Closet Muse privacy

Privacy Policy

Last updated September 26, 2026

What we collect

We collect account details, style choices, wardrobe records and photos you add, outfit plans, confirmed wear actions, wishlist items, subscription status, and actions you choose to save. Camera, location and browser notification permissions are optional. This website does not access Apple Health or automatically sync Apple Calendar.

How information is used

We use information to provide private wardrobe organization, outfit planning, requested photo features, subscriptions and support. When you enable eligible Style Memory, confirmed wears and combinations worn together help rank your clothes. Viewing a suggestion or generating a try-on does not mean you wore it. We do not sell personal information.

Optional Google sign-in

Google shares your verified email, name and account identifier when you choose Google sign-in. We store the identifier to recognize your account. Sign-in itself grants no access to your calendar, Gmail or files. We do not store your Google password or basic sign-in access tokens.

Optional Apple sign-in

When available and chosen by you, Apple sign-in shares a verified email or private relay address and an Apple account identifier. We store that identifier, the sign-in client identifier, an encrypted refresh credential and its last verification time. These let us recognize your account, check an Apple-origin session on its next use after 24 hours, and revoke Apple authorization during account deletion. We do not receive your Apple password. Apple sign-in does not connect Calendar, Health, iCloud files or a native app.

This initial option creates new ordinary member accounts; it does not link an existing Closet Muse account or grant owner, personal-edition or complimentary privileges. Existing members should use their existing sign-in method to avoid creating a second closet or subscription. Password setup and deletion confirmation use email recovery, including through your Apple relay address if you chose Hide My Email. Keep that forwarding active or contact support for assistance.

Account deletion attempts Apple revocation before erasing the retained credential. If revocation cannot be confirmed, deletion pauses for retry or support rather than reporting success. A one-way deletion marker rejects sign-ins begun before deletion for ten minutes; expired markers and sign-in attempts are removed during subsequent Apple sign-in or deletion activity. Encrypted credentials are excluded from member and owner diagnostic exports. Removing access in your Apple account does not itself delete your Closet Muse records or cancel a subscription.

Optional calendar connection

Google Calendar is a separate connection that you choose in Planner. If available and authorized by you, Closet Muse requests read-only access to events on calendars you own and uses only your primary calendar. We store an encrypted refresh credential, your connection date and last refresh time so you can reconnect without signing in to Google on each visit. When you choose Load or Refresh, our server reads up to 400 events for the next two weeks and returns their titles and dates to your current page. Titles marked private are hidden; descriptions, attendees and locations are not returned. There is no continuous background calendar sync and no ability to create, edit or delete Google events.

Fetched events are not persisted as a calendar feed, shared with Gift Circle or sent to an AI or shopping provider. Only the title, date and optional time of an event you select become account data when you explicitly save an outfit plan. Disconnect removes our saved credential and requests revocation at Google; if revocation cannot be confirmed, remove access in your Google account too. Revocation can affect other grants for the same Google project. Saved outfit plans remain until you delete them. Calendar file imports are reviewed locally on your device with the same explicit-save rule. Automatic Apple Calendar access is not implemented.

Closet Muse’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Gift Circle

Wishlist items are private by default. Sharing begins only after the invited recipient accepts. They can see only product hints you explicitly share, including saved size, colour and priority when provided. Private notes, wardrobe and fit photos, calendar events, mood and wear history are never included. Removing or changing a partner revokes previous sharing.

Photos

Wardrobe photos and completed try-on results are stored privately. HEIC conversion runs on your device before upload. A person photo used for Try On is sent for that request but not added to your Closet Muse library. New three-angle body-fit captures are unavailable; any older captures can be reviewed and deleted in Profile. No automatic body measurements or interactive 3D model are generated.

Service providers

Closet Muse uses Render for hosting, Stripe for payments and SendGrid for account email. Requested weather uses MET Norway. Optional Calendar uses Google; notifications use the push service supplied by your browser or device. Photo identification, try-on and approved retailer search use the configured providers described below. Provider processing is governed by each provider’s own terms and retention practices.

Optional garment identification

Only after you choose Agree & identify photo is that clothing photo sent to the configured vision service, such as Google Gemini. Suggested details need your review; they do not verify brands, retailers, materials, sizes or authenticity. Manual entry does not send a photo for identification.

AI photo try-on

With your explicit consent, your selected person and clothing photos are sent to FASHN under its data-retention policy. Completed previews are saved privately so you can revisit them. You can delete individual previews. Account deletion removes your saved results, request metadata and member usage records held by Closet Muse. Anonymous monthly credit totals remain for spending limits, without your email identifier, request identifiers or individual generation dates.

Optional local weather

You can choose a city or request approximate device location. City searches use a city directory hosted by Closet Muse; search text is not sent to a geocoding provider but may appear in our request logs. Only when you select a city or request device weather are rounded coordinates sent through our server to MET Norway. Your choice stays in memory for this page visit, not in your account profile or browser storage. Coordinates may appear in request logs and a temporary forecast cache. Forecasts expire, and Clear weather removes the current forecast and its styling context. Browser settings control device-location permission.

Shopping suggestions

When an approved catalog is connected, your product search words are sent to that catalog provider. Closet Muse ranks returned products against your wardrobe, budget and the optional occasion, saved plan and current weather you choose. Your wardrobe, plan details, weather and wear history are not included in the catalog request. Initial style choices and, only while Style Memory is enabled, confirmed wear preferences can affect ranking. These are suggestions, not verified fit, availability or suitability guarantees.

Optional device reminders

After you enable reminders on a device, we store its push-service endpoint and encryption keys, your reminder choices, time zone and delivery metadata. Delivery metadata is kept for seven days. Browser push services deliver encrypted, generic messages: no event titles, garments, photos, health, location or payment details appear in the message or on the lock screen. Daily and saved-plan reminders are best effort; device settings, network availability and service interruptions can delay or prevent them.

You can turn off a device or save a pause across your account in Display & notifications. Account deletion removes push records. A message already in transit may still arrive. Turn off reminders before handing a shared device to someone else. The service worker does not cache private pages, API records or photos, and a reminder opens the normal sign-in-protected app.

Recovery snapshots

Recovery is off until you enable it in Profile. It retains up to seven snapshots of wardrobe details, wishlist, plans, boards and packing lists for seven days. Deleted record details can remain until expiry or erasure. Photos, fit captures, credentials and learned preferences are excluded. Restoring records does not restore erased learning. Turning recovery off or deleting your account removes hosted snapshots. These snapshots share the hosting disk and are not an independent disaster-recovery backup.

Service alerts

Account-scoped diagnostics record feature categories, counts and times, without stack traces, photos or private notes. Optional service email requires separate consent and uses SendGrid to send to your sign-in address. Attempts are limited to once every six hours; checks run while the app is open. Open and click tracking are disabled.

Administrative access

Platform operators can access hosting infrastructure and private backups to maintain the service. Backups must be stored securely. Gift Circle permissions never grant administrative access.

Your choices

You can pause or erase learning, export account records, revoke Gift Circle access, delete photos and try-on results, and permanently delete a standard member account from Profile. Read about automatic learning. Subscription and pending-checkout checks run before account deletion. Limited infrastructure or provider logs may remain for their normal security, legal and operational retention periods.

Contact

Contact owner@closetmuse.ca for privacy questions or assistance with reserved accounts.

Return to Closet Muse