StyTrix ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered fashion design platform.
1. Information We Collect
Personal Information
When you register for an account, we may collect:
- Name and email address
- Company or organization name
- Job title
- Payment information (processed securely through third-party providers)
Usage Information
We automatically collect certain information when you use our platform:
- Device and browser information
- IP address and location data
- Usage patterns and feature interactions
- Design assets you create and upload
Analytics & Session Replay
We use analytics tools (including PostHog) to understand how our platform is used. This includes session replay, which records interactions such as clicks, scrolling, page navigation, and text you type into the platform (for example, prompts entered in the AI assistant). Passwords are always masked and never recorded, and payment details are entered on our payment provider's secure pages, which are not recorded. For visitors who are not signed in, this data is collected anonymously. When you sign in, we associate this data — including session replays — with your account identifier, email address, and name so we can diagnose issues, provide support, and improve your experience. You can learn more about the cookies involved and how to manage them in our Cookie Policy.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send promotional communications (with your consent)
- Respond to your comments, questions, and requests
- Monitor and analyze usage trends to improve user experience
- Detect, prevent, and address technical issues and security threats
3. Your Design Content
You maintain full ownership of all designs you create on StyTrix.
We do not use your design content to train our AI models without your explicit permission. Your creative work remains your intellectual property.
We may access your content only to provide the services you request, ensure platform security, or comply with legal obligations.
4. Data Security
We implement enterprise-grade security measures to protect your information:
- Encryption of data in transit and at rest
- Regular security audits and assessments
- Access controls and authentication measures
- Secure cloud infrastructure with leading providers
5. Data Sharing
We do not sell your personal information. We may share your information with:
- Service providers who assist in operating our platform
- Business partners with your consent
- Legal authorities when required by law
6. Third-Party AI Agents & MCP Connectors
StyTrix offers a Model Context Protocol (MCP) server that lets you connect third-party AI assistants — such as Claude.ai, Claude Code, and Cursor — to your StyTrix account. See our MCP documentation for details.
- Access is granted only through OAuth 2.1 sign-in and can be revoked by you at any time.
- A connected agent acts solely on the account you authorize and can only use the documented tools.
- Prompts and images you send through a connected agent are processed to fulfil your request and may be shared with the AI provider operating that agent and with our generation providers.
- We do not sell this data and do not use your design content to train our models without your explicit permission.
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability
- Withdraw consent at any time
Most of these rights can be exercised directly from your account: open Dashboard → Privacy to manage analytics and marketing consent or to delete your account. See section 11 for how to submit any other request.
8. Legal Basis for Processing
Where the GDPR or a similar law applies, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Creating your account, storing your projects and designs, running AI generation you request, processing payments | Performance of a contract (Art. 6(1)(b)) |
| Keeping billing and tax records, responding to lawful requests from authorities | Legal obligation (Art. 6(1)(c)) |
| Securing the platform, preventing abuse and fraud, diagnosing errors, aggregated product analytics | Legitimate interests (Art. 6(1)(f)) — you may object at any time |
| Session replay linked to your account, marketing emails, non-essential cookies | Consent (Art. 6(1)(a)) — withdraw in Dashboard → Privacy or via the unsubscribe link |
For users in Taiwan we process personal data in accordance with the Personal Data Protection Act (個人資料保護法), including its requirements on notice, purpose limitation and the rights of data subjects.
9. How Long We Keep Your Data
We keep personal data only as long as needed for the purpose it was collected for, and then delete or anonymise it. Our main retention periods are:
| Data | Retention |
|---|---|
| Account profile, projects, canvases, generated images and videos, custom models | For as long as your account exists; deleted when you delete your account |
| Billing, invoice and tax records | 7 years after the transaction, as required by tax and accounting law |
| Free-trial and newsletter sign-ups that never became an account | 90 days after the last interaction |
| Raw product analytics events and session replays | Up to 13 months; aggregated statistics without personal data are kept longer |
| AI request traces used for debugging and cost monitoring | Up to 90 days |
| Security and administrative audit logs | 12 months online, then archived for up to 3 years |
| Encrypted backups | 30 days on a rolling basis; deleted data disappears from backups within that window |
| Service health checks and operational logs | 30 days, or the retention period of the hosting provider |
Blog posts, prompt libraries and other platform content authored by our staff are not personal data of our users; if the author's account is deleted, the content is kept and the author reference is anonymised.
10. Subprocessors
We rely on a small number of third-party providers to host the platform, process payments, send email, and run the AI models behind our tools. The full list of these providers, what they process and where they are located is published on ourSubprocessors page. Enterprise customers with a data processing agreement are notified before a new subprocessor starts processing their data.
11. Exercising Your Rights (Data Subject Requests)
Delete your account yourself
Go to Dashboard → Privacy and chooseDelete account. After you confirm, we erase your profile, projects, canvases, generated media and usage data across all of our systems, keep only the billing records we are legally required to retain, and remove your sign-in. Deletion is permanent and cannot be undone.
Other requests
To access, export, correct or restrict your data, or to object to processing, emailprivacy@stytrix.com (orhello@stytrix.com) from the address linked to your account. Please tell us which right you are exercising. We may ask you to confirm your identity before acting.
- We acknowledge every request within 5 business days.
- We complete requests within 30 days. Where a request is complex, we may extend this once by a further 30 days and will tell you why.
- Exports are provided as machine-readable files (JSON) covering the data we hold about you. Signed-in users can download one directly from Dashboard → Privacy → “Download my data”.
- Requests are free of charge unless they are manifestly unfounded or excessive.
If you believe we have not handled your request correctly, you may lodge a complaint with the data protection authority in your country. Security researchers can reach us atsecurity@stytrix.com.
12. International Data Transfers
StyTrix is headquartered in Taiwan. Your information may be transferred to and processed in Taiwan or other countries where our service providers operate — principally the United States, where most of our subprocessors are located. Where required, we rely on the European Commission's Standard Contractual Clauses or equivalent safeguards for such transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
14. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: privacy@stytrix.com