Privacy Policy
Effective date: September 29, 2026
Introduction
ChicUp is operated by Brito Labs LLC, a Florida limited liability company (“Brito Labs,” “ChicUp,” “we,” “us,” or “our”). This Privacy Policy explains how information is collected, used, disclosed, retained, and deleted when you use the ChicUp mobile application, website, and related services.
By using ChicUp, you acknowledge the practices described in this Privacy Policy.
Information we collect
Account information
When you use Sign in with Apple, we may receive:
- Your Apple account identifier
- Your name, if you choose to share it
- Your email address or Apple private relay email, if you choose to share it
Profile and personalization information
We may collect:
- First name
- Optional tagline
- Optional profile photo
- Styling goals and style context
- Silhouette and fit preferences
- Height
- Color preferences
- Womenswear or Menswear preference
- Style swipes and favorite styles
- Other optional onboarding answers
Wardrobe and styling information
We may collect and store:
- Wardrobe items and item photographs
- Clothing category, color, material, pattern, style, and fit
- Optional brand, price, and size
- Outfit photographs
- Saved and favorite outfits
- Outfit scores and feedback
- Generated looks, descriptions, and preview images
- Detected clothing attributes
Subscription and transaction information
Apple processes payments. We do not receive or store complete payment-card information.
We may receive and store:
- Subscription product
- Subscription status
- Purchase and renewal dates
- Transaction identifiers
- Price and storefront country
- Eligibility and entitlement information
Approximate location
ChicUp may request approximate location while the app is in use. Approximate location is sent to Apple WeatherKit and Apple geocoding services to provide weather and display a city on the Outfit Score screen.
We do not request precise location. The city is not stored in our database and is not included in shared images.
Diagnostic and performance information
Firebase Crashlytics and Firebase Performance Monitoring may process:
- Crash reports and stack traces
- Device model
- Operating-system version
- App version
- Installation identifier
- App-start timing
- Network-performance timing
- IP address as part of normal network communication
- Technical error information
ChicUp does not use Firebase Analytics and does not track in-app interactions for advertising or behavioral profiling.
Support communications
If you contact us, we receive the information you provide, including your email address, message, and any attachments you choose to send.
How we use information
We use information to:
- Create and maintain accounts
- Authenticate users through Sign in with Apple
- Build and organize digital wardrobes
- Personalize outfit recommendations
- Detect and categorize clothing
- Score and explain outfits
- Generate look previews
- Save outfits, favorites, and preferences
- Provide weather-aware styling information
- Process and verify subscription access
- Restore purchases
- Provide customer support
- Diagnose crashes and improve reliability and performance
- Protect ChicUp against abuse, fraud, and security threats
- Comply with legal obligations and enforce our Terms
AI and photo processing
ChicUp resizes photographs before processing.
- Anthropic receives resized copies of up to approximately 1024 pixels for outfit scoring and clothing detection, along with relevant clothing attributes and style preferences. It does not receive your name, email, account identifier, or location from ChicUp.
- OpenAI receives cropped clothing images and clothing descriptions to generate look-preview images. It does not receive your name, email, account identifier, or location from ChicUp.
- remove.bg receives cropped garment images to remove their backgrounds. It does not receive your account or profile information from ChicUp.
We store submitted photos, detected clothing attributes, scores, feedback, generated-look text, and generated images. We do not store raw prompts or raw AI responses.
We do not train our own models using user photos. Based on the commercial API services used for the release build, Anthropic and OpenAI do not use submitted API data to train their models by default. Anthropic and OpenAI generally delete API inputs and outputs within approximately 30 days, subject to their policies and limited exceptions. remove.bg generally deletes submitted images within approximately 60 minutes.
ChicUp does not perform facial recognition, identity matching, biometric analysis, or create face templates. On-device body-position detection may be used solely to assist with photo framing.
Service providers
We use the following service providers:
- Apple: Sign in with Apple, In-App Purchase, WeatherKit, geocoding, location services, and the iOS share sheet
- Google Firebase: Authentication, Firestore, Cloud Storage, Cloud Functions, Crashlytics, and Performance Monitoring
- RevenueCat: Subscription management, purchase history, entitlement status, device information, country or locale, and related subscription processing
- Anthropic: Clothing detection and outfit scoring
- OpenAI: Generation of look-preview images
- remove.bg: Garment-background removal
Kingfisher is used for local image caching and Lottie is used for animations. These libraries do not independently collect user information in the ChicUp release build.
Service providers process information to perform services for ChicUp and are subject to their own terms, privacy policies, and contractual obligations.
Data storage and international processing
ChicUp’s primary database, file storage, and server functions use Google Cloud’s us-central1 region in the United States.
Some infrastructure and service providers may process limited information through global systems or in other jurisdictions. Anthropic and OpenAI process ChicUp API data in the United States. remove.bg is based in the European Union and may process garment images there.
By using ChicUp outside the United States, your information may be transferred to and processed in countries with different data-protection laws. Where required, we use appropriate contractual and legal protections.
Retention
We retain active account information, profile information, onboarding answers, wardrobe data, photographs, outfits, scores, favorites, and generated looks until the user deletes the relevant content or account.
Additional retention periods include:
- ChicUp server logs: up to 30 days
- Deleted files recoverable by ChicUp: up to 7 days
- Google administrative audit logs: up to 400 days; these concern infrastructure administration and do not contain user photo content
- Anthropic and OpenAI API inputs and outputs: generally deleted within approximately 30 days, subject to provider policies and limited exceptions
- remove.bg garment images: generally deleted within approximately 60 minutes
- RevenueCat: pseudonymous transaction records may be retained for accounting, refunds, fraud prevention, and subscription administration
We may retain information longer where required by law, necessary to resolve disputes, prevent fraud, or enforce agreements.
Account deletion
Users can delete their accounts through:
Profile → Account & Settings → Delete Account
Account deletion removes ChicUp’s active copies of:
- Firebase Authentication account
- Profile and profile photo
- Onboarding answers
- Wardrobe items and photographs
- Outfits and photographs
- Scores and feedback
- Generated and favorited looks and images
- Subscription records stored by ChicUp
- Other user-linked application records
It also revokes Sign in with Apple access and clears local ChicUp data from the device.
Deleted files may remain recoverable for up to 7 days, and technical logs may remain for up to 30 days. RevenueCat may retain pseudonymous transaction records. AI providers delete previously submitted information according to their own retention schedules.
Users may also request deletion by emailing britolabsai@gmail.com. Email deletion requests will be processed within 30 days after appropriate account verification.
Deleting a ChicUp account does not cancel an Apple subscription. Subscriptions must be canceled separately through Apple.
Sharing and disclosure
We may disclose information:
- To the service providers listed in this policy
- When a user directs us to share something through the iOS share sheet
- To comply with applicable law, regulation, legal process, or government request
- To protect users, ChicUp, Brito Labs LLC, or others against fraud, abuse, security threats, or harm
- As part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections
ChicUp has no social feed or other in-app social features in the release build. Users cannot post publicly, view other users’ content, create public profiles, comment, vote, follow, or send messages, and ChicUp provides no other user-to-user interaction.
Content leaves ChicUp only when a user intentionally shares it through the iOS share sheet. ChicUp does not publish or display that content to other users inside the app.
No sale, advertising, or tracking
We do not:
- Sell personal information
- Share personal information for cross-context behavioral advertising
- Display third-party advertising
- Use advertising identifiers
- request Apple’s tracking permission
- Use advertising or attribution SDKs
Security
We use administrative, technical, and organizational safeguards designed to protect information. Photos and other information are transmitted over HTTPS. Firebase encrypts supported data in transit and at rest.
No security system is completely secure, and we cannot guarantee absolute security.
Your privacy rights
Depending on where you live, you may have rights to:
- Access personal information
- Correct inaccurate information
- Delete personal information
- Receive a portable copy of certain information
- Restrict or object to certain processing
- Withdraw consent where processing is based on consent
- Appeal certain privacy decisions
- Lodge a complaint with an appropriate data-protection authority
To exercise a privacy right, email britolabsai@gmail.com. We may need to verify your identity before completing a request.
Because ChicUp does not sell personal information or share it for cross-context behavioral advertising, there is no sale or advertising-sharing opt-out required for ChicUp’s current practices.
Legal bases for EEA, UK, and similar jurisdictions
Where required, we process information under one or more of these legal bases:
- Performance of our contract with the user
- The user’s consent
- Our legitimate interests in operating, securing, supporting, and improving ChicUp
- Compliance with legal obligations
Children
ChicUp is intended for users age 13 and older. We do not knowingly collect personal information from children under 13.
If you believe a child under 13 has provided information to ChicUp, contact britolabsai@gmail.com so we can investigate and delete it.
Users who are minors must have permission from a parent or legal guardian where required by applicable law.
Third-party links and services
ChicUp may link to Apple or other third-party services. Their privacy practices are governed by their own policies.
Changes to this policy
We may update this Privacy Policy when ChicUp’s features, providers, or legal obligations change. We will update the effective date and provide additional notice where legally required.
Contact
Brito Labs LLC
Florida, United States
britolabsai@gmail.com
