roro

Privacy Policy

Privacy Policy

Effective: May 9, 2026

This Privacy Policy describes how Roro (“we”, “us”, “our”) collects, uses, and shares information when you use the Roro mobile app and related services (the “Service”). We’ve tried to write this in plain English and we keep data collection minimal — only what we need to make the app work for you.

1. Information you provide

  • Account info. Email address (and a password hash if you sign up with email), or your Apple user ID and optional name/email if you use Sign in with Apple.
  • Closet content. Photos of clothing items, outfits, tags, brands, sizes, materials, notes, calendar entries, packing lists, inspirations, and any other content you create in the app.
  • Sharing data. If you share a closet with another user, we store the invite recipient’s email and the relationship between accounts so we can deliver and revoke access.
  • Reports. If you report content as abusive or inappropriate, we collect the report contents and the related content/user identifiers so we can review the report.
  • Support correspondence. If you email us, we keep your message and our reply.

2. Information collected automatically

  • Device basics. Operating system, device model, app version, and a stable installation identifier so we can troubleshoot bugs and protect against abuse.
  • Crash and error logs. If the app crashes or hits an error, we record the stack trace and basic device info. We do not send the content of your photos or notes in these logs.
  • Approximate location (only when you enable it). If you grant location permission, we use your coordinates to fetch local weather for outfit suggestions. We do not store your historical location.
  • Push notification token (only when you enable it). If you grant notification permission, we receive an opaque push token from Apple and store it on our server so we can deliver transactional notifications (for example, someone shared their closet with you, or your invite was accepted). Push tokens are not used for marketing and are removed when you delete your account.

3. Information from your camera and photos (only when you choose)

The app requests access to your camera and photo library so you can add clothing photos. Photos are uploaded to our storage so they’re available across your devices and can be shared with people you invite. You can delete any photo at any time, which removes it from our servers within 30 days.

4. We do not collect or use

  • Tracking identifiers (IDFA). We do not request App Tracking Transparency permission and do not track you across apps or websites.
  • Advertising data. We do not show ads and do not sell or share your information for advertising.
  • Microphone. The app does not use the microphone.
  • Health data. The app does not access HealthKit.

5. How we use your information

  • To run the Service: store your closet, sync across your devices, and let you share closets with people you invite.
  • To analyze clothing photos with AI when you ask the app to (for example, to detect category, color, or pattern).
  • To fetch weather when you enable location permission.
  • To prevent abuse, debug crashes, and improve the Service.
  • To respond to support requests and to send essential service emails (for example, account verification or password reset).
  • To deliver transactional push notifications when you grant notification permission (for example, share invites, invite acceptances, or other account activity).

6. Service providers

We use a small number of providers to operate the Service. They process information only on our instructions and only as needed for the purposes shown.

ProviderPurposeData they may process
SupabaseDatabase, authentication, file storageAccount info, closet content, photos
AppleSign in with Apple, App Store deliveryApple user ID, optional name/email on first sign-in
Anthropic (Claude)AI image analysis on requestPhoto and prompt sent for the analysis call
Open-MeteoWeather lookups when location is enabledApproximate coordinates for the lookup only
Vercel · RailwayWeb hosting and API hostingStandard request logs
ResendTransactional emailEmail address and message contents
Apple Push Notification serviceDelivery of transactional push notificationsOpaque push token and notification payload

We instruct AI providers not to use your content to train their models, where the provider supports that option.

7. Sharing your information

We do not sell your personal information. We share information only:

  • With service providers, as listed above.
  • With other users you choose to share a closet with — they will see the items and outfits you have shared.
  • To comply with law, court orders, or lawful government requests; to protect the rights, property, or safety of Roro, our users, or others; or in connection with a merger, acquisition, or sale of assets, with notice to affected users.

8. Your choices and rights

  • Access & export. You can view and edit your closet content at any time inside the app.
  • Permissions. Camera, photo library, and location permissions can be changed in your device’s Settings.
  • Account deletion. Tap your profile, then “Delete Account”. We permanently remove your account, photos, sessions, and all closet data from our active systems immediately, and from backups within 30 days. If you signed in with Apple, we also revoke our access to your Apple ID.
  • Communication preferences. Service emails (verification, password reset, security) cannot be turned off because they are required to operate your account.

9. Region-specific rights

EEA, UK, Switzerland. You have rights under the GDPR/UK GDPR to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. The legal bases for our processing are: performance of our contract with you (running the Service), our legitimate interests (security, fraud prevention, product improvement), your consent (location, optional features), and legal compliance. You can lodge a complaint with your local data protection authority.

California. Under the CCPA/CPRA you can request to know what personal information we have, request deletion, and opt out of “sharing” for cross-context behavioral advertising. We do not sell or share personal information for advertising purposes. To exercise rights, email hi@hellogoodday.com.

To make any request, email us from the address on your account so we can verify ownership.

10. Data retention

  • Account and closet data: kept for as long as your account is active.
  • Backups: closet data is removed from backups within 30 days of account deletion.
  • Logs and crash reports: kept for up to 90 days.
  • Reports of abuse: kept for up to 1 year for moderation history.

11. Security

We use industry-standard safeguards: HTTPS for all transport, encrypted storage at rest, hashed passwords, scoped access tokens, and restricted database access. No service is 100% secure; please use a strong, unique password and protect your device.

12. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please email hi@hellogoodday.com and we will delete it.

13. International transfers

We are based in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Where required, we use Standard Contractual Clauses or other approved transfer mechanisms.

14. Changes to this Policy

We may update this Privacy Policy from time to time. If we make a material change, we’ll notify you in the app or by email at least seven days before it takes effect. The “Effective” date at the top reflects the latest version.

15. Contact

Privacy questions: hi@hellogoodday.com
Reports of abuse: hi@hellogoodday.com
General support: hi@hellogoodday.com


© 2026 Roro. All rights reserved. · Terms of Service