Legal
Privacy Policy
Ojo Wardrobe App
Effective Date: August 15, 2026
1. Introduction
Welcome to Ojo ("we," "our," or "us"). We are committed to protecting the privacy of every user of our mobile wardrobe application ("the App"). This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what choices you have regarding your data.
By downloading or using the App, you agree to the collection and use of your information as described in this policy. If you do not agree, please do not use the App.
Developer / Data Controller: Ojo Studio, LLC · Contact email: support@ojoapp.io · Website: https://ojoapp.io
2. Information We Collect
2.1 Information You Provide Directly
When you create an account or use the App, you may provide:
- First and last name — used to personalise your account
- Email address — used to create and authenticate your account
- Password — if you sign up with email, your password is stored only as a salted cryptographic hash. We never store or have access to it in plain text. If you sign in with Apple or Google instead, no password is created
- Username — a display name of your choosing
- Date of birth — collected at sign-up to confirm you meet the minimum age requirement described in Section 9
- Location — either a city name you enter manually, or, if you choose "My Location," your device's GPS coordinates read on demand at that moment. The coordinates for the location you set are saved to your account so that scheduled notifications, such as your morning brief, can retrieve local weather while the App is closed. If you turn on Trip Mode, the App also reads your location on demand to detect when you have arrived at a saved trip destination. We do not track your location continuously or in the background, and we do not keep a history of where you have been
- Style preferences — your clothing style, temperature and humidity comfort thresholds, unit preferences, any additional cities you save, and — only if you choose to provide it — gender, which is used to tailor outfit suggestions
- Clothing item photos and metadata — images you upload or capture of your garments, plus descriptions, categories, colours, fabrics, and (optionally) merchant and purchase price
- Outfit wear history — records of which outfit suggestions you marked as "Wore this today," and the weather conditions at the time, which is what allows the App to learn your preferences
- Trip information (optional) — for trips you add, the airline, confirmation number, travel dates, origin/destination airports, and destination city, plus any outfit plans you build for them
2.2 Information Collected Automatically
When you use the App, we may automatically collect:
- Push notification token — a device-specific token used solely to deliver notifications you have enabled (e.g. morning brief, weather changes)
- Device information — device model, OS version, and app version
- Crash reports — error logs to help us identify and fix bugs
2.3 Information We Do NOT Collect
We do not collect financial or payment information, social media profiles, contacts, or biometric data of any kind. We do not track your location in the background, and we do not build an advertising profile about you — see the Location entry above for exactly how location is used.
2.4 Photo Recognition Happens On Your Device
When you photograph a garment, the App identifies what it is — the garment type, its dominant colours, and a best-guess fabric — using a machine-learning model that runs entirely on your device. Your photo is not sent to us or to any third party for that recognition step. Images are uploaded to our image storage only so your closet is backed up and available across your devices, as described in Section 4.
3. How We Use Your Information
We use the information we collect solely to operate and improve the App: account creation and authentication; generating personalised outfit suggestions based on your closet, preferences, and local weather; remembering your style preferences and outfit history across sessions and devices; producing your wardrobe insights and weekly recap; identifying gaps in your closet relative to your local weather; populating the home-screen and lock-screen widgets; sending notifications you have enabled; powering the optional trip planner and Trip Mode; and diagnosing crashes.
We do not use your data for advertising, and we do not sell your personal information to any third party.
4. How We Store and Protect Your Information
Your account data, closet metadata, outfit history, and trip information are stored in MongoDB Atlas, a cloud database service. The images of your clothing items are stored on Cloudflare R2, an object-storage service used as our image CDN; image filenames are random identifiers that contain no personal information. All data is transmitted over HTTPS/TLS encrypted connections, and access is limited to authorised systems.
Passwords are never stored in readable form — only as a salted bcrypt hash. Authentication tokens are held in your device's secure storage (iOS Keychain / Android Keystore).
If you add an Ojo widget to your home or lock screen, the App writes a small snapshot — today's outfit, the forecast, and thumbnail images — into a shared container on your device so the widget can render without a network call. That snapshot stays on your device and is removed when you delete the App.
No method of electronic storage or transmission is 100% secure. If a breach occurs that is likely to affect your rights, we will notify you promptly.
5. Third-Party Services
The App uses a limited number of third-party services to function. Each service receives only the data needed to perform its role:
- MongoDB Atlas — cloud database used to store your account, closet metadata, outfit history, and trip information.
- Cloudflare R2 — object storage used to host the clothing item images you upload or capture. Images are served via CDN over HTTPS.
- Apple WeatherKit — receives the latitude/longitude resolved from the city you have set in order to return local weather conditions. Apple does not receive your account identifier. See Apple's data-source attribution for the full list of data sources.
- Expo Push Notification Service — receives your device push token (and the contents of the notifications you have enabled) so it can deliver them to your device.
- Sign in with Apple (optional) — if you choose to sign in with Apple, Apple returns a stable identifier for your account and, on your first sign-in only, your name and email address. If you use Apple's "Hide My Email," we receive a private relay address instead of your real one, and that is all we ever see.
- Google Sign-In (optional) — if you choose to sign in with Google, Google returns your email address and basic profile information so we can create and authenticate your account. We do not request access to your Gmail, contacts, or any other Google data.
- Resend — transactional email provider used to deliver account emails such as password resets. It receives your email address and the contents of that message. We do not send marketing email.
- Open-Meteo — a free geocoding service used to power the city search box (e.g. when setting your default city or planning a trip). It receives the text you type and returns matching places with their coordinates. It does not receive your account identifier or any other information about you.
- Sentry — error and crash reporting. When the App or our API hits an error, Sentry receives the error itself, your device model, OS version, and app version, so we can find and fix it. We have switched off the features that would send more than that: it does not receive your IP address, it does not record your screen or your session, and it does not receive your console logs. It never receives your closet images, your outfit history, or the contents of your account.
5.1 Shopping Links
Where the App detects a gap in your wardrobe, it may offer a "Shop" link. Tapping it opens a Google Shopping search in your browser for a generic garment description such as "lightweight rain jacket." No account information, closet data, or identifier is included in that search, we receive nothing back from it, and we have no affiliate relationship with any merchant shown.
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may disclose your information only in these limited circumstances:
- Service providers: Third-party vendors (MongoDB Atlas, Cloudflare R2, Apple WeatherKit, Expo Push, Resend, and — if you sign in with Apple or Google — Apple or Google) acting on our behalf under their published privacy and security terms.
- Legal compliance: If required by law, court order, or governmental authority.
- Safety: To protect the rights, property, or safety of our users or the public.
- Business transfer: If we merge with or are acquired by another company, with advance notice to you.
7. Data Retention
We retain your personal information for as long as your account is active. Account data and wardrobe data are kept until you delete your account. Individual outfit wear-history entries are automatically deleted three years after the date they were recorded — this history is what lets the App learn your preferences over multiple seasons. You can clear your wear history at any time from within the App without deleting your account.
When you delete your account, your profile, closets, wear history, trips, and trip plans are erased immediately, and any remaining copies are removed within 30 days.
8. Your Privacy Rights
8.1 All Users
You may access, correct, or delete your data at any time within the App. To request a downloadable copy of your data, contact us at support@ojoapp.io.
8.2 California Residents (CCPA)
California residents have the right to know what personal information we collect, request its deletion, opt out of its sale (note: we do not sell data), and not be discriminated against for exercising these rights.
9. Children's Privacy
The App is not intended for children under the age of 13 and complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13.
We ask for your date of birth when you create an account, and we check it on our servers rather than only in the app. If you sign in with Apple or Google, neither service tells us your date of birth, so we ask you for it directly before the account can be used. Until we have it, the account cannot store or retrieve any of your information.
If the date of birth given puts you under 13, the account and everything stored in it are deleted rather than kept.
If you believe a child under 13 has provided us information under a different date of birth, contact us at support@ojoapp.io and we will delete it promptly.
Users aged 13–17 may use the App with parental awareness.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date and notify you via in-app notification or email. Your continued use of the App after changes constitutes acceptance.
11. Contact Us
If you have any questions about this Privacy Policy, contact us at support@ojoapp.io. We aim to respond within 30 calendar days.