← Back to OUTFIT ENVY

PRIVACY AND DATA USE

What we use, and why

OUTFIT ENVY uses the photo you choose and the clothes reference you choose to make a clothing swap. The photos are sent only when you ask us to prepare or create that clothing swap.

Your account

When you create an account, we keep your name, email address, a protected password verifier, sign-in sessions, account status, credit activity, and your chosen background material. We use these details to let you sign in, keep account choices together across your signed-in devices, protect your account, and help with support when you ask. We also keep the minimum non-image record of completed requests and repeated user-correctable photo errors. If you ask to reset your password, we keep only a protected one-time reset-token hash and non-sensitive security-event timestamps until the token expires or is used.

Your photos and clothing swaps

Your chosen photos are processed by our clothing swap service and OpenAI to identify the intended person and clothing reference and make the image. We keep the created image and its two original input photos together in a private, account-bound record for up to 3 days. Recent shows you only the created image. You can delete a saved image sooner, and deleting your account removes any remaining service copy. If you choose Photo refund in Help, you select one created image from Recent. That places the private three-photo set into an owner-only review queue; the input photos are never shown in the customer app. A refund request does not automatically change credits. Standard support staff cannot browse photos; an authorized owner can open a submitted request, and every review is logged. If you use Take Photo in the Android app, the phone keeps a temporary private camera file only long enough to attach it and schedules deletion within 15 minutes.

OpenAI has its own documented API data controls. Its standard abuse-monitoring records can retain API content and related metadata for up to 30 days in some circumstances. If OpenAI’s automated safety systems flag a possible serious safety issue, it may keep a photo for manual review under its own rules. We do not promise that another service has no retention when its published policy says otherwise.

Credits and purchases

Store purchases are not enabled until the release configuration is complete. When they are enabled, we keep the minimum protected purchase and notification record needed to put valid credits on the right account, restore them after a device change, and handle a store refund or revocation. Account shows you a short list of your own confirmed credit activity, but your App Store or Google Play receipt stays with that store. A normal clothing swap costs 1 credit. The first two user-correctable photo errors are free; later repeated user-correctable errors in the same rolling day can use one credit. An image-provider content-policy block creates no image and does not return the credit used for that request. We do not keep the raw store purchase token in your account record.

Support access

Authorized support staff can search an account by name to help with account, credit, deletion, and clothing swap status questions. Their lookups are recorded. The support console does not show your password, session token, provider key, or full store payment token. Standard support account lookups do not show photos; only the authorized owner can open a submitted Photo refund request under the three-day policy. Use Email support in Help if you need assistance with a completed image.

Delete your account

You can delete your account from Account in the app, or use the web account deletion page. We immediately revoke sign-ins and erase your name, email, password verifier, saved photos, and the platform account identifiers used to connect purchases to your profile. We keep only the minimum opaque financial and audit record required for secure reconciliation, if one is required.

Privacy questions

For privacy questions, contact support@theoryofpositiveexistence.com.

Before release

This policy is the in-app development disclosure. A production release requires an owner-published privacy-policy URL, a support contact, accurate Apple privacy answers, accurate Google Data Safety answers, and a review of every active data recipient and retention setting.