Privacy Policy

    Closet DJ

    Last updated: 30 August 2026

    1. Who We Are

    Closet DJ ("we", "us", or "our") is a digital wardrobe management application. We are responsible for your personal data as described in this policy.

    For privacy-related questions, contact us at privacy@closetdj.com.

    2. What This Policy Covers

    This policy explains:

    • What personal data we collect
    • Why we collect it
    • How we use and store it
    • Who we share it with
    • Your rights over your data

    3. Data We Collect

    Account Data

    When you register or sign in, we collect:

    • Email address: used to identify your account
    • Full name: if provided during sign-up or via Google/Apple sign-in
    • Password (stored securely as a hash): if you use email/password login
    • Authentication provider info: if you sign in with Google or Apple

    Wardrobe & Clothing Data

    Everything you add to your wardrobe:

    • Clothing item names, brands, types, colours, sizes, and notes
    • Clothing photos you upload
    • Storage locations you assign to items
    • Outfit combinations you build
    • Laundry status of your items
    • Wardrobe items you import (from a connected wardrobe app such as Whering or Indyx, or from store-order screenshots), which may include data originally held by that third-party service

    Trip Planner Data

    • Trip name, destination, and dates
    • Which clothing items or outfits you pack for each trip

    Calendar & Scheduler Data

    • Outfits or individual items you schedule on specific dates
    • If you subscribe to an external calendar feed (via an ICS/webcal URL you provide), the event titles, dates, and times from that feed, fetched on your behalf and stored so they can appear alongside your schedule

    Style Assistant Data

    • Conversation messages between you and the AI Style Assistant (Pro plan)
    • Clothing items referenced in those conversations

    Voice Recordings

    • Audio you record when using voice input for the Style Assistant, sent for transcription and not retained after it has been transcribed to text (see Section 5)

    Photos of You, Your Avatar & Try-On Images

    If you use Try It On, you can create an avatar of yourself so you can see how outfits from your wardrobe would look on you. This is entirely optional: nothing in this section is collected unless you choose to set it up, and you are asked to tick a consent box before any photo of you is uploaded.

    • A full-body photo and a face close-up that you upload: used only to generate your avatar, and automatically deleted from our systems as soon as the avatar has been generated. We do not keep the original photographs of you.
    • Your generated avatar and profile portrait: AI-generated images that resemble you, created from the two photos above. These are kept until you replace them or delete your account. They are a synthetic likeness rather than a photograph of you.
    • Try-on images: AI-generated images showing your avatar wearing clothes from your wardrobe. Kept until you delete them individually or delete your account.

    These files are held in a separate, private storage area from your clothing photos, accessible only to your own account.

    Appearance Profile

    When your avatar is generated, an AI vision model also writes a short written description of your physical appearance. This is used so that styling suggestions actually suit you, for example not recommending a colour that would wash you out. It covers:

    • Shown to you and editable at Profile → Colouring & features: skin tone and undertone, hair colour, eye colour, eyebrows, freckles, tattoos, and piercings
    • Stored and used by our AI features but not displayed in the app: impression of height, build and proportions, scars and birthmarks, and other notable body and facial characteristics

    Some of this may be sensitive data. Details such as scars, birthmarks or body characteristics could indirectly reveal a visible disability or health condition, which is treated as special category data under Article 9 of the GDPR. We ask for your explicit consent before generating your avatar, and we process this information for the sole purpose of personalising styling suggestions to you. The AI is instructed to describe only what is visible in factual terms and is expressly prohibited from inferring your age, ethnicity, nationality, or any medical diagnosis; where it cannot tell, it records nothing.

    This description is generated by AI and may simply be wrong. You can review and correct the visible fields at any time at Profile → Colouring & features. The fields that are not displayed in the app are still your personal data: they are included in full if you request a copy of your data, and they are deleted when you generate a new avatar, remove your avatar, or delete your account. "Not displayed" means they are kept out of the everyday interface because they are sensitive, never that they are withheld from you.

    You can withdraw from all of this at any time. Removing your avatar in the app erases the avatar, the profile portrait, and the entire appearance profile. Try-on images can be deleted individually from your profile, and are all erased automatically if you generate a new avatar or delete your account.

    Subscription & Billing Data

    • Your subscription tier (Free DJ, Welcome Pass, DJ Lite, or DJ Pro)
    • Welcome Pass status, start date, end date, and feature usage summary
    • AI credit usage
    • Billing history managed by Stripe (see Section 6)

    Technical & Device Data

    When you use the app, we automatically collect:

    • IP address: used to estimate your city and country for weather and personalisation
    • Device type (Desktop, Mobile, Tablet) and operating system: logged for support purposes
    • User agent string: the technical identifier of your browser or device
    • Push notification token: used to deliver in-app alerts and reminders (mobile app only), managed by OneSignal
    • Behavioural analytics events: page views, feature interactions, and AI feature usage, captured via PostHog (EU servers, eu.i.posthog.com)
    • Session recordings & console logs: PostHog records session activity and captures browser/app console log output by default to help us diagnose errors and improve stability
    • Application & error logs: server-side and in-app activity and error reports, which may include your user ID, request details, and technical error context, are captured in PostHog (EU servers, eu.i.posthog.com) to diagnose problems and monitor reliability. Logs produced by our hosting platform itself are stored separately with Axiom
    • Performance traces: to find slow or failing requests, we record timing data for the actions you take in the app. A trace records which app function ran, how long each step took, and whether it failed, and is linked to your user ID and to the log entries from the same request. Traces are stored in PostHog (EU servers, eu.i.posthog.com)
    • User profile data sent to PostHog on every sign-in: when you sign in, your PostHog profile is updated with the following fields: email address, gender, approximate city, country and country code, subscription tier, trial status, billing mechanism, AI credits used, operating system, device type, platform (web/iOS/Android), and whether you are using the native app

    Location Data

    By default, we use your IP address to detect your approximate city and country code (ISO 3166-1 alpha-2, e.g. "MT") each time you sign in. This is handled by Cloudflare, which places the address to a city and country for us. Where that is unavailable we fall back to ipapi.co, a service we are in the process of retiring.

    On our iOS and Android apps, if you grant the operating-system location permission, we take a one-off precise device GPS reading to determine your city and country more accurately. Your exact coordinates are sent to BigDataCloud to convert them into a place name (reverse geocoding); we store only the resulting city and country code, not your raw coordinates. This is controlled entirely by the location permission on your device; you can revoke it at any time in your device settings, and we fall back to IP-based detection.

    Your city and country are stored in your settings and used to power the weather feature and to personalise AI responses (for example, suggesting climate-appropriate outfits). You can update or remove this at any time from Account Settings.

    Support Interaction Data

    When you contact our support team, we share your name, email address, subscription tier, operating system, and approximate location (city and country) with our support system to help our team assist you more effectively. Support conversations are relayed to our team through Telegram so we can respond to you.

    Marketing & Email Preferences

    When you create an account, you are opted in by default to receive occasional marketing emails from us, including styling tips, product updates, and special offers. You can opt out at any time from Account Settings → Email Preferences. Opting out of marketing emails does not affect transactional emails (such as account, billing, and security notifications), which we always need to send.

    Guest (Pre-Registration) Accounts

    If you start trying Closet DJ before signing up, we create a temporary anonymous guest account so your progress (such as items you add during onboarding) isn't lost. When you register, this guest account is merged into your new account. If you don't sign up, the guest account and any data in it are automatically deleted after a short period.

    4. Why We Use Your Data

    PurposeLegal Basis
    Creating and managing your accountPerformance of contract
    Providing wardrobe, outfit, and trip planning featuresPerformance of contract
    Processing payments and managing subscriptionsPerformance of contract
    Powering AI features (photo import, image enhancement, Style Assistant, voice input)Performance of contract
    Transcribing voice input for the Style AssistantPerformance of contract
    Generating your avatar from photos you upload (Try It On)Consent (explicit, given in-app before upload)
    Recording a description of your appearance to personalise styling adviceExplicit consent (Art. 9(2)(a) where any of it is special category data)
    Generating try-on images of your avatar wearing your clothesPerformance of contract
    Importing outfits/items and syncing calendar feeds you connectPerformance of contract
    Showing weather-based outfit suggestionsPerformance of contract
    Sending welcome and transactional emailsPerformance of contract
    Providing customer support via live chatLegitimate interest
    Detecting approximate location via IP addressLegitimate interest
    Detecting precise location via device GPS (native apps)Consent (device permission)
    Logging device and OS info for support and debuggingLegitimate interest
    Improving the app and fixing bugsLegitimate interest
    Recording performance traces to diagnose slow or failing requestsLegitimate interest
    Sending marketing emails (styling tips, product updates, offers)Consent (opt-in)
    Product analytics and app improvement (PostHog)Legitimate interest
    Complying with legal obligationsLegal obligation

    5. AI Features & Your Data

    Closet DJ uses AI in three ways:

    Photo Import: When you upload a photo of yourself or a clothing item, our AI analyses the image to identify and categorize clothing. Images and prompts are sent to Google Gemini for processing via Lovable's AI gateway. Uploaded images are then discarded and deleted.

    Image Enhancement: When you use the image enhancement feature, your clothing item photo is processed by an AI model to generate an improved product-style image. The result replaces or supplements the original photo in your wardrobe. This feature consumes AI credits.

    Style Assistant (Pro plan): Conversations with the Style Assistant are stored so you can refer back to them. Your messages, wardrobe context, and approximate location are sent to Google Gemini / Open AI's ChatGPT for processing to generate responses. You can adjust how the assistant speaks to you using the "DJ Tone" personalisation toggle in Account Settings.

    Try It On (avatar and try-on images): If you choose to set up an avatar, the full-body photo and face close-up you upload are sent to Google Gemini via Lovable's AI gateway to generate your avatar and profile portrait. In the same process, a separate AI vision request produces the written description of your appearance covered in Section 3. Your uploaded photographs are deleted from our systems once generation completes. When you then use Try On, your avatar and the photos of the clothing items in that outfit are sent to the same provider to produce the try-on image. Underwear and lingerie are never rendered on your avatar; they are shown on a plain mannequin instead. Your appearance description is also included in Style Assistant and outfit-suggestion requests so that recommendations suit your colouring.

    Voice Input: If you speak to the Style Assistant instead of typing, the audio you record is sent to Google Gemini (via Lovable's AI gateway) to be transcribed into text. Only the resulting text is used to generate a response and stored with your conversation; the audio recording is not retained after transcription.

    AI Providers: AI requests are processed by one or more of the following providers depending on the feature and configuration:

    • Google Gemini (Google LLC): used for photo import, image enhancement, voice transcription, avatar and try-on image generation, and the Style Assistant
    • OpenAI / ChatGPT (OpenAI, LLC): used for the Style Assistant

    All AI requests are sent through Lovable's AI gateway, which forwards them to the provider above that serves the model in question. The specific model used may vary per request and is not determined by user selection. Your data is not routed to any AI provider other than those listed here.

    AI Analytics via PostHog: Every AI request, including photo imports, image enhancements, and Style Assistant messages, fires an analytics event to PostHog (EU servers, eu.i.posthog.com). Each event contains:

    • Your input: a truncated version of your prompt or image description (up to 5,000 characters)
    • The AI's response: a truncated version of the output (up to 5,000 characters)
    • Technical metadata: AI model name, provider name, response time (latency), and token counts

    This data is used solely to monitor AI feature performance and reliability.

    We do not use your photos or wardrobe data to train AI models for third parties. Each provider's API usage policy governs how they handle your data. We do not opt in to any data sharing for model training purposes.

    6. Third Parties We Work With

    ServicePurposePrivacy Policy
    SupabaseDatabase, authentication, and file storagesupabase.com/privacy
    StripeWeb payment processing and subscription managementstripe.com/privacy
    Apple (App Store billing)In-app subscription billing for iOS usersapple.com/legal/privacy
    Google (Play Store billing)In-app subscription billing for Android userspolicies.google.com/privacy
    RevenueCatSubscription lifecycle management for iOS and Androidrevenuecat.com/privacy
    ResendTransactional and marketing email deliveryresend.com/legal/privacy-policy
    OneSignalPush notification delivery (mobile app)onesignal.com/privacy-policy
    TelegramRelaying support conversations to our teamtelegram.org/privacy
    AxiomApplication logging and error monitoringaxiom.co/privacy
    OpenAI (ChatGPT)AI processing for the Style Assistantopenai.com/policies/privacy-policy
    PostHogProduct analytics, session recordings, console logs, and AI event tracking (EU-hosted)posthog.com/privacy
    LovableApplication hosting and AI gatewaylovable.dev/privacy
    Google GeminiAI model for photo analysis, Style Assistant, and avatar/try-on image generation and appearance analysispolicies.google.com/privacy
    Google (Sign-in)Optional sign-in via Google accountpolicies.google.com/privacy
    Google AdSenseSelecting, serving and measuring ads on free accountspolicies.google.com/technologies/ads
    Apple (Sign-in)Optional sign-in via Apple IDapple.com/legal/privacy
    Open-MeteoWeather data (uses your city/coordinates)open-meteo.com/terms
    CloudflareIP-based location detection at logincloudflare.com/privacypolicy
    ipapi.coReverse-geocoding GPS coordinates to a city/country (native apps)ipapi.co/privacy
    BigDataCloudbigdatacloud.com/privacy

    Stripe handles all web payment transactions directly. For iOS users, payments are processed by Apple through the App Store. For Android users, payments are processed by Google through the Play Store. We never see or store your full card or payment details on any platform.

    When you use AI features, your data (images or chat messages) passes through Lovable's AI gateway before reaching the AI model. AI processing is performed by Google Gemini, and for the Style Assistant also by OpenAI (ChatGPT). The model used may vary per request. Each provider processes data in accordance with their own privacy policy.

    Every AI request also sends an event to PostHog (EU servers, eu.i.posthog.com) containing: a truncated version of your input (up to 5,000 characters), a truncated version of the AI's response (up to 5,000 characters), the model name, provider, response time, and token counts.

    7. Where Your Data Is Stored

    Your data is stored on Supabase infrastructure, primarily in the EU/EEA. Some third-party services (Stripe, Google, OneSignal, RevenueCat, OpenAI, Resend, Telegram, Axiom, BigDataCloud) may process your data in the United States or other countries. PostHog processes analytics data within the EU (Ireland). Where data is transferred outside the EU/EEA, appropriate safeguards such as Standard Contractual Clauses are in place.

    8. How Long We Keep Your Data

    Data TypeRetention Period
    Account and wardrobe dataFor as long as your account is active
    Clothing imagesFor as long as your account is active
    Guest (pre-registration) account dataMerged into your account on sign-up, or deleted automatically if you don't register
    Subscribed calendar feed eventsRefreshed while the subscription is active; removed when you remove the feed or delete your account
    Voice recordingsNot retained after transcription
    Full-body photo and face close-up you upload for your avatarDeleted automatically as soon as your avatar has been generated
    Generated avatar and profile portraitUntil you remove or regenerate your avatar, or delete your account
    Try-on imagesUntil you delete them, generate a new avatar, or delete your account
    Appearance profile (including the fields not shown in the app)Until you remove or regenerate your avatar, or delete your account
    Email send logsUp to 12 months
    Device, user agent, and hosting platform logs (Axiom)Up to 12 months
    Style Assistant conversationsDeleted when you delete your account
    AI credit usage logsDeleted when you delete your account
    Support chat historyDeleted when you delete your account
    PostHog data (behavioural, session and AI events; application and error logs; performance traces)As per PostHog's data retention policy (posthog.com/privacy)
    Marketing email preferencesUntil you change them or delete your account
    Billing recordsAs required by applicable tax and financial laws

    When you delete your account, all your personal data is permanently deleted from our systems. This includes your clothing items, outfits, trips, AI Style Assistant conversations, AI credit usage logs, device records, and account information. Billing records may be retained longer where required by applicable tax and financial law.

    9. Your Rights

    As a user, you have the right to:

    • Access: request a copy of the personal data we hold about you
    • Rectification: ask us to correct inaccurate data. Because your appearance profile is written by AI and can be wrong, you can edit it yourself at any time at Profile → Colouring & features
    • Erasure: delete your account and all associated data, including wardrobe items, AI conversations, credit usage logs, and device records (available directly in Account Settings)
    • Portability: request your data in a structured, machine-readable format
    • Restriction: ask us to limit how we use your data
    • Object: object to processing based on legitimate interest
    • Withdraw consent: where processing is based on consent (for example, marketing emails can be turned off at any time from Account Settings → Email Preferences, and your avatar and appearance profile can be erased at any time from Profile → Avatar)
    • Opt out of personalized ads: free accounts can review or withdraw their advertising choices at any time from Settings → Account → Privacy → Ad privacy choices, or remove ads entirely by upgrading to a paid plan

    To exercise any of these rights, email us at privacy@closetdj.com or use the in-app chat. We will respond within 30 days.

    If you are located in the EU, you also have the right to lodge a complaint with your national data protection authority.

    California Residents

    Serving personalized ads involves sharing identifiers such as your advertising ID and IP address with Google, which California law treats as a "sale" or "sharing" of personal information for cross-context behavioural advertising. You have the right to opt out. Google's consent tool presents a "Do Not Sell or Share My Personal Information" choice to residents of California and other US states with comparable laws; you can open it at any time from Settings → Account → Privacy → Ad privacy choices. You can also email privacy@closetdj.com with the same subject line. We do not sell or share personal information belonging to anyone we know to be under 16, and we will not discriminate against you for exercising this right.

    10. Cookies & Local Storage

    Closet DJ uses browser local storage and session storage to keep you logged in and remember temporary preferences.

    PostHog may set cookies or use local storage to link analytics events and session recordings to your user profile across sessions.

    Advertising Cookies

    Free accounts are supported by ads. Our advertising partner, Google, may set cookies and read your device's advertising identifier in order to select ads, measure how they perform, limit how often you see the same ad, and detect fraud. Where you have given consent, those ads are personalized, which means Google may build an interest profile and show you ads based on your activity across other sites and apps. Which plans carry ads is set per plan; our Pricing page lists exactly what each plan includes.

    We never hand your wardrobe, photos, outfits, avatar, appearance profile or Style Assistant conversations to advertisers. What Google receives is limited to standard ad-request information: your IP address, device and browser details, your advertising identifier, and which screen the ad was shown on.

    Your advertising choices are collected and stored by Google's consent tool, which appears the first time an ad is about to be shown to you. It is the single place these choices live, so what you set there is what applies. You can reopen it at any time from Settings → Account → Privacy → Ad privacy choices to review or withdraw your choices. On iOS, Apple separately asks for your permission to track before any personalized ad is served.

    Declining does not necessarily remove ads. Depending on the choices you make, you may see contextual ads that are not based on your interests, ads served without cookies or device identifiers, or in some cases no ads at all. If you want ads removed outright, see the Pricing page for which plans are ad-free.

    Advertising Is Not the Same as Shopping Recommendations

    Closet DJ also shows shopping recommendations, for example in the Style Assistant and in the Store. Some of those links are affiliate links, meaning we may earn a commission if you buy through them. These are not the advertising described above: they are not sold by Google, they are chosen for their relevance to your wardrobe rather than to an advertiser, and no advertiser pays us to place them.

    Because of that, a plan being ad-free does not remove shopping recommendations. Being on an ad-free plan means no advertising is served to you; the Style Assistant and the Store can still recommend products that carry an affiliate link.

    11. Children's Privacy

    Closet DJ is not intended for children under the age of 13 (or 16 in some EU countries). We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us at privacy@closetdj.com and we will delete it promptly.

    12. Changes to This Policy

    We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. For significant changes, we will notify you by email or through a notice in the app.

    13. Contact Us

    Privacy enquiries: privacy@closetdj.com

    General support: support@closetdj.com or the in-app live chat

    This privacy policy is governed by the laws of Malta and the European Union's General Data Protection Regulation (GDPR).