Outfitter Privacy Policy
Effective date: August 1, 2026 Last updated: August 1, 2026
Outfitter ("Outfitter," "we," "us") is a mobile app for digitizing your closet, sharing outfits, and getting anonymous feedback on what you wear. It is operated by Christopher Day, an individual developer, who acts as the data controller for the personal data described here. Contact: support@outfitter.style.
This policy explains what we collect, why, who else touches it, and the choices you have. The short version: we collect what the product visibly needs, we don't sell your data, and votes are anonymous by architecture - we never show anyone how you voted.
1. What we collect
Account information. Email address and password (passwords are hashed by our authentication provider; we never see them), your username, display name, and optional bio and profile photo. We also record the date and version of the Terms you accepted.
Photos and content you post. Outfit photos, clothing photos (and the cutout versions the app generates on your device), captions, occasion and formality labels, and clothing details (brand, model, type, size). Posts and clothing items you publish are public to other users.
Body measurements (optional). Height and weight, if you choose to add them. These are visible to other users - they power sizing context on your posts and the "people your size" feature. Don't add them if you don't want them shown. You can remove them at any time in Edit Profile.
Location (optional, city-level only). If you choose to attach a location to a post, we store a city-level label (city, region, country) - never GPS coordinates. Photos are re-encoded before upload, which strips EXIF metadata including any embedded GPS position.
Activity. Votes, "this or that" picks, saves, follows, blocks, and reports. Votes, picks, and saves are private: other users never see how you voted or what you saved (a post's author can see that their post was saved, but the full list of who saved what is not browsable). Follows are public.
Feedback and reports. If you report content or send feedback, we store the report/message along with your profile id.
Crash and diagnostic data. If an error or crash occurs, our crash reporting service (Sentry) receives technical data: stack trace, device model, OS version, and app version. We do not send it your name or email, and we don't use analytics SDKs.
We do not collect your contacts, precise location, background location, browsing history, or any data from other apps.
2. Device permissions and how we use them
- Camera - to photograph outfits and clothing. Requested when you first open the camera.
- Photo library - album picks go through your device's system photo picker, so Outfitter only ever receives the specific photos you choose. We never scan or upload your library.
- Location (approximate, while in use) - requested only if you tap the location control on a post, and used once to suggest a city label.
3. Why we process your data (legal bases)
- To provide the service (GDPR Art. 6(1)(b), performance of contract): accounts, posting, voting, feeds, boards, search.
- Safety and moderation (legitimate interest, Art. 6(1)(f)): screening images, handling reports/blocks, rate-limiting abuse.
- With your consent (Art. 6(1)(a)): optional data like measurements and post locations - given by adding them, withdrawn by removing them.
- Crash diagnostics (legitimate interest): keeping the app working.
4. Who else processes your data
We share data only with the service providers that run the product ("processors"), never with advertisers or data brokers:
- Supabase - our backend: database, authentication, and image storage. Hosted in the United States.
- OpenAI - every image is screened by an automated moderation model before upload to detect nudity, graphic violence, and self-harm imagery. Images sent to the moderation API are not used to train OpenAI's models per OpenAI's API data-usage terms.
- Sentry - crash and error reporting (technical data only).
- Resend - sends account emails (confirmation, password reset, email change).
- Apple / Google - app distribution; their own privacy policies apply to the stores themselves.
If we ever transfer data across borders (e.g., EU users with US hosting), we rely on our processors' standard contractual clauses and equivalent safeguards.
5. What other users can see
Public: your username, display name, bio, profile photo, height/weight (if added), your published posts and clothing items with their labels and any city label you attached, and who you follow. Private: your email, your votes/picks, your saved lists, your blocks, your reports, and your drafts (drafts are stored only on your device, never on our servers).
6. Retention and deletion
- Account deletion is in-app: Settings → Delete account. Your content disappears from the app immediately; after a 30-day grace period (during which signing back in restores everything), your account, content, and stored images are permanently and automatically deleted.
- Deleted content: when you delete a post or clothing item, it leaves the app immediately and its image files are permanently purged from storage within about 7 days (the window exists so reported content can be reviewed).
- Reports may be retained after the reported content is gone, for safety and legal purposes.
- Crash data retention follows Sentry's retention window (90 days).
7. Your rights
Depending on where you live (GDPR in the EU/UK, CCPA/CPRA in California, and similar laws elsewhere), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Most of this is self-serve: edit your profile, remove optional data, or delete your account entirely in-app. For anything else - or to exercise any right - email support@outfitter.style and we'll respond within 30 days. We do not sell or share personal data as defined by the CCPA, and we don't use it for targeted advertising, so there is nothing to opt out of. You also have the right to complain to your local data protection authority.
8. Children
Outfitter is not for children under 13 (or the higher minimum age your country sets for consenting to data processing - 16 in parts of the EU). We don't knowingly collect data from children under these ages; if you believe a child is using Outfitter, email us and we'll remove the account.
9. Security
Data moves over HTTPS/TLS only. Database access is enforced by row-level security (your private rows are not readable by other users, at the database layer), image uploads are size- and type-restricted, and write operations are rate-limited server-side. No system is perfectly secure - if a breach affects your data we'll notify you as applicable law requires.
10. Changes
We'll update this policy as the product evolves. Material changes will be flagged in-app (the app records the version you accepted and will ask again when it changes), and the "last updated" date above always reflects the current version.
11. Contact
Questions, requests, complaints: support@outfitter.style.