Stailas← Back home

Privacy Policy

Last updated: August 25, 2026

Stailas exists so you can understand your own wardrobe — not so anyone else can. This policy explains, in plain language, what data we collect, why, who touches it, and the rights you have over it. It applies to the Stailas app, website and the Stailas Cam.

1.Who we are

The service is operated by Stailas Inc., a Delaware corporation (registered office: 1111B S. Governors Ave., Suite 39276, Dover, DE 19904, USA; studio: 136 Madison Ave., 5th Floor, New York, NY 10016, USA). For data protection law (including the EU and UK GDPR), Stailas Inc. is the data controller of the personal data described here.

Questions, requests or complaints: lookinggood@stailas.com or our contact form.

2.What we collect

  • Subscription data — a random billing customer identifier, current plan and entitlement status. RevenueCat and the payment provider retain the transaction, billing email and payment details; Stailas does not receive or store your full card number.
  • Account data — your name, email address and a hashed password (we can never see the password itself).
  • Stailas Cam availability interest — if you ask to be notified, we store the email address you submit, your language preference and, when the submitted address matches a signed-in account, a link to that account.
  • Camera preorder data — when you preorder, Stripe collects your email, name, billing and delivery details and payment information. Stailas stores the contact and shipping details, order reference, payment status, amounts, accepted terms version and fulfillment history needed to administer the order. Stripe receives card details directly; Stailas does not store your full card number.
  • To provide and administer Stailas Pro — checkout, entitlement checks, renewals, cancellation and customer support. Legal basis: performance of our contract with you and compliance with accounting and tax obligations.
  • Outfit photos — the pictures you take of your daily looks, via the app or a Stailas Cam, with their timestamps. These are photos of you, and we treat them as the most sensitive thing we hold.
  • RevenueCat (USA) — cross-platform subscription entitlements and billing lifecycle.
  • Stripe (USA and applicable regional entities) — web payment processing, subscription management, fraud prevention and tax calculation where enabled. Stripe receives payment details directly.
  • Derived wardrobe data — what our AI produces from your photos: background-removed cutouts, colour palettes, style/season tags and a catalogue of individual garments.
  • Style Profile choices — life settings, visual clothing foundations, presentation intentions, colour energy and feedback that you deliberately give us. We use these to personalise suggestions and form revisable beliefs that you can correct; we do not use them for advertising.
  • Optional Google Calendar context — if you connect it, Stailas reads event titles, times and attendee counts to show your day and improve outfit suggestions. Events are read from Google when needed and are not copied into our database. We store an encrypted connection token and only the schedule-style preferences you explicitly save.
  • Device data — if you use a Stailas Cam, its device identifier and which account slots it is linked to; on the native app, a push notification token if you enable notifications.
  • Technical data — IP address and basic request metadata, used only for security (rate-limiting, abuse prevention, signup alerts). Our rate-limiting logs are automatically deleted within about a day.
  • Weather location — an approximate city-level location inferred from your request, or a location you deliberately share or search for, to show weather alongside outfits and wardrobe suggestions. Shared coordinates are rounded before storage. You can use New York City as the fallback instead, and we do not use weather location for advertising.
  • Diagnostics and performance data — privacy-scrubbed crash reports, stack traces and sampled performance timings help us find and fix reliability problems. We configure Sentry not to collect user profiles, cookies, request or response headers and bodies, URL query parameters, database query data, or AI inputs and outputs.
  • Optional product analytics — if you allow it, Google Analytics for Firebase receives pseudonymous app/device identifiers, screens and a small activation sequence such as sign-up and first-outfit completion. Advertising identifiers and ad personalization are disabled; we do not send Google your email, name, photos or wardrobe contents.
  • Messages you send us — if you use the contact form, the name, email and message you submit.
  • Email delivery — for onboarding messages, we record basic delivery state such as delivered, bounced, complained or suppressed so we can stop sending to an invalid address or someone who does not want the messages. We do not enable invisible open pixels or tracked links for these messages without first giving you a separate choice.

We do not collect contacts, browsing history or outfit-photo data for advertising. Location is used only when needed for wardrobe weather and is reduced to an approximate area before storage. We run no third-party advertising tracker inside the signed-in wardrobe app. On public acquisition funnels, TikTok Pixel, Reddit Pixel or Pinterest Tag runs only after you choose “Allow measurement” for the attributed channel and records page visits and selected funnel milestones. Stailas does not send those platforms your answers, email address, name, password or outfit photo. Pinterest enhanced matching is disabled. Onboarding is tailored using the product steps you actually complete, not by silently monitoring whether you read an email.

3.Why we use it (and our legal basis)

  • To run the service — storing your photos, building your style log, wardrobe catalogue and editable Style Worlds. Legal basis: performance of our contract with you.
  • To keep accounts safe — login throttling, abuse prevention, security notifications. Legal basis: our legitimate interest in a secure service.
  • To provide calendar-aware suggestions — only when you choose to connect Google Calendar, we use read-only event context to show your day, recognize repeated lunch or dinner patterns and offer preferences for you to approve. Legal basis: performance of our contract with you; you can disconnect at any time.
  • To communicate — required transactional email such as password resets and account-deletion confirmations, plus a short onboarding sequence tied to the product steps you complete. Required messages are necessary to perform our contract; onboarding and its limited engagement delivery processing rely on our legitimate interest in helping users understand the service without sending irrelevant reminders. Every onboarding message includes an opt-out.
  • Product updates and promotional email — these are separate from onboarding and are off by default. We send them only when you explicitly opt in, and you can withdraw that consent at any time.
  • Stailas Cam availability — if you select “Notify me”, we use the submitted address to tell you when the Cam becomes available. Legal basis: your consent. This does not place an order or opt you into unrelated promotional email.
  • Camera preorders — to take payment, confirm and fulfill the order, handle cancellations, refunds, returns, fraud prevention, support, accounting and tax records. Legal basis: performance of our contractand compliance with legal obligations.
  • Paid-acquisition measurement — on the public test funnels, the attributed TikTok, Reddit or Pinterest measurement tag records visits and a small set of conversion milestones only after explicit consent. Legal basis: consent. Refusing or withdrawing consent does not affect access to the funnel or service.
  • Cross-platform product analytics — Google Analytics for Firebase measures the same privacy-limited activation milestones on web, iOS and Android only after you allow product analytics. Legal basis: your consent. You can disable optional measurement from this Privacy Policy without losing access to Stailas.

We do not sell your personal data. We use consented acquisition measurements to understand campaign performance, not to advertise outfit photos, profile answers or account details. If we ever want to use your data for something new that needs consent, we will ask first.

4.How AI processes your photos

This is the part most people ask about, so here it is precisely. When a photo lands in your account, two things happen:

  • Background removal runs on our own servers using an open-source model — the photo does not leave our infrastructure for this step. (If our local model fails, an optional fallback to the remove.bg API may be used, only when configured.)
  • Outfit analysis — the clothing cutout is sent to Anthropic (the AI provider behind Claude) to identify garments, colours, styles and seasons and to assign the limited profile-photo suitability score described below. Under Anthropic's commercial API terms, this data is not used to train their models.
  • Garment catalogue images — after a new garment is detected, its individual source crop (not the whole outfit unless the crop itself contains it) is sent to OpenAI to create a clean, body-neutral ecommerce-style image. The original crop remains stored and available in garment detail. This phase does not build a body profile or provide virtual try-on. Under OpenAI's business/API data controls, API data is not used to train models by default.

Stailas does not perform facial recognition, identify people, compare faces, or build biometric identifiers. To choose a small profile avatar, the existing outfit-analysis step may assign a bounded photo-suitability score based only on whether a face is visible, frontal, looking toward the camera, sharp and evenly lit. It does not infer attractiveness, emotion, health, ethnicity, gender, age, or personal traits. The score is account-private and stored with the rest of the outfit analysis.

If a photo contains several people whose outfits are visible, Stailas may store anonymous rectangular regions long enough to ask which outfit you want scanned. These regions are not compared with other photos and are not used to identify anyone.

5.Who we share data with

We share personal data only with the service providers (processors) that host and power Stailas, under contracts limiting them to processing on our instructions:

  • Vercel (USA) — application hosting.
  • Neon (USA) — our database.
  • Cloudinary (USA/Israel) — image storage and delivery.
  • Anthropic (USA) — AI outfit analysis, as described above.
  • OpenAI (USA) — body-neutral garment catalogue image generation, as described above.
  • Resend (USA) — transactional and onboarding email, including delivery, bounce, complaint and suppression events.
  • Sentry (USA) — privacy-scrubbed crash reporting and sampled performance diagnostics, as described above.
  • Google Analytics for Firebase (USA and other locations described by Google) — consented, pseudonymous product usage and activation measurement across web, iOS and Android. Advertising identifiers and ad personalization are disabled.
  • Google Calendar API (USA and other locations described by Google) — if you connect it, Google supplies the read-only events you ask Stailas to use. Stailas does not add, edit or delete Google Calendar events.
  • remove.bg / Kaleido (Austria) — optional background-removal fallback, only if enabled.
  • Apple Weather and Apple Maps (USA and other locations described by Apple) — historical/current weather and place search when you use wardrobe weather. We send approximate coordinates or the place query you enter, not your Stailas account identity or outfit photo.
  • TikTok (USA and other locations described in TikTok's privacy documentation) — consented measurement of public acquisition-funnel visits and selected conversion milestones.
  • Pinterest (USA and other locations described in Pinterest's privacy documentation) — consented measurement of Pinterest-attributed public funnel visits, completed outfit results and account creation. Enhanced matching is disabled.

Our marketing pages embed a Google Maps office locator and link to Instagram; loading those pages causes your browser to make requests to Google, which has its own privacy policy. The app itself embeds neither.

Beyond providers: we would disclose data if the law genuinely required it, or as part of a merger/acquisition (in which case this policy still binds the data). No one else.

6.International transfers

Stailas is operated from the United States and our providers process data there. If you use Stailas from the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the US. Where GDPR applies, we rely on the European Commission's Standard Contractual Clauses (and equivalent UK/Swiss safeguards) built into our providers' data processing agreements, along with the security measures described below.

7.Cookies

The app uses a single strictly-necessary session cookie (httpOnly) to keep you signed in. Because it is essential to provide the service you asked for, it does not require consent.

The one-time measurement prompt stores your optional cross-platform product-analytics choice under stailas_google_analytics_consent. Firebase Analytics remains off until you choose “Allow”. The prompt disappears after either answer and is never shown inside a signed-in account.

On /test/1–3, the one-time measurement prompt asks before loading TikTok Pixel. Your choice is stored in your browser under stailas_tiktok_tracking_consent. If you allow measurement, TikTok may set or read advertising measurement identifiers according to its own policy. Third-party embeds on marketing pages, such as Google Maps, are governed by the provider's policy.

When you arrive through a tagged Reddit ad, the same choice applies before loading Reddit Pixel. It is stored under stailas_reddit_tracking_consent. If allowed, Reddit receives page visits, successful account creation and a custom FirstOutfitUpload event during that attributed browser session. Stailas does not send Reddit your email, name, password, outfit photos or wardrobe details, and Reddit's automatic email and phone matching are disabled in the Stailas business account.

You can withdraw all optional measurement permission here without keeping a cookie control on every page.

In the iOS app, Apple's AdServices framework may tell Stailas that an install or re-download was attributed to an Apple Ads campaign. Stailas keeps only the campaign, ad group, keyword, ad, conversion and country identifiers Apple returns and joins them to product activation events such as the first outfit. This attribution does not include your Apple ID, email, photos or wardrobe details and does not use App Tracking Transparency permission.

8.How long we keep data — and the 30-day deletion window

We keep your data for as long as your account exists, because the product is your accumulated wardrobe history. When you delete your account (Settings → Account → Delete account):

  • Your account is deactivated immediately and signed out everywhere.
  • For 30 days nothing is erased, so you can change your mind — signing back in restores everything.
  • After 30 days, everything is permanently erased: your account record, photos, wardrobe data, and the underlying image files in our image storage. This cannot be undone.

Individual photos and garments you delete in-app are removed — including the stored image files — right away, with no grace period. Security logs (IP rate-limiting) expire within about a day on their own.

Disconnecting Google Calendar revokes the connection and deletes the encrypted token and saved calendar preferences. Because raw event copies are not stored, there is no separate Stailas event history to delete.

A Stailas Cam waitlist address is kept until we send the availability notice, you ask us to remove it, or two years pass after your latest request — whichever happens first. You can request removal at any time using the contact address below.

Camera preorder and transaction records are kept for fulfillment, support, accounting, tax and legal-retention periods even if you do not create a Stailas account; payment-card data remains with Stripe.

9.Your rights

Wherever you live, you can:

  • Access your data — your photos and wardrobe are always visible and downloadable in the app, and you can ask us for a copy of everything else.
  • Correct it — name, email and password are editable in Settings; analysis tags can be edited in the app.
  • Delete it — self-service, as described above.

If you are in the EEA, UK or Switzerland, you additionally have the rights to data portability, to restrict or object to processing, to withdraw consent at any time, and to lodge a complaint with your local supervisory authority.

If you are a California resident, you have the rights to know, to delete, and to non-discrimination under the CCPA/CPRA. We do not sell or share personal information as those terms are defined there.

To exercise any right, email lookinggood@stailas.com. We respond within 30 days and may need to verify you control the account.

10.Security

All traffic is encrypted in transit (HTTPS). Passwords are stored only as salted hashes. Sessions use httpOnly cookies immune to script theft. Login and reset endpoints are rate-limited against guessing, password-reset links are single-use and expire within an hour, and sensitive account changes require your current password. No system is perfectly secure, but if a breach ever affects your data we will notify you and the relevant authorities as the law requires. Google Calendar refresh tokens are encrypted at rest with an application key that is not stored in the database.

11.Children

Stailas is not directed at children. You must be at least 13 to use it (16 where you live in the EEA, unless your parent or guardian consents). If we learn we hold an underage account, we will delete it.

12.Changes to this policy

If we change this policy in a way that matters — new data, new purpose, new recipient — we will update the date above and notify you by email or in-app before the change takes effect. Continuing to use Stailas after that means the updated policy applies.