Last updated: 29 September 2026
Shkaf is a digital wardrobe, outfit planner, and social styling service available through its mobile apps and related website and services (the “Service”). This policy explains how we handle personal information when you use the Service. It applies worldwide; additional rights may apply where you live.
Controller. haip IT FZ LLE, Creative Tower, PO Box 4422, Fujairah, United Arab Emirates. Email: hello@shkaf.app.
Information we handle
| Category | Examples and source |
|---|---|
| Account and profile | Your name, nickname, email, password hash or third party sign-in information, profile photo, biography, Instagram link, profile visibility, account identifiers, and account settings. We receive these from you and, if you choose social sign-in, the sign-in provider. |
| Wardrobe and planning | Photos, item and outfit details, brands, prices and currencies, colors, notes, calendar dates, trip names and dates, and packing or styling selections that you enter or upload. Photos may include people or information visible in the image. |
| Optional body and style details | Age, gender, clothing size, weight, height, bust, hip, and waist measurements when you choose to provide them. These can be sensitive; you do not need to provide every optional field to use the basic Service. |
| Social activity | Public or private posts, shared looks, follows, stylist or administrator relationships, reactions, votes, reports, blocks, and related notifications. Other users may provide information about you through these interactions. |
| Device and operation | Push notification tokens, app or device identifiers used for sign-in, analytics or synchronization, app activity and diagnostics, IP address, log and error data, and support messages. The iOS app stores some information in Core Data and on your device and synchronizes supported records with our servers. |
| Analytics | App events and screen views, a device identifier, account ID, nickname, item and look counts, subscription events, and diagnostic or performance information. The iOS app sends analytics to Amplitude and Firebase Analytics and uses Sentry and Firebase Crashlytics for diagnostics. |
| Purchases | Subscription status and transaction identifiers supplied by Apple, RevenueCat, or Google, if you purchase premium features. We do not need your full payment card number for store-billed purchases. |
You may decline optional fields and device permissions, but related features may then be unavailable. Camera and photo access are used when you choose to capture or upload images; notification permission is used for push alerts. The iOS app also downloads a background-removal model and runs image processing on device.
Why we use information
We use account, wardrobe, planning, and device data to create and secure accounts; store and synchronize your wardrobe, looks, calendar, and trips; provide styling, social and premium features; deliver notifications you enable; provide support; and prevent abuse. For people in the EEA, UK, and other regions requiring a legal basis, this processing is generally necessary to perform our contract with you.
We use security logs, diagnostics, reports, and usage analytics to maintain, troubleshoot, measure, and improve the Service and protect users. On iOS, Amplitude and Firebase Analytics receive app activity and some account-linked events. Where legally permitted, we rely on our legitimate interests in understanding and improving a safe, reliable Service; where consent is required, consent is the legal basis. We use transaction records and respond to lawful requests to meet legal obligations. You can withdraw optional device permissions through device settings and contact us to object to analytics or ask about other choices. Withdrawal does not affect earlier lawful processing.
What others can see
Your profile can be public or private. A public profile, public posts, shared looks, photos, social interactions, and information you put in them may be seen, copied, or shared by other users. Private settings limit in-app access but do not undo copies already made by others. Stylists or people you authorize to manage your profile may access and change the information that feature permits. Review your visibility settings before sharing photos, measurements, calendar plans, or trip details. Reports you submit are available to the team handling safety concerns.
Who receives information
We share information with service providers who host the Service and images, deliver email and push notifications, provide analytics, process purchases, process crash and error reports, and support operations. The iOS app uses Amplitude, Firebase Analytics, Firebase Messaging and Crashlytics, Sentry, and RevenueCat. The server uses cloud image storage and may send operational alerts through Slack. Apple, Google, and Instagram may receive information when you use their sign-in or store services. Operational alerts can include an account email and event details.
We share content with other users according to your settings and actions. If you open a link to an independent website, that site may collect information under its own policy. We may disclose information when reasonably necessary to comply with law, protect rights or safety, or as part of a business transfer, subject to applicable safeguards.
Shkaf does not show advertisements or sponsored listings and does not collect or share information for advertising.
International transfers
We operate from the UAE. Our production database, uploaded images, and backups are hosted in Europe. Providers supporting analytics, notifications, diagnostics, purchases, and support may process limited information in other countries. Where law requires a transfer safeguard, we use an applicable mechanism such as an adequacy decision or standard contractual clauses. You may ask us for details at hello@shkaf.app.
Website cookies
Our website uses a cookie to remember your cookie notice choice. It may also use cookies required to operate the site. You can remove or block cookies in your browser settings, although some site features may then work differently. We will update this section and request any consent required by law before adding nonessential website analytics or advertising cookies.
Retention and deletion
We keep account and content information while your account is active and as needed to provide the Service. You can use Settings → Delete Account in the app. This closes access to the account and removes its posts from normal display. We retain closed-account data and backups for up to one month, then delete or anonymize them, unless a specific legal obligation, security investigation, or dispute requires longer retention. We keep transaction and compliance records for periods required by law. If you want personal information erased sooner or have questions about retained data, contact us; we will handle the request under applicable law. Deleting the app from your device does not close your account or cancel a store subscription.
You can change some profile information and delete individual content in the app. If you cannot access the app, you can request account deletion by emailing hello@shkaf.app with the subject “Delete my Shkaf account” from the address associated with your account. You may also use that address to request access, a copy, correction, or erasure of your data. We may verify that the request is from the account holder.
Your choices and rights
You can choose profile visibility, withdraw device permissions, disable push notifications, and manage content and social connections through available controls. Depending on where you live, you may have rights to access, correct, delete, receive a portable copy of, restrict or object to processing of your information, or withdraw consent. You may appeal a refusal or complain to your local data protection authority where applicable. We may verify your identity before acting on a request and will respond within the time required by law.
California residents may also request to know, correct, or delete information and, if applicable, opt out of sale or sharing for cross-context behavioral advertising and limit certain uses of sensitive information. We do not penalize people for exercising their rights. Contact hello@shkaf.app to make a request.
Children
The Service is designed for a general audience and is not directed to children. If a child uses the Service, a parent or guardian must provide any consent required by local law. A parent or guardian who believes a child has provided personal information without required consent can contact us to request review and deletion.
Security and changes
We use reasonable technical and organizational measures to protect information, including protected connections and access controls. No system is completely secure. We may update this policy as the Service changes. We will post the new version with a new effective date and give additional notice or seek consent where law requires it.
Contact
haip IT FZ LLE, Creative Tower, PO Box 4422, Fujairah, United Arab Emirates · hello@shkaf.app.