Effective August 12, 2026

Orlo Privacy Policy

This policy explains what Orlo processes, where it is stored, why it is used, and the choices available to you.

Published by the app provider. This policy is not a substitute for independent legal advice.

Who is responsible

Orlo is provided by Joseph Hoffmann, 5908 Mt Vernon Way, Racine, Wisconsin 53406-2759, United States.

For privacy questions or rights requests, email superdipj@gmail.com. EEA/UK representative details: Not applicable at launch because Orlo is offered only in the United States.

Adults only

Orlo is intended only for people aged 18 or older. The app asks Apple for an age-range declaration, or uses an in-app adult self-attestation if that result is declined or unavailable. Orlo does not store your birthdate.

Information stored on your devices and in iCloud

Garment cutouts, thumbnails, garment details, saved looks, and suggestion history are stored with SwiftData in your private iCloud account so they can sync between your Apple devices. Apple provides the private CloudKit service.

A body reference, pending preview jobs, and Generated Previews stay in a separate protected local store. They are excluded from iCloud and device backup. Deleting the body reference also deletes all local previews derived from it.

A temporary source garment photo may be kept in protected local storage while you edit a draft. It is deleted when the item is saved or cancelled, and abandoned drafts are deleted after seven days. The approved wardrobe item keeps only the cutout and thumbnail, not the source capture.

Subscription and consent state may be cached in the device Keychain. The app uses PhotosPicker without requesting broad photo-library access and asks for camera access only when you choose Camera.

Remote processing you choose

Orlo asks for separate, versioned permission before the first remote garment upload and before the first body-photo upload. Revoking permission blocks future uploads and cancels work that has not started. Local wardrobe and on-device cutout features remain usable.

For Automatic Details, Orlo may send a garment cutout to obtain controlled category, color, material, season, occasion, confidence, and warning codes. For Suggestions, Orlo first creates legal combinations on device, then may send owned-item identifiers and controlled attributes so submitted candidate IDs can be reranked. For a Generated Preview, Orlo may send one adult body reference and up to three selected garment cutouts. These features do not make fit, sizing, health, eligibility, or purchasing decisions.

Before upload, garment photos are normalized, location and other EXIF metadata are removed, and the source capture is not retained after successful save. Remote processing is disabled unless the applicable country, consent, age, privacy, health, safety, cost, and quality gates are active.

Processors and service providers

Apple provides private CloudKit synchronization, StoreKit purchases and entitlement evidence, App Attest security signals, and age-range sharing. Apple processes information under its own terms and privacy policy.

Cloudflare operates Orlo's API gateway, job workflow, security controls, database, and private temporary object storage. Requests contain attestation and pseudonymous transaction signals needed to protect the service and enforce entitlements and quotas.

OpenAI may process a garment cutout for Automatic Details, controlled outfit-candidate data for Suggestions, and an adult body reference plus selected garment cutouts for an illustrative Generated Preview. Orlo activates a route only after its applicable privacy, country, safety, health, cost, and quality gates pass.

Google provides Firebase Analytics only when you explicitly turn on App Analytics. It receives a resettable app-instance identifier, app and device context, coarse region, and the limited events described below. Google signals, user-provided data, advertising integrations, ad personalization, granular location/device collection, and custom user IDs are disabled.

Orlo does not sell personal information, serve ads, or give processors permission to use your content for their own advertising. Current processor links are available from the Processors section in app Settings. You can also review Apple Privacy, Cloudflare's Privacy Policy, OpenAI API data controls, and Firebase Privacy and Security.

Optional app analytics

App Analytics is off by default. If you opt in during onboarding or in Settings, Orlo sends Google Firebase Analytics only coarse screen and funnel events: onboarding completion; garment add or update; style and Generated Preview request, success, failure category, cancellation, and coarse latency bucket; paywall source; and subscription checkout or restore outcome. The app never sends wardrobe or body images, garment names or attributes, prompts, search text, notes, free-form text, exact timing, exact location, Orlo account or transaction identifiers, job IDs, or custom user IDs to Firebase.

Firebase uses a resettable app-instance identifier and automatically collected app/device context to produce aggregate reports. Orlo disables IDFA-capable Analytics, IDFV collection, automatic screen reporting, Google signals, advertising features, and ad personalization. Withdrawing App Analytics in Settings immediately stops future collection and asks the SDK to reset its local analytics data and app-instance identity. Delete All Content also turns analytics off and performs that reset.

The linked Google Analytics property is configured for two-month event and user-data retention without resetting retention on new activity. Aggregated standard reports may be retained differently by Google. Analytics is also suppressed in debug builds, simulators, UI automation, and TestFlight builds.

Service and security records

The service keeps an attested installation identifier and public key, a server-peppered hash of Apple's App Transaction identity, verified storefront and entitlement state, preview quota totals, consent and age-policy versions, idempotency records, and content-free security and operational events. This supports authentication, purchase restoration, the two-preview lifetime allowance across reinstalls and devices, fraud prevention, reliability, cost controls, and Apple transaction reconciliation.

Operational logs are designed to contain only request or job IDs, provider/model/prompt/schema versions, timings, usage cost, country, and stable error codes. They must not contain images, prompts, garment descriptors, signed transactions, presigned upload URLs, or provider outputs.

Retention and deletion

Orlo schedules remote inputs for deletion immediately after inference. Successful results are deleted from Orlo's temporary storage after app acknowledgement or at their 24-hour expiry. A bucket-wide one-day lifecycle rule is an additional asynchronous safety net, so infrastructure deletion may finish after the exact expiration time. Content-free job and operational records are retained for up to 30 days.

Pseudonymous security, entitlement, transaction reconciliation, and lifetime quota records may remain longer while needed to provide and protect the service, preserve purchase and lifetime allowance state, meet legal obligations, and resolve disputes. Deleting app content does not reset prior purchase or preview-quota history. A verified deletion request removes or de-identifies eligible service records, subject to necessary security, anti-fraud, transaction, dispute, and legal retention.

Under OpenAI's default API controls, customer content may appear in abuse-monitoring logs for up to 30 days. Retention can be longer when legally required or reasonably necessary to protect OpenAI's services or others from harm. OpenAI states that API content is not used to train its models unless the account owner explicitly opts in. Image inputs are scanned for potential child sexual abuse material and may be retained for manual review when flagged, including when Zero Data Retention is enabled. Zero Data Retention is an optional future privacy improvement, not a prerequisite for the accurately disclosed route.

Revoking consent cannot guarantee deletion of processor records already retained for safety, security, transaction, or legal reasons.

Why information is processed

Depending on where you live, Orlo relies on your consent for optional remote image processing; performance of the service contract for wardrobe, synchronization, entitlement, and requested features; legitimate interests in security, fraud prevention, reliability, and service improvement that do not override your rights; and compliance with legal obligations. You can withdraw consent for future remote processing in Settings without affecting earlier lawful processing.

International processing

Orlo and its processors may handle information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, Orlo will use an approved transfer mechanism and other safeguards identified during legal review. Processor availability is restricted by country and current provider terms.

Your choices and privacy rights

In Settings you can edit or remove wardrobe items, revoke future remote processing, turn optional App Analytics on or off, delete the body reference and every derived local preview, delete app-managed content, restore purchases, and manage a subscription. Cloud or server deletion may need a network connection and retry.

Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, withdraw consent, or appeal a decision by emailing superdipj@gmail.com. We may verify the request and may retain limited records where the law permits or requires. You may also complain to your local privacy regulator.

Security

Orlo uses protected local storage, private CloudKit, App Attest, short-lived access tokens and upload URLs, scoped storage, encryption in transit, access controls, rate and spend limits, and content-minimized logs. No method of storage or transmission is completely secure.

Changes to this policy

Material changes will be reflected by a new effective date and, when required, an in-app notice or renewed consent. Earlier versions will be retained as required by law.

Contact

Privacy: superdipj@gmail.com
Support: superdipj@gmail.com
Postal address: 5908 Mt Vernon Way, Racine, Wisconsin 53406-2759, United States