docs
  1. SCAYLE Extensions
  2. Virtual Try-on Add-on
  3. Data Privacy And Retention

Data Privacy and Retention

The Virtual Try-On Add-on processes customer photos, so it includes privacy controls at every step.

Every generation requires the customer to accept a consent notice before their photo is processed. The storefront passes the accepted consentVersion on the generate request. The consentVersion is handled and passed by the widget itself. The consent text, wording, and version is defined by SCAYLE.

For each generation, the Add-on records a consent entry that includes:

  • The consent version the customer accepted
  • The IP address at the time of acceptance
  • The user agent at the time of acceptance

Image Handling and Content Safety

The Add-on protects customer images as follows:

  • Sanitization on upload – the Add-on downscales the customer image to a maximum edge length, 1024 px by default, and processes it before it reaches the generation service. This reduces unnecessary data and upload size.
  • Time-limited access – generated images are never served from a public URL. They are available only through signed URLs that expire after a short time, 15 minutes by default.
  • Session lifetime – try-on sessions have a limited lifetime, 60 minutes by default. After that, the session is closed.

The Add-on also validates input images and runs content-safety checks on generations:

  • Unsuitable input images are rejected with the image_validation_failed error.
  • Generations that violate the safety policy are blocked with the content_blocked error.

Retention

The Add-on retains personal data only as long as needed:

  • Saved images – retained for 90 days by default, then deleted automatically. This applies only to registered customers, because guest customers can't save generated images.
  • Generation logs – retained for 180 days in production environments and 90 days in non-production environments by default.

Customer Anonymization

The Virtual Try-On Add-on listens to the customer-anonymized webhook (see customer-anonymized for more information). When a customer exercises their right to erasure in SCAYLE, the Add-on automatically anonymizes or removes the try-on data linked to that customer, in line with the erasure request.

Summary of Privacy-Relevant Defaults

These values are fixed to stay in line with active GDPR guidelines:

ControlDefault
Signed image URL lifetime15 minutes
Session lifetime60 minutes, for registered and guest customers
Saved image retention90 days, for registered customers
Generation log retention

180 days in production
90 days in non-production

Consent captured per generationYes, with consent version, IP address, and user agent
Customer erasureSupported through the customer-anonymized webhook