Where photos live, what Ello stores and what it deliberately doesn't, and how data is deleted — written to be shown to your own customers if they ask.
The short version: Shopper photos and saved looks live on the shopper's own device. For each render, the photo is sent to the try-on model to generate the image and is not persistently stored on Ello's servers — Ello keeps anonymous usage events, not photos. Consent is presented at upload, the camera-based live mirror asks explicitly, and Shopify's GDPR deletion webhooks are fully implemented: uninstall the app and your event data is purged.
Anonymous usage events: a random session identifier (no name, no email, no account), which products were tried on, which pages and entry points were used, and cart/purchase events for attribution. This is what powers your analytics. Emails exist only if you enable the optional lead-capture prompt — and shoppers are told plainly: no spam, unsubscribe anytime.
| Event | What happens |
|---|---|
| Shopper clears browser data | Photo and wardrobe are gone — they only ever lived on the device. |
| Photo fails the body check | Any previously saved photo is actively cleared, not just ignored. |
| Customer data request / redact (GDPR) | Handled via Shopify's official privacy webhooks, verified and automated. |
| You uninstall Ello | Shopify sends the shop-redact webhook (~48h later) and Ello purges the store's event data — try-ons, widget events, carts, purchases, exposures. Retention is simple: kept while you have the app, deleted after. |
If a customer asks you about their photo: The honest one-liner: "Your photo stays on your device; it's sent once per try-on to generate the image and isn't stored on the servers." The full policy lives at ellotryon.com/legal.
No. The photo is forwarded to the try-on model to generate the result image and is not persistently stored on Ello's servers. The shopper's photo and saved looks live in their own browser, on their own device.
Ello implements all three of Shopify's mandatory privacy webhooks — customer data request, customer redact, and shop redact — with verification. Uninstalling the app triggers a purge of the store's event data.
Only if you turn on the optional lead-capture prompt, which asks after a number of try-ons you choose and never blocks the result. Captured emails are listed on the Leads page with CSV export.
Shoppers are identified only by a random session ID — no name, email, or account. That anonymous ID is what connects a try-on to a later purchase for your attribution.