1. Operator (Data Controller)
CabinApp is operated by RA. SOFT LTD, a limited company registered in England and Wales. The CabinApp brand and its related rights and obligations are held by RA. SOFT LTD.
- Company number: 17199432
- Registered address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
CabinApp ("we", "our", or the "Service") is operated by RA. SOFT LTD. This Policy explains what personal data we collect, how we collect it, every purpose for which we use it, and the service providers with whom it may be shared.
2. Data We Collect and How We Collect It
2.1 Data you provide
- Account data: name, email address, and authentication identifiers.
- Profile data: age, gender, height, weight, and optional body measurements.
- Image data: profile/body photos you capture or select, garment/product images you upload or import, saved model photos, and generated try-on, Studio, angle, and video results.
- AI instructions: selected size/model/scene/motion options, optional model-appearance choices (including ethnicity, skin tone, hair and eye characteristics), and any optional free-text instruction you enter. Ethnicity is an optional choice you make for a Studio model; CabinApp does not infer it from your photo.
- Support messages and AI-result reports you submit, including the reported result identifier, category, optional note, and an optional reply email on the public support form.
2.2 Data collected automatically
- Session, device type, app version, language, and basic diagnostic data.
- Feature usage, credit/subscription status and purchase history, generation history, and security logs.
- Consent evidence: consent surface, policy version and hash, selected language, timestamp, operation, and limited request metadata.
- For abuse prevention on the public support form: a coarse/truncated IP prefix and a shortened browser User-Agent; if you are signed in, the submission may also be linked to your account identifier.
We receive this data directly from your entries and selected photos, from your use of the app, from Apple or Google sign-in through Firebase Authentication, and from payment providers. We do not receive or store your full payment-card number.
3. How We Use Data
- Authenticate your account and provide customer support.
- Create virtual try-on, Cabin Studio, angle, 360, and video results.
- Personalize a requested Studio model using your optional appearance selections, including ethnicity when you choose to provide it.
- Provide an optional AI size recommendation from your saved measurements.
- Screen images for safety and prevent unlawful or abusive content.
- Store your private library and synchronize it across your account.
- Operate subscriptions and credits, validate receipts and entitlements, analyze subscription performance, prevent fraud, diagnose faults, and secure the Service.
- Comply with legal obligations and enforce our terms.
We do not sell personal data or uploaded photos. Mobile uploads and saved results are private by default. If you deliberately use a web publishing or share-link feature, only the content you select is made available through that feature until you remove or disable it.
Support content and contact/network identifiers remain in CabinApp's restricted support systems and service-email flow. Any separate operational support alert contains only an opaque internal record reference and fixed event name, not the message, subject, email, account identifier, IP prefix, or User-Agent.
4. Third-Party AI Processing and Your Permission
Before any supported AI action sends personal data outside CabinApp, the app displays a language-matched disclosure naming the data, recipient, and purpose. The AI action remains disabled until you actively check the permission box. Permission is requested for the relevant action; declining it prevents that transfer and does not prevent use of non-AI account features.
4.1 Google LLC — Gemini API and Google Cloud Vision
- Data sent: the person/body or model photo, garment/product image, an existing generated result, selected scene/model instructions and optional appearance choices (including ethnicity), and, only for size recommendation, relevant measurements.
- Purpose: virtual try-on and Studio image generation, optional size recommendation and Studio backdrop processing (Gemini); image safety screening (Cloud Vision SafeSearch).
4.2 OpenAI, L.L.C. — OpenAI API, only when the server fallback is enabled
- Data sent: the person/body image, garment/product image, and generation instruction required for that requested result.
- Purpose: image editing/generation if the configured primary generation path cannot be used.
4.3 fal – Features & Labels, Inc. (fal.ai) — video and 360 generation
- Data sent: the selected source or generated person image, relevant start/end frames, and selected motion, duration, and scene instructions.
- Purpose: produce the video or 360 animation you request.
We do not include your name, email address, authentication credentials, or payment information in AI-generation requests. We require each AI processor to handle the transferred data under contractual, confidentiality, security, and data-protection obligations that provide the same or equivalent protection required by this Policy and applicable law. Provider information: Google Privacy Policy, Gemini API Terms, OpenAI Privacy Policy, fal Privacy Policy, and fal API Services Terms.
5. Other Service Providers
We also use Google Cloud / Firebase (authentication, database, and private storage), Vercel (web/API hosting), Apple App Store, Google Play, and RevenueCat (purchase history, receipt validation, subscription analytics, and entitlement status), Stripe where web payments are offered, Resend / Zoho Mail (service email), website analytics, and operational diagnostic services. They receive only the data needed to perform their service and may not use it for their own unrelated marketing.
6. Legal Bases
Depending on your location and the operation, we process data to perform our contract with you, on the basis of your explicit permission for third-party AI sharing, to comply with law, and for legitimate interests such as security, fraud prevention, and service reliability where those interests do not override your rights.
7. Storage, Retention, and Deletion
- Account/profile data and private saved photos remain while your account is active, subject to the deletion options and requests described below. Saved results and their linked Studio selection metadata, including an optional ethnicity/model-appearance choice, remain until you delete the relevant result or delete your account.
- A QR photo-transfer link becomes unusable after 10 minutes. Its private temporary copy is deleted immediately after a completed transfer or cancellation. If the browser is abandoned or cleanup is interrupted, the copy is removed by the next daily automated sweep; a prefix-limited storage lifecycle also makes any missed QR-transfer object eligible for deletion after two days.
- Account deletion removes associated active-system personal data within 30 days, except records we must retain for legal, fraud-prevention, transaction, or compliance purposes and limited backup cycles.
- Google Cloud Vision states that images submitted through its online API are processed in memory and are not persisted as part of that service.
- For fal requests, CabinApp disables platform request/response payload storage where the provider supports it. Temporary generated-media delivery files may remain for the provider's operational lifecycle before expiry.
- Where OpenAI API abuse-monitoring logs apply, they may be retained for up to 30 days unless law or a security investigation requires longer retention.
- Consent records may be retained as needed to demonstrate compliance and defend legal claims; they do not permit a new AI transfer after you decline permission.
8. Security and International Transfers
We use TLS in transit, platform encryption at rest, private object storage, owner-scoped authorization, least-privilege access, and operational reviews. Providers may process data outside your country. Where required, we use lawful transfer safeguards and processor terms designed to preserve equivalent protection. No system can guarantee absolute security.
9. Your Choices and Rights
- Decline or leave the AI-sharing checkbox unchecked; no covered AI transfer occurs.
- Withdraw permission for future AI transfers at any time by not approving the next action.
- Delete individual saved results where a delete control is available. To remove stored profile/model photos, contact us with a privacy request or delete your account from Account > My Data.
- Request access, correction, deletion, restriction, objection, or portability where applicable.
- Complain to your local data-protection authority.
A completed generation cannot be retroactively undone, but withdrawal stops new covered transfers. You may also contact privacy@cabinapp.co.
10. Age Requirement
AI photo-generation features are intended for people aged 18 or older. Do not upload a recognizable third party without the necessary rights and permission.
11. Cookies and Analytics
We use essential session technologies and limited operational diagnostics to secure and keep the service reliable. The iOS and Android apps do not send optional app-open, tap, advertising, or cross-app tracking events. Our website may use Vercel Web Analytics and server-side Sentry diagnostics where permitted; these are not used for third-party advertising or cross-app tracking. Website cookie choices can be changed through the available cookie settings.
In the mobile apps, account-linked generation history, credit counters, and consent records are used only to provide the requested app functionality; they are not sent as product-interaction analytics.
12. Contact