Privacy Policy
Last updated: August 21, 2026
1. Who we are
Closetize is a wardrobe-management app with personalized outfit recommendations, and closetize.co is its website. Both are operated by Yaroslav Chekin, a sole proprietor doing business as Closetize, 11341 National Blvd #1047, Los Angeles, CA 90064, United States ("Closetize", "we", "us"). We are the data controller (or, in Australia and New Zealand terms, the agency/organisation) responsible for your personal information under this policy.
Privacy questions and requests: hello@closetize.co.
This policy covers the Closetize iOS app and the closetize.co website. It explains what we collect, why, who we share it with, how long we keep it, and your rights. In short: we do not sell your data, we do not show ads, and we limit collection to what is needed to provide, secure, operate, personalize, and improve Closetize.
2. Data we collect
Required vs. optional. An email address (or Apple's private relay address), a password or Apple sign-in credential, and your first name are needed to create and secure an account; without them you cannot use Closetize. Everything else — clothing photos, extended profile preferences, GPS location, receipt forwarding, push notifications, and third-party AI processing — is optional. If you skip something optional, only the related feature or the degree of personalization is unavailable.
Account information
When you sign up we collect your email address, a password (stored only as a hash), and your first name (and last name if you give one). If you sign in with Apple, Apple sends us your name and email address (or a private relay address if you hide your email).
Profile and style preferences
During onboarding and in settings you can tell us your gender preference, age range, lifestyle, style personality, favorite brands, work dress code, and temperature sensitivity. We use these to personalize outfit recommendations.
Clothing photos and wardrobe data
When you add items we store the photos you take or import, the background-removed versions we generate, and item details (name, category, colors, pattern, material, brand, size, length, fit, style tags, and the source of the item). Photos are stored on Cloudinary.
Location
With your permission we collect your device's GPS coordinates to fetch local weather for outfit recommendations. You can enter a city instead. The coordinates or city you choose are saved to your profile so we can show weather without asking again. We never track your location in the background.
Outfit history, feedback, and wear log
We store the outfits we generate for you, the ones you save, dismiss, swap, or plan, the outfits you log as worn, and any thumbs-up/down feedback. We use this to improve your future recommendations and build your Style DNA (see section 5).
Subscription and purchases
If you subscribe to Closetize Pro, Apple processes the payment; we never see your card details. We receive from Apple via RevenueCat (our subscription-management provider) your subscription status, product (monthly/annual), purchase and renewal dates, trial status, and a pseudonymous transaction record, linked to your account by your random account identifier. We store a Pro/not-Pro flag on your profile.
Push notifications (optional)
If you turn on notifications we store a device push token (issued by Apple/Expo), your platform, and your device's time zone so we can send your morning look and evening plan at a sensible local time. Notifications contain your own planned occasion and the weather — never promotions.
Receipt emails (optional)
If you forward a purchase-confirmation email to your personal Closetize forwarding address, we fetch that email, extract product information (item name, brand, price, size, image), and then discard the email content. We keep only the extracted item rows you import.
Bug reports and feedback
If you send feedback from the app we collect your message, an optional screenshot, the screen you were on, and basic device information.
Usage analytics
We collect usage events (for example "outfit generated", "item added") with PostHog, along with your device language and region, app version, and a random account identifier. These events are pseudonymous — linked to your account by that identifier, never by your name or email. Event properties can include the screen you were on, a garment's category and internal item identifier, the outfit occasion you chose, the temperature at the time you generated outfits, planned dates, the retailer of an imported receipt, counts, and timing. We do not send PostHog your clothing photos, receipt-email content, feedback messages, name, or email address. Analytics are disabled in development builds.
Error reports
We use Sentry to capture crashes and errors: stack traces, device model and OS, app version, language setting, and the same random account identifier, so we can tell whether a problem affects one account or many.
Data we do not collect
We do not collect your precise location in the background, your contacts, your photos beyond the ones you choose to add, health data, payment-card details, or advertising identifiers, and we do not use any advertising or tracking SDK.
3. How we use your data and our legal bases
| Purpose | What we use | Legal basis (UK GDPR) |
|---|---|---|
| Provide the service — account, wardrobe, outfit recommendations, weather, plans, wear log, receipt import | Account, profile, wardrobe, location/city, outfit history, receipts | Performance of our contract with you (Art. 6(1)(b)) |
| AI processing by third-party AI providers (photo analysis, outfit generation, swaps, receipt parsing, Style DNA) | Clothing photos, wardrobe details, style preferences, forwarded receipts | Your consent (Art. 6(1)(a)) — asked during onboarding, changeable any time in Profile → Privacy |
| Closetize Pro subscription — entitlement, restore, renewal status | Subscription status and transaction record from Apple/RevenueCat | Contract (Art. 6(1)(b)) |
| Push notifications | Push token, platform, time zone | Your consent (OS permission + in-app toggle), withdrawable any time |
| Product analytics — understand which features are used, fix what isn't working | Pseudonymous usage events | Our legitimate interest in improving the product (Art. 6(1)(f)); you can object — see section 12 |
| Error monitoring and security — crash fixing, abuse prevention, rate limiting, fraud and cost control | Error reports, pseudonymous identifiers, request logs | Our legitimate interest in keeping the service reliable and secure (Art. 6(1)(f)) |
| Website traffic measurement and the homepage A/B test | Google Analytics cookies and events; A/B cookie | Your consent (cookie banner) — see section 8 |
| Waitlist and launch emails | Email address, signup source | Your consent when you join the waitlist; unsubscribe any time |
| Responding to you, legal compliance, enforcing our Terms | Whatever the request or obligation involves | Legitimate interests; legal obligation (Art. 6(1)(c)) |
We do not use your data for advertising, we do not sell it, and we do not "share" it for cross-context behavioural advertising.
4. AI processing and your consent
Some features send data to third-party AI providers:
- Google LLC (Gemini API): clothing photos and the optional product name when you add an item (analysis); text descriptions of your wardrobe items, your style preferences, Style DNA, style notes, and current weather when you generate outfits or swaps (no photos are sent for outfit generation, and your name is not sent); the text of receipt emails you forward when our deterministic parsers cannot read them (AI fallback); and wardrobe and wear data when we compute your Style DNA.
- fal (Features & Labels, Inc.): the URL of a clothing photo, for background removal and upscaling.
None of this runs until you allow AI processing on the consent screen during onboarding, and you can withdraw that permission at any time in Profile → Privacy → Data processing. With AI processing off you can still add and organize your wardrobe manually; AI-dependent features are unavailable. Forwarded receipts are first read by our own parsers without AI; only the AI fallback step is covered by this consent.
We do not use your data to train AI models. Google's paid Gemini API terms state that Google does not use prompts or responses to improve its products and logs them for up to 55 days to detect abuse. fal's terms license your photos to fal only to provide its service and allow fal to use anonymised or aggregated usage data (which may be derived from inputs) to improve and develop its services and models; fal receives only the photo URL — never your name or account identifier — and retains processing request data for up to 30 days by default.
5. Profiling and automated processing
Outfit recommendations and Style DNA are produced by automated profiling of your wardrobe, preferences, and feedback. They are suggestions inside the app — they do not produce legal effects or similarly significant effects about you, and no decision about you (for example pricing or access) is based on them. You can see and edit the inputs (your profile and wardrobe), refresh or influence Style DNA through your feedback, and stop the profiling entirely by turning off AI processing or deleting your account.
7. Where your data is stored and international transfers
Our servers and most of our providers are in the United States (our database is hosted in the US East region). If you use Closetize from the United Kingdom, Australia, New Zealand, or elsewhere, your personal data is transferred to and processed in the United States (and, for the website waitlist only, in the European Union where Brevo is located).
- UK: where a US provider is certified under the EU-US Data Privacy Framework and its UK Extension, we rely on that certification; otherwise we rely on the provider's data processing agreement incorporating the UK International Data Transfer Addendum / Standard Contractual Clauses. Contact us for a copy of the relevant safeguard.
- Australia: we take reasonable steps (APP 8) to ensure overseas providers handle your information consistently with the Australian Privacy Principles, through the contracts described above. The countries involved are listed in the table in section 6.
- New Zealand: our overseas providers are bound by contracts providing comparable safeguards to the New Zealand Privacy Act 2020 (IPP 12). The countries involved are listed in section 6.
9. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile, wardrobe, photos, outfit history, wear log, receipts, push tokens, subscription status | Until you delete your account (immediately removed; see section 10). Not deleted on any schedule before then. |
| Weather | Cached in memory for about 10 minutes; not stored. |
| Forwarded receipt emails | Content discarded immediately after parsing; only extracted item rows are kept. |
| Usage analytics (PostHog) | Until you delete your account — we purge the PostHog person record and its events on deletion (section 10). |
| Error reports (Sentry) | Events expire under Sentry's retention period (currently 90 days); they carry only your random account identifier, never your name or email. |
| Operational ledgers (rate-limit state and AI cost accounting) | Keyed by a random account identifier only, with no profile data. Rate-limit state is swept automatically every hour; cost-accounting rows are kept as financial records and are not linked back to a person once the account is deleted. |
| Waitlist emails (Brevo) | Until you unsubscribe or 24 months after launch. |
| Website analytics (Google Analytics) | Up to 14 months for user-level and event data (the GA4 property's retention setting; aggregated reports are not affected). |
| Backups | Encrypted database backups are kept for up to 7 days and then overwritten. |
10. Account deletion
You can delete your account in the app at Profile → Delete Account (type DELETE to confirm). We process deletion immediately and it cannot be undone. When you delete your account:
- your account and every record linked to it in our database are permanently deleted (profile, wardrobe, outfit history, wear log, feedback, receipts, push tokens, subscription status, consent records); the only rows that remain are the pseudonymous operational ledgers and the encrypted backups described in section 9 — they hold no profile data and carry only your former random identifier;
- we ask Cloudinary to delete your images (shared starter-wardrobe images that are not yours are kept); if a deletion request fails we complete it on request — email hello@closetize.co if you want confirmation;
- we ask PostHog to delete the analytics person record and events linked to your account identifier;
- we delete your subscription-management record at RevenueCat (a random account identifier plus Apple purchase history); if that request fails we are alerted and complete it by hand — email hello@closetize.co if you want confirmation;
- crash reports at Sentry that reference your account identifier expire under Sentry's retention period (we do not store your name or email there);
- a Closetize Pro subscription is not cancelled by deleting your account — cancel it in your Apple subscription settings.
You can also ask us to delete your data by emailing hello@closetize.co.
11. Security
Your data is protected by row-level security in our database (other users cannot read your rows; only our own server functions can, for the purposes in this policy), all traffic is encrypted in transit (HTTPS/TLS), passwords are hashed and never stored in plain text, and API keys live only on our servers. AI processing runs through our own server functions, so our provider keys are never in the app. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the relevant regulator as required by law.
12. Your rights and how to use them
Depending on where you live (in particular under UK data-protection law, the Australian Privacy Principles, the New Zealand Privacy Act 2020, and California law) you have rights to:
- access the personal data we hold about you and get a copy;
- correct inaccurate data (most profile data can be edited directly in the app);
- delete your data (Profile → Delete Account, or email us);
- port your data — we will export your wardrobe and profile in a machine-readable format on request;
- object to or restrict processing based on our legitimate interests (for example product analytics);
- withdraw consent at any time — AI processing in Profile → Privacy, notifications in Profile or iOS Settings, cookies via the footer link, emails via unsubscribe — without affecting processing before withdrawal;
- complain to a supervisory authority.
To exercise a right, email hello@closetize.co from the address on your account (we may ask you to confirm it is you). We respond within one month (UK), within 20 working days (New Zealand), and otherwise within 30 days; we will tell you if we need longer. We do not charge for reasonable requests and we will not treat you differently for exercising your rights.
Regulators: UK — Information Commissioner's Office (ico.org.uk); Australia — Office of the Australian Information Commissioner (oaic.gov.au); New Zealand — Office of the Privacy Commissioner (privacy.org.nz); California — Office of the Attorney General (oag.ca.gov/privacy). We would appreciate the chance to address your concern first.
California notice. Closetize does not currently meet the thresholds that make the CCPA/CPRA apply to a business (we are well below the revenue and consumer-count thresholds and we do not sell or share personal information). We honor the rights above voluntarily. Categories of personal information we collect in the past 12 months: identifiers (email, name, account identifier), characteristics you choose to provide (age range, gender preference), commercial information (subscription status), internet/app activity (usage events), geolocation (if you allow it), visual information (clothing photos), and inferences (the Style DNA and outfit-recommendation profiles we generate from your wardrobe, preferences, and feedback). We disclose them only to the service providers in section 6.
13. Children
Closetize is not directed at children and you must be at least 13 to create an account (see our Terms). We do not knowingly collect personal data from children under 13 (or under the age of digital consent where you live). If you believe a child has created an account, email hello@closetize.co and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will post the new version here with a new "Last Updated" date and, for material changes, notify you in the app or by email before they take effect. Earlier versions are available on request.
15. Contact
Privacy questions, rights requests, or complaints: hello@closetize.co, or write to Yaroslav Chekin (doing business as Closetize), 11341 National Blvd #1047, Los Angeles, CA 90064, United States.