EveryCloset 隐私政策 · Privacy Policy

最后更新 / Last updated: 2026-10-06 · EveryCloset

概述

EveryCloset 是一款衣橱管理与穿搭记录 App。我们的原则很简单:衣橱内容默认只存在你的设备上;只有你主动使用云端或 AI 功能时,必要的数据才会离开设备。

我们不出售你的个人数据,不将数据用于广告定向,不追踪你跨 App 或网站的行为,也不会把你的照片用于模型训练。

1. 本机数据(默认不上传)

衣物照片、衣物属性、搭配、穿着记录、个人资料、灵感参考图、购物候选、旅行计划和风格报告默认保存在你的设备上,我们无法访问。

当你主动开启 iCloud 同步后,这些数据会同步到你自己的私人 iCloud 数据库(CloudKit 容器 iCloud.com.clcdreamland.everycloset)。该数据由 Apple 依据 iCloud 条款保管,我们无法读取其中的内容。

2. EveryCloset 服务账户(使用 Apple 登录后)

登录后,为了在设备间同步已购权益并防止额度被滥用,我们的服务器会保存:

关于邮箱的三点说明:

保留期:直到你注销账号。注销后这些数据会被删除。

3. AI 功能(需你明确同意后才会发送照片)

首次使用前,App 会单独征求你的明确同意,说明将发送什么、发送给谁、用于什么目的。你可以拒绝;拒绝后自动识别与风格画像补全将停止,手动录入不受影响。你可以随时在 App 的「关于 → 隐私政策 → AI 照片上传」中更改。

实际接收方

发送内容与用途

功能发送内容
衣物识别与风格画像你选择的衣物照片
AI 平铺图衣物照片
AI 试穿你的全身照 + 衣物照片
个人色彩分析你的面部照片
灵感分析你选择的参考穿搭照片
搭配 / 衣橱 / 购物 / 旅行建议文字描述与衣物属性(不发送照片),可能包含身高、身体尺寸、体型备注、风格偏好、常穿场景、颜色偏好、季节色彩类型;在你请求当日或行程建议时,还会包含你填写的城市名与你自行选择的气温区间

照片不会在我们的服务器上保存:服务器仅在内存中转发给上述服务商以完成你发起的那一次请求,请求结束后不落盘。我们不会将照片用于训练,也不会用于本政策未说明的用途。上述服务商可能在你所在地区之外处理数据。

面部数据:个人色彩分析与 AI 试穿

个人色彩分析是可选功能,使用一张你用 App 内相机当场拍摄的正面面部照片,不能从相册里选。这张照片在你的设备上完成分析:由 Apple 的 Vision 框架定位人脸,App 采样肤色、唇色、虹膜色的近似色值(HEX)与照片质量信号。发色不是从照片推断的,由你自己确认或填写。结果不会识别你的身份,也不会推断健康状况、年龄、种族或生物识别身份。

在 App Store 版本实际使用的配置下,面部照片本身不会上传。离开设备的只有推导出的色值(HEX)、数值化色彩维度、你确认的发色,以及你完成的色布选择;这些经 HTTPS 发送到我们的服务器,再转给 DeepSeek 生成文字说明,DeepSeek 始终拿不到面部照片。

该功能另有一个旧版分支,只有在 App 被显式配置为使用它时才会走到:此时裁剪后的面部照片会发送到我们的服务器,服务器仅在内存中转发给当次实际服务的视觉模型商。可能处理上传照片的公司为:阿里云通义千问(DashScope)、智谱(北京智谱华章科技)负责图像理解;火山引擎(北京火山引擎科技)负责图像生成;以及我们用作容量与故障转移的签约图像处理中转服务。该照片不写入磁盘、数据库、请求日志或分析记录,并在请求完成、取消或失败后即被丢弃。

AI 虚拟试穿会上传你提供的全身照与衣物照片,并转发给上述图像生成服务商。全身照通常会包含你的面部,因此同样适用本节的说明。

含面部照片的存放位置:我们的服务器从不保存。在你的设备上,你保存用于试穿的全身照(以及你设置的头像,如有)存放在 App 的数据库中;如果你开启 iCloud 同步,它们会一并保存在你自己的私人 iCloud 数据库里。除此之外不留存任何内容:服务器不保留可供再次使用的副本,色彩分析用的面部照片连本机也不保存——离开该流程即丢弃。由于我们不建立任何生物识别模板,因此并不存在可供比对的人脸特征数据。

保留与你的控制:传输中的照片只在你发起的那一次请求期间存在。在你的设备上,试穿照片与生成结果保留到你主动删除(个人资料 → 试穿照片 → 删除)或删除数据为止。第三方服务商对其收到的数据是独立处理者,可能按各自的安全、合规或运行条款保留记录;我们不持有可再次使用的副本,也无法代表其删除该等记录。任何照片上传前都需要你的明确同意(首次上传前在 App 内询问),你可以在「关于 → 隐私政策 → AI 照片上传」随时撤回,撤回后不再发起任何照片传输。

4. 天气与位置

本 App 不接入任何天气服务,也不读取你的位置:未申请定位权限,没有位置数据从设备发出,也不会由任何服务商代我们获取天气。

旅行计划里的气温区间由你点选(例如 12–19°C),它不是设备测温,也不是任何服务商提供的数据,而是你自己对目的地的判断。这个区间会随那一次 AI 打包请求发送到我们的服务器并转发给上述文本模型,用来决定哪些衣物适合这次旅行;不选则照常生成计划,只是不套用气温规则。

5. 购买与订阅

支付由 Apple 通过 StoreKit 处理,我们不接触你的支付卡信息。服务器会接收并校验 Apple 签名的交易凭证与 App Store 服务器通知,用于确认会员权益、处理退款与撤销。我们会保存交易号、商品 ID、金额与时间等记录用于对账;注销账号时这些记录会解除与账号的关联。

6. 反馈

你主动提交的反馈内容、分类与可选的回复邮箱会保存在我们的服务器,仅用于处理与回复这条反馈。注销账号时会被删除。

7. 诊断与用量数据

保留期:请求日志、服务商调用记录与诊断数据保留 180 天,之后自动删除;服务端 AI 对话记录保留 30 天,之后自动删除。

注销账号时,诊断与交易记录会解除与账号的关联后保留为匿名统计,以便我们如实统计稳定性与收入,不再能关联到你。

8. 安全

所有网络传输使用 HTTPS。服务器上的会话令牌与 Apple 刷新令牌加密存储;生产环境校验 DeviceCheck 凭据、限制请求体大小并启用限流。服务器按最小权限运行。

9. 你的控制与删除

你也可以通过下方邮箱联系我们请求协助。

10. 儿童

本 App 不面向儿童,我们不会有意收集儿童的个人数据。如果你是未成年人,请在监护人同意后使用。

11. 政策变更

本政策更新时,我们会更新本页顶部的「最后更新」日期;涉及数据用途的重大变更会在 App 内提示。

12. 个人信息处理者

本 App 的个人信息处理者为:Zhao Jingxi (赵境熙)。我们决定本政策所述个人信息的处理目的与处理方式,并对处理活动负责。

我们仅在本政策所述的范围内处理你的个人信息;超出范围或变更用途时会重新征求你的同意。

13. 联系方式

如对本政策或你的个人信息有任何疑问,或需要行使查阅、复制、更正、删除、撤回同意、注销账号等权利,请联系:2812453128@qq.com

我们会在收到你的请求后尽快处理,通常不超过 15 个工作日。


Overview

EveryCloset is a wardrobe management and outfit logging app. Our principle is simple: your wardrobe stays on your device by default, and data only leaves it when you deliberately use a cloud or AI feature.

We do not sell your personal data, use it for advertising, track you across other apps or websites, or train models on your photos.

1. On-device data (not uploaded by default)

Clothing photos, garment attributes, outfits, wear logs, your profile, inspiration references, shopping candidates, trip plans and style reports are stored on your device. We cannot access them.

If you turn on iCloud sync, this data syncs to your own private iCloud database (CloudKit container iCloud.com.clcdreamland.everycloset). Apple holds it under the iCloud terms and we cannot read its contents.

2. EveryCloset service account (after Sign in with Apple)

To sync purchased benefits across devices and prevent quota abuse, our server stores:

Three things worth knowing about the email:

Retention: until you delete your account, at which point these rows are deleted.

3. AI features (photos are sent only after your explicit consent)

Before the first upload the app asks for your explicit consent, stating what is sent, to whom, and why. You may decline; automatic recognition and style-profile backfill then stop, while manual entry keeps working. You can change this at any time in the app under About → Privacy Policy → AI photo upload.

Actual recipients

What is sent, and why

FeatureWhat is sent
Garment recognition and style profileThe clothing photos you select
AI flat layClothing photos
AI try-onYour full-body photo plus clothing photos
Personal colour analysisYour face photo
Inspiration analysisThe reference outfit photos you select
Outfit / wardrobe / shopping / trip adviceText descriptions and garment attributes (no photos), which may include height, body measurements, body-shape notes, style preferences, wearing occasions, colour preferences and seasonal colour type; plus the city name you typed and the temperature range you chose when you ask for a daily or trip recommendation

Photos are never stored on our server. They are forwarded in memory to the providers above to complete the single request you initiated, and are not written to disk. We do not train on your photos or use them for anything this policy does not describe. These providers may process data outside your region.

Face data: personal colour analysis and AI try-on

Personal colour analysis is optional. It uses one front-facing face photo that you take with the in-app camera; it cannot be chosen from your photo library. That photo is analysed on your device: Apple's Vision framework locates the face, and the app samples approximate skin, lip and iris colour values (HEX) plus photo-quality signals. Hair colour is not inferred from the photo — you confirm it yourself. The result does not identify you and does not infer health status, age, race or biometric identity.

In the configuration the App Store build actually ships, the face photo itself is not uploaded. What leaves your device is the derived colour values (HEX), the numeric colour dimensions, the hair colour you confirmed, and the colour-drape choices you made. They travel over HTTPS to our server and on to DeepSeek, which writes the explanation; DeepSeek never receives a face photo.

This feature also has a legacy branch, reachable only when the app is explicitly configured to use it. It sends the cropped face photo to our server instead, which relays it in memory to the vision provider serving that request. The companies that may process an uploaded photo are: Alibaba Cloud Qwen (DashScope) and Zhipu (Beijing Zhipu Huazhang Technology) for image understanding, Volcano Engine (Beijing Volcano Engine Technology Co., Ltd.) for image generation, and a contracted image-processing relay that we use for capacity and failover. The photo is not written to disk, our database, request logs or analytics, and it is discarded when the request completes, is cancelled or fails.

AI virtual try-on uploads the full-body photo you supply together with your garment photos and forwards them to the image-generation provider above. A full-body photo normally shows your face, so the same handling applies to it.

Where face-bearing photos are stored. Never on our server. On your device, the full-body photo you save for try-on (and your avatar, if you set one) lives in the app's database, and both are included if you turn on iCloud sync — in which case they are stored in your own private iCloud database. A generated try-on result stays in the app until you delete it, and you can copy it into the system Photos library yourself from the result screen; once it is there, it is governed by the Photos app and your iCloud Photos settings, not by us. Nothing else is kept: our server holds no reusable copy, and the face photo used for colour analysis is not stored even locally — it is discarded when you leave that flow. No facial-recognition template exists, because none is created; we build no biometric identifier of any kind.

Retention, and your control. A photo in transit exists only for the single request you started. On your device, the try-on photo and generated results are kept until you remove them (Profile → try-on photo → Remove) or delete the data. Third-party providers are independent controllers of what they receive and may keep records required by their own security, compliance or operational terms; we hold no reusable copy and cannot delete their records on their behalf. Every photo upload requires your explicit consent first — asked in the app before the first upload — and you can withdraw it at any time under About → Privacy Policy → AI photo upload, which stops all future photo transfers.

4. Weather and location

The app does not use any weather service and does not read your location. It requests no location permission, no location data leaves your device, and no provider fetches weather on our behalf.

The temperature range in a trip plan is chosen by you (for example 12–19°C). It is not a device reading and not supplied by any provider — it is your own judgement about the destination. That range travels with that one AI packing request to our server and on to the text models above, to decide which garments suit the trip. Choose none and the plan is still generated, simply without a temperature rule.

5. Purchases and subscriptions

Payment is handled by Apple through StoreKit; we never see your payment card details. Our server receives and verifies Apple-signed transactions and App Store Server Notifications to confirm membership, process refunds and revocations. We keep transaction records (transaction ID, product ID, amount, time) for reconciliation; deleting your account unlinks them from you.

6. Feedback

Feedback you submit, its category and an optional reply address are stored on our server only to handle and answer that feedback. They are deleted when you delete your account.

7. Diagnostics and usage data

Retention: request logs, provider-call records and diagnostics are kept for 180 days and then deleted automatically; server-side AI conversations are kept for 30 days and then deleted automatically.

When you delete your account, diagnostics and commerce records are unlinked from your account and retained only as anonymous statistics, so our reliability and revenue figures stay truthful without identifying you.

8. Security

All network traffic uses HTTPS. Session tokens and the Apple refresh token are encrypted at rest. Production verifies DeviceCheck credentials, caps request body size and applies rate limiting. The server runs with least privilege.

9. Your controls and deletion

You can also contact us at the address below for help.

10. Children

This app is not directed at children and we do not knowingly collect their personal data. If you are a minor, please use it with a guardian's consent.

11. Changes to this policy

When this policy changes we update the "Last updated" date at the top of this page. Material changes to how data is used are surfaced in the app.

12. Data controller

The controller of the personal information described in this policy is Zhao Jingxi (赵境熙). We determine the purposes and means of the processing described here and are responsible for it.

We process your personal information only for the purposes described in this policy; if we ever go beyond them we will ask for your consent again.

13. Contact

Questions about this policy or your personal data, or to exercise your rights of access, correction, deletion, withdrawal of consent, or account deletion: 2812453128@qq.com

We aim to respond as quickly as possible and normally within 15 business days.