Privacy Policy
DRAFT — not reviewed by a lawyer. Lines marked ⚖️ need a lawyer's check before launch.
Effective date: October 1, 2026
Who we are: Cardrobe is run by Yu-Xin Wang, an individual based in Arizona, USA ("we", "us").
Contact: hello@cardrobe.app
Cardrobe is a place to post a photo of your outfit for each week's theme and give ⭐ to other people's fits. This policy explains, in plain English, what we collect, why, who helps us run the app, and how to delete your data.
Short version: we collect only what the app needs to work. We don't sell your data, we don't show ads, and deleting your account deletes your posts and photos.
1. What we collect
| What | Why |
|---|---|
| Your email address | To sign you in. We email you a one-time code; there's no password. |
| That you confirmed you're 13 or older, and when | Cardrobe is for people 13 and up (see section 6). Other users can't see this. |
| Your photos | To show your fit in the theme feed. See section 3 for exactly how photos are handled. |
| Your posts: which theme each photo was for, and when you posted | To show the feed and your Closet. |
| Your stars: which posts you starred | To show you which posts you've starred, and to show each poster their own star count. Only the person who posted can see how many stars a post has. |
| Reports you make: which post you reported, and when | So we can review posts that might break our Terms. The person you reported isn't told who reported them. |
| Blocks: who you blocked | So you and that person don't see each other's posts. |
| Usage events: when you sign up, post (with the theme and whether it's your first post), give a ⭐, or report a post | To understand how the app is used, for example how many people post each week. These events are linked to a random user ID, not your email, and never include photos. |
| Crash reports: what went wrong, your device model and system version, the app version | To find and fix bugs. Linked to the same random user ID, never your email. No screenshots. |
What we don't collect: your contacts, your precise location, your camera roll (you choose one photo at a time), or payment details. We don't collect a push-notification token, because reminders are scheduled on your phone (section 5).
2. Who helps us run the app
We use these services to run Cardrobe. They process your data only to provide their service to us.
| Service | What it does for us | What it receives |
|---|---|---|
| Supabase | Sign-in, database, and photo storage | Your email, photos, posts, stars, reports, blocks, the 13+ confirmation. Supabase may also log technical details such as IP addresses for security. ⚖️ |
| Resend | Sends the sign-in code email | Your email address and the code |
| PostHog | Usage analytics (section 1) | Usage events and your random user ID. We turn off location lookup from IP addresses. ⚖️ |
| Sentry | Crash reports (section 1) | Crash details, device model and system version, your random user ID |
- Data location: Supabase stores data in the United States (Supabase, West US region). PostHog and Sentry store data in the United States. ⚖️ If you have users outside the US (for example in the EU or UK), transfers to US services need a legal basis. Check which one applies.
- PostHog IP addresses: check that "discard client IP data" is actually turned on in PostHog before relying on the sentence above. ⚖️
We don't sell your personal information and we don't share it with advertisers.
3. How photos are handled
- Before upload, on your phone: your photo is resized (to at most 1080px wide) and re-saved as a new JPEG. This removes hidden photo data (EXIF), including GPS location, before the photo leaves your phone.
- Stored privately: photos are kept in private storage, not at public web addresses. The app shows a photo through a link that stops working after one hour.
- Who can see your photo: anyone signed in to Cardrobe can see your post in that theme's feed, except people you've blocked or who have blocked you. Posts reported by several people are hidden from everyone but you until we review them.
- Copies on your phone: the app keeps a copy of each photo you post on your phone for My Closet. That copy stays on your phone until you delete the post, delete your account, or delete the app.
- We don't use your photos for advertising, sell them, or use them to train AI models. ⚖️ Confirm this matches what the service providers are allowed to do under their terms.
4. How long we keep data, and how to delete it
- Deleting a post removes the post, its photo, and its stars right away.
- Deleting your account (Settings → Delete account) removes, right away:
- your photos
- your posts, stars, reports, and blocks
- your profile
- your sign-in account
- Backups: our database provider may keep backups for a limited time before they're overwritten. ⚖️ Check Supabase's backup retention for our plan and state the number of days.
- Analytics and crash reports: usage events and crash reports are kept for as long as PostHog and Sentry retain them under our settings. When you delete your account, we delete your analytics profile on request, and we're working on doing this automatically. ⚖️ State actual retention periods and the deletion process.
- Reports: reports are deleted with the reported post or with your account.
5. Notifications
If you turn on "New theme reminders", your phone schedules a reminder for when each new theme starts. These reminders are scheduled on your phone, so we don't receive a notification token or any data about them. You can turn them off anytime in your phone's Settings.
6. Age requirement: 13 and older
Cardrobe is only for people 13 and older. You must confirm you're 13 or older to sign in. If we learn that someone under 13 has an account, we'll delete it. If you believe a child under 13 is using Cardrobe, contact us at hello@cardrobe.app.
⚖️ Check the minimum age for every country where the app is available. Some countries require parental consent for users under 16. Also check US state laws on teen users and app store age checks.
7. Your choices and rights
You can:
- See your data: your posts are in My Closet.
- Delete a post, or your whole account, in the app.
- Turn reminders off in your phone's Settings.
- Contact us at hello@cardrobe.app to ask for a copy of your data, to correct it, or with any privacy question.
Depending on where you live, you may have more rights, such as objecting to certain processing or complaining to a data protection authority. ⚖️ List the applicable rights (e.g. GDPR, UK GDPR, CCPA/CPRA) and our legal basis for each use of data: contract, legitimate interests, or consent.
8. Security
We use access rules in our database so people can only change their own data, keep photos in private storage, and never put admin keys in the app. No system is perfectly secure, so please use an email account only you can access.
9. Changes
If we change this policy, we'll update the date at the top. If a change is significant, we'll also tell you in the app.
10. Contact
Questions? Email hello@cardrobe.app.