Privacy Policy

Last Updated: October 12, 2025

Introduction

Welcome to What's My Shape ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our AI-powered shape identification tools.

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the site or use our services.

Information We Collect

Personal Data

We may collect personal identification information, including but not limited to:

  • Email address (if you contact us)
  • Name (if provided when contacting us)
  • Images you upload for analysis (not stored)
  • Device information and IP address
  • Usage data and interaction with our website

Images and Analysis Data

When you use our shape identification tools, we temporarily process the images you upload to provide our services. We do not store your images in any database or permanent storage. All image processing is done in real-time, and images are automatically discarded after analysis.

AI and Biometric Data Processing

Our shape identification tools use artificial intelligence to analyze facial features, body shapes, and other physical characteristics from the images you upload. Please be aware of the following:

  • Biometric Information: While we analyze physical characteristics, we do not create or store biometric identifiers (as defined by laws such as BIPA in Illinois) that could be used to identify you specifically.
  • AI Processing: Our AI models analyze images to determine shape characteristics but do not use this data to identify individuals.
  • Temporary Processing: Image analysis occurs in real-time and processed data is not retained in any database or permanent storage. Your images are automatically discarded after analysis.
  • No Database Storage: We do not maintain a database of user images or analysis results. Each analysis is performed independently and results are delivered directly to you without being stored.

For users in Illinois, Texas, Washington, and other states with specific biometric privacy laws, we confirm that we do not store or share any biometric identifiers or biometric information as defined by those laws.

How We Use Your Information

We may use the information we collect for various purposes, including:

  • Providing and maintaining our services
  • Processing your image to deliver shape analysis results
  • Improving our AI algorithms and services
  • Responding to your inquiries and support requests
  • Sending you service-related notifications
  • Detecting and preventing fraudulent activities
  • Complying with legal obligations

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and store certain information. Cookies are files with a small amount of data that may include an anonymous unique identifier.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service.

We use the following types of cookies:

  • Essential cookies: Necessary for the operation of our website
  • Analytical/performance cookies: Allow us to recognize and count visitors and see how they move around our website
  • Functionality cookies: Enable us to personalize content
  • Targeting cookies: Record your visit to our website, the pages you have visited, and the links you have followed

Third-Party Services

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our services
  • To provide the service on our behalf
  • To perform service-related functions
  • To assist us in analyzing how our service is used

These third parties may have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Our service may include links to third-party websites. These third-party sites have separate and independent privacy policies. We have no responsibility or liability for the content and activities of these linked sites.

Third-Party Service Providers We Use

  • Analytics: Google Analytics, to track and analyze website usage
  • Cloud Services: We may use cloud providers like AWS, Google Cloud, or Azure to process and temporarily store data
  • Payment Processing: If applicable, payment information is processed by secure third-party payment processors

Data Security

The security of your data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

We implement appropriate technical and organizational measures to maintain the safety of your personal data, including:

  • Using encryption when processing your images
  • Regular security assessments and testing
  • Access controls to limit data access to authorized personnel
  • Secure data deletion practices

Data Retention

We do not maintain a database of user information. The only personal data we may retain is contact information if you choose to reach out to us. We do not store any images you upload for analysis - they are processed in real-time and immediately discarded after providing you with results.

Any analytics data we collect about website usage is anonymized and cannot be used to identify individual users.

Children's Privacy

Our services are not intended for use by children under the age of 13 (or 16 in the European Union). We do not knowingly collect personally identifiable information from children under 13 (or 16 in the EU). If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

If we need to rely on consent as a legal basis for processing your information and your country requires consent from a parent, we may require your parent's consent before we collect and use that information.

Your Data Protection Rights

For European Economic Area (EEA) Residents (GDPR)

If you are a resident of the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR). We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

Under the GDPR, you have the following rights:

  • Right to access: You have the right to request copies of your personal data.
  • Right to rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • Right to erasure: You have the right to request that we erase your personal data, under certain conditions.
  • Right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • Right to object to processing: You have the right to object to our processing of your personal data, under certain conditions.
  • Right to data portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

For California Residents (CCPA)

The California Consumer Privacy Act (CCPA) provides California residents with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.

Under the CCPA, California residents have the right to:

  • Right to know: You have the right to request that we disclose information to you about our collection and use of your personal information over the past 12 months.
  • Right to delete: You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions.
  • Right to opt-out of sales: You have the right to opt-out of the sale of your personal information. Note that we do not sell personal information.
  • Right to non-discrimination: You have the right not to be discriminated against for exercising any of your CCPA rights.

How to Exercise Your Rights

To exercise your data protection rights described above, please submit a verifiable request to us by:

Only you, or a person registered with your state's authority that you authorize to act on your behalf, may make a verifiable request related to your personal information.

Your request must:

  • Provide sufficient information that allows us to reasonably verify your identity.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

Since we do not maintain a database of user information or store uploaded images, most data requests will be limited to analytics information that cannot be tied to specific individuals.

We will respond to a verifiable request within 30 days of receipt. If we require more time, we will inform you of the reason and extension period in writing.

International Data Transfers

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

For EEA users, we ensure that your data is protected when transferred outside the EEA by using Standard Contractual Clauses approved by the European Commission or by relying on other legal transfer mechanisms.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

Accessibility and Inclusive Design

What's My Shape is committed to ensuring digital accessibility for people of all abilities. We strive to meet WCAG 2.1 AA standards and continuously work to improve the user experience for everyone.

We recognize that our shape identification tools analyze physical characteristics, and we are committed to:

  • Providing inclusive descriptions and alternatives for users who may not be able to upload or view images
  • Ensuring our results and recommendations are presented in an accessible, non-discriminatory manner
  • Acknowledging and respecting the diversity of human physical characteristics
  • Avoiding language or categorizations that could be considered insensitive or exclusionary

If you encounter any accessibility barriers on our website or have suggestions for improvement, please contact us using the information provided in the Contact Us section.

© 2025 What's My Shape. All rights reserved.