Privacy Policy
Last updated: October 3, 2026
Closet Call (operated by Closet Call L.L.C.) helps you catalogue your closet, build outfit boards, share looks with friends and the community, and get AI styling, including reimagined renders and virtual try-on. This policy explains what we store, what’s private versus public, and how your data is used to power and improve the app’s AI features.
Closet Call is for adults 18 and older. You must be at least 18 to create an account or use Closet Call (see our Terms of Service). We don’t knowingly collect personal information from anyone under 18. If you believe someone under 18 has an account, email [email protected] and we’ll close it.
What we store
- Your account. Email address and sign-in details, handled by our authentication provider (Clerk). Your closet data and images are stored with our database and storage provider (Supabase).
- Your closet. Item photos you upload (and any background-removed cut-outs we generate), plus the metadata you add (name, category, size, and color tags), and, for each item, a small numeric embedding your device computes from the photo (see “On-device processing”). It is used only for your own tagging suggestions and duplicate detection, is never shared with another user or sent to an AI provider, and is deleted with the item. If you lend a piece, its name can also appear in a friend’s saved look for up to 30 days after their access ends (see “When a borrowed piece ends”).
- Your boards. The outfit layouts you create and, if you add one, the backdrop photo behind an outfit (it may show you) with the body lines you mark on it. If a look you saved holds a piece a friend lent you, we also keep, after that permission ends, the piece’s name, which account it belonged to and when the permission ended, for up to 30 days (see “When a borrowed piece ends”).
- Your calendar. When you plan an outfit for a day, we store that day, the outfit, and any occasion or time you add, plus whether you marked it worn.
- Your fit checks. When you run a fit check on a render, we keep the score, the written verdict, the full feedback text and the occasion you typed, against your account (the photo itself is not kept; see “Fit check”).
- Your settings and quotas. Your style preference, any custom occasion or vibe chips you type, your “Help improve our AI” choice, and per-day usage counters for the AI features.
- Your rank and payments. If you subscribe to a paid rank, payment is handled by Stripe on its own pages: Stripe collects your card, name, email and billing address, and we never see or store your card number. We keep your Stripe customer ID, your rank, your subscription’s status and renewal date, whether it is set to cancel, the date a renewal payment failed (if one did), and a record of each checkout you start (the rank you chose and when). Stripe uses your billing address to work out sales tax, and emails you if a payment fails or your card is about to expire.
- Your usage. To apply each rank’s limits, we record each use of Fit Check, the Stylist, Studio renders and your own AI key, the seconds you spend in Closet calls, and how long the app is open each day (counted in one-minute steps, only while it is on screen). These records hold no content: no photos, no text, no outfits. They are kept while you have an account.
- Location, only if you turn it on. The outfit calendar and Home widget can show local weather. If you allow it, the app reads your device location and sends approximate coordinates (rounded to about a kilometre) to a weather service through our own server; you can instead type a place name, and you can decline entirely and simply not see weather. We do not use location for anything else, and it is not attached to your account.
- Your profile and social activity. A handle, an optional display name and an optional “About me” bio (all three public to any signed-in user), your friend/follower connections, your close-friends list, and the posts, reposts, likes, saves and comments you create in Community.
- Your messages. The text of direct messages and the handles stamped on them, plus any photo you attach (including the reference photo in a Second opinion, which may show your face or body). Attachments are stored in your private bucket until you delete your account.
- Your Studio images. Renders you create in Studio (reimagined styles, touch-ups, and virtual try-ons) are saved to your account, along with your saved try-on photo if you set one (the default photo the try-on mirror uses). You can replace it at any time.
Closet images live in a private storage bucket. Row-Level Security scopes every record to its owner: your closet is private by default, and other users see only what you explicitly share or post.
What’s private, what’s public
- Private by default: your closet, boards, Studio renders, saved try-on photo, and messages.
- Shared with people you choose: closet shares (see “Community closet sharing”), Closet call boards (see “Closet calls”), direct messages, and video calls.
- Public when you choose: posts you publish to the Community feed (including any photos in them) carry an audience you pick: everyone, friends, close friends, or only you. A post stays visible to its audience until you delete it. Your handle, display name and “About me” bio are visible on your public profile and posts.
- Hiding a garment withdraws the looks it is in. If any garment in a posted outfit is currently hidden, that post’s outfit is withheld from everyone but you: the layout, the items and the images all become unavailable. Deleting a garment does not do this: an old post keeps rendering, because deleting something from your closet is a tidy-up, not a privacy decision.
Community closet sharing
You can share your closet with up to 8 people you add in Community. A share is permission to look, not a copy. Your friend never gets direct access to your closet database, and sharing does not duplicate your images into their account:
- When you share, the app records a grant addressed to one specific friend: the relationship and an expiry date, nothing else. It contains no copy of your items.
- When that friend opens your closet, our server checks the grant on every single read, garment by garment, and then hands their app 15-minute links to the images it is allowed to show. Nothing longer-lived leaves our servers on this path.
- Because the check is live, changes take effect immediately. Hide a garment and it is gone from their view on their very next look. Add a garment and it appears there. You no longer need to re-share.
- You choose how long a share lasts, up to 30 days (or 4 weeks). When it expires, their view goes empty.
- You can revoke a share at any time, and revoking also ends anything borrowed under it (below).
- Hiding is stronger than pausing. If you hide a garment, anything borrowed from it is ended permanently: un-hiding later does not restore it. Your friend would have to borrow again, which only happens if you leave the piece visible.
- A share shows individual garments, not your saved outfits. Your friend browses your closet piece by piece; the outfits you have composed are not part of what a share reveals.
Borrowing. From a closet shared with them, a friend can borrow a piece to style with. A borrowed piece is a pointer back to your original, not a duplicate: its photo stops showing when you revoke, when the share expires, or when you hide the garment. After that, a look your friend saved keeps the piece’s name and your username for 30 days, never its photo (see “When a borrowed piece ends”). Pieces saved from a Closet call are borrowed the same way (see “Closet calls”).
Sharing attires. You can also send a friend a selection of up to 30 of your saved attires, with an optional note, for 1 day up to 4 weeks. Your friend can view only the attires you selected: their layout and name, your pieces in them with their names, types, colors and pictures, the attire’s cover picture if you set one (for example a Studio try-on of you), and its backdrop photo if you set one (it may show you), with the body lines you marked on it, once it has passed our content check. They can view them only while the share lasts and only while nothing in them is hidden. Attires holding hidden or borrowed pieces cannot be sent. You can end the share at any time, and a block ends it. When it ends, their app shows only that access ended, with no attire name or picture, and that entry is removed 30 days later.
A recipient could still keep what they were shown (e.g. a screenshot) while a share is active. Share only with people you trust, just as you would when showing someone your closet in person.
Closet calls
A Closet call is a live call in which you and one friend build an outfit together on a shared board. It follows the same rules as closet sharing above (permission to look, checked live, with short links), and the call itself is the permission:
- Your closet is shared for the length of the call, and only if you share it. If you start a Closet call, placing it is what shares your closet: as soon as the board connects, the other person can see your non-hidden items and outfits, with no separate step to confirm. If you join someone else’s call, your closet is shown only if you agree to share it during the call. Either way, your act of sharing is recorded on our server, and the other person’s app can only obtain your pieces by asking our server for them. The call channel between the two devices carries identifiers and the names of the outfits you offer; every garment name, category and image comes from our server on request. Hidden items are never included.
- Every image link lasts 15 minutes, and our server re-checks before renewing one: that the call is still live (or ended less than 15 minutes ago), that you are still sharing, that neither of you has blocked the other, and that the piece is still visible. Hide a garment and it leaves their board within ten minutes at most; block the person or let the call end and no new links are issued. A link already handed over stops working at its 15-minute expiry.
- Saving a look does not copy your garments. If your friend saves an outfit you built together, your pieces in it are saved as borrowed pieces: pointers back to your originals, exactly like borrowing from a shared closet. Their photos stop showing when the call’s 15-minute grace period ends, when you hide the garment, or when either of you blocks the other. No photo of yours is written into their account; what their look keeps after that is described in “When a borrowed piece ends”.
- “Keep a copy” is the one way a garment of yours becomes theirs, and only you can grant it. During a call you can offer a specific piece to the other person. The offer is for that piece, for that person, and can be used once. If they accept it, our server copies the image into their closet and marks the result as a copy credited to you; a copy can never be lent onward by them. A copy you have consented to is theirs: it is not removed by hiding, revoking, blocking, or by deleting your account (deleting your account removes only your username from it). That is what consent means here, so offer only what you are happy for them to keep.
- Styling in a call. Calling a friend lets them style with your pieces (never hidden ones) for the default time you set: 1 day unless you change it, up to 30 days. Answering shows your closet view only, until you allow the caller to style with your pieces, again for the default time you set. That permission covers every call between the two of you until it runs out, and a block ends it.
- Saving a look when a call ends. You can save the look you built to your attires, the other person’s, or both. Our server writes every copy you choose, including the one in the other person’s attires, under the name you typed. Each copy keeps only the pieces its owner may use: their own, and yours only under a permission you gave. If your connection drops, the look waits on your phone and is saved when you’re back online.
When a borrowed piece ends
A permission to use a friend’s piece ends when the closet share runs out or is revoked, when a Closet call’s 15-minute grace period ends, when the owner hides or deletes the piece, or when one of you blocks the other. When it does:
- The photo goes. The borrower’s app can no longer get the piece’s picture from our server, and no picture of it is stored in their account. No new link is issued; a device may briefly keep what it already showed, and screenshots are covered above.
- The look moves to Expired. A look the borrower saved that holds the piece moves to their Expired collection. It keeps its name and the borrower’s own pieces as they were. Where the lent piece was, it shows an outlined space reading “Expired” and the piece’s name (or its type, such as “Top”, when it had no name). Under the look’s name it credits the owner, for example “With @alex’s 2 pieces”.
- Everything goes after 30 days. 30 days after the permission ended, the look is deleted, together with the piece’s name, the owner’s username and our record of that lending. A look saved later with the same piece gets no extra time: it is deleted on the same day. The borrower can delete a look sooner. If the piece is lent to them again before then (for example they borrow it again from a closet the owner shares with them), the look returns with its photos and leaves Expired.
- What we keep for those 30 days. The piece’s name as it was when it was lent, which account it belonged to (shown by that account’s username), and a record of the lending: the piece’s identifier and when the permission started and ended, so the look can be deleted on time. Nothing else about the piece is kept: no photo, size, colors or other details. Only the borrower sees the name and username.
- If one of you blocks the other, the look keeps the pieces’ names but no longer shows the owner’s username; it reads, for example, “With 2 borrowed pieces”.
- If the owner deletes their Closet Call account, their pieces’ names and their username are removed from these looks at once. The look shows “Item not found” where each piece was and “Shared user not found” in place of the credit, and it is still deleted 30 days after the permission ended.
- Renew. From an expired look, the borrower can ask the owner to lend the pieces again. The owner decides whether, and for how many days.
If you lend pieces, this means a friend’s saved look can show your piece’s name and your username for up to 30 days after their access ends, but never its photo. That includes a piece you later rename, hide or delete: the look keeps the name it had when you lent it. If you change your username, those looks show the new one. For immediate removal of all user info, choose Terminate permissions at the top right of the event under Wardrobe share (coming soon). Until then, deleting your account removes it at once. A copy you let a friend keep with “Keep a copy” is different: it is theirs, with its photo and name (see “Closet calls”); if you delete your account, your username is removed from it.
Video calls
Live calls connect device-to-device where possible; when a direct connection isn’t possible, call media is relayed through call servers. Call audio and video are never recorded or stored by us. We do keep a record that a call happened (who called whom, whether it was answered, when it started and ended, and which kind of call it was) so that both people can see their call history and so we can apply daily limits. We also keep connection statistics (whether a relay was used, connection timing, and data-transfer counts) to diagnose call reliability and estimate service costs. These statistics contain no call audio, video, photos or messages.
AI styling, Studio renders & virtual try-on
We use your data to power and improve the app’s AI features:
- AI suggestions and outfit rating. When you use AI-powered styling, your closet metadata (item names, categories, sizes, colors) is sent to our model provider (Anthropic) to generate a suggestion or rating; your closet photos are not. It is used to serve your request and is not used by that provider to train their models when these features run on Closet Call’s account; with your own AI key, that company’s terms for your account apply (see “Your own AI key”). The request also carries any free text you type (your styling request, and for a fit check the occasion and note) and a derived summary of your own taste signals.
- Fit check. If you ask for a fit check, the outfit photo you choose, which may show your face or body, is sent to our model provider (Anthropic) to rate the outfit. Camera metadata (including any location data) is stripped before upload. The photo is processed only to serve that request, is never uploaded to our storage, is not retained by that step, and is not used by the provider to train their models when these features run on Closet Call’s account; with your own AI key, that company’s terms for your account apply (see “Your own AI key”).
- Your own AI key (optional). In Profile → Settings → AI provider you can save your own Anthropic or OpenAI API key so Stylist and Fit check run on your account with that company instead of ours. Only one key is stored at a time, and Settings names the company yours is with. When you do, the closet metadata and fit-check photos described above are sent to the company whose key you saved, under your account and their terms for it, not ours. How they retain or use that data is governed by your agreement with them, and the no-training promise above is theirs to make. We encrypt your key at rest, never show it again beyond its last four characters, never log it, and use it only for these two features. Your key never affects anything else: Studio runs on our own rendering service, and background removal and smart tagging run on your device (see “On-device processing”). If we ever pause own-key routing, Settings says so and these features run on Closet Call’s account until it resumes. The key is deleted when you remove it or delete your account. Closet Call’s own styling signals (see “Improving and training” below) are logged the same way whichever key is used. Saving the key is your consent to this change of processor. You can remove it at any time; choosing “Closet Call AI” switches back without deleting it.
- On-device processing. Two things that look like AI features never leave your device: background removal (the cut-out we make from a closet photo) and smart tagging (the category and colour suggestions when you add an item). Both run in your browser or app: the model is downloaded to you, rather than your photo being uploaded to it. Your closet photos are still stored in your private bucket, because that is your closet; but nothing is sent anywhere in order to tag them or cut them out.
- Automated image safety checks. Every image you upload is checked by an automated nudity classifier on our server. Images you post, send or set as your profile picture are refused if flagged. Images in your private closet, mirror, covers, backdrops and Studio storage are kept for you even when flagged, but are not made available to other users through our sharing services. We knowingly retain these flagged private images for your own use. We store the classifier verdict and scores, model and policy identifiers, check time, and the image's Storage version. A refused public-destination upload also creates a moderation report; a flagged private upload does not. On-device checks before sharing and checks by the Studio rendering service remain additional safeguards. Signed links already issued may remain usable until their expiry; automated checks can make mistakes.
- Studio renders and virtual try-on. When you use Studio, your source image (a photo you choose, which may show your face or body; or an attire snapshot), plus, for try-on, your circled region and the garment image, is sent to our own image-rendering service, which runs on cloud GPU infrastructure (currently RunPod). It is processed only to produce your render and is not kept by the rendering service; the finished image is saved to your account. Because these photos can be sensitive, we ask for your explicit consent before the first photo you submit; you can decline and simply not use the feature.
- Improving and training our own recommendation models. We log how you interact with suggestions (which looks you save, feedback you give on Studio renders, and the outfits you build), and we may use this data, together with your closet metadata, to improve and train our own recommendation models so suggestions get better over time. This uses your personal taste metadata only: the signals above plus your closet’s text details (categories, colors, names), never your stored images.
- No photos are collected for training. Your photos (closet images, fit-check photos, Studio photos, and your saved try-on photo) are used only to serve your requests and are never collected or used to train models when these features run on Closet Call’s account; with your own AI key, that company’s terms for your account apply (see “Your own AI key”). If we ever want to use photos to improve our own image models in the future, that will be strictly opt-in through a separate, explicit consent, and unless you give it, nothing changes.
- Wherever practical we use de-identified or aggregated data for model training. We don’t sell your data, and we don’t use it to train models for unrelated purposes.
If you’d prefer your data not be used to train our models, turn off “Help improve our AI” in Profile → Settings at any time. Your taste metadata is then excluded from model training; the app still logs the same signals solely to power your own personalized suggestions, and nothing more.
What we don’t do
- We don’t sell your data.
- We don’t expose your closet to other users except through a share you explicitly create, a Closet call you take part in, or a post you publish.
- API keys for AI features stay server-side, including any key you add yourself (stored encrypted, deleted with your account); your images and metadata are not sent to third parties except as needed to provide the service (storage, auth, payments (Stripe), and the AI processing described above). We also send crash and error reports to Sentry from the production app, to find bugs; these carry technical context about the failure, not your photos, and are scrubbed of personal details before they are sent. The web app reports aggregate page views to Vercel Web Analytics, which does not use cookies or build a profile of you.
- We don’t store your IP address. Nothing we built records it. The services that carry your requests see it to do their job: Vercel serves the web app (its analytics uses the address only to work out the country of a visit and does not keep it), Supabase runs our database, storage and functions, Clerk signs you in and records the address, browser and device of each sign-in as your account’s activity, Cloudflare checks that a sign-up is human and relays call traffic, Stripe collects it when you pay, and Hostinger serves our website. Each keeps it in its own logs for a limited time under its own policy. Open-Meteo (weather), Anthropic, OpenAI and RunPod never receive it: those requests go through our servers. During a Closet or video call your phone may connect directly to your friend’s phone, and then each phone can see the other’s address; when no direct path is available the call goes through the relay instead.
Reporting, blocking & community rules
Community content is governed by our Community Guidelines, which you accept when you first use social features. You can report any post or profile and block any user from within the app; reports are reviewed and acted on. Content that breaks the rules can be removed and repeat violators can lose access.
Your controls
- Edit or delete any closet item or board at any time. A published post cannot be edited, but you can change its audience or delete it, and hiding any garment in it withdraws the look immediately. Studio renders cannot yet be deleted individually. They are removed when you delete your account. A friend’s saved look that held a piece you lent keeps the name it had when you lent it, and your username, for up to 30 days after their access ends, even if you rename, hide or delete the piece (see “When a borrowed piece ends”).
- Hide any item or outfit from others (“Hide from others”). This is the main privacy control: a hidden garment disappears from live shared closets, permanently ends anything borrowed from it, and withdraws any posted look it appears in. It does not reach a copy you explicitly let a friend keep (see “Keep a copy” under “Closet calls”). A look a friend already saved keeps only the piece’s name and your username, for up to 30 days.
- Replace your saved try-on photo at any time. There is not yet a way to remove it without replacing it; deleting your account removes it.
- Direct messages cannot be deleted individually. A conversation is removed when either of you deletes your account.
- Revoke any share you have given, at any time.
- Report or block any user from their profile or content. Blocking also ends any call in progress and clears the relationship between you.
- Delete your account from Profile → Settings to remove your data, including any AI key you saved, and your pieces’ names and your username from looks friends saved. A copy a friend kept with “Keep a copy” stays theirs, with its photo and name, but loses your username. It also cancels any paid rank at once and deletes your customer record at Stripe. Stripe keeps records of past payments as the law requires.