Data Retention & Privacy
The FASHN API keeps a record of each request for usage analytics, monitoring, and debugging, and holds generated outputs for a limited time so you can retrieve them. Request records store request details such as parameters and URLs, not copies of your images, and outputs expire within days. This page lists what is retained and for how long, then shows how to limit retention further with short-lived signed URLs or base64 inputs.
What is retained, and for how long
| Data | What is kept | How long |
|---|---|---|
| Request record | Timestamp, model, parameters, submitted input URLs, <base64> placeholders for base64 inputs, output references, and status and error information | Not deleted automatically |
| Input image sent as a URL | The image is fetched only to process the request. The request record stores the submitted URL, not a copy of the image | The URL string stays with the request record |
| Input image sent as base64 | Used only to process the request | The temporary processing copy is deleted when the request finishes, with a one-day automatic cleanup backstop |
| Output as a CDN URL (default) | The output file on FASHN's CDN | Scheduled for deletion after three days |
Output as base64 (return_base64: true) | The output, returned by the status endpoint | Available for 60 minutes after completion, after which the status endpoint returns "<base64>_expired" |
| AI provider processing | Images and prompts, processed by FASHN's AI and infrastructure providers (Subprocessor List) only to run the request | Governed by provider data-processing agreements |
FASHN does not use Customer Content to train, fine-tune, or improve its own or third-party AI models unless you expressly opt in through a separate agreement. This commitment is set out in the Terms of Service.
What a request record can reveal
Request records power your API analytics, such as how many requests you made in the last 30 days, to which endpoints, how many succeeded or failed, and how many credits they used. You can also browse them in request history for monitoring and debugging. A record contains no image data of its own:
- Base64 inputs and outputs appear only as
<base64>placeholders. - Submitted URLs link to the image, which stays viewable only while the URL remains publicly accessible. A short-lived signed URL stops working once it expires.
- Output URLs stop serving the image once the output expires, although a CDN cache can briefly outlast deletion. Download any outputs you need to keep.
Deleting request records
There is currently no deletion endpoint. To have request records deleted, contact legal@fashn.ai and include your Organization and the relevant prediction IDs.
Minimizing what is retained
The examples below use Try-On Max. The same approaches apply to all other endpoints where applicable.
| Strategy | Send inputs as | Request record shows |
|---|---|---|
| Short-lived signed URLs (recommended) | URLs with the shortest validity period that still allows the request to complete | URLs that become inaccessible after expiry |
| Base64 | Base64-encoded strings | <base64> placeholders |
| Hybrid | URLs for non-sensitive images (product catalogs), base64 for sensitive images (customer photos) | Catalog image URLs and <base64> placeholders for customer photos |
Base64 increases the request size, so short-lived signed URLs are generally recommended for better reliability and can provide similar privacy. With any of these strategies, set return_base64: true to shorten the window during which the output is available.
A complete request using short-lived signed URLs:
To send base64 instead, replace each URL with a data URI. The hybrid approach combines the two. In the following inputs, the customer photo is sent as base64 and the catalog image as a URL:
Legal terms
FASHN's full terms are published in the Legal Center: the Terms of Service, Privacy Policy, Data Processing Addendum for business customers, and Subprocessor List.