Privacy Policy

Effective date: July 3, 2026 | Version 3.3

Alate ("we", "our", "the app") is a mobile application developed by Bits of Tessellate that helps you predict whether clothing items will fit based on your body profile. This policy explains what data we collect, how we use it, and your rights.

TL;DR: Your body profile is stored on your device. When you run a fit check it is sent to our own server to compute the result, then immediately discarded — never stored on our servers, never shared with anyone, never sent to an AI service. Product URLs you paste are scraped in real time and discarded. We don't sell data, don't run ads, don't track you across apps.

1. Data We Collect

a) Body Profile Data

When you build your profile, you provide height and six body proportions: shoulder, bust, waist, hip, thigh type, torso length. This data is stored on your device via AsyncStorage. When you run a fit check, your body profile is sent to our own backend so our fit algorithm can compute the prediction. It is used in memory for that single request and then discarded — it is not stored on our servers, not logged, not used to build any profile of you, and never sent to any third party or AI service. We do not sync your body profile to any cloud account or database.

b) Product URLs (ephemeral)

When you paste or share a product URL, we send that URL to our backend to scrape publicly available product information (name, price, image, description, material, sizes) from the source website. The URL is processed in real time and discarded. We do not persist URLs with your identity on our servers. The fit check result is stored locally on your device as part of your fit history.

c) Fit Check History (device-only)

Results of your fit checks (product name, image URL, fit score, warnings, recommended size, timestamps) are stored locally on your device. This data is not synchronised to any cloud service.

d) Device Identifier

On first launch, the app generates a random UUID stored locally and includes it as an X-Device-Id header on backend requests. This identifier is used solely for rate-limiting (to prevent abuse) and is not linked to your identity, name, email, or body profile. It is regenerated if you reinstall the app.

e) Google Account (optional)

If you choose to sign in with Google on the Account screen, we receive your email address and profile name via Supabase Auth. Sign-in is optional. Your body profile, fit history, and calibration work without an account. Signing in is currently used only for future cross-device sync features — which we will disclose here before launching.

f) Crash Reports

We use Sentry and Firebase Crashlytics to collect crash reports and performance traces. These include stack traces, device model, OS version, and a random session identifier. No body profile data, URLs, or account details are included in crash reports. Crash data helps us fix bugs and is retained for 90 days.

g) Brand Request Data (server-side)

If you paste a URL from a brand we don't yet support, the URL and brand domain are recorded in our backend so we can prioritise which storefronts to onboard next. We do not contact the brand on your behalf, and your body profile is never associated with the request.

Optionally, you may opt in to be notified by email when we add support for that brand. If you provide an email, it is stored alongside the brand entry for the sole purpose of sending that single notification — never used for marketing, newsletters, or any other communication. Providing this email is optional; the rest of the app works without it.

h) Shared Measurement Snapshots (optional, server-side)

If you choose to share your measurements, the specific values you select are stored anonymously on our servers — with no name, account, or device identifier attached — behind a random link. You pick how long the link lives (from 1 week to 3 months); the snapshot is automatically deleted once it expires. Sharing is entirely optional, and only the fields you tick are included.

i) Measurement Sheet Scanning (optional, not stored)

If you choose to scan a tailor's measurement sheet, the photo is sent once to our AI provider (Anthropic) solely to read the numbers on it. Under our agreement, that image is not used to train any AI model, and we do not store the photo. Only the values you review and approve are saved, and they stay on your device.

j) Restock Alerts (optional, email waitlist)

If your recommended size is sold out, you may ask to be emailed when it returns. If you opt in, we store your email address, the product URL, and the size — solely to send that back-in-stock notification. Stock is re-checked against the live store; we never store the merchant's inventory. The email is never used for marketing, and you can unsubscribe from any alert email.

2. Age Requirement

Alate is intended for users aged 16 or older. On first launch, the app asks you to confirm your age. If you indicate you're under 16, the app will not collect body profile data from you. Users under 16 who circumvent the age gate by providing inaccurate information are not our intended audience; we will promptly delete any data we discover was collected from someone under 16.

3. How We Scrape Product Data

Alate fetches publicly accessible product pages to extract fit-relevant information. Our scraping practice:

4. Service Providers

We use the following service providers strictly to operate the app. Your body profile is processed only by our own backend (hosted on Vercel) — transiently, to compute a fit check, and never stored (see section 1a). None of the other providers below receive your body profile data.

No personal data is sold to any party. We have not sold personal information in the preceding 12 months.

5. Security

6. Data Retention

7. Your Rights

At any time you can:

8. Brand Opt-Out

If you operate a storefront and prefer Alate not scrape your site, submit an opt-out request at this page. Your origin will be added to our blocklist within 24 hours. We honour the opt-out even if it conflicts with our technical ability to scrape; we do not require justification.

9. Additional Rights for EEA/UK Residents (GDPR)

If you are in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation:

10. California Residents (CCPA/CPRA)

If you are a California resident:

Categories collected: Identifiers (email, name — only if you sign in via Google); Sensory/Geolocation — none; Internet activity (product URLs, ephemeral); random device identifier (rate-limiting only).

11. Indian Residents (DPDP Act 2023)

Data Fiduciary: Bits of Tessellate. Contact: privacy@tessellate.co.in.

Consent: Before we collect body profile data, the app's age gate and profile setup screen show a clear notice explaining the data and purpose. Proceeding constitutes consent. You may withdraw at any time by deleting your profile.

Purpose limitation: Body profile data is used exclusively to compute fit predictions. We do not process it for any other purpose.

Children's data: Alate is not intended for persons under 18 in India without verifiable parental consent. The 16+ age gate is a minimum; persons aged 16-17 in India who use the app should do so with parental awareness.

Grievance Officer:
Name: Saptami
Email: privacy@tessellate.co.in
Response time: within 15 days.

12. Children's Privacy

Alate is not directed at children. The app's age gate asks all users to confirm they are 16 or older. We do not knowingly collect data from children under 16. If we become aware of such collection we will delete the data promptly. Parents or guardians who believe their child has submitted data to Alate may email privacy@tessellate.co.in for deletion.

13. App Store Privacy Details

Tracking: Alate does not track you across other companies' apps or websites. We do not use the IDFA or any device advertising identifier.

Data linked to you: Email address and name (only if you sign in via Google). Brand-request notify email (only if you opt in to "notify me when added"; held for up to 30 days after the notification is sent).

Data not linked to you: Body profile (stored on your device; sent to our backend transiently for each fit check and discarded, never stored server-side), fit history (device-only), product URLs from successful scrapes (ephemeral), unsupported-brand URL + brand domain (anonymised demand signal when no notify email is provided), device identifier (rate-limiting only), crash reports (PII-scrubbed).

Data used to track you: None.

14. Changes to This Policy

We may update this policy. Changes will be posted on this page with an updated effective date and version number. Continued use after changes constitutes acceptance.

15. Contact

Publisher: Bits of Tessellate

Email: privacy@tessellate.co.in

Design note: This page will be redesigned in a future release to match the Alate app's visual identity. Feature-flagged v2 is on the roadmap; v1 (this page) remains authoritative until then.