Privacy policy

Last updated: October 5, 2026.

Mawap is a wardrobe app. This page says what data it processes, why, for how long, who it goes to, and what you can ask for. It is written to be read in full.

Who is responsible

Mawap is published on a non-professional basis by a natural person, whose identity is registered with the host (see the legal notices). For any questions about your data: contact.mawap@gmail.com.

What the application processes

  • Your account: email address, password (kept hashed, never in plain text), display first name, and, if you use “Continue with Google” or “Continue with Apple”, the identifier that this service sends to us.
  • Your onboarding and "About me" answers: what you want from Mawap, occasions, styles, your body shape, your size if you provide it, your city, the calendar you use, and, if you fill them in, your job, your date of birth and your free note. The city is used for weather on the home screen and wardrobe storage advice. If you use “Use my location”, its position is rounded before storage; your movements are not tracked. Your body shape, your job and your note are used for the stylist's advice; your date of birth, to check your age. The calendar you name is kept to recognise your trips one day: the app has no access to it today.
  • Your wardrobe: clothing photos, categories, colors, brands, sizes, prices and notes.
  • Your body measurements, if you provide them. They are optional. Your weight is only used for the build of the mannequin in the visuals; your sizes by brand, your other sizes and your note on measurements help the stylist look for the right size.
  • Your full-length photo and the avatar derived from it, if you enable “See on me”, as well as the haircut and beard you choose for your avatar, if you specify them. They are sent only after your explicit consent, which is never preselected.
  • Your use: outfits, calendar, trips, desires.
  • Social: friends, messages, stories, reactions. If you turn it on in Settings, Friends, your friends see the day and month of your birthday (never the year) and your friends list. With your list visible, friends of your friends may see you in “You may know…”, computed only from friendship links, never from your contacts. You can opt out at any time.
  • Notifications: the technical address of the subscriber device.
  • Security: a counter of connection attempts, which contains the entered email address.
  • The image generation log, to keep the service's accounts.

On what basis

The execution of the service you request, for the account, the wardrobe and Mawap, the stylist, when you write to it. Your explicit consent for the full-length photo: it can show a veil worn, therefore reveal religious beliefs, and this is the most protective basis. Your explicit consent too, separate and optional, for the stylist to take your veil into account. Legitimate interest in account security and audience measurement.

Nothing is decided automatically

No decision concerning you is made by a machine alone. The outfits, the colors detected in a photo and the advice are suggestions: you can correct everything, and the composition of an outfit never depends on an artificial intelligence model: it follows fixed rules, written in the application. When a part is automatically filled in when added, the form has a button to validate or correct what has been guessed.

To whom this data goes

19 third-party services are involved. None receives more than what is written here.

  • Anthropic: the photo of an added part, reduced to 512 px and stripped of its metadata (including the shooting location), to pre-fill its file; and, on request, contextual advice: request, metadata of the wardrobe's pieces (category, colour, brand, material, season, style, never their name or photo), declared sizes and wardrobe sections, a summary of the most worn colours, budget and answers from "About me" (never the date of birth), job, body shape, sizes by brand and other declared sizes (never the weight), today's temperature and optional photo, reserved for the validated pilot. UNITED STATES ; Standard API retention up to 30 days, security exceptions and legal obligations.
  • Supabase: all account data and all files (photos of clothing, fitting photos, returns). servers in Ireland; American company.
  • Vercel: hosting of the application, its technical logs and audience measurement. servers in Dublin; American company.
  • OpenAI: the full-length photo, the avatar derived from it, the photos of clothing sent to make a visual, the drawing instructions, and the haircut and beard chosen for the avatar. UNITED STATES.
  • Hugging Face: clipping template download. No images are sent there. UNITED STATES.
  • IMG.LY: download of the background-removal model that runs on your device. No image is sent there, only what a web page sends when it loads (IP address, browser). Germany.
  • Google (connexion): email address, name and Google ID, if you choose “Continue with Google”. UNITED STATES.
  • Apple (connexion): your email address, real or replaced by a relay address @privaterelay.appleid.com if you choose to hide it, your first name the first time, and Apple ID, if you choose “Continue with Apple”. UNITED STATES.
  • Google Programmable Search: the product name or barcode typed, when the image search goes through this fallback engine. UNITED STATES.
  • Google Play (paiement): when you buy a premium or a ticket from the application: the transaction itself is done with Google Play, which does not send us any means of payment. We receive the token of the purchase, the product purchased, its status, its end date, the billing country and the order number, to open the corresponding right and keep it up to date. UNITED STATES.
  • Brave Search: the product name or barcode typed, to find an image of the part. UNITED STATES.
  • UPCitemdb: the scanned barcode. UNITED STATES.
  • TikTok: the address of the shared video, sent to its public oEmbed point to retrieve the thumbnail; the call comes from the server, never from the browser, therefore without cookies or the person's IP address. United States (ByteDance); the sticker is served from a European CDN.
  • Open Products Facts: the scanned barcode. France.
  • Open-Meteo: a city you search for, and the coordinates of your home city or a travel destination, for weather. Germany.
  • Wikipédia: the name of a travel destination, to illustrate the file. Wikimedia Foundation, United States.
  • Resend: your email address and link, when you request to reset your password. UNITED STATES ; no European region.
  • Apple, Google, Mozilla (notifications): the technical address of your device, and a contact address attached to each shipment. depending on browser and device.
  • Sentry: Server error reports: message, call stack, page address (cleaned) and deployed version. Never the IP address, never the headers, never the content of a form. UNITED STATES.

The full-length photo is sent to OpenAI, in the United States. OpenAI keeps it for up to 30 days to monitor abuse, then deletes it. It is not used to train its models. Removing your photo in the app deletes the photo, avatar and all renders, but cannot delete anything in OpenAI during these 30 days.

When you write to Mawap, the stylist, your request is sent to Anthropic, in the United States, with the details of your pieces (category, colour, brand, material, season, style, never their name or photo), the sizes and departments you have declared, the day's temperature (never your city) and the photo you add, if any. A summary of the colours you wear most, worked out from the outfits you marked as worn, is also sent: you can see and correct it in Settings, My style. Your budget, if filled in under Settings, your answers in "About me" (your styles, your occasions, what makes dressing hard for you, your cuts, your body shape, your job and your note) and the sizes you wrote in your measurements are also sent, never your weight or your date of birth. Your body shape is used to choose cuts: the stylist never gives an opinion on your body. Nothing is sent until you write to it. Anthropic keeps these exchanges for up to 30 days, except for security or a legal obligation. In the app, the conversation disappears when you close it, after 30 minutes without a message or after 2 hours: only the outfits you save remain. If you wear the veil, this information is sent to Anthropic only if you allow it in Settings (Avatar), where you can withdraw this consent at any time: without it, the stylist knows nothing about your veil, and the app adds it to its outfits itself.

What the app gains, and what it doesn't do with your data

Mawap is free and currently does not receive any commission: when the application shows you a part found at a merchant, no one pays it for that.

That may change: paid partnerships with brands or stores are being considered. If this happens, three things are acquired from now on:

  • this will be written here before the first paid link appears;
  • the links concerned will be marked as such in the application;
  • neither your wardrobe, nor your measurements, nor your photos will be transmitted to a partner: a merchant only ever receives the search that you typed, like today.

Transfers outside Europe

Several of these services process data in the United States. These transfers are based on the EU and US data protection framework and, in turn, on the standard contractual clauses of the European Commission. This framework is the subject of an appeal pending before the Court of Justice: we are not relying on it alone. You can obtain a copy of these safeguards by writing to contact.mawap@gmail.com.

How long

  • Your account and your wardrobe: as long as the account exists.
  • A piece or outfit deleted: 30 days in the recycle bin, files included, then actual deletion.
  • Stories: 48 hours.
  • Notifications: 90 days.
  • A message withdrawn: 30 days after its withdrawal.
  • The outfit suggestion journal: 12 months.
  • Connection attempts: 7 days.
  • The generation log: kept, and anonymized when the account is deleted.

What a shared space really shows

When you give a loved one the right to modify your wardrobe, they can read and modify your body measurements. It's not a fault, it's what sharing does. The fitting results never leave your space: no one else sees them.

What is written on your device

The application sets strictly necessary connection cookies (session, security of connections by Google and Apple, active space) and keeps your display preferences (theme, columns, temperature unit, time zone, screens already viewed). It also keeps a copy of your wardrobe in the browser, to work offline. None of this is for tracking you, and none of it is shared. There is therefore no consent banner: there is no tracer that would require one. Vercel audience measurement does not write anything to your device.

How this data is protected

  • Exchanges between your device and the application are encrypted throughout the journey, and your browser is instructed never to connect to it again otherwise.
  • Once received, your data are stored encrypted: the database, files (clothing photos, try-on photos and generated images) and daily backups. A disk removed from the data center would not be readable. This does not protect against someone entering through the service itself. The hosting provider commits to this in its contract; this is the only protection listed here that our own code cannot prove.
  • Your password is never kept in plain text or readable by anyone: it is transformed by an irreversible calculation, with a different random value for each account. Two people who choose the same password therefore do not have the same fingerprint.
  • The database cannot be searched from any browser. It refuses any request that does not come from the application server. Even someone reading the code on the page has no door to push.
  • It is the server which checks, at each reading, that what you request belongs to you or has been opened to you by someone. These checks are listed one by one, and an automatic check refuses any new request that is not included there.

These measures cannot make a data breach impossible. If one occurs, it is recorded and reported to the CNIL within 72 hours when the law requires it. If it poses a high risk to you, we notify you directly in the app and by email, identifying the data affected.

Your rights

  • Take your data with you: Settings, My account, “Export my data”. Immediate.
  • Delete your account: Settings, My account. Immediate too, with no withdrawal period.
  • Access, rectification, opposition, limitation: by email to contact.mawap@gmail.com. We respond within a month, or two more if the request is complicated, and in this case we tell you beforehand.
  • Complaint to the CNIL, at any time, without notifying us.

What the export does not contain

  • The text of messages sent to you. They belong to the person who wrote them, and we do not export anyone else's data. You keep the date and the name of the sender: these are facts that concern you.
  • The fingerprint of your password, the keys of your devices subscribed to notifications and the proof of purchase issued by the app store: these are secrets, not data to take elsewhere.

What deletion doesn't do, and you need to know it

  • The messages you sent remain with their recipients, as is.
  • What has already gone to the image generation service remains there for up to 30 days.
  • The outfits of your loved ones which contained one of your pieces continue to exist, without it.
  • The generation log survives, anonymized.
  • Database backups retain a copy of your data until they expire, at most eight days. They are read only to restore the service after an incident.

Minors

You must be 16 years or older to open an account, whatever country you live in: this is the highest threshold set by European law, so no parental consent is asked for. A date of birth that gives less than 16 years is not saved.

If this page changes

The date at the top is authentic. A change that affects what goes to a third party will be announced in the application, not just here.

Privacy policyTerms of useLegal notice