Last updated: September 22, 2026
This policy describes what personal data we collect when you use STILGIA, how we use it and what your rights are. STILGIA is operated by an individual based in Germany (full details available on request to support@stilgia.com).
We collect only the data we need to make the app work: (a) email, name and a hashed password when you create your account with email; (b) one optional front photo to generate virtual try-ons (you can change or delete it at any time); (c) photos of the clothes you choose to upload to your wardrobe; (d) approximate location when you use the weather feature and, if you use STILGIA Loop, your device location as described in section 8; (e) your preferred language and theme; (f) the data required to process your subscription (we do not store card numbers — payments are handled by Apple and Google through their stores). If you sign in with Google, we receive your email address, your name and your profile picture and store them for your account; we do not store permanent Google tokens or your Google user ID. If you sign in with Apple, we may receive a stable Apple identifier, your real email or a Private Relay forwarding address, and your name when Apple provides it during the first authorisation; we do not store identity or refresh tokens. We do not use advertising trackers and we do not sell your data. Technical logs and diagnostic events: pseudonymised technical and diagnostic events about how the service behaves (errors, response times, which features are used, subscription conversions). These events carry an internal random user ID and a per-request correlation ID — never your name, email, photos, image URLs or free-text prompts.
Your data is used solely to: manage your account and authentication, organise your wardrobe, generate AI virtual try-ons and outfit suggestions, process subscription payments, send you functional notifications (not commercial) about your account, and provide support. We do not perform advertising tracking. We process the diagnostic events described in the section on data we collect in reliance on legitimate interest (Art. 6(1)(f) GDPR) to diagnose errors, keep the service secure and stable, and understand in aggregate how features are used so we can improve the service. These events are pseudonymised: they contain neither your name nor your email, but they remain linked to an internal identifier and we therefore treat them as personal data. You have the right to object to this processing at any time by contacting us (see the sections on your rights and contact); we will assess your request in accordance with Art. 21 GDPR.
To deliver the service we rely on these providers, which process data under their own data processing terms and agreements: Apple App Store and Google Play (payment processing and subscription management), Cloudinary (secure image storage), fal.ai (automatic background removal from clothing photos), Emergent Integrations (access to OpenAI / Anthropic / Google AI models for the virtual stylist and clothing analysis), Resend (transactional email delivery) and Open-Meteo (public weather data for the weather feature). Sentry (Functional Software, Inc.) — backend error monitoring; receives sanitised error reports with a pseudonymous user ID, never photos, image URLs, emails or request bodies. Sentry may process data in the United States; the safeguards applicable to those transfers are the ones Sentry documents in its privacy policy and legal documentation. See https://sentry.io/privacy/. Mixpanel, Inc. — product analytics with EU Data Residency (events stored in the EU); receives pseudonymised usage events only — feature used, latency, plan tier — never photos, URLs, emails or prompt text. See https://mixpanel.com/legal/privacy-policy/.
STILGIA's avatar uses an optional frontal photograph that may show your face and body. We only process the photograph you deliberately upload: we never extract, compute or store facial geometry, biometric templates or any biometric identifier. The image is used exclusively to generate your avatar and virtual try-ons; never for identification, authentication, facial recognition or advertising. All photographs are uploaded over HTTPS to Cloudinary, our image hosting provider. Each user's images are stored in a separate folder under a long, randomly generated identifier, and there is no public index or listing of any user's folder. Individual image URLs are not authenticated: anyone who obtains an exact link could access that image, so protection relies on transport encryption and on those URLs being practically impossible to guess. The app only ever exposes your own image URLs to you. To generate your avatar and virtual try-ons, the image is sent to Google Gemini (through our AI infrastructure provider, Emergent). We send the image only for the purpose of fulfilling your request and grant these providers no other use of it. Their handling of submitted data is governed by their own API terms and privacy policies. Retention: within our systems, face data is kept only until you delete it. Uploading a new avatar photo replaces the previous one; the old photo is scheduled for deletion from Cloudinary shortly afterwards (within minutes), and any copy that could not be removed at that moment is deleted at the latest when you delete your account. When you delete your avatar, the photo and the Try-On images generated with it are deleted from our systems and from Cloudinary as part of the same request; cached copies on content delivery networks may take a short additional time to expire. Deleting your account triggers erasure of the remaining images in our systems as part of the deletion request itself, and we commit to completing erasure from our systems within at most 30 days. Any retention by the third-party AI providers that processed an image is governed by their own terms (see the providers section). Processing of your photograph is based on your explicit consent. You can withdraw consent at any time from Settings → AI processing consent → Revoke, or by deleting the avatar. After you revoke it, the app will not start new AI image operations without asking for your consent again.
We keep your data while your account is active. Account deletion is available at the bottom of the Settings screen ("Delete account"). You will be asked to type a confirmation word before deletion proceeds. Deletion removes your images and records, subject to the exceptions described in this policy, in particular the retention rules (including the minimal residual billing record and legally required billing records) and the STILGIA Loop rules. You can also request deletion by writing to support@stilgia.com from the email address linked to your account. We commit to completing erasure from our systems within a maximum of 30 days. We may retain only: (a) accounting and billing records for the legal periods applicable in Germany, currently up to 8 years where required under §147 AO and §257 HGB — some of these records may be held by the payment processors (Apple, Google or others) that issued or handled the original transaction; (b) a minimal residual billing record of pseudonymised technical data — platform purchase identifiers and a one-way (hashed) form of your email address, never the email in clear text, and never your name, photos or content — only for as long as necessary to prevent fraud, resolve disputes, correctly process store subscription events that may arrive after deletion (such as refunds or renewals handled by Apple or Google) and support purchase recovery. Our telemetry records are automatically deleted from our systems after 90 days. When you delete your account, we immediately delete your telemetry and conversion records from our systems and irreversibly unlink AI technical metrics from your identifier. Pseudonymised events received by our analytics and monitoring providers (Mixpanel and Sentry) are retained in accordance with each provider's own retention policies.
As a user in the European Union you have the right to access, rectify, delete, object to or limit the processing of your data, and to data portability. To exercise these rights write to support@stilgia.com and we will reply within 30 days.
STILGIA is not directed to children under 16. We do not knowingly collect data from minors. If you believe a minor has shared information with us, please write to us and we will delete it.
Location. If you use STILGIA Loop, we use your device location to find garments near you. The location stored for a listing is approximate (snapped to a coarse grid of roughly one kilometre) together with a readable area label. Other users never receive your exact coordinates or address: they only see the approximate area and an approximate distance. The precise position used to calculate distances is processed for that purpose and is not publicly visible. Listings. When you publish a garment, the following may be visible to other nearby users: the garment photo, category/type, colours, size, condition, listing type (gift, sale or swap), price where applicable, description, approximate area and approximate distance, and your first name. Your email, phone number and exact location are never shown. Messages. Messages you exchange with other users about a listing are stored to provide the communication feature and for safety purposes. Reports and blocks. If you report a listing, conversation or user, we store the report (reason, optional comment and a minimal snapshot of the listing) to review it and to prevent abuse. Reported users are not told who reported them. If you block a user, we store the block relationship to enforce it in both directions. Certain report information may be retained in limited form where necessary for safety, investigation, abuse prevention and legal obligations. Transfers. When a Loop handover is confirmed, an independent copy of the garment's necessary information and image is created for the recipient's Wardrobe. That copy belongs to the recipient's records and may survive the later deletion of the previous owner's account. Account deletion. If you delete your account: your Loop listings are deleted; your conversations and messages are deleted; your blocks are removed; active handovers are cancelled; reports you made are anonymised; reports made about you may be retained in limited form for safety and legal reasons; and garments already transferred to other users remain in their Wardrobes as described above.
If we update this policy we will notify you in-app and show the new date at the top of this document. When changes are substantial we will request your explicit consent before applying them.
For any privacy question write to support@stilgia.com. We reply within 7 business days at the latest.