Your wardrobe.
Your data.

Clear information about what Elnoly processes, why, and how you stay in control.

At a glance

  1. Local-first wardrobe
  2. Photos only when you use AI
  3. No ads or cross-app tracking

Privacy Policy

Last updated: September 9, 2026

On this page

What we process

This Privacy Policy applies to the Elnoly iOS app, its supporting API, and this privacy website. Elnoly is operated by an independent developer. The contact for the data controller is Petr.salsa@icloud.com.

Elnoly is designed to keep most of your information on your device. Sign in with Apple creates a pseudonymous Elnoly account used for paid AI features, App Attest security, purchases, support lookup, and account deletion. We do not sell personal data, serve advertising, or track you across apps or websites.

Information kept on your device

  • Wardrobe photos and garment details such as names, categories, colors, patterns, materials, brands, sizes, prices, purchase dates, notes, favorites, and archive status.
  • Outfits, planning dates, wear history, item usage counts, and related notes.
  • Style interactions, preferences, optional structured body-proportion and personal-color profiles, stylist memory, recommendations, and locally cached results. The source photos used to estimate those profiles are not saved by Elnoly.
  • Managed family profiles created by an adult account holder, including a name or nickname, broad age group, optional sizes, assigned garments, photos, and packing plans. These profiles have no separate login and are excluded from Elnoly Wardrobe Backup.
  • Purchase entitlement status supplied through Apple StoreKit. We do not receive your payment card details.
  • The name and email Apple supplies at sign-in, the app session, App Attest device state, and support ID needed to use and manage the pseudonymous server account. The readable name and email remain on the device; the Elnoly server receives only the verified identity token and stores one-way hashes as described below.
  • The most recent location used for local weather may be cached in the app's private on-device storage so a forecast and optional weather notification can be refreshed without building a location history. Elnoly 1.3 and later store only coordinates rounded to about one kilometre and delete them after no more than six hours.

Wardrobe garment details and catalog photos are backed up to private Elnoly storage under your pseudonymous account only if you turn on Wardrobe Backup in Profile → Privacy & Data. The setting is off by default. Depending on your Apple device and backup settings, local app data may additionally be included in an encrypted device or iCloud backup controlled by Apple.

Information processed by our service

  • Photos you intentionally select when using AI clothing analysis, catalog-image creation, an optional body-proportion profile, or an optional personal-color estimate, plus catalog photos and garment details stored when you enable wardrobe backup and restoration.
  • Garment metadata and random item identifiers needed to generate outfit recommendations. Stylist requests do not include wardrobe photos.
  • When you change the app language, garment names, types, colors, patterns, materials, styles, and seasons are sent in limited batches for AI translation. Brands are supplied only as translation context and should remain unchanged. Photos, notes, sizes, prices, and purchase dates are not sent. Translations are cached only on your iPhone and do not overwrite the original wardrobe data.
  • Messages you send to the AI stylist, up to a limited amount of recent chat context, and the wardrobe and preference context needed to answer. Chat text stays in the local conversation history and is not stored in the server-side stylist memory.
  • A limited server-side style profile and structured stylist memory under the pseudonymous account, including preferences and interactions with random item IDs. It does not contain wardrobe photos, garment names, or chat text.
  • Weather context, occasion, style preferences, and recent-wear information needed for a requested recommendation. Exact location is not sent to the Elnoly backend.
  • A public product URL you paste for shop import. The Elnoly API normally fetches the page and its public product-image metadata; failed imports may record the merchant host and a technical error reason, not the full pasted URL, in infrastructure logs.
  • Sign in with Apple identity tokens are sent to the Elnoly API for verification. We store one-way HMAC hashes of the Apple user identifier and, when Apple supplies it, the account email address. We do not store a readable Apple email, Apple password, or payment details.
  • Purchase and entitlement records needed to grant Premium and AI-photo credits, such as product and transaction identifiers, purchase, expiration or revocation dates, environment, and current balance. Apple processes payment-card details; Elnoly does not receive them.
  • Operational records such as request time, operation, model, success or error status, provider request ID, token usage, estimated cost, and limited derived clothing-analysis fields.
  • A one-way hash of the network IP address, grouped into one-minute windows, used only to prevent abuse and excessive requests. We do not store the raw IP address in our application database.

How AI features work

AI features are optional and run only when you choose to use them. Selected photos or relevant wardrobe metadata are encrypted in transit and sent to the dedicated Elnoly API hosted on Cloudflare at elnoly-api. The API sends the minimum content needed for the requested task to OpenAI.

  • Clothing analysis: the selected photo is processed to identify visible garments and their attributes.
  • Catalog-image creation: a selected garment crop is processed to produce a clean catalog presentation and checked against the source for identity consistency.
  • Manual catalog metadata: the cutout and white background are created on your iPhone. If you use the free metadata helper, the finished cutout is processed once to suggest editable garment details; it is not stored by the Elnoly backend.
  • Inspiration analysis: an inspiration image you choose is analyzed once to extract style signals. The image is not stored by the Elnoly backend.
  • Body-proportion profile: if you explicitly choose photo estimation, one full-body photo is processed once to derive broad clothing-relevant proportions. Elnoly does not store the photo; only a limited structured profile remains on your iPhone and is used as soft styling guidance.
  • Personal-color estimate: if you explicitly request it, one front-facing photo of your face and neck is processed once to estimate a 12-season color type and confidence. Elnoly does not store the photo; only the structured estimate remains on your iPhone. The feature does not identify you or infer ethnicity, health, or attractiveness, and a manually entered professional result can replace it at any time.
  • Product import: when you paste a public shop link, the Elnoly API normally fetches the public product page and image metadata to help you review or assess the item. If that request fails, the iPhone may fetch the same public page and product image directly. In that case, the shop or its image host receives ordinary web-request information such as your IP address, user agent, and language preference under its own privacy terms. Elnoly does not use the link for advertising or affiliate tracking.
  • Outfit stylist: shortlisted garment metadata, random item IDs, weather context, occasion, and relevant preferences are processed. Wardrobe photos are not sent for stylist recommendations.
  • Stylist chat and planning: your message or planning request, recent limited context, eligible wardrobe metadata, and relevant preferences are processed to answer or create a plan. Full chat messages remain local and are not added to server-side stylist memory.
  • Wardrobe translation: after you choose another app language, selected text fields from saved garments are translated in limited batches. No wardrobe photo is included and the translated display copy remains on your iPhone.
  • Visual outfit review: when a generated or manually composed outfit is visually checked, the app creates a temporary white-background preview from catalog photos and sends that preview to the AI without a photo of a person. The preview is not stored in the wardrobe backup or usage database.
  • Managed family wardrobes: an adult may create a local profile for a child or another family member. If the adult explicitly uses catalog AI, the selected photo is processed under the adult account with only the broad audience value child, teenager, or adult. The member name, exact age, and profile ID are not sent.

Photos are not stored in the Elnoly usage database or written to application logs. Source photos used for AI analysis and catalog requests pass through server memory only to fulfill the request. If you turn on Wardrobe Backup, final catalog photos are stored in the private Cloudflare R2 bucket elnoly-images under your pseudonymous user prefix. They are not sent to OpenAI merely because they are backed up.

OpenAI states that API data is not used to train its models unless the API customer explicitly opts in. OpenAI may retain API abuse-monitoring logs, which can include submitted content, for up to 30 days unless legal or security requirements require longer retention. See OpenAI platform data controls.

Location and weather

With your permission, Elnoly requests a new location only while the app is in use and asks iOS for kilometre-level accuracy. The app may keep the most recent location only in its private on-device storage to reuse the forecast and support an optional weather notification; it does not build a location history. Elnoly 1.3 and later round this cache to about one kilometre, expire it after no more than six hours, and remove it when local app data is deleted.

The app first uses Apple WeatherKit for local weather. If WeatherKit fails, it rounds latitude and longitude to about one kilometre and sends that approximate location directly to Open-Meteo for a fallback forecast. The Elnoly backend and OpenAI do not receive your current location.

For a travel plan, the destination text is sent to Apple's map service to find the place and to the Elnoly API and OpenAI as part of the requested plan. WeatherKit, or Open-Meteo as fallback, receives the destination coordinates needed for the forecast. The saved destination and finished plan remain on your device.

You can revoke access at any time in iOS Settings. See Apple WeatherKit and Open-Meteo terms.

Service providers

We use service providers only to operate requested features. They process information under their own terms and privacy commitments.

ProviderPurposeInformation involved
CloudflareAPI hosting, encrypted transport, App Attest verification support, rate limiting, D1 database, private R2 storage, shop-page retrieval, and securityRequests, selected AI content and pasted public shop links in transit, technical records, pseudonymous account records, hashed network identifier, and private uploaded images when used
OpenAIClothing, inspiration, body-proportion and personal-color analysis; catalog-image processing; garment consistency checks; wardrobe translation; stylist chat; product assessment; and outfit or travel recommendationsSelected photos, messages, destination and plan conditions, or the minimum wardrobe metadata and preference context needed for the requested AI feature
AppleSign in with Apple, App Attest, location permission, Maps place lookup, WeatherKit forecasts, StoreKit purchases, App Store update lookup, and optional device backupsAuthentication and device-attestation data, destination search text, approximate location for weather, purchase transactions, app identifier and storefront region for update checks, and backup data according to your Apple settings
Open-MeteoFallback weather forecasts when WeatherKit is unavailableApproximate rounded location sent directly from the app
Public shops and image hosts you chooseDirect fallback import of a public product page and image when the Elnoly API cannot retrieve itThe pasted public URL and ordinary web-request information such as IP address, user agent, and language preference, handled under that site's own terms
GitHubHosting this public privacy and support websiteGitHub logs visitor IP addresses for security; this website adds no analytics or advertising trackers

Providers may process data in countries outside your own. Where required, they use contractual and legal safeguards for international transfers. Their policies are available from Cloudflare, OpenAI, Apple, Open-Meteo, and GitHub.

Retention and deletion

  • Local wardrobe data: remains on your device until you delete individual items, use the in-app deletion action, delete your account, uninstall the app, or remove applicable backups through Apple.
  • Server account data: app sessions, App Attest records, style profile, structured stylist memory, purchase entitlements and transaction references, and the pseudonymous account record remain while needed to provide the service, until they expire or are rotated, or until you delete your account, subject to legal retention requirements for purchase and security records.
  • Wardrobe backup: when enabled, final catalog photos and garment details remain in private R2 storage under your pseudonymous account until you turn the backup off, delete the related item, choose “Delete local data and wardrobe backup,” or delete your account. Turning backup off keeps the local wardrobe and deletes the cloud copy. Uninstalling the app alone leaves an enabled backup available for restoration.
  • Photos handled for AI: source photos used for AI analysis are not retained in our usage database or application logs. OpenAI may retain abuse-monitoring data for up to 30 days as described above.
  • On-device weather location: may be held in private app storage to reuse local weather without creating a history. Elnoly 1.3 and later keep only an approximately one-kilometre location for less than six hours and delete it on expiry or when local app data is deleted.
  • Technical usage records: are retained for up to 90 days for reliability, cost control, security, and troubleshooting, then deleted.
  • Hashed rate-limit records: are retained for up to 48 hours, then deleted.
  • Support email: is retained for as long as needed to resolve the request and normally no longer than 24 months after the last communication, unless a longer period is legally required.

See the Data choices page for step-by-step deletion and permission instructions.

Your choices and rights

You control whether Elnoly can access Photos, Camera, and Location and whether Wardrobe Backup is enabled. You can revoke permissions in iOS Settings, turn backup on or off in Profile → Privacy & Data, and continue using features that do not require them. You can delete individual wardrobe items, stylist preferences, local app data together with the wardrobe backup, or the full Elnoly account from inside the app.

Depending on your region, you may have rights to access, correct, delete, restrict, or object to processing of personal data; receive a portable copy where applicable; withdraw consent; and lodge a complaint with your local data-protection authority. To make a request, email Petr.salsa@icloud.com.

For support or privacy lookup, use the anonymous Support ID shown in Profile after Sign in with Apple. Because Elnoly stores pseudonymous records and no readable Apple identity, this Support ID helps us locate your account without asking for wardrobe photos or sensitive information.

Legal grounds

Where the GDPR or similar law applies, optional permissions, wardrobe backup, and AI-photo processing rely on your request and consent; delivering requested app features is necessary to provide the service; and limited security, rate-limiting, and reliability records rely on legitimate interests in operating and protecting the service. You may withdraw consent by revoking a permission, turning backup off, or not using the optional feature.

Children

Elnoly is not directed to children and a child does not create a separate Elnoly account. An adult account holder may create a managed local wardrobe profile for a child or another family member. The adult controls the profile and can delete it in Profile → Active Wardrobe → Manage Family Members.

The profile name or nickname, broad age group, optional sizes, garments, catalog photos, and packing plans remain on the adult’s iPhone and are excluded from Elnoly Wardrobe Backup. If the adult explicitly invokes catalog AI, the selected photo is processed temporarily under the adult account with only a broad child, teenager, or adult value; the member’s name, exact age, and profile ID are not sent. Contact us if you believe information was provided without appropriate adult authority.

Changes

We may update this policy when the app, service providers, or legal requirements change. The “Last updated” date identifies the current version. Material changes will be presented through this page and, where appropriate, inside the app.

Contact

Questions, support requests, or privacy requests can be sent to:

Elnoly — independent developer
Email: Petr.salsa@icloud.com
GitHub: @petrsalsa-svg