Privacy Policy
Effective Date: 2026-07-10 · Last Updated: 2026-07-10
Cloura Team ("we", "our", "us", or "Cloura") operates the Cloura mobile application for iOS and Android (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.
By using the Service, you agree to this Privacy Policy, our Terms of Service, and any other relevant documentation. If you do not agree, please stop using the Service.
1. Information We Collect
We collect information you provide directly and information generated through your use of the Service:
- Account Information: Email address, display name, and authentication credentials. If you sign in with Apple or Google, we receive your name and email as authorized by you (including Apple's private relay address if you choose to hide your email).
- Clothing Photos: Photos you upload of clothing items for your digital wardrobe. Photos are stored in encrypted cloud storage and are never shared with other users without your explicit action. EXIF GPS coordinates are stripped on upload.
- Style & Profile Data: Display name, gender (optional), style preferences, and body measurements (optional). This powers personalized outfit recommendations.
- AI Chat Data: Messages you send to the AI stylist and its responses, stored to maintain conversation history and context.
- Wardrobe Data: Clothing item details including AI-inferred attributes (category, color, style tags) and notes you add.
- Subscription Data: Subscription tier, purchase and renewal dates, trial status, and transaction verification data received from Apple's App Store or Google Play via RevenueCat. We do not receive or store your payment card details — all billing is handled by the platform.
- Device Information: Device type, OS version, app version, language/region settings, and push notification token (if enabled).
- Log & Diagnostic Information: IP address (used for coarse country-level identification and fraud prevention, not precise location), crash logs, and performance metrics.
What we do NOT collect
- Precise GPS location. We do not request location permission.
- Contacts, SMS, call logs, microphone, or background camera access.
- Persistent hardware identifiers (IMEI, MAC, IDFA, Android Advertising ID).
- Email content or email-inbox integration. We do not connect to your email account.
2. How We Use Your Information
We use your information exclusively to provide, secure, and improve the Service:
- Register and authenticate your account
- Identify and classify clothing items you upload
- Generate personalized outfit recommendations
- Power the AI stylist chat with context about your wardrobe and previous conversations
- Maintain your conversation and outfit history
- Process and verify subscription purchases via Apple's App Store or Google Play
- Send service-related notifications and optional daily styling reminders (only if you opt in)
- Detect and prevent fraud, abuse, and security incidents
- Diagnose crashes and improve reliability
We do NOT:
- Sell, rent, or trade your personal information to any third party
- Use your photos or chat content to train any general-purpose foundation model
- Use your data for cross-context behavioral advertising
- Share your wardrobe content with other users without your explicit action
3. AI-Generated Content Disclosure
The Service uses third-party AI models to provide its core features:
- Clothing Image Recognition: When you upload a clothing photo, the image is sent to Google Gemini to identify category, color, and style. Images are not retained by the provider after the request and are not used to train its foundation models.
- AI Stylist Chat: Your chat messages and relevant wardrobe context are sent to Google Gemini (Gemini 2.5 Flash) to generate recommendations. Same retention and no-training conditions apply.
- Output is informational only. AI Output is an AI-generated suggestion, not professional advice, and may be inaccurate or unsuitable for your context. You are solely responsible for decisions you make based on it.
4. Data Sharing & Third-Party Service Providers
We do not sell, rent, or trade your personal information. We share data only with the service providers below, each bound by a data-processing agreement:
| Provider | Purpose | Data shared |
| Railway (hosting + database) | App hosting, database, file storage | All user data |
| Cloudflare (R2 storage + CDN) | Image storage and delivery | Clothing photos |
| Google Gemini | Image recognition & outfit generation | Clothing photos, chat messages, wardrobe context |
| RevenueCat | Subscription lifecycle management | Anonymous user ID, subscription events, device model |
| Apple Inc. | Sign in with Apple, App Store purchases | Apple ID token, transaction events |
| Google LLC | Sign in with Google, Play Billing | Google account basic profile, transaction events |
| Apple Push / Firebase Cloud Messaging | Push notification delivery | Push token, notification payload |
We may also disclose personal information when you consent, when required by valid legal process, or in a business reorganization (merger, acquisition, or asset sale), in which case the successor will be bound by an equivalent policy.
5. Data Retention & Deletion
| Data type | Retention period |
| Account profile (email, display name) | While active; 30 days after deletion, then erased |
| Wardrobe photos and items | While active or until you delete them; 30 days from active storage, 60 days from backups |
| AI chat history | Until you delete it, or up to 12 months |
| Subscription and transaction records | 5 years (tax / accounting / consumer-protection law) |
| Login and security logs | 180 days (up to 2 years for incident investigations) |
| Email verification codes | 10 minutes, invalidated after use |
Account deletion
You can delete your account at any time from Settings → Account → Delete Account or by emailing cloura.support@gmail.com. Deletion removes your profile, wardrobe, photos, AI chat history, and preferences from active storage immediately; backups are purged within 30 days. Some records may be retained where required by law.
6. Your Rights & Choices
You can exercise the following through in-app controls or by contacting cloura.support@gmail.com:
- Access — view the data we hold and request an exportable copy (JSON)
- Correction — update inaccurate data via in-app Settings
- Deletion — delete individual items, your chat history, or your entire account
- Withdraw consent — revoke consent for marketing or optional features at any time
- Notifications — manage push notifications via your device's OS settings
California (CCPA / CPRA)
If you are a California resident, you have the right to know, delete, and correct your personal information, and to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, email cloura.support@gmail.com with the subject "CCPA Request"; we respond within 45 days.
Mainland China (PIPL)
If you reside in mainland China, you have the right to be informed, to decide, to restrict or refuse processing, to portability, and to deletion of your personal information.
7. Data Security
- Encryption in transit: TLS 1.2+ for all network traffic
- Encryption at rest for stored data; credentials hashed
- Access controls: least-privilege, audit logging
- Rate limiting on public API endpoints
- Token-based authentication: short-lived access tokens, rotating refresh tokens
No online service is 100% secure. Protect your account with a strong, unique password and device-level biometric/passcode protection.
8. Children's Privacy
The Service is not intended for children under 13 (or under 16 in jurisdictions setting a higher digital-consent age). We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided us with personal information, contact cloura.support@gmail.com and we will promptly delete it.
9. Cookies & Similar Technologies
The Cloura mobile app is a native application and does not use web cookies. We use local device storage (e.g. SharedPreferences, NSUserDefaults) to save your login token, consent version, and preferences, and JWT session tokens for authentication. Uninstalling the app or clearing its data removes this local data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date reflects the latest revision. Material changes will be communicated through in-app notice, push notification, or email in advance, and your renewed consent will be requested where required by law. Continued use after the effective date constitutes acceptance.
11. Contact Us
- Operator: Cloura Team (individual developer)
- Governing law: laws of the People's Republic of China (mainland)
- Email: cloura.support@gmail.com
- In-app: Settings → Help & Feedback
We aim to respond to all privacy inquiries within 30 days.