The Decision Most People Skip
You open a new app. It asks you to scan your body or type in your measurements. You tap Allow and move on. That moment deserves more attention than it usually gets.
Body measurements are not neutral numbers. They are biometric data: persistent, unique, and linked to your physical identity. Once shared, they are difficult to unlink from you. The app collecting them may store them, share them with third parties, use them to train models, or sell access to them. Most people do not know which of those things is happening.
This post is about what to look for before you hand that data over, and what a responsible app should be able to show you.
Why Measurements Sit in a Different Category
A username can be changed. A password can be reset. A body measurement profile cannot be meaningfully anonymized once it is combined with your age, height, weight, and purchase history. That combination is specific enough to identify you in a dataset even without your name attached.
Several jurisdictions already treat biometric data as a protected category. Illinois' Biometric Information Privacy Act (BIPA) is the most cited example in the United States. The EU's GDPR places biometric data in a special category requiring explicit consent and stricter handling. California's CPRA extends similar protections. Compliance with these frameworks is not optional for apps operating in those markets. It is a legal floor, not a feature.
When an app asks for your measurements, it is asking you to contribute data that sits at or near that legal threshold. Treat it accordingly.
Six Things to Demand Before You Scan
1. A Plain-Language Privacy Policy That Covers Biometric Data Specifically
Generic privacy policies written to cover all user data are not sufficient. Look for a policy that names body measurements, body scans, or biometric data explicitly. It should state what is collected, how long it is retained, who can access it, and whether it is used for model training. If the policy does not address these points, that is an answer in itself.
2. Clear Disclosure of Third-Party Sharing
Ask whether your measurements are shared with brands, retailers, advertisers, or data brokers. Some apps are built on the premise of sharing your size data with partner brands to improve recommendations. That may be acceptable to you. It may not be. The point is that you should know before you scan, not after you read a headline about a data partnership.
3. Opt-Out Rights That Are Actually Usable
A privacy policy that grants you the right to delete your data is only useful if the deletion mechanism works. Test it. Request deletion of your account and your associated measurement data. A responsible app should confirm deletion in writing and specify how long the process takes. If the only path to deletion is a support email with no response SLA, that is a red flag.
4. On-Device Processing or Explicit Cloud Storage Disclosure
Body scan data can be processed on-device, meaning your measurements are computed locally and only the output (a set of numbers) is transmitted. Or raw scan data can be uploaded to a server. These are meaningfully different from a privacy standpoint. Ask which model the app uses. If raw video or depth data leaves your device, you should know where it goes and how it is secured.
5. No Sale of Measurement Data as a Default
Some apps monetize user data by selling it to third parties. Body measurement data should not be sold without your explicit, affirmative consent. Look for a clear statement that your data is not sold. If the policy uses language like "we may share data with trusted partners for purposes including marketing," that is not a prohibition on sale. It is permission dressed in softer language.
6. A Retention Limit
Data that is not retained cannot be breached. Ask how long the app keeps your measurement profile after you stop using the service. Indefinite retention is not a reasonable default for biometric data. A defined retention window, with automatic deletion after account closure, is a reasonable expectation.
What This Means for Brands Collecting Measurements
If you are an apparel brand or retailer building a sizing or fit tool, the same standards apply in reverse. You are the data controller. Your customers are entitled to the same disclosures listed above. Building a measurement collection flow without a biometric-specific privacy policy, a deletion mechanism, and a clear data-sharing disclosure is a compliance risk and a trust risk.
Returns driven by poor fit cost the apparel industry significant revenue every year. Solving that problem with body data is a reasonable goal. Doing it without adequate data governance is not.
The brands that will earn long-term trust from customers who care about fit are the ones that treat measurement data with the same seriousness they apply to payment data. That means internal data handling policies, vendor contracts that restrict downstream use, and customer-facing disclosures that do not require a law degree to parse.
Where Alex Folzi Stands
Alex Folzi is a pre-launch platform, currently waitlist-gated and under App Store review. Its premise is a single scan that builds a personal measurement profile, used to match garments to the person rather than the other way around. Because that premise depends entirely on body data, the privacy architecture is not an afterthought. It is the product.
The specific technical and legal details of Alex Folzi's data handling will be published as the platform moves toward launch. If you are on the waitlist, those details will be part of what you review before you scan.
The Short Version
Before you give any app your body measurements: read the biometric data section of the privacy policy (if there is none, stop there), confirm whether raw scan data leaves your device, verify that a real deletion mechanism exists, and check whether your data can be sold or shared with third parties without your consent. These are not unreasonable demands. They are the minimum.
Fit is a garment problem. Your data is yours.
If you work in apparel technology or data governance and want to think through responsible data collection practices, reach out to IT Custom Solution for a brief conversation about how managed services and compliance frameworks intersect in this space.