Privacy policy
Privacy Policy — Vèra (iOS & Android app)
Last updated: 20 September 2026
This is the privacy policy for the Vèra mobile app on the App Store and
Google Play. It replaces, for the app, the founding-tester pilot policy at
privacy.html, which continues to cover only the Vèra web pilot and its
tester application form. If you used the web pilot, that policy still applies to
that experience.
Questions about your data: .
1. Who we are
Vèra is a personal wardrobe and styling app: you build a digital closet, get a style read, plan outfits, and — if you choose — preview clothes on a photo of yourself. Vèra is operated by Cannappy, the controller of the data described here.
You do not need an account, and we do not ask for your name, email address, or phone number to use the app. Signing in with Facebook is optional (§7). On first launch the app generates a private device code and stores it in your device's secure storage (the iOS Keychain / Android encrypted storage). That code is what the app trades with our server for a session, and it is the identifier your closet and usage are stored under. It stays on your device; we never link it to your name or email, because we never collect those.
2. What stays on your device and is never sent to us
- Photos of your clothes. When you add a piece, the photo is processed on your device, including background removal (the cut-out). The original clothing photo is never uploaded to us and never sent to analytics.
- Your full-body photo, by default. A photo of yourself that you set for try-on stays on your device unless and until you start a try-on and agree to the on-screen consent (see §4). It is never sent to analytics.
- Anything you type into the donation drop-off finder beyond what is needed for that one lookup (see §5), and your diary notes, a borrower's name for a lent item, and the reminder time you pick — these stay on your device and are never sent to us.
3. What the app stores on our server, and why
Your closet needs to survive reinstalling the app or moving to a new device, so the following is stored on our infrastructure (Cloudflare) under your device code:
| What | Why |
|---|---|
| Your style quiz answers and the style "reveal" they produce (aesthetic blend, style score). | To rebuild your profile and personalise suggestions. |
| Each closet piece's category, name, colours, wear count and when it was last worn; your saved looks; your week plan; lending and donation status. | So your wardrobe, history and plans are there when you reopen the app. |
We store the details of a piece (its type, colours, name), never the photo of it. Clothing photos stay on your device (§2).
You can erase this record from inside the app ("Reset my closet"), which deletes it immediately.
4. Try-on and scenes (only when you ask, and only with consent)
Vèra can preview an outfit on a photo of you ("try it on") and then restage that result in a shareable setting (a "scene"). These are the only features that send a photo of you off your device, and they run only after you agree on a one-time consent screen where you choose how your photo is handled.
- The try-on preview. When you start a try-on, a copy of your full-body photo and the cut-outs of the pieces you picked are sent — through our server (Cloudflare) — to our try-on provider, Runware (with fal as a fallback), to generate the image. There are two ways your photo is handled, and you choose:
- One-time: the copy is uploaded only for that one try-on and deleted from our storage the moment the try-on finishes, whether it succeeded or failed. A copy that was uploaded but never used is deleted within 30 minutes.
- Stored avatar (optional, one per account): you can instead keep the photo on our server as your reusable try-on avatar, so future try-ons show your own body and previous results can be reused without a fresh render. If you choose this, the photo is kept until you replace or remove it in the app; replacing or removing it deletes the previous photo.
- Scenes. After a try-on, you can restage that result in a setting (for example a red carpet or a magazine cover). Our server sends the try-on result — which already shows you — and the setting you picked to our image provider (Runware). Nothing new is uploaded from your device. The finished scene is held on our storage only until your app downloads it, and in any case no longer than one hour, then deleted. After that it exists only on your device.
Your photos are used only to create these images. They are never sent to analytics, never used for advertising, and never used to train models. If you decline the consent, nothing is uploaded and the preview stays on your device.
Try-on and scenes may cost in-app credits (see §8).
5. Weather and the donation drop-off finder
- Weather-aware suggestions use the climate you chose in the style quiz (for example "warm" or "cold"). The app does not read your device location and does not call any weather service to do this.
- The donation drop-off finder helps you find nearby places to donate clothes. The app does not read your device's GPS location. Instead you type a town or city, and that text is sent to OpenStreetMap's public services — Photon (to turn the place name into a point) and Overpass (to find drop-off spots nearby). What you type is used only for that lookup, is stored nowhere, and is never sent to Vèra. Opening directions to a spot hands the destination to your device's maps app.
6. Analytics (PostHog)
We use PostHog (hosted in the United States, us.i.posthog.com) to
understand how the app is used and improve it. Analytics is configured
conservatively:
- Autocapture is off and session recording/replay is off. We do not record your screen and do not capture raw taps or on-screen text. We send only a specific, named list of events.
- What those events contain: which screens and features you reach; your quiz answers as short labels (for example an aesthetic name or a count of occasions); counts and numbers (items added, your style score, timing); your device and OS type; app-generated identifiers (your device code, item and look identifiers); and an approximate location that PostHog derives from your IP address. The app itself does not request location permission.
- No photos, ever. No clothing photo, full-body photo, try-on result, or scene image is ever sent to analytics — this boundary is built into the app.
- Diagnostics. If the app hits an error, we send a truncated error message and whether it was fatal, so we can measure and fix crashes. We do not send stack traces from the app's analytics path, images, or your personal content.
- Feedback. If you choose to send feedback from your Profile, the text you write and your rating (if you give one) are sent to analytics.
- Your device code is the identifier events are grouped under. Because we never hold your name or email, this stays pseudonymous to us.
We do not use analytics for advertising, and we do not track you across other apps or websites.
7. Facebook: install measurement and optional sign-in
- Install and event measurement (Meta SDK). The app includes Meta's SDK so we can tell whether an install came from a Facebook or Instagram ad, and measure that ad. Meta receives that the app was installed and opened, basic device and app information, and your device's advertising identifier. On iOS the advertising identifier is read only if you allow tracking when the app asks; if you decline, it is not used. The SDK is not sent your closet, your photos, or anything you type. Meta handles what it receives under its own privacy policy.
- Continue with Facebook (optional). You can choose to sign in with Facebook. If you do, Meta shares with us the public profile fields you approve (your name and, if you allow it, your email address). We use them only to recognise you on a new device and to answer your requests. We do not post to Facebook or read your friends. You can remove Vèra at any time in Facebook under Settings, Apps and Websites; then ask us to delete what we hold (see the data deletion page).
8. Purchases
Vèra's try-on and scene features use in-app credits. Some try-on capacity is free (a small daily allowance); additional capacity may be offered as an in-app purchase.
When in-app purchases are enabled, they are handled by the App Store or Google Play, and validated for us by RevenueCat. In that case we (via RevenueCat) receive your purchase and entitlement status tied to your device code, and a store receipt to confirm the purchase — never your card number or full payment details, which are handled entirely by Apple or Google. We do not use purchase data for advertising.
9. Who we share data with
We share data only with the service providers that make the app work, each acting on our behalf:
- Cloudflare — hosts the app's backend, stores your closet record, and transiently holds a try-on photo or a scene image for as long as §3–§4 describe. No clothing photos.
- Runware (with fal as fallback) — our try-on / scene image providers. They receive a copy of your full-body photo and garment cut-outs only when you run a try-on you consented to, and a try-on result plus a setting only when you ask for a scene.
- PostHog — our analytics processor (§6).
- Meta — install measurement, and sign-in if you choose Facebook (§7).
- OpenStreetMap (Photon and Overpass) — only the town you type into the donation finder, and only when you use it (§5). No identifier is attached.
- RevenueCat and Apple / Google — only if you make an in-app purchase (§8).
We do not sell your data, we do not share it with data brokers, and we do not use it for cross-app advertising or tracking.
10. How long we keep it
- Closet record: kept while your app is in use, then deleted after a period of inactivity. "Reset my closet" deletes it immediately.
- One-time try-on photo: deleted when that try-on finishes (success or failure); if uploaded but never used, within 30 minutes.
- Stored avatar: kept until you replace or remove it in the app.
- Scene image: deleted as soon as your app downloads it, and within one hour regardless.
- Analytics: retained up to 12 months, then deleted or anonymised.
- Purchase/entitlement records (when purchases are enabled): kept as long as needed to provide and support your purchases and to meet legal and accounting obligations.
11. Your choices and rights
- You can use the app without ever running a try-on; decline the try-on consent and no photo leaves your device.
- You can remove a stored avatar at any time in the app.
- You can reset your closet at any time, which deletes your server record.
- You can ask us to see, correct, or delete your data by emailing ; the steps are on the data deletion page, https://vera.cannappy.org/data-deletion.
- If you are in the EU or UK, you have rights under the GDPR / UK GDPR, including access, correction, deletion and portability.
- If you are a California resident, you have rights under California privacy law to know what is collected about you and to request its deletion. We do not sell or "share" your personal information as those terms are defined there.
12. Children
Vèra is not directed to, and is not intended for, anyone under 18. We do not knowingly collect data from anyone under 18. If you believe a child has used the app, contact and we will delete the data.
13. Changes to this policy
If what we collect or how we use it changes, we will update this page and the date at the top.
Vèra · Cannappy