Effective 5 October 2026. This notice covers the Closet Muse Android closed-test app and its managed AI service, operated by the Closet Muse developer. Contact the developer using the Support / privacy request form in Settings or on this website. Public-release operator and support details must match the final store listing.
Garment photos, clothing descriptions, saved outfits, preferences and an optional face reference are stored on your phone. Local outfit suggestions and automatic background removal run on the device. We do not provide cloud wardrobe sync in this version. Exported backups are files you control; they exclude personal API keys, account tokens, face references and generated previews.
Photo analysis sends the selected garment photo to your chosen AI provider. Styling sends clothing descriptions and your request. Outfit previews send the selected garment photos; personalised previews also send your face reference with your approval. AI images are illustrations and cannot predict fit. Use only adult reference photos that you have permission to use. API providers process this content under their own terms and retention policies.
Closet Muse AI sends requests through our Cloudflare gateway to Google Gemini. Your personal Gemini or OpenAI connection sends requests directly to that provider; a custom connection sends them to your configured server. Your personal keys are not sent to the Closet Muse gateway. Personal API connections require active Premium; provider fees may apply. Managed AI never generates outfit images.
AI features are for adults aged 18 and over. Unpaid Gemini may use submitted content to improve Google products and may involve human review. Do not submit personal, confidential or sensitive information to unpaid Gemini, including selfies. Confirm a billing-enabled Google project before using Gemini with a face reference or in the EEA, Switzerland or UK. The managed service enforces its configured regional and data-use restrictions. Consent does not override provider terms.
Firebase handles managed account email, password authentication and verification. The app stores encrypted sign-in tokens using Android Keystore and does not store your password. Personal Gemini/OpenAI keys are encrypted with Android Keystore. A custom-server access token is stored in the app's private settings. Device loss or compromise can affect locally stored data.
Cloudflare processes connections and request metadata including IP addresses. Our D1 database stores keyed hashes for usage and abuse controls, not wardrobe photos. For membership administration, a separate directory stores your verified Firebase account ID and email, last connection time, and complimentary grant status. Only configured administrators can search it. Membership changes record the administrator, target, reason and before/after status; these audit entries are kept for 90 days and removed at the next daily cleanup (within 91 days). Prior-day allowance counters are pruned on the next allowance reservation; old minute counters are pruned on the next authenticated request. Minimal technical error logs are used for debugging; request photos, passwords, API keys and prompts are not deliberately logged by the gateway. Cloudflare platform logs have provider-controlled retention, currently up to 3 days on the free plan; verify this before public release if the plan changes.
Only when you press Send, we receive the category, message, optional contact email and optional generated text shown in the report form. Photos and API keys are not attached. A keyed hash of the connection address limits report abuse. Reports are kept for investigation for 30 days, then removed at the next daily cleanup (within 31 days). Do not enter passwords, API keys or sensitive information in a report. Reports are reviewed by the developer; urgent safety issues should be reported to the appropriate authorities.
You can remove a garment or face photo, delete all local app data, disconnect an API key, and export your wardrobe. Deleting a managed account removes its Firebase sign-in record and membership directory entry and revokes complimentary access. Minimal hashed trial-eligibility records are retained for up to 91 days after directory removal to prevent trial replay. Paid membership records are separate. The app offers a separate option to also erase this device's wardrobe. The external account-deletion page works without installing the app. External deletion cannot erase files on your phone or backups you exported; erase those yourself. Current-day pseudonymous abuse counters may remain temporarily for fraud prevention as described above. Submitted reports are not linked to your account; use a support/privacy request with your report reference to request their deletion.
Google, OpenAI, Cloudflare and your custom provider may process data outside your country. See their privacy notices for their processing and rights. You may request access, correction or deletion of information held by us through Support / privacy request. We do not sell your wardrobe. This preparation build bundles Google Play Billing, AdMob and Google UMP code, with purchases and ad initialization disabled. No ads are requested or purchases offered in this test build. Before enabling them, the public notice and store Data safety declarations must describe the actual SDK processing. In a future enabled test, purchase verification stores keyed account identifiers, encrypted Play purchase tokens, product IDs, status, expiry and purchase reconciliation on our server. Refund and verification records are retained for reconciliation. Managed image generation is disabled. This version does not offer image credits or store generated images on the gateway. The final paid release must specify retention periods and deletion rights for transaction records. Face and wardrobe input photos are not stored by the gateway. Provider retention policies apply.