Wellfolded is a wardrobe and outfit-planning app. This page lists what it collects, where that data lives, who else receives any of it, and how to have it deleted.
What is collected
| Data | Where it is stored | Who else sees it | How long it is kept |
|---|---|---|---|
| Stylist conversations | Your account | Google Gemini, to answer questions | Until you clear them or delete the account |
| Home city and trip destinations | Your chosen home place and trip itinerary | Open-Meteo for weather; Gemini for outfit ideas, Ask and trip plans you request | Until changed, or trip or account deletion |
| Receipts you choose to read | Confirmed details only; receipt never stored | Gemini, after consent, on request | Receipt discarded after the read; confirmed piece and price details until you delete them |
| Account email and password | Account; password only as a one-way hash | Resend, to deliver sign-in and deletion codes | Until you delete your account |
| Garment photos | Private object storage | Google Gemini, only for the garment finder or flat-lay tool | Until you delete the piece or its photo |
| Body and try-on photos, measurements | Photos in private object storage; measurements in your profile | Google Gemini: measurements as text, and with See it on you on, your reference photo with each render you ask for and nowhere else | Until replaced, deleted or account deletion |
| Color and undertone profile | Your profile record | None. Quiz and confirmed skin, hair and eye references are hex colors only; no photo is sent | Until changed or account deletion |
| Color selfie | Private object storage; the undertone, depth and contrast reading in your profile | Google Gemini, only after you allow its separate disclosure and ask for a read | Until you replace, delete or revoke it, or delete your account |
| Outfits, wear history, trips, occasions and recommendation feedback | Your account record; feedback keeps the piece, reason and bounded context | None | Until deleted or undone, or account deletion |
| Fragrance data, including a bottle photo | Account; photos in private object storage | None. A bottle photo is kept as taken and never sent anywhere | Until you delete the fragrance |
| Device location | Cached on this device so the weather card reopens without asking; never in your account | Open-Meteo and Nominatim | Until sign-out, account switch, deletion, or clearing app data |
| Outfit diary, diary photos, and lookbooks | Account; photos in private object storage | None unless you choose to add it to a private style-circle link | Until you delete it or your account; deleted photos are queued for object removal |
| Private style-circle packets and feedback | A snapshot in the app database, behind a random expiring link that alone serves its media | The people you give the link to see only that packet; feedback only if you allow it | Until expiry, revocation or account deletion |
| Product analytics events | Product analytics is off. The app records and sends no usage events. | None | None |
| Service cost records | The app database: which AI model ran for your request, how much work it did, and when. No photos, text or other content. | None | Kept to run the service and plan its costs. Deleting your account removes the link to you. |
| Beta requests, permissions and delivery records | App database; confirmation and invite links hashed, in queued mail until sent or canceled | Resend for access mail you request; Loops only with confirmed optional email permission | Unconfirmed requests 30 days; links 24 hours to confirm, 7 days for invitations, 180 days for preferences; delivery receipts and abuse-free measurement records 90 days; confirmed requests reviewed after 180 days. Account deletion removes linked contact and permission records |
| Tester feedback and lifecycle activity | The app database. All admitted testers see your alias, text, votes and staff replies; planning timestamps stay private | None for the board; Loops only gets bounded template links for updates you allow | Identifying text until you withdraw it or delete your account, which also removes votes; a minimal withdrawn or moderation record stays for board integrity. Lifecycle timestamps go with the account |
| Crash reports | Not stored in this app’s own database | Sentry | Governed by Sentry’s own retention |
| Retailer links pasted to import a product | Your account record; the fetched photo joins your garment photos | The retailer’s site, via our server | An unfinished import expires after 30 minutes; the photo follows garment-photo retention |
| Backups | Copies of the app database and photos on the app’s own server | None | Up to 30 days, then erased |
Who else receives data
These are the only outside services this app sends anything to.
- Google Gemini. Depending on the tool: garment and body photos, measurements as text, wardrobe text, plans, questions, home city, trip destinations and receipts you choose. It identifies garments, builds flat-lays, reads fit, renders try-on, suggests outfits, answers Ask, plans trips and reads receipts.
- The object storage backend. Every uploaded photo and try-on render, on local disk or in a private S3-compatible bucket. S3 photos are served only through short-lived signed links requested via this app’s server.
- Open-Meteo and OpenStreetMap Nominatim. Your device’s rounded coordinates, only while the weather card is open, for the outfit-planning forecast and a short place name.
- Sentry. An error type, message and small bounded context such as a screen name, never your email or free text, to fix crashes.
- A transactional email provider. Your email and a requested sign-in or deletion code, or a beta confirmation or invitation link. It is Resend, on separate access-mail and sign-in credentials, only when configured and explicitly enabled.
- Loops. Your confirmed email and fixed template links, only with optional email permission; never private wardrobe, feedback text, body or color details. It sends planning notes and feedback or return updates you choose; unsubscribing stops locally queued mail at once and asks Loops to suppress you.
- Retailer hosts. A request from our server for the product page or image at a link you paste. It reads a product’s title, brand and photo to speed up adding a piece.
What is never collected or sold
- No advertising software development kit is present in this app.
- No tracking or attribution software development kit is present in this app.
- No data is sold to anyone.
- Analytics events carry only a few fixed properties, never your email, a photo, a garment name, a measurement or free text.
Beta permissions and shared feedback
No marketing visitor tracking is on. Account admission never depends on analytics or email choices. Planning notes, feedback updates and return reminders each need separate email permission; the preferences link can space out or stop optional mail. Return reminders use only whether you filed an owned piece and saved a complete outfit, and when you last saved a plan; these facts stay local even if you decline analytics. A one-way email hash is kept to block unwanted re-enrollment; deletion and suppression requests to vendors retry until acknowledged.
Deleting an account
An account and everything it owns can be deleted two ways: Settings > Your data, or from the public deletion page without signing in. Deleting an account removes garment photos, body photos and measurements, the color profile, outfits and wear history, trips and occasions, and fragrance data, along with the account itself.
Contact
Questions about this policy can be sent to [email protected].