Last updated: June 24, 2026
Privacy Policy
This Privacy Policy explains how Wardrobely (“Wardrobely”, “we”, “us” or “our”) collects, uses, shares, retains and protects your personal information when you download, install, register for, access or use our iOS application, our websites at wardrobely.app (the “Site”), and any related features, content and services we provide (collectively, the “Service”). This Policy also describes your rights and the choices you have in relation to your personal information. By accessing or using the Service you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, do not use the Service.
This Policy is effective as of June 24, 2026 and supplements, but does not replace, any other notices or consent forms we provide to you at the point information is collected.
1. Who we are and how to contact us
The controller of your personal information is Wardrobely (the trading name of the entity identified at the end of this Policy). For any privacy enquiry, to exercise your rights, or to contact our Data Protection Officer, or for general support, email us.
2. Scope of this Policy
This Policy applies to personal information processed by Wardrobely in connection with the Service. It does not apply to third-party products, websites, apps or services that we do not own or control, even if you access them through the Service. Those third parties handle your information under their own policies, and we encourage you to read them.
3. Information we collect
3.1 Information you provide directly
- Account details — your name, email address and a password (which we store only as a salted hash), or the unique identifier returned by Sign in with Apple or Google. With Sign in with Apple we receive only the data Apple makes available to us, including private relay email addresses where you have chosen to hide your real address.
- Profile and preferences — style preferences, optional body profile information (such as height, sizes and fit preferences) and other inputs you choose to add to personalize recommendations.
- Photos and wardrobe content — images of your clothing, outfits and accessories, together with the items, looks, collections, favourites, notes and tags you create. You decide what to upload; you can delete this content at any time.
- Communications — messages and attachments you send to our support team or to the in-app AI stylist, including prompts, follow-ups and feedback (thumbs up / thumbs down).
- Purchases and subscriptions — Wardrobely Pro subscription status, free-trial eligibility, transaction identifiers, promo codes you redeem and tax-related information. Apple processes the payment itself; we do not receive or store your full payment card number or CVV.
- Survey, beta and research participation — if you opt in to surveys, interviews or beta features, the responses, recordings (where you have consented) and feedback you share.
3.2 Information collected automatically
- Device information — device model, operating system version, locale, language, time zone, screen settings, Wardrobely app version, build number, and a per-install identifier we generate for the app.
- Usage and diagnostics — features used, in-app screens visited, taps and gestures, session start and end times, performance metrics, crash logs and stack traces.
- Approximate location — derived from your device's coarse location and/or IP address. We use this only for weather-aware outfit picks and regional content. Precise GPS is never required and we will ask you first if we ever need it.
- Network information — IP address, mobile carrier and general connection type, used for security, fraud prevention and reliability.
- Identifiers and similar technologies — software development kits (SDKs), Apple's IDFV (vendor identifier) and, where you have granted App Tracking Transparency permission, Apple's IDFA. Used for security, analytics, attribution and abuse prevention.
- Cookies and similar technologies on the Site — strictly necessary cookies are always set; analytics and preference cookies are set only as described in section 12.
3.3 Information from third parties
We may receive information from sign-in providers (Apple, Google), Apple's App Store and App Store Connect (e.g. subscription status, refunds), our payment and fraud-prevention partners, weather data providers, customer-support tools, and analytics or attribution providers, all consistent with their policies and the permissions you have granted.
3.4 Information we do not collect
We do not collect government identifiers, full payment card numbers, precise GPS location, contacts, calendars, microphone input or health data through the Service. We do not perform biometric identification on the photos you upload (face matching, fingerprinting or similar), and we do not use them to infer protected characteristics.
4. How we use your information
We use personal information for the following purposes. The legal bases that apply where the GDPR or UK GDPR governs the processing are listed in section 5.
- Provide the Service — create and authenticate your account, sync your wardrobe across your devices, save your outfits and preferences, and process subscriptions.
- Digitize your wardrobe — analyse the photos you upload to detect garments and auto-tag category, dominant colour, season, fit and formality.
- Generate AI styling recommendations — produce daily outfit picks, layered Studio suggestions, match scores and AI stylist chat responses based on your wardrobe, preferences and context such as weather and time of day.
- Personalize the experience — streaks, badges, weekly activity stats, saved looks and feature recommendations.
- Communicate with you — service announcements, transactional messages, replies to support requests, and — only where you have opted in or where allowed by law — marketing.
- Improve and develop the Service — measure feature usage, fix bugs, train and tune our own models on data you have consented to share (see section 6), test new experiences and run A/B experiments.
- Security and abuse prevention — detect, prevent and respond to fraud, account takeover, scraping, automated abuse, unsafe content and violations of our Terms of Use.
- Comply with law — meet legal, tax, accounting and regulatory obligations and respond to lawful requests.
5. Legal bases (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases for the processing described above:
- Performance of a contract — to deliver the Service you have requested and to manage your account and subscription.
- Your consent — for marketing communications, for certain device permissions (camera, photo library, notifications, precise location), for App Tracking Transparency, and for any use of your content to improve our AI models.
- Our legitimate interests — to operate, secure, improve and personalize the Service, to understand how it is used, to prevent fraud and abuse, and to communicate non-marketing information about the Service. We balance these interests against your rights and freedoms.
- Legal obligation — to comply with applicable law, court orders and regulatory requirements.
- Vital interests — in rare cases to protect the life or safety of any person.
6. Photos, AI processing and automated decisions
Photos and prompts you submit are used to identify and tag garments, build looks, score outfit matches and answer AI stylist questions. Processing may take place on your device and/or on our servers and trusted AI sub-processors. Where processing happens off-device, content is transmitted over TLS, stored encrypted at rest and access is restricted.
- We do not use your photos for biometric identification (face matching, fingerprinting or similar).
- We do not sell your photos or personal content, ever.
- We do not use your personal content to train third-party generative models unless you give us specific, unbundled consent, which you can withdraw at any time in Settings.
- Outputs from the AI stylist are suggestions, not professional advice. They may be incomplete or inaccurate. Always use your own judgement before acting on a recommendation.
- Automated outfit picks, match scoring and personalization do not produce legal or similarly significant effects about you. You can always override a suggestion, ask the AI stylist for an alternative, or turn personalization off in Settings. Where required by law, you have the right to request human review of any decision based solely on automated processing.
7. How we share information
We share personal information only as described below and only as necessary for the purpose stated.
- Service providers (sub-processors) — cloud hosting and storage, AI inference, push notifications, email delivery, customer-support tooling, product analytics, crash reporting and payment processing. They act on our written instructions and only for the purposes we authorise.
- App stores and payment processors — Apple and our payment partners process subscription purchases, refunds and family-sharing entitlements.
- Legal and safety — to comply with applicable law, valid legal process, government requests, to enforce our Terms of Use, and to protect the rights, property, safety and security of Wardrobely, our users and the public.
- Business transfers — in connection with a proposed or completed merger, acquisition, financing, insolvency or sale of all or part of our assets. We will notify you of such a transfer where required by law.
- With your direction or consent — for example when you choose to share a look with another app or service.
- Aggregated or de-identified data — that cannot reasonably be used to identify you.
We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising as those terms are defined under California law or comparable U.S. state laws. We do not run third-party advertising inside the app.
8. International data transfers
We may transfer, store and process personal information in countries outside your country of residence, including in the United States and the European Union. Where required, we use appropriate safeguards for those transfers, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, the EU-U.S. and UK-U.S. Data Privacy Frameworks. You may request a copy of the safeguards by contacting us.
9. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service, and for the additional periods described below to meet legal, tax, accounting, security and dispute-resolution requirements. Indicative retention periods:
- Account, profile and wardrobe content — until you delete the item, delete your account, or 12 months after prolonged inactivity, whichever is sooner.
- Subscription and billing records — up to 7 years, where required by tax and accounting law.
- Support communications — up to 24 months after the issue is resolved.
- Security logs and abuse signals — typically up to 12 months, longer where an investigation is open.
- Analytics and crash diagnostics — aggregated or de-identified after 14 months at most.
Backups are overwritten on a rolling schedule of up to 35 days. After deletion, residual copies may persist briefly in backups and cache layers, but they are not used for any operational purpose and are purged on the standard cycle.
10. Security
We implement technical and organizational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These include TLS in transit, encryption at rest for sensitive data, scoped access controls and least-privilege administration, separation of production and development environments, secrets management, code review, periodic vulnerability scanning, logging and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affects your personal information, we will notify you and the relevant supervisory authority as required by law.
11. Your rights and choices
Subject to applicable law, you have the following rights regarding your personal information:
- Access a copy of the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your account and content, in-app or by contacting us.
- Port your data in a structured, commonly used and machine-readable format.
- Restrict or object to certain processing, including processing based on our legitimate interests and direct marketing.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint with your local data protection authority (and, in the EEA, with the supervisory authority of your habitual residence).
- Manage device permissions — camera, photo library, notifications and location — through iOS Settings at any time.
- Opt out of marketing by using the unsubscribe link in our emails or by changing your notification preferences in the app.
- App Tracking Transparency — where applicable we will ask for your permission through Apple's ATT framework before tracking across other apps and websites; you can change your choice in iOS Settings.
To exercise any right, email us. We may need to verify your identity before acting on your request, and we will respond within the timeframes required by applicable law (typically within one month under the GDPR / UK GDPR, and within 45 days under California law, subject to extensions where permitted).
11.1 California, Colorado, Virginia, Connecticut, Utah and other U.S. state rights
If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the rights to know, access, delete, correct and port your personal information, to opt out of its sale or sharing (we do neither), to opt out of profiling that produces legal or similarly significant effects (we do not engage in such profiling), and to limit the use of sensitive personal information. You may also designate an authorised agent to act on your behalf, subject to verification. We will not discriminate against you for exercising your privacy rights.
11.2 Do Not Track and Global Privacy Control
Our Site honours the Global Privacy Control (GPC) signal as an opt-out of sale or sharing where applicable law requires it. Browsers send Do Not Track signals inconsistently, and we do not currently take additional action based on DNT.
12. Cookies and similar technologies on the Site
Our Site uses a small number of strictly necessary cookies to load, secure and remember your preferences. Where required by law we will ask for your consent before setting analytics or preference cookies, and you can change your choice at any time through our in-page cookie controls or your browser. The Wardrobely iOS app does not use browser cookies; it uses local storage and SDKs as described in section 3.
13. Children's privacy
The Service is not directed to children under 13, or under the minimum age required in your country (16 in much of the EEA and the UK without parental consent). We do not knowingly collect personal information from children below those ages. If you believe a child has provided us information, please contact us and we will delete it. We will respect applicable parental-consent requirements where they apply.
14. Accessibility
We are committed to making this Policy accessible. If you need it in an alternative format, please contact us.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make a material change, we will revise the “Last updated” date, notify you in the Service or by email where required, and, where required by law, obtain your renewed consent. If you continue to use the Service after the changes take effect, you are bound by the updated Policy.
16. Contact us
For questions or privacy requests, including EEA / UK matters for our Data Protection Officer, contact us.
Wardrobely is a trading name of the legal entity identified at wardrobely.app/legal. Replace the bracketed details below before launch: [legal entity name], [registered address], [company number], and (for EEA / UK) [name and address of EU / UK representative appointed under Article 27 GDPR / UK GDPR].
