Privacy Policy

Nothing To Wear · Last updated 4 August 2026

Nothing To Wear is in private beta. This policy describes what the app does today. If we change what we collect or who we share it with, we will update this page and tell beta participants directly.

The short version

Who we are

Nothing To Wear ("we", "the app") is operated by Arianna Choza, an individual based in California, who is the controller of the personal data described below. You can reach us at hello@nothingtowear-app.com with any privacy question or request.

What we collect

Account information

You sign in with Google. From that sign-in we receive and store your name, email address, and profile photo URL. We never see or handle your Google password.

Account sign-in requests no access to your Gmail. Connecting Gmail is a separate, optional step with its own permission prompt, described below.

Your closet

Whatever you add to the app, whether typed in yourself or imported:

Gmail (optional)

If you choose to import from email, we ask Google for read-only access to your Gmail (gmail.readonly). This is what actually happens with it:

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used solely to provide the Gmail import feature you requested. We do not use it for advertising, profiling, marketing, model training, or any purpose unrelated to that feature, and we do not sell it. We do not transfer it to third parties except as necessary to provide the feature, for security, or when required by law.

You can revoke this access at any time at myaccount.google.com/permissions.

Product analytics — opt-in

When you first use the app we ask whether we may collect analytics. If you accept, we record which features you use and how you move through the app, tied to your account, using PostHog.

This includes session replay. Session replay records your interactions with the app so we can see where something broke rather than guess. Text you type is masked and is not captured in these recordings. Replay only runs for users who have opted in.

If you decline, none of this is collected. Before you answer, a small number of first-run events are held in your browser's memory only — never sent anywhere, never written to storage. If you accept, they are sent. If you decline, they are destroyed.

Crash reports — always on

Separately from analytics, we always collect crash and error reports through Sentry so we can fix what breaks. These contain the technical details of the failure — the error, where in the code it happened, and the app version. They are configured to minimize personal information and to exclude closet contents, Gmail message contents, and other user-provided content, and they include no session recording. This runs whether or not you accept analytics, which is why the in-app banner discloses it separately rather than asking permission for it.

Feedback

If you send feedback from inside the app, we store your message along with technical context to help us reproduce the problem: app version, the screen you were on, the page address, your browser's user-agent string, and your screen size.

Why we use it

Purpose Data used
Providing the app — storing and syncing your closet across devices Account information, closet contents
Importing items you asked us to import Gmail messages, read in your browser and not retained
Keeping the app working — diagnosing crashes and failures Crash reports, feedback
Improving the app — understanding which features are used Analytics, only with your consent

We do not sell personal data. We do not share it with advertisers. We do not use it to build profiles for anyone other than you, and we do not use your closet or your email to train machine-learning models.

Who else handles your data

We use a small number of service providers. They process data on our behalf, under their own security commitments:

Provider What they handle
Supabase Sign-in, database, and photo storage — this is where your closet lives
Vercel Hosting and delivery of the app itself
Google Sign-in, and the Gmail API when you connect it
PostHog Product analytics and session replay — only if you opt in
Sentry Crash and error reports

We may also disclose data if we are legally required to, or where it is necessary to protect the safety and security of the service.

How long we keep it

Your choices and rights

Depending on where you live, you may also have the right to access, correct, or restrict the processing of your data, to object to it, or to complain to a data-protection authority. Write to hello@nothingtowear-app.com and we will help.

Security

Your data is transmitted over encrypted connections and stored with per-user access rules enforced at the database level, so one account cannot read another's closet. The Gmail token is kept out of persistent storage specifically to reduce the damage a compromised browser could do. No service is perfectly secure, and this is beta software — please don't put anything in it you couldn't stand to lose.

Children

Nothing To Wear is not intended for children under 13, and we do not knowingly collect their data.

Changes to this policy

If this policy changes materially, we will update the date at the top of this page and notify beta participants by email.

Contact

Questions, requests, or complaints: hello@nothingtowear-app.com.