← hoilo.app

Privacy Policy

Last updated 5 August 2026

Hoilo is an iPhone app that generates virtual try-on images. This policy explains exactly what it does with your photos and data.

Short version: your photos live on your phone. Creating a try-on necessarily sends two images to Google's Gemini API, because that is the service that generates the result. Separately, Hoilo can send diagnostics to a small server we run — including, if you switch it on, the generated try-on image itself. Both diagnostics settings are off unless you turn them on. There is no account, no advertising and no cross-app tracking.

Who is responsible

Hoilo is operated by Juraj Škvarla, Prague, Czech Republic — the data controller for the purposes of the GDPR. Contact: jurajskvarla@gmail.com.

What stays on your device

Deleting an item in the app deletes it. Deleting the app deletes all of it. None of this is synced to an account, because there is no account.

What always leaves your device

Generating a try-on

When you start a try-on, Hoilo sends your active photo and the garment image over HTTPS to Google's Gemini image generation API, which returns the generated image. This is the core function of the app and cannot be switched off — without it there is no try-on. Google's handling of these requests is governed by its own terms and privacy documentation for the Gemini API. Hoilo sends no name, email or account identifier with the request.

The same request also carries two device-level identifiers to our own server, and unlike the diagnostics below this cannot be switched off: Apple's identifier for vendor (specific to Hoilo on your device, reset if you delete the app) and a short-lived Apple DeviceCheck token. They exist for one purpose — counting the free try-ons a device has used, so that the free allowance survives a delete-and-reinstall. Neither identifies you, and neither is sent to Google.

Buying Pro

The purchase itself happens in Apple's App Store, not in Hoilo: we never see your Apple Account, your name or your payment details. What Hoilo sends to our own server is what the App Store told it — the StoreKit transaction identifier, so the server can ask Apple whether the subscription is live, and what the paywall did: that it opened, which plan was selected, and the outcome the App Store returned, including Apple's own error code when a purchase fails. It also carries the same device identifier described above plus the app version, iOS version, device model and locale.

This is not covered by the diagnostics switches below, for the same reason the free-try-on count is not: a purchase that silently fails is otherwise invisible to us, and a subscriber who paid and did not get Pro is a problem we have to be able to see. It carries no photo, no product link and no page content. Settings → Diagnostics → Delete uploaded data erases these records along with everything else.

Reading a product page

If you paste or share a product link, Hoilo requests that page in order to find the product photo, and in a few cases requests a product endpoint the shop operates for its own website. The shop's servers see that request much as they would a browser visit, including your IP address. Hoilo sends them nothing about you beyond what any web request contains.

Optional diagnostics — off by default

Hoilo can report how it is performing to a server we operate (a Cloudflare Worker with a Cloudflare D1 database and an R2 storage bucket). This is how we find out which shops fail to resolve and how long generation really takes. It is controlled by two independent switches under Settings → Diagnostics, and both are off until you turn them on. Nothing described in this section happens on a fresh install.

“Share usage stats” — off by default

When enabled, each try-on attempt sends: a device identifier (Apple's identifier for vendor, which is specific to Hoilo on your device and is reset if you delete the app); whether the attempt succeeded; how long it took; the product URL, page title and product image URL; the error message when one occurs; the app version and build; your iOS version, device model and locale; and an internal reference to which of your saved photos was used. It does not include any photo.

Error messages are shortened and stripped of API keys before they are sent.

“Include generated images” — off by default, and requires the switch above

When enabled, the generated try-on image is also uploaded and stored in our R2 bucket, so that output quality can be reviewed. That image shows your face and body. Please read that sentence twice before enabling it.

Uploaded images are not published anywhere and are not reachable by a public URL; retrieving one requires an administrative key that is not present in the app. They are deleted automatically 30 days after upload.

Legal basis, retention and processors

The legal basis for diagnostics is your consent, which you may withdraw at any time by turning the switches off. Usage rows are kept until you delete them (see below) or until they are no longer useful for diagnosing the app. Images are deleted after 30 days. The processors involved are Cloudflare (hosting, database, object storage) and, for generation itself, Google. These are US-headquartered providers and data may be processed outside the EEA under their respective transfer terms.

Deleting what was uploaded

Settings → Diagnostics → Delete uploaded data erases every diagnostics row and every uploaded image held for your device, immediately and permanently. It needs a network connection, and it tells you if it failed rather than claiming success. You can also ask by email at the address above.

Turning the switches off stops further uploads but does not by itself delete what was already sent — use the delete action for that.

What Hoilo does not do

Purchases

If you buy Hoilo Pro, the purchase is processed by Apple. Hoilo receives only whether the purchase is valid — never your payment details.

This website

hoilo.app is a static site hosted on Netlify. Netlify records basic server request data (such as IP address and user agent) for delivery and security purposes. The site sets no advertising or analytics cookies. If you submit your email in the waitlist form, that email is stored in Netlify Forms and used only to tell you when Hoilo is available; ask at the address above and it will be deleted.

Children

Hoilo is not directed at children under 13, must not be used by them, and must not be used to generate images of children.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict and object to the processing of your personal data, and the right to withdraw consent. Because everything essential stays on your device, you exercise most of this directly in the app: the diagnostics switches, the delete action above, deleting individual items, or deleting the app. For anything else — including the website waitlist — write to the address above. You also have the right to complain to your local supervisory authority.

Changes

If this policy changes, the date above changes with it. Material changes will be reflected in the app before they take effect.