← back to misfit

legal

privacy policy

This policy explains what misfit collects, why, who processes it, and how you stay in control. misfit is operated by Ana Soares, Billstedter Hauptstrasse 98, 22117 Hamburg, Germany — the controller under the GDPR.

Last updated: 13 August 2026

1. What we collect

misfit works without an account. If you create one, we collect more.

  • Account data: your email address and authentication data (a hashed password and session tokens) when you choose to save your progress.
  • Anonymous session identifier: a random ID stored on your device so guests can keep their wardrobe and results.
  • Uploaded photos: selfies used for the colour season and Kibbe analysis, and photos of garments you add to your wardrobe.
  • Derived analysis data: your colour season, Kibbe style family, confidence scores, feature descriptions and wardrobe scoring — all derived from your input and images.
  • Preferences: language, onboarding state, shopping list and app settings.
  • Basic technical data: device/browser information and error logs needed to keep the service running.

2. Sensitive nature of photos

Photos of your face and body are personal data that can reveal your appearance. We treat them accordingly: they are used only to produce your styling analysis, are never sold, never used for advertising, and are never used to train third-party AI models beyond what is described below.

3. Third-party AI providers and processors

misfit cannot produce your analysis without sending your images and text input to specialist providers. They act as data processors on our behalf, under data processing agreements, and may only use the data to deliver the requested service.

  • Anthropic (Claude) — styling, colour season and Kibbe analysis. Receives your uploaded images and the descriptions you enter.
  • OpenAI — image generation for illustrated garment suggestions. Receives text prompts describing pieces; it does not receive your selfies for this purpose.
  • Lovable AI Gateway — routes AI requests to the model providers above and to Google Gemini for text-based styling responses.
  • Supabase (backend, database, authentication and file storage, hosted in the EU) — stores your account, wardrobe items, photos and analysis results.
  • Microsoft Clarity — anonymised product analytics used to understand how the app is used.

4. International transfers

Some processors (notably OpenAI, Anthropic and Microsoft) are based in the United States. Transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

5. Legal basis

  • Consent (Art. 6(1)(a) GDPR): uploading photos and running the AI analysis. You give consent by choosing to upload; you can withdraw it at any time by deleting the photos or your account.
  • Contract (Art. 6(1)(b) GDPR): providing your account, wardrobe and saved results.
  • Legitimate interest (Art. 6(1)(f) GDPR): keeping the service secure, debugging errors and understanding aggregate usage.

6. Retention

  • Photos and analysis results: kept until you delete them or delete your account.
  • Guest (anonymous) data: kept for up to 12 months of inactivity, then deleted.
  • Account data: kept while your account exists, deleted within 30 days of a deletion request.
  • Error logs and analytics: retained for a maximum of 12 months.
  • AI providers process data transiently and do not retain it as part of a long-term profile of you.

7. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, data portability, and object to processing based on legitimate interest. You may also withdraw consent at any time without affecting past processing. Write to misfit@misfitapp.com and we will respond within 30 days. You also have the right to complain to a supervisory authority — in our case the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit.

8. Deleting your data

You can delete individual wardrobe photos in the app at any time. To delete your account, all photos and all derived analysis data, email misfit@misfitapp.com from your registered address.

9. Cookies and local storage

misfit uses no advertising cookies and no cross-site tracking.

  • Essential (no consent required): local storage for your session ID, language choice, onboarding progress and cached results; authentication tokens for signed-in users.
  • Non-essential (consent required): Microsoft Clarity product analytics. Where consent is required in your jurisdiction, it is requested before non-essential analytics are activated, and you can object at any time via the contact email.

10. Security

Data is transmitted over TLS and stored with access controls that scope every record to your account or anonymous session. No system is perfectly secure, but we work to keep exposure minimal and to fix issues quickly.

11. Children

misfit is not intended for children under 16. We do not knowingly collect their data.

12. Changes and contact

We may update this policy as misfit evolves; the date above always reflects the current version. For any data protection matter, contact misfit@misfitapp.com.