privacy policy
effective date: april 10, 2026
introduction
Drape (“we,” “us,” or “our”) is an iOS application that lets you virtually try on outfits using AI and manage a digital wardrobe. This privacy policy explains what information we collect, how we use it, and the choices you have. It applies to all users of the Drape app.
This policy is effective as of April 10, 2026. If you have questions, you can reach us at hello@weardrape.app.
information we collect
information you provide
- Account information. When you create an account, we collect your email address, display name, and avatar URL. You can sign up with Apple Sign In or email. If you use Drape without creating an account, we assign a random installation ID (a UUID with no connection to your device identity) so your data can be preserved until you sign up.
- Face and body photos. During onboarding, you provide a selfie and body photo. These are used to generate your personalized AI model — an avatar that preserves your facial features for virtual try-on. Photos are resized to a maximum of 1024 pixels and compressed before any transmission.
- Clothing item photos. You photograph or import images of your clothing. Background removal is performed entirely on your device. Photos may be sent to our servers for AI-powered metadata extraction and image enhancement.
- Gender and body type. During onboarding, you can optionally select your gender (female, male, non-binary, or prefer not to say) and body type (slim, normal, or plus). These selections are used to customize AI-generated try-on images and select appropriate body templates.
- Style preferences. You choose one to four style tags (such as casual, streetwear, edgy, artsy, sporty, vintage, or formal) that are stored in your profile to personalize outfit suggestions.
- Onboarding survey answers. You may answer multiple-choice questions about your shopping frustrations. These responses are used for product analytics only and are not stored in your profile database.
- Clothing item metadata. For each item in your wardrobe, we store details such as name, category, colors, material, style tags, warmth, pattern, formality, brand, size, purchase price, and favorite or wishlist status. This metadata can be extracted automatically by AI or entered manually.
- Calendar entries and saved outfits. You can assign outfits to dates and save or bookmark curated outfit suggestions. This data is stored locally and synced to the cloud for Pro subscribers.
information collected automatically
- Analytics events. We collect product analytics events such as app opens, onboarding step completions, paywall impressions, and AI feature usage. These events are associated with your user ID to help us understand product usage patterns. No personal data such as names, emails, or photos is included in analytics events.
- Coarse location. With your permission, we access your city-level location to provide weather-based outfit suggestions through Apple WeatherKit. Location data is used ephemerally and is never stored on our servers.
- Subscription and purchase data.We record your subscription status, tier, billing period end date, and remaining AI credits. Purchase transactions are processed through Apple's App Store and managed by our subscription partner.
- Generation logs. When you use AI features, we log the function name, status, duration, and non-identifying metadata (such as selected gender and body type) for debugging and service reliability. These logs are deleted when you delete your account.
information from third parties
- Apple Sign In. If you sign in with Apple, we receive the user identifier, email address (which may be a private relay address), and display name that Apple provides.
- Subscription status. Our subscription management partner notifies us of purchase events, renewals, cancellations, and subscription transfers so we can update your account accordingly.
information we do not collect
We do not collect or use the Identifier for Advertisers (IDFA), Identifier for Vendors (IDFV), or any persistent device identifiers. We do not use advertising SDKs, cookies, or cross-app tracking technologies. We do not collect push notification tokens — all notifications are local to your device.
how we use your information
- Providing the core service. We use your photos, gender, body type, and style preferences to generate AI try-on images, extract clothing metadata, enhance product photos, and deliver personalized outfit suggestions.
- Managing your account. We use your email and display name to authenticate you, associate your data with your account, and communicate service-related information.
- Weather-based recommendations. We use your coarse location ephemerally to fetch weather conditions and suggest weather-appropriate outfits.
- Improving the product. We use analytics events to understand how the app is used, identify issues, and improve features. These events are linked to your user ID but do not contain personal details such as names, emails, or photos.
- Subscription management. We use purchase data to grant access to Pro features, track AI credit balances, and manage billing states.
- Debugging and reliability. We use generation logs to monitor AI service performance, diagnose failures, and maintain service quality.
how we share your information
We do not sell your personal information. We do not share your data with advertisers. We do not engage in cross-app tracking. We share data with third-party services only as necessary to operate Drape:
- Supabase(database, authentication, file storage, and server-side functions). Your account information, clothing metadata, and uploaded photos are stored on Supabase's US-based infrastructure. Supabase processes this data on our behalf to provide database, authentication, and storage services.
- RevenueCat (subscription and in-app purchase management). RevenueCat receives a randomly generated user identifier (not your email or name) and purchase transaction data to manage subscriptions, verify entitlements, and process billing events.
- Amplitude(product analytics). Amplitude receives event names, minimal string properties, and your user ID to provide product analytics. No names, emails, photos, or device identifiers are sent to Amplitude. Analytics data is processed in Amplitude's EU data center.
- Third-party AI image generation services (AI processing). Your photos are sent as encoded images to third-party AI services through our server-side functions for try-on image generation, metadata extraction, and image enhancement. These services process the images to produce results and do not retain your photos after processing is complete.
- Apple WeatherKit(weather data). Your location coordinates are sent to Apple's WeatherKit service to retrieve current weather conditions for outfit suggestions. Apple's privacy policy governs their handling of this data.
- Apple Sign In(authentication). If you choose to sign in with Apple, the standard Apple authentication flow is used. Apple's privacy policy governs their handling of authentication data.
We may also share information if required by law, legal process, or government request, or to protect the rights, safety, or property of Drape, our users, or others.
photo and image processing
Photos are central to how Drape works. Here is exactly what happens with your images:
onboarding photos
When you set up your profile, you provide a face photo and body photo. These are saved to your device and uploaded to our cloud storage. They are then sent to third-party AI services to generate your personalized user model — an AI avatar that preserves your facial features for realistic virtual try-on. Before any transmission, photos are resized to a maximum of 1024 pixels and compressed.
clothing photos
When you add clothing to your wardrobe, background removal is performed entirely on your device — no cloud processing is involved for this step. Clothing photos may be sent to AI services for automatic metadata extraction (identifying category, color, material, and other attributes) and image enhancement. For free users, clothing photos and wardrobe data remain entirely on your device. Pro subscribers' wardrobe data is synced to the cloud.
try-on generation
When you use the virtual try-on feature, your user model, face photo, and the selected outfit photo are sent to third-party AI services through our server-side functions. The AI service generates a composite image of you wearing the outfit. The result is returned to the app, stored locally, and stored in the cloud for Pro users.
pre-authentication uploads
If you provide photos before creating an account, they are uploaded using your random installation ID. When you later create an account, these photos are migrated to your authenticated user storage. The installation ID is not a device identifier and cannot be used to track you across apps.
sharing and saving
You can optionally save try-on results to your device's photo library or share them to social media. These actions are initiated entirely by you — we do not automatically share your images anywhere.
face data and biometric information
When you provide a face photo during onboarding, it is sent to third-party AI services to generate a personalized user model — an AI representation that preserves your facial features for virtual try-on. This process may involve analysis of your facial geometry.
We do not store biometric templates or facial geometry data. The AI service processes your face photo to generate try-on images in real time and does not retain biometric data after processing. Your original face photo is stored as an image file, not as a biometric template.
Your consent. By providing your face photo during onboarding, you consent to this processing. You can withdraw consent at any time by deleting your account, which permanently removes your face photo from our servers.
For Illinois residents: We collect and use your face photo as described above. Your face photo is sent to third-party AI services for processing. We do not sell, lease, or trade your face photo or any derived biometric data. Your face photo is retained on our servers as long as your account exists and is permanently deleted when you delete your account. The third-party AI service does not retain your photo after processing. By using the virtual try-on feature, you consent to this collection and use of your face photo.
data storage and security
We use industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS.
- Photos and account data are stored on Supabase's US-based infrastructure with row-level security policies that restrict access to authenticated users viewing their own data.
- Authentication is handled through Supabase Auth with support for Apple Sign In's privacy relay and token-based sessions.
- Server-side functions that process your photos run in isolated environments and do not persist image data beyond the processing request.
- For free users, wardrobe data is stored only on your device.
While we take reasonable steps to protect your information, no system is completely secure. We encourage you to keep your device secure.
your rights and choices
all users
- Access your data. You can view all data associated with your account within the app at any time.
- Delete your account. You can delete your account from the Profile section of the app. When you delete your account, we permanently delete all server-side data, including your profile, photos, wardrobe metadata, saved outfits, calendar entries, and generation logs. If you signed in with Apple, your Apple authentication token is revoked. Local files on your device remain until you uninstall the app.
- Withdraw consent for location.You can disable location access at any time through your device's Settings. Weather-based outfit suggestions will no longer be available.
- Use the app without an account. You can use basic wardrobe features without creating an account. Your data stays on your device until you choose to sign up.
California residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose about you.
- Request deletion of your personal information.
- Request correction of inaccurate personal information we hold about you.
- Opt out of the sale or sharing of your personal information. We do not sell or share your personal information as defined by the CCPA, so there is nothing to opt out of.
- Limit the use of sensitive personal information. We use your photos (which may constitute sensitive personal information) solely to provide the virtual try-on service you requested. We do not use sensitive personal information for purposes beyond what is necessary to provide the service.
- Non-discrimination for exercising your privacy rights.
To exercise these rights, contact us at hello@weardrape.app. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf. We may require the agent to provide proof of authorization and may still verify your identity directly.
European Economic Area, UK, and Swiss residents (GDPR)
If you are located in the EEA, UK, or Switzerland, you have the right to:
- Access, correct, or delete your personal data.
- Restrict or object to processing of your personal data.
- Data portability — receive your data in a structured, machine-readable format. Contact us to request a data export.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data protection authority.
Our legal bases for processing your data are:
- Performance of a contract — providing the wardrobe management, outfit suggestions, and account services you signed up for.
- Consent — processing your photos for AI virtual try-on, accessing your location for weather-based suggestions, and collecting analytics data. You can withdraw consent at any time by deleting your photos, disabling location access, or deleting your account.
- Legitimate interests — improving and securing our service, monitoring for abuse, and maintaining service reliability through generation logs.
To exercise these rights, contact us at hello@weardrape.app.
children's privacy
Drape is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@weardrape.app and we will promptly delete the data.
international data transfers
Drape is operated from the United States. Your account data and photos are stored on US-based infrastructure. When you use AI-powered features, your photos may be transmitted to third-party AI services that process data in international regions, including Asia-Pacific. Analytics data is processed in the European Union.
If you are located outside the United States, your information will be transferred to and processed in the United States and potentially other countries. For transfers outside the EEA, we rely on Standard Contractual Clauses approved by the European Commission, or your explicit consent where you initiate the use of AI features that require such transfers. You can request a copy of the applicable safeguards by contacting us.
data retention
- Account data and photos. Retained as long as your account exists. Permanently deleted from our servers when you delete your account.
- Local data. Wardrobe data, cached images, and locally stored photos remain on your device until you uninstall the app, even after account deletion.
- Generation logs. Retained as long as your account exists. Deleted when you delete your account.
- Analytics data. Analytics event data linked to your user ID is retained by our analytics provider according to their data retention policies. When you delete your account, we reset your analytics identity. However, previously collected event data may persist in aggregated form.
- Subscription records. Purchase and subscription history is maintained by Apple and our subscription management partner according to their respective retention policies.
- AI service processing. Third-party AI services process your photos in real time and do not retain them after processing is complete.
changes to this policy
We may update this privacy policy from time to time. When we make changes, we will update the effective date at the top of this page and notify you through the app. We encourage you to review this policy periodically.
If we make material changes to how we handle your photos or personal data, we will provide prominent notice within the app before the changes take effect.
contact us
If you have any questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:
- Email: hello@weardrape.app
- Website: weardrape.app
This privacy policy is governed by the laws of the State of California, United States, except where overridden by mandatory local data protection laws such as the GDPR.