Privacy Policy
Effective date: August 16, 2026
This policy explains what Rate The Fit ("we", "us") collects, why, and what control you have over it. We aim to keep it plain: we collect the minimum needed to rate your outfits and run the Service, we do not sell your data, and you can delete everything at any time.
1. What we collect
Photos you submit. When you rate an outfit, the photo you take or choose is uploaded to our servers, compressed, and stored so we can generate your rating and show your looks history.
Generated content. The score, verdict, commentary, suggestions, and AI-generated suggestion images tied to each of your looks.
Account data. If you create an account: your mobile phone number, handled by our authentication provider (Supabase). We use it to text you a one-time sign-in code and to identify your account. There is no password. We do not send marketing texts, and we do not share your number or your consent to receive texts with third parties for marketing purposes. Anonymous use requires no account.
Device identifier. A random UUID created on first launch and stored in your device keychain. It links your free anonymous rating and your looks to your device, and helps prevent abuse of free credits. It is not your advertising ID and it does not track you across other apps.
Billing data. If you subscribe, payment is handled by Stripe. We receive your subscription status and a Stripe customer reference; we never see or store your full card number.
Basic technical logs. Standard server logs (timestamps, request paths, status codes, approximate IP-derived region) kept briefly for security and debugging.
Product analytics. We use PostHog to understand how the app is used: which screens you open and which actions you take (for example, creating a rating or sharing a look), along with app lifecycle events. Once you sign in, these events are associated with your account identifier, an opaque random id, so we can tell repeat use from new use. We do not send your phone number, email address, or photos to PostHog. Automatic capture is switched off, so we only record the specific events we have deliberately added. We do not use PostHog analytics for advertising or sell analytics data.
Advertising measurement. We use Meta App Events to measure whether ads on Instagram or Facebook lead to app opens and a limited set of actions: completing onboarding, signing in, creating a rating, opening subscription checkout, and starting a trial. We ask for permission through Apple's App Tracking Transparency prompt before enabling this measurement. If you grant permission, Meta may receive Apple's advertising identifier (IDFA); if you decline, we do not collect it. We do not send Meta your phone number, email address, or photos. Apple may also provide Meta with privacy-preserving, aggregated attribution reports. We do not show ads inside Rate The Fit.
We do not collect your contacts or precise location.
2. How your photos are used
Your photo is sent to our servers and shared with our AI provider (Google Gemini) solely to produce your rating and generate suggestion images. Photos and generated images are stored in private storage and served back to you through short-lived signed URLs (valid about 7 days, refreshed on demand). We do not use your photos to train our own models, and we do not sell them. Our AI provider processes them under its API terms, which restrict use of customer data.
Looks you choose to share. Your looks are private by default. If you tap Share on a look, we create a link (for example https://www.ratethe.fit/fit/abc123) that shows that look's photo, score, and commentary to anyone who opens it, with no account required. The link contains a long random value so it cannot be guessed, but it is genuinely public: treat it like an unlisted page, and only send it to people you want to see the look. Nothing is shared until you tap Share, and deleting your account removes the shared page.
3. How long we keep things
Your looks (photos, generated images, ratings) are kept until you delete them or your account, so your history works as intended. If you rated anonymously and never sign up, your single look remains linked only to your device UUID. Server logs are retained for a short operational window and then discarded.
4. Who we share with
We share data only with the processors needed to run and measure the Service: Supabase (authentication and database), Twilio (delivering sign-in text messages), Google (AI rating and image generation), Stripe (payments), PostHog (product analytics), Meta (advertising measurement), and our hosting provider (Railway). Each receives only what it needs. We may disclose information if required by law or to protect the Service from abuse. We do not sell or rent personal information to anyone. Mobile phone numbers and text-message consent are never shared with third parties for marketing or promotional purposes.
5. Your controls
Delete your account. Settings → Delete Account permanently removes your account, all photos, generated images, ratings, your Stripe customer record, and cancels any active subscription. This is immediate and irreversible.
Access and correction. You can view your looks in the app at any time. For a copy of your data, or to change the phone number on your account, contact us.
Text messages. Reply STOP to any message to stop receiving texts, or HELP for help. Because texts are how we sign you in, opting out means you can no longer sign in by text.
Anonymous use. You can try the Service once without giving us any account information at all.
Depending on where you live (for example the EU/EEA, UK, or California) you may have additional legal rights, such as the right to access, port, correct, or erase your data, and the right to complain to a supervisory authority. Email us and we will honor them.
6. Security
Data travels over TLS. Images live in private buckets accessible only through signed URLs. Sign-in codes are single-use and expire quickly, and we never store a password; access tokens are stored in your device keychain, not in plain files. No system is perfectly secure, but if we learn of a breach affecting your data we will notify you as required by law.
7. Children
Rate The Fit is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has used the Service, contact us and we will delete the data.
8. Changes
If we materially change this policy we will tell you in the app before the change takes effect. The current version always lives in the app under Settings, and online at https://www.ratethe.fit/privacy
9. Contact
Privacy questions or requests: hello@ratethe.fit