WhichFit

Privacy Policy

Last updated July 15, 2026

The short version

WhichFit helps you decide what to wear. It is built to read your clothes, not you. You can start deciding without an account, and we don't sell your data.

Your outfit photos & notes

When you ask for a decision, your outfit photos (and the optional note you type about the occasion) are sent to our server and on to Google Gemini, our third-party AI provider, which analyzes them and returns the ranking. We process your photos to provide that result and do not store them on our servers; they are handled in memory and discarded after the response. The ranking result itself (not your photos), including the occasion label, is kept on our server for up to 14 days to power the locked-result reveal, then deleted; this applies even if you don't have an account. Your note is also sent to that AI provider for the ranking, and (only if you sign in and save the decision) it is stored privately with that saved decision. Friend-vote links share the outfit photos you chose and the occasion label, but not your private decision note. Friends can optionally leave a short moderated note with their vote. Two exceptions for photos:

AI training: WhichFit uses a paid AI tier, under which Google does not use your photos to train AI models.

Face data: WhichFit does not collect face data. Your photos may include your face, but we never perform facial recognition or facial analysis, never extract facial features or measurements from any photo, and never create, store, or share any data that identifies a face.

What you tell us during setup

When you first open WhichFit, setup asks you a few things about yourself: an age bracket (for example, 18 to 24), your gender or wardrobe preference, and your style, occasion, and goal preferences. We collect these during setup and use them only to personalize your outfit advice: they are included in the ranking request sent to Google Gemini so your advice fits you better. This is first-party personalization. It is not used to track you across other apps or services.

Your answers are stored tied to your device and, once you sign in, your account, and are retained until you delete your account. They’re included in your data export and deletion.

Location

Location is optional. If you allow it, your approximate location is used only to factor local weather into your outfit advice. We request low-accuracy location and round it to roughly a city-block grid before it leaves your device, so we never receive your precise GPS coordinates. That approximate location is shared with our weather provider (Apple WeatherKit) to look up local conditions; we don't store your location.

Device & fraud prevention

To prevent abuse of invite codes, we use a random identifier stored securely on your device together with your IP address. Both are cryptographically hashed (HMAC) on our server, so we never store your raw device identifier or IP address.

Account (optional)

You can start a decision without signing in. If you choose to create an account, we use Supabase to manage it via a one-time email code or Sign in with Apple. You can delete your account anytime in Settings, which removes your account, associated profile, saved decisions and linked photos, and vote links tied to your account. Some abuse-prevention and analytics records may be retained after being separated from your account.

Subscriptions & purchases

If you subscribe to WhichFit Pro, the purchase is processed through Apple, and we use RevenueCat (a third-party subscription processor) to manage entitlements and tell the app whether your subscription is active. RevenueCat receives your purchase and subscription details (such as which plan you bought, its status, and renewal events) and an identifier we link it to: your account identifier if you're signed in, or your app's random device identifier if you're not. We use this only to deliver and restore your subscription.

Usage analytics

We record basic product events (for example, completing a decision) tied to your hashed device identifier, so we can understand how the app is used and improve it.

Tracking & attribution

We use Tenjin (a mobile measurement partner) to understand which links and marketing campaigns bring people to WhichFit, so we can see what's working. WhichFit does not show Apple's App Tracking Transparency prompt and never reads your device's advertising identifier (IDFA). Campaign measurement relies on Apple's SKAdNetwork, which reports installs in a privacy-preserving way that is not linked to you.

Service providers

We rely on these processors to run WhichFit, and we do not sell your data. Each provider processes your data only to deliver its service to us, under contract terms that protect it to the same standard as this policy:

Your choices and rights

Children

WhichFit is for people aged 18 and older. We do not knowingly collect personal data from children, and our analysis rejects photos that appear to show minors.

Changes & contact

We'll update this policy as the app evolves. Questions about your privacy? Contact support@whichfit.app.