Stylopia (the "app") is a virtual dressing room: you build a model from
our library, dress it in garments from our catalogue or ones you design, and
see how the outfit looks. This page describes exactly what the app and its
backend (stylopia.app, the "service") do with your data —
no more, no less than what the software actually does.
No photographs of you
- The app does not take, ask for, or accept photographs of you. It has no camera permission and no microphone permission, and it does not open your photo gallery. There is no way to bring a picture of your own into Stylopia.
- Instead you build a model: a body from our library and, if you like, one of our faces. Garments come from our catalogue, or you design your own by describing the changes you want.
- This is a deliberate limit, and it may be lifted later. If it is, this policy and the in-app briefing change, and you are asked to read the briefing again before anything of yours is used.
What stays on your device
- Your models, looks and designs, your wardrobe, and the names you give them are stored only inside the app, on your phone.
- Nothing is uploaded in the background, except the Google Drive backup if you turn it on (below). You can use the app without an account; signing in with Google is optional.
- Uninstalling the app deletes all of it.
Backup to your own Google Drive
Because your models, looks and designs exist only on your phone, the app recommends backing them up, and you can turn this on or off at any time in Settings. It is off until you turn it on.
- When it is on, your models, looks and designs are copied to a Stylopia folder in your own Google Drive, together with a file listing their names, your wardrobe (catalogue garments by name only) and the instructions you wrote for your designs.
- The copies go straight from your phone to Google. Our server is not involved and never receives them.
- The app asks Google only for access to the files it creates itself
(the
drive.filepermission). It cannot see anything else in your Drive. - It runs in the background, only on Wi-Fi unless you choose otherwise. Deleting something in the app moves its copy to your Drive's bin, where Google keeps it for 30 days.
- On a new phone, sign in with the same Google account and the app offers to restore what the backup holds.
- Turning backup off, or deleting your Stylopia account, leaves your Drive as it is: those files are yours, in your own storage.
What is sent, and when
Only when you ask for something — never in the background:
- Wearing garments: the model on screen and the garments you chose go to the service, which asks an AI image model to dress the model and returns the result. Catalogue garments go by name, since the service already has their pictures. The model and your own designs go as a fingerprint of the picture, and the picture itself only if the service no longer has it.
- Building a model: what you send is the choices you made — a body, and a face if you picked one — not a picture. The service assembles the model from its own library.
- Designing or altering a garment: your written instructions and the garment you started from are sent; the AI model draws the new garment and, separately, suggests a name and a place in the wardrobe for it.
- Speaking instead of typing: if you dictate your instructions, your phone's own speech recognition turns them into text, under its own terms. We never receive the recording.
- Sharing to another app: the picture is made on your phone and handed to the app you choose. It does not pass through us.
Every picture sent is one the app made or shipped with. The service checks that before doing anything, and refuses a picture it cannot recognise as its own.
Who processes it
- OpenAI, L.L.C. (openai.com, United States) — its image model generates every result, and a language model suggests names for new garments. Under OpenAI's business terms, what we send is not used to train its models by default. The model a quality tier uses can change on our side without an app update; a provider is only ever used to make the one result you asked for, and only if it grants commercial use of that result.
- Google — sign-in, purchases through Google Play, and, if you turn it on, the backup in your own Google Drive, under your agreement with Google. If you are signed in, Google's Firebase Cloud Messaging also delivers our notifications to your phone, such as the one saying a friend joined from your invite.
- RevenueCat, Inc. (United States) — our payment service, which tells the service what was bought so your stitches can be credited.
What our servers keep
None of it is a picture of you. Some of it may be your ideas: the garments you design are kept for a while, as below. The words you write to design them are not kept.
- A working store of recent models and designs, so the next Wear or edit does not have to send them again. Ones not used for a while are cleared automatically.
- Results made only from what the app ships with — the sample model in the bundled garments, or a library face on a library body. They are kept and reused so nobody pays twice for the same picture, and nothing of yours can end up there.
- A record of every picture the service made: a fingerprint of the picture and whose it is. That is how the service recognises its own pictures. The record is not the picture.
- A short technical log of each request — the time, the kind of request, your account if you are signed in, and your internet address — deleted after 30 days.
- A random app identifier, which marks what you make as yours before you sign in. It identifies the app installation, not you or your device.
- Sharing inside Stylopia and Report a problem — see below.
If you sign in with Google
Signing in is optional. If you do, we store:
- Your Google account identifier, email address, display name, and profile picture URL — supplied by Google's own sign-in flow. We never see or store your Google password.
- A session token (hashed, not the raw token) so you can stay signed in.
- Your stitch balance and a record of your purchases.
- If you invite friends: the code in your invite link, and the private messages we send you inside the app, such as the one saying a friend joined and stitches were added. The message never says who joined.
- A one-way fingerprint (a hash) of your email address and of your Google account identifier, recorded the first time you sign in. It is how we make sure each account counts for an invite reward only once, and it cannot be turned back into your address. If you signed in from a friend's invite link, it also records that your sign-in earned them their reward.
- So that we can send you notifications: the notification address Google gives the app on your phone (a push token) and the language the app is set to. It is removed when you sign out on that phone, when Google reports it no longer works, and when you delete your account. Your phone's own settings can turn the notifications off at any time.
This is kept until you delete your account. Signing out revokes your session token immediately without deleting anything.
Sharing inside Stylopia
Sharing is always your own choice, one model or look at a time. Nothing is shared because you signed in, and nothing is public by default.
- Only models and looks the service made can be shared inside the app. This is enforced on our side, not just hidden in the interface.
- A shared model or look is stored on our servers while it stays shared, and served only to the people you chose.
- Stopping a share deletes it from our servers, and nobody can open it again. Someone who already viewed it may still have a copy of their own. We cannot reach that, and you should not share anything on the assumption it can be taken back.
- If you build a look from a model or look someone shared with you, they can see what you made with it.
Reporting a problem
If you use Report a problem, the model, your own designs and the result are uploaded; catalogue garments go by name. They are kept so we can investigate, reachable only by the operator over an administrative connection, and never served back to the app. They are deleted once the issue is closed; ask us and we will delete yours sooner.
What this app never does
- No analytics, no behavioural tracking.
- We do not sell or share your data, and use what you send only to make what you asked for.
- We do not train any model of our own on what you send.
Deleting your account
You can delete your account at any time:
- In the app: More → Delete account.
- On the web, if you no longer have the app installed: stylopia.app/delete-account.
This erases your account, your stitch balance, everything you shared and its files, everyone you granted access to, and your sign-in sessions. It cannot be undone, and stitch balances have no cash value and are not refundable.
Four things are deliberately kept, and none of them identifies you afterwards:
- Records of payments, as part of our own accounting. They no longer point to an existing account.
- Your username is retired, not released — it is never given to someone else. A username that a stranger could re-register would let them receive things other people meant for you.
- The fingerprints of your email and Google account, so that deleting an account and signing up again cannot earn the same invite reward twice. They are hashes, not your address, and no longer point to an account.
- Server logs keep their shape — an error, a request count — with your account identifier removed.
What is on your phone stays until you uninstall the app.
International transfer
The processors above are based in the United States, so what you send and your account data may be processed there, outside the country you're in.
Children
Stylopia is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.
Security
All traffic to the service runs over HTTPS. Session tokens are stored hashed, not in plain text. No system is perfectly secure, but we keep as little as the app needs to work.
Changes to this policy
We may update this page as the app changes. Material changes are reflected in the in-app privacy briefing shown before first use, which you're asked to accept again when it materially changes.
Contact
Mohammad Amiri Moalla — amiri.moalla@gmail.com