Privacy Policy
Version 1.0, effective 19 August 2026. Dressing App sees your wardrobe, your measurements and, if you allow it, a photo of your body. That is intimate data. This document says exactly what we do with it, who it is sent to, and how to retrieve or erase it.
1. Data controller
The data controller is Bakouch Daniel, sole trader (micro-entreprise), business number SIRET 108 534 470 00019, 98 avenue Achille Peretti, 92200 Neuilly-sur-Seine, France.
Contact for any question or request about your data: support@dressing-app.com, with "GDPR" in the subject line.
2. What we collect
Your account: email address, and a password we never see. It is hashed by our authentication provider with a salt unique to your account, and that hashing is irreversible.
Your profile: username, bio, gender, city, measurements (height, weight, build), style preferences, colours you like or avoid, brands, dress rules you set yourself.
Your images: profile photo, photos of your clothes and their cut-out versions, DRESSING Real photos, and a mannequin photo. The last is a full-length photo of you, optional, used only to produce worn-outfit renders. It is stored privately, kept separate from your profile photo, and appears nowhere without your action.
Your usage: outfits generated and worn, dates, associated weather and occasion, history, statistics, Crowns and Carats, badges, streak, challenges, memories kept by the stylist, and conversations with it.
Your location, if you allow it: an approximate position, at neighbourhood level, to get the weather around you. It is not retained. You can decline and type a city instead.
Your social activity in the app: friends, requests, follows, posts, reactions, reports and blocks.
Your subscription: status, plan, renewal date. No banking data ever reaches us.
Your device: a technical identifier generated by the app and kept in the phone keychain. It serves only to recognise a trusted device at sign-in, and to prevent one phone being used to multiply free trials. It cannot track you outside the app and disappears on uninstall.
Crash reports: error type, code location, device model, system version, together with your account’s technical identifier. No image, no screenshot, no wardrobe or conversation content, no email address and no username are included.
3. Why, and on what legal basis
Performance of the contract: creating and running your account, analysing your clothes, generating outfits, running the stylist, remembering your preferences, running the social features you enable, managing subscriptions.
Your consent, withdrawable at any time: producing worn-outfit renders from your mannequin photo, sending you product emails (off by default), using your location.
Legal obligation and legitimate interest: moderating published images, detecting abuse, trial fraud and fake accounts, sending security and account emails, fixing bugs from crash reports, keeping accounting records.
Where the basis is consent, you can withdraw it at any time without affecting what was done before.
4. What we do not do
We do not sell your data. To anyone, ever. We do not pass it to any data broker, advertising network or social platform.
We do not train any artificial intelligence model on your photos or conversations, and our providers are not permitted to.
We do not carry out advertising profiling, and no decision producing legal effects concerning you is taken by an entirely automated process.
This website uses no analytics, no advertising cookies and no third-party trackers.
5. Who your data is sent to
Supabase receives all your data and files, for database and storage hosting. European Union, Ireland.
Anthropic receives garment photos, wardrobe context, preferences, weather and the messages you send the stylist, to analyse pieces, generate outfits and run the conversational stylist. United States.
FASHN AI receives your mannequin photo and the composite outfit image, to produce the photorealistic render. United States.
Google Cloud Vision receives images at the moment of publication, to filter inappropriate content. United States.
Resend receives your email address and the message content, to send emails. United States.
RevenueCat, Apple and Google receive a purchase identifier and subscription status, for payment. United States.
Sentry receives technical crash reports and the account identifier, to fix crashes. European Union, Germany.
Open-Meteo receives an approximate position, with no identifier, for weather and city name. European Union, Germany.
Vercel hosts this website. United States.
We may also disclose data to an administrative or judicial authority where the law requires it, and keep a copy of reported content for as long as needed to handle the report and justify the decision.
6. Transfers outside the European Union
Your data is hosted in the European Union, in Ireland.
Some providers are established in the United States. Those transfers rely on the European Commission’s standard contractual clauses, supplemented where applicable by the provider’s certification under the EU US Data Privacy Framework.
In practice, two categories of image leave the European Union: garment photos sent to Anthropic, and your mannequin photo sent to FASHN. If that does not suit you, you can use the app without adding a mannequin photo: the photorealistic render is then replaced by a flat composition of your pieces, and nothing goes to FASHN.
7. How long we keep it
While your account exists, your data is kept so the service works.
After you delete your account, it is erased within 30 days at the latest. In practice, erasure from the database and file storage is immediate: the 30-day window covers the rotation of technical backups, on which data persists for a few days before being overwritten.
A few strictly limited exceptions. Accounting records relating to a purchase are kept for 10 years, as the law requires, and contain none of your photos. A copy of reported content and the decision taken are kept for up to 1 year, to justify the decision and handle an appeal. Sign-in alert logs are kept for 90 days. The device fingerprint tied to a free trial is kept for 12 months and contains neither your name nor your email.
An account inactive for 3 years is deleted, after a warning email sent 30 days beforehand.
8. Deleting your account
In the app: Settings, then account deletion. Deletion is immediate and permanent.
It erases your profile, your wardrobe and all its photos including cut-out versions, your history, your outfits, your conversations with the stylist, your DRESSING Real photos, your posts and their images, your mannequin photo and the renders derived from it, your friendships, and your authentication account. A confirmation email is sent.
Not erased: the accounting records and moderation copies mentioned above.
Deleting your account does not cancel your subscription, which is managed from your app store. Do that first.
9. Your rights
The GDPR gives you rights of access, rectification, erasure, restriction, objection and portability.
Access and portability: write to support@dressing-app.com and we will send a copy of your data in a readable format within one month. Rectification: most information can be changed directly in the app settings. Erasure: the account deletion button in the app.
Objection and withdrawal of consent: delete your mannequin photo to stop photorealistic rendering, untick product emails in settings, withdraw location permission in your phone settings.
If our answer does not satisfy you, you can lodge a complaint with the French data protection authority, CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr.
10. Security
Traffic between the app and our servers is encrypted, and data is encrypted at rest.
Access to your data is partitioned at the database level: a row-level security rule means an account can only read its own data, independently of the app code.
Wardrobe, profile and mannequin photos live in private storage, reachable only through signed, temporary links. Only DRESSING Real photos and outfit posts, which you trigger yourself, sit in public storage.
Access keys for the artificial intelligence services are never in the app: everything goes through our servers.
An email alert is sent when you sign in from an unknown device. That message never contains a password reset link: if you receive one claiming to come from us, it does not.
In the event of a data breach likely to create a risk to your rights, we notify the CNIL within 72 hours and notify you directly where the risk is high.
11. Minors
The app is not for under-13s.
In France, processing the data of a minor under 15 for an online service requires the joint consent of the minor and the holder of parental authority. If you are between 13 and 15, you must therefore have a parent’s agreement. We may ask for confirmation of it.
If you are a parent and find an account was created by your child without your agreement, write to support@dressing-app.com and the account and data will be deleted.
The social feed prohibits publishing content depicting a minor suggestively. Automated moderation is set to reject such images, and any report to that effect is handled as the highest priority.
12. Cookies
This is a static website. It sets no analytics cookies, no advertising cookies and no third-party trackers. No consent banner is needed, because there is nothing to consent to.
The contact form transmits only what you write in it, plus one technical value used to limit automated submissions.
If an analytics tool were ever added, a compliant consent banner would be put in place first, and this document updated.
13. Changes
This document may change. Any substantial change is announced in the app and by email at least 30 days before it takes effect. The version date is shown at the top.
