SnapFyt ("we," "our," or "us") helps you find clothing and accessories visible in a photo. This policy explains what we collect, why we collect it, how it's used, who it's shared with, and the choices you have. We've structured it to match Apple's App Privacy Details categories so it's easy to cross-reference what you see on the App Store nutrition label.
The short version: we use the photo you upload to find matching products, we ask for App Tracking Transparency (ATT) consent after your first search so we can measure our own ads on Meta and TikTok, and we send those ad platforms events like "installed" and "started trial" — never your photos, your searches, or your account details. See §3 for who receives what, §5 for how to opt out, and §8 for CCPA/CPRA rights. SnapFyt is currently available in the United States and Canada.
Below is everything SnapFyt collects, organized by Apple's data-type categories.
| Apple category | What it means for SnapFyt | Linked to you |
|---|---|---|
| Contact Info | Email address (required for sign-in). First/last name (optional). Instagram handle (optional — used as your public display name in the SnapFyt Feed). | Yes |
| User Content | Photos you upload to search, the search regions you draw, comments you write on shared sessions, your profile picture (if you upload one). | Yes |
| Identifiers | An internal account ID we generate when you sign up. Apple's Identifier For Vendor (IDFV) — an anonymous, vendor-scoped device identifier used to attribute launch telemetry and analytics events to a single install; it is not shared across other developers' apps, and it resets when you delete our apps. Apple's Advertising Identifier (IDFA) — used only if you grant App Tracking Transparency ("ATT") consent when we ask; used for ad measurement (see §3). You can revoke consent at any time in iOS Settings → Privacy & Security → Tracking. Apple's AdServices attribution token — a short-lived Apple-issued token, exchanged once on your first launch with Apple's servers to determine whether you installed SnapFyt from an Apple Search Ads campaign. Not an advertising profile, not linked across apps, and exempt from ATT per Apple's own framework. | Yes |
| Location | Coarse country, region, and city derived from your request IP address when you launch the app or click a SnapFyt short link (e.g., snapfyt.app/…). We do not request GPS location, and we do not access your device's location services. | Yes (tied to your account when signed in; anonymous otherwise) |
| Usage Data | Which searches you ran, which results you tapped, who you follow, what you saved or liked. Used to power Feed ranking, History, and Saved. | Yes |
| Search History | The photos, regions, attributes, and results from each session you save. Visible to you in History; visible to others only if you set the session to Public or Friends. | Yes |
| Diagnostics | iOS version, device model, app version, and error messages — sent when the iOS app encounters an error, so we can debug. We do not capture screen recordings or arbitrary device data. | Yes (tied to your account if signed in; anonymous otherwise) |
| Optional Profile Info | Gender (optional, used for fashion recommendations) and IG handle (optional). | Yes |
| Purchases | Your SnapFyt subscription status (trial / active / expired), the plan you chose (Monthly or Annual), and the Apple transaction identifier, received from Apple when you start a free trial or subscribe. We never see or store your card or payment details — Apple processes all payments via In-App Purchase. | Yes |
We do not:
The third parties we hand data to are limited to the providers that power SnapFyt's core function:
| Provider | What we send | Why |
|---|---|---|
| Anthropic (Claude API) | The cropped image region you tag, plus a short text prompt. | Visual description & attribute extraction. |
| SerpAPI | The same cropped region's URL or extracted text query. | Google Lens / Google Shopping lookups for matching products. |
| Resend | Your email address, when you trigger a password reset. | Send the reset email. |
| Microsoft Azure | All API traffic, since SnapFyt's backend runs on App Service. | Hosting. |
| Affiliate networks & retailers | An affiliate tracking code (and standard web request data your device sends, e.g., IP, when you follow the link) | Attribute purchases so we earn commission. Each retailer/network has its own privacy policy we don't control. |
| Meta (Facebook / Instagram advertising) | Conversion event names (e.g., "install," "registration," "trial start," "subscription purchased"), your IDFA (only with ATT consent), IDFV, and standard app + device metadata their SDK collects. | Measure which Meta ads produced SnapFyt installs and paid conversions. Governed by Meta's privacy policy. |
| TikTok (TikTok for Business advertising) | Same shape as Meta above. | Measure which TikTok ads produced SnapFyt installs and paid conversions. Governed by TikTok's privacy policy. |
| Apple (AdServices attribution API) | The AdServices attribution token issued to your device on first launch. Exchanged once with Apple's servers; not stored past exchange. | Determine whether your install came from an Apple Search Ads campaign. Apple's own framework; ATT-exempt per Apple's documentation. |
Our service providers — Anthropic, SerpAPI, Microsoft Azure, and Resend — process personal data only on our instructions, under agreements that require them to protect it to a standard equal to this policy. They may not use your data for their own purposes, including training AI models.
Our advertising partners — Meta and TikTok — receive the conversion events listed above under their own privacy policies. They do not receive your name, email address, photos, search history, comments, or the contents of any session. If you decline (or revoke) App Tracking Transparency consent, their SDKs still initialize (which iOS requires) but do not receive your IDFA, and the events sent contain significantly less linkable information.
Anthropic and SerpAPI do not retain submitted images after our request is processed; images are used solely to generate the search result returned to you.
None of these are given access to your account password, your friends list, or your private (non-public) sessions for any purpose other than fulfilling the request you made.
You must be at least 13 to use SnapFyt. If you are in the EU or UK, you must be at least the age of digital consent in your country (between 13 and 16). We do not knowingly collect personal information from anyone below the applicable age. Because SnapFyt includes public social features (the Feed, public sessions, comments, and display names), we strongly discourage minors from creating public profiles. If you believe someone under the applicable age has provided us information, email privacy@snapfyt.com and we will delete it.
Passwords are stored as bcrypt hashes, never as plaintext. All API traffic between the SnapFyt app and our backend is sent over HTTPS / TLS. Cookies are HTTP-only with SameSite protection. The database is hosted on a private network and is not internet-reachable.
That said: no system is unbreakable. If a breach occurs that affects your account, we'll notify you by email within 72 hours of discovery as required by applicable regulations.
SnapFyt is currently available in the United States and Canada. If you are a California resident, you have rights including access, correction, deletion, portability, the right to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising, and the right not to be discriminated against for exercising them. To exercise any of these, email privacy@snapfyt.com from the address associated with your account.
"Sharing" for cross-context behavioral advertising. To measure the performance of our advertising on Meta and TikTok, SnapFyt transmits conversion events (such as install, registration, trial start, and subscription purchase) to those platforms. Under the California Privacy Rights Act ("CPRA"), this transmission may constitute "sharing" of personal information for cross-context behavioral advertising. We do not sell personal information for money. To opt out of this sharing, email privacy@snapfyt.com with the subject "Do Not Share My Info" (see §5). Declining or revoking App Tracking Transparency consent in iOS also substantially reduces what these platforms receive.
Canadian residents (PIPEDA). You have similar rights of access, correction, and withdrawal of consent for personal information we hold about you. Use the same email address to exercise them.
International transfers. Our processors (Anthropic, SerpAPI, Microsoft Azure, Resend) and our advertising partners (Meta, TikTok, Apple) may process data in the United States and, in some cases, in other jurisdictions where they operate. Where we transfer Canadian personal data outside Canada, we rely on our contracts with these processors and the safeguards required by PIPEDA.
If you are outside the United States and Canada, SnapFyt is not currently offered in your App Store storefront and this policy does not describe processing of your data. Any expansion into additional territories will be accompanied by a review of applicable local privacy law before the app becomes available.
If we make material changes, we'll update the "Last updated" date at the top and, for significant changes, post an in-app notice the next time you sign in. Continued use after a change means you accept the revised policy.
Questions, data requests, or anything else about this policy: privacy@snapfyt.com