Privacy Policy
What we collect, why, who we share it with, and how you stay in control. Plain English, no dark patterns.
- Kapsee is run by condu s. r. o., a Slovak company. We are the data controller.
- We store your email, a hashed password, the photos you take (of a garment, or an ordinary photo that may show you wearing your clothes), the garment facts and crops we extract from them, your wardrobe items, and basic usage logs.
- Your photos are sent to AI providers to read what the garments are: Anthropic (Claude vision, shopping verdicts) and Google (Gemini, wardrobe-from-photo — only with your separate in-app consent). We name every processor below.
- For wardrobe-from-photo we blur other people's faces before the photo leaves our server, and we delete the original photo once you confirm your pieces (or automatically within 1 hour if you walk away). Only the crop of each garment stays.
- We never sell your data, run no ad networks, and our analytics is cookieless.
- You can download all your data or delete your account from inside the app at any time.
1. Who is responsible for your data
The data controller for Kapsee is:
- Company
- condu s. r. o.
- Registered office
- Hraničná 19068/34, 821 05 Bratislava – Ružinov, Slovak Republic
- IČO
- 54351448
- DIČ
- 2121649299
- IČ DPH
- SK2121649299
- Commercial register
- Obchodný register Mestského súdu Bratislava III, oddiel: Sro, vložka č.: 158391/B
- Contact
- hello@kapsee.com
We have not appointed a statutory Data Protection Officer, as we are not required to. For any privacy question, write to hello@kapsee.com and a human will answer.
Acceptance at registration. When you create an account, a checkbox asks you to confirm: "By creating an account you confirm you have read and agree to these Terms and our Privacy Policy." Ticking it records your acceptance of this Privacy Policy and our Terms of Service.
2. What we collect
| Data | Why we hold it |
|---|---|
| Email address | Your login identity, account recovery, and transactional email (e.g. password reset). |
| Password | Stored only as a bcrypt hash — we never keep the plaintext and cannot see your password. |
| Photos of clothing | The core of the app. You snap a garment; we process the image to understand what it is. |
| Wardrobe-from-photo images | An ordinary photo you choose to upload — it may show you wearing your clothes, or garments laid out. Processed only with your separate in-app consent (see section 3a). The original is deleted after you confirm; only the crop of each garment is kept. |
| Extracted garment facts | The structured attributes read from a photo (type, colour, pattern, material cues) that drive the verdict. |
| Photo consent record | The timestamp and version of the consent text you accepted for wardrobe-from-photo, so we can prove what you agreed to (GDPR Art. 7(1)). |
| Wardrobe items | The pieces you keep in your digital wardrobe so Kapsee can compare a new item against what you own. |
| Usage & security logs | Basic technical logs (timestamps, request/error info, IP for a short window) to run the service and prevent abuse. |
Planned, not yet collected: a price field per item is on our roadmap. If and when we add it, this policy will be updated before that data is collected.
We do not intentionally collect special-category data. A wardrobe-from-photo image may naturally show you — that's expected and handled as described in section 3a. Beyond that, please don't upload photos unrelated to your clothes.
3. Who processes your data (sub-processors)
To run Kapsee we rely on a small number of vetted providers. We share the minimum needed and only for the purpose below. This is the full list:
| Processor | What they do | What they receive |
|---|---|---|
| Anthropic (Claude vision API) | Reads your clothing photo to extract garment facts (type, colour, etc.). | The clothing photo you take, at the moment you request a verdict. This is a genuine cross-processor data flow and we disclose it plainly. |
| Google (Gemini API) | Powers wardrobe-from-photo: detects the garments in your photo and draws a clean product-style image of each piece. | The photo you upload for wardrobe-from-photo — after we blur other people's faces on our server, and only if you have given the separate in-app consent (section 3a). We use Google's paid API tier, where Google does not use your photos to train its models. |
| Resend | Sends transactional email (verification, password reset, account notices). | Your email address and the message content. |
| Hetzner | Hosting and servers. Infrastructure is located in Germany / the EU. | All application data at rest, as our hosting provider. |
Each provider processes data under its own data-processing terms. See Anthropic's privacy terms, Google's data processing terms, Resend's DPA, and Hetzner's privacy policy. Where a provider processes data outside the EEA, that transfer is governed by the safeguards in its terms (e.g. Standard Contractual Clauses). We do not use any advertising, data-broker, or tracking third parties.
3a. Wardrobe-from-photo, step by step
Since August 2026 you can build your wardrobe from an ordinary photo — one of you wearing your clothes, or of garments laid out. Because such a photo can show you (and possibly other people), it gets stricter handling than a plain garment snap:
- Consent first. The feature does nothing until you accept a short consent screen in the app. We record the date and the exact version of the text you accepted. You can withdraw this consent at any time in your account settings — the feature simply switches off.
- Other people's faces are blurred on our server before the photo is sent anywhere. If the photo contains one face, we treat it as yours and leave it as-is; if it contains two or more, all faces are blurred — recognising which one is you is exactly the kind of processing we don't want to do.
- The photo is sent to Google (Gemini) to detect the garments and draw a clean image of each piece. We use the paid API tier, where Google does not use your photos for training its models.
- You review the result — each detected piece side by side with the matching part of your photo — and confirm what goes into your wardrobe.
- The original photo is then deleted from our server. Only the crop of each confirmed garment stays. If you abandon the flow mid-way, the photo is deleted automatically — drafts expire after 1 hour and a cleanup job removes the file.
4. Why we're allowed to process it (lawful bases)
- Performance of a contract (GDPR Art. 6(1)(b)). Storing your account, wardrobe and photos and returning verdicts is the service you signed up for.
- Legitimate interests (Art. 6(1)(f)). Keeping the service secure, preventing abuse, and basic diagnostics. We balance this against your rights.
- Consent (Art. 6(1)(a)) for wardrobe-from-photo — processing a photo that may show you, including sending it to Google as described in section 3a. Given in-app, recorded with date and text version, withdrawable at any time in account settings. Withdrawal doesn't affect processing that already happened.
- Consent (Art. 6(1)(a)) also covers any optional communication you opt into. You can withdraw consent at any time.
5. How long we keep it
We keep your data for as long as your account exists. When you delete your account, your personal data — including your photos, extracted facts and wardrobe — is deleted. Short-lived technical logs age out on their own. Backups roll over on their normal cycle. We may retain the minimum required by law (e.g. accounting records) where a legal obligation applies.
One exception is shorter than that: the original photo you upload for wardrobe-from-photo is deleted as soon as you confirm your pieces, and at the latest about an hour after upload if you don't finish the flow (section 3a). We keep only the garment crops you confirmed.
6. Your rights
Under GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to certain processing. Two of these are built right into the app:
- Download my data (export). Export a copy of your account data from your account settings — this is a live feature, not a request form.
- Delete account. Permanently delete your account and associated personal data from account settings.
- Rectification. Correct your email and account details in settings at any time.
You can also exercise any right by emailing hello@kapsee.com. You have the right to lodge a complaint with the Slovak supervisory authority, the Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk), or with the authority in your EU country of residence.
7. Security
Passwords are stored only as bcrypt hashes. Access to production data is limited. We host within the EU with Hetzner. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
8. Cookies & analytics
Kapsee uses a single strictly-necessary cookie (capsule_session) to keep you logged in, and privacy-friendly, cookieless analytics (Umami) that sets no cookies and does not track you across sites. Full detail in our Cookie Notice. We do not sell data and use no advertising cookies.
9. Children
Kapsee is not intended for anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected here with a new "last updated" date, and where required we'll notify you. Continued use after an update means you accept the revised policy.
In one line
Your photos, your wardrobe, your call. We process what we need to answer "yes or no", we name everyone who touches it, and you can take it all back with one tap.
See also: Terms of Service · Cookie Notice · Imprint.