Skip to main content
Alex FolziOpen your wardrobe ↗
Menu

Journal Body Data & Privacy

Consent That Means Something: Why Body Data Should Be Off by Default and Deletable on Demand

Body measurements are intimate. Here is what off-by-default data settings and real deletion rights look like in practice, and why they matter.

The Decision Most Apps Skip

A shopper opens a fit app, taps through three permission screens, and scans their body. Somewhere in that flow, a checkbox grants the company rights to store, analyze, and in some cases share that scan. The checkbox is pre-ticked. The shopper is thinking about jeans, not data licensing. They tap Continue.

That moment is where body data consent breaks down. Not because users are careless, but because the defaults are set against them.

Why Body Measurements Are Different

A chest measurement is not the same as a browsing cookie. It is a permanent physical attribute. Combine chest, waist, hip, inseam, shoulder width, and neck circumference and you have a biometric profile that can follow a person across platforms, correlate with health data, and persist long after the original purchase decision.

Most privacy frameworks treat body scan data as ordinary personal data. Some jurisdictions classify it as biometric data, which triggers stricter rules. But classification alone does not protect anyone. The mechanism of consent does.

Off by Default: What It Actually Means

Off by default means the system collects only what is needed to complete the immediate task, and nothing else, unless the user explicitly enables additional uses. It is the opposite of the pre-ticked checkbox.

In practice, an off-by-default body data system looks like this:

  • Session-only storage. Measurements are used to generate a size recommendation, then discarded unless the user actively saves them.
  • Granular permissions. Saving a scan, sharing it with a brand, and allowing aggregate research are three separate choices, each requiring a distinct opt-in.
  • Plain language. Permissions are written in the same register as the rest of the product, not buried in a 4,000-word terms document.
  • No dark patterns. The Save my data button is not larger, brighter, or positioned to be the path of least resistance.

This is harder to build than a single consent banner. It requires product decisions, not just legal ones.

Deletable on Demand: The Harder Problem

Deletion rights exist in law in many markets. The General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in the United States both give users the right to request erasure. The gap is between the legal right and the operational reality.

Common failure modes:

  • Deletion requests routed to a support queue with no SLA.
  • The primary record deleted but derived data (model training sets, aggregated profiles) retained.
  • Data shared with third-party brands or logistics partners that are not covered by the deletion request.
  • No confirmation that deletion actually occurred.

Deletable on demand means the user submits one request, receives a timestamped confirmation, and the data is gone from every system where it was stored, including downstream partners. That requires data mapping: knowing exactly where each piece of data lives before a deletion request ever arrives.

The Brand Side of This Equation

Apparel brands that integrate body scan data into their sizing or returns workflows inherit the consent obligations of the data they receive. If a fit platform shares a customer's measurements with a brand to improve pattern grading, the brand is now a data processor. They need to know:

  • What consent the customer gave at the point of scan.
  • Whether that consent covers the brand's intended use.
  • What their obligation is if the customer later requests deletion.

This is not hypothetical. As body scanning becomes more common in retail, regulatory scrutiny of downstream data use is increasing. Brands that treat fit data as a free input to their product development process, without auditing the consent chain, are accumulating liability.

For Independent Tailors

A tailor who takes measurements by hand and writes them in a notebook is already operating a body data system. The notebook is low-tech, but the obligations are real. If that tailor moves to a digital system, whether a spreadsheet, a CRM, or a fit platform, the questions become:

  • Does the client know their measurements are stored digitally?
  • Can they ask for those measurements to be deleted?
  • Who else can access the system?

The answer to all three should be simple to give. If it is not, the system needs work before it needs more features.

What Alex Folzi Is Building Toward

Alex Folzi is a pre-launch platform, currently waitlist-gated and under App Store review, built on the premise that a person scans themselves once and maintains a real digital closet. The data model being developed treats body measurements as belonging to the user. That means off-by-default storage, explicit opt-in for any sharing, and deletion that actually removes data from the system rather than archiving it under a different label.

The iOS app is not generally available yet. But the consent architecture is a design constraint from the start, not a compliance layer added after launch. That order matters. Retrofitting consent onto a data model built for extraction is expensive and usually incomplete.

A Short Checklist for Any Fit Platform or Brand

  1. Are storage and sharing separate opt-ins, or bundled into one consent?
  2. Is the default state no storage or storage enabled?
  3. Can a user delete their data in under three steps?
  4. Does deletion cover derived data and downstream partners?
  5. Is there a timestamped confirmation of deletion?
  6. Has the consent language been tested with actual users, not just reviewed by legal?

Six questions. Most platforms cannot answer yes to all six today.

The Takeaway

Consent that means something is operational, not ornamental. It requires defaults set in the user's favor, deletion that reaches every system where data lives, and plain language that does not require a law degree to parse. Body measurements are intimate data. The systems that handle them should be built accordingly.

If you are thinking through data governance for a fit platform, a retail integration, or a tailoring practice moving to digital tools, IT Custom Solution's Consulting and AI Advisory practice works with teams on exactly these kinds of data architecture and compliance questions. Worth a conversation if the checklist above surfaced gaps.

← All Journal notes