Skip to content

Effective: April 15, 2026

Privacy Policy

Anhui Shuzhi Huyu Technology Co., Ltd. ("Tomirro", "we", or "the Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you use our Tomirro mobile application ("App" or "Application") and related services (collectively, "Services"). By using our Services, you consent to the collection and use of information in accordance with this Policy.

01Information We Collect

1.1 Information You Provide

  • Account Information: When you register using Sign in with Apple, we collect your email address (you may choose to use Apple's private email relay to hide your real email).
  • Profile Information: You may optionally provide a profile photo.
  • Garment Photos: Photos of clothing you upload to build your digital wardrobe. These photos may be taken via the in-app camera or imported from your photo library.
  • Communications: When you contact us for support, we collect the information you provide in your messages.

1.2 Automatically Collected Information

  • Device Information: Device model, operating system version, and unique device identifier (installation ID).
  • Usage Information: Basic app usage data, such as app launches and feature access records.
  • Location Information: With your permission, we collect your approximate location (city level) to provide weather-based outfit recommendations. We only collect location when you use this feature and do not continuously track you.
  • Camera & Photo Library: With your permission, we access your camera to photograph garments and your photo library to import existing photos. We only access photos you explicitly select.

1.3 Information from Third Parties

  • Sign in with Apple: When you authenticate via Apple, we receive your Apple ID token and exchange it with our authentication service to create your account.
  • Weather Data: We obtain weather information from a third-party weather service (QWeather) based on your location to provide weather-based outfit recommendations.

02How We Use Your Information

We use the information we collect to:

  • Provide Core Services: Manage your account, store your wardrobe data, and enable all app features.
  • AI-Powered Features: Use AI to analyze garment photos, extract textual descriptions of garment attributes (such as category, color, style, material, etc.), and generate standardized garment display images based on those descriptions for your digital wardrobe.
  • Daily Outfit Recommendations: Recommend suitable items from your wardrobe each day based on real-time weather information at your location.
  • Product Improvement: Analyze anonymized usage patterns to improve app performance, fix bugs, and develop new features.
  • Customer Support: Respond to your inquiries and provide technical assistance.
  • Security: Detect and prevent fraud, abuse, and security incidents.
  • Legal Compliance: Comply with legal obligations and enforce our Terms of Service.

Important: How We Use Your Photos

Your garment photos are used for the following purposes:

  • AI analysis to extract textual descriptions of garment attributes
  • Generating standardized garment display images based on text descriptions, stored in your digital wardrobe
  • Providing weather-based outfit recommendations
  • Analyzing anonymized usage patterns to optimize service features and product experience

We will not:

  • Use your photos for facial recognition or identity verification
  • Use your photos to train general AI models for the benefit of other users or third parties
  • Share your photos with other users without your explicit consent
  • Sell your photos to advertisers or marketing companies

Your photos are private to your account.


03How We Share Your Information

We do not sell your personal information. We may share information in the following limited circumstances:

3.1 Service Providers

We share information with trusted third-party service providers who perform services on our behalf:

  • Cloud Storage: Amazon Cloud OSS (Object Storage Service) for storing garment photos and media files.
  • Authentication: Apple, for secure user authentication infrastructure.
  • Database & Cache: AWS RDS (PostgreSQL) and ElastiCache (Valkey/Redis) for data storage.
  • AI Services: Third-party AI providers for garment recognition, attribute extraction, and image generation (photos are processed securely; providers do not retain data).
  • Weather Data: QWeather API for obtaining weather information.

These providers are contractually bound to protect and use your data only for the specific purposes we designate.

3.2 Legal Requirements

We may disclose your information if required by law or in response to valid legal requests (such as subpoenas, court orders, or government investigations).

3.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction. We will notify you via email and/or prominent in-app notice before your information is transferred.

3.4 With Your Consent

We may share information with third parties when we have obtained your explicit consent.


04Data Security

We employ industry-standard security measures to protect your information:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS (TLS 1.2+).
  • Encryption at Rest: Sensitive data is encrypted when stored on our servers.
  • Secure Authentication: We use JWT (JSON Web Tokens) with RS256 (Sign in with Apple via Supabase) for secure API access.
  • Keychain Storage: Authentication tokens and sensitive data are securely stored in your device's iOS Keychain.
  • Access Controls: Strict access controls limit who within our organization can access your personal information.
  • CDN Authentication: Media files are served through CDN with Type-A URL signing to prevent unauthorized access.
  • Regular Security Audits: We regularly review and update our security practices.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.


05Data Retention

We retain your personal information for as long as necessary to provide the Services and fulfill the purposes described in this Privacy Policy:

  • Active Accounts: Your data is retained while your account is active.
  • Deleted Items: When you delete a garment item, it is immediately removed from the app. Backend data is permanently deleted from servers within 30 days.
  • Account Deletion: When you delete your account, we immediately begin the deletion process. Most data is deleted within 30 days, though certain information may be retained longer for legal, security, or operational reasons.
  • Legal Obligations: We may retain certain information as required by law, such as for tax, accounting, or anti-fraud purposes.
  • Backup Systems: Data in backup systems may be retained for up to 90 days before permanent deletion.

06Your Privacy Rights & Choices

6.1 iOS Permissions

You can control the following permissions through iOS Settings:

  • Location: Choose "Never", "Ask Next Time", or "While Using the App".
  • Photo Library: Choose to grant access to all photos, selected photos, or no photo access.
  • Camera: Enable/disable camera access for photographing garments.

If you deny these permissions, the app will continue to work, but certain features will be limited.

6.2 Account Settings

Within the app, you can:

  • View and edit your profile information
  • Delete individual garments or photos
  • Delete your account and all associated data

6.3 Data Rights (Based on Your Jurisdiction)

Regarding your personal information, you may have the following rights:

  • Right of Access: Request a copy of the personal information we hold about you.
  • Right of Rectification: Request correction of inaccurate or incomplete information.
  • Right of Erasure: Request deletion of your personal information (subject to legal retention requirements).
  • Right to Data Portability: Request a copy of your data in a machine-readable format.
  • Right to Object: Object to certain types of information processing.
  • Right to Restrict: Request that we limit how we use your information.
  • Right to Withdraw Consent: Withdraw consent for consent-based processing (without affecting the lawfulness of processing prior to withdrawal).

To exercise these rights, please contact us at privacy@tomirro.com. We will respond to your request within 30 days.

6.4 Account Deletion

To delete your account:

  • Go to Settings → Delete Account
  • Confirm your decision
  • Your account and related data will be permanently deleted within 30 days

Warning: Account deletion is permanent and cannot be undone. All your garments, photos, and preferences will be permanently deleted.


07Children's Privacy

Tomirro is not intended for children under the age of 13 (or the applicable digital consent age in your jurisdiction). We do not knowingly collect personal information from children under 13.

If we discover that we have inadvertently collected information from a child under 13, we will promptly delete that information. If you believe we have collected information from a child under 13, please contact us at privacy@tomirro.com.


08International Data Transfers

We operate globally, and your information will not be transferred to, stored, or processed in countries outside your country of residence, including:

  • North American countries: For database and application infrastructure (AWS RDS, ElastiCache, ECS)

Data protection laws in these countries may differ from those in your country. When we transfer information internationally, we implement appropriate safeguards to ensure your information is protected in accordance with this Privacy Policy and applicable laws.


09Third-Party Links & Services

The App may contain links to third-party websites or services (such as weather APIs). This Privacy Policy does not cover the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you interact with.


10Advertising & Tracking

We do not use:

  • Third-party advertising networks
  • Cross-site tracking cookies
  • Behavioral advertising pixels
  • Third-party analytics tools

11Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • We will update the "Effective" date at the top of this Policy
  • For significant changes, we will notify you through the App or via email
  • Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy

We encourage you to review this Privacy Policy periodically.


12GDPR Rights (EU Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your information based on consent, contractual necessity, legitimate interests, or legal obligations.
  • Data Controller: Anhui Shuzhi Huyu Technology Co., Ltd. is the data controller of your personal information.
  • Automated Decision-Making: We use AI to provide outfit recommendations, but these do not have legal or similarly significant effects on you. You can always disregard AI suggestions.
  • Right to Complain: You have the right to lodge a complaint with your local data protection authority.

13CCPA Rights (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Know what personal information we collect, use, disclose, and sell (we do not sell information).
  • Right to Delete: Request deletion of your personal information.
  • Right to Opt-Out: Opt out of the "sale" of personal information (not applicable, as we do not sell data).
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact privacy@tomirro.com or use the in-app deletion feature.


14Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Anhui Shuzhi Huyu Technology Co., Ltd.

In-App Feedback: Send an email to the product team via the in-app feedback portal

Company Address: Hefei, Anhui Province, China

Response Time: We will respond to privacy-related inquiries within 30 days.

Last Updated: April 16, 2026