SPOOKYFITS

SpookyFits Privacy Policy

Last Revised: October 29th, 2025

Effective Upon Tapping "Get Started" or Using the App

1. INTRODUCTION AND ACCEPTANCE

This Privacy Policy describes how SPOOKYFITS LLC, a limited liability company ("Company," "we," "us," or "our"), collects, uses, stores, and shares your information through the SpookyFits app and service. By tapping "Get Started" or using SpookyFits, you consent to the data practices described in this policy. Your continued use of the app after this "Last Revised" date constitutes acceptance of the updated Privacy Policy. If you do not agree, you must discontinue use of the app.

2. INFORMATION WE COLLECT

2.1 User Content and Personal Data

When you use SpookyFits, we collect the content you provide or generate. This includes photos or images of you, any other images or text you upload, and AI-generated outputs created through the app. Such content may contain personal data, including your likeness, biometric information in photos, your name, username, and any other identifying material you choose to provide. We also collect any feedback, comments, or messages you send within the app.

2.2 Biometric Data Collection and Use

SpookyFits collects and processes biometric data as part of its core functionality. When you upload a photo, we automatically extract facial geometry, facial landmark data, body measurements, and other physical characteristics from your photos.

Purpose: We collect biometric data to generate AI-powered costume transformations, improve transformation accuracy, detect human bodies in photos, and remove backgrounds. We do not use biometric data to identify you or verify your identity.

Retention: We retain your photos and biometric identifiers while your account is active. We make reasonable efforts to delete guest users' photos shortly after upload. You may request deletion of your photos and biometric data at any time by contacting support@spookyfits.com. Biometric data used for AI model training is retained only in anonymized form.

Consent and Opt-Out: By uploading photos and using transformation features, you consent to our collection and processing of your biometric data. You may withdraw consent by deleting your account or contacting support@spookyfits.com.

2.3 Automatic Data Collection

SpookyFits may automatically collect certain data, including device type, operating system, unique device identifiers, IP address, and general location information. We may use cookies or similar technologies to remember your preferences or track aggregate usage.

3. HOW WE USE YOUR INFORMATION

3.1 Providing and Improving the Service

We use your personal data and User Content to operate SpookyFits's core features, such as generating your costume images, displaying results to you, and allowing you to share or save them. We analyze usage patterns and feedback to fix bugs, train algorithms (for example, improving our AI models), and develop new features.

3.2 Marketing and Promotional Use

By using SpookyFits, you agree that the Company may use the content you upload or create (including your uploaded photos, your generated costume images, and any associated likeness or persona) for promotional, marketing, and commercial purposes with your consent. This means we may feature your before-and-after costume images, username, or any testimonials or feedback you provide in our advertisements, social media posts, app store previews, promotional emails, and on our website.

If you do not wish to have your content used for promotional purposes, you may opt out by contacting support@spookyfits.com with the subject line "Opt-Out of Promotional Use." We will remove your content from future promotional materials, though content already published in advertisements or marketing campaigns prior to your opt-out request may continue to appear as we cannot recall previously distributed materials. You may also request deletion of your content entirely, which will result in removal from our active systems as described in the Data Retention section below.

3.3 Third-Party Service Providers and Data Sharing

SpookyFits relies on third-party service providers to operate the Service. We share your personal data and User Content with the following categories of providers:

Third-party service providers are contractually required to protect your data and use it only for the purposes for which it was shared, in accordance with applicable law and this Privacy Policy. We do not currently sell your personal data to third parties in exchange for monetary compensation, though we may share data with affiliates, partners, and service providers as described in this Privacy Policy and our Terms of Service, including pursuant to the license you granted for User Content. To the extent required by applicable law (including the CCPA), you have the right to opt out of the "sale" or "sharing" of personal information as those terms are defined under such laws.

3.4 Personalization and Advertising

We may use your data to personalize your experience (for example, suggesting popular costume themes based on your usage) and to serve you relevant in-app offers. We do not sell your personal data to third-party advertisers.

3.5 Compliance and Safety

We may access, preserve, and share your information with law enforcement or other parties if we in good faith believe doing so is required to comply with law or legal process (such as responding to a subpoena or court order), or to protect the rights, property, or safety of the Company, our users, or the public. This can include disclosures for the purposes of intellectual property infringement investigations or to report unlawful content. If a third party claims that content you uploaded infringes their intellectual property rights or violates their legal rights, we may provide that third party with information about you (such as your registered email, account information, or other identifying information) so they can pursue the matter through appropriate legal channels. We may also share your information to enforce our Terms of Service or other policies, to respond to claims of content violation, or to comply with the Digital Millennium Copyright Act (DMCA) or other intellectual property laws.

4. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)

If you are a California resident, you have specific privacy rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

4.1 Your California Privacy Rights:

These rights are subject to limitations and exceptions under the CCPA and CPRA. We may retain information necessary for legal compliance, to complete transactions, or as otherwise permitted by law.

To exercise your California privacy rights, contact us at support@spookyfits.com with subject line "California Privacy Rights Request." We will respond within 45 days of receipt as required by law.

5. GUEST USERS AND REGISTERED USERS

5.1 Guest Users:

If you use SpookyFits without creating an account, we make reasonable efforts to delete your photos and biometric identifiers shortly after upload.

5.2 Registered Users:

If you create an account, photos, biometric data, and other User Content are retained while your account remains active, or until you delete the content or account.

6. EMAIL COMMUNICATIONS AND MARKETING

We may send transactional emails (account creation, password reset, subscription notices, policy updates) which you cannot opt out of, and marketing emails (new features, promotions, surveys) which you can opt out of by clicking "Unsubscribe" in any marketing email or contacting support@spookyfits.com.

7. ANALYTICS AND USAGE TRACKING

We collect detailed analytics and usage data including feature usage, navigation patterns, session data, interaction data, transformation metrics, device and technical data, crash reports, and performance metrics. We use this data for app improvement, bug fixing, user experience optimization, A/B testing, personalization, and business intelligence.

8. PHOTO STORAGE AND PROCESSING

When you upload a photo, we perform body detection, background removal, image optimization, and format conversion. Photos are stored in processed, optimized formats (PNG with alpha channel transparency) rather than as original uploads. Biometric data is extracted and stored separately as numeric data.

9. DATA RETENTION

We retain and use your information based on our consideration of various criteria, including whether we need the information to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, prevent harm, and protect the Services and our rights.

9.1 Retention While Account is Active

For registered users with active accounts, we retain personal information while your account remains active.

9.2 Retention After Account Deletion

When you delete your account, we will make reasonable efforts to delete your User Content (including photos, images, and AI-generated outputs) from our active systems. Some data may be anonymized and retained for analytics and AI model training. Data may persist in backups and disaster recovery systems as operationally necessary.

We may retain certain information as necessary for legitimate business purposes, legal compliance, fraud prevention, and operational requirements, including transaction records, data subject to legal obligations, and anonymized analytics data.

Content that has already been published in promotional materials prior to your deletion request may continue to appear in those already-distributed materials, as we cannot recall previously published content.

10. SECURITY MEASURES AND DATA PROTECTION

We implement reasonable security measures to protect your personal information and User Content from unauthorized access, disclosure, alteration, or destruction. However, no security measures are perfect, and we cannot guarantee that unauthorized access, hacking, data breaches, or other security incidents will never occur. Transmission of information via the internet and electronic storage of data inherently carries risks. By using SpookyFits, you acknowledge and accept these inherent risks. In the event of a security breach, we will take responsibility as required by applicable law and provide notifications as legally required.

10.1 Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify affected users as required by applicable law. Notification may be provided via in-app alert, email, or other means as permitted by law.

11. CHILDREN'S PRIVACY AND COPPA COMPLIANCE

SpookyFits is not intended for use by children under the age of 13, and we do not knowingly collect personal information from children under 13.

11.1 Prohibition on Use by Children Under 13

Children under 13 years of age are prohibited from using SpookyFits, creating accounts, or uploading photos. If we become aware that a user is under 13, we will delete the user's account and all associated data.

11.2 Parental Rights for Users Aged 13-17

Users between the ages of 13 and 17 may use SpookyFits with parental consent. Parents or legal guardians have the right to review, correct, or delete their child's personal information by contacting support@spookyfits.com with the subject line "Parental Privacy Request."

11.3 Reporting Underage Users

If you believe a user of SpookyFits is under 13 years of age, please contact support@spookyfits.com with the subject line "Underage User Report."

12. YOUR PRIVACY RIGHTS – SUMMARY

Depending on your jurisdiction, you may have the following rights, subject to limitations and exceptions under applicable law:

To exercise any of these rights, contact us at support@spookyfits.com with a clear subject line indicating your request. We will respond within the timeframes required by applicable law. We may require verification of your identity before fulfilling your request.

13. BUSINESS TRANSFERS AND ACQUISITIONS

In the event that the Company undergoes a business transition, such as a merger, acquisition, sale of assets, bankruptcy, or other corporate restructuring, your personal information and User Content may be transferred to a successor entity as part of the transaction. This transfer may occur without your prior consent, as permitted by law. The successor entity will assume the rights and obligations under this Privacy Policy and the Terms of Service.

14. CHANGES TO PRIVACY POLICY

We may update this Privacy Policy from time to time. The "Last Revised" date at the top will indicate when the latest changes became effective. If we make material changes, we will make reasonable efforts to notify users as required by applicable law. It is your responsibility to review this Privacy Policy periodically. By continuing to use SpookyFits after an update becomes effective, you acknowledge and agree to the revised policy. If you do not agree to the updated Privacy Policy, you must discontinue use of SpookyFits.

15. DISPUTE RESOLUTION, ARBITRATION, AND GOVERNING LAW

Any dispute, claim, or controversy arising out of or relating to this Privacy Policy, your personal information, our data practices, or your use of SpookyFits shall be subject to the dispute resolution, binding arbitration, class action waiver, and governing law provisions set forth in our Terms of Service, which are incorporated into this Privacy Policy by reference. You agree that any disputes regarding privacy, data protection, or this Privacy Policy will be resolved exclusively through binding arbitration on an individual basis (not as a class action), and you waive your right to a jury trial, as more fully described in the Terms of Service. The Terms of Service provisions governing dispute resolution, arbitration procedures, arbitration costs, governing law, and exceptions to arbitration apply equally to disputes arising under this Privacy Policy. This Privacy Policy and any disputes arising from it shall be governed by the laws specified in the Terms of Service, without regard to conflict of law principles.

16. SEVERABILITY AND INTEGRATION

If any provision of this Privacy Policy is found to be illegal, invalid, or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect, and the unenforceable provision shall be deemed modified to the minimum extent necessary to make it enforceable while preserving its intent to the greatest extent possible. This Privacy Policy, together with our Terms of Service, constitutes the entire agreement between you and the Company regarding the subject matter herein and supersedes any prior or contemporaneous understandings or agreements (whether written or oral) regarding privacy and data practices.

17. CONTACT

If you have questions or concerns about your privacy or our data practices, you can contact our support team at support@spookyfits.com. We value your trust and will do our best to address your concerns while balancing the innovative, community-driven nature of the SpookyFits experience.