Privacy Policy
Last updated: 29 August 2026 · Version française
This policy covers both the weartag.app website (the creators' space, which uses an account) and the Weartag mobile app for iOS (used by viewers, without any account). The general sections describe the service as a whole; the "Weartag iOS app" section states exactly what applies to the app.
Data controller
The data controller is Omar Ouhab, publisher of weartag.app. Any request regarding your data : hello@weartag.app.
Weartag iOS app (viewers, no account)
The Weartag mobile app for iOS works without any account : no sign-up, no password. After your first successful scan, the app may offer once to let you leave your email address so we can tell you about what's new ; this is entirely optional, you can skip the screen, and the app works exactly the same if you decline. You paste or share the link of a TikTok video or post, and the app shows you the clothes it spotted and where to buy them.
What the app sends to our servers when you run a scan- the TikTok URL you paste or share
- the creator's @handle for that video, when available, so any commission is attributed to the right creator
- for a photo carousel, the list of images you choose to analyse
From that link, our servers fetch the post's cover image (never the video itself) and analyse it to detect clothing. The record created in our database carries no account identifier and nothing that identifies you personally.
What stays only on your phone- the history of your recent scans (the last 10 at most), for the home screen
- whether you have already seen the home screen and dismissed certain hints
- when you open the app, it reads the clipboard to spot a possible TikTok link and offer to paste it ; this read stays local, and nothing is sent until you start a scan yourself
These items are stored locally and disappear if you delete the app. The app does not access your camera, your photos, your contacts, or your location.
Shopping linksWhen you tap a product, the app opens a link provided by our server, which redirects you to the merchant via weartag.app/r/…. That click is counted for the creator — date, device type (user-agent), referring page and approximate country — without ever storing your IP address, without cookies and without any visitor identifier.
Abuse preventionBecause scanning is free and account-less, we cap the number of scans per day using a simple daily counter tied to a non-reversible technical fingerprint derived from your IP address (HMAC-SHA256). Your IP address is never stored in the clear, no advertising identifier is used, and no cross-app or cross-site tracking is possible. The app therefore does not request tracking permission (App Tracking Transparency).
What the app does not do- no account, no password
- no mandatory email address : it is asked once, it can be declined, and declining blocks nothing
- no advertising identifier (IDFA), no ad tracking
- no analytics tool and no error-reporting tool embedded in the app
- no selling or renting of your data
Data collected (website account)
Account- email address and password (the password is hashed by our authentication provider; we never have access to it)
- display name, username, language, country
Creator profile, filled in at sign-up
- main platform, follower range, content style, brands mentioned, linking habits
- contact channel and handle (for example an Instagram username), acquisition source, profile picture
Content- videos you upload and their thumbnails
- clothes detected in those videos and the matching merchant products
Links and statistics- generated links and their short codes
- per-link click counters, including the number of requests filtered out as non-human
- commissions attached to your account and their status
Payout details- IBAN, BIC and account-holder name, or the email address of your payment service
- this data is encrypted server-side before storage; the interface only ever shows the last few characters
What we do not collect. Clicks on your links are recorded as
aggregated counters per link. No IP address, no visitor identifier and no browsing profile is stored for those clicks.
Purposes
- provide the service : analysing videos, detecting clothing, generating links, running the public shop
- calculate the commissions owed to you and pay them out
- authenticate you, secure accounts and prevent fraud
- respond when you contact us and send the emails required for the service
- measure site audience in aggregate and improve the product
Legal basis
- Performance of the contract — account, provision of the service, calculation and payment of commissions
- Legal obligation — retention of records related to payouts
- Legitimate interest — security of the service, fraud prevention, aggregated audience measurement, and providing the iOS app you use without an account (analysing a TikTok link you submit voluntarily)
- Consent — communications that are not essential to the service, which you can withdraw at any time
Retention periods
- Account and profile : as long as the account exists, then deleted within 30 days of its closure
- Videos and thumbnails : until you delete them, or until the account is closed
- Links, click counters and commissions : kept as long as they may give rise to a payout, then anonymised
- Payout details : until changed or until the account is closed
- Accounting records related to amounts paid : the applicable statutory retention period
- iOS app — local history : on your device only, until you uninstall the app or clear its data
- Analysed TikTok cover images : clothing crops are deleted within 12 hours at the latest, re-hosted full images within 7 days
- App abuse-prevention counter (non-reversible fingerprint) : a daily counter, reset every day
Processors and transfers outside the European Union
We rely on the following providers, each for a specific purpose :
- TikTok — the link you submit in the app is sent to TikTok to fetch the post's cover image and the creator's name.
- Supabase — database, authentication and storage. Data is hosted in the European region eu-west-1 (Ireland).
- Vercel Inc. — website hosting. United States.
- Cloudinary — hosting and processing of uploaded videos.
- Google Cloud Vision — image analysis for clothing detection. United States.
- SerpAPI — searching for matching products at merchants. United States.
- Anthropic — automated processing to help identify items. United States.
- Resend — sending the service's emails.
- Crisp — support messaging, when you open a conversation.
- Plausible — audience measurement without cookies or individual identifiers.
- Sentry — technical error reports, when this feature is enabled (server-side; not embedded in the iOS app).
- Partner affiliate networks — for tracking the commissions attached to your links.
Some of these providers are established outside the European Union, in particular in the United States. These transfers are governed by the safeguards provided for by the GDPR, in particular the European Commission's standard contractual clauses or the provider's adherence to a recognised transfer framework.
Your data is never sold, rented, or handed over to third parties for advertising purposes.
Your rights
You have the right to access, rectify, erase, restrict the processing of, and object to the processing of your data, as well as the right to data portability. Where a processing activity relies on your consent, you can withdraw it at any time.
To exercise these rights, write to hello@weartag.app. We respond within one month. Proof of identity may be requested in the event of reasonable doubt.
You may also lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or with the supervisory authority of your country of residence.
Cookies and local storage
The website uses no advertising cookies and no marketing trackers. There is therefore no consent banner. The iOS app uses no cookies at all.
On the website, the following are used only :
- a session token, essential to keep you signed in
- your language preference, kept in the browser's local storage
- a possible referral code, kept temporarily to credit the person who invited you
- the support messaging, which sets its own identifiers when you open a conversation
- audience measurement, performed without cookies and without individual identifiers
You can erase these items at any time from your browser settings; signing out will be the consequence.
Newsletter
Email address offered in the iOS appAfter your first successful scan, the app may offer to let you leave your email address. This offer is optional and appears only once : if you skip it twice, or if you give your address, it never comes back.
- Purpose — to tell you about what's new at Weartag. Nothing else : your address is never tied to the videos you analyse, to your history, or to any advertising profile.
- Legal basis — your consent, given by entering your address, withdrawable at any time.
- Data stored — your email address, the date of consent and its source (« iOS app »), so that we can prove when and where you consented.
- Unsubscribing — in one click via weartag.app/newsletter-desinscription, a link present in every email, or simply by writing to hello@weartag.app.
- Retention — until you unsubscribe.
The website offers an optional subscription to the Weartag newsletter ("Be first to hear what's new").
- Purpose — keeping you informed about Weartag news (features, partner brands).
- Legal basis — your consent, given when you subscribe and withdrawable at any time.
- Data — your email address, the date and exact wording of the consent, and a non-reversible technical fingerprint (HMAC-SHA256) derived from the IP address, used solely to prevent abuse (a daily request cap). No IP address is ever stored in the clear.
- Retention — until you unsubscribe; the anti-abuse fingerprint only feeds a daily counter.
- Recipient — Supabase (hosted in the European region eu-west-1, Ireland). The email-sending tool will be named here before the first send.
- Unsubscribing and rights — one click at weartag.app/newsletter-desinscription (every email will also link there), or by simply writing to hello@weartag.app.
© 2026 Weartag — All rights reserved