Privacy Policy

Last updated: July 20, 2026

Introduction

VouchStyle (“we”, “us”) operates the VouchStyle web application. This Privacy Policy explains what information we collect, how we use it, and the choices you have. This policy is effective as of July 20, 2026. For any questions about this policy, contact us at contact@vouchstyle.com.

Information We Collect

Account: When you create an account, we collect your email address and a password (stored as a one-way hash; we never see your plaintext password). If you sign in with Google, we receive your Google profile name, email address, and avatar.

Optional profile: You may optionally provide an age band to tune trend relevance; “Prefer not to say” is always available.

Per verdict: When you request an outfit verdict, we receive one outfit photo (up to 12 MB; JPG, PNG, or WEBP), an optional occasion description, an optional free-text question (up to 300 characters), an optional location (latitude/longitude and/or city name), your selected language, and your selected AI personality.

Information We Derive

Based on your photo and inputs, our AI generates: an estimated presentation/gender context, a garment breakdown (items detected in the photo), a verdict label and rating (0–10), reasoning text explaining the verdict, suggested fixes, weather information for the provided location (fetched to contextualize the verdict), and knowledge sources cited from our fashion reference database.

How We Protect Your Photos

Your outfit photos are encrypted at rest with AES-256-GCM authenticated encryption — the same standard used by banks and governments. Each account has its own 256-bit data key, which is itself encrypted (“wrapped”) under a server master key and stored separately from your photos. Your photos are stored on disk as encrypted ciphertext only (.enc files); decompressed plaintext images are never persisted to disk. Only the encrypted form is ever at rest.

How You Access Your Photos

Decrypted photo access is gated by short-lived HMAC-SHA256 signed URLs with a default 1-hour expiry. Only your authenticated account can request a signed URL for your own photos. Requests without a valid, unexpired signed token are rejected with HTTP 403. This means even if someone guessed a photo’s storage path, they could not view it without a valid signed URL issued to your account.

Sharing

When you choose to share a verdict card, only the verdict text, rating, and reasoning are published on an unguessable share URL (/share/<slug>); your uploaded outfit photo is NOT displayed on the shared card. The share slug is randomly generated and unguessable, so only people you give the link to can view it.

In a future update, opting to share may also decrypt and include your rendered outfit photo on the shared card so friends see the look alongside the verdict. Sharing is always opt-in: nothing is published until you explicitly generate a share link.

AI Processing

Outfit analysis runs on VouchStyle’s servers. The default pipeline runs a local model (self-hosted via Ollama) so your photo does not leave our infrastructure. When the local model is unavailable or slow, VouchStyle may fall back to a third-party AI provider (OpenAI), in which case your photo (as a base64-encoded image) is transmitted to that provider for analysis and held by them subject to their own data handling practices.

Third-Party Processors

  • Stripe — payment processing; your card data never touches VouchStyle servers (you are redirected to Stripe’s hosted checkout).
  • Supabase — PostgreSQL database hosting; stores your account, analyses, and encrypted image keys, but NOT plaintext photos.
  • OpenAI — AI analysis fallback only, when the local model is unavailable.
  • Open-Meteo — weather data by latitude/longitude.
  • Geocoding provider — location name to coordinates lookup.
  • Self-hosted Plausible-style analytics — see the Analytics section below.

Analytics

VouchStyle uses cookie-less, self-hosted Plausible-style analytics that records aggregate page views without tracking cookies and without building cross-site behavioral profiles. No third-party advertising or tracking scripts are loaded. We do not sell or share analytics data with any third party.

Data Retention & Deletion

Your account data and verdict history are retained until you delete your account or request deletion via contact@vouchstyle.com. Encrypted photos are retained with your account and deleted when your account is deleted. To request deletion, email the contact address in the Introduction section.

Your Rights

Depending on where you live, you may have rights under applicable data-protection laws (including the EU/UK GDPR, Brazil’s LGPD, and California’s CCPA, where they apply to you), including the right to access, rectify, erase, restrict, or port your personal data, and to object to or withdraw consent for processing. To exercise any right, email contact@vouchstyle.com with the subject “Data request”. VouchStyle responds to verified requests within 30 days.

Changes to This Policy & Contact

We may update this policy from time to time; the “Last updated” date at the top will reflect the most recent change. Material changes will be surfaced on the landing page or via email to active accounts where feasible. For any question about this policy, email contact@vouchstyle.com.

Privacy Policy