Indosso Privacy Policy
Effective Date: June 1, 2026
Last Updated: August 17, 2026
Indosso is operated by KSK Digital LLC, a Wisconsin limited liability company ("Indosso," "we," "us," or "our").
This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and what choices and rights you have. It works alongside our Terms of Use and Data & Memory Promise.
Indosso is a personal outfit assistant that helps you get dressed using clothing you already own. It does not sell products, run ads, use advertising networks, or profile users for marketing.
Your privacy matters because this app is built on trust — not surveillance.
1. Scope of This Policy
This Privacy Policy applies to the Indosso mobile application, website, account services, outfit generation, closet features, trip planning, packing features, weather-related features, and related services.
It does not apply to third-party websites, app stores, payment processors, operating systems, sign-in providers, weather providers, map and geocoding providers, or other services we do not control.
2. Minimum Data Collection Principle
We collect only what is reasonably needed to provide, secure, maintain, understand, and improve Indosso.
We do not collect data for advertising, data brokerage, or unrelated profiling. We do not collect information from outside Indosso to build profiles about you. We use limited analytics to understand how Indosso is used, measure referrals, maintain reliability, and improve the service. We do not use analytics to judge your clothing choices or create advertising profiles.
3. Our Privacy Promise
In plain language, here is what Indosso does and doesn't do with your information.
What we store about you
Your closet, saved outfits, confirmed wear history, trips, settings, and preference-related data — so the app remembers them across sessions and devices.
Your email and account identifiers — so you can sign in and keep your data synced.What we measure, and only if you agree
Indosso asks once whether you are willing to let us measure how the app is used. Until you answer, no analytics runs at all. If you say no, no analytics runs and nothing about the app changes. Basic server and security logs, described below, exist either way — they keep the service running and are not analytics. You can change your answer at any time in Settings.
If you agree, we use Google Analytics / Firebase Analytics and Vercel Web Analytics to understand how the app and website are used and to improve Indosso. That may include visits, sessions, page or screen views, general feature use, subscription interactions, referrals, city-level location, and basic device, browser, operating-system, and app-version information.What we don't do
We do not sell personal information, run ads, track you across unrelated apps or websites, or use analytics to build advertising profiles or judge your style. We do not intentionally send your email, Firebase account ID, closet contents, individual outfit pieces, trip destinations, precise GPS location, or payment credentials through analytics.
The rest of this policy explains the same commitments in the more specific language data protection laws expect.
4. What We Collect
Account Information
When you create or access an account, we collect:
- Email address
- Google sign-in provider information, if you choose Sign in with Google
- A user ID generated by Firebase Authentication
- A Firebase Installation ID generated by Firebase SDKs included in the mobile app, used by Firebase to deliver service updates and to identify app installations for security and fraud prevention. It is associated with your account, is not used for advertising, and is regenerated if you reinstall the app.
- Your network IP address at the moment of sign-up, sign-in, password reset, or account-deletion requests. Firebase Authentication uses this transiently for abuse detection and rate limiting. We do not store or correlate IP addresses with your closet or trip data, and we do not use them for advertising.
- Basic authentication and security records, such as sign-in timestamps and authentication events
Your email is used so your closet syncs across your devices and survives reinstalls, for sign-in, for account recovery, and for legally required notices. It is not used for marketing and is not sold.
Purpose: To create your account, let you sign in, sync your data, secure your account, and provide the app. Source: You, Google if you choose Google Sign-In, and Firebase Authentication. Legal basis where required: Contract performance, legitimate interest, and legal obligation where applicable. Retention: While your account is active, unless a shorter or longer period is required for security, legal, backup, or account-integrity purposes.
Closet and Outfit Data
When you use Indosso, we may store:
- Closet items — each item is a selection from our built-in catalog of garment templates, with a color, pattern, and material you choose. We store these as references to catalog entries plus your selections, not as uploaded images. Indosso does not currently take or store photos of your real clothes.
- Saved outfits
- Confirmed wear history, including the final outfit you said you wore and the context saved with that wear
- Committed changes you make to outfit suggestions, along with preference controls such as Keep, Forget, and Reset
- App settings, including whether learned personalization is on or off
- Trip planning and packing list information
Indosso may derive limited, app-specific preference information from your own confirmed wears, committed changes, and preference controls. Saved outfits and recent history may also be used where appropriate to manage repetition and order recommendations. This information is used for Indosso's own outfit features; it is not used to create advertising, marketing, identity, or sensitive-trait profiles, and it is not based on other users' behavior.
If a future version adds the ability to upload your own clothing photos, we will update this Privacy Policy and request the appropriate device permission before that feature is enabled.
Purpose: To generate and save outfit suggestions, maintain your closet and wear history, personalize the order of suggestions and limited comfort defaults, support trip planning and packing lists, sync your account, maintain your preference controls, and help avoid unwanted outfit repetition. Source: You and your use of the app. Legal basis where required: Contract performance and legitimate interest. Retention: While your account is active, subject to your available controls and the more specific retention rules in Section 10.
Outfit Generation Data
Indosso uses the closet and context information you provide to generate outfit suggestions. Inputs may include closet item attributes, saved outfits and recent history, confirmed wears, committed changes to suggestions, occasion, activity, weather context, trip context, and your settings and preferences.
Indosso may use limited learned preference information to order recommendations that already meet its normal outfit rules and quality requirements, and — where a rule reflects personal comfort rather than a fixed requirement — to adjust that comfort default for you. Learned preferences are specific to your account and are based on your own use of Indosso; Indosso does not use collaborative filtering or other users' behavior to infer what you should prefer.
Memory and personalization exist to support your next decision — not to replace it. Learned preferences do not override your choice, and they are not used to relax rules that exist for suitability, dress-code, or safety reasons. You can turn learned personalization off in Settings. When it is off, learned preferences stop influencing your recommendations, but your wear history and preference-related records are not automatically deleted.
Indosso does not build advertising, marketing, identity, or sensitive-trait profiles about you. We do not use outfit generation to infer your identity or determine sensitive traits. We do not judge whether your clothing choices are "good" or "bad." We do not use your closet data for advertising, sell your closet data, or use it to train third-party advertising or marketing systems.
Purpose: To provide outfit recommendations, personalize the order of suggestions and limited comfort defaults, reduce unwanted repetition, and provide related app features. Source: You and your use of the app. Legal basis where required: Contract performance and legitimate interest. Retention: While your account is active, subject to your available controls and the more specific retention rules in Section 10.
Location and Weather Data
Location-based weather context is optional.
When you enable weather context, Indosso may use:
- Approximate coordinates from your device, with your permission
- Trip destination names you enter manually
- Geocoding information needed to interpret a destination
- Country or region information needed to display local weather units
We use location information only to retrieve weather, climate, geocoding, or unit-format information, or to apply local formality context to outfit suggestions. We do not use it to track where you go. We do not use background location tracking.
Coordinates used for current weather are not saved to your closet or profile. Current-weather requests normally go through our server to WeatherAPI.com. If that request fails, the app may send the coordinates supplied by your device directly to Open-Meteo; in that fallback case, Open-Meteo also receives your device IP address. The coordinates may be precise or approximate depending on your device permission settings. Trip destination names you enter may be saved as part of your trip plan.
When you confirm that you wore an outfit, Indosso may save a limited observation of the weather conditions associated with that wear, when available. This is stored with the wear record so Indosso can remember the conditions in which the outfit was actually worn. The coordinates used to obtain current weather are not saved as part of that wear record.
Purpose: To provide weather-aware outfit suggestions, trip planning context, climate averages, local unit formatting, and limited weather context for confirmed wear history. Source: Your device permission settings, information you enter, your confirmed use of the app, and our weather and geocoding providers. Legal basis where required: Consent for device location access; contract performance or legitimate interest for trip destination processing and app-requested wear-history features. Retention: Device coordinates used for live weather are used for the request and are not saved to your closet or profile. A limited weather observation associated with a confirmed wear may be retained as part of that wear record until the wear record or your account is deleted. Weather and geocoding providers may retain request logs under their own terms. Trip destination names are retained while the related trip plan exists or until your account is deleted.
Device Permissions and App Controls
Some app features require device-level permissions, such as location access for weather context.
You can control these permissions through your device settings. If you disable a permission, the related feature may not work, but you can continue using the parts of Indosso that do not require that permission.
Indosso does not use device permissions for background location tracking, cross-app tracking, advertising, or unrelated profiling.
Technical, Security, and Operational Data
We collect or receive limited technical data needed to keep the app working:
- Device type, operating system version, browser information, and app version, used for troubleshooting and compatibility
- Crash reports from app store platforms, when available
- Operational logs from Firebase Authentication and Firestore, such as sign-in events and database reads and writes
- Basic server logs needed to diagnose errors, protect the service, and prevent abuse
We do not use this data for behavioral advertising or cross-app tracking.
These logs are pseudonymous. Where they identify an account at all, they do so using an internal identifier rather than your name or email. We may also read them in aggregate to understand general service use and improve reliability and the product. They are not tied to advertising and are not used to build a profile of you.
Purpose: To maintain reliability, troubleshoot errors, secure the service, prevent abuse, support compatibility, and understand general service use in aggregate.
Source: Your device, browser, app stores, Firebase, hosting providers, and server systems.
Legal basis where required: Legitimate interest and legal obligation where applicable.
Retention: Kept only as long as reasonably needed for security, troubleshooting, reliability, legal compliance, backup, or account-integrity purposes. Server request logs held by our hosting provider are retained for a short period set by that provider's plan and are not kept by us beyond it.
Operator Access to Account Data
Indosso is operated by one person. To investigate a bug you report, or a fault affecting outfit generation, that operator may need to look at the data for an individual account, including its closet contents and generated outfits.
This access is limited to diagnosing and fixing problems and to maintaining the security and integrity of the service. It is not used to review, rate, or judge anyone's clothing, and it is not used for marketing.
Purpose: To diagnose and fix faults, support you when you contact us, and maintain the service.
Source: Your account data as already described in this section.
Legal basis where required: Legitimate interest in operating and repairing the service, and contract performance where you have asked us for support.
Retention: A copy made to investigate a fault is held on operator systems, separately from your account record. It is used only for that investigation and any related support, and is not added to your account or used for analytics or marketing. Any onward disclosure is governed by Sharing and Disclosure below, and how long such a copy is kept follows the general rules in Data Retention below.
Analytics and Usage Data
Analytics runs only if you agree to it. When you first use Indosso you are asked a single question: whether you are willing to let us measure how the app is used. Until you answer, neither analytics service loads and neither collects anything. If you decline, they never load, and every feature of Indosso works exactly as it otherwise would.
If you agree, Indosso uses Google Analytics / Firebase Analytics and Vercel Web Analytics to understand how the app and website are used, measure referrals, maintain reliability, and improve the service.
When enabled, the analytics services may collect or derive:
- App or website visits, sessions, page or screen views, and engagement
- General feature use and subscription or upgrade interactions
- Page URL or route, referrer, and campaign information such as UTM parameters
- Location derived from technical connection information, which may be as specific as your city
- Detailed browser, device, operating-system, screen, platform, and app-version information, which may include device brand and model
- Pseudonymous browser, session, or app-installation identifiers used to distinguish visits and installations
Indosso may send limited analytics measurements about feature use and subscription interactions, together with general context needed to understand those interactions. We do not intentionally send your email, Firebase Authentication user ID, closet contents, individual outfit pieces, trip destinations, precise GPS coordinates, or payment credentials through analytics.
Google Analytics may use a first-party browser identifier or a pseudonymous app-installation identifier to distinguish users, installations, and sessions. Vercel Web Analytics records anonymized page views and limited analytics measurements without cookies and uses a short-lived visitor hash.
We use analytics to understand how people find and use Indosso and to improve the app, website, onboarding, reliability, and product decisions.
We do not use analytics data to target advertisements, build cross-context advertising profiles, judge clothing choices, infer sensitive traits, or sell personal information. We do not intentionally connect analytics identifiers to your email or closet for marketing.
We have not switched on the Google Analytics features that would produce advertising-style information about you. Google Signals is off, so Google does not add demographic or interest categories to your activity. User-provided data collection is off, so we do not send Google any email addresses or phone numbers to match against. No Google Ads account is linked to our Analytics property, and no BigQuery or other export destination is configured, so there is nowhere for audience data to be sent.
Your choice, and how to change it
- You are asked once, during setup. No analytics is collected before you answer.
- Declining costs you nothing. No feature is withheld, delayed, reduced, or repeatedly re-asked.
- You can change your answer at any time in Settings, in either direction.
- When you turn analytics off, the page reloads. That is deliberate: a measurement script that has already started running cannot be reliably stopped in place, so we restart the app without it. After the reload, collection has stopped.
- Your answer is stored on the device and browser where you gave it, and only there. It is not attached to your Indosso account and does not travel with you. If you use Indosso in a different browser, or on a phone as well as a computer, you will be asked again on each one, and each can be set differently.
- Turning analytics off stops future collection. It does not delete measurements already recorded before you changed your answer, though those records are pseudonymous and are generally not identifiable as yours.
- If you were already using Indosso before this choice existed, you are asked once, the first time you open the app after the change ships. Until you answer, analytics does not run for you either.
- Because the answer lives in your browser's local storage, clearing your browsing data for Indosso erases it. The choice returns to unanswered, analytics stays off, and you are asked again the next time you open the app.
- Your answer is not analytics data and is never sent to Google or Vercel.
Purpose: Analytics, service improvement, reliability, and measuring referrals and product use.
Source: Your device, browser, and your use of the app or website.
Legal basis where required: Your consent. You may withdraw it at any time in Settings, and withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
Retention: Analytics data is retained according to our configured provider settings and the service terms of Google Analytics and Vercel. We keep access to it only as long as reasonably needed for the purposes described above.
Payment and Subscription Information
Indosso offers Free and Premium subscriptions ($9.99/month or $89.99/year). On Android, purchases are processed through Google Play and managed through RevenueCat. On the website, checkout is processed by Stripe.
For Google Play purchases, RevenueCat receives your Firebase Authentication user ID as its App User ID so the subscription can be connected to your Indosso account. RevenueCat may also process Google Play purchase tokens, purchase and subscription status, entitlement history, last-seen time, and device or technical information needed to manage purchases.
For website checkout, Stripe processes the checkout and transaction information needed to complete and manage the subscription. Depending on what the checkout requests and what you provide, this may include contact information, billing information, payment-method information, transaction amount and date, subscription status, IP address, and device information. We associate the Stripe Checkout Session with your Indosso account so paid access can be applied to the correct account.
Indosso does not collect or store your full credit card number, debit card number, banking credentials, or full payment credentials. Google Play and Stripe handle payment credentials under their own privacy terms. We receive limited purchase, subscription, and entitlement information, such as whether your subscription is active, expired, canceled, refunded, or in a trial period.
Purpose: To process purchases, provide paid access, manage subscriptions, confirm entitlements, process refunds or support requests, prevent fraud, and comply with tax, accounting, or legal requirements.
Source: You, Google Play, RevenueCat, and Stripe.
Legal basis where required: Contract performance, legitimate interest, and legal obligation.
Retention: Purchase, subscription, entitlement, and transaction records are kept as long as needed to provide paid access, resolve disputes, prevent fraud, comply with legal obligations, or maintain business records. Google Play, RevenueCat, and Stripe also retain data under their own applicable terms.
Communications With Us
If you contact us for support, privacy requests, feedback, or business inquiries, we may collect your name (if provided), email address, message contents, and any files, screenshots, or details you choose to include.
Purpose: To respond to you, provide support, resolve issues, process privacy requests, and improve the app. Source: You. Legal basis where required: Contract performance, legitimate interest, consent where applicable, and legal obligation where applicable. Retention: Kept as long as needed to respond, resolve the issue, maintain reasonable business records, or comply with law.
Marketing, Research, and Push Notifications
Indosso does not use your personal information for third-party advertising, behavioral marketing, or marketing profiles.
If we offer optional newsletters, surveys, research requests, promotional emails, or push notifications in the future, we will only use them as described at the time you sign up or opt in. You will be able to unsubscribe or turn off optional communications.
We may still send non-marketing service communications, such as account notices, security notices, billing or subscription notices, legal updates, or important app-related messages.
5. What We Do Not Collect or Do
Indosso does not:
- Sell your personal information
- Use advertising networks or run third-party behavioral ads
- Use analytics data to target advertising or build advertising profiles
- Track you across unrelated apps or websites
- Use background location tracking
- Intentionally send your email, Firebase account ID, closet contents, individual outfit pieces, trip destinations, precise GPS coordinates, or payment credentials through analytics
- Use analytics to judge your style, infer sensitive traits, or create a personal clothing score
- Build marketing cohorts from your closet contents or styling choices
- Infer age, gender, income, health, body type, race, religion, sexuality, or other sensitive traits
- Collect height, weight, body measurements, body size, body shape, or physical appearance details unless a future feature clearly asks for that information and you choose to provide it
- Take or store photos of your real clothes — closet items are selected from our built-in catalog, not photographed
- Scrape or collect data about you from outside the app
- Use your closet data to advertise products to you
- Require you to make your closet public
- Collect speculative personal data solely for unrelated future features without first updating our disclosures where required
6. How We Use Your Information
We use information to:
- Create and secure your account
- Store and sync your closet
- Generate outfit suggestions from what you own
- Save outfits and maintain confirmed wear history
- Support trip planning and generate packing lists
- Provide optional weather-aware suggestions
- Personalize the order of outfit suggestions, and limited comfort defaults, using limited learned preferences
- Maintain preference controls such as Personalization on/off, Keep, Forget, and Reset
- Avoid unwanted outfit repetition
- Process subscriptions or purchases
- Provide customer support
- Maintain app security and reliability
- Understand app and website use
- Measure referrals and general service use
- Improve the product, onboarding, and service quality
- Comply with legal obligations
We do not use your data for advertising, data brokerage, cross-context tracking, or unrelated profiling.
7. Legal Bases for Processing
Where data protection laws require a legal basis, we rely on the following:
- Contract performance — to provide the app features you request, including account access, closet storage, outfit generation, saved outfits, trip planning, packing lists, sync, export, and deletion.
- Consent — for optional features that require your permission, such as device location access for weather context, optional communications, and all analytics collection. We ask for analytics consent everywhere, not only where local law requires it, and no analytics is collected until it is given.
- Legitimate interest — to secure the app, prevent abuse, maintain reliability, diagnose errors, respond to support requests, reduce unwanted repetition, and provide limited first-party personalization using your own account activity, provided those interests do not override your rights and freedoms and subject to applicable law. Analytics measurement is not carried out on this basis; it relies on your consent.
- Legal obligation — to comply with applicable laws, court orders, tax and accounting obligations, security obligations, and valid legal requests.
You may withdraw consent where processing is based on consent. Withdrawing consent may limit features or measurements that depend on that permission. Analytics is not carried out on the basis of legitimate interest, so there is no analytics processing to object to on that ground — you simply turn it off in Settings. Where applicable law gives you a right to object to or restrict processing we carry out under legitimate interest, you may turn learned personalization off in Settings where that control applies, or contact us at privacy@indosso.app.
8. Service Providers and Third Parties
Indosso uses service providers and third-party platforms to operate the app and website. The current services that may process user or device information are described below. We do not authorize these providers to use Indosso data for our advertising or to build advertising profiles about Indosso users.
Google Firebase and Google Analytics
We use Firebase Authentication and Cloud Firestore for account sign-in, authentication, database storage, and account-level sync. We also use Google Analytics / Firebase Analytics for the limited analytics described in the “Analytics and Usage Data” section.
Depending on the environment, Google Analytics may process pseudonymous browser identifiers, app-installation identifiers, session information, location that may be as specific as your city, detailed device and browser information, automatically collected measurements, and the limited analytics measurements described above.
We do not use Google Analytics for advertising, Google Ads targeting, or cross-context behavioral profiles. We do not intentionally send your email, Firebase Authentication user ID, closet contents, individual outfit pieces, trip destinations, precise GPS coordinates, or payment credentials through analytics.
Google processes this data under Google's applicable Firebase and Google Analytics terms and data-processing commitments. Where applicable, Google provides international-transfer safeguards such as the EU-US Data Privacy Framework and Standard Contractual Clauses.
Vercel Hosting and Web Analytics
We use Vercel to host the website and serverless parts of Indosso. Vercel Web Analytics records anonymized website page views, referrers, campaign information, approximate region, browser, operating system, and device type. It may also receive the limited analytics measurements described above when they occur on the Vercel-hosted website.
Vercel Web Analytics does not use cookies for visitor identification. It uses a short-lived hash created from the incoming request and reports aggregated statistics. We do not intentionally place personal information in analytics URLs, query parameters, or analytics properties.
RevenueCat
We use RevenueCat to manage Google Play subscriptions and entitlement status in the Android app. The RevenueCat SDK is configured with your Firebase Authentication user ID as its App User ID so a purchase can be connected to the correct Indosso account.
RevenueCat may process that user ID, Google Play purchase tokens or receipt information, purchase and subscription history, entitlement status, last-seen time, and technical information such as device type, operating system, and IP address. We do not send RevenueCat your closet contents, outfit pieces, or trip destinations.
Stripe
We use Stripe Checkout to process website subscriptions. When you enter the website checkout flow, Stripe may process contact, billing, payment-method, transaction, subscription, IP-address, device, and fraud-prevention information. Stripe may collect information entered into its checkout page even when a transaction is not completed, as described in Stripe's own privacy notices.
Indosso associates the Checkout Session with your Indosso account so the resulting entitlement can be applied to the correct account. Indosso does not receive or store your full payment-card number or full payment credentials.
WeatherAPI.com
We use WeatherAPI.com to retrieve current weather conditions and short-range forecasts when you enable weather context. The normal request is sent through our server, so WeatherAPI.com receives the requested coordinates and our server connection rather than your device IP address. We do not send your name, email, Firebase account ID, or closet data to WeatherAPI.com. WeatherAPI.com may process the request under its own privacy policy.
Open-Meteo
If the normal server weather request fails, Indosso may use Open-Meteo as a direct fallback. In that case, the app sends the coordinates supplied by your device directly to Open-Meteo in the request URL, and Open-Meteo also receives your device IP address and technical request information. The coordinates may be precise or approximate depending on your device permission settings.
Open-Meteo states that its server logs may contain IP addresses, requested URLs, and geographic coordinates and that individual log files are deleted after its stated retention period. We do not send your name, email, Firebase account ID, closet data, or trip plans in the Open-Meteo request.
Climate Normals (Bundled Dataset)
For trip planning, we use a static, bundled dataset of monthly climate averages (1991–2020) to estimate what the weather is typically like for a destination and month. The dataset is part of our app and travels with each release — no third-party climate service is contacted from your device or our server when you plan a trip. The dataset is derived from publicly available climate data: the World Bank Climate Change Knowledge Portal (CCKP, ERA5 historical, licensed CC-BY 4.0) for temperature and precipitation, and TerraClimate (Abatzoglou et al., 2018, CC0 public domain) for wind and humidity.
OpenStreetMap Nominatim
We use OpenStreetMap Nominatim to convert your coordinates to a country code so we can display local units and to convert trip destination names you enter into map locations. Where requests are routed through our server, your device IP address is not exposed to Nominatim by us. Some requests may be sent directly from your device, in which case Nominatim may receive your IP address along with the coordinates or destination name for that request. The OpenStreetMap Foundation may process those requests under its own privacy policy.
Upstash Redis
We use Upstash Redis as a server-side cache for geocoding requests and responses. Cached entries may include location search text, coordinates, country codes, and geocoding results. The cache reduces repeated requests and is not used for advertising or profiling.
Google Play and Google Sign-In
Google may process information when you download Indosso through Google Play, use Google Play billing or store crash reporting, or choose Google Sign-In. Google's processing is governed by its own privacy terms.
Other Hosting and Infrastructure Providers
We use hosting, serverless, storage, logging, security, domain, and infrastructure providers to deliver the app and keep it reliable. These providers may process limited technical information needed to operate their services.
We do not use advertising networks or data brokers. Google Analytics / Firebase Analytics and Vercel Web Analytics are used only for the limited analytics purposes described in this Policy.
9. Sharing and Disclosure
We disclose information only in these limited situations:
- With service providers that help us operate, secure, host, analyze, and improve Indosso, including Firebase, Google Analytics, Vercel, and Upstash
- With WeatherAPI.com, Open-Meteo, and OpenStreetMap Nominatim for the limited weather and geocoding requests described above
- With Google Play, Google Sign-In, RevenueCat, and Stripe when needed for sign-in, purchase, subscription, payment, refund, fraud prevention, or entitlement handling
- If you ask us to disclose information or direct us to export it
- To comply with law, legal process, subpoenas, court orders, or valid government requests
- To protect the rights, safety, and security of users, Indosso, KSK Digital LLC, or others
- To investigate, prevent, or respond to fraud, abuse, security incidents, or illegal activity
- In connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to this Privacy Policy or a policy with materially similar protections unless you consent otherwise
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
10. Data Retention
We keep personal information only as long as reasonably needed for the purpose it was collected.
In general:
- Account data is kept while your account is active.
- Closet, saved-outfit, confirmed-wear, trip, packing, preference-related, and other app data are kept while your account is active, until you delete the related data where a deletion control is available, or until you delete your account.
- Turning learned personalization off stops learned preferences from influencing your recommendations; it does not delete your wear history or preference evidence.
- Forget tells Indosso not to use earlier evidence for that learned tendency. Later behavior may teach a similar tendency again.
- Reset learned preferences starts learning again from the reset point forward. It does not delete your historical Wear History.
- Device coordinates used for live weather are used for the request and are not saved to your closet or profile. A limited weather observation associated with a confirmed wear may remain with that wear record. Weather and geocoding providers may retain request logs under their own terms.
- Trip destinations are kept while the related trip plan exists or until your account is deleted.
- Support messages are kept as long as needed to respond, resolve issues, and maintain reasonable business records.
- Security, technical, and operational logs are kept only as long as reasonably needed for security, troubleshooting, reliability, legal compliance, backup, or account-integrity purposes. Server request logs held by our hosting provider expire on a short schedule set by that provider's plan.
- Analytics data exists only for people who agreed to analytics, and is retained according to our configured Google Analytics and Vercel settings and their applicable service terms, and is accessed only as long as reasonably needed for the purposes described in this Policy.
- Purchase, subscription, entitlement, and transaction records may be kept by Indosso, Google Play, RevenueCat, and Stripe as long as needed for access, accounting, legal, tax, dispute, refund, support, or fraud-prevention purposes.
Deleting your Indosso account deletes active account, closet, saved-outfit, confirmed-wear, trip, and preference-related account data as described above, subject to brief backup retention periods that do not exceed 30 days, security logs, legal obligations, dispute records, and other information we are required or permitted to retain. Analytics records are generally pseudonymous or anonymized and may not be directly linked to your Indosso account, so deleting your account may not automatically identify and remove previously collected aggregate or pseudonymous analytics records.
11. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect your information. These include:
- Encrypted transmission using HTTPS
- Account-based access controls
- Firebase Authentication security controls
- Firestore security rules and access controls
- Limited access to systems that process user data
- Operational monitoring for reliability and abuse prevention
- Use of service providers with security and data processing commitments
No internet or electronic storage system is perfectly secure, so we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will take appropriate steps and notify you where required by law.
12. Your Choices and Rights
You own everything you put into Indosso.
Depending on where you live, you may have rights to:
- Access your personal information — see what we have on file for your account
- Correct inaccurate information — edit closet items, outfits, and preferences directly in the app
- Delete your information — clear your closet, or delete your account entirely
- Export / portability — obtain a copy of available account data in a structured, machine-readable format. The current export may include your closet, saved outfits, wear history, trips, settings, and preference-related data. Export is offered on a best-effort basis as described in our Terms of Use; the availability, scope, format, and contents of any export may change over time, and some data may not be included
- Restrict or object to certain processing where required by applicable law
- Withdraw consent where processing is based on consent — by changing the related setting, deleting the related data, or deleting your account
- Turn analytics on or off at any time in Settings, on each browser or device you use
- Control learned personalization in Settings. Turning it off stops learned preferences from influencing your recommendations. You can Keep or Forget individual learned tendencies and Reset learned preferences. Forget and Reset change what evidence Indosso uses for learning; they do not automatically erase historical Wear History
- Appeal or complain if you believe your request was handled incorrectly
- Lodge a complaint with a data protection authority where applicable
Within the app, you can edit closet items, delete items, delete outfits or wear records where available, clear your closet, export available account data, change settings, turn analytics on or off, control learned personalization, disable location access, or delete your account. You can also control device permissions, such as location access, through your device settings.
Deletion is permanent and does not restrict your ability to use the app.
To exercise your rights, contact privacy@indosso.app. We may need to verify your request before acting on it. We will respond within a reasonable time and, where required by law, within the time period required by that law.
13. California Privacy Notice
This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies.
Categories of Personal Information We May Collect
Depending on how you use Indosso, we may collect:
- Identifiers: email address, Firebase account ID, Google sign-in provider ID, Firebase Installation ID, RevenueCat App User ID, Stripe checkout account reference, and pseudonymous browser or app-installation analytics identifiers
- Internet or electronic network activity information: page or screen views, sessions, engagement, general feature use, subscription or upgrade interactions, referrals, campaign information, browser, device, operating-system, app-version, and limited technical, security, and operational logs
- Geolocation data: coordinates supplied by your device when you enable weather context; trip destinations you enter; location search and geocoding data; and location derived by analytics providers from technical connection information, which may be as specific as your city where you have agreed to analytics
- User-generated content: closet items selected from our built-in catalog, saved outfits, confirmed wear history, committed outfit changes, preference controls, trip plans, packing data, and support messages
- Commercial information: Google Play, RevenueCat, and Stripe purchase, transaction, subscription, and entitlement information
- Inferences: limited app-specific preferences derived from your own confirmed wears, committed changes, and preference controls to personalize recommendations and reduce unwanted repetition — not advertising, marketing, identity, or sensitive-trait profiling
Sources
We collect this information from you, your device, Google Sign-In, Google Play, RevenueCat, Stripe, analytics providers, weather and geocoding providers, and our other service providers.
Purposes
We use this information for the purposes described in this Privacy Policy, including account access, app functionality, outfit generation, learned personalization, repetition management, trip planning, packing lists, weather context, analytics, referral measurement, product improvement, security, support, and legal compliance.
Selling or Sharing
Indosso does not sell personal information. Indosso does not share personal information for cross-context behavioral advertising.
Sensitive Personal Information
Indosso does not use sensitive personal information to infer characteristics about you. Device location is used only when you enable weather context and only for the app feature you requested.
California Rights
California residents may have the right to know, access, correct, delete, obtain a portable copy of, limit certain uses of sensitive personal information, and opt out of sale or sharing. Because Indosso does not sell personal information or share it for cross-context behavioral advertising, there is no sale or sharing to opt out of.
To exercise your rights, contact privacy@indosso.app.
14. Browser Privacy Signals
Some browsers or devices may offer “Do Not Track,” Global Privacy Control, or similar privacy signals.
Indosso does not sell personal information or share personal information for cross-context behavioral advertising. Because there is no sale or advertising sharing to opt out of, Global Privacy Control does not change those practices.
Browser “Do Not Track” signals do not operate as a universal switch for ordinary product analytics. Indosso does not rely on them, because it asks you directly instead: analytics does not run until you agree, and the control stays available in Settings. Where applicable law gives you a right to object to or restrict analytics processing, contact privacy@indosso.app.
15. European Union and United Kingdom Users
If you are in the European Union, European Economic Area, or United Kingdom, you have rights under applicable data protection laws, including the right to access, correct, delete, restrict, object, port your data, withdraw consent, and lodge a complaint with a supervisory authority.
KSK Digital LLC is based in the United States. Your information may be processed in the United States and in other countries where our service providers operate.
Where required, we rely on appropriate safeguards for international data transfers, such as data processing agreements, Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms used by our service providers.
16. Brazil Privacy Notice
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados, including the right to confirm processing, access data, correct incomplete or inaccurate data, anonymize or delete unnecessary or excessive data, obtain portability where applicable, receive information about sharing, revoke consent, object to unlawful processing, and lodge a complaint with the Autoridade Nacional de Proteção de Dados.
To exercise these rights, contact privacy@indosso.app.
Your information may be processed in the United States and in other countries where our service providers operate. We use service providers and safeguards intended to protect your information consistent with this Privacy Policy.
17. Children's and Teen Privacy
Indosso is intended for users 13 years of age and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Our Terms of Use require users who are under the age of majority in their jurisdiction to use Indosso with the permission and supervision of a parent or legal guardian.
Teenagers may use Indosso. The same privacy-protective product design applies to teen users: closets are private by default, Indosso does not run ads or build advertising profiles, analytics is optional, and learned personalization is limited to app-specific outfit preferences with controls available in Settings.
Age and parental-authorization rules differ by jurisdiction and can also depend on the legal basis used for a particular type of processing. Indosso's general minimum age of 13 does not override those local requirements. For example, where consent is the legal basis for an online service offered directly to a child in the European Union, the applicable age for the child's own consent may vary by Member State between 13 and 16.
If you believe a child under 13 has provided personal information to Indosso, or you have a question about a minor's privacy, contact privacy@indosso.app and we will take appropriate steps.
18. Cookies, Website Analytics, and Tracking Technologies
Indosso uses Google Analytics and Vercel Web Analytics on its website and in the shared web application code. Neither loads until you have agreed to analytics. Before you answer, and at any time after you decline or switch analytics off, these technologies are not requested, not loaded, and not running.
Google Analytics may use a first-party cookie or similar browser identifier to distinguish visits and sessions. It may collect page views, sessions, engagement, referrals, campaign information, location that may be as specific as your city, and detailed browser or device information.
Vercel Web Analytics does not use cookies for visitor identification. It records anonymized page views, referrers, campaign information, approximate region, browser, operating system, and device type using a short-lived visitor hash.
Indosso may send the limited analytics measurements described in the “Analytics and Usage Data” section to Google Analytics and Vercel Web Analytics.
We do not use these technologies for third-party advertising, cross-site advertising profiles, or data brokerage. We ask for your consent before loading them regardless of whether local law requires it, and your answer is stored on that browser or device only.
19. Third-Party Links and Services
Indosso may include links to third-party websites, app stores, help resources, payment flows, sign-in providers, weather providers, or other services that we do not control.
Information you provide to those third parties is governed by their privacy policies, not this Privacy Policy. We are not responsible for the privacy, security, or content practices of third-party services.
20. No Public Closet or Social Feed by Default
Indosso is designed as a private personal closet and outfit planning tool.
Unless a future version clearly says otherwise and gives you specific controls, your closet, saved outfits, trip plans, and packing lists are not public social posts and are not visible to other users.
If we ever add public, sharing, community, or social features, we will update this Privacy Policy before launch of those features and explain what is visible, who can see it, and what controls you have.
21. International Users
If you access Indosso from outside the United States, your data may be processed in the United States or in other regions where Firebase and our service providers operate. We use service providers that process data on our behalf, and your rights described above apply regardless of where your data is processed.
22. Changes to This Policy
We may update this Privacy Policy as Indosso evolves.
If changes are material, we will notify you in the app, by email, or by another appropriate method. We do not retroactively change how your past data is interpreted without providing notice where required by law.
The "Last Updated" date at the top shows when this policy was last revised.
23. Contact
For privacy questions or requests, contact:
KSK Digital LLC Wisconsin, United States