Privacy Policy
Version 1.0 · Effective date: July 15, 2026 · Last updated: August 18, 2026
This policy explains how Fitable SL ("Fitable", "we", "us") collects and uses personal data when you use fitable.es and the Fitable services (the "Services"). It is written to meet the requirements of the EU General Data Protection Regulation ("GDPR"), including the information duties of Articles 13 and 14, and Spain's Organic Law 3/2018 on Data Protection and Digital Rights ("LOPDGDD").
Fitable is an AI-powered product-photography and social-content platform for fashion e-commerce brands. Most of our customers are businesses, but this policy applies to every user of the Services, including individual consumers.
We have tried to keep this policy short and readable. If anything is unclear, write to us at fitable.ai@gmail.com — we would rather answer a question than hide behind fine print.
In short:
- We collect what we need to run your account, process your content through our AI pipeline, and bill you — nothing more.
- We never sell your data, and we never use your content to train our own AI models.
- Analytics and marketing email run only with your consent.
- Your card number lives with Stripe, not with us.
- We are established in Spain; some of our providers process data in the United States, protected by the EU-US Data Privacy Framework and Standard Contractual Clauses.
- You have the full set of GDPR rights, exercised free of charge via fitable.ai@gmail.com.
The sections below are the legally complete version of those promises.
1. Who is responsible for your data
The controller of your personal data is:
- Fitable SL, a limited company (sociedad limitada) incorporated in Spain
- Registered address: Carrer de Sant Antoni Maria Claret 362, 08041 Barcelona, Spain
- Privacy contact: fitable.ai@gmail.com
We have not appointed a Data Protection Officer, because one is not mandatory for our processing profile. All privacy matters are handled by our privacy contact at the address above, and that contact is the fastest route for any question or request under this policy.
2. Where we are established
Fitable SL is established in Spain. The GDPR therefore applies to us directly as a controller based in the European Union, and we are not required to appoint a representative in the Union under Article 27 GDPR. Our lead supervisory authority is the Spanish Data Protection Agency (AEPD); section 13 explains how to lodge a complaint with it.
3. What data we collect from you
Data you give us
- Account data — name, email address, password (stored only as a salted hash), language and workspace preferences.
- Business details — brand name, storefront URL, and other information you provide about your brand.
- Uploaded content — product photos, brand assets, reference images and any other files you upload for processing.
- Brand and social data — sources you connect or point us to, such as your storefront catalogue or your Instagram handle (see section 4 for third-party data these may contain).
- Support communications — messages you send to fitable.ai@gmail.com and related correspondence.
Data collected automatically
- Usage data — how you interact with the Services: features used, generations run, pages visited, and settings chosen.
- Device and connection data — browser type, operating system, screen characteristics, IP address, and the approximate location derived from the IP address.
- Log data — server and security logs recording requests, errors and authentication events.
Payment data
- Payment metadata — plan, purchase and invoice history, billing country, and the last digits and brand of your card.
- Full card data is collected and handled by Stripe, our payment processor. Fitable never stores your card number.
4. Data we obtain from public sources and connected platforms
This section is our information notice under Article 14 GDPR for personal data we do not collect from the person it relates to.
When you ask Fitable to import your storefront or analyze an Instagram feed, we retrieve content from those sources: product listings, images, captions, and public feed posts. That content can incidentally include personal data of third parties — for example, models appearing in photos, customers pictured in user-generated content, or account names of people who commented on public posts.
- Categories of data — images of people, names or handles visible in public posts, and text associated with public content.
- Sources — the storefront or website you connect, and publicly accessible Instagram profiles or feeds you identify to us.
- Purpose and legal basis — deriving your brand's visual style, composition patterns and content profile so we can generate on-brand imagery and planning suggestions (legitimate interest of our customer in analysing their own brand presence, Article 6(1)(f) GDPR).
- What we do not do — we do not use this content to identify individuals, we do not build profiles of the people who appear in it, we do not contact them, and we do not share it with third parties for their own purposes.
Providing an individual privacy notice to every person who may appear in public brand content would involve disproportionate effort within the meaning of Article 14(5)(b) GDPR. This publicly available policy therefore serves as the information notice for those data subjects. Any such person may contact fitable.ai@gmail.com to exercise the rights described in section 13, including objection and erasure.
5. Why we process your data and on what legal basis
We process personal data only for the purposes below, each matched to a legal basis under Article 6 GDPR:
- Providing your account and the Services (registration, authentication, workspace management, content storage, customer support) — performance of a contract, Article 6(1)(b).
- AI generation processing (running your uploads and instructions through our AI pipeline to produce the imagery you request) — performance of a contract, Article 6(1)(b).
- Payments, invoicing and accounting records — compliance with legal obligations, Article 6(1)(c), including Spanish tax and commercial-record requirements.
- Product analytics via PostHog (understanding feature usage to improve the product) — your consent, Article 6(1)(a). Analytics runs only if you consent, and you can withdraw at any time.
- Marketing email (news, tips, offers) — your consent, Article 6(1)(a). Every message includes an unsubscribe link, and unsubscribing takes effect immediately.
- Security, fraud and abuse prevention (log analysis, rate limiting, detecting misuse of the AI features) — our legitimate interest, Article 6(1)(f), in keeping the Services secure, protecting our users, and preventing fraudulent or abusive use of the platform.
- Establishing, exercising or defending legal claims — our legitimate interest, Article 6(1)(f), in protecting our legal position.
If we ever need to process your data for a new purpose not covered above, we will inform you first and, where required, ask for your consent.
6. AI features and how your content is processed
The following features of Fitable are AI-powered:
- Scene and model image generation, including virtual try-on style imagery.
- Storefront import and brand-profile analysis.
- Public Instagram feed analysis.
- Content-planning and posting suggestions derived from your brand profile.
How this processing works:
- The people shown in generated imagery are synthetic, AI-generated models — they are not real persons, unless you yourself upload imagery of real people.
- When you run a generation, your selected images and instructions are sent to our AI model providers — Google (Gemini image models) and fal.ai — which act as our processors and return the generated result. Text you provide (brand descriptions, product details, captions and planning instructions) may also be sent to OpenAI, which acts as our processor for text analysis, planning suggestions and content-safety screening.
- Where technically possible, generated images carry machine-readable markings identifying them as AI-generated, consistent with Article 50 of the EU AI Act, and we preserve those markings through our pipeline.
- Fitable does not use your content to train its own AI models. Our agreements with our model providers limit them to processing your content in order to deliver the generation you requested.
7. Imagery of real people
Content you upload, and public feeds we analyze at your request, may incidentally contain images of real people. We process such imagery to derive style and composition — lighting, framing, palette, mood — and not to uniquely identify anyone.
- We do not perform biometric identification.
- We do not build face-recognition profiles or databases.
- We do not match faces across accounts, sources or the open web.
As set out in our Terms of Service, you warrant that you hold the necessary rights, releases and consents for any real people depicted in content you upload.
8. Signing in with Google
If you sign in with Google, we receive your name, email address and basic profile information from your Google account. We use this data only to create and operate your Fitable account. We do not request access to your Gmail, contacts, calendar or files.
Fitable's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your consent, for security purposes, or to comply with the law.
9. Who we share data with
We share personal data with the following service providers (sub-processors), each bound by a data-processing agreement under Article 28 GDPR that restricts them to processing on our documented instructions:
- Vercel — application hosting and content delivery.
- Neon (EU region) — managed Postgres database that stores your account, workspace and content records.
- Upstash (EU region) — managed Redis for sessions, caching and rate limiting.
- Google — OAuth sign-in, Google Cloud Storage (EU region) for the images you upload and we generate, and Gemini AI image-generation models.
- fal.ai — AI image generation.
- OpenAI — AI text analysis, planning suggestions and content-safety screening of the text you provide.
- Apify — retrieval of the public social-media feeds you ask us to analyse (see section 4).
- Stripe — payment processing. For certain fraud-prevention and regulatory-compliance processing, Stripe acts as an independent controller under its own privacy policy.
- Sentry — error monitoring, so we can detect and fix failures in the Services (technical event data, which may include your user identifier and IP address).
- PostHog (EU-hosted) — product analytics (only if you have consented to analytics).
- Resend — transactional email delivery (sign-in emails, receipts, service notices).
Beyond these providers, we may disclose data:
- Where required by law, regulation or a valid legal request.
- To protect the rights, property or safety of Fitable, our users or the public.
- In connection with a merger, acquisition or asset sale — in which case we will notify you before your data becomes subject to a different privacy policy.
We do not sell personal data, and we do not share it with third parties for their own marketing.
10. International transfers
Fitable SL is established in Spain. Some of the providers listed in section 9 process personal data in the United States.
For transfers from the EU/EEA we rely on the following safeguards:
- The EU-US Data Privacy Framework, where the recipient holds a current certification under it.
- The European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented with additional measures where needed, as the fallback mechanism for recipients not covered by a certification.
You can request a copy of the applicable safeguards by writing to fitable.ai@gmail.com.
11. How long we keep your data
We keep personal data only as long as needed for the purpose it was collected for, and then delete or block it:
- Account data — for the life of your account; after account deletion, blocked until the statutory limitation periods for legal claims have lapsed (LOPDGDD Article 32), then erased.
- Uploaded and generated images — for the life of your account, plus a 30-day grace period after account deletion in case you change your mind, then erased.
- Billing records and invoices — 6 years, as required by the Spanish Commercial Code; blocked once the 4-year tax limitation period has run.
- Analytics data — up to 24 months.
- Server and security logs — 12 months.
- Consent and suppression records (proof that you gave or withdrew consent, unsubscribe lists) — until you withdraw consent, plus as long as needed to demonstrate compliance.
"Blocking" (bloqueo) is a requirement of Spanish law under which deleted data is locked away — accessible only to courts, public authorities or for legal-claim purposes — until the relevant limitation periods expire, after which it is permanently erased.
Data in encrypted backups is overwritten on the backup rotation cycle following deletion.
12. Automated decision-making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). AI generation produces creative imagery at your request; it does not make decisions about you.
13. Your rights
Under the GDPR and the LOPDGDD you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to the retention obligations in section 11.
- Restrict processing in the circumstances set out in Article 18 GDPR.
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible.
- Object to processing based on legitimate interest, and to direct marketing at any time.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
How to exercise them:
- Email fitable.ai@gmail.com from the address associated with your account, or describe your relationship to the data if you are not a user (for example, you appear in content we analyzed).
- Exercising your rights is free of charge.
- We may ask you to verify your identity before acting on a request.
- We respond within one month, extendable by two further months for complex requests — we will tell you if that happens and why.
You also have the right to lodge a complaint with a supervisory authority — in Spain, the AEPD (Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es) — or with the authority of your country of residence.
14. Children
The Services are designed for business users aged 18 or over and are not directed at minors. Under Spanish law (LOPDGDD Article 7), the age of digital consent is 14. We do not knowingly collect personal data from anyone under 14. If you believe a child under 14 has provided us with personal data, contact fitable.ai@gmail.com and we will delete it.
15. Cookies and analytics
Cookies
We use a small set of cookies and similar technologies:
- Essential cookies — required for sign-in, session management and security. These are always active because the Services cannot function without them.
- Analytics (PostHog) — used only with your consent, to understand how the product is used and to improve it.
We do not use advertising cookies and we do not permit third-party ad tracking on the Services.
Managing your preferences
Analytics runs only if you have consented. You can change your cookie preferences at any time from the cookie settings in the app, and you can clear or block cookies through your browser. Withdrawing consent stops analytics collection going forward; it does not retroactively delete aggregated statistics that no longer identify you.
16. Security and data breaches
We protect personal data with technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest.
- Access controls with least-privilege internal access to production systems.
- Network isolation of production infrastructure.
- Logging, monitoring and alerting on suspicious activity.
- Vendor due diligence and data-processing agreements with every sub-processor.
No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Article 33 GDPR), and we will inform you directly without undue delay where the breach is likely to result in a high risk to you (Article 34 GDPR).
17. Changes to this policy
We may update this policy as the Services or the law evolve.
- Material changes take effect no earlier than 30 days after we notify you by email or in-app notice. If you do not agree, you may terminate your account before the changes take effect; consumers receive a pro-rata refund of prepaid, unused subscription fees.
- Non-material changes (clarifications, typos, contact updates) take effect on posting.
- Prior versions are available on request at fitable.ai@gmail.com.
18. Language
This policy is published in English, Spanish and Catalan. In case of discrepancy, the English version prevails, except where mandatory law grants you, as a consumer, the right to rely on the version in the language in which the Services were marketed to you.
19. Contact
- Privacy matters: fitable.ai@gmail.com
- Legal notices: fitable.ai@gmail.com
- General support: fitable.ai@gmail.com
If you contact us about personal data, please tell us whether you are a Fitable user or a third party whose data may appear in analyzed content — it helps us route and resolve your request faster.
