Data Privacy and Retention
The Virtual Try-On Add-on processes customer photos, so it includes privacy controls at every step.
Consent
Every generation requires the customer to accept a consent notice before their photo is processed. The storefront passes the accepted consentVersion on the generate request. The consentVersion is handled and passed by the widget itself. The consent text, wording, and version is defined by SCAYLE.
For each generation, the Add-on records a consent entry that includes:
- The consent version the customer accepted
- The IP address at the time of acceptance
- The user agent at the time of acceptance
Image Handling and Content Safety
The Add-on protects customer images as follows:
- Sanitization on upload – the Add-on downscales the customer image to a maximum edge length, 1024 px by default, and processes it before it reaches the generation service. This reduces unnecessary data and upload size.
- Time-limited access – generated images are never served from a public URL. They are available only through signed URLs that expire after a short time, 15 minutes by default.
- Session lifetime – try-on sessions have a limited lifetime, 60 minutes by default. After that, the session is closed.
The Add-on also validates input images and runs content-safety checks on generations:
- Unsuitable input images are rejected with the
image_validation_failederror. - Generations that violate the safety policy are blocked with the
content_blockederror.
Retention
The Add-on retains personal data only as long as needed:
- Saved images – retained for 90 days by default, then deleted automatically. This applies only to registered customers, because guest customers can't save generated images.
- Generation logs – retained for 180 days in production environments and 90 days in non-production environments by default.
Customer Anonymization
The Virtual Try-On Add-on listens to the customer-anonymized webhook (see customer-anonymized for more information). When a customer exercises their right to erasure in SCAYLE, the Add-on automatically anonymizes or removes the try-on data linked to that customer, in line with the erasure request.
Summary of Privacy-Relevant Defaults
These values are fixed to stay in line with active GDPR guidelines:
| Control | Default |
|---|---|
| Signed image URL lifetime | 15 minutes |
| Session lifetime | 60 minutes, for registered and guest customers |
| Saved image retention | 90 days, for registered customers |
| Generation log retention | 180 days in production |
| Consent captured per generation | Yes, with consent version, IP address, and user agent |
| Customer erasure | Supported through the customer-anonymized webhook |