1. Scope and controller
This Privacy Policy applies to the Tessa’s Family Platform, including Closet, Pantry, Garage, Vanity, Cabinet, household profiles, private Locations, websites, accounts, memberships, marketplace features and related services. Tessa’s Closet LLCdetermines how account information is handled for these services.
2. Our privacy-first commitments
- No selling: we do not sell, rent, license or trade personal information.
- No advertising data sharing: we do not disclose personal information to advertisers, data brokers or unrelated marketers, and we do not use it for cross-context behavioral advertising.
- Completely ad-free: we do not display banner ads, native ads, paid product placements, sponsored search results or affiliate links. Brands cannot pay to appear in an outfit, recipe, Cabinet result, shopping suggestion or search result. Your own Shopping List and optional member marketplace are user-requested tools, not third-party advertising.
- No quiet repurposing: private photos, measurements, medicine inventory and household activity are used only to provide features you request, secure the service and meet legal obligations—not to create unrelated commercial profiles.
- No promotional spam: creating an account does not enroll you in marketing. We send necessary account, security, billing and service messages. Any future promotional newsletter requires a separate choice and an easy unsubscribe.
- Device-first media: private Closet, Pantry, Garage, Vanity, Cabinet, Location, body-reference and saved try-on images remain in storage controlled by your browser or personal device unless you deliberately request one-time processing or publish a seller image.
A secure account still requires a limited online record—such as your email, one-way password record or social-login identifier, session, membership, optional synced text details and transaction records. We describe those records below instead of pretending everything can stay offline while sign-in and synchronization still work.
One account; protected family content
Members may sign in with Email, Google, or ChatGPT. One account may identify a household across Closet, Pantry, Garage, Vanity and Cabinet and shares only the minimum account-level records needed for sign-in, family profiles, app access, membership, billing and referral rewards. Personal content is not used to target an upgrade, advertisement, sponsored placement or affiliate offer.
Authorized administrators may access account identity, membership, selected-app access, subscription and transaction records when reasonably needed to operate billing, grant complimentary access, prevent abuse or assist a member. Administrator access is role-based, can be limited to specific permissions, and material changes are recorded in an audit log. The administration system is intentionally separated from wardrobe and body photos, household inventories, receipt images, Location photos and other private family content.
Provider identities are matched to the member’s verified email and provider identity. A social identity already attached to another member is not silently reassigned.
Household profiles, Pet profiles, Fit Profiles and private Comfort Mode
Household managers may create family profiles for people and pets, assign or reassign items, record optional birth dates, gender choices, sizing and measurements, and coordinate occasion or travel plans. Human birth dates stay within the signed-in household account and may be used to calculate age so the Fit Profile avoids adult-only questions for young children. Pet profiles may include species, breed, birth or adoption date, weight, identifying details, veterinarian contact, feeding instructions, allergies, equipment sizes and household care notes. Hidden fields remain saved unless the member deletes them. Profile details are not public and are not used for advertising.
Gender and age guide which common human fit questions appear. Family Profiles provide Male and Female choices so measurements, sizing and Live Model references stay connected to the correct person. Pets do not receive human Fit Profile or clothing questions. Pet food, treats, medications, supplements, leashes, crates, carriers, grooming tools and other supplies may be associated with the pet across Pantry, Cabinet, Garage, Search and Shopping List.
Comfort Mode is optional and separate from Easy View, the readability setting. It may store information you enter about fluctuation, bloating or pressure, fit, fabric, temperature, coverage, easy foods and other comfort preferences. We do not diagnose health conditions, infer this information from behavior, include it in advertising or routine analytics. AI use requires a separate choice. Adults manage child and pet profiles.
3. Information we handle
| CATEGORY | EXAMPLES | WHERE IT LIVES |
|---|---|---|
| Private images | Closet, Pantry, Garage, Vanity, Cabinet and Location photos; real-life Looks & Events photos; body references; saved style canvases; and AI results | Your browser/device storage |
| Temporary AI working copies | A reduced clothing, grocery, tool or household-item copy and its finished catalog draft for a Smart Capture or Smart Intake job you start | Protected processing only; deleted after delivery or scheduled for expiration |
| Account details | Name, email, one-way salted password record when Email is used, provider identity, secure session records, app entitlements, plan and account status | Shared secure account service |
| Social sign-in | Google provider ID or ChatGPT authenticated email, plus name and email when you choose that button | Secure account database; provider passwords are never shared with us |
| Wardrobe metadata | Brand, size, category, color, one- through five-star rating, private fit/styling notes, wear history and saved outfit references | Device and, when signed in, account database |
| Measurements | Height, weight, body shape, fit notes and measurements you choose to enter | Account database; removable in Profile |
| Household and Comfort Mode | Family roles, person and pet item assignments, sizes, trip plans and optional private comfort preferences | Account database with profile-owner restrictions for Comfort Mode |
| Pet profiles | Optional species, breed, birth or adoption date, weight, identifying details, veterinarian contact, feeding instructions, allergies, care notes and equipment sizes | Private household account database; never public or used for advertising |
| Family Fit Profiles | Optional birth date, calculated age, gender choice, sizes, measurements, fit, style and comfort notes | Private household account database |
| Private Location Map | Human-readable indoor storage paths such as “drawer under the microwave,” confirmed labels and item-to-location links | Account database; reference photos remain on the device unless deliberately submitted for one AI analysis |
| Garage metadata | Tools, vehicles, maintenance, warranties, lending, seasonal storage and item locations | Device and, when signed in, account database |
| Vanity metadata | Makeup and personal-care names, brands, categories, family assignment, quantity, expiration and exact location | Account database; private product photos remain on the device |
| Medicine metadata | Medicine, first-aid and medical-device names; visible label details; family assignment; quantity; expiration; exact location; and optional family-profile allergy or prior-reaction notes | Private household account database; private product photos remain on the device |
| Cabinet Guide request | The selected family member, symptom description, duration, severity, saved allergy/reaction text and eligible saved non-prescription label facts | Transient AI request processing; the symptom request and generated guidance are not added to the household record |
| Search and Shopping List | Household search terms; Empty / Missing status; Need, In Cart and Put Away state; spoken text after your device converts it; and links to saved items | Private household account database and transient request processing |
| Module preferences | Which entitled spaces the household owner chooses to show or hide | Private household account database; hiding a space does not delete its data |
| Marketplace data | Deliberately published listings, member-selected photos, city-level location and private messages | Marketplace database and published image storage |
| Insurance & Replacement Value Vault | Replacement values, serial and contract numbers, appraisal details, collections and valuables, appliance and vehicle warranties, extended service plans, home warranties, coverage dates, claim contacts, photos and supporting documents | Encrypted device storage only. The vault passphrase is not received by Tessa’s and cannot be recovered by us. Encrypted backup files go only where the member chooses to save them. |
| Payments | Stripe customer/payment references, subscription status, invoices and transaction status | Stripe and limited references in our account database |
| Technical data | IP address, browser/device information, security and error records | Service and infrastructure logs |
4. The device-first photo vault
Private images are stored through browser-controlled device storage. We do not receive a copy simply because you add a Closet, Pantry, Garage, Vanity, Cabinet or Location item, or save a real-life outfit in Looks & Events. Clearing site data, deleting the installed web app, switching browsers or devices, using private browsing, or losing the device may remove those images. We cannot restore images we never possessed.
A reduced working copy leaves the device only after you deliberately request AI processing. A seller photo becomes cloud-hosted only when you intentionally publish it to the marketplace. The app identifies those steps before upload.
The Insurance & Replacement Value Vault adds a separate member-created encryption layer for values, appraisal files, receipts, warranty contracts and service plans. Tessa’s does not synchronize or index the decrypted Vault, receive the passphrase, or have a recovery key. Only the facts and optional item photo you deliberately send for one replacement-value estimate are processed for that request. Appraisal, warranty and service-plan documents are never sent to AI automatically.
5. How we use information
- Provide accounts, memberships, optional wardrobe syncing and requested features.
- Personalize requested outfit, packing, sizing, meal, Cabinet-label-review and marketplace features using the information you choose to provide.
- Use private fit and styling notes only as context for the features you request—not for advertising or an unrelated profile.
- Process membership payments and subscription changes. Tessa’s Marketplace does not process member-to-member purchases, seller payouts or marketplace fees.
- Secure the service, prevent fraud, enforce policies and troubleshoot errors.
- Send requested or necessary account, billing, renewal, security, policy and service messages.
- Comply with law and establish or defend legal claims.
We do not sell personal information, display third-party ads, accept sponsored placement, earn affiliate commissions, use personal information for behavioral advertising, or knowingly use private images to train a Tessa’s Closet model.
6. AI processing
AI image processing is opt-in. For Fast Capture, Bulk Upload, Smart Intake and Add While Shopping, the app first saves or prepares the selected source, then creates a separate reduced working copy for the protected job. Opening a screen does not transmit a photo.
The job may isolate a garment, grocery, tool, personal-care product or medicine package; read visible label details; prepare a clean catalog image; and suggest Closet, Pantry, Garage, Vanity or Cabinet. Uncertain details should be flagged for confirmation. AI does not prove product identity, quantity, expiration, food safety, ownership, medicine directions or correct storage. Review every result before saving.
Vanity AI Look Studio may process selected text-only Closet and Vanity details, an optional reduced outfit photo, occasion preferences and an optional adult portrait after separate consent. The outfit photo is used for the requested palette and style analysis. An AI Mirror portrait is used only to create that preview; the generated image returns to the device and is not saved to the household account. AI Mirror does not perform face identification, sensitive-trait inference or skin diagnosis. Saved look recipes may synchronize as text; any saved preview remains in browser-controlled device storage.
Cabinet Guide processes the selected family profile’s saved allergy/reaction text, the symptom description entered for that request and eligible saved non-prescription label facts. It screens for urgent language and may identify products whose saved Drug Facts uses are relevant enough to reread on the physical package or discuss with a pharmacist. It is not a diagnosis, prescription, dosage calculator, interaction checker or guarantee of safety or accuracy. Prescription, expired, allergy-matched and label-incomplete products are excluded from automated matching. The selected person’s allergy status must be confirmed before product matching.
Looks & Events and Try It on Me retain their separate opt-in controls and image limitations. Temporary working copies and delivered server results are deleted after successful delivery or automatic expiration under the service’s cleanup process. AI providers process a request only to provide the selected feature under their applicable business/API terms. Provider retention, security monitoring and legal obligations may still apply; do not submit information that is unnecessary for the request.
7. Private Locations, weather and camera access
The Tessa Location Map describes storage inside a home or other storage place. It does not require GPS coordinates, map pins or a street address. A family may save helpful paths such as “Kitchen → drawer under the microwave,” “Garage → workbench → lower cabinet,” or “Storage Unit 2 → Aisle B → Shelf 3 → Bin 6.” Multiple off-property units may be named by the household. Closed and open location photos remain on the device; a reduced copy is sent only when someone deliberately requests AI analysis, then confirmed labels and paths may sync to the household account.
Geographic location access is requested through your device only when you separately choose local weather or nearby marketplace features. We use it for the requested forecast, packing or matching experience; we do not add it to the private household Location Map, sell it or use it to build an advertising profile. Camera, microphone and photo-library access occur only after you choose a related action and remain subject to device permissions. Voice-list entry receives the text your device or browser produces, not permission to listen continuously.
11. Retention and deletion
We retain account and optional synced information while the account is active and as needed to provide the service. Temporary Smart Capture and Smart Intake job files are removed after the finished result reaches the device or scheduled for cleanup after 36 hours; an AI provider may separately retain request data for the limited period described in its API privacy commitments. After paid access ends, paid-tier cloud records and intentionally published seller-photo copies may be scheduled for deletion after a 30-day warning period. Private images already on your device are not remotely erased.
Membership billing, tax, fraud, security and dispute records may be retained longer when reasonably necessary or legally required. Deleting measurements does not automatically delete membership billing records or your entire account.
12. Your choices and privacy rights
You can edit saved details, delete device images, delete measurements, remove listings, manage billing and sign out through the app. You may request access, correction, deletion, removal of a Google or ChatGPT connection, or a portable copy of applicable account information through Account & Membership or by emailing us. We will verify requests reasonably and will not discriminate for exercising a privacy right.
Because we do not sell or share personal information for cross-context behavioral advertising, there is no advertising-data sale to opt out of. We will honor applicable privacy preference signals and provide legally required controls if our practices ever materially change.
13. Cabinet, allergies and consumer health information
Cabinet names, label facts, symptom text, allergy/reaction notes and family assignments may be sensitive consumer health information. Tessa’s is a household organization service, not a healthcare provider, pharmacy, insurer or HIPAA-covered medical record service. That does not reduce our privacy obligations: we treat Cabinet information as private, prohibit advertising and sale uses, minimize AI transmission and limit processing to the feature an adult deliberately requests.
If a qualifying security incident involves identifying health information, we will investigate promptly and provide notices to affected people and regulators as required by applicable law. Do not use Cabinet as the only copy of medical information needed in an emergency.
14. Security, incidents and international use
We use reasonable administrative, technical and organizational safeguards, data minimization and role-based access controls, but no internet service is perfectly secure. If we learn of a security incident, we investigate, contain and provide legally required notices. The service is operated from the United States. If you use it elsewhere, information processed online may be transferred to and handled in the United States.
15. Children and adult-managed family profiles
Tessa’s Closet is for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Children may not create accounts, accept terms, operate AI features or submit information directly. An adult account owner may enter limited information into an adult-managed child profile for family organization. If we learn that a child submitted personal information directly, contact us so we can review and delete it as appropriate.
16. Updates and contact
We may update this policy as features and laws change. We will post the revised effective date and provide additional notice when required.
Privacy or deletion request?
Email hello@tessascloset.com with “Privacy Request” in the subject line. Include the email used for the account and whether you want a social-login connection removed or the entire account deleted.
8. Google and ChatGPT sign-in
If you choose “Continue with Google” or “Continue with ChatGPT,” that provider confirms your identity and shares the identity information shown during sign-in, such as the name and email needed to create or locate your Tessa’s Closet membership. We do not receive or store your Google or ChatGPT password. ChatGPT sign-in does not independently share your conversations, memory, files, tokens, billing information or other ChatGPT account data with Tessa’s Closet.
When an authenticated provider email matches an existing Tessa’s Closet email, the social identity is linked to that same member so membership and closet records remain together. You can request removal of a social-login connection or deletion of the associated Tessa’s Closet account by contacting us below.