# ClosyAI Privacy Policy

**Effective Date:** September 9, 2025
**Last Updated:** August 20, 2026

ClosyAI Inc. ("ClosyAI," "we," "our," or "us") provides a mobile application and website that helps users organise their wardrobes, generate AI-powered outfits, and plan what to wear for events. We respect your privacy and are committed to protecting your personal information.

---

## 1. Information We Collect

**Account Information**
Your email address and password (stored as a secure hash) when you register. If you sign in via Apple or Google, we receive only the information those services make available (typically email and name).

**User Content**
Photos of clothing items you upload, outfit combinations you save, style preferences, occasion and weather settings, and any notes or custom labels you add. When you upload a clothing photo, it is sent to Google Cloud's AI services in the EU for automated garment detection and attribute classification (colour, type, fit, formality, material). This powers your digital closet — no photo is shared with other users or used to train third-party AI models.

**Profile and Preferences**
Gender, style preferences (e.g. casual, elegant, sporty), colour preferences, occasion preferences, hair and nail colour, and other personalisation settings you provide.

**Calendar Data**
If you enable calendar sync, we access the events on your device calendar solely to display them inside the app for outfit planning. We do not store raw calendar event data on our servers beyond the event details you explicitly import into ClosyAI.

**Location Data**
If you allow location access, we use your approximate GPS coordinates to look up local weather conditions and suggest weather-appropriate outfits. We do not store your precise location or build a location history.

**Push Notification Tokens**
If you grant notification permission, we store a device token to send you outfit reminders and upload completion alerts. You can revoke permission at any time in your device Settings.

**Device and Usage Information**
App version, device model, operating system version, and pseudonymised event data (e.g. screens visited, features used) to diagnose issues and improve the app. In production builds, crash reports and error stack traces are collected via Sentry to help us identify and fix bugs. Sentry events are tagged with a pseudonymised 8-character prefix derived from your Supabase user UUID (not your email, name, or any other personal identifier); this prefix is stable per-user so we can correlate crash patterns for a single account during diagnostics. Sentry data does not include your clothing photos or outfit content.

**Service and Diagnostic Records**
When you use a feature, we record what our systems did so we can operate the Service and fix it when it breaks: that an outfit generation ran and which rules applied, that a photo upload succeeded, failed, or was rejected (for example because it contained more than one garment), that an email or notification was sent, and that an error occurred. These records are keyed to your account, contain identifiers and short reason codes rather than free text, and **do not** include your photos or outfit content.

**We keep these records whether or not you enable Product Analytics**, because without them we cannot tell that something went wrong for you, cannot answer a support request, and cannot fix the fault. They are separate from the behavioural analytics described below, they are never shared with our analytics provider, and they are covered by the same retention, export and deletion rights as the rest of your data. You may object to this processing at any time by emailing support@closyai.com.

**Analytics Data** *(optional — off unless you turn it on)*
Behavioural usage events — such as screens visited, sessions, and features tapped — collected **only if you enable Product Analytics** in **Settings → Privacy**. Pseudonymised usage events are also sent to PostHog when this setting is enabled. PostHog `distinct_id` is your Supabase user UUID — a pseudonymous identifier that does not contain your email, name, or any other directly identifying field, but is a stable per-user reference. This data does not include photos or outfit content. These identifiers are not personally identifying on their own but can be joined with our user database if we re-identify them; we treat them as pseudonymised data and protect them accordingly.

**Subscription and Purchase Data**
If you subscribe to Closy Pro or Closy Pro+, Apple processes payment on your behalf. We receive confirmation of your subscription status (active, cancelled, expired) and the subscription expiry date from RevenueCat, our subscription management provider. We do not receive or store your payment card details.

**Receipt-Ingestion Data**

ClosyAI offers optional ways to add items to your closet beyond uploading photos: forwarding retailer order-confirmation emails to a unique ClosyAI alias, pasting product URLs, or uploading screenshots of receipts. If you use these features, we collect:

- **Forwarded email content.** If you forward an email to your unique alias (`<token>@inbound.closyai.com`), we receive the full email — sender address, subject, body text and HTML, and message headers including authentication signatures used to verify the sender is a legitimate retailer. We never read your mailbox; we only receive what you (or a forwarding rule you set up in your email provider) explicitly send to your alias.
- **Purchase information extracted from those receipts.** Item names, brands, colours, sizes, prices, order numbers, retailer names, and product image URLs. This information is presented to you for review before any closet entry is created — nothing is added to your closet without your explicit Approve action.
- **Pasted URLs and uploaded receipt images.** If you use an "Import a Receipt" feature, we receive the URL or image you submit. URLs are fetched server-side to extract product details. Receipt images are processed via OCR and pattern recognition.

**Receipt-ingestion retention.** Raw forwarded email content (including third-party CC addresses, original message headers, and any personal correspondence visible in the message) is automatically purged from our systems **within 30 days** of receipt. Only the structured item attributes that you explicitly approve persist as your closet entries.

**Body Photo (Optional, Pro+ Virtual Try-On feature)**
If you enable the Virtual Try-On feature available to Pro+ subscribers, you may optionally upload a single full-body photo of yourself to render outfits onto. This photo is private to your account.

- **Why we collect it.** Your body photo is the reference image used to generate Virtual Try-On renders showing how outfits from your closet would look on you.
- **Where it is stored.** In a private, access-controlled storage bucket. Only your authenticated account can read, replace, or delete it. ClosyAI staff do not access body photos in normal operation.
- **Where it is sent.** When you initiate a Try-On render with your body photo, your photo is sent — alongside the relevant clothing item images from your closet — to Google Cloud's AI image-generation service for the rendering call. No EU-region option is available for image generation: your body-photo data is **stored at rest in the EU**, but the **image-generation processing itself may take place outside the EEA** (e.g. in the United States). This transfer is governed by Google's Cloud Data Processing Addendum, the EU Standard Contractual Clauses, and Google's EU-US Data Privacy Framework certification; Google's terms state that this content is **not used to train Google's models**, is not subject to human review, and that any abuse logs are retained only for a limited period. ClosyAI does not retain any copy of your body photo on Google's systems beyond the duration of the rendering call. *(The same applies to **all image generation** — the "Me" render, the mannequin, and the full-body reconstruction step: all of it is processed outside the EEA under the same safeguards. All **text and vision analysis** continues to be processed in the EU.)*
- **You control it.** You can re-take or delete your body photo at any time via Settings → Virtual Try-On. Deletion removes the photo from our storage immediately. Account deletion also removes any uploaded body photo.
- **Mannequin alternative.** You may use Virtual Try-On without uploading a body photo. In that case, ClosyAI generates a one-time fashion mannequin tailored to your gender and skin-shade profile fields. The mannequin is not based on your photograph.
- **Sharing privacy invariant.** When you share or save a Virtual Try-On render, you choose at the time of action whether to use the version rendered on your body photo or the mannequin variant. The default is the variant you are currently viewing. We surface a [Me] / [Mannequin] toggle prominently so the choice is explicit. The mannequin-only fallback for shared images remains available at server level should it be re-enabled in the future.

**Virtual Try-On Rendered Images**
The PNG images produced by Virtual Try-On renders are stored in your account's private storage and are deleted automatically after **90 days** of generation, or sooner if you delete your account. **Renders attached to an outfit you have saved are kept for as long as you keep that outfit**, so a look you deliberately saved does not disappear or cost you a re-render; they are deleted when you delete the outfit or your account. You can re-render any outfit at any time within your monthly quota.

---

## 1A. Legal Basis for Processing (EEA/UK users)

Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases for processing your personal data:

- **Contract (Art 6(1)(b))** — account creation, closet storage, outfit generation, calendar planning, subscription management, transactional emails (welcome, password reset, deletion confirmation). Required to deliver the Services you signed up for.
- **Consent (Art 6(1)(a))** — location access, push notifications, **product analytics (both the in-app behavioural events and the pseudonymised events sent to PostHog)**, body-photo upload and Virtual Try-On, calendar sync, receipt-email forwarding, monthly Style Digest. You may withdraw consent at any time in Settings; withdrawal does not affect prior lawful processing. Where you decline or withdraw, behavioural analytics stops, no events are sent to PostHog, and any behavioural data PostHog already holds for your account is deleted.
- **Legitimate interest (Art 6(1)(f))** — **service and diagnostic records** (see Section 1: records of what our systems did, kept so we can operate the Service, detect faults, and answer support requests), crash diagnostics (Sentry), fraud prevention, security monitoring. Our interest is operating a reliable, secure Service; we balance this against your privacy by keeping these records minimal — identifiers and reason codes, no photos or outfit content — retaining them under the schedule in Section 4, and never sharing them with our analytics provider. **These records are kept whether or not you enable Product Analytics**, because a Service that cannot see its own failures cannot fix them for you. You may object via support@closyai.com.
- **Legal obligation (Art 6(1)(c))** — tax records, lawful disclosure requests, App Store / RevenueCat receipt retention required by accounting law.

---

## 2. How We Use Your Information

We use your information to:

- Provide core app functionality — closet storage, AI outfit generation, event planning, and outfit history.
- Personalise outfit suggestions based on your style preferences, saved items, and occasion.
- Send transactional emails (account confirmation, password reset, subscription status changes).
- Send push notifications for outfit reminders, upload completions, and feature updates (only if you have granted permission).
- Detect weather at your location to generate weather-appropriate outfit suggestions.
- Display your device calendar events inside the app for outfit planning (only if you enable calendar sync).
- Generate AI-powered wardrobe insights for Pro+ subscribers, including seasonal readiness scores, wardrobe gap analysis, and closet analytics.
- Generate Virtual Try-On image renders for Pro+ subscribers — composite your body photo (or a generated mannequin) with clothing item images from your closet, via Google Cloud's AI image-generation service.
- Send a monthly personalised Style Digest email to Pro+ subscribers who have opted in, summarising their most-worn pieces and outfit patterns.
- Analyse pseudonymised usage data to fix bugs and improve the product.
- Process and manage your Closy Pro subscription.
- Respond to support inquiries.
- Enforce our Terms of Use and comply with legal requirements.

We do not use your clothing photos or outfit data to train AI models belonging to third parties.

---

## 3. Data Sharing

We do not sell or rent your personal data.

We share limited data with the following categories of service providers solely to operate the app:

| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, file storage, authentication, serverless functions | Account data, user content, preferences |
| RevenueCat | Subscription lifecycle management | Subscription status, expiry date, Apple subscriber ID |
| Resend | Transactional email delivery | Email address, first name |
| Expo / EAS | App distribution and push notification delivery | Push notification tokens |
| PostHog | Pseudonymised product analytics (EU-hosted). Identified by a pseudonymous account identifier — not directly identifying on its own, but joinable with our user database. | Usage events (no photos or content) |
| Sentry | Crash reporting and error diagnostics (production only). User events tagged with a pseudonymised 8-character prefix derived from the Supabase user UUID. | Device model, OS version, pseudonymised crash traces and stack traces |
| Mapbox / Photon | Event location geocoding — converts location names you enter into coordinates for weather lookup | Location text entered by you for events (e.g. "Paris, France") |
| Google Cloud | All AI/ML processing: garment photo analysis, outfit generation, AI-powered wardrobe report, monthly style digest copy, receipt content extraction, receipt-screenshot OCR, in-store item check, mannequin generation, and Virtual Try-On image rendering (Pro+). **Text and vision** processing (garment analysis, outfit generation, wardrobe report, style digest, receipt extraction and OCR, in-store item check, moderation) is routed to Google's **EU region**, keeping that processing inside the EU. **All image generation** — mannequin generation, mannequin renders, the Virtual Try-On "Me" render, and full-body reconstruction — is processed **outside the EEA** (e.g. the US), because no EU-region option is available for image generation; that data is **stored at rest in the EU**, under Google's Cloud DPA + EU Standard Contractual Clauses + EU-US Data Privacy Framework. In all cases, under Google Cloud's terms, which prohibit training on your content and human review of it. | Clothing photos, anonymised item attributes, prompts, wardrobe summary data (Pro+ wardrobe report), receipt content (forwarded retailer emails, pasted product URLs, uploaded receipt images), body photo and selected clothing images during Try-On render calls. |
| Postmark | Inbound email reception for the receipt-ingestion forwarding alias | Forwarded retailer email content (subject, body, headers) when you use email-forwarding receipt-import. |
| Bright Data | Server-side fetching of product pages from retailers that block direct fetches (Amazon, etc.) | The URL you pasted; the page content received from the retailer (used solely for item extraction; not stored beyond the 30-day raw-payload retention window). |
| Clipdrop (Stability AI) | Fallback background removal when client-side cutout is unavailable | Limited fallback for client-side cutout failure on receipt-imported items only. Native iOS/Android on-device background removal is the primary cutout path for user-uploaded photos and most scanner items; Clipdrop is rarely invoked. |
| Replicate (Marqo / fashionSigLIP) | Visual embeddings used to improve outfit variety and similar-item lookup | Closet item images (cutout) and pseudonymous user identifier. Vendor's posted policy is no training on customer content; DPA pending (see §6). |
| Apple / Google | Payment processing for in-app subscriptions | Handled entirely by the respective platform; we receive only subscription status |

We may disclose personal data if required by applicable law, court order, or to protect ClosyAI's legal rights.

---

## 3A. Automated Processing and AI Models

ClosyAI uses automated processing extensively to deliver core features: garment classification (color, garment type, material, formality, season), outfit generation, wardrobe-gap analysis, weather-appropriate scoring, body-photo classification (full-body vs partial), and Virtual Try-On image rendering. We rely primarily on AI models provided by Google Cloud. **Text and vision analysis** (understanding your garment photos and generating outfit suggestions) is processed in the EU. **Image generation** (Virtual Try-On renders, the mannequin, and full-body reconstruction) is processed outside the EEA, because no EU-region option is available for it. See §6. We update the specific models we use as Google releases and retires them; the safeguards described here apply to all of them.

**Provenance watermarking.** Images generated for you — Virtual Try-On renders, the generated mannequin, Style the Scene background edits, and full-body reconstruction — carry an invisible, machine-readable watermark applied by our AI provider (Google) that identifies them as AI-generated. The watermark is embedded in the image itself and travels with any copy you export or share. **It marks the image as AI-generated; it does not identify you, and we do not use it to track you or your images.** Renders with a generated background additionally carry a visible **AI-generated** label in the share footer.

These automated decisions **do not produce legal or similarly significant effects on you** under Art 22 GDPR. You can override any AI suggestion, edit any item attribute we have inferred about your closet, regenerate any outfit, and request human review of any automated outcome by contacting support@closyai.com.

---

## 4. Data Retention

We retain your data for as long as your account is active. If you delete your account:

- **Personal data** (account information, uploaded photos, closet items, outfits, events, preferences, and associated records) is deleted from our systems immediately upon account deletion.
- **Receipt-ingestion raw payloads** — raw forwarded email content, pasted URL contents, and uploaded receipt images you submit are automatically purged from our systems within **30 days** of receipt, regardless of whether your account is active. Only the structured item attributes you explicitly approve persist as closet entries.
- **Body Photo (Virtual Try-On)** — retained until you delete it via Settings → Virtual Try-On, or until account deletion. Replacing it removes the prior version. The photo is never shared between users or used for any purpose besides generating Virtual Try-On renders for your own account.
- **Virtual Try-On rendered images** — automatically purged from our systems **90 days** after generation, regardless of whether your account is active. We may keep a render longer where it is attached to an outfit you have saved, so that reopening a saved look does not require re-generating it. You can re-render any outfit at any time within your monthly quota (30 renders included with Pro+; additional via the Try-On Power Pack consumable).
- **Per-user generated mannequin** — if you have used Virtual Try-On with the mannequin option, a single generated PNG sized to your gender and skin-shade profile fields is cached in access-controlled private storage. It is regenerated when you tap "Regenerate mannequin" in Settings. Account deletion removes it.
- **Email forwarding aliases** — if you configure a per-user alias for receipt-ingestion, you can revoke it from in-app Settings at any time, which immediately invalidates the alias at our mail provider; future mail to the old alias is dropped. Account deletion also revokes any active alias.
- **Deleted items and outfits** — when you delete a closet item or a saved outfit, an internal snapshot of that record is briefly retained so we can answer data-access requests and measure deletion rates. These snapshots are not readable by anyone using the app, are **automatically purged after 90 days**, and are removed immediately on account deletion.
- **Usage and diagnostic records** — behavioural events such as feature usage patterns and generation counts, and service records such as job outcomes and errors. On account deletion the user identifier on these records is overwritten with a single shared placeholder value that is identical for every deleted account. What remains — the action name, timing, and technical context — carries no identifier of yours, and because the original identifier is overwritten rather than stored, that step cannot be reversed. These de-identified records may be retained indefinitely and are used for aggregate product analytics, and to keep the service working and diagnosable.

  While your account is active these same records **are** linked to you by your account identifier. We describe them as *pseudonymised*, not anonymous: they remain personal data, and your access, correction, and erasure rights apply to them in full.

You may request deletion at any time by using the "Delete account" option in Settings, or by emailing support@closyai.com. While your account is active we can locate and delete your usage records on request, because they are linked to your account identifier. Once an account has been deleted, the records described above no longer carry any identifier of yours, so we can no longer single them out — which also means they can no longer be traced back to you.

---

## 5. Subscriptions and In-App Purchases

ClosyAI offers optional paid subscriptions ("Closy Pro" and "Closy Pro+") processed entirely through Apple's App Store. We do not collect, see, or store your payment details — all billing is handled by Apple.

**Subscription plans:**
- Closy Pro Monthly: $14.99 per month, no free trial
- Closy Pro Annual: $119.99 per year ($10.00/month), with a 7-day free trial for new subscribers
- Closy Pro+ Monthly: $29.99 per month, no free trial
- Closy Pro+ Annual: $199.99 per year ($16.67/month), with a 7-day free trial for new subscribers

**Free trial:** A 7-day free trial is available on both annual plans (Closy Pro Annual and Closy Pro+ Annual) for new subscribers only (one trial per Apple ID). Full plan access is granted during the trial. Payment is charged to your Apple ID account at the end of the trial period unless cancelled at least 24 hours before the trial ends.

**Auto-renewal:** Subscriptions automatically renew at the end of each billing period unless cancelled at least 24 hours before the renewal date. Your Apple ID account is charged for renewal within 24 hours prior to the end of the current period.

**Managing or cancelling:** Go to iOS Settings → [Your Name] → Subscriptions → Closy Pro, or visit [apple.com/bill](https://support.apple.com/billing). Cancelling stops future renewals; you retain Pro access until the end of the current paid period.

**Refunds:** All refund requests are handled directly by Apple. To request a refund, visit [reportaproblem.apple.com](https://reportaproblem.apple.com).

**Downgrade:** When a subscription expires or is cancelled, your account reverts to the free tier. Your closet, outfit history, and all data are always retained — nothing is deleted on downgrade.

---

## 6. International Data Transfers

Personal data may be transferred to and processed in the United States and other countries outside the EEA/UK by the following processors: Supabase (US), Google Cloud (text and vision processing in the **EU region**; **all image generation** outside the EEA — EU residency at rest, processing may occur in the US; covered by Google's Cloud DPA, SCCs, and EU-US Data Privacy Framework), Postmark (US), Sentry (per DSN region), PostHog (EU), Resend (US), RevenueCat (US), Apple (US, IAP infrastructure includes EU regions), Expo/EAS (US), Mapbox (US) / Photon (DE) for geocoding, Bright Data (distributed), Clipdrop / Stability AI (EU — France), and Replicate (US).

For transfers to countries that the European Commission has not deemed to provide an adequate level of protection, we rely on:

- **EU Standard Contractual Clauses (2021/914)** with each US-based processor;
- **UK International Data Transfer Addendum** for UK users;
- **Supplementary technical and organisational measures** including TLS-in-transit, at-rest encryption (Supabase Storage + Postgres), **EU region configuration for text and vision processing** (all such calls are routed to Google's EU region), per-user access controls on stored photos, and access logging;
- **Transfer Impact Assessments (TIAs)** completed for each named processor.

Copies of SCCs and TIA summaries are available on request from support@closyai.com.

---

## 7. Security

We use industry-standard safeguards including encryption in transit (TLS), encrypted storage, and row-level security on our database. However, no system is 100% secure. If you believe your account has been compromised, contact us immediately at support@closyai.com.

---

## 8. Cookies and Tracking

**Mobile app.** The ClosyAI mobile app does not use browser cookies. It uses PostHog for pseudonymised in-app analytics as described in Section 1, which you can disable in **Settings → Privacy → Product Analytics**. The app does not include any third-party advertising SDKs, cross-app tracking SDKs, or cross-site tracking technologies, and does not request App Tracking Transparency (ATT) permission.

**Website (closyai.com).** Our marketing website may use strictly necessary cookies to operate the site, and where applicable a consent banner for any non-essential analytics or preference cookies (EEA/UK only). You can control cookies through your browser settings. Where the consent banner is shown, you may accept, reject, or manage individual categories.

---

## 9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

- **Access and Portability:** Request a copy of the data we hold about you. You can also generate a portable export yourself from **Settings (look for "Download my data")**, which produces a JSON archive of your account data (closet, outfits, events, preferences).
- **Correction:** Request correction of inaccurate data. Most profile and item attributes are editable directly in the app.
- **Deletion ("right to be forgotten"):** Use **Settings → Delete Account** for immediate self-service deletion, or email support@closyai.com (see Section 4 for what is deleted, retained, or anonymised).
- **Objection / Restriction (Art 21):** You may object to processing based on our legitimate interests (e.g. diagnostics analytics) — see channel-specific controls below — or request restriction by emailing support@closyai.com.
- **Withdraw consent (Art 7(3)):** Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

**Channel-specific opt-outs (Art 21 right to object to marketing):**

- **Push notifications** (outfit reminders, upload-completion alerts, feature updates): toggle per-category in **Settings → Notifications**, or revoke all push permission in your device Settings.
- **Transactional email** (account confirmation, password reset, subscription receipts, deletion confirmation): these are sent on the contractual legal basis and cannot be opted out of while your account is active; deleting your account stops them.
- **Style Digest / promotional email** (Pro+ monthly summary, product updates): opt in via **Settings**; opt out at any time from the same screen or via the unsubscribe link in each email.
- **In-app product analytics (PostHog)**: opt out in **Settings → Privacy → Product Analytics**.

**GDPR (EEA/UK):** ClosyAI Inc. is the data controller for the personal data described in this Policy. You have the right to lodge a complaint with your local data protection supervisory authority (a list is maintained by the European Data Protection Board at edpb.europa.eu). For UK residents, the supervisory authority is the Information Commissioner's Office (ico.org.uk).

**CCPA (California):** We do not sell or share personal information for cross-context behavioural advertising. California residents may request disclosure of categories of personal information collected and shared in the prior 12 months.

**LGPD (Brazil):** For users in Brazil, ClosyAI Inc. is the data controller (*controlador*) and processes personal data under the *Lei Geral de Proteção de Dados* (Law No. 13.709/2018, "LGPD"). Under LGPD Art. 18 you may request: confirmation that we process your data; access to it; correction of incomplete or inaccurate data; anonymisation, blocking, or deletion of unnecessary or excessively processed data; data portability; deletion of data processed with your consent; information about the entities with which we share your data; and revocation of consent. To exercise any of these rights, or to reach our Data Protection Officer (*Encarregado*), email support@closyai.com. You also have the right to lodge a complaint with Brazil's data-protection authority, the ANPD (*Autoridade Nacional de Proteção de Dados*, gov.br/anpd).

**Response time.** We will acknowledge requests within a reasonable time and respond substantively within **30 days** of verifying your identity. Where a request is particularly complex or numerous, GDPR Art 12(3) permits us to extend by a further two months; we will tell you within the first 30 days if that applies.

To exercise any right not covered by the in-app controls above, email support@closyai.com.

---

## 10. Children's Privacy

ClosyAI is not directed to children. We do not knowingly collect personal data from anyone under the age of **13** in the United States (per COPPA), or under the digital-consent age set by your EEA member state under GDPR Art 8 (this is **16** by default and is set lower — between 13 and 16 — by some member states; for example, France, Germany, Luxembourg and the Netherlands set 16, while Belgium, Denmark, Estonia, Finland, Portugal, Spain and Sweden set 13). If you are below the applicable age, you may not use the Services without a parent or legal guardian's verified consent. In Brazil, under the LGPD, the personal data of children (under 12) is subject to specific parental-consent requirements (Art. 14); our 13-year minimum age excludes this group, and personal data of adolescents (12–17) is processed in their best interest.

If you believe a child has provided us with personal data without the required consent, contact us at support@closyai.com and we will delete it promptly.

---

## 11. Business Transfers

If ClosyAI is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent in-app notice before your data is subject to a different privacy policy.

---

## 12. Law Enforcement

We may disclose your personal information if required to do so by law, valid legal process, or to protect the rights, property, or safety of ClosyAI, our users, or the public.

---

## 13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and notify you via email or an in-app notice. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

---

## Contact Us

**Data Controller**
ClosyAI Inc.
Email: support@closyai.com
Website: https://www.closyai.com

**Data Protection contact**
For privacy enquiries, subject-rights requests, or data-protection complaints, please email **support@closyai.com**. We respond within 30 days as required by GDPR Art 12(3). For complex requests we may extend by up to two further months and will notify you of any such extension within the initial 30 days.

**EEA / UK users**
You may also lodge a complaint with your local Data Protection Authority. UK users may complain to the Information Commissioner's Office (ico.org.uk).