Privacy Policy

Last updated: May 16, 2026

1. Who we are

OutfitScore ("we", "our", "us") is an AI fashion-rating app for iOS that scores your outfit across four axes — color harmony, fit, occasion, and trend — and generates three styled alternatives that preserve your face and body. This Privacy Policy explains what we collect, why, and the controls you have. We are the data controller for your account data.

2. Information we collect

  • Outfit photos: the images you upload to be scored. Used as input to AI scoring and as a reference for alternative-outfit generation.
  • Scores and critiques: the 0-100 score, axis-level breakdown, and written critique generated for each outfit. Saved to your style history.
  • Generated alternatives: the three AI-generated alternative-outfit images per score.
  • Anonymous device ID: a per-install identifier used to attribute credits and subscription state to your device. Not linked to your name or email.
  • Subscription state: entitlement status from RevenueCat / Apple. We do not see your card details.
  • Credits balance: remaining free or subscription credits attached to your install.
  • Locale: the device language, used to localize critiques and prompts.
  • Push token (optional): stored only if you opt in to notifications, so we can tell you when scoring is complete.
  • Diagnostics: anonymous usage events and crash logs (you can opt out in Settings).

3. How we use your data

  • Score your outfits across color harmony, fit, occasion, and trend.
  • Generate three styled-alternative outfit images that preserve your face and body.
  • Save your scores, critiques, and alternatives to your private style history.
  • Send transactional push notifications you've opted into (scoring complete, monthly credit reset).
  • Enforce subscription entitlements, credit balances, and prevent abuse.
  • Improve scoring quality and prompt safety.
  • Provide customer support when you contact us.

We do not sell your data, share it with advertisers, or train third-party AI models on your photos.

4. Sub-processors

  • Google (Gemini API) — outfit analysis, scoring, and alternative-outfit image generation. Inputs are not stored by Google for training under our enterprise terms.
  • Cloudflare R2 — outfit photo and generated-image storage.
  • RevenueCat — subscription receipt validation.
  • Apple (APNs) — push notification delivery.
  • Hetzner Cloud (EU) — application servers and database hosting.

5. Where your data is stored

Our primary database is hosted in the European Union (Hetzner, Germany). Image objects are stored on Cloudflare R2 (multi-region). AI scoring and generation occur on Google Cloud servers (region varies). Your data may therefore be transferred outside your country of residence; where required, we rely on Standard Contractual Clauses.

6. How long we keep it

  • Outfit photos, scores, critiques, alternatives: kept while your install is active.
  • Source photos used only for scoring: deleted within 24 hours once the score and alternatives are rendered.
  • Diagnostic events: 90 days, then aggregated.
  • Backups: encrypted database snapshots retained for 30 days.
  • Deleted accounts / uninstalls with deletion request: erased within 30 days, except where law requires us to retain receipts.

7. Your rights (GDPR, UK GDPR, CCPA)

You can exercise the following rights at any time, directly inside the app under Settings → Privacy:

  • Access & portability: tap "Export my data" to receive a JSON archive with your scores, critiques, and generated alternatives.
  • Erasure ("right to be forgotten"): tap "Delete account" — your data is hard-deleted within 30 days.
  • Rectification: delete individual outfits from style history any time.
  • Object / restrict: contact us at the email below.
  • Lodge a complaint with your local supervisory authority.

8. Children

OutfitScore is rated 4+ but is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with information, contact us and we will delete it.

9. Content safety

Every uploaded outfit photo is run through a content-safety filter before scoring. Photos containing nudity, sexual content, or other prohibited material are refused. Users who repeatedly attempt to upload prohibited content are credit-throttled and may ultimately be suspended.

10. Security

Data in transit is encrypted with TLS 1.3. Database backups and stored images are encrypted at rest. Refresh tokens are stored as salted hashes. We follow OWASP top-10 mitigations and rotate secrets quarterly.

11. Changes

We may update this policy. Material changes will be announced in-app at least 14 days before they take effect.

12. Contact

Questions or rights requests: support@purifyos.app