Effective date: 27 July 2026 · Last updated: 27 July 2026
The Try-On is provided by Olena Gertsuska, an individual entrepreneur (empresário em nome individual / independent worker) established in Portugal, with tax identification number (NIF) 318064839, trading as “Morphy.Vision” (“Morphy”, “we”, “us”, “our”). “Morphy.Vision” is a business name; the data controller is the named individual above.
You will normally encounter the Try-On embedded on the website of an eyewear retailer or brand (the “Retailer”) whose products you are browsing. The relationship between us and the Retailer is described in Section 12.
| Question | Answer |
|---|---|
| Does the Try-On use my camera? | Only the Live Try-On does, and only after you tap “Enable Camera”. The 360° Viewer never uses the camera. |
| Is my camera video uploaded? | No. Video is processed frame-by-frame in your browser and discarded. It is never sent to us or to any third party. |
| Do you scan or store my face? | We compute face-position points on your device to place the glasses. These points are held in memory only for the instant they are used and are never stored or transmitted. |
| Do you use cookies or tracking? | No. The Try-On sets no cookies, uses no advertising or analytics trackers, and does not use browser local storage to profile you. |
| Do you sell my data? | No. We do not sell or “share” (as defined by California law) personal information, and we do not use it for cross-context behavioural advertising. |
| Who can see my try-on session? | Only you, on your own screen. |
| What does leave my device? | Only ordinary technical requests needed to load the app (e.g. your IP address and browser type reaching our hosting provider), the same as visiting any website. See Section 4. |
This policy covers the Morphy.Vision Try-On application (the Live Try-On and the 360° Viewer) wherever it is embedded or hosted.
It does not cover:
Note on “biometric” data. Because these measurements are used solely to place a graphic on screen, are processed only on your device, are never retained, and are never used to identify a specific individual, we do not use them as biometric identifiers. Even so, because some laws define biometric terms broadly, we address them expressly in Section 11 (Illinois, Texas, Washington and similar) and treat this category with the highest level of care.
To deliver the Try-On to your browser, the application files (code, 3D glasses models, fonts) are served from our hosting/CDN provider. As with visiting any website, your browser’s request necessarily includes:
Our hosting provider may process this in server logs for security, fraud prevention, load balancing and reliability. We do not use this data to build a profile of you, and we do not combine it with the camera/face processing (which never reaches any server).
The app loads a small configuration file (models.json) listing available frames and their images.
This is generic product data and contains no information about you.
| Processing activity | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Running the on-device camera & face-position processing | To provide the try-on visual you requested | Consent (Art. 6(1)(a)), given by tapping “Enable Camera”; and/or performance of the service you requested. You may withdraw consent at any time by closing the window or revoking camera permission. |
| Serving the application files (technical/hosting data) | To deliver, secure and maintain the Service | Legitimate interests (Art. 6(1)(f)) in operating and securing the Service |
| Ensuring security and preventing abuse | Protecting the Service and users | Legitimate interests (Art. 6(1)(f)) and legal obligations |
To the extent any face-position processing were ever treated as special-category (biometric) data under Article 9, our basis would be your explicit consent (Art. 9(2)(a)) — but as explained above, this data is never stored or used to identify you.
We use the limited information described above only to:
We do not use any information for advertising, profiling, automated decision-making with legal or similarly significant effects, or to train machine-learning models on your face.
We do not sell or rent personal information, and we share it only as follows:
The on-device machine-learning model is Google’s open-source MediaPipe, which we self-host; using the Try-On sends no request and no data to Google.
A current list of sub-processors is available on request at privacy@morphy.vision.
The camera and face-position processing happens on your own device and is not transferred anywhere. For the limited technical/hosting data (Section 4.3), our provider (Vercel Inc.) serves the application via a global edge/CDN network and is established in the United States, so data may be processed in the United States and other regions. Where such processing involves transfers out of the EEA, the UK or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and/or the applicable Data Privacy Framework, as applicable. You may request details of these safeguards using the contact in Section 15.
Depending on where you live, you may have some or all of the rights below. Because we do not retain your camera or face data and hold no account for you, in most cases we will have no personal information about you to access, correct or delete beyond transient hosting logs.
EEA / UK / Switzerland (GDPR / UK GDPR): the rights to access, rectification, erasure, restriction, objection, data portability, and to withdraw consent at any time, plus the right to lodge a complaint with your supervisory authority (e.g. your national data protection authority, or the UK ICO).
California (CCPA/CPRA): the rights to know, access, delete, and correct personal information; to opt out of sale/sharing and of certain use of sensitive personal information; and to non-discrimination for exercising your rights. We do not sell or share personal information and do not use sensitive personal information for purposes requiring an opt-out. “Shine the Light” requests: we do not disclose personal information to third parties for their direct marketing.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other US states with comprehensive privacy laws: the rights to access, correct, delete, obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in those activities through the Try-On.
Canada (PIPEDA / Québec Law 25), Brazil (LGPD), Australia (Privacy Act), and other jurisdictions: equivalent rights of access, correction, deletion and withdrawal of consent, and the right to complain to your local regulator (e.g. the OPC, ANPD, or OAIC).
How to exercise your rights: contact us at privacy@morphy.vision. We will respond within the timeframe required by applicable law. We may need to verify your request; because we hold so little data, verification may be limited to the information contained in your request. You may use an authorised agent where the law permits.
This section addresses laws that regulate “biometric identifiers” or “biometric information,” including the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington’s biometric law (RCW 19.375).
If, in the future, we introduce any feature that would collect or store biometric identifiers, we will first provide the specific written notice and obtain the written consent (release) required by applicable law, and publish the required retention-and-destruction schedule.
The Try-On is not directed to children and does not knowingly collect personal information from children. Because no camera or face data is retained, the Service does not create records about any user, including minors. If you believe a child has used the Service in a way that raises a concern, contact us at privacy@morphy.vision. Retailers are responsible for any age-related restrictions on their own sites.
Because the sensitive processing happens on your device and nothing is uploaded, the primary protection for your camera and face data is architectural: there is no server-side copy to breach. For the limited technical data that does reach our hosting provider, we and our provider maintain appropriate technical and organisational measures, including encryption in transit (HTTPS/TLS), access controls, and secure, industry-standard infrastructure. The Service is served only over HTTPS, which browsers require for camera access.
For any privacy question or to exercise your rights:
We are established in Portugal, and our lead supervisory authority is the Portuguese Comissão Nacional de Proteção de Dados (CNPD) (www.cnpd.pt). If you are in the EEA/UK/Switzerland you may also lodge a complaint with your local supervisory authority; if you are in another jurisdiction, with your local data protection or consumer-protection regulator.
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice where appropriate. The version in force is the one published with the Service at the time you use it.