Privacy policy
Effective 2 October 2026
Orelune is operated by Rahul Kiran Sethuram. For a privacy question or request, write to support@orelune.app.
Personal data we collect
We collect these categories of personal data:
- Your sign-in identity: Auth0 (Okta) gives us an issuer and subject, from which we make your account identifier. For identity, the closet service stores only those three values, not your email, name or password. Auth0 keeps your sign-in information. If you choose Google or Apple sign-in, that provider may give Auth0 your name and email; Apple may give a private-relay address instead. We link a verified social identity to your existing primary account only if the email uniquely matches, so your closet stays with that account. An unverified or ambiguous match is not linked, and a private-relay address may result in a separate account.
- Your closet: piece names, details, notes, photos, saved looks, corrections and studio-shot change requests. A photo of a piece may also show people, bystanders or surroundings. If you choose to upload a photo of yourself for a try-on, we store that reference photo and the resulting try-on images. We keep generated studio shots alongside your original photos.
- Service activity: timestamps, image-limit reservations, temporary single-use upload-link IDs, and access-key labels, permissions, creation and last-use times and hashes rather than plain-text keys. We also process error and request logs and your questions and requests so we can answer you. If you attach a photo in ChatGPT, it may give us a temporary file link that we use to fetch your photo.
- Places you choose to share: if you give us a city or place for an outfit forecast, we process its text and the date or period you request. We save the standardized place text, resolved name and coordinates in a shared Cloudflare D1 lookup table without your account ID, so a repeat lookup does not need another geocoding request. We do not ask for your device location or save the place as a closet item. Please enter a city or place, not a private address.
Purposes of use
We use this information to verify your sign-in, keep closets separate, identify and organise your pieces, search your closet, suggest looks, make automatic studio shots and try-ons, show images, apply usage limits, and run and protect the service. When you add an eligible piece photo, we automatically send it for analysis and studio-shot generation. If you do not want that, do not upload the photo. If you save a reference photo of yourself, requesting looks in ChatGPT or on the web automatically starts try-ons for up to four looks shown first, using that photo and eligible piece photos. Access-key assistants do not start try-ons until you explicitly request one. You can also request a try-on for another look or choose a detailed re-render.
Recipients of your data
These categories of recipients process your data on our behalf or when you use Orelune through them:
- Cloudflare hosts our service and keeps your account and closet records in its D1 database, images in R2 storage, and image-generation jobs in Queues. Its infrastructure may also process operational logs and backups.
- Auth0 (Okta) handles sign-in and links verified, uniquely matching Google or Apple identities to existing accounts. It holds your sign-in information; the closet service receives only issuer and subject and does not send closet photos to Auth0. If you choose Google or Apple sign-in, that provider may share your name and email with Auth0 under its own privacy policy. Neither receives closet photos through sign-in. Google sign-in is separate from image processing by Google Gemini.
- OpenRouter and the model providers it uses, currently Google Gemini models, process piece photos for analysis and automatic studio shots, and your reference and eligible piece photos for automatic and individually requested try-ons. When you ask for a studio-shot change, we send your request text with the original photo.
- OpenStreetMap Nominatim receives only the city or place text you choose for an outfit forecast, and only if that place is not already in our cache. MET Norway receives the resulting approximate coordinates, rounded to four decimal places, for the forecast. Neither receives closet photos, your sign-in identity or account ID with the request. Without a place from you, we make no request to a weather provider. Forecast data is credited to MET Norway under CC BY 4.0; place data is © OpenStreetMap contributors under ODbL.
- OpenAI/ChatGPT receives your app requests and results when you use Orelune there, including closet details and, in some results, image content. ChatGPT handles files you attach before it sends us a temporary download link. Its app display loads short-lived image links from our service.
- Other assistants you connect with your own access key receive requests and results, including piece details and signed, temporary image links in piece-detail, display and ready try-on-status results. Anyone holding one of those links can see its image until the link expires. Their providers may keep conversations or links under their own policies; check those policies before connecting.
We do not sell your personal data, show ads or train our own models on your content. Outside providers process information under their own policies and may keep it beyond our control.
Data retention
Your closet records, original photos, studio shots, reference photos, try-on images and image-limit reservation records do not expire automatically. A piece record and its image files stay until you replace or delete the piece or erase your account. You can delete reference photos and try-on images one by one in Studio, or erase them with your account. Deleting a piece or reference photo does not erase earlier try-on images showing it. We count reservations from the previous 24 hours for daily limits and lifetime Free try-ons across the account's history, but do not automatically remove older records. If you delete your account, anonymous Free quota counts remain for the shared Free allowance; other account-linked quota records are removed. Expired single-use upload-link IDs are cleared when another token is claimed; merely issuing a link does not save its ID. Temporary image links normally expire after one hour and upload links after 15 minutes; an expired link does not delete its photo. Image-generation queue messages are processed or retried. Providers keep operational logs and infrastructure backups under their own policies, so we cannot promise a fixed retention period for those.
Access-key hashes, labels, permissions, activity and revocation times stay until you erase your account, even if you revoke a key; revocation immediately stops it working. Your shared browser session lasts seven days, and the temporary sign-in cookie lasts 10 minutes. Signing out clears the browser session and ends your Auth0 single sign-on session before you return home. It does not revoke keys or delete your closet; neither does a cookie expiring.
Our shared place lookup cache keeps the standardized place text, display name and coordinates without an account link or automatic expiry. Unknown place text is also kept in a shared cache for a 24-hour retry window, though expired records are not automatically deleted. We cannot identify and remove one account's cached places on account deletion without affecting other people's shared lookups. To remove a particular cached place, contact support with the place text. Forecasts stay only in temporary service memory until the provider's cache expires. Nominatim and MET Norway may keep their own request logs under their policies.
Your controls and deletion
In the web app, you can add and correct pieces, replace photos and delete individual pieces, reference photos and try-on images. You can also correct piece details and replace photos in ChatGPT. Uploading a try-on reference photo is optional; after that, creating looks in ChatGPT or on the web can automatically request try-ons, while access-key assistants require an explicit request. To erase your entire Orelune account, sign in to the web app with Auth0 and choose Settings → Delete account. Or write from your sign-in address to support@orelune.app to request removal of a piece or your account. We verify emailed requests and complete removal from our service within 30 days. Account deletion removes account-linked D1 records, R2 images and your issuer-and-subject identity mapping, except anonymous Free quota counts described above. Deleting a piece removes its image files and takes it out of saved looks, but leaves earlier try-on images; deleting a reference photo also leaves earlier try-on images. Disconnecting the ChatGPT app stops future access, not storage. Deleting from our service does not itself erase copies held by ChatGPT, your sign-in or image providers, Cloudflare logs or backups, or a separately kept owner-run local Photos catalog. Tell us if your request includes those local copies.
At your account page, you can create read-only or read/write access keys, see active keys and revoke any you no longer trust. We show each key in plain text only once; never paste it into a conversation. Erasing your account removes all its access keys.
International processing and changes
Orelune is not directed to children under 13. Cloudflare, Auth0, Google or Apple sign-in providers, OpenAI and image providers may process your information in other countries, where protections and legal rights can differ. If the service changes, we may update this policy and post the new version and effective date here. For questions or privacy requests, write to support@orelune.app.