Lace Riot does not save your incoming personal photo, custom garment photo, or custom garment description as an image file, base64 string, or prompt in its database. To perform a virtual try-on, however, the photo is transmitted through the Lace Riot server and sent to fal.ai. The generated result is hosted externally and must remain available long enough to display and download it. We cannot promise that a provider URL will work indefinitely.
1. Who is responsible and what this policy covers
The business operating the Service under the Lace Riot name (“Lace Riot”, “we”, “us”) is responsible for the processing described in this policy. Privacy contact: contact@laceriot.com. We do not invent or publish a legal-entity name or postal address that has not been established; the relevant storefront and transaction records may provide additional operator details.
This policy covers laceriot.com, the Lace Riot mobile app, virtual try-on, visual product search, purchases, support, feedback, attribution, and technical events. Fal.ai, OpenAI, Apple, Google, hosting providers, and linked sellers may act as processors, service providers, contractors, or independent businesses depending on the activity and applicable law. A seller you open from a search result applies its own policy.
2. Information we process
| Category | Examples and source | Purpose |
|---|---|---|
| Photo of you | One photo you select from your library or take with the camera; only your own photo as an adult aged 18+ | Create the AI preview you request |
| Outfit reference | A selected catalogue image, or a garment-only image you choose for Custom Outfit | Virtual try-on; catalogue images may also be used for optional visual product search |
| Custom description | Up to 500 characters you enter to describe the garment or styling for a subscriber-only Custom Outfit request | Guide that one requested virtual try-on |
| Result and operations | Externally hosted result URL, outfit identifier, provider model, status, error, and timestamps | Display, history, credit accounting, support, security, and diagnostics |
| App identifier | A random app/device or account identifier; it is not Apple's advertising identifier | Balance, subscription state, limits, continuity, security, and abuse prevention |
| Purchases | Product ID, receipt or purchase token, transaction ID, entitlement, and credit count; not full card details | Verify, renew, restore, reconcile, and prevent duplicate crediting |
| Technical and attribution events | App version, platform, IP and request data visible to infrastructure, errors, conversion events, and limited Apple attribution data where available | Deliver, secure, diagnose, measure, and protect the Service |
| Feedback and contact | Rating, optional comment, technical context, email address, and message content you choose to send | Support, safety, dispute handling, and product improvement |
We do not require a profile containing your name, phone number, contacts, or precise location. If you email us, we necessarily receive your email address and message. A server, hosting provider, content-delivery network, or security service may receive IP address, user-agent, request timing, and related technical information.
3. Your photo, step by step
- Selection on your device. iOS or Android gives the app access to the photo you select or take, according to the system permission you grant.
- Preparation on your device. The app may resize, reformat, or compress the image and encode it for transmission.
- Encrypted transport. The app sends the person image over HTTPS with the random app identifier and either a selected catalogue outfit identifier or the custom garment image and description.
- Processing by Lace Riot. The server validates the request and handles the incoming person photo, custom garment image, and custom description in working memory. The Service code does not write those input images, base64 payloads, or the custom description to the Lace Riot database.
- Generation by fal.ai. The server sends fal.ai your photo, the selected catalogue or custom garment reference, and a server-generated instruction. For Custom Outfit, that instruction includes your bounded garment description as untrusted descriptive text. Fal.ai runs the configured model and creates a synthetic output.
- Provider storage control. Requests use
X-Fal-Store-IO: 0, which asks fal.ai not to enable persistent platform storage for the input/output payload. Fal.ai documentation explains that this does not automatically delete files from its CDN or eliminate security, legal, or infrastructure records. - Result URL. Fal.ai returns a URL for the generated image. Lace Riot stores the URL, status, model, error code if any, a catalogue outfit identifier or custom-outfit flag, and time—not the input prompt or a binary copy of the generated image in its database.
- Display and local saving. The app loads the image from the external URL. It is placed in your photo library only if you tap Save and grant the relevant system permission.
The provider-hosted result and technical, security, backup, or compliance copies may be subject to fal.ai's current rules and retention. We do not control or guarantee the expiry date of a particular URL. Save a result locally if you want to keep it, or contact us if you want to request deletion of associated records.
4. Product search does not receive your personal photo
When you run visual product search, the app sends OpenAI only the selected catalogue outfit image, trusted catalogue information, a search instruction, language or region context, and a one-way safety value derived from the random app identifier. Your personal try-on photo is not part of this request.
The request uses the OpenAI Responses API, web search, and store=false. That setting disables storage of the response object as application state; it is not a promise of zero logs. Under OpenAI's published API data controls, standard abuse-monitoring logs may generally be retained for up to 30 days, with longer or content-specific retention where law or safety review requires. API data is not used to train OpenAI models by default unless the API account owner opts in; Lace Riot does not opt in.
The response and cited links are returned to the app. The current implementation does not save the product-search response in the Lace Riot database. Once you open a result, the independent website processes information under its own privacy policy.
5. Organisations that may receive information
| Organisation | What it may receive | Role and information |
|---|---|---|
| fal.ai / Features & Labels, Inc. | Your photo, outfit image, instruction, output, and technical request data | AI media generation; privacy policy and I/O retention information |
| OpenAI | Outfit image without your personal photo, instruction, safety value, and technical data | Visual product search; API data controls |
| Apple | App Store receipt, transaction identifiers, and limited attribution information | Payment, entitlement, restoration, and attribution; Apple Privacy |
| Purchase token, product, and app package identifier | Google Play payment and entitlement; Google Privacy | |
| Hosting, CDN, and security providers | HTTP requests, IP address, technical identifiers, result delivery, and error logs | Operate, deliver, protect, and diagnose the Service |
We may also disclose information reasonably necessary to professional advisers, a successor in a genuine corporate transaction, or a competent authority when required by law or necessary to protect people, rights, safety, or Service integrity. We do not sell personal photos or use them for behavioural advertising.
6. Purposes and legal grounds
We process information only for the purposes described here: to perform your requested feature, manage purchases and credits, provide support, maintain security, prevent abuse and duplicate transactions, diagnose failures, comply with law, and establish or defend legal claims.
- United Kingdom: where UK GDPR applies, the main grounds are performance of a contract or steps you request, compliance with legal obligations, legitimate interests in security, fraud prevention, diagnostics, and legal claims after balancing interests, and consent where the law requires it.
- Canada: where PIPEDA or substantially similar provincial law applies, we rely on meaningful consent and other grounds permitted by law, limit collection to identified reasonable purposes, and permit withdrawal of consent subject to legal or contractual limits and reasonable notice.
- United States: we collect and disclose the categories listed in this policy for the stated operational, security, support, transaction, and legal purposes, including through service providers or contractors. State-law rights apply where the relevant law covers us and the request.
A face photo is personal information, but Lace Riot does not use facial recognition or process it to uniquely authenticate or identify you. The model analyses visual features to perform an image transformation. A photo can nonetheless reveal sensitive information, so upload only an ordinary, non-explicit fashion photo and do not submit material revealing health, intimate life, or other sensitive circumstances.
7. Retention
- Input photos and custom description in the Lace Riot database: not stored as image files, base64 payloads, or prompt text. Working-memory, transport, and short-lived infrastructure buffers may exist as needed to complete and protect the request.
- Generation record and result URL: retained while reasonably needed for history, balance, support, security, transaction integrity, and legal claims, or until a valid deletion request where no exception applies.
- fal.ai: we request disabled I/O storage through the header described above, but a result CDN file and data required for provider security or law may remain under the provider's current rules.
- OpenAI: product search uses
store=false; standard abuse-monitoring retention and documented exceptions may still apply. - Purchase and transaction records: retained as needed for store reconciliation, accounting or tax requirements, fraud prevention, and legal claims.
- Support and feedback: retained while handling the request, improving and protecting the Service, and managing legal claims; unnecessary sensitive attachments may be removed sooner.
We do not state one fictional deadline for every record. Where a fixed period is not appropriate, we use criteria including account/app activity, entitlement validity, technical purpose, abuse risk, applicable limitation periods, provider dependencies, and legal obligations.
8. International processing
Providers may be located or operate infrastructure outside your country, including in the United States. Information may therefore be processed in jurisdictions with different privacy laws and may be available to local authorities under lawful process. Where UK transfer rules apply, we use an available legal mechanism such as adequacy regulations, approved contractual safeguards, or another permitted basis. Canadian users understand that service providers outside Canada may process information under foreign law. We apply contractual and technical safeguards where appropriate and available.
9. Your privacy choices and rights
Depending on your location, the law, and the processing involved, you may have rights to know or access information, receive a copy, correct inaccurate information, delete information, restrict or object to processing, obtain portability, withdraw consent, opt out of certain uses, and appeal a refusal. Exceptions may apply for security, legal compliance, transaction records, another person's rights, or legal claims.
Email contact@laceriot.com with “Privacy request” in the subject. Include the random app identifier from Settings if available; it helps locate records without asking for your name. We may request proportionate verification so that we do not disclose or delete the wrong person's information. Do not send your photo, password, full card number, or sign-in code for verification.
You may use an authorised agent where applicable law permits, subject to verification of authority and identity. We will not discriminate against you for exercising a privacy right. If we deny a request, we will explain the reason and any available appeal unless law prevents that disclosure.
- UK: rights may include being informed, access, rectification, erasure, restriction, objection, and portability. You may complain to the Information Commissioner's Office.
- Canada: you may request access and challenge the accuracy or completeness of personal information, withdraw consent subject to lawful limits, and challenge compliance. You may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial regulator.
- United States: covered state laws may provide rights to know, access, delete, correct, obtain portability, opt out, limit certain sensitive-data uses, and appeal. You may also contact your state attorney general or privacy authority.
10. United States notice at collection
During the preceding 12 months, the Service may have collected the categories described in Section 2: identifiers and network activity, commercial and transaction records, user-provided photos and related visual information, generated-result metadata, app events, feedback, and support communications. Sources are you, your device, Apple or Google transaction systems, our providers, and normal Service interactions. Purposes and recipient categories are described in Sections 5 and 6.
We do not sell personal information for money. We do not “sell” or “share” personal information for cross-context behavioural advertising, and we do not use personal photos for targeted advertising, as those terms are defined by applicable US state privacy laws. We have no actual knowledge that we sell or share personal information of anyone under 18; the Service prohibits all use by minors.
11. Automated processing
Generation and product matching are automated, but they are not intended to make a decision producing legal or similarly significant effects about you. A safety rule, rate limit, credit check, or provider filter may automatically reject a request. Contact Support if you believe a block is mistaken.
We do not use your photo to decide credit, employment, insurance, healthcare, identity verification, emotion, attractiveness, or another high-impact matter.
12. Adults only and no third-party photos
The Service is for adults aged 18 and older. You may upload only your own photo. If you believe a child or another person was uploaded without authority, contact us immediately with technical context, but do not resend or distribute the image. We will respond according to the credibility of the report, applicable law, safety needs, and our ability to identify the record.
13. Security and its limits
Measures include HTTPS transport, server-side API keys, request validation, rate limits, pseudonymous identifiers, and data minimisation. No system is completely secure. Do not upload material whose disclosure could cause you serious harm; an ordinary, clothed fashion photo is sufficient for virtual try-on.
If you suspect a security incident, email contact@laceriot.com promptly without attaching a sensitive file.
14. Website, device storage, and analytics
The current public website does not set its own marketing cookies or include behavioural-advertising trackers. Hosting and security infrastructure may create necessary request logs. The mobile app stores settings, a random identifier, and operational information locally. You control camera, photo-library, and notification permissions in your device settings.
15. Changes and contact
We may update this policy as the Service, providers, or laws change. We will update the effective date and provide additional notice where a change materially affects your rights and the law requires it. Questions, requests, and complaints: contact@laceriot.com. See the Terms and Support page for related information.