The small print
Privacy policy
Last updated August 22, 2026
This Privacy Policy describes how Feminize collects, uses, discloses, retains and safeguards personal information. Please read it together with the Terms, which govern your use of the same services.
1. Introduction and Scope
1.1 This Privacy Policy (the “Policy”) describes the collection, use, disclosure, retention and safeguarding of Personal Information by Feminize (“Feminize”, “we”, “us” or “our”) in connection with the website located at feminizetheworld.com (the “Site”) and the Feminize mobile application (the “App”, and together with the Site, the “Services”).
1.2 Capitalised terms used but not otherwise defined where they first appear have the meanings given in Section 19 (Definitions).
1.3 This Policy is drafted from the Services as they are built. Where it describes what happens to a photograph, a record or an address, that description is intended to be exact rather than illustrative, and it is maintained as the software changes.
1.4 This Policy does not apply to any third-party website, application or service that the Services may link to, each of which is governed by its own privacy practices.
2. The Accountable Organisation and How to Reach Us
2.1 The Services are operated by Feminize, 29 Seneca Crescent, Brantford, Ontario, Canada, which is the organisation accountable for Personal Information under this Policy and which, for the purposes of the GDPR, acts as the controller in respect of that Personal Information.
2.2 Privacy enquiries, requests to exercise the rights described in Section 13, and complaints may be addressed to hello@feminizetheworld.com. We acknowledge such requests promptly and substantively respond within thirty (30) days, or within such shorter period as applicable law requires.
2.3 We have not appointed a data protection officer, no such appointment being required of an organisation of our size and processing profile, and enquiries reach a person rather than a queue.
3. Personal Information We Collect
3.1 Account Information. The email address with which you sign in; your name, where you supply one or where Apple or Google passes one to us; and either (a) a password, which is retained solely as a salted cryptographic hash from which the password cannot be recovered, or (b) a record that you authenticate through Apple or through Google. Where you use Apple’s Hide My Email facility, the only address we receive or hold is the relay address Apple issues, and that relay address is the address to which we write.
3.2 Pattern Content. The photographs you capture of pattern pieces, together with everything the software derives from them, including outlines, observations, measurements, semantic features, reconstructions, drafted pattern documents and the successive versions of those documents.
3.3 Transaction Information. The items you purchase, the amounts paid, the shipping and billing addresses supplied, and the contact details given at checkout. Payment card numbers are never transmitted to us and are never held by us: card data is collected and processed by Stripe, and we retain only Stripe’s record of the outcome of a payment together with the identifier by which that payment may be traced.
3.4 Communications and Marketing Preferences. Where you join the drop list, or ask to be told when an item has returned to stock, the address you supply for that purpose, retained until you unsubscribe.
3.5 Technical and Security Records. (a) Where a purchased digital pattern is downloaded, we record against the corresponding entitlement the time of the download, the IP address from which it was made and the browser user-agent string, retaining the fifty (50) most recent such records for that entitlement; this record exists to detect the redistribution of licensed files and for no other purpose. (b) IP addresses are processed transiently, and are not stored by us for this purpose, in order to apply rate limits and to protect checkout against automated abuse. (c) Our infrastructure providers generate ordinary server and request logs in the course of operating the Services, and those logs may contain IP addresses.
3.6 Information We Do Not Collect. We operate no advertising technology, no third-party analytics, no tracking pixels, no cross-site or cross-application tracking, no device fingerprinting and no behavioural profiling. We do not collect precise geolocation. We do not use your photographs for biometric identification, and the Services perform no facial recognition of any kind. We do not acquire Personal Information from data brokers.
4. Purposes for Which Personal Information Is Used
4.1 To provide the Services: to authenticate you, to process the photographs you submit into measurements and drafted pattern documents, to present that work back to you, and to maintain your account.
4.2 To improve measurement accuracy: the shapes and measurements the software derives from photographs, dissociated from your account, are used to improve the measuring itself, which is the mechanism by which each pattern you scan is measured more accurately than the last. Your photographs are not published, and the derived data used for this purpose is not attributed to you.
4.3 To fulfil transactions: to take payment through Stripe, to confirm, dispatch and where necessary refund an order, and to make available the digital patterns you have licensed.
4.4 To communicate with you: to send the transactional messages the Services require, including confirmations, dispatch notices, password resets and material changes to this Policy, and to send the marketing messages you have asked for and may stop at any time.
4.5 To secure the Services and comply with law: to detect and prevent fraud, abuse and the unauthorised redistribution of licensed files, to enforce the Terms, and to meet obligations imposed on us by applicable law, including the record-keeping obligations described in Section 11.
4.6 Limitation of purpose. Personal Information is not used for any purpose beyond those enumerated in this Section 4. In particular, and for the avoidance of doubt: nothing is sold, nothing is licensed to a third party for that third party’s own purposes, nothing is published, and nothing is used to determine or infer your identity, your characteristics or your behaviour beyond what operating the Services requires.
5. Legal Bases for Processing
5.1 This Section 5 applies where the GDPR or the UK GDPR governs our processing of your Personal Information. Where those regimes do not apply, our processing rests on consent, express or implied, in accordance with PIPEDA.
5.2 Performance of a contract (Article 6(1)(b)): the processing described at Sections 4.1, 4.3 and, so far as it concerns transactional messages, 4.4.
5.3 Legitimate interests (Article 6(1)(f)): the processing described at Sections 4.2 and 4.5, our legitimate interests being, respectively, the improvement of a product our customers rely on for accuracy, and the security and integrity of the Services. We have assessed those interests as not overridden by your interests or fundamental rights, having regard to the dissociation described at Section 4.2 and to the narrow scope of the records described at Section 3.5.
5.4 Consent (Article 6(1)(a)): marketing messages, and the transmission described in Section 7, which occurs only if you choose to use the pattern assistant. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
5.5 Compliance with a legal obligation (Article 6(1)(c)): the retention of transaction records described at Section 11.2.
6. Service Providers and Disclosure to Third Parties
6.1 We disclose Personal Information only to the service providers on which the Services run, each of which processes it on our instructions, for the purposes we specify, and for no purpose of its own. Those providers are:
6.1.1 Google Cloud Platform (Google LLC), which provides the compute, the database and the object storage in which your account, your Pattern Content and your orders are held, and which generates the operational logs described at Section 3.5(c);
6.1.2 Stripe, Inc., which collects and processes payment card data and effects payment, and to which we disclose the order amount, the currency and the contact and address details necessary to complete the transaction;
6.1.3 Resend (Plus Five Five, Inc.), which delivers the transactional and marketing email described at Section 4.4, and to which we disclose the recipient address and the contents of the message;
6.1.4 Apple Inc. and Google LLC, in their capacity as sign-in providers, and only where you choose to authenticate through them, in which case the exchange is limited to what the sign-in protocol carries; and
6.1.5 OpenAI, OpenCo, L.L.C., in the single and optional circumstance described in Section 7.
6.2 Domain name resolution for feminizetheworld.com is served by Cloudflare, Inc. Cloudflare is not interposed in the connection between you and the Services, does not terminate the encrypted connection and does not see the contents of your traffic.
6.3 We may disclose Personal Information where compelled to do so by a court of competent jurisdiction, by a lawfully issued order or demand, or by a legal or regulatory obligation to which we are subject. Where the law permits us to notify you of such a demand, we will.
6.4 If the business is sold, merged or reorganised, Personal Information may be transferred as part of that transaction. Any acquirer will be bound by commitments no less protective than those in this Policy, and you will be notified before your Personal Information becomes subject to a materially different policy.
6.5 We do not sell Personal Information, we do not share it for cross-context behavioural advertising, and we do not disclose it to advertising networks, data brokers or any other party for that party’s independent purposes.
7. The Pattern Assistant
7.1 The Services include an optional pattern assistant. If, and only if, you choose to use it, the message you write, the preceding turns of that conversation and the pattern document you are working on are transmitted to OpenAI in order that a response may be generated and returned to you.
7.2 The pattern document transmitted under Section 7.1 consists of the geometry the software has drafted — points, curves, seam allowances and their labels. Your photographs are not transmitted to OpenAI or to any other model provider, and no image data leaves our infrastructure for that purpose.
7.3 If you never open the pattern assistant, nothing whatever is transmitted under this Section 7.
7.4 Content transmitted under this Section 7 is sent through OpenAI’s application programming interface. We do not authorise the use of that content to train OpenAI’s models, and OpenAI’s applicable terms provide that content submitted through its interface is not so used absent the customer’s election, which we have not made.
8. Where Personal Information Is Held, and International Transfer
8.1 Personal Information is held on Google Cloud Platform infrastructure in the us-central1 region, in the United States, and with the service providers named in Section 6, whose own processing may occur in the United States or elsewhere.
8.2 It follows that Personal Information is subject to the laws of the United States and may be accessible to United States courts, law enforcement and regulatory authorities under those laws, including pursuant to lawful orders that we may be prohibited from disclosing to you.
8.3 Where Personal Information originating in the European Economic Area or the United Kingdom is transferred outside that territory, that transfer is made in reliance on the European Commission’s Standard Contractual Clauses, or the United Kingdom Addendum thereto, as incorporated into our agreements with the relevant service provider.
8.4 The rights conferred by Canadian, European and United Kingdom law over Personal Information are honoured in respect of Personal Information to which they apply, irrespective of the territory in which the servers holding it are situated.
9. Security Safeguards
9.1 We maintain administrative, technical and physical safeguards proportionate to the sensitivity of the Personal Information concerned, including those specified in this Section 9.
9.2 In transit. All connections to the Services are encrypted using Transport Layer Security. The Site asserts HTTP Strict Transport Security with a two-year maximum age, inclusive of subdomains, such that a conforming browser will refuse an unencrypted connection to it. Outbound electronic mail is transmitted over an implicitly encrypted channel.
9.3 At rest. Personal Information held in our database and in our object storage is encrypted at rest by the infrastructure providers named in Section 6.1.1, using keys those providers manage. We do not at present operate customer-managed encryption keys.
9.4 Credentials. Passwords are stored only as PBKDF2-HMAC-SHA256 derivations with a per-account random salt and a work factor of twenty-five thousand iterations, and are compared in constant time. We cannot read, recover or disclose your password, and no member of this business is able to do so.
9.5 Photographs. The storage bucket holding captured photographs is configured to prevent public access at the platform level; no photograph is reachable by URL alone. Photographs are uploaded from your device directly to that bucket under a short-lived signed authorisation, so that image bytes do not transit our application servers, and every subsequent read is authenticated and checked against the chain of ownership from the image to the account requesting it. A request that does not satisfy that check is refused.
9.6 Purchased pattern files. Purchased pattern files are streamed through the application behind a live entitlement check rather than exposed by redirect, so that a download link cannot outlive the entitlement it was issued against.
9.7 Access and secrets. Access to production systems is restricted to those who require it to operate the Services. Credentials for third-party services are held in a managed secret store and injected at runtime rather than committed to source or written to disk.
9.8 No method of transmission over the internet, and no method of electronic storage, is entirely secure. We do not warrant absolute security, and nothing in this Section 9 is to be read as such a warranty.
10. Breach Notification
10.1 In the event of a breach of security safeguards involving Personal Information under our control where it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual, we will report the breach to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, and will maintain the record of breaches that PIPEDA requires.
10.2 Where the GDPR or the UK GDPR applies, we will notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of a personal data breach, and will communicate the breach to affected data subjects where it is likely to result in a high risk to their rights and freedoms.
11. Retention and Disposal
11.1 Account Information and Pattern Content are retained for so long as your account subsists, and are erased on deletion of the account in accordance with Section 12.
11.2 Transaction Information is retained for six (6) years following the sale to which it relates, that being the period for which Canadian tax law requires a business to be able to produce its records. This retention is a legal obligation and survives deletion of your account, as Section 12.3 explains.
11.3 Marketing addresses are retained until you unsubscribe, upon which they are erased.
11.4 The download records described at Section 3.5(a) are retained for so long as the entitlement to which they attach subsists, and in any event only as to the fifty (50) most recent downloads of that entitlement, each earlier record being displaced as a later one is written.
11.5 Automated database backups are taken daily. A record erased from the live database may persist in a backup until that backup expires, which will not exceed thirty-five (35) days from the date of erasure. Backups are not consulted to restore an individual record that a person has asked us to erase.
11.6 Operational logs generated by our infrastructure providers are retained according to those providers’ default retention periods and are not consulted except in the course of diagnosing a fault or investigating a security incident.
12. Deletion of Your Account
12.1 You may delete your account from within the App, at Account, then Delete my account. No approval by us is required and the deletion is not reversible.
12.2 Deletion erases: the photographs themselves, as objects in storage; every capture session, piece, observation, measurement, reconstruction, semantic feature, drafted document and document version derived from them; your queued processing jobs and editor sessions; your sign-in credential, whether a password hash or a link to Apple or Google, and every active session; your account record, including your name; your saved addresses; your basket; and your subscriptions to the drop list and to any back-in-stock alert. If the pattern service cannot be reached to erase your photographs, the deletion fails and reports as failed rather than proceeding and leaving them behind.
12.3 Deletion does not erase: orders, their transactions and their receipts, which are retained for the statutory period stated at Section 11.2. You should understand precisely what that means, because it is not nothing — a retained order continues to contain the email address and the shipping address given at the time of the sale. It no longer refers to any account, and is not used to contact you or to build a profile of you; it survives as the record of a sale that the law requires us to be able to produce. Nor does deletion reach the entitlement records for patterns you have purchased and their associated download records, which are retained on the same basis, or the copies of transaction data held by Stripe and of delivered messages held by Resend, each of which is subject to that provider’s own retention practices, or the backups described at Section 11.5, or the operational logs described at Section 11.6.
12.4 If you purchased from the Site without creating an account in the App, or if you wish the erasure described at Section 12.2 to be carried out on your behalf, write to hello@feminizetheworld.com and it will be done.
13. Your Rights
13.1 Subject to the exceptions that applicable law provides, you have the right to: obtain confirmation of whether we hold Personal Information about you and a copy of it; have inaccurate Personal Information corrected; have Personal Information erased; object to, or obtain the restriction of, processing carried out on the basis of our legitimate interests; receive Personal Information you have provided in a structured, commonly used and machine-readable format and have it transmitted to another organisation; and withdraw a consent previously given.
13.2 To exercise any of those rights, write to hello@feminizetheworld.com. We may ask you to verify your identity where necessary to protect the Personal Information in question, and will not ask for more information than that verification requires. There is no charge for a request, save that we may charge a reasonable fee for a manifestly unfounded or excessive request, or refuse it, as applicable law permits.
13.3 We will not deny you goods or services, charge you a different price, or provide you a different level of service, because you exercised a right under this Section 13.
13.4 If you are dissatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada. If you are in the European Economic Area or the United Kingdom, you may instead complain to the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. Nothing in this Policy limits your right to do so, and we would rather you told us first.
14. Notice to Residents of California
14.1 This Section 14 supplements the remainder of this Policy and applies to residents of the State of California.
14.2 In the preceding twelve (12) months we have collected the following categories of personal information as those categories are defined by the California Consumer Privacy Act: identifiers, in the form described at Section 3.1; commercial information, in the form described at Section 3.3; internet or other electronic network activity information, in the form described at Section 3.5; and visual information, in the form of the photographs described at Section 3.2. The sources, purposes and recipients of each are as stated at Sections 3, 4 and 6 respectively.
14.3 We have not in the preceding twelve (12) months sold personal information, and we have not shared personal information for cross-context behavioural advertising. We do not have actual knowledge of selling or sharing the personal information of consumers under sixteen (16) years of age.
14.4 We do not use or disclose sensitive personal information for any purpose other than those permitted without a right to limit under the California Consumer Privacy Act and its implementing regulations.
14.5 California residents may exercise the rights to know, to delete, to correct and to non-discrimination as described at Section 13, and may do so through an authorised agent, in which case we will require written proof of that authorisation. Requests are made to hello@feminizetheworld.com.
15. Cookies and Local Storage
15.1 One cookie keeps you signed in. It holds a session token, is marked HttpOnly and Secure, is restricted to same-site requests, and expires fourteen (14) days after it is issued. Where you sign in through Apple or Google, short-lived cookies are also set for the duration of that redirect in order to defeat cross-site request forgery, and are discarded once it completes.
15.2 A cookie is additionally set for members of this business who are previewing unpublished editorial content in the administration interface. It is not set for ordinary visitors.
15.3 Certain preferences are held not in a cookie but in your browser’s local storage, which is to say on your own device, and are never transmitted to us. These are your choice of light or dark theme and, before you sign in, the identifier of your shopping basket.
15.4 There are no advertising cookies and no analytics cookies to consent to, which is why you are not asked to consent to any. The typefaces used on the Site are downloaded at the time the Site is built and are served from our own infrastructure, so that visiting the Site causes your browser to make no request to any third party other than Stripe, and that only at checkout.
16. Children
16.1 The Services are not directed to children under the age of thirteen (13), and accounts are not knowingly created for them. Where the GDPR applies, the Services are not directed to children under the age of sixteen (16) or such lower age, not below thirteen (13), as the relevant member state has specified.
16.2 If we learn that we hold Personal Information collected from a child below the applicable age without the consent required by law, we will erase it. A parent or guardian who believes that to have occurred should write to hello@feminizetheworld.com and we will act on it.
17. Automated Processing
17.1 The measurement of a photographed pattern piece is performed automatically by software. It is a measurement rather than a decision about you: it produces no legal effect concerning you and does not similarly significantly affect you, and it is therefore not a decision within the meaning of Article 22 of the GDPR.
17.2 The output of that processing is presented to you for your own inspection before you act on it, and Section 5 of the Terms explains the reliance you should and should not place on it.
18. Changes to This Policy
18.1 This Policy may be amended. The date shown at the head of this document is the date on which the words below it last changed, and it is set by hand rather than by the act of correcting a typographical error, so that it means what a reader takes it to mean.
18.2 Where an amendment is material — which is to say, where it alters what is collected, the purposes for which it is used, the parties to whom it is disclosed, or the period for which it is retained — every person holding an account will be notified by email before the amendment takes effect.
19. Definitions
19.1 “Personal Information” means information about an identifiable individual, and includes “personal data” as defined by the GDPR and “personal information” as defined by the California Consumer Privacy Act.
19.2 “Pattern Content” has the meaning given at Section 3.2.
19.3 “PIPEDA” means the Personal Information Protection and Electronic Documents Act (Canada), as amended, together with any legislation that replaces it.
19.4 “GDPR” means Regulation (EU) 2016/679, and “UK GDPR” means that Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018.
19.5 “Terms” means the terms of service governing use of the Services, available at feminizetheworld.com/terms.