Back to Outffy

Privacy Policy

Last updated: August 26, 2026

1. Who we are

Outffy is operated by Polina Kozinskaya, sole trader, [Legal entity / address] ("Outffy", "we", "us"). We are the data controller for the personal data described in this policy.

Privacy contact: privacy@outffy.app. General support: support@outffy.app.

2. What this policy covers

Outffy turns photos of you into a photoreal digital twin, photos of your clothes into a digital wardrobe, and lets an AI stylist compose outfits on that twin. This policy explains what data the app and the website collect, why, who processes it, how long we keep it, and how you can delete it. It applies to the Outffy mobile app, the API behind it, and the pages on our website.

3. What we collect

  • Account data: your email address (email sign-in) or the identifier Apple or Google gives us when you sign in with them, an optional display name, your time zone and app language, and the dates your account was created and last used.
  • Face and body photos: the photos you choose to build and refine your digital twin. Your face and body photos are uploaded to generate your twin; the generated twin is kept privately with your account until you delete it, and the original photos are not kept on our servers after generation (a copy stays on your device).
  • Wardrobe photos: the photos of clothes you scan. They are uploaded and processed into transparent item cards with tags (category, colour, material, season, formality, fit). The cards are stored with your account; the original scan photos are not kept on our servers after processing.
  • Measurements and parameters: the height, weight, age, body shape and style preferences you enter to shape your twin and the stylist's suggestions.
  • Generated images and content you create: your twin portraits, item cards, try-on renders, outfit collages, saved outfits, capsules, planner entries, the messages you exchange with the AI stylist, and any reports you file about a generated image.
  • Weather requests: the city or destination you type when building a capsule, sent as a place name only, without your precise location. The app does not request device location.
  • Usage and diagnostics: server logs (request time, IP address, app version, device type, request identifiers, errors) and, when crash reporting is enabled in a release, crash reports containing the app state at the time of the crash. We do not use third-party advertising or analytics SDKs and we do not track you across other apps or websites.

4. Why we use it

  • To provide the service: generate your twin, digitise your wardrobe, render outfits on your twin, suggest looks, build capsules and keep your planner.
  • To keep your account working: sign you in, send one-time codes, restore your data on a new device, and delete everything when you ask.
  • To keep the service safe and reliable: prevent abuse, apply per-user generation caps, investigate reports about generated images, and diagnose crashes and errors.
  • To answer your messages to support.
  • To meet legal obligations.

We do not sell your data, we do not show ads, and we do not use your photos or generated images to advertise to you or to anyone else.

5. Legal bases (GDPR)

  • Consent (Art. 6(1)(a)) and explicit consent (Art. 9(2)(a)) for uploading and processing face and body photos, which may reveal characteristics that are sensitive under data-protection law. You give this consent in the app before the first photo leaves your device and can withdraw it at any time by deleting your twin or your account.
  • Performance of a contract (Art. 6(1)(b)) for your account, your wardrobe, generated images, outfits, capsules, planner and stylist chat.
  • Legitimate interests (Art. 6(1)(f)) for security, abuse prevention, usage caps, diagnostics and crash reports, and for answering support requests.
  • Legal obligation (Art. 6(1)(c)) where a law requires us to keep or disclose data.

6. AI processing

Generating a twin, an item card, a try-on render or a stylist reply means sending the relevant photos, measurements and text to a third-party AI model. Today these vendors are Google Gemini (item cards, try-on renders, the stylist) and OpenAI (the digital twin). If you connect your calendar, event names are also sent to Google Gemini so we can show them in English in the app; we do not store them on our servers, we never change your calendar, and you can turn this off in Profile → Permissions. We use their business and API tiers, which do not train on your data, and we send each vendor only what the specific generation needs. Generated results are AI images: they can be inaccurate and are not a guarantee of fit. Every render carries an AI label, and you can report any generated image from the app.

7. Who processes your data

We use these processors under data-processing agreements:

  • Supabase — database, authentication and private file storage for your account (hosted on AWS in [Supabase region]).
  • Vercel — hosting of the API and the website.
  • Google (Gemini API) — AI generation of item cards, try-on renders and stylist replies.
  • OpenAI — AI generation of the digital twin.
  • Apple (Sign in with Apple) and Google (Google sign-in), when you choose them to sign in.
  • Resend — delivery of one-time sign-in codes and account emails.
  • Sentry — crash reports, when crash reporting is enabled in a release.
  • Open-Meteo — weather forecasts for capsules, given a place name only.

We disclose data to authorities only when the law requires it. We do not share your data with advertisers or data brokers.

8. International transfers

Our processors may store or process data in the United States and other countries outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework.

9. How long we keep it

  • Account, photos-derived content, measurements, generated images, outfits, capsules, planner and stylist chat: for as long as your account exists. When you delete your account everything above is removed from our database and storage.
  • Accounts that never completed sign-up (anonymous accounts) are automatically deleted after 30 days of inactivity.
  • Original face, body and wardrobe photos: not kept on our servers after the generation they were uploaded for.
  • Server logs: up to 90 days. Crash reports: up to 90 days.
  • Reports about generated images: until the report is resolved, then up to 12 months as a record of the decision.
  • Backups: deleted data may remain in encrypted backups for up to 30 days before it is overwritten.

10. Your rights

You can ask us to access, correct, export, restrict or delete your personal data, object to processing based on legitimate interests, and withdraw consent at any time. You can also complain to your data-protection supervisory authority.

  • Delete in the app: Profile → Account → Delete account. This permanently removes your account and all data listed above. Profile → Account → Delete my data wipes your content but keeps the account.
  • Delete from the web: our delete-account page explains the same path and an email fallback if you have already uninstalled the app.
  • Export: email privacy@outffy.app and we will send a copy of your data within 30 days.

11. Children

Outffy is for people aged 16 and over. We ask you to confirm this before any photo is captured, and we delete accounts we learn belong to younger users.

12. Security

Your data is stored in a private bucket and database rows that only your account can read (row-level security), served through short-lived signed links, and transferred over TLS. Access to production systems is limited to the operator. No system is perfectly secure; if a breach affects you we will notify you as the law requires.

13. Changes

We will update this policy when the service changes. The "Last updated" date at the top tells you when. For material changes we will notify you in the app before they take effect.

14. Contact

Privacy questions and requests: privacy@outffy.app. Support: support@outffy.app. Postal address: [Legal entity / address].

Outffy

A stylist, a digitized wardrobe, and a twin that wears both.

Made for the clothes you already own.