version 1.2026.09.05 · last updated 5 September 2026
privacy policy
the short version
- klozt is a digital closet. You photograph clothes you own, klozt tags them, and it suggests an outfit each day.
- We collect your account details, your wardrobe photos and their tags, your outfit history, and, only if you allow it, your approximate location, used to fetch local weather.
- Each wardrobe photo is sent once to an AI vision service to guess the garment type and colour. The vendors, and what each does with the photo, are listed below.
- We do not run ads, sell data, use analytics or tracking SDKs, or do facial recognition.
- You can export or delete everything yourself from Profile → Privacy Center.
who we are
klozt is made and operated by its founder, an individual based in India, not a company ("klozt", "we", "us"). We will add the operator's full legal name and postal address here before klozt is released publicly on the app stores. For the purposes of:
- the Digital Personal Data Protection Act, 2023 (India) — we are the Data Fiduciary
- the General Data Protection Regulation (EU/UK) — we are the Controller
- the California Consumer Privacy Act / CPRA — we are the Business
Contact our privacy team at privacy@klozt.in. Under DPDP and the Information Technology Rules the founder acts as Grievance Officer, reachable at the same address with the subject line "grievance — DPDP".
what we collect
Account data. Your email address, display name, date of birth, which sign-in method you use (email and password, Google, or Apple), and the identifier Firebase Authentication assigns to you. If you sign in with Google or Apple, we receive the name and email address they share. We never see your password; Firebase handles it.
Date of birth. Used once at sign-up to check that you are 18 or older, then stored with your account. If the date shows you are under 18, we refuse the account and record that the sign-in identity is not age-verified, so it cannot try again with a different date.
Wardrobe photos and tags. The photos you add to your closet, plus the tags on each item: category, colour, occasion, season, weather, and any notes you add.
Outfit history. The outfits klozt suggested, whether you accepted or skipped them, and the items you mark as worn.
Approximate location. Only if you grant the app's location permission. The app asks for coarse (city-level) location and sends it with your daily-outfit request so we can look up the weather. We do not store it in our database; it stays in server memory, rounded to roughly a kilometre, for at most an hour to cache the weather result. Denying the permission is fine: the app falls back to a default city and the calendar season.
Consent records. Which consents you gave or withdrew, when, from which app version, together with a truncated IP address and your device's user-agent string.
Technical data. Our servers keep short-lived operational logs: timestamps, request paths, error messages, your device's user-agent string, and an IP address with the last part removed. There is no third-party analytics, advertising, or crash-reporting SDK in the app.
We do not collect precise location, contacts, biometrics, government identifiers, payment card details, or any information about race, religion, health, sexual orientation, or political views.
how we use it
| purpose | data | legal basis (GDPR) | DPDP ground |
|---|---|---|---|
| create and run your account | account data | contract (Art. 6(1)(b)) | §7(a) performance of service |
| check you are 18 or older | date of birth | legal obligation (Art. 6(1)(c)) | §9 |
| store your closet and show it across devices | wardrobe photos and tags | consent (Art. 6(1)(a)), the "store my wardrobe photos" consent | §6 consent |
| tag a garment's type and colour with an AI vision service | wardrobe photo | consent (Art. 6(1)(a)) | §6 consent |
| suggest a daily outfit | tags, outfit history, weather | contract | §7(a) |
| fetch local weather | approximate location | consent (the location permission) | §6 consent |
| keep the service secure and prevent abuse | technical data, consent records | legitimate interests (Art. 6(1)(f)) | §7(g) |
| answer your rights requests and support emails | account data, your message | legal obligation / contract | §7(a), §7(c) |
You can withdraw any consent in Profile → Privacy Center or by revoking the permission in your phone's settings. Withdrawal does not undo processing that already happened.
AI tagging of wardrobe photos
When you add a photo to your closet, klozt shrinks it to at most 1024 pixels on its longest side and sends it once to one AI vision service, which returns the garment's category and colour so you do not have to type them. Nothing else is sent with the photo: not your name, your email, or your other items.
We use free tiers of these services and try them in order. If one is out of quota or unavailable we try the next; if all are unavailable we estimate the dominant colour on our own server and ask you to fill in the rest yourself.
| service | operated by | where the photo is processed | what they say about your photo |
|---|---|---|---|
| Google Gemini API | Google LLC (United States) | Google data centres | On the free tier, Google may use inputs to improve its products and may have people review them. |
| Mistral AI API | Mistral AI (France, EU) | European Union | Not used to train models; the training option on our workspace is switched off. |
| Z.ai (GLM) | Zhipu AI (China) | Singapore, per their policy | Processed in real time and not stored, per their policy. |
The app also supports Groq and OpenRouter as fallbacks, but they are not enabled today. We will update this table before enabling either.
There is currently no per-account switch to turn AI tagging off. Until we add one, adding a photo means it will be sent to one of the services above. This is on our list; email privacy@klozt.in if it matters to you and we will prioritise it.
We never send your photos to any AI service for any purpose other than tagging that photo, and we do not use them to train any model of our own.
who we share with
We use these companies as processors. Each receives only what is listed.
- Firebase Authentication (Google LLC, United States) — signs you in, stores your email and sign-in credentials, sends password-reset emails, and handles Google and Apple sign-in.
- Render (Render Services, Inc., United States) — runs our API server and job queue in Oregon, United States. Everything you send the app passes through it.
- Neon (Neon, Inc., United States; our database is hosted in Singapore) — stores your account data, tags, outfit history, and consent records.
- Cloudflare R2 (Cloudflare, Inc., United States) — stores your wardrobe photos. The app fetches them through links that expire within minutes.
- OpenWeatherMap (OpenWeather Ltd, United Kingdom) — receives approximate coordinates and returns the weather. No account data is sent.
- The AI vision services in the table above — receive the wardrobe photo only.
- Apple App Store and Google Play — if you install klozt through them, they handle the download and any future subscription. We never see your payment card.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not share it with data brokers.
where your data lives
Our servers run in the United States (Render, Oregon) and our database in Singapore (Neon). Photos are stored with Cloudflare R2 in the Asia-Pacific region. The AI services process photos in the locations listed above.
For users in the EU/UK, transfers outside the EEA rely on the European Commission's Standard Contractual Clauses in each processor's data processing agreement. For DPDP purposes, we transfer data outside India only where the Government of India has not restricted it under §16.
how long we keep things
| data | how long |
|---|---|
| wardrobe photos and tags | until you delete the item or your account; the photo file is removed from storage on deletion and its database record is purged within 7 days |
| outfit history and wear log | until you delete your account |
| account data | until you delete your account, plus the 14-day grace period described below |
| consent records | while your account exists; deleted with it. A record that a deletion happened, without your identity, is kept for audit. |
| approximate location | never written to our database; server memory for at most 1 hour |
| server logs | no more than 30 days |
| sign-in sessions | 30 days, or until you sign out |
| data export archive | 7 days after we generate it |
your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you
- correct anything inaccurate
- delete your data (subject to legal retention exceptions)
- port your data in a machine-readable format
- withdraw consent at any time
- complain to your supervisory authority: the Data Protection Board of India under DPDP, your national data protection authority under GDPR, or the California Privacy Protection Agency under CCPA
- opt out of sale or sharing (CCPA) — klozt does not sell or share personal information for cross-context behavioural advertising
- non-discrimination — exercising a right never gets you worse service
You can exercise most of these yourself in Profile → Privacy Center. For anything else, email privacy@klozt.in. We respond within 30 days under GDPR and DPDP and 45 days under CCPA.
export and deletion
In Profile → Privacy Center you can:
- Request a copy of your data. We prepare a JSON archive of your account, closet tags, outfit history, and consent records, and give you a download link that stays valid for 7 days.
- Delete your account. This starts a 14-day grace period during which you can cancel from the same screen. After 14 days we permanently delete your photos, tags, outfit history, consent records, account, and your Firebase sign-in identity.
If you cannot open the app, email privacy@klozt.in from the address on your account and we will do the same for you. Step-by-step instructions are on the delete account page.
children
You must be 18 or older to use klozt. We do not knowingly collect data from anyone under 18, and the sign-up flow refuses accounts that give a date of birth under 18. If you believe a minor has created an account, email privacy@klozt.in and we will remove it.
The 18+ floor is deliberately above the GDPR minimum (13 to 16, depending on the country) and the CCPA minimum (13). Under DPDP §9, processing a child's data requires verifiable parental consent; we chose not to build that flow and to gate sign-up at 18 instead.
what we do not do with your photos
- no facial recognition, face matching, or biometric identification
- no attempt to infer race, ethnicity, religion, age, sex, sexual orientation, or any other protected characteristic
- no sharing of your photos with other users, brands, or advertisers
- no training of our own models on your photos
- no sending of your photos to any AI service except once, for tagging, as described above
security
- all traffic between the app and our servers uses TLS
- our database, photo storage, and backups are encrypted at rest by the providers listed above
- photos are only reachable through signed links that expire within minutes
- access to production systems is limited to the operator, protected by two-factor authentication, and logged by each provider
- if a breach affects you we will notify you and the relevant regulator within the legal timelines: 72 hours under GDPR Art. 33, and without delay under DPDP §8(6)
changes to this policy
When we change this policy in a way that matters to you (retention, sharing, a new processor, a new purpose) we will bump the version at the top, raise the app's consent version so you see a notice the next time you open klozt, and ask you to review what changed. We do not silently change retention or sharing.
contact
klozt is made and operated by its founder, an individual in India.
Grievance Officer: the founder, privacy@klozt.in (subject: "grievance — DPDP")