Privacy policy

Effective 2 October 2026

Orelune is operated by Rahul Kiran Sethuram. For a privacy question or request, write to support@orelune.app.

Personal data we collect

We collect these categories of personal data:

Purposes of use

We use this information to verify your sign-in, keep closets separate, identify and organise your pieces, search your closet, suggest looks, make automatic studio shots and try-ons, show images, apply usage limits, and run and protect the service. When you add an eligible piece photo, we automatically send it for analysis and studio-shot generation. If you do not want that, do not upload the photo. If you save a reference photo of yourself, requesting looks in ChatGPT or on the web automatically starts try-ons for up to four looks shown first, using that photo and eligible piece photos. Access-key assistants do not start try-ons until you explicitly request one. You can also request a try-on for another look or choose a detailed re-render.

Recipients of your data

These categories of recipients process your data on our behalf or when you use Orelune through them:

We do not sell your personal data, show ads or train our own models on your content. Outside providers process information under their own policies and may keep it beyond our control.

Data retention

Your closet records, original photos, studio shots, reference photos, try-on images and image-limit reservation records do not expire automatically. A piece record and its image files stay until you replace or delete the piece or erase your account. You can delete reference photos and try-on images one by one in Studio, or erase them with your account. Deleting a piece or reference photo does not erase earlier try-on images showing it. We count reservations from the previous 24 hours for daily limits and lifetime Free try-ons across the account's history, but do not automatically remove older records. If you delete your account, anonymous Free quota counts remain for the shared Free allowance; other account-linked quota records are removed. Expired single-use upload-link IDs are cleared when another token is claimed; merely issuing a link does not save its ID. Temporary image links normally expire after one hour and upload links after 15 minutes; an expired link does not delete its photo. Image-generation queue messages are processed or retried. Providers keep operational logs and infrastructure backups under their own policies, so we cannot promise a fixed retention period for those.

Access-key hashes, labels, permissions, activity and revocation times stay until you erase your account, even if you revoke a key; revocation immediately stops it working. Your shared browser session lasts seven days, and the temporary sign-in cookie lasts 10 minutes. Signing out clears the browser session and ends your Auth0 single sign-on session before you return home. It does not revoke keys or delete your closet; neither does a cookie expiring.

Our shared place lookup cache keeps the standardized place text, display name and coordinates without an account link or automatic expiry. Unknown place text is also kept in a shared cache for a 24-hour retry window, though expired records are not automatically deleted. We cannot identify and remove one account's cached places on account deletion without affecting other people's shared lookups. To remove a particular cached place, contact support with the place text. Forecasts stay only in temporary service memory until the provider's cache expires. Nominatim and MET Norway may keep their own request logs under their policies.

Your controls and deletion

In the web app, you can add and correct pieces, replace photos and delete individual pieces, reference photos and try-on images. You can also correct piece details and replace photos in ChatGPT. Uploading a try-on reference photo is optional; after that, creating looks in ChatGPT or on the web can automatically request try-ons, while access-key assistants require an explicit request. To erase your entire Orelune account, sign in to the web app with Auth0 and choose Settings → Delete account. Or write from your sign-in address to support@orelune.app to request removal of a piece or your account. We verify emailed requests and complete removal from our service within 30 days. Account deletion removes account-linked D1 records, R2 images and your issuer-and-subject identity mapping, except anonymous Free quota counts described above. Deleting a piece removes its image files and takes it out of saved looks, but leaves earlier try-on images; deleting a reference photo also leaves earlier try-on images. Disconnecting the ChatGPT app stops future access, not storage. Deleting from our service does not itself erase copies held by ChatGPT, your sign-in or image providers, Cloudflare logs or backups, or a separately kept owner-run local Photos catalog. Tell us if your request includes those local copies.

At your account page, you can create read-only or read/write access keys, see active keys and revoke any you no longer trust. We show each key in plain text only once; never paste it into a conversation. Erasing your account removes all its access keys.

International processing and changes

Orelune is not directed to children under 13. Cloudflare, Auth0, Google or Apple sign-in providers, OpenAI and image providers may process your information in other countries, where protections and legal rights can differ. If the service changes, we may update this policy and post the new version and effective date here. For questions or privacy requests, write to support@orelune.app.