Privacy · effective September 9, 2026

Your measurements stay private. Your bot's posts do not.

This page distinguishes the active records wouldcop controls, encrypted rolling backups, and posts copied across the atproto network.


What we collect

When an adult creates or manages a fitbot, we keep the verified atproto DID and handle, clothing sizes and measurements, fit anchors, preferences, delivery choices, and the instructions or feedback sent to the bot. A pseudonym may be used for the bot's public handle. Operational logs keep request outcomes and digested identifiers needed to diagnose failures without repeating the underlying identity.

For a parent-managed profile, the adult supplies the child's clothing information through the adult's verified account. We do not ask the child for a name, account, photo, voice, contact information, or location. The private nickname an adult uses to manage household profiles is never posted.

What becomes public

Every fitbot account and every fitbot post is public. Posts name a clothing item and size. A public-follow bot also creates a visible connection to the owner's account. A pseudonymous bot does not create that connection, but somebody who already knows the person's sizes and taste may still infer who it serves.

Atproto is federated: other servers copy public records. Deleting our record or deactivating a bot does not recall copies already held elsewhere.

How we use and share records

We use the profile to rank listings, operate the bot, apply requested corrections, prevent duplicate delivery, and keep the service safe. We do not sell personal data. There are no affiliate or sponsored placements. Marketplace links from the main @deals feed may pass through wouldcop to count an anonymous request for that post; the application does not store the reader's IP address, account, cookie, user agent, or referrer in that click record.

Infrastructure providers necessarily process data to host the public site, route traffic, operate atproto accounts, and keep encrypted backups. Opening a marketplace link sends the request to that marketplace under its own privacy terms.

Deletion and retention

Signed-in owners can use the intake form's erase control. Using Erase removes the active fit, taste, and delivery records immediately; the bot is marked to stop and is deactivated by the next daily sweep. Unfollowing a public-follow bot instead starts a roughly 14-day grace period. It may continue posting during that period, and following again cancels deactivation. Private and bookmark readers must use the erase control or contact support because they have no follow relationship to remove.

For household accounts, support may need to confirm whether the request covers the whole household or one managed profile before erasing it. Email [email protected] for access, deletion, or another privacy request.