Closet Theory
Privacy Policy.
Version 2026-07-23
The short version
We collect what we need to style you well, encrypt sensitive things, never sell your data, and let you walk away with a copy at any time. The longer version below covers each piece.
Who we are
Closet Theory is a product of Trivora Dynamics Private Limited (CIN U47110MH2025PTC457934), a company incorporated in India under the Companies Act, 2013, with its registered office at Floor 3, A Block, Shivsagar Estate, Dr Annie Besant Road, Worli, Mumbai, Maharashtra 400018, India. We are the data fiduciary (DPDPA) and controller (GDPR) for the personal data described here. Reach us at team@closettheory.co or +91 96066 64267.
What we collect
From you, directly:
- Account details: name, email, password (hashed), date of birth (optional), city, zone.
- Body data: two photos of you, height, weight, age, and the measurements + body-shape derived from them via our scan provider. Stored encrypted at rest.
- Wardrobe data: photos of your garments and the attributes we infer (category, colour, fabric, fit).
- Preferences: aesthetic leanings, fits you love or avoid, occasion mix, palette preferences.
- Personal context (optional): your city for weather, your calendar for what’s on this week, your weekly plan. You control these per-feature.
- Conversations: chats with our styling assistant Closet Theory and outfit feedback you give.
- Payment data (Shop orders): when you buy something through the Shopping tab, our payment gateway partner collects your card, UPI, or bank details directly — we receive only the order amount, a transaction reference, and its status, never your full card or account number.
From your device, automatically:
- Sign-in session cookies (strictly necessary).
- Basic device + diagnostic information so we can fix bugs and detect abuse. We hash IP addresses before storing them.
What we do with it
- Run the service: build your digital twin, recommend outfits, catalogue your wardrobe, talk with you through Closet Theory.
- Personal-colour analysis: we send your scan photo to a vision model to extract a palette that flatters you. The result is stored; the photo is not retained by the model provider.
- Photoreal portrait: if you opt to generate one, we send your scan photos to an image model to produce a styled portrait. Again, no retention by the model provider.
- Safety and integrity: detect and prevent fraud, abuse, and security incidents.
- Improving the product: only if you opt in to the “Help us improve recommendations” setting. Otherwise, your content is not used to train models.
Legal bases
We rely on:
- Performance of the contract you accept when you sign up.
- Your explicit consent for sensitive uses (body photos, training data, marketing).
- Legitimate interests where they don’t override your rights — e.g. fraud prevention, system security.
- Compliance with applicable law.
Who sees your data
No advertisers, no data brokers. We use a small set of processors strictly to run the service:
- Cloud hosting and database (Supabase, Vercel).
- Body-scanning provider for measurements + the OBJ mesh.
- AI providers for colour analysis, photoreal portrait, and the styling assistant.
- Storage provider for your encrypted photos and avatar files.
- Payment gateway for processing Shop orders and subscriptions — PCI-DSS compliant; we never receive or store your full card details.
- Optional, with consent: calendar provider for your weekly plan.
Each processor is bound by a written data-processing agreement that forbids using your data for their own purposes.
How long we keep it
- Account data: while your account is active, plus 30 days after you delete.
- Scan photos: while your account is active. Deleted on request or account closure.
- Garment photos: while active in your wardrobe.
- Conversation history: 24 months rolling, unless you delete sooner.
- Consent and access audit logs: 36 months, for legal compliance.
- Order and payment records: 8 years, as required under Indian tax and company law.
Your rights
You can:
- Download a copy of your data — Profile · Privacy → Download my data.
- Correct or update what we hold — most of it is editable in-app.
- Withdraw a consent at any time — toggles in Profile · Privacy.
- Delete your account — Profile · Privacy → Delete my account.
- Object to a specific use of your data by writing to us.
- Complain to the Data Protection Board of India or your local supervisory authority.
Security
We encrypt PII (name, phone, email, address) and sensitive blobs at the application layer with AES-256-GCM before they reach the database. All connections are over TLS. Row-Level Security restricts data access to the owning member. Staff access is least-privilege and audited.
Children
Closet Theory is not directed at children under sixteen. We do not knowingly collect data from them. If you believe we have, write to us and we will delete it.
Changes
When this policy materially changes, we’ll tell you in-app or by email and ask you to accept the new version before continuing to use the service.
Contact
team@closettheory.co or +91 96066 64267 — for any privacy question or right-exercise request. Full company details and grievance redressal are on our Contact page.