← ReelMachi

Privacy Policy

Last updated 28 July 2026

Before you publish: replace [LEGAL ENTITY], [REGISTERED ADDRESS] and [GOVERNING JURISDICTION] throughout this document, and confirm the support address below is monitored. These are the only facts on this page I could not determine from the codebase.

ReelMachi is a virtual try-on app. This policy explains exactly what we collect, what happens to your photos, and who else touches your data. It describes how the app actually behaves, not an aspiration.

The short version

What we collect

Data Why How long we keep it
Email address To create your account and sign you in with a one-time code. There is no password. Until you delete your account.
Generation photos The person and garment photos for a single try-on or edit, so the AI model can produce your image. Deleted as soon as the generation is delivered. A cleanup job removes anything abandoned within the hour, and storage-level expiry removes anything remaining within one day.
Generated images Returned to your device and saved locally by you. Deleted from our storage once your device confirms it has saved the image, and in any case within the hour.
Account & plan record Your plan, remaining credits and renewal date, so the app knows what you are entitled to. Until you delete your account.
Usage counts Per generation: the mode used, how many images were involved, credits charged and our provider cost. Used for capacity and pricing. No image data is recorded. Until you delete your account.
Purchase records Which product you bought and when, so entitlements and refunds reconcile correctly. Until you delete your account, subject to any tax or accounting retention we are legally required to observe.
Feedback & feature requests Only if you choose to send them. Feature requests and their vote counts are visible to other users once approved; feedback is private to us. Until you delete your account.

We do not use advertising identifiers, third-party analytics SDKs, or cross-app tracking. We do not build advertising profiles.

What happens to a photo, step by step

  1. You pick a photo of yourself and one or more garments. Both are read from your device's local app storage.
  2. The app requests short-lived, single-purpose upload links and sends the images directly to private encrypted storage. The links expire after five minutes.
  3. Our server passes time-limited read links to our AI provider, which generates your image and writes it back to the same private storage.
  4. The source photos are deleted immediately once the model has finished with them.
  5. Your device downloads the result and saves it locally. Your device then tells our server, which deletes the generated image from storage.
  6. Anything left behind by an interrupted generation is removed by an hourly cleanup job, backed by a one-day storage expiry rule.
Our servers never store or forward the image bytes themselves — images travel directly between your device, our private storage, and the AI provider, using links that expire.

Who else processes your data

Provider What they handle
Cloudflare Hosts our API and the private, short-lived storage that generation images pass through.
InstantDB Stores your account, plan and usage records, and sends your sign-in codes.
Runware Runs the AI models that produce your try-on and edited images.
RevenueCat Manages subscription state and tells us when a purchase, renewal, refund or cancellation happens.
Apple / Google Process all payments. We never receive your payment details.

These providers act on our instructions and may process data outside your country. We do not sell your personal information.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing.

One record intentionally survives account deletion: a one-way fingerprint of your email address, kept solely to record that the mailbox has already used its one free trial. It cannot be reversed into your address and is never used to contact you.

Children

ReelMachi is not directed at children and is not intended for anyone under 13 (or the minimum age of digital consent where you live, if higher). If you believe a child has given us personal data, contact us and we will delete it.

Security

All traffic uses TLS. Sign-in tokens are held in your device's hardware keychain. Storage links are cryptographically signed, scoped to a single object and expire in minutes. Access to production data is limited to administrators.

No system is perfect. If you find a security issue, please report it to the address below and we will act promptly.

Changes

If we change this policy materially we will update the date above and, where the change is significant, notify you in the app.

Contact

[email protected]
[LEGAL ENTITY], [REGISTERED ADDRESS]