EveryCloset 隐私政策 · Privacy Policy
概述
EveryCloset 是一款衣橱管理与穿搭记录 App。我们的原则很简单:衣橱内容默认只存在你的设备上;只有你主动使用云端或 AI 功能时,必要的数据才会离开设备。
我们不出售你的个人数据,不将数据用于广告定向,不追踪你跨 App 或网站的行为,也不会把你的照片用于模型训练。
1. 本机数据(默认不上传)
衣物照片、衣物属性、搭配、穿着记录、个人资料、灵感参考图、购物候选、旅行计划和风格报告默认保存在你的设备上,我们无法访问。
当你主动开启 iCloud 同步后,这些数据会同步到你自己的私人 iCloud 数据库(CloudKit 容器 iCloud.com.clcdreamland.everycloset)。该数据由 Apple 依据 iCloud 条款保管,我们无法读取其中的内容。
2. EveryCloset 服务账户(使用 Apple 登录后)
登录后,为了在设备间同步已购权益并防止额度被滥用,我们的服务器会保存:
- 账户标识:Apple 提供的用户标识经单向哈希后的值。它不是你的 Apple ID,也无法反推出你的 Apple ID。
- 联系邮箱:你在首次授权「通过 Apple 登录」时提供给 EveryCloset 的邮箱地址(你可能选择 Apple 的「隐藏我的邮箱」转发地址,见下)。它用于在账户层面识别你、处理你的求助与售后、以及在必要时就你的账户与你联系;我们不会用它发送营销邮件,也不会把它卖给或提供给任何第三方用于其自身目的。
- 设备标识:用于免费额度计数与设备绑定。
- 已购图像点数余额、订阅权益与到期时间。
- 会话令牌:注销账号后立即全部失效。
- 加密保存的 Apple 刷新令牌:仅用于在你注销账号时按 Apple 要求撤回 Sign in with Apple 授权;注销后即销毁。
关于邮箱的三点说明:
- Apple 只在你首次授权时把邮箱交给 App,之后不再重复提供。因此我们只能保存那一次收到的地址;如果你在 2026 年 10 月之前注册,我们的服务器当时没有请求过这个地址,也就无法事后补取。
- 如果你使用 Apple 的「隐藏我的邮箱」,我们拿到的是形如
xxxxx@privaterelay.appleid.com的中转地址。我们照原样保存和使用:发给它的邮件会由 Apple 转交给你,我们看不到你的真实邮箱。 - 它与「反馈」里可选填的回复邮箱是两回事:那是你在某一条反馈里单独留的地址。
保留期:直到你注销账号。注销后这些数据会被删除。
3. AI 功能(需你明确同意后才会发送照片)
首次使用前,App 会单独征求你的明确同意,说明将发送什么、发送给谁、用于什么目的。你可以拒绝;拒绝后自动识别与风格画像补全将停止,手动录入不受影响。你可以随时在 App 的「关于 → 隐私政策 → AI 照片上传」中更改。
实际接收方
- 文本与图像理解:DeepSeek、阿里云通义千问(DashScope)、智谱(北京智谱华章科技)
- 图像生成:火山引擎(北京火山引擎科技有限公司)、阿里云通义千问(DashScope,故障转移备用)
发送内容与用途
| 功能 | 发送内容 |
|---|---|
| 衣物识别与风格画像 | 你选择的衣物照片 |
| AI 平铺图 | 衣物照片 |
| AI 试穿 | 你的全身照 + 衣物照片 |
| 个人色彩分析 | 你的面部照片 |
| 灵感分析 | 你选择的参考穿搭照片 |
| 搭配 / 衣橱 / 购物 / 旅行建议 | 文字描述与衣物属性(不发送照片),可能包含身高、身体尺寸、体型备注、风格偏好、常穿场景、颜色偏好、季节色彩类型;在你请求当日或行程建议时,还会包含你填写的城市名与你自行选择的气温区间 |
照片不会在我们的服务器上保存:服务器仅在内存中转发给上述服务商以完成你发起的那一次请求,请求结束后不落盘。我们不会将照片用于训练,也不会用于本政策未说明的用途。上述服务商可能在你所在地区之外处理数据。
面部数据:个人色彩分析与 AI 试穿
个人色彩分析是可选功能,使用一张你用 App 内相机当场拍摄的正面面部照片,不能从相册里选。这张照片在你的设备上完成分析:由 Apple 的 Vision 框架定位人脸,App 采样肤色、唇色、虹膜色的近似色值(HEX)与照片质量信号。发色不是从照片推断的,由你自己确认或填写。结果不会识别你的身份,也不会推断健康状况、年龄、种族或生物识别身份。
在 App Store 版本实际使用的配置下,面部照片本身不会上传。离开设备的只有推导出的色值(HEX)、数值化色彩维度、你确认的发色,以及你完成的色布选择;这些经 HTTPS 发送到我们的服务器,再转给 DeepSeek 生成文字说明,DeepSeek 始终拿不到面部照片。
该功能另有一个旧版分支,只有在 App 被显式配置为使用它时才会走到:此时裁剪后的面部照片会发送到我们的服务器,服务器仅在内存中转发给当次实际服务的视觉模型商。可能处理上传照片的公司为:阿里云通义千问(DashScope)、智谱(北京智谱华章科技)负责图像理解;火山引擎(北京火山引擎科技)负责图像生成;以及我们用作容量与故障转移的签约图像处理中转服务。该照片不写入磁盘、数据库、请求日志或分析记录,并在请求完成、取消或失败后即被丢弃。
AI 虚拟试穿会上传你提供的全身照与衣物照片,并转发给上述图像生成服务商。全身照通常会包含你的面部,因此同样适用本节的说明。
含面部照片的存放位置:我们的服务器从不保存。在你的设备上,你保存用于试穿的全身照(以及你设置的头像,如有)存放在 App 的数据库中;如果你开启 iCloud 同步,它们会一并保存在你自己的私人 iCloud 数据库里。除此之外不留存任何内容:服务器不保留可供再次使用的副本,色彩分析用的面部照片连本机也不保存——离开该流程即丢弃。由于我们不建立任何生物识别模板,因此并不存在可供比对的人脸特征数据。
保留与你的控制:传输中的照片只在你发起的那一次请求期间存在。在你的设备上,试穿照片与生成结果保留到你主动删除(个人资料 → 试穿照片 → 删除)或删除数据为止。第三方服务商对其收到的数据是独立处理者,可能按各自的安全、合规或运行条款保留记录;我们不持有可再次使用的副本,也无法代表其删除该等记录。任何照片上传前都需要你的明确同意(首次上传前在 App 内询问),你可以在「关于 → 隐私政策 → AI 照片上传」随时撤回,撤回后不再发起任何照片传输。
4. 天气与位置
本 App 不接入任何天气服务,也不读取你的位置:未申请定位权限,没有位置数据从设备发出,也不会由任何服务商代我们获取天气。
旅行计划里的气温区间由你点选(例如 12–19°C),它不是设备测温,也不是任何服务商提供的数据,而是你自己对目的地的判断。这个区间会随那一次 AI 打包请求发送到我们的服务器并转发给上述文本模型,用来决定哪些衣物适合这次旅行;不选则照常生成计划,只是不套用气温规则。
5. 购买与订阅
支付由 Apple 通过 StoreKit 处理,我们不接触你的支付卡信息。服务器会接收并校验 Apple 签名的交易凭证与 App Store 服务器通知,用于确认会员权益、处理退款与撤销。我们会保存交易号、商品 ID、金额与时间等记录用于对账;注销账号时这些记录会解除与账号的关联。
6. 反馈
你主动提交的反馈内容、分类与可选的回复邮箱会保存在我们的服务器,仅用于处理与回复这条反馈。注销账号时会被删除。
7. 诊断与用量数据
- 应用事件:事件名称、应用版本、构建号。不包含衣橱内容、照片或你写的文字。
- 崩溃与卡顿诊断:由 Apple MetricKit 生成的错误类别、错误代码、应用与系统版本、设备型号。不包含照片、衣橱内容或自由文本。
- 请求日志:接口路径、状态码、耗时、应用版本,用于稳定性排查与限流。
保留期:请求日志、服务商调用记录与诊断数据保留 180 天,之后自动删除;服务端 AI 对话记录保留 30 天,之后自动删除。
注销账号时,诊断与交易记录会解除与账号的关联后保留为匿名统计,以便我们如实统计稳定性与收入,不再能关联到你。
8. 安全
所有网络传输使用 HTTPS。服务器上的会话令牌与 Apple 刷新令牌加密存储;生产环境校验 DeviceCheck 凭据、限制请求体大小并启用限流。服务器按最小权限运行。
9. 你的控制与删除
- 本机数据:设置 → 数据管理 → 删除本机数据。
- iCloud 数据:设置 → 数据管理 → 删除 iCloud 数据。
- 服务账户:设置 → 账户与点数 → 注销账号。这会同时撤回你的 Sign in with Apple 授权,并删除服务端账号及其关联数据(包括从 Apple 取得的联系邮箱、反馈、服务端对话与订阅关联)。它不会取消你的 App Store 订阅,也不会删除本机或 iCloud 衣橱数据。
- 已购图像点数不会随注销账号删除,这是刻意的。它们属于你的 App Store 购买而不是 EveryCloset 账号,所以注销不会收回你付过钱的点数——它们在本机仍可继续使用。它们与你没有任何可关联信息:记录只是一个由 App 保存的随机钱包标识和一个余额,不含姓名、邮箱或 Apple 标识。
- 保留的唯一记录:注销后,为满足安全与反滥用要求,我们会保留该 Apple 账号标识对应的一个会话版本号(不含任何内容),使注销前签发的登录令牌永久失效。
你也可以通过下方邮箱联系我们请求协助。
10. 儿童
本 App 不面向儿童,我们不会有意收集儿童的个人数据。如果你是未成年人,请在监护人同意后使用。
11. 政策变更
本政策更新时,我们会更新本页顶部的「最后更新」日期;涉及数据用途的重大变更会在 App 内提示。
12. 个人信息处理者
本 App 的个人信息处理者为:Zhao Jingxi (赵境熙)。我们决定本政策所述个人信息的处理目的与处理方式,并对处理活动负责。
我们仅在本政策所述的范围内处理你的个人信息;超出范围或变更用途时会重新征求你的同意。
13. 联系方式
如对本政策或你的个人信息有任何疑问,或需要行使查阅、复制、更正、删除、撤回同意、注销账号等权利,请联系:2812453128@qq.com
我们会在收到你的请求后尽快处理,通常不超过 15 个工作日。
Overview
EveryCloset is a wardrobe management and outfit logging app. Our principle is simple: your wardrobe stays on your device by default, and data only leaves it when you deliberately use a cloud or AI feature.
We do not sell your personal data, use it for advertising, track you across other apps or websites, or train models on your photos.
1. On-device data (not uploaded by default)
Clothing photos, garment attributes, outfits, wear logs, your profile, inspiration references, shopping candidates, trip plans and style reports are stored on your device. We cannot access them.
If you turn on iCloud sync, this data syncs to your own private iCloud database (CloudKit container iCloud.com.clcdreamland.everycloset). Apple holds it under the iCloud terms and we cannot read its contents.
2. EveryCloset service account (after Sign in with Apple)
To sync purchased benefits across devices and prevent quota abuse, our server stores:
- Account identifier: a one-way hash of the user identifier Apple provides. It is not your Apple ID and cannot be turned back into one.
- Contact email address: the address you share with EveryCloset the first time you authorize Sign in with Apple (you may choose Apple's Hide My Email relay instead — see below). It is used to identify your account, to handle your support and after-sales requests, and to contact you about your account when necessary. We do not use it for marketing, and we never sell it or hand it to a third party for that party's own purposes.
- Device identifier: used for free-tier counting and device binding.
- Purchased image-credit balance, subscription entitlement and expiry.
- Session tokens, all of which stop working immediately when you delete your account.
- An encrypted Apple refresh token, used solely to revoke your Sign in with Apple grant when you delete your account, and destroyed at that point.
Three things worth knowing about the email:
- Apple hands the address to the app only on the first authorization and never repeats it. So we can only keep the one we were given then. If you signed in before October 2026, our server had not asked for it and there is no way to go back and request it for an existing account.
- If you use Apple's Hide My Email, what we receive is a relay such as
xxxxx@privaterelay.appleid.com. We store and use it as given: mail sent to it reaches you through Apple, and we never see your real address. - It is separate from the optional reply address on a feedback submission, which is an address you type for one specific report.
Retention: until you delete your account, at which point these rows are deleted.
3. AI features (photos are sent only after your explicit consent)
Before the first upload the app asks for your explicit consent, stating what is sent, to whom, and why. You may decline; automatic recognition and style-profile backfill then stop, while manual entry keeps working. You can change this at any time in the app under About → Privacy Policy → AI photo upload.
Actual recipients
- Text and image understanding: DeepSeek, Alibaba Cloud Qwen (DashScope), Zhipu (Beijing Zhipu Huazhang Technology)
- Image generation: Volcano Engine (Beijing Volcano Engine Technology Co., Ltd.), Alibaba Cloud Qwen (DashScope, failover provider)
What is sent, and why
| Feature | What is sent |
|---|---|
| Garment recognition and style profile | The clothing photos you select |
| AI flat lay | Clothing photos |
| AI try-on | Your full-body photo plus clothing photos |
| Personal colour analysis | Your face photo |
| Inspiration analysis | The reference outfit photos you select |
| Outfit / wardrobe / shopping / trip advice | Text descriptions and garment attributes (no photos), which may include height, body measurements, body-shape notes, style preferences, wearing occasions, colour preferences and seasonal colour type; plus the city name you typed and the temperature range you chose when you ask for a daily or trip recommendation |
Photos are never stored on our server. They are forwarded in memory to the providers above to complete the single request you initiated, and are not written to disk. We do not train on your photos or use them for anything this policy does not describe. These providers may process data outside your region.
Face data: personal colour analysis and AI try-on
Personal colour analysis is optional. It uses one front-facing face photo that you take with the in-app camera; it cannot be chosen from your photo library. That photo is analysed on your device: Apple's Vision framework locates the face, and the app samples approximate skin, lip and iris colour values (HEX) plus photo-quality signals. Hair colour is not inferred from the photo — you confirm it yourself. The result does not identify you and does not infer health status, age, race or biometric identity.
In the configuration the App Store build actually ships, the face photo itself is not uploaded. What leaves your device is the derived colour values (HEX), the numeric colour dimensions, the hair colour you confirmed, and the colour-drape choices you made. They travel over HTTPS to our server and on to DeepSeek, which writes the explanation; DeepSeek never receives a face photo.
This feature also has a legacy branch, reachable only when the app is explicitly configured to use it. It sends the cropped face photo to our server instead, which relays it in memory to the vision provider serving that request. The companies that may process an uploaded photo are: Alibaba Cloud Qwen (DashScope) and Zhipu (Beijing Zhipu Huazhang Technology) for image understanding, Volcano Engine (Beijing Volcano Engine Technology Co., Ltd.) for image generation, and a contracted image-processing relay that we use for capacity and failover. The photo is not written to disk, our database, request logs or analytics, and it is discarded when the request completes, is cancelled or fails.
AI virtual try-on uploads the full-body photo you supply together with your garment photos and forwards them to the image-generation provider above. A full-body photo normally shows your face, so the same handling applies to it.
Where face-bearing photos are stored. Never on our server. On your device, the full-body photo you save for try-on (and your avatar, if you set one) lives in the app's database, and both are included if you turn on iCloud sync — in which case they are stored in your own private iCloud database. A generated try-on result stays in the app until you delete it, and you can copy it into the system Photos library yourself from the result screen; once it is there, it is governed by the Photos app and your iCloud Photos settings, not by us. Nothing else is kept: our server holds no reusable copy, and the face photo used for colour analysis is not stored even locally — it is discarded when you leave that flow. No facial-recognition template exists, because none is created; we build no biometric identifier of any kind.
Retention, and your control. A photo in transit exists only for the single request you started. On your device, the try-on photo and generated results are kept until you remove them (Profile → try-on photo → Remove) or delete the data. Third-party providers are independent controllers of what they receive and may keep records required by their own security, compliance or operational terms; we hold no reusable copy and cannot delete their records on their behalf. Every photo upload requires your explicit consent first — asked in the app before the first upload — and you can withdraw it at any time under About → Privacy Policy → AI photo upload, which stops all future photo transfers.
4. Weather and location
The app does not use any weather service and does not read your location. It requests no location permission, no location data leaves your device, and no provider fetches weather on our behalf.
The temperature range in a trip plan is chosen by you (for example 12–19°C). It is not a device reading and not supplied by any provider — it is your own judgement about the destination. That range travels with that one AI packing request to our server and on to the text models above, to decide which garments suit the trip. Choose none and the plan is still generated, simply without a temperature rule.
5. Purchases and subscriptions
Payment is handled by Apple through StoreKit; we never see your payment card details. Our server receives and verifies Apple-signed transactions and App Store Server Notifications to confirm membership, process refunds and revocations. We keep transaction records (transaction ID, product ID, amount, time) for reconciliation; deleting your account unlinks them from you.
6. Feedback
Feedback you submit, its category and an optional reply address are stored on our server only to handle and answer that feedback. They are deleted when you delete your account.
7. Diagnostics and usage data
- App events: event name, app version, build number. No wardrobe content, photos or user-written text.
- Crash and hang diagnostics: error category, error code, app and OS version, device model, as produced by Apple MetricKit. No photos, wardrobe content or free-form text.
- Request logs: endpoint path, status code, duration, app version, used for reliability and rate limiting.
Retention: request logs, provider-call records and diagnostics are kept for 180 days and then deleted automatically; server-side AI conversations are kept for 30 days and then deleted automatically.
When you delete your account, diagnostics and commerce records are unlinked from your account and retained only as anonymous statistics, so our reliability and revenue figures stay truthful without identifying you.
8. Security
All network traffic uses HTTPS. Session tokens and the Apple refresh token are encrypted at rest. Production verifies DeviceCheck credentials, caps request body size and applies rate limiting. The server runs with least privilege.
9. Your controls and deletion
- On-device data: Settings → Data Management → Delete local data.
- iCloud data: Settings → Data Management → Delete iCloud data.
- Service account: Settings → Account & credits → Delete account. This also revokes your Sign in with Apple grant and deletes the server-side account and its linked data — including the contact email obtained from Apple, plus feedback, server-side conversations and subscription links. It does not cancel your App Store subscription and does not delete local or iCloud wardrobe data.
- Purchased image credits survive account deletion, and that is deliberate. They belong to your App Store purchase rather than to your EveryCloset account, so deleting the account does not take back points you paid for — they stay usable on this device. Nothing links them to you: the record is a random wallet identifier the app holds and a balance, with no name, email or Apple identifier attached.
- The one record we keep: after deletion we retain a single session version number for that Apple account identifier (containing no content) so that any sign-in token issued before deletion stays permanently invalid. This is an anti-abuse and security measure.
You can also contact us at the address below for help.
10. Children
This app is not directed at children and we do not knowingly collect their personal data. If you are a minor, please use it with a guardian's consent.
11. Changes to this policy
When this policy changes we update the "Last updated" date at the top of this page. Material changes to how data is used are surfaced in the app.
12. Data controller
The controller of the personal information described in this policy is Zhao Jingxi (赵境熙). We determine the purposes and means of the processing described here and are responsible for it.
We process your personal information only for the purposes described in this policy; if we ever go beyond them we will ask for your consent again.
13. Contact
Questions about this policy or your personal data, or to exercise your rights of access, correction, deletion, withdrawal of consent, or account deletion: 2812453128@qq.com
We aim to respond as quickly as possible and normally within 15 business days.