# ClosyAI Privacy Policy

**Effective Date:** September 9, 2025
**Last Updated:** June 17, 2026

ClosyAI Inc. ("ClosyAI," "we," "our," or "us") provides a mobile application and website that helps users organise their wardrobes, generate AI-powered outfits, and plan what to wear for events. We respect your privacy and are committed to protecting your personal information.

---

## 1. Information We Collect

**Account Information**
Your email address and password (stored as a secure hash) when you register. If you sign in via Apple or Google, we receive only the information those services make available (typically email and name).

**User Content**
Photos of clothing items you upload, outfit combinations you save, style preferences, occasion and weather settings, and any notes or custom labels you add. When you upload a clothing photo, it is sent to Google Vertex AI (Gemini models) in the EU for automated garment detection and attribute classification (colour, type, fit, formality, material). This powers your digital closet — no photo is shared with other users or used to train third-party AI models.

**Profile and Preferences**
Gender, style preferences (e.g. casual, elegant, sporty), colour preferences, occasion preferences, hair and nail colour, and other personalisation settings you provide.

**Calendar Data**
If you enable calendar sync, we access the events on your device calendar solely to display them inside the app for outfit planning. We do not store raw calendar event data on our servers beyond the event details you explicitly import into ClosyAI.

**Location Data**
If you allow location access, we use your approximate GPS coordinates to look up local weather conditions and suggest weather-appropriate outfits. We do not store your precise location or build a location history.

**Push Notification Tokens**
If you grant notification permission, we store a device token to send you outfit reminders and upload completion alerts. You can revoke permission at any time in your device Settings.

**Device and Usage Information**
App version, device model, operating system version, and pseudonymised event data (e.g. screens visited, features used) to diagnose issues and improve the app. In production builds, crash reports and error stack traces are collected via Sentry to help us identify and fix bugs. Sentry events are tagged with a pseudonymised 8-character prefix derived from your Supabase user UUID (not your email, name, or any other personal identifier); this prefix is stable per-user so we can correlate crash patterns for a single account during diagnostics. Sentry data does not include your clothing photos or outfit content.

**Analytics Data**
Pseudonymised usage events collected via PostHog to understand how features are used and improve the product. PostHog `distinct_id` is your Supabase user UUID — a pseudonymous identifier that does not contain your email, name, or any other directly identifying field, but is a stable per-user reference. This data does not include photos or outfit content. These identifiers are not personally identifying on their own but can be joined with our user database if we re-identify them; we treat them as pseudonymised data and protect them accordingly.

**Subscription and Purchase Data**
If you subscribe to Closy Pro or Closy Pro+, Apple processes payment on your behalf. We receive confirmation of your subscription status (active, cancelled, expired) and the subscription expiry date from RevenueCat, our subscription management provider. We do not receive or store your payment card details.

**Receipt-Ingestion Data**

ClosyAI offers optional ways to add items to your closet beyond uploading photos: forwarding retailer order-confirmation emails to a unique ClosyAI alias, pasting product URLs, or uploading screenshots of receipts. If you use these features, we collect:

- **Forwarded email content.** If you forward an email to your unique alias (`<token>@inbound.closyai.com`), we receive the full email — sender address, subject, body text and HTML, and message headers including authentication signatures used to verify the sender is a legitimate retailer. We never read your mailbox; we only receive what you (or a forwarding rule you set up in your email provider) explicitly send to your alias.
- **Purchase information extracted from those receipts.** Item names, brands, colours, sizes, prices, order numbers, retailer names, and product image URLs. This information is presented to you for review before any closet entry is created — nothing is added to your closet without your explicit Approve action.
- **Pasted URLs and uploaded receipt images.** If you use an "Import a Receipt" feature, we receive the URL or image you submit. URLs are fetched server-side to extract product details. Receipt images are processed via OCR and pattern recognition.

**Receipt-ingestion retention.** Raw forwarded email content (including third-party CC addresses, original message headers, and any personal correspondence visible in the message) is automatically purged from our systems **within 30 days** of receipt. Only the structured item attributes that you explicitly approve persist as your closet entries.

**Body Photo (Optional, Pro+ Virtual Try-On feature)**
If you enable the Virtual Try-On feature available to Pro+ subscribers, you may optionally upload a single full-body photo of yourself to render outfits onto. This photo is private to your account.

- **Why we collect it.** Your body photo is the reference image used to generate Virtual Try-On renders showing how outfits from your closet would look on you.
- **Where it is stored.** In a private, access-controlled storage bucket. Only your authenticated account can read, replace, or delete it. ClosyAI staff do not access body photos in normal operation.
- **Where it is sent.** When you initiate a Try-On render with your body photo, your photo is sent — alongside the relevant clothing item images from your closet — to Google's Gemini image-generation service (Vertex AI) for the rendering call. This specific render uses a Gemini 3 image model that Google currently serves only via a **global endpoint**: your body-photo data is **stored at rest in the EU**, but the **image-generation processing itself may take place outside the EEA** (e.g. in the United States). This transfer is governed by Google's Cloud Data Processing Addendum, the EU Standard Contractual Clauses, and Google's EU-US Data Privacy Framework certification; Google's Vertex AI terms state that this content is **not used to train Google's models** and is not subject to human review, and abuse logs are retained no more than 55 days. ClosyAI does not retain any copy of your body photo on Google's systems beyond the duration of the rendering call. *(The mannequin alternative below, and all of our other AI processing, stay within the EU region — only the body-photo "Me" render uses the global endpoint.)*
- **You control it.** You can re-take or delete your body photo at any time via Profile → Body Photo. Deletion removes the photo from our storage immediately. Account deletion also removes any uploaded body photo.
- **Mannequin alternative.** You may use Virtual Try-On without uploading a body photo. In that case, ClosyAI generates a one-time fashion mannequin tailored to your gender and skin-shade profile fields. The mannequin is not based on your photograph.
- **Sharing privacy invariant.** When you share or save a Virtual Try-On render, you choose at the time of action whether to use the version rendered on your body photo or the mannequin variant. The default is the variant you are currently viewing. We surface a [Me] / [Mannequin] toggle prominently so the choice is explicit. The mannequin-only fallback for shared images remains available at server level should it be re-enabled in the future.

**Virtual Try-On Rendered Images**
The PNG images produced by Virtual Try-On renders are stored in your account's private storage and are deleted automatically after **90 days** of generation, or sooner if you delete your account. You can re-render any outfit at any time within your monthly quota.

---

## 1A. Legal Basis for Processing (EEA/UK users)

Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases for processing your personal data:

- **Contract (Art 6(1)(b))** — account creation, closet storage, outfit generation, calendar planning, subscription management, transactional emails (welcome, password reset, deletion confirmation). Required to deliver the Services you signed up for.
- **Consent (Art 6(1)(a))** — location access, push notifications, optional product analytics, body-photo upload and Virtual Try-On, calendar sync, receipt-email forwarding, monthly Style Digest. You may withdraw consent at any time in Settings; withdrawal does not affect prior lawful processing.
- **Legitimate interest (Art 6(1)(f))** — crash diagnostics (Sentry), pseudonymised funnel analytics (PostHog), fraud prevention, security monitoring. Our interest is operating a reliable, secure Service; we balance this against your privacy by minimising data collected and pseudonymising where possible. You may object via support@closyai.com.
- **Legal obligation (Art 6(1)(c))** — tax records, lawful disclosure requests, App Store / RevenueCat receipt retention required by accounting law.

---

## 2. How We Use Your Information

We use your information to:

- Provide core app functionality — closet storage, AI outfit generation, event planning, and outfit history.
- Personalise outfit suggestions based on your style preferences, saved items, and occasion.
- Send transactional emails (account confirmation, password reset, subscription status changes).
- Send push notifications for outfit reminders, upload completions, and feature updates (only if you have granted permission).
- Detect weather at your location to generate weather-appropriate outfit suggestions.
- Display your device calendar events inside the app for outfit planning (only if you enable calendar sync).
- Generate AI-powered wardrobe insights for Pro+ subscribers, including seasonal readiness scores, wardrobe gap analysis, and closet analytics.
- Generate Virtual Try-On image renders for Pro+ subscribers — composite your body photo (or a generated mannequin) with clothing item images from your closet, via Google's Gemini image-generation API.
- Send a monthly personalised Style Digest email to Pro+ subscribers who have opted in, summarising their most-worn pieces and outfit patterns.
- Analyse pseudonymised usage data to fix bugs and improve the product.
- Process and manage your Closy Pro subscription.
- Respond to support inquiries.
- Enforce our Terms of Use and comply with legal requirements.

We do not use your clothing photos or outfit data to train AI models belonging to third parties.

---

## 3. Data Sharing

We do not sell or rent your personal data.

We share limited data with the following categories of service providers solely to operate the app:

| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, file storage, authentication, serverless functions | Account data, user content, preferences |
| RevenueCat | Subscription lifecycle management | Subscription status, expiry date, Apple subscriber ID |
| Resend | Transactional email delivery | Email address, first name |
| Expo / EAS | App distribution and push notification delivery | Push notification tokens |
| PostHog | Pseudonymised product analytics (EU Cloud — `eu.posthog.com`). `distinct_id` is the user's Supabase UUID (pseudonymous, not directly identifying on its own but joinable with our user database). | Usage events (no photos or content) |
| Sentry | Crash reporting and error diagnostics (production only). User events tagged with a pseudonymised 8-character prefix derived from the Supabase user UUID. | Device model, OS version, pseudonymised crash traces and stack traces |
| Mapbox / Photon | Event location geocoding — converts location names you enter into coordinates for weather lookup | Location text entered by you for events (e.g. "Paris, France") |
| Google Cloud (Vertex AI — Gemini models) | All AI/ML processing: garment photo analysis (detect-components, analyze-llm), outfit generation, AI-powered wardrobe report, monthly style digest copy, receipt content extraction, receipt-screenshot OCR, in-store item check, mannequin generation, and Virtual Try-On image rendering (Pro+). Since 2026-06-11, these surfaces route through Vertex AI's `europe-west1` endpoint under the EU Data Boundary (Assured Workloads — `regional-data-boundary` regime). **Exception (since 2026-06-16): the Virtual Try-On "Me" render** (compositing your body photo with clothing) uses a Gemini 3 image model that Google serves **only via a global endpoint** — data is **stored at rest in the EU** but **ML processing may occur outside the EEA** (e.g. the US), under Google's Cloud DPA + EU Standard Contractual Clauses + EU-US Data Privacy Framework. In all cases, per Google's Vertex AI Service Specific Terms §17 (no training), DPA §7.1.2 (no eyes-on review), and SST §19h (no output storage beyond what is necessary to generate the response). | Clothing photos, anonymised item attributes, prompts, wardrobe summary data (Pro+ wardrobe report), receipt content (forwarded retailer emails, pasted product URLs, uploaded receipt images), body photo and selected clothing images during Try-On render calls. |
| Postmark | Inbound email reception for the receipt-ingestion forwarding alias | Forwarded retailer email content (subject, body, headers) when you use email-forwarding receipt-import. |
| Bright Data | Server-side fetching of product pages from retailers that block direct fetches (Amazon, etc.) | The URL you pasted; the page content received from the retailer (used solely for item extraction; not stored beyond the 30-day raw-payload retention window). |
| Clipdrop (Stability AI) | Fallback background removal when client-side cutout is unavailable | Limited fallback for client-side cutout failure on receipt-imported items only. Native iOS/Android on-device background removal is the primary cutout path for user-uploaded photos and most scanner items; Clipdrop is rarely invoked. |
| Replicate (Marqo / fashionSigLIP) | Visual embeddings used to improve outfit variety and similar-item lookup | Closet item images (cutout) and pseudonymous user identifier. Vendor's posted policy is no training on customer content; DPA pending (see §6). |
| Apple / Google | Payment processing for in-app subscriptions | Handled entirely by the respective platform; we receive only subscription status |

We may disclose personal data if required by applicable law, court order, or to protect ClosyAI's legal rights.

---

## 3A. Automated Processing and AI Models

ClosyAI uses automated processing extensively to deliver core features: garment classification (color, garment type, material, formality, season), outfit generation, wardrobe-gap analysis, weather-appropriate scoring, body-photo classification (full-body vs partial), and Virtual Try-On image rendering. We rely primarily on Google Vertex AI Gemini models (currently `gemini-2.5-flash` and `gemini-2.5-flash-lite` for text/vision, `gemini-2.5-flash-image` for mannequin image generation, and `gemini-3.1-flash-image` for the Virtual Try-On "Me" body-photo render) routed through the EU Data Boundary as described in §6 — except the Try-On "Me" render, which runs on a global endpoint as described there.

These automated decisions **do not produce legal or similarly significant effects on you** under Art 22 GDPR. You can override any AI suggestion, edit any item attribute we have inferred about your closet, regenerate any outfit, and request human review of any automated outcome by contacting support@closyai.com.

---

## 4. Data Retention

We retain your data for as long as your account is active. If you delete your account:

- **Personal data** (account information, uploaded photos, closet items, outfits, events, preferences, and associated records) is deleted from our systems immediately upon account deletion.
- **Receipt-ingestion raw payloads** — raw forwarded email content, pasted URL contents, and uploaded receipt images you submit are automatically purged from our systems within **30 days** of receipt, regardless of whether your account is active. Only the structured item attributes you explicitly approve persist as closet entries.
- **Body Photo (Virtual Try-On)** — retained until you delete it via Profile → Body Photo, or until account deletion. Replacing it removes the prior version. The photo is never shared between users or used for any purpose besides generating Virtual Try-On renders for your own account.
- **Virtual Try-On rendered images** — automatically purged from our systems **90 days** after generation, regardless of whether your account is active. You can re-render any outfit at any time within your monthly quota (30 renders included with Pro+; additional via the Try-On Power Pack consumable).
- **Per-user generated mannequin** — if you have used Virtual Try-On with the mannequin option, a single generated PNG sized to your gender and skin-shade profile fields is cached in the same private storage bucket as body photos. It is regenerated when you tap "Regenerate mannequin" in Settings. Account deletion removes it.
- **Email forwarding aliases** — if you configure a per-user alias for receipt-ingestion, you can revoke it from in-app Settings at any time, which immediately invalidates the alias at our mail provider; future mail to the old alias is dropped. Account deletion also revokes any active alias.
- **Anonymised usage data** — behavioural events such as feature usage patterns, generation counts, and interaction timing — may be retained indefinitely in pseudonymised form. This data has your identity permanently removed (your user identifier is replaced with an anonymous token) and cannot reasonably be re-linked to you. It is used solely for aggregate product analytics and improving the app.

You may request deletion at any time by using the "Delete account" option in Settings, or by emailing support@closyai.com. If you wish to request deletion of pseudonymised records that may have originated from your account, contact us at support@closyai.com. Note that because these records contain no personal identifiers, we cannot guarantee all such records can be identified and removed.

---

## 5. Subscriptions and In-App Purchases

ClosyAI offers optional paid subscriptions ("Closy Pro" and "Closy Pro+") processed entirely through Apple's App Store. We do not collect, see, or store your payment details — all billing is handled by Apple.

**Subscription plans:**
- Closy Pro Monthly: $14.99 per month, no free trial
- Closy Pro Annual: $119.99 per year ($10.00/month), with a 7-day free trial for new subscribers
- Closy Pro+ Monthly: $29.99 per month, no free trial
- Closy Pro+ Annual: $199.99 per year ($16.67/month), with a 7-day free trial for new subscribers

**Free trial:** A 7-day free trial is available on both annual plans (Closy Pro Annual and Closy Pro+ Annual) for new subscribers only (one trial per Apple ID). Full plan access is granted during the trial. Payment is charged to your Apple ID account at the end of the trial period unless cancelled at least 24 hours before the trial ends.

**Auto-renewal:** Subscriptions automatically renew at the end of each billing period unless cancelled at least 24 hours before the renewal date. Your Apple ID account is charged for renewal within 24 hours prior to the end of the current period.

**Managing or cancelling:** Go to iOS Settings → [Your Name] → Subscriptions → Closy Pro, or visit [apple.com/bill](https://support.apple.com/billing). Cancelling stops future renewals; you retain Pro access until the end of the current paid period.

**Refunds:** All refund requests are handled directly by Apple. To request a refund, visit [reportaproblem.apple.com](https://reportaproblem.apple.com).

**Downgrade:** When a subscription expires or is cancelled, your account reverts to the free tier. Your closet, outfit history, and all data are always retained — nothing is deleted on downgrade.

---

## 6. International Data Transfers

Personal data may be transferred to and processed in the United States and other countries outside the EEA/UK by the following processors: Supabase (US — AWS us-east-2), Google Cloud / Vertex AI (EU `europe-west1` under EU Data Boundary for all processing EXCEPT the Virtual Try-On "Me" body-photo render, which uses a Gemini 3 image model on Google's global endpoint — EU residency at rest, processing may occur in the US; covered by Google's Cloud DPA, SCCs, and EU-US Data Privacy Framework), Postmark (US), Sentry (per DSN region), PostHog (EU Cloud — `eu.posthog.com`), Resend (US), RevenueCat (US), Apple (US, IAP infrastructure includes EU regions), Expo/EAS (US), Mapbox (US) / Photon (DE) for geocoding, Bright Data (distributed; currently inactive), Clipdrop / Stability AI (EU — France), and Replicate (US).

For transfers to countries that the European Commission has not deemed to provide an adequate level of protection, we rely on:

- **EU Standard Contractual Clauses (2021/914)** with each US-based processor;
- **UK International Data Transfer Addendum** for UK users;
- **Supplementary technical and organisational measures** including TLS-in-transit, at-rest encryption (Supabase Storage + Postgres), EU Data Boundary / Assured Workloads region selection for Vertex AI workloads (active since 2026-06-11), per-user signed-URL access controls on closet and body photo buckets, and access logging;
- **Transfer Impact Assessments (TIAs)** completed for each named processor.

Copies of SCCs and TIA summaries are available on request from support@closyai.com.

---

## 7. Security

We use industry-standard safeguards including encryption in transit (TLS), encrypted storage, and row-level security on our database. However, no system is 100% secure. If you believe your account has been compromised, contact us immediately at support@closyai.com.

---

## 8. Cookies and Tracking

**Mobile app.** The ClosyAI mobile app does not use browser cookies. It uses PostHog for pseudonymised in-app analytics as described in Section 1, which you can disable in **Settings → Privacy → Product Analytics**. The app does not include any third-party advertising SDKs, cross-app tracking SDKs, or cross-site tracking technologies, and does not request App Tracking Transparency (ATT) permission.

**Website (closyai.com).** Our marketing website may use strictly necessary cookies to operate the site, and where applicable a consent banner for any non-essential analytics or preference cookies (EEA/UK only). You can control cookies through your browser settings. Where the consent banner is shown, you may accept, reject, or manage individual categories.

---

## 9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

- **Access and Portability:** Request a copy of the data we hold about you. You can also generate a portable export yourself from **Settings → Privacy → Export My Data**, which produces a JSON archive of your account data (closet, outfits, events, preferences).
- **Correction:** Request correction of inaccurate data. Most profile and item attributes are editable directly in the app.
- **Deletion ("right to be forgotten"):** Use **Settings → Delete Account** for immediate self-service deletion, or email support@closyai.com (see Section 4 for what is deleted, retained, or anonymised).
- **Objection / Restriction (Art 21):** You may object to processing based on our legitimate interests (e.g. diagnostics analytics) — see channel-specific controls below — or request restriction by emailing support@closyai.com.
- **Withdraw consent (Art 7(3)):** Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

**Channel-specific opt-outs (Art 21 right to object to marketing):**

- **Push notifications** (outfit reminders, upload-completion alerts, feature updates): toggle per-category in **Settings → Notifications**, or revoke all push permission in your device Settings.
- **Transactional email** (account confirmation, password reset, subscription receipts, deletion confirmation): these are sent on the contractual legal basis and cannot be opted out of while your account is active; deleting your account stops them.
- **Style Digest / promotional email** (Pro+ monthly summary, product updates): opt in via **Settings → Email Preferences**; opt out at any time from the same screen or via the unsubscribe link in each email.
- **In-app product analytics (PostHog)**: opt out in **Settings → Privacy → Product Analytics**.

**GDPR (EEA/UK):** ClosyAI Inc. is the data controller for the personal data described in this Policy. You have the right to lodge a complaint with your local data protection supervisory authority (a list is maintained by the European Data Protection Board at edpb.europa.eu). For UK residents, the supervisory authority is the Information Commissioner's Office (ico.org.uk).

**CCPA (California):** We do not sell or share personal information for cross-context behavioural advertising. California residents may request disclosure of categories of personal information collected and shared in the prior 12 months.

**Response time.** We will acknowledge requests within a reasonable time and respond substantively within **30 days** of verifying your identity. Where a request is particularly complex or numerous, GDPR Art 12(3) permits us to extend by a further two months; we will tell you within the first 30 days if that applies.

To exercise any right not covered by the in-app controls above, email support@closyai.com.

---

## 10. Children's Privacy

ClosyAI is not directed to children. We do not knowingly collect personal data from anyone under the age of **13** in the United States (per COPPA), or under the digital-consent age set by your EEA member state under GDPR Art 8 (this is **16** by default and is set lower — between 13 and 16 — by some member states; for example, France, Germany, Luxembourg and the Netherlands set 16, while Belgium, Denmark, Estonia, Finland, Portugal, Spain and Sweden set 13). If you are below the applicable age, you may not use the Services without a parent or legal guardian's verified consent.

If you believe a child has provided us with personal data without the required consent, contact us at support@closyai.com and we will delete it promptly.

---

## 11. Business Transfers

If ClosyAI is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent in-app notice before your data is subject to a different privacy policy.

---

## 12. Law Enforcement

We may disclose your personal information if required to do so by law, valid legal process, or to protect the rights, property, or safety of ClosyAI, our users, or the public.

---

## 13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and notify you via email or an in-app notice. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

---

## Contact Us

**Data Controller**
ClosyAI Inc.
Email: support@closyai.com
Website: https://www.closyai.com

**Data Protection contact**
For privacy enquiries, subject-rights requests, or data-protection complaints, please email **support@closyai.com**. We respond within 30 days as required by GDPR Art 12(3). For complex requests we may extend by up to two further months and will notify you of any such extension within the initial 30 days.

**EEA / UK users**
You may also lodge a complaint with your local Data Protection Authority. UK users may complain to the Information Commissioner's Office (ico.org.uk).