心橱 / Closet Dairy ← 返回首页 / Home

心橱隐私政策 / Closet Dairy Privacy Policy

生效日期 / Effective date: 2026-07-29

1. 适用范围与运营方 / Scope and operator

本政策适用于心橱 / Closet Dairy iOS App 及其配套服务。心橱由 App Store 产品页所列开发者运营,是本政策所述服务端数据的处理方。App 以本地衣橱数据为主,同时提供可选账号、订阅、天气、AI 识别和虚拟试穿能力。

This policy applies to the Closet Dairy iOS app and its supporting services. Closet Dairy is operated by the developer identified on its App Store product page and is responsible for the server-side processing described here. The app is local-first, with optional account, subscription, weather, AI recognition, and virtual try-on features.

2. 本地衣橱数据 / Local wardrobe data

衣物、穿搭、日历记录、旅行计划、分类、标签、品牌、尺码、颜色、收藏、废衣篓和本地图片默认保存在您的设备上。登录账号不会自动上传本地衣橱主数据。您主动导出的备份文件由您自行保管。

Your wardrobe items, outfits, calendar entries, travel plans, categories, tags, brands, sizes, colors, favorites, trash, and local images remain on your device by default. Signing in does not automatically upload the local wardrobe database. You control and safeguard any backup files you export.

如果您主动开启 iCloud 同步,衣橱主数据会通过 Apple CloudKit 保存到您 Apple ID 对应的 iCloud 私有数据库,用于您自己的多设备同步;该同步与心橱后端账号相互独立,并受 Apple 的 iCloud 条款与隐私政策约束。

If you enable iCloud sync, wardrobe data is stored in the private CloudKit database associated with your Apple ID for your own cross-device sync. This is separate from your Closet Dairy backend account and is governed by Apple's iCloud terms and privacy policy.

3. 账号、验证与订阅 / Accounts, verification, and subscriptions

Anonymous use creates a random account identifier and necessary device-identifier hashes for account separation, free entitlements, and abuse prevention. Sign in with Apple processes the identifier and any name or email you choose to share. Email sign-up or sign-in processes the address, an email hash, password hash, verification status, and sessions. Verification messages are delivered through Resend, while codes are stored only as short-lived hashes. StoreKit and the App Store process purchases and restores; our backend stores necessary transaction identifiers, subscription and entitlement status, AI-credit balances, and processing records.

4. 位置与天气 / Location and weather

天气功能仅在您授权“使用 App 期间”位置权限后请求当前位置。经纬度会发送到心橱后端,并按所请求的天气类型转发给彩云天气或 Visual Crossing,用于查询当前、明日、历史或旅行区间天气,以及生成穿搭推荐所需的天气信号。App 会在设备本地缓存天气结果和最近一次天气坐标以减少重复请求。

After you grant While Using the App location access, coordinates are sent to the Closet Dairy backend and, depending on the requested forecast, to Caiyun Weather or Visual Crossing. They provide current, next-day, historical, or travel-range weather and weather signals used for outfit suggestions. The app caches weather results and the latest coordinate locally to reduce repeated requests.

5. 照片、相机与用户内容 / Photos, camera, and user content

相机和相册权限用于添加衣物照片、保存处理后的图片、批量导入衣物和配置虚拟试穿头像。普通衣橱图片默认保存在设备本地。App 只会处理您主动选择、拍摄或保存的内容。

Camera and photo-library access are used to add clothing photos, save processed images, import items, and configure a virtual try-on avatar. Regular wardrobe images remain on device by default. The app processes only content you choose to capture, select, or save.

6. AI 与虚拟试穿 / AI and virtual try-on

AI 识别、批量补齐、对话推荐和虚拟试穿是可选功能。使用时,您选择的图片、衣物属性、文字提示、对话内容和必要的天气上下文会通过心橱后端发送给当前配置的 AI 服务提供商,以生成结果。App 会在首次启用相关能力前说明离端处理;虚拟试穿另有单独同意流程。

为转发 AI 图片,后端临时图片输入通常在 10 分钟后过期;虚拟试穿输入通常在 30 分钟后过期,服务端试穿结果通常在 24 小时后过期。您可在 App 中撤回相关授权、删除本地头像并清理本地试穿历史。AI 提供商对其收到数据的处理还受其自身政策约束。

AI recognition, bulk enrichment, chat recommendations, and virtual try-on are optional. Selected images, clothing attributes, prompts, conversations, and necessary weather context are sent through the Closet Dairy backend to the currently configured AI provider to generate results. Off-device processing is disclosed before activation, and virtual try-on has a separate consent flow. Temporary backend image inputs normally expire after 10 minutes; virtual try-on inputs normally expire after 30 minutes and server-side try-on results after 24 hours. You can revoke related consent, delete the local avatar, and clear local try-on history. The AI provider's own policy also applies to data it receives.

7. 服务提供商与披露 / Service providers and disclosure

为提供您选择的功能,我们可能使用 Apple(登录、CloudKit、StoreKit 与订阅)、Cloudflare(API 托管、数据库、安全与临时对象存储)、Resend(验证码邮件)、彩云天气和 Visual Crossing(天气),以及当前配置的 AI 服务提供商。我们只为提供功能、安全、计费、合规和支持所必需的目的传递数据。

We may use Apple for sign-in, CloudKit, StoreKit, and subscriptions; Cloudflare for API hosting, databases, security, and temporary object storage; Resend for verification email; Caiyun Weather and Visual Crossing for weather; and the currently configured AI provider. Data is disclosed only as needed for functionality, security, billing, compliance, and support.

我们不出售个人数据,不使用这些数据进行第三方广告,也不进行跨 App 或跨网站跟踪。除服务提供商外,只有在您指示、法律要求、保护用户和服务安全,或业务依法重组时才会披露必要数据。

We do not sell personal data, use it for third-party advertising, or track you across apps or websites. Apart from service providers, necessary data is disclosed only at your direction, when legally required, to protect users and the service, or as part of a lawful business reorganization.

8. 日志、安全与留存 / Logs, security, and retention

App 和后端可能记录请求 ID、错误码、接口状态、用量计数、AI 计费状态和订阅通知处理结果,用于安全、稳定性、额度控制、财务核对和问题排查。设计上不会在应用日志中保存明文访问令牌、第三方密钥、完整图片或 App Store 通知原文。

本地数据保留到您在设备、备份或 iCloud 中删除。服务端账号数据在账号有效期间保留;发起注销后账号进入删除处理中状态,并计划在 30 天处理期后清除可识别账号、会话、权益、用量和 AI 结果。为结算、退款、防欺诈或法定义务所需的最少财务记录可能在去标识化后继续保留。其他运行和安全记录仅在实现上述目的所需期间保留,之后删除或去标识化。

The app and backend may record request IDs, error codes, endpoint status, usage counts, AI billing state, and subscription-notification outcomes for security, reliability, quota enforcement, financial reconciliation, and troubleshooting. Application logs are designed not to contain plaintext access tokens, provider secrets, full images, or raw App Store notifications. Local data remains until you delete it from the device, backups, or iCloud. Server account data remains while the account is active. After an account-deletion request, the account enters a processing state and identifiable account, session, entitlement, usage, and AI-result data is scheduled for removal after a 30-day processing period. Minimum financial records needed for settlement, refunds, fraud prevention, or legal obligations may be retained in de-identified form. Other operational and security records are kept only as long as needed for these purposes, then deleted or de-identified.

9. 您的选择与权利 / Your choices and rights

You can revoke system permissions in iOS Settings; revoke AI or virtual try-on consent and clear related local data in the app; request account deletion in Account & Entitlements; delete device data in Data Management; cancel auto-renewal through Apple; and use the Support page to request access, correction, deletion, or an explanation of server-side account data we hold.

10. 儿童与跨境处理 / Children and international processing

心橱并非专门面向儿童设计。未达到所在地独立同意年龄的用户应在监护人同意和指导下使用。由于服务提供商可能在不同国家或地区处理数据,使用联网功能可能涉及跨境传输;我们会通过数据最小化、访问控制和服务商协议降低风险。

Closet Dairy is not directed specifically to children. Anyone below the age of independent consent where they live should use it with a guardian's consent and guidance. Because service providers may process data in different countries or regions, networked features can involve international transfers; we reduce risk through data minimization, access controls, and provider agreements.

11. 更新与联系我们 / Updates and contact

功能、服务提供商或法律要求发生重要变化时,我们会更新本政策、生效日期,并在适当情况下通过 App 或网站提示。隐私、账号删除、订阅和支持请求请通过帮助与反馈页面提交。

If features, providers, or legal requirements materially change, we will update this policy and its effective date and, where appropriate, provide notice in the app or on the website. Submit privacy, deletion, subscription, and support requests through the Support page.