervisory authority (the full list is at edpb.europa.eu; in the UK, the ICO at ico.org.uk). We would appreciate the chance to address your concern first, but you may go to the authority directly.
EU Representative: [EU REPRESENTATIVE — DECISION NEEDED if offering services to EU users without an EU establishment (GDPR Art. 27)] UK Representative: [UK REPRESENTATIVE — same decision under UK GDPR]
13. Your Rights — California (CCPA/CPRA)
13.1 Your rights
California residents may exercise, free of charge, up to twice in any 12-month period (deletion and correction are not so limited):
- Right to know/access: the categories and specific pieces of personal information we have collected about you, the sources, our purposes, and the categories of recipients — Sections 2, 5, and 6 provide these disclosures, and you may request an individualized report;
- Right to delete, subject to statutory exceptions (we will tell you if we rely on one, and which);
- Right to correct inaccurate personal information;
- Right to opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of — and we treat GPC signals as valid opt-outs anyway (Section 7);
- Right to limit use of sensitive personal information: we use sensitive personal information (Body Scan Data) only to provide the service you requested — never to infer characteristics about you beyond clothing fit, and never for model training. We honor limit requests regardless;
- Right to non-discrimination for exercising any right.
13.2 How to submit and what happens next
Email help@anthroutfit.com with the subject "California Privacy Request." We verify your identity by confirming control of the email on the account (and, where the request involves specific pieces of sensitive data, one additional account detail); we never require a government ID unless the law demands it. An authorized agent may act for you with your signed permission; we may still confirm the request with you directly. We confirm receipt within 10 business days and respond within 45 calendar days, extendable once by 45 days with notice. If we deny a request, we explain why, and you may appeal by replying to the denial; appeal outcomes come with an explanation and the contact for the California Privacy Protection Agency and Attorney General.
We do not use or disclose personal information for purposes incompatible with these disclosures, and we do not knowingly sell or share the personal information of anyone under 16 — our service is 18+.
California "Shine the Light" (Civ. Code §1798.83): we do not disclose personal information to third parties for their direct marketing purposes.
14. Your Rights — Washington & Other U.S. States
Washington (My Health My Data Act). To the extent your Body Scan Data qualifies as "consumer health data," you have the rights to: confirm whether we collect, share, or sell it (we never sell it); access it, including a list of the third parties and affiliates with whom we have shared it and an active email address for each; withdraw consent; and delete it. We collect and share consumer health data only with the consent described in our Biometric Data Consent Notice, and we do not and will not geofence any facility that provides health care services. Submit requests as in Section 13.2; appeals work the same way, and you may contact the Washington Attorney General if an appeal fails.
Nevada. Nevada residents may direct us not to sell covered information; we do not sell it, and you may register the direction anyway at help@anthroutfit.com.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws. You have substantially similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and significant profiling. We do not sell personal data, serve targeted advertising, or profile you in furtherance of decisions with legal or similarly significant effects, so those opt-outs are satisfied by default. Exercise any right per Section 13.2; where your state provides an appeal right, the appeal procedure in Section 13.2 applies.
Texas (CUBI) and Illinois (BIPA). Our biometric commitments — consent before capture, a published retention and destruction schedule, no sale or profit, disclosure only to processors — appear in Section 4 and in the Biometric Data Consent Notice, which is designed to satisfy the written-notice-and-consent requirements of those statutes.
15. Automated Processing
Generating your avatar and measurements is an automated computation — that is the product. But we make no decisions producing legal or similarly significant effects about you by automated means: no credit, insurance, employment, pricing, or eligibility decisions of any kind. Measurements are statistical estimates offered for clothing fit; they are not medical assessments (see our Terms of Service for the full disclaimer). If you believe an automated output about you is wrong, contact us and a human will review it.
16. Business Customers (When We Are a Processor)
If a retailer or other business gives you access to our technology under a contract with us, that business is the controller of its own customer data and its privacy notice governs that relationship; we process such data as its processor and route data subject requests to it. This Policy governs everything we do as a controller — including the consumer App and this website.
17. Age Requirement & Children
Anthroutfit is for adults aged 18 and over. This is not merely a statement of intent — it is enforced:
- At sign-up you must confirm your date of birth. We compute your age from it, record only whether you met the 18 threshold and when you attested, and discard the date of birth itself. There is no birthday stored anywhere in our systems.
- The check happens on our servers, not only in the app, so it cannot be bypassed by modifying the client.
- Until an account has completed that attestation and accepted the current Privacy Policy, Terms of Service, and Biometric Data Consent Notice, our servers refuse the scanning and measurement parts of the service for that account.
- If an account is found to be under 18, it is refused and removed.
We do not knowingly collect personal information from anyone under 18, and in particular not from children under 13 (COPPA). We do not knowingly sell or share personal information of consumers under 16. If you believe a minor has provided us personal information, contact help@anthroutfit.com; if we learn of such collection, we delete the data promptly and terminate the account.
18. Changes to This Policy
We will post changes here with a new effective date and version number. Because your acceptance is recorded against a specific version, a new version asks you to review and accept it before you continue using the scanning parts of the service — your earlier acceptance is preserved, not overwritten.
For material changes — any change to what we collect, why, how long we keep it, or who receives it — we give at least [30] days' advance notice by email or in-app notification before the change takes effect, and where a new purpose requires consent, we ask for it rather than assume it. No change will retroactively expand the use of Body Scan Data collected under an earlier version without your fresh, explicit consent.
19. Contact Us
Adam Tran, doing business as Anthroutfit 4739 Irvin Square, Alexandria, VA 22312, United States Privacy requests: help@anthroutfit.com Legal notices: help@anthroutfit.com
If you have a disability and need this Policy in an alternative format, contact us and we will provide it.
20. Version History
| Version | Date | Change |
|---|---|---|
| 2.0 | 2026-08-27 | Rewritten to describe Anthroutfit's actual operations. Removed content describing an unrelated video-production business. Corrected the hosting description (Cloudflare, not Netlify). Clarified that no photograph or video is ever captured. Removed claims of a model-improvement opt-in toggle, an in-app privacy settings screen, multi-factor authentication, application-layer encryption at rest, a rehearsed incident-response plan, and automatic time-based purge windows — none of which exist. Replaced them with the safeguards that do exist and an explicit statement of current limits. Added the enforced 18+ age requirement (Section 17) and the immediate effect of account deletion and consent withdrawal (Section 8). |
| 1.0 | — | Initial draft (never published) |