← Back to OUTFIT ENVY

PRIVACY AND DATA USE

What we use, and why

OUTFIT ENVY uses the photo you choose and the clothes reference you choose to make a clothing swap. The photos are sent only when you ask us to prepare or create that clothing swap.

Your account

When you create an account, we keep your name, email address, a protected password verifier when you choose password sign-in, sign-in sessions, account status, credit activity, and your chosen background material. If you choose Apple or Google sign-in, we also keep the provider name, that provider's account identifier for OUTFIT ENVY, and the verified email the provider supplies. For Apple sign-in, we keep an encrypted refresh credential so we can revoke the Apple connection when you disconnect it or delete your account, plus Apple's latest reported status for private-email forwarding so we do not send account mail to a disabled relay address. We use these details to let you sign in, connect only the provider account you approve, keep account choices together across your signed-in devices, protect your account, and help with support when you ask. We do not keep the raw Apple or Google identity token, Apple authorization code, or raw Apple refresh credential. We also keep the minimum non-image record of completed requests and repeated user-correctable photo errors. If you ask to reset your password or request an emailed deletion link, we keep only a protected hash of the one-time token until it expires, is replaced, or is used. Password-reset security-event timestamps contain no token.

Your photos and clothing swaps

Your chosen photos are processed by our clothing swap service and OpenAI to identify the intended person and clothing reference and make the image. We keep the created image and its two original input photos together in a private, account-bound record for up to 3 days. Recent shows you only the created image. You can delete a saved image sooner, and deleting your account removes any remaining service copy. If you choose Photo refund in Help, you select one created image from Recent. That places the private three-photo set into an owner-only review queue; the input photos are never shown in the customer app. A refund request does not automatically change credits. Standard support staff cannot browse photos; an authorized owner can open a submitted request, and every review is logged. If you use Take Photo in the Android app, the phone keeps a temporary private camera file only long enough to attach it and schedules deletion within 15 minutes.

OpenAI has its own documented API data controls. Its standard abuse-monitoring records can retain API content and related metadata for up to 30 days in some circumstances. If OpenAI’s automated safety systems flag a possible serious safety issue, it may keep a photo for manual review under its own rules. We do not promise that another service has no retention when its published policy says otherwise.

Credits and purchases

Store purchases are not enabled until the release configuration is complete. When they are enabled, we keep the minimum protected purchase and notification record needed to put valid credits on the right account, restore them after a device change, and handle a store refund or revocation. Account shows you a short list of your own confirmed credit activity, but your App Store or Google Play receipt stays with that store. A normal clothing swap costs 1 credit. The first two user-correctable photo errors are free; later repeated user-correctable errors in the same rolling day can use one credit. An image-provider content-policy block creates no image and does not return the credit used for that request. We do not keep the raw store purchase token in your account record.

Support access

Authorized support staff can search an account by name to help with account, credit, deletion, and clothing swap status questions. Their lookups are recorded. The support console does not show your password, session token, provider key, or full store payment token. Standard support account lookups do not show photos; only the authorized owner can open a submitted Photo refund request under the three-day policy. Use Email support in Help if you need assistance with a completed image.

Delete your account

You can delete your account from Account in the app, or use the web account deletion page. The web page accepts an existing password or emails a one-time link to the account address, including for Apple- or Google-only accounts. The deletion link expires after 15 minutes, can be used once, is stored only as a protected hash, and still requires an explicit final deletion confirmation. We immediately revoke OUTFIT ENVY sign-ins and erase your name, email, password verifier, linked Apple or Google identity record, saved photos, and the platform account identifiers used to connect purchases to your profile. When Apple sign-in is connected, we attempt to revoke that provider authorization after deletion is confirmed. Your local account data is still erased if Apple is unavailable, the encrypted refresh credential is not retained for a retry, and the confirmation tells you how to stop using OUTFIT ENVY in Apple Account settings when manual action is needed. We keep only the minimum opaque financial and audit record required for secure reconciliation, if one is required.

Privacy questions

For privacy questions, contact support@theoryofpositiveexistence.com.

Before release

This policy is the in-app development disclosure. A production release requires an owner-published privacy-policy URL, a support contact, accurate Apple privacy answers, accurate Google Data Safety answers, and a review of every active data recipient and retention setting.