Privacy Policy
The short version
WhichFit helps you decide what to wear. It is built to read your clothes, not you. You can start deciding without an account, and we don't sell your data.
Your outfit photos & notes
When you ask for a decision, your outfit photos (and the optional note you type about the occasion) are sent to our server and on to Google Gemini, our third-party AI provider, which analyzes them and returns the ranking. We process your photos to provide that result and do not store them on our servers; they are handled in memory and discarded after the response. The ranking result itself (not your photos), including the occasion label, is kept on our server for up to 14 days to power the locked-result reveal, then deleted; this applies even if you don't have an account. Your note is also sent to that AI provider for the ranking, and (only if you sign in and save the decision) it is stored privately with that saved decision. Friend-vote links share the outfit photos you chose and the occasion label, but not your private decision note. Friends can optionally leave a short moderated note with their vote. Two exceptions for photos:
- If you create a friend-vote link, the outfit photos you chose to share are stored in a private cloud bucket so your friends can view them, and the link stores the occasion label shown on the vote page. Access to photos is through short-lived signed links, and the vote link expires after 7 days.
- When you sign in, decisions you save (and their photos) are stored privately in your account, so they sync across your devices. They’re access-controlled: only you can read them. Without an account, saved decisions stay on your device.
AI training: WhichFit uses a paid AI tier, under which Google does not use your photos to train AI models.
Face data: WhichFit does not collect face data. Your photos may include your face, but we never perform facial recognition or facial analysis, never extract facial features or measurements from any photo, and never create, store, or share any data that identifies a face.
What you tell us during setup
When you first open WhichFit, setup asks you a few things about yourself: an age bracket (for example, 18 to 24), your gender or wardrobe preference, and your style, occasion, and goal preferences. We collect these during setup and use them only to personalize your outfit advice: they are included in the ranking request sent to Google Gemini so your advice fits you better. This is first-party personalization. It is not used to track you across other apps or services.
Your answers are stored tied to your device and, once you sign in, your account, and are retained until you delete your account. They’re included in your data export and deletion.
Location
Location is optional. If you allow it, your approximate location is used only to factor local weather into your outfit advice. We request low-accuracy location and round it to roughly a city-block grid before it leaves your device, so we never receive your precise GPS coordinates. That approximate location is shared with our weather provider (Apple WeatherKit) to look up local conditions; we don't store your location.
Device & fraud prevention
To prevent abuse of invite codes, we use a random identifier stored securely on your device together with your IP address. Both are cryptographically hashed (HMAC) on our server, so we never store your raw device identifier or IP address.
Account (optional)
You can start a decision without signing in. If you choose to create an account, we use Supabase to manage it via a one-time email code or Sign in with Apple. You can delete your account anytime in Settings, which removes your account, associated profile, saved decisions and linked photos, and vote links tied to your account. Some abuse-prevention and analytics records may be retained after being separated from your account.
Subscriptions & purchases
If you subscribe to WhichFit Pro, the purchase is processed through Apple, and we use RevenueCat (a third-party subscription processor) to manage entitlements and tell the app whether your subscription is active. RevenueCat receives your purchase and subscription details (such as which plan you bought, its status, and renewal events) and an identifier we link it to: your account identifier if you're signed in, or your app's random device identifier if you're not. We use this only to deliver and restore your subscription.
Usage analytics
We record basic product events (for example, completing a decision) tied to your hashed device identifier, so we can understand how the app is used and improve it.
Tracking & attribution
We use Tenjin (a mobile measurement partner) to understand which links and marketing campaigns bring people to WhichFit, so we can see what's working. WhichFit does not show Apple's App Tracking Transparency prompt and never reads your device's advertising identifier (IDFA). Campaign measurement relies on Apple's SKAdNetwork, which reports installs in a privacy-preserving way that is not linked to you.
Service providers
We rely on these processors to run WhichFit, and we do not sell your data. Each provider processes your data only to deliver its service to us, under contract terms that protect it to the same standard as this policy:
- Google (Gemini): AI outfit and note analysis
- Supabase: accounts, database, and shared-photo storage
- RevenueCat: subscription management (WhichFit Pro)
- Tenjin: install and marketing attribution
- Vercel: server hosting
- Resend: account sign-in emails
- Apple WeatherKit: weather (receives your approximate location). Weather data is provided by Apple Weather.
Your choices and rights
- Start a decision without an account.
- Decline location and still get advice.
- Turn tracking off at the prompt, or anytime in iOS Settings → Privacy & Security → Tracking.
- Download a copy of your data in Settings → Privacy & safety → Download my data.
- Delete your account and its data anytime in Settings → Delete account.
- Report a result you feel crossed a line.
Children
WhichFit is for people aged 18 and older. We do not knowingly collect personal data from children, and our analysis rejects photos that appear to show minors.
Changes & contact
We'll update this policy as the app evolves. Questions about your privacy? Contact support@whichfit.app.