Chammy — Privacy Policy
Effective date: 2026-07-19 Last updated: 2026-09-07 (usage analytics now include the words typed into the Skin search when no Skin matched — see §3.6. Previously 2026-08-23: optional share links for Sets: you can publish a copy of a set of your cards to a web page and share the link — see §3.4 and §5; cards using your body photo are included only if you explicitly choose so for that share. Previously 2026-07-26: optional "About you" profile — birth month + year replaces the age range, see §3.8)
This Privacy Policy explains how Bhudiskul Amphansang, an individual entrepreneur based in Thailand operating under the name "Chammy" ("Chammy", "we", "us", "our"), collects, uses, stores, shares, and protects your personal data when you use the Chammy mobile application and the services behind it (together, the "Service").
We are the data controller of your personal data under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). Where you use the Service from the European Economic Area or the United Kingdom, the EU/UK General Data Protection Regulation ("GDPR") also applies, and this Policy is written to satisfy both.
The short version: Chammy is a fashion try-on and outfit-scoring app. To work, it needs photos of your body and your clothes. Those photos are processed by our own software on servers we operate — they are never sold, never used for advertising, never used to train AI models, and never shown to other users. Chammy is free, supported by clearly labeled sponsored content and affiliate shop links — with no third-party ad networks and no ad tracking. We collect in-app usage statistics (never your photos) to improve the app and to build anonymous fashion-trend insights; you can turn usage statistics off at any time. You can delete your photos, your creations, or your entire account at any time.
1. Who we are and how to contact us
| Data controller | Bhudiskul Amphansang (individual entrepreneur, operating as "Chammy") |
| Location | Thailand — postal address available on lawful request via support@chammy.cloud |
| Website | https://chammy.cloud |
| Privacy contact | support@chammy.cloud |
| General support | support@chammy.cloud |
2. What this Policy covers
This Policy covers the Chammy mobile app for iOS and Android and the Chammy backend service (API) that the app communicates with. It does not cover third-party websites or services that you may reach through links inside the app (for example, a garment's external shop page or a link in an announcement); those are governed by their own privacy policies.
3. Personal data we collect
3.1 Account data (when you sign in)
Chammy uses third-party sign-in only (Google, Facebook, or Apple). We never see or store a password for you. When you sign in, we receive and store:
- Your email address, as provided by the sign-in provider.
- A stable account identifier issued by that provider (e.g. your Google account ID or Facebook app-scoped ID). This is a random identifier, not your profile or friends list.
- The date your Chammy account was created and a random internal Chammy user ID that we generate.
- Records of the confirmations you give — the timestamps of your Terms acceptance, age confirmation, and (if given) body-photo consent, together with the policy version you consented to. We keep these because the PDPA requires us to be able to demonstrate consent.
We do not collect your name, username, phone number, full birthday, contact list, or social-media profile content. (The optional "About you" profile can ask for your birth month and year — never the exact day; see §3.8.) If you sign in with Apple and choose "Hide My Email," we receive and use the relay address Apple provides.
3.2 Photos you upload — including sensitive body photos
The core of Chammy is photos:
- Body photos — full-body photos of yourself (up to 10), taken with your camera or chosen from your photo library, used to render virtual try-ons and styled looks.
- Garment photos — photos of your clothing items (up to 100, tops and bottoms combined), tagged as tops or bottoms.
Body photos are an adults-only feature and are treated as sensitive personal data. Uploading them requires confirming in the app that you are at least 18 years old and have reached the age of majority where you live (20 in Thailand) — see our Terms of Service §2. We only collect and process body photos with your explicit consent, which we ask for inside the app before your first upload. You can withdraw this consent at any time by deleting your body photos or your account (see Section 10); withdrawing consent will stop the try-on features from working but does not affect the lawfulness of processing before withdrawal.
You must only upload photos of yourself, or of items you own or are entitled to photograph. Never upload photos of other people without their permission, and never upload photos of anyone under 18.
3.3 Data derived from your photos (created automatically)
When you upload a photo, our software automatically generates working data from it:
- Background-removed cutouts of your body and garments (so try-ons look clean).
- Body pose landmarks — a set of 33 geometric points (shoulders, hips, knees, etc.) detected on your body photo, used only to locate where tops and bottoms sit on your body. These landmarks are not used to identify you, are not a facial recognition or biometric identification system, and are never compared against other people's data.
- Garment characteristics — dominant colors and automatically classified attributes of your clothing (e.g. sleeve length, neckline, fit).
3.4 Content you create in the app
- Looks / try-on previews — AI-generated images of you wearing selected garments, together with their outfit scores and timestamps.
- Sticker cards — collage-style cards you compose from your photos, notes, stickers, and backdrops.
- Skins and CHAM sets — your saved style definitions and shortlists.
- Sets — named groups of your looks and cards that you create to organize them.
- Share-link pages (optional) — if you choose to share a Set by link, we store the copies of the card images you selected for that share, so the shared page can display them (see Section 5). These copies exist only for as long as the link does.
- Flags you set, such as favorites.
3.5 Technical data
- IP address — used transiently in server memory to rate-limit requests and protect the Service from abuse. It is not written to a database or profile.
- Session token — after sign-in, the app stores an authentication token in your device's secure storage (iOS Keychain / Android Keystore equivalent) so you stay signed in. It contains your Chammy user ID, not your email.
- Basic server logs — standard technical logs (e.g. error messages and request records) that may reference your internal user ID and IP address, kept for debugging and security and automatically deleted on rotation (see Section 8).
3.6 Usage analytics (in-app activity)
To understand how Chammy is used and to improve it, our servers record in-app interaction events, for example:
- which Skins (style templates) you view, and for how long;
- when you run a CHAM match, and with which Skin;
- which features you use on a match result (e.g. Boost, Dominators, swapping garments in the Match Lab);
- when you keep, export, or try on a look (the score and Skin involved — never the image itself);
- when you view the details of a suggested garment we curate, or open its shop link (the Skin and curated item involved — the link itself is opened by your browser and carries no identifier, see Section 6);
- when you add or remove a garment (its category and the detected colors and attributes described in Section 3.3 — never the photo itself);
- the words you type into the Skin search only when nothing matched (so we can teach the search the words people actually use); we keep at most 40 characters and drop anything that looks like an email address or phone number.
Each event also records which platform it came from (iOS or Android) so we can tell how the app performs on each. This is a two-value technical tag; it is not a device identifier and cannot be used to single you out.
We also record when the app was first opened and, where known, how you heard about Chammy (for example, that you joined through a tester invitation or entered a creator's invite code). This "source" is a short label from a fixed list we maintain — it is stored on your account like the optional profile answers in Section 3.8, it never contains free text you type, and we use it only to understand, in aggregate, which channels bring people to Chammy and how well the app serves them.
These events are stored against a pseudonymous identifier — a one-way code derived from your account, not your email or name. They never contain your photos, your body data, or your notes; the only wardrobe information they carry is the detected garment attributes and colors. They are collected by our own servers only — no third-party analytics SDK is embedded in the app, and events are never shared with anyone in identifiable form.
You can turn usage analytics off for your account at any time in the app (see Section 10); core features keep working exactly the same.
3.7 What we deliberately do NOT collect
- ❌ No advertising identifiers (IDFA/AAID) and no third-party ad networks or ad SDKs. Sponsored content in Chammy (Section 6) is chosen and served by us and clearly labeled — no ad network builds a profile of you.
- ❌ No third-party analytics or behavioral tracking SDKs — the usage analytics in Section 3.6 are collected by our own servers only.
- ❌ No tracking of you across other companies' apps or websites.
- ❌ No precise location — no GPS, and we do not derive your location from your IP address. The only location-type data is the optional region/province you choose yourself in your profile (Section 3.8).
- ❌ No contacts, messages, calendar, or files beyond the photos you explicitly pick.
- ❌ No payment or financial data (the app currently has no purchases).
- ❌ We never infer personal characteristics (such as age, gender, or body shape) from your photos.
3.8 Optional profile details ("About you")
After you sign up (and any time in Account → About you) we offer an entirely optional profile card asking, in Thai and English: your gender, your birth month and year (never the exact day — we use it to compute your age group, which then stays up to date on its own), where you live (a region of Thailand you choose, optionally a province — never GPS), and your favorite style vibes. Every field can be skipped, changed, or cleared at any time. Your birth month and year never leave your account record: analytics and any aggregate insights only ever see the derived age group. If the age computed from what you enter is under 13 we do not store it (Chammy accounts require you to be at least 13 — see §13), and if it shows you are under 18 the adults-only body-photo features are locked and any stored body photos are deleted (§7).
We use these answers for one purpose: to break the aggregated statistics described in Sections 3.6 and 6 into groups (for example, "streetwear interest by age group"). They are stored on your account record only — they are never attached to individual usage events, and anything shared outside Chammy is aggregated with minimum group sizes so it can never identify you.
4. How we use your personal data
| Purpose | Data used | Legal basis (PDPA / GDPR) |
|---|---|---|
| Create and operate your account; keep you signed in | Account data, session token | Performance of a contract (PDPA §24(3) / GDPR Art. 6(1)(b)) |
| Render virtual try-ons, cutouts, and styled looks | Body photos, garment photos, derived data | Explicit consent (PDPA §26 / GDPR Art. 9-equivalent treatment); contract for non-sensitive elements |
| Score outfits and show your results | Garment attributes, looks | Performance of a contract |
| Show anonymous, aggregate features (e.g. "most-CHAMmed skins" leaderboard, score percentile curves) | Counts and scores stripped of any identity — other users can never see who you are, your photos, or your data | Legitimate interest (PDPA §24(5) / GDPR Art. 6(1)(f)) in providing app features with anonymized data |
| Improve the Service — understand which features are used and how (usage analytics, Section 3.6) | Pseudonymized in-app interaction events | Legitimate interest (PDPA §24(5) / GDPR Art. 6(1)(f)); you can object or turn this off at any time (Section 10) |
| Break aggregated statistics into groups (e.g. style trends by age group or region) | Optional profile details (Section 3.8), joined to statistics on our servers only — never attached to individual events, never shared in identifiable form | Voluntary provision + legitimate interest; every field is optional and removable at any time |
| Produce aggregated, anonymized fashion-trend and engagement insights (e.g. which styles, colors, or garment attributes are popular), which we may use commercially, including sharing or selling insights to partners such as brands | Statistics computed from usage events and garment attributes, aggregated across many users with minimum group sizes — never photos, never identities; the output can never identify you | Legitimate interest; the shared output is anonymized and is no longer personal data |
| Measure and report the performance of sponsored content to its sponsor | Aggregated view/engagement counts only — sponsors never receive personal data | Legitimate interest |
| Protect the Service (rate limiting, abuse prevention, security) | IP address (transient), technical logs | Legitimate interest in security |
| Respond to your support requests | Email, correspondence | Performance of a contract / legitimate interest |
| Comply with law (e.g. lawful orders, tax, accounting) | Relevant records | Legal obligation (PDPA §24(6) / GDPR Art. 6(1)(c)) |
Automated processing and AI. Try-on images are generated by machine-learning models, and outfit scores are computed automatically. These models run only on infrastructure operated by or for us (our servers and the data processors named in Section 6) — your photos are never sent to a third-party AI service for that service's own purposes, and we do not use your photos or content to train machine-learning models, ours or anyone else's. Outfit scores are for entertainment and styling inspiration only; no automated decision with legal or similarly significant effect is made about you.
5. Who can see your content
By default, only you. Your photos, looks, sticker cards, and wardrobe are visible only to your own signed-in account. Chammy has no public profiles, no followers, and no user-to-user browsing. Leaderboards and percentile features show only anonymous, aggregated numbers about skins (style templates), never about identifiable users.
If you choose to export or share a look or sticker card, the app saves it to your own photo library or hands it to your device's share sheet — from that point, distribution is under your control and outside the Service.
Share links (optional, you decide each time). You can choose to share one of your Sets as a web page hosted by us. If you do:
- The app makes copies of the card images you selected at that moment and publishes them on a page at a unique, hard-to-guess link (
chammy.cloud/s/…). The page shows only those image copies and the set's name — never your email, account, wardrobe, or anything else. - Anyone who has the link can open the page — treat the link like anything else you send to people. The page is not listed anywhere, and we tell search engines not to index it, but we cannot control who a recipient forwards the link to.
- Cards that use your body photo are NOT included by default. If a set contains such cards, the app asks you at share time; unless you explicitly choose to include your body photo for that specific share, the shared versions are composed without it (garments only). This choice is per share and is never remembered as a default.
- The shared page is a snapshot: later changes to your set or cards do not appear on it.
- You can remove a share link at any time in the app — the page and its image copies are deleted immediately, and the link stops working. Share links are also deleted when you delete your account (Section 8).
6. Who we share personal data with
We do not sell personal data, and we do not share it with advertisers or data brokers. We share data only with:
- Sign-in providers (Google LLC, Meta Platforms, Inc., Apple Inc.) — when you use their sign-in, the standard authentication exchange takes place with them under their own privacy policies. We receive your email and account identifier; we do not send them your photos or in-app activity.
- Hosting and infrastructure providers (data processors) — Hostinger International Ltd. (cloud server hosting; our servers are located in Malaysia), and — once on-photo try-on rendering launches — a serverless GPU compute provider (RunPod, Inc.) that processes try-on render jobs. They store and process data on our behalf, under contracts that restrict them to our instructions and require appropriate security (PDPA §40 data processing agreements / GDPR Art. 28 terms).
- Authorities and legal process — if required by applicable law, court order, or to protect the rights, safety, or property of our users, the public, or Chammy.
- Business transfers — if Chammy is involved in a merger, acquisition, or asset sale, personal data may transfer under confidentiality obligations; we will notify you of any change of controller or material change in practice.
Aggregated trend insights (not personal data). We may create statistics about how Chammy is used — for example, which styles, colors, or garment attributes are popular across the user base — by aggregating pseudonymized usage events (Section 3.6) across many users, with minimum group sizes and no identifiers. We may use these insights commercially, including sharing or selling them to partners such as fashion brands. They are anonymous by construction: they can never identify you, and they never include your photos or your individual wardrobe.
Sponsored content and advertising. Chammy is free and supported by clearly labeled sponsored content: announcements on the in-app billboard, and sponsored Skins, backdrops, or suggested garments (marked "Ad" or "Sponsored"). This is first-party advertising — chosen and served by us, not by an ad network. Sponsors receive only aggregated performance reports (e.g. total views and engagement counts), never your identity or personal data. We do not use third-party ad networks or advertising identifiers, and sponsored placements are not personalized to you using your personal data.
Affiliate shop links. Some garments shown in the app link to an external shop page. Some of these are affiliate links: if you open one (it opens in your browser) and make a purchase, we may earn a commission at no extra cost to you. Opening the link sends the merchant only the standard web request your browser makes — we do not send the merchant your identity or your Chammy data. The merchant's site is governed by its own privacy policy (Section 2).
One-time technical note: the machine-learning models we use are downloaded from their public distributors (e.g. Hugging Face, Google) when our servers are first set up. That download involves no user data. Model inference on your photos happens only on infrastructure operated by or for us (the processors above) — never on a third party's own AI service.
7. International data transfers
We are based in Thailand. Our servers are hosted in Malaysia. Where personal data is transferred out of Thailand, we do so in accordance with PDPA §28–29 — to destinations with adequate protection or under appropriate safeguards (such as contractual protections with our processors) — and, for EEA/UK users, under GDPR Chapter V mechanisms where applicable.
8. How long we keep your data
| Data | Retention |
|---|---|
| Photos, derived data, looks, sticker cards, skins, sets | Until you delete them in-app or delete your account |
| Share-link pages and their image copies (Section 5) | Until you remove the link in-app (immediate) or delete your account |
| Account data (email, provider IDs) | Until you delete your account |
| Data after account deletion | Permanently deleted from live systems within 30 days of a verified deletion request (in-app deletion takes effect immediately); residual copies in secured backups are purged on the backup rotation cycle, within 90 days |
| Usage analytics events (Section 3.6) | Up to 12 months from collection, then deleted or reduced to anonymous aggregates; purged when your account is deleted |
| Optional profile details (Section 3.8) | Until you change or clear them in the app, or delete your account |
| IP addresses used for rate limiting | Held only in server memory; not persisted |
| Technical/error logs | Up to 90 days, then deleted or anonymized |
| Records we must keep by law (if any) | For the legally required period only |
9. How we protect your data
- All traffic between the app and our servers is encrypted in transit (HTTPS/TLS).
- Sign-in tokens are stored in your device's secure storage, not in plain files.
- Your photos and data are stored with access controls so that only your authenticated account can retrieve them through the Service; media endpoints verify ownership on every request.
- Uploads are strictly validated (file type, size, and image-bomb protections) and rate-limited to prevent abuse.
- Access to production systems is restricted to authorized personnel who need it to operate the Service, and personnel access is logged. Server administration requires key-based authentication, and the administrative console additionally requires two-factor authentication.
- Servers receive security updates automatically and are protected by a firewall and intrusion-mitigation tooling; regular backups are kept so your data survives hardware failure.
- No system is 100% secure. If a data breach occurs that is likely to result in risk to you, we will notify the Thai Personal Data Protection Committee ("PDPC") within 72 hours as required by PDPA §37(4) and inform affected users where required.
10. Your rights and how to exercise them
Under the PDPA (and, where applicable, the GDPR) you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted ("right to be forgotten").
- Portability — receive your data in a commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — restrict processing in certain circumstances.
- Withdraw consent — at any time, for processing based on consent (including body-photo processing), without affecting prior lawful processing.
- Complain — lodge a complaint with the Personal Data Protection Committee (PDPC), Thailand (www.pdpc.or.th), or with your local supervisory authority if you are in the EEA/UK.
How to exercise these rights:
- In the app: you can delete individual photos, looks, sticker cards, skins, and sets at any time, remove any share link you created (the shared page disappears immediately — Section 5), and you can delete your entire account (with all its data) from Account → Delete account. You can also turn usage analytics (Section 3.6) off for your account at any time from Account → Data & Permissions — collection stops and the app keeps working exactly the same — and edit or clear the optional profile details (Section 3.8) any time from Account → Data & Permissions → About you.
- On the web / by email: follow the steps at https://chammy.cloud/legal/account-deletion or email support@chammy.cloud from the address linked to your account. We may ask you to verify ownership of the account before acting.
We will respond to rights requests without undue delay and in any event within 30 days (PDPA) of a verified request. Exercising your rights is free of charge.
11. Children
Chammy is not intended for children under 13, and you must be at least 13 to create an account (see the age requirements in our Terms of Service). We do not knowingly collect personal data from children under 13.
Body photos are for adults only. The body-photo features require an in-app confirmation that you are at least 18 years old and have reached the age of majority where you live (20 in Thailand); we do not knowingly process body photos of minors. Users aged 13–17 may use the non-body features (with the involvement and consent of a parent or legal guardian, per the Terms), which limits their data to garment photos, wardrobe content, and account data.
If you believe a child under 13 has an account, or that a minor has uploaded body photos, contact support@chammy.cloud and we will delete the data promptly.
12. Changes to this Policy
We may update this Policy from time to time. For material changes — especially any change to how body photos are processed — we will notify you in the app and, where required by law, ask for your renewed consent before the change applies to you. The "Last updated" date at the top shows the current version. Continued use of the Service after a non-material update takes effect constitutes acknowledgment of the revised Policy.
13. Contact
Questions, concerns, or rights requests: support@chammy.cloud Controller: Bhudiskul Amphansang, Thailand — postal address available on lawful request via the email above. Website: https://chammy.cloud
If you are not satisfied with our response, you may contact the Personal Data Protection Committee of Thailand or your local data protection authority.