PRIVACY
What StyleStack collects, where it goes, and how to destroy it.
DRAFT — FINAL TEXT PENDING
EVERY FACT STATED BELOW IS TRUE OF THIS APP TODAY. THE FINAL WORDING IS NOT SETTLED.
WHAT WE HOLD
StyleStack stores what you put into it: photographs of your clothes and of yourself wearing them, the attributes attached to each item, the fits you build, the lookbook entries you log, and the profile you write. It stores your email address because that is how you sign in.
It does not ask for your name, your address, your phone number, your date of birth, or your location, and there is nowhere in the product to enter them.
PHOTOGRAPHS GO TO A MODEL PROVIDER
When you upload an item photograph, the image is sent to a third-party model provider — the Anthropic Messages API — which reads it and returns the tags that describe the garment: its type, its colours, its material. This happens for item photographs at upload time.
This is a processor relationship: the provider receives the image in order to answer that one question. If you are not comfortable with a photograph leaving this system, do not upload it.
WHO ELSE PROCESSES YOUR DATA
Two other companies hold your data because the product runs on them. Supabase provides the database and the object storage — including the private bucket that holds your original, uncut photographs. Vercel hosts and serves the application.
There is no fourth party. No advertising network, no analytics vendor, no session-recording tool, no marketing platform, no data broker.
WHAT "PUBLIC" MEANS HERE
Nothing you upload is public unless you make it public, and the controls are specific rather than a single all-or-nothing switch.
Your profile has a master switch. While it is off, everything below it is unreachable no matter how any other flag is set — this is the retraction that always works.
Your wardrobe has three states: private, semi-public, and public. Private shows nobody your items. Semi-public shows only the items you have individually flagged. Public shows the wardrobe.
A lookbook entry carries its own public flag, and an item carries its own. A fit is visible when the chain from the master switch down to that flag permits it.
A post is a separate act. Publishing a post does not merely reveal something you already had; it publishes it in its own right, with its own door and its own retraction. Deleting a post retracts the post. Turning off the master switch retracts everything at once, posts included.
DELETION IS REAL
Deleting your account is not a flag on a row that stays in the database. The bytes are destroyed: every object under your prefix in all six storage buckets is removed, and every row you own is deleted, with the database cascading the deletion through everything attached to it.
The operation destroys the files before it destroys the rows, and if any file fails to delete it retries once and then aborts the whole operation rather than leaving your account half-deleted. If it aborts, your account is still intact and you can try again — you are never left in a state where the record of your data is gone but the data is not.
Your handle is released when the account is deleted and becomes available to somebody else.
COOKIES
Session cookies only — the ones that keep you signed in. There is no analytics cookie, no advertising cookie, no third-party script of any kind on any page.
There is no cookie banner because there is nothing to consent to. That is a design decision, not an oversight.
REPORTS AND BLOCKS
When you report something, the report is stored: who reported, what was reported, the reason, and any note you wrote. It is kept so that a pattern across several reports remains visible, which is the only thing that makes reports worth collecting.
When you block somebody, the block is stored until you remove it. Blocking hides each of you from the other and removes the follow relationships between you in both directions. It does not touch the other person's own data: their posts, their wardrobe, and their account are unaffected, and nothing is deleted from their side. They are not told that you blocked them.
Unblocking does not restore the follow relationships. Nothing in the system remembers what they were.
CONTACT
StyleStack is run by one person. The contact address for privacy questions, including a request to see or delete your data, will be published here with the final text.