Outfit

Privacy Policy

Last updated 7 September 2026

Outfit is an AI travel stylist. It plans what to wear on a trip. This policy explains exactly what leaves your phone, who receives it, and what you can refuse without losing the app.

No account, and no profile of you

Outfit has no sign-up, no login and no password. We never ask for your name, email address or phone number. Your trips, plans, wardrobe photos and preferences are stored on your device, in the app's own storage. Deleting the app deletes them.

So that our server can apply fair-use limits and confirm whether you have a subscription, the app generates a random identifier the first time it runs and keeps it in the device keychain. It is not derived from your device's hardware, it is not shared with advertisers, and it identifies a device — not a person.

What is sent when you generate a plan

Generating a plan requires a server, because the stylist is a large language model. When you tap Generate outfits, and only then, the app sends to our proxy server, and our proxy forwards to Anthropic PBC (the provider of the Claude model that writes your plan):

What is sent when you photograph a garment

If — and only if — you add a piece to your wardrobe from a photo, the app sends that single photograph to our proxy, which forwards it to Anthropic so the model can describe the garment (its type, colour, material and warmth). Our proxy does not store the image: it passes it through and returns the description. Anthropic's own handling and retention of API data is governed by Anthropic's privacy policy and its commercial terms.

You are asked for permission before the first plan is generated and again before the first photo is sent. You can decline both and keep using Outfit — you can enter your wardrobe by hand, and the app still gives you weather, the packing list and everything stored on your device.

What is sent when you ask to see an outfit on yourself

“See it on me” is optional, is asked for one outfit at a time, and has its own permission — a picture of a person is not the same thing to send as a picture of a jumper, so agreeing to garment tagging does not agree to this.

When you ask for a render, the app sends the reference photograph of you and a description of the outfit to our proxy, which forwards them to Google (the Gemini image model) and returns the rendered picture. Our proxy does not keep a copy. Google’s handling is governed by the Gemini API terms and Google’s privacy policy. The reference photo is stored only on your device, is never included in a plan or a packing list, and can be deleted at any time from Profile.

Shop links

When Outfit shows a link to a retailer, that link may be wrapped so the shop knows the visit came from Outfit and we may earn a commission. Where that happens the link passes through Awin, an affiliate network, and the app says so beside the link.

What is passed is a coarse label naming the screen you tapped from — plan or gaps — and nothing else. Your device identifier is never sent to the affiliate network, and neither is your destination, your wardrobe or anything you typed.

Who else receives data

WhoWhat they getWhy
Anthropic PBCTrip details and preferences; a garment photo only when you add oneWrites the outfit plan and describes garments
Google LLCA photograph of you, and a description of one outfit — only when you ask for a render, and only after separate consentRenders “See it on me”
Awin LtdOnly that a visit came from Outfit, with a label naming the screen (plan or gaps). No device identifierAttributes a shop visit so we may earn a commission
RevenueCat, Inc.The random device identifier and your purchase receiptsManages subscriptions and restores purchases
AppleYour purchase; and the coordinates of the destination you searched, sent to Apple WeatherKitPayment, and the forecast
Vercel and UpstashThe requests above, and per-device countersHosting and fair-use limits
PostHog (EU servers)Named product events — a screen opened, a plan generated, a paywall shown — with the random device identifierShows us which parts of the app get used. Switch it off under Settings → Privacy

The PostHog integration carries no session replay and no automatic capture: it sends the events Outfit names in its own code and nothing else. It never receives a destination, a garment name, a photo, or any text you type.

We do not sell your data, we do not use it for advertising, and we do not track you across other companies' apps or websites. Outfit contains no advertising SDK and requests no tracking permission.

Location and photos

Outfit never asks for your device location. A destination is a place you type. Photo-library and camera access are used only for pictures you deliberately choose — the clothes you add to your wardrobe, and, if you use it, the one reference photograph for “See it on me”. Those images stay on your device apart from the two requests described above, each of which you are asked about separately and can refuse while continuing to use the app.

Weather

Forecasts come from Apple Weather. See Apple's weather data sources.

Children

Outfit is not directed at children under 13 and we do not knowingly collect their data.

Your rights

Because there is no account, the fastest way to erase everything is to delete the app. For anything held server-side against your device identifier — fair-use counters and subscription status — write to menan@titanix.dev and we will delete it. If you are in the EU or UK you have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your supervisory authority.

Changes

If this policy changes materially, the app will tell you before the change takes effect.