Who we are
Qlofi (“we”, “us”) is a personal colour-and-style service: the Qlofi app for iPhone and the website qlofi.com. Qlofi is currently operated by its founder as an individual business; when that changes, we will name the legal entity here. For anything in this policy, contact hello@qlofi.com — we are the “data controller” for the personal data described below.
Your analysis photo
Colour analysis starts with a photo of you. Here is exactly what happens to it:
- The photo is sent over an encrypted connection and processed in memory to classify your colouring (season, undertone, depth, chroma, contrast, eye colour).
- It is not saved by us — not to our database, not to our file storage, not to logs. Once the analysis returns, the photo is gone from our systems. (The classification provider may hold API inputs briefly for abuse monitoring — see “Service providers” below.)
- What we keep are the derived results only: your season, palette, contrast profile and the individual colour values read from your skin, hair and eyes.
- This is not facial recognition. We extract colour values (skin, hair and eye tones) for style classification only. We do not identify you, create facial-geometry maps, or process your photo as biometric identification data.
- One exception, and it is your choice: after analysis you can choose to keep that photo as your profile picture. If you say yes, it is uploaded to your private folder in our storage. If you say no, it is never persisted anywhere.
What we store
Account
Your email address and sign-in credentials (handled by our authentication provider — we never see your password), plus an optional username and the optional profile picture above.
Colour profile
The results of your analysis: season, palette colours, contrast profile, eye-enhancement colours and a confidence score.
Wardrobe
Items you add — garment photos, names, brands and the colours we derive from them — so Qlofi can style you from what you own. Wardrobe items are visible only to you.
Styling sessions & feedback
The moods and occasions you pick (including free-text you type), the weather used for the session, the looks Qlofi proposed, which one you chose or rejected, your pre-wear and post-wear feedback, and wear logs. This is what lets Qlofi learn what actually works for you.
Free-text is sent to our styling provider to compose your looks, so please avoid typing sensitive personal information — full names, addresses, health details — into occasion or mood fields. “Dinner with friends” styles just as well as the specifics.
Plans & trips
If you plan ahead: the dates and destinations you enter, the looks styled for them and packing lists built from them.
Website waitlist
If you sign up on qlofi.com we store your email address, which form you used (early access or waitlist) and the time. We use it for one thing: contacting you about access to Qlofi. Ask and we remove you.
qlofi.com itself sets no cookies and runs no analytics or tracking scripts — the only data that leaves the page is the email you choose to submit. That is also why there is no cookie banner: there is nothing to consent to.
Location & weather
Weather-aware styling is optional and permission-based. If you allow location access, your coordinates are rounded to roughly city level (~1 km) before being sent to the Open-Meteo weather service, with no account identifiers attached. We do not keep a history of your movements. For trips, the destination you type is geocoded the same way.
Notifications
Reminders (like the post-wear check-in) are scheduled locally on your device. We do not operate a push-notification server and do not collect push tokens. Notification permission is asked for in the app and you can revoke it in iOS Settings at any time.
Analytics
We use PostHog (EU-hosted) to understand how the app is used — screens visited, features used, where people get stuck. This is product analytics tied to your account, used only to improve Qlofi. We do not use advertising SDKs, cross-app tracking, or data brokers, and we do not use analytics data for ad targeting.
Shopping links
When you tap a product, you leave Qlofi and open the retailer's own site — their privacy policy applies there. Shopping links may be routed through an affiliate network that records the click so the retailer can pay Qlofi a commission; the network may set a cookie in your browser during the redirect so the store can attribute the purchase. The link carries no personal data about you from us. Purchases are entirely between you and the store.
Sharing
Share cards (your colour identity, a look) leave the app only when you share them. Private free-text you typed about an occasion is stripped from shared captions and cards by design.
Service providers
Qlofi runs on a small set of processors. Each receives only what its job requires:
| Provider | Job | What it receives |
|---|---|---|
| Supabase | Database, sign-in, file storage | The account and app data described above |
| OpenAI | Photo colour classification | Your analysis photo — no name or email attached. We do not store it; OpenAI may retain API inputs for up to 30 days solely for abuse monitoring, then deletes them. Never used to train their models |
| Anthropic | Outfit composition & style read-outs | Your palette, wardrobe item descriptions, mood/occasion text — never your photo. Anthropic may retain API inputs for up to 30 days for abuse monitoring, then deletes them. Never used to train their models |
| PostHog (EU) | Product analytics | Usage events tied to your account ID |
| Open-Meteo | Weather & place lookup | Coarse coordinates or a typed place name — no account identifiers |
| Affiliate networks | Shop-link commission | The click on a product link — no account data |
Some providers process data outside the EU (for example OpenAI and Anthropic in the US). Where that happens, transfers rely on the providers' EU-approved safeguards (standard contractual clauses / Data Privacy Framework).
Security & retention
Data travels encrypted (TLS) and is stored behind per-account access rules — your rows are readable by your account only. Analysis photos are processed in memory and never written to disk. We keep your data while your account exists; when you delete your account, your profile, wardrobe, styling history and images are erased from the active database immediately and purged from secure automated backups within 30 days. Waitlist emails are kept until launch communications are done or you ask to be removed, whichever comes first.
Your rights
Under the GDPR (and similar laws) you can ask us at any time to:
- Access the data we hold about you, and receive a copy (portability)
- Correct anything inaccurate
- Delete your account and data — available directly in the app (Profile → Delete account) or by email
- Object to or restrict a particular use
- Withdraw consent where processing is based on it (e.g. location)
Email hello@qlofi.com and we will act on it promptly. You also have the right to complain to your local data-protection authority.
Children
Qlofi is not directed at children and is intended for users aged 16 and over. We do not knowingly collect data from anyone younger; if you believe we have, contact us and we will delete it.
Changes
If this policy changes, we will update the date at the top; for material changes we will tell you in the app before they take effect.