Facondia Lab by nicastro.in
Home Apps Books Resources Authors Initiative Settemotivi ODV Legal
EN ▾
  • Italiano
  • English
  • Español
  • Français
  • Deutsch
  • 한국어
  • 日本語
  • 简体中文
  • Română
  • Polski
  • Português (Brasil)
  • Türkçe
  • Bahasa Indonesia
Home Apps Books Resources Authors Initiative Settemotivi ODV Legal
All Site-wide Chroma Closet Elephant Steampunk Morse Code Park Pin Data deletion
Legal documents › Chroma Closet › Privacy Policy
Index
  1. 1. Data Controller
  2. 2. Who This Policy Applies To
  3. 3. Minimum Age
  4. 4. Personal Data We Collect
    1. 4.1 Data Provided Directly by the User
    2. 4.2 Automatically Collected Data
    3. 4.3 Data We Do NOT Collect
    4. 4.4 Device Permissions Required by the App
  5. 5. Purposes and Legal Bases of Processing
  6. 6. Third-Party Services (Sub-processors and Partners)
  7. 7. Automatic Google Drive Backup
  8. 8. International Data Transfers
  9. 9. Data Retention
  10. 10. Your Rights
    1. 10.0 Account Deletion
    2. 10.1 GDPR Rights (EU/EEA and UK)
    3. 10.2 CCPA/CPRA Rights (California, USA)
    4. 10.3 LGPD Rights (Brazil)
    5. 10.4 APP Rights (Australia)
    6. 10.5 PIPEDA/CPPA Rights (Canada)
    7. 10.6 PDPA Rights (Thailand and Singapore)
    8. 10.7 POPIA Rights (South Africa)
    9. 10.8 PIPL Rights (People’s Republic of China)
    10. 10.9 APPI Rights (Japan)
    11. 10.10 PIPA Rights (South Korea)
    12. 10.11 DPDP Rights (India)
    13. 10.12 FADP Rights (Switzerland)
    14. 10.13 152-FZ Rights (Russian Federation)
    15. 10.14 Other jurisdictions
  11. 11. Minors — COPPA (USA)
  12. 12. Data Security
  13. 13. Advertising, Push Notifications and Consent (AdMob / Google UMP / Firebase Cloud Messaging)
  14. 14. Cookies and Tracking Technologies
  15. 15. Automated Decisions and Recommendations
  16. 16. Changes to This Policy
  17. 17. Governing Law and Jurisdiction
  18. 18. Contact

Privacy Policy

Last updated August 6, 2026

Version: 1.6 Effective date: June 18, 2026 Last updated: August 6, 2026

1. Data Controller

Sara Nicastro Trieste (Italy) Email: saranicastro.sn@gmail.com

(“Data Controller”, “we”, “us”)

For any questions regarding this Policy or the processing of your personal data, please contact us at the email address above.

Data Protection Officer (DPO): No Data Protection Officer has been appointed under GDPR Art. 37, as the Data Controller is a sole independent developer who does not carry out large-scale processing or systematic processing of special categories of data.

2. Who This Policy Applies To

This Privacy Policy (“Policy”) applies to the Chroma Closet mobile application (“App”), available on the Google Play Store for Android devices, developed and managed by the Data Controller named above.

By using the App, you accept the practices described in this Policy. If you disagree, please do not use the App.

3. Minimum Age

The App is intended for users aged at least 13 years. We do not knowingly collect personal data from children under the age of 13, or under the higher threshold set by the user’s country of residence for autonomous digital consent (between 13 and 16 years in European Union countries; 14 years in Italy, pursuant to Legislative Decree 101/2018; 14 years in South Korea, pursuant to PIPA; 14 years in China, pursuant to the PIPL). If you believe a minor has provided us with personal data without parental consent, contact us immediately: we will delete the data within 72 hours.

4. Personal Data We Collect

4.1 Data Provided Directly by the User

CategoryDescriptionWhere processed
Account credentialsSign in with Google (the App uses Sign in with Google exclusively; no proprietary passwords are managed). The OAuth token is used only at the moment of authentication and is not stored by the App: access tokens are managed by the device’s Google services. The App stores on the device, in encrypted form, only the Google account identifier and the associated email addressGoogle Identity Services (Google LLC) + encrypted local storage on the device
Wardrobe contentPhotos of garments, categories, subcategories, colours, brand, materials, condition, purchase price, tags, favourites, notesLocal device + Google Drive (automatic backup)
Outfits and collectionsGarment combinations saved by the user, with name, description, tags and any additional photosLocal device + Google Drive (automatic backup)
Wear diaryDates on which you wear garments or outfits and related notes, entered in the App’s calendar; feeds the usage statisticsLocal device + Google Drive (automatic backup)
Purchase evaluations (“Consultant”)Photos of garments you are considering buying, with price, store and notesLocal device + Google Drive (automatic backup)
Style preferencesColour season, body shape. Any body measurements entered in the body shape quiz are not stored: only the result (the shape) is keptLocal device + Google Drive (automatic backup)

4.2 Automatically Collected Data

CategoryDescriptionPurposeService
Usage dataScreens visited, features used, session durationAnalytics, product improvementFirebase Analytics
Diagnostic dataStack traces, device type, OS version, App version at time of crashBug identification and fixingFirebase Crashlytics
Advertising identifiersAndroid Advertising ID (AAID). In regions where the law requires it (e.g. EU, United Kingdom), collection for advertising purposes only takes place with your explicit consent through the form described in section 13; elsewhere, according to your device’s advertising settings (see sections 13 and 14 for how to disable it)Personalised advertising (AdMob); usage measurement and analytics (Firebase Analytics)Google AdMob, Firebase Analytics
Purchase dataSubscription status, transaction ID, type of product purchasedPremium subscription managementRevenueCat Inc.
RevenueCat technical dataRevenueCat may collect additional technical data (e.g. device identifiers, OS version, IP address) in accordance with its own privacy policySubscription service operationRevenueCat Inc.
Push notification tokenDevice identifier generated by Firebase Cloud Messaging, used to deliver notificationsSending transactional/service notifications (see section 13)Firebase Cloud Messaging

Note on Firebase Crashlytics: crash reports contain technical information about the App’s state at the time of the error. In exceptional cases, these reports may include fragments of user-generated text (e.g. outfit or garment names) if they were present in memory at the time of the crash. Such data is used exclusively for bug fixing and is deleted after 90 days.

4.3 Data We Do NOT Collect

  • Garment photos are analysed by artificial intelligence exclusively on your device. The App uses two models, both bundled with the App (no download from external services): a classifier (TFLite), which suggests the garment’s category and colour, and a segmentation model (U2Net, TFLite), which cuts the garment out of the photo background. Both models run entirely on the device: photos are never sent to our servers or to any third-party service for analysis.
  • The artificial intelligence models are pre-trained and do not train on your data or the photos you take. Both models are static and change only with App updates. No user data is used to improve or retrain the models.
  • We do not collect geolocation data. Photos you take or import are always re-processed and re-compressed by the App before being saved: in this process, the original EXIF metadata (including any GPS coordinates, device model, and timestamp embedded by the operating system) is not retained. The files included in the Google Drive backup are therefore also free of such metadata.
  • We do not collect biometric data.
  • We do not sell personal data to third parties.

4.4 Device Permissions Required by the App

PermissionReasonRequired
CameraTake photos of garments directly in the AppNo (you can use photos from the gallery)
Notifications (Android 13+)Show App notifications: Google Drive backup status and transactional/service notifications (see section 13)No — if denied, the App still works but you will not receive any notification, including service ones
InternetCommunication with Firebase, AdMob, RevenueCat; Google Drive backupYes, for cloud features

Gallery: photo selection from the gallery is handled by the Android system photo picker (Photo Picker), which requires no storage permission: the App only receives the photos you choose and never has access to your entire gallery.

Google Account: signing in with a Google account (required to use the App) and the separate, optional authorisation for Google Drive backup are not Android permissions but authorisations managed through your Google account, revocable at any time from myaccount.google.com > Security > Apps with account access.

You can revoke permissions at any time from Android settings (Settings > Apps > Chroma Closet > Permissions), bearing in mind that revoking required permissions may limit App functionality.

5. Purposes and Legal Bases of Processing

PurposeLegal basis (GDPR Art. 6)Details
Account creation and managementPerformance of contract (Art. 6.1.b)Required to access the App’s features
Service operation (wardrobe, outfits)Performance of contract (Art. 6.1.b)Core App function
Automatic backup to Google DrivePerformance of contract + Consent (Art. 6.1.a/b)The user explicitly authorises access to Google Drive via OAuth on first use of the backup
Analytics and product improvementLegitimate interest (Art. 6.1.f)To improve stability and usability; does not include individual profiling; interest balanced against the user’s reasonable expectations
Diagnostics and crash reportingLegitimate interest (Art. 6.1.f)To ensure service stability; interest balanced against data minimisation
Sending transactional/service notificationsPerformance of contract + Legitimate interest (Art. 6.1.b/f)Notifications required for the Service to function (e.g. confirmation of actions, security alerts, subscription-related communications) — see section 13
Personalised advertising (AdMob)Consent (Art. 6.1.a)Requested via Google UMP before any tracking; revocable at any time
Non-personalised advertisingLegitimate interest (Art. 6.1.f)Contextual ads without individual profiling
Premium subscription managementPerformance of contract (Art. 6.1.b)Verification and activation of paid features
Compliance with legal obligationsLegal obligation (Art. 6.1.c)E.g. responding to lawful requests from authorities

6. Third-Party Services (Sub-processors and Partners)

We use the following third-party services, each subject to its own privacy policy:

ServiceProviderPurposePrivacy policy
Google Identity Services (Sign in with Google)Google LLCUser authenticationhttps://policies.google.com/privacy
Firebase AnalyticsGoogle LLCApp usage analysishttps://firebase.google.com/support/privacy
Firebase CrashlyticsGoogle LLCCrash diagnosticshttps://firebase.google.com/support/privacy
Firebase Cloud MessagingGoogle LLCSending transactional/service push notificationshttps://firebase.google.com/support/privacy
Google AdMobGoogle LLCIn-app advertisinghttps://policies.google.com/privacy
Google Drive APIGoogle LLCAutomatic backup of wardrobe data and photoshttps://policies.google.com/privacy
RevenueCatRevenueCat Inc.In-app subscription managementhttps://www.revenuecat.com/privacy
Google Play BillingGoogle LLCIn-app payment processinghttps://policies.google.com/privacy

All listed providers process data in compliance with the GDPR (including through Standard Contractual Clauses where applicable) and the laws of the United States and other countries in which they operate. This Policy does not cover the privacy practices of third-party websites and services accessible through links in the App. Links to providers’ policies are subject to change by the respective third parties; if a link is broken, please search for the updated privacy policy directly on the provider’s website.

7. Automatic Google Drive Backup

The App performs automatic backups of your data — garments with photos and metadata, outfits, wardrobes, wear diary, purchase evaluations, colour season and body shape — to your personal Google Drive account, once you have authorised access through Google’s OAuth process. Google Drive backup is a Premium plan feature and can be enabled/disabled from the Profile screen.

What is NOT included in the backup: in-app credits and the expanded limits obtained by spending credits (additional garment and outfit slots) are stored exclusively on the device and are not included in the backup: uninstalling the App or switching devices means they are permanently lost. The only exception is individual garments already unlocked with credits, whose unlocked status is recorded in the backup and survives a restore.

What this means for you:

  • Backup data is stored in your personal Google Drive account, not on the Data Controller’s servers, in an area reserved for applications (the so-called “application data folder”), not visible when browsing your Google Drive files.
  • Only the App can read this data: neither the Data Controller nor any other application has access to it (Google accesses it under the terms of your Google account).
  • You can delete the backup data at any time from Google Drive: Settings > Manage apps > Chroma Closet > Delete hidden app data.
  • You can revoke the App’s access to Google Drive at any time from your Google account settings (myaccount.google.com > Security > Apps with account access).
  • Without Google Drive access, the App works normally but your data remains on the device only.

8. International Data Transfers

The third-party providers listed (Google LLC, RevenueCat Inc.) are headquartered in the United States and may transfer and process personal data in the US and in other countries outside the European Union.

Such transfers take place in compliance with applicable regulations, including:

  • Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914/EU);
  • Google’s participation in the EU–US Data Privacy Framework (in force since July 2023).

Note for residents of Japan: under Art. 28 of the APPI, the transfer of personal data to a third party located in a foreign country is subject to specific requirements when that country is not recognised by the Personal Information Protection Commission as having a data protection system equivalent to Japan’s (unlike the European Economic Area and the United Kingdom, the United States does not fall within this recognition). By using the App and enabling features that involve sending data to Google LLC and RevenueCat Inc. (both headquartered in the United States — see section 6), you provide your consent to such transfer. You may withdraw consent at any time by disabling the affected features (Drive backup, personalised advertising) or by discontinuing use of the App, it being understood that this may limit its functionality.

Note for residents of Russia: under Art. 12 of Federal Law No. 152-FZ on personal data, the cross-border transfer of personal data to countries that do not ensure adequate protection (which, for the purposes of that law, includes the United States) requires the data subject’s consent. By using the App and enabling features that involve sending data to Google LLC and RevenueCat Inc. (both headquartered in the United States — see section 6), you provide such consent, which you may withdraw at any time by disabling the affected features (Drive backup, personalised advertising) or by discontinuing use of the App.

Note for residents of China: under Art. 39 of the Personal Information Protection Law (PIPL), the transfer of personal data outside the People’s Republic of China requires the data subject’s separate and specific consent, in addition to a personal information protection impact assessment. By using the App and enabling features that involve sending data to Google LLC and RevenueCat Inc. (both headquartered in the United States — see section 6), you provide such separate consent, which you may withdraw at any time by disabling the affected features (Drive backup, personalised advertising) or by discontinuing use of the App.

9. Data Retention

CategoryRetention period
Account data (email and account identifier on the device)For the duration of the account; deleted immediately upon account deletion from the App. This data exists exclusively on your device: the Data Controller cannot delete it remotely — an email request can only concern data processed by third-party providers (see sections 6 and 10.0)
Aggregated analytics data14 months (Firebase Analytics default setting)
Crash logs90 days (Firebase Crashlytics)
Push notification token (FCM)For the duration of the installation linked to the account; deleted on App uninstall, logout, or account deletion (see section 10.0)
Subscription dataFor the duration of the commercial relationship + applicable fiscal/legal obligations (max 10 years)
Local data (wardrobe, photos)Until the App is uninstalled or manually deleted by the user
Google Drive backupUntil deleted by the user (Google Drive > Settings > Manage apps > Delete hidden app data) or access is revoked

Note on logging out: signing out of the App (logout) does not delete the account’s local data, which remains on the device for a possible later sign-in with the same account. To delete it permanently, use account deletion (see section 10.0) or uninstall the App.

10. Your Rights

10.0 Account Deletion

You can delete your account directly from the App (Profile > Delete account). Deletion is permanent and irreversible and involves:

  • automatic deletion of the backup file from your Google Drive (see note below);
  • deletion of all wardrobe data, photos, and preferences on the device;
  • deletion of the account identifier and associated email stored on the device, disconnecting your Google account from the App;
  • unregistering the push notification token (FCM) associated with the account, stopping the delivery of notifications;
  • disconnection of the RevenueCat subscription profile from the device. Subscription data already recorded by RevenueCat and Google Play (e.g. accounting and tax records) is not automatically deleted, as it is subject to legal retention obligations; you may request its deletion, to the extent permitted by law, by writing to the Data Controller.

Usage and diagnostic data (Firebase Analytics / Crashlytics): this data is not associated with a profile accessible to the Data Controller and is deleted automatically at the end of the retention periods indicated in section 9 (14 months and 90 days respectively). You may request earlier deletion by writing to the Data Controller.

Google Drive Backup: during account deletion, the App automatically deletes the backup file created in your Google Drive. Deletion is performed on a “best effort” basis: if it fails (for example, due to no network connection at that moment), the file remains in your personal Google Drive space — always and only under your control — and you can delete it at any time from Google Drive (Settings > Manage apps > Chroma Closet > Delete hidden app data) or by revoking the App’s access from your Google account (myaccount.google.com > Security > Apps with account access).

If you have already uninstalled the App: instructions for deleting your account and data are also available on the dedicated web page nicastro.in/en/legale/data-deletion-cancellazione-dati/. Account deletion is performed from within the App, because the Data Controller operates no servers of their own and has no access to your data; if you uninstalled the App without first deleting your account:

  • your local data (wardrobe, photos, preferences) was already removed from the device by Android when the App was uninstalled;
  • any backup file in your Google Drive remains under your exclusive control: you can delete it from Google Drive (Settings > Manage apps > Chroma Closet > Delete hidden app data) and revoke the App’s access at myaccount.google.com > Security > Apps with account access, without reinstalling the App;
  • alternatively, you can reinstall the App, sign in with the same Google account and use Profile > Delete account;
  • for data processed by third-party providers (see section 6), you can write to the Data Controller at the email address shown at the top of this document.

10.1 GDPR Rights (EU/EEA and UK)

As a data subject under the GDPR (EU Regulation 2016/679) and UK GDPR, you have the right to:

  • Access (Art. 15): obtain confirmation of processing and a copy of your personal data.
  • Rectification (Art. 16): correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”, Art. 17): request the deletion of data, subject to legal obligations requiring its retention.
  • Restriction of processing (Art. 18): request the suspension of processing in certain circumstances.
  • Data portability (Art. 20): receive your data in a structured, machine-readable format. Note: since your wardrobe data resides exclusively on your device (and, if backup is enabled, in your personal Google Drive) and the Data Controller has no access to it, the Data Controller cannot materially provide you with a copy of that data; the App does not currently offer an export feature. The right remains fully exercisable for data processed by third-party providers (see section 6).
  • Objection (Art. 21): object to processing based on legitimate interest, including profiling.
  • Withdrawal of consent: withdraw consent at any time (e.g. advertising preferences) without affecting the lawfulness of prior processing.
  • Complaint: lodge a complaint with the competent supervisory authority:
    • Italy and EU: Garante per la Protezione dei Dati Personali (Italian Data Protection Authority, garanteprivacy.it, +39 06 696771)
    • United Kingdom: Information Commissioner’s Office (ICO, ico.org.uk, 0303 123 1113)

To exercise your rights, write to saranicastro.sn@gmail.com with subject “GDPR Rights Request”. We will respond within 30 days (extendable to 90 days in particularly complex cases, with notice within the first month).

10.2 CCPA/CPRA Rights (California, USA)

If you are a California resident, under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to:

  • Know what categories of personal data we collect and with whom we share it (see sections 4 and 6).
  • Deletion of your personal data, subject to the exceptions provided by law.
  • Correction of inaccurate personal data.
  • Opt-out from the sale or sharing of personal data. We do not sell personal data. The display of personalised ads through Google AdMob may constitute “sharing” of personal data under the CPRA: you can opt out at any time by disabling ad personalisation using the controls described in Section 13 (Android Settings > Google > Ads, or by resetting your Android Advertising ID), or by sending a request to the email address indicated below. After opting out, you will only receive non-personalised ads.
  • Non-discrimination for exercising your CCPA/CPRA rights.
  • Limitation of use of sensitive information (where applicable).

Do Not Track (DNT): Chroma Closet is a native mobile application and does not operate via a browser. DNT signals sent by browsers do not apply to the App and are not recognised. To manage advertising tracking preferences, use the controls described in section 13 and Android settings (Settings > Google > Ads).

To exercise CCPA/CPRA rights, contact us at saranicastro.sn@gmail.com with subject “California Privacy Request”. We will respond within 45 days, extendable by a further 45 days with notice.

Other US states: if you reside in another United States state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Texas, Oregon, Montana), we grant you rights equivalent to those described in this section (access, correction, deletion, opt-out from sale/sharing, non-discrimination), in addition to the minimum standard described in section 10.14. Contact us at the same email address, stating your state of residence.

10.3 LGPD Rights (Brazil)

If you are a Brazil resident, under the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei n. 13.709/2018), you have the right to: confirmation of processing, access, correction, anonymisation/blocking/deletion of unnecessary data, portability, information on third parties with whom data is shared, withdrawal of consent, and objection to processing. We will respond within 15 days of a request. You may lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados, gov.br/anpd).

10.4 APP Rights (Australia)

If you are an Australian resident, data processing complies with the Australian Privacy Principles (APP, Privacy Act 1988 Cth). You have the right to access your personal data and request its correction; we will respond within 30 days. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC, oaic.gov.au).

10.5 PIPEDA/CPPA Rights (Canada)

If you are a Canadian resident, we process your data in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the Consumer Privacy Protection Act (CPPA) and equivalent provincial laws (PIPA Alberta/BC, Loi 25 Québec). You have the right of access and rectification; we will respond within 30 days. You may lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca).

10.6 PDPA Rights (Thailand and Singapore)

If you are a resident of Thailand, we comply with the Personal Data Protection Act B.E. 2562 (PDPA 2019). If you are a resident of Singapore, we comply with the Personal Data Protection Act 2012 (PDPA). In both cases you have the right of access, correction, erasure, and data portability. To exercise these rights, contact us at the email address listed.

10.7 POPIA Rights (South Africa)

If you are a South African resident, we process your data in compliance with the Protection of Personal Information Act (POPIA, Act 4 of 2013). The Information Regulator is the competent supervisory authority (inforegulator.org.za, inforeg@justice.gov.za).

10.8 PIPL Rights (People’s Republic of China)

If you are a resident of the People’s Republic of China, we process your data in compliance with the Personal Information Protection Law (PIPL, in force since 1 November 2021). You have the right to request access to and a copy of your personal data, correction of inaccurate data, deletion, withdrawal of consent to processing, and an explanation of the rules by which we process your personal data. You may lodge a complaint with the Cyberspace Administration of China (CAC, cac.gov.cn). The PIPL also requires your separate consent for the transfer of your personal data outside of China (Art. 39): see the dedicated note in section 8.

10.9 APPI Rights (Japan)

If you are a resident of Japan, we process your data in compliance with the Act on the Protection of Personal Information (APPI, Act No. 57 of 2003, as amended). You have the right to request disclosure (開示請求) of the purposes of use and the personal data held, correction, addition, or deletion (訂正・追加・削除) of inaccurate data, and suspension of use or erasure (利用停止・消去) where processing does not comply with the APPI or is no longer necessary for the stated purposes. To exercise these rights, contact us at the email address indicated at the top of this document. The competent supervisory authority is the Personal Information Protection Commission (個人情報保護委員会, PPC — ppc.go.jp).

10.10 PIPA Rights (South Korea)

If you are a resident of the Republic of Korea, we process your data in compliance with the Personal Information Protection Act (PIPA, Act No. 10465 of 2011, as amended). You have the right to request access to, rectification of, deletion of, and suspension of the processing of your personal data. You may lodge a complaint with the Personal Information Protection Commission (PIPC, pipc.go.kr). The PIPA also requires your consent for the transfer of your personal data outside of South Korea: by using the App and enabling features that involve sending data to Google LLC and RevenueCat Inc. (both headquartered in the United States — see section 6), you provide such consent, which you may withdraw at any time by disabling the relevant features or discontinuing use of the App.

10.11 DPDP Rights (India)

If you are a resident of India, we process your data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act). You have the right to access your personal data, to request its correction and erasure, and to nominate a person to exercise your rights in the event of incapacity or death. You may lodge a complaint with the Data Protection Board of India.

10.12 FADP Rights (Switzerland)

If you are a resident of Switzerland, we process your data in compliance with the Federal Act on Data Protection (revised FADP, in force since 1 September 2023). You have rights of access, rectification, and erasure comparable to those provided by the GDPR (see section 10.1). The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch).

10.13 152-FZ Rights (Russian Federation)

If you are a resident of the Russian Federation, we process your data in compliance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (as amended). You have the right to request access to, rectification of, blocking of, and deletion of your personal data, and to withdraw your consent to processing at any time. You may lodge a complaint with Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology and Mass Media, rkn.gov.ru).

Data localisation (Art. 18(5)): Russian law requires that the initial collection of personal data of Russian citizens be carried out using databases located within the territory of the Russian Federation. The Developer does not operate its own servers: App data resides exclusively on your device and, if you enable Premium backup, in your personal Google Drive account, under your exclusive control — not on infrastructure operated by the Developer inside or outside Russia. The third-party providers listed in section 6 (Google LLC, RevenueCat Inc.) act as independent data controllers and may process data outside the Russian Federation as part of their respective services (see also the cross-border transfer note in section 8).

10.14 Other jurisdictions

If you reside in a country not expressly listed in this section, we apply in any event, as a minimum standard, the protections provided by the GDPR (access, rectification, erasure, objection — see section 10.1). You may exercise the rights granted by the law of your country of residence by writing to saranicastro.sn@gmail.com: we will respond within 30 days.

11. Minors — COPPA (USA)

In compliance with the Children’s Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.), the App is not intended for children under 13 and we do not knowingly collect personal data from such minors without verifiable parental consent. If you are a parent or guardian and believe your child has created an account, contact us immediately at saranicastro.sn@gmail.com: we will delete the data within 72 hours.

12. Data Security

We implement technical and organisational measures appropriate to the risk, including:

  • Data transmission via encrypted connections (HTTPS/TLS 1.2+).
  • Authentication via Sign in with Google (Google Identity Services). Access tokens are not stored by the App; the account identifier and associated email are stored on the device in encrypted form (Android Keystore, where available; if the Keystore is temporarily unavailable, this data remains protected by the App’s private sandbox).
  • Local data protected by the Android OS sandbox (scoped storage).
  • No servers of the Data Controller’s own: data resides on the device and, if backup is enabled, in your personal Google Drive account.
  • Regular security updates to the App.

No data transmission or storage system can guarantee absolute security. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you without undue delay, in accordance with GDPR Art. 34. The breach will also be reported to the competent supervisory authority within 72 hours under GDPR Art. 33.

13. Advertising, Push Notifications and Consent (AdMob / Google UMP / Firebase Cloud Messaging)

The App uses Google AdMob exclusively in the rewarded ads format: there are no banners or automatically displayed ads. An ad plays only when you explicitly request it (for example, by tapping “Watch an ad” to earn in-app credits — see the Terms and Conditions for how the credit system works). Ads apply to the free plan: Premium users do not encounter ads in normal use of the App.

In regions where the law requires it (e.g. European Union, United Kingdom, Switzerland), before any data collection for advertising purposes you are presented with a GDPR-compliant consent form (via Google User Messaging Platform — UMP) in which you can:

  • Accept personalised ads (based on your interests and behaviour).
  • Decline personalisation (you can still play non-personalised contextual ads).

In regions where local law does not require the consent form, ads may be personalised based on your device’s and Google account’s advertising settings. You can turn off personalisation at any time using the controls described below.

How to change your preferences: you can review or change your advertising consent at any time from within the App (Profile > Ad preferences > Manage, which reopens the Google UMP consent form, where required for your region). Alternatively, you can disable ad personalisation directly in Android settings (Settings > Google > Ads > Opt out of ads personalisation) or reset your Android Advertising ID. To manage Google ad settings: adssettings.google.com

Firebase Analytics: usage data collection is based on legitimate interest (see section 5) and there is no in-App switch to disable it. You can object to the processing at any time by writing to saranicastro.sn@gmail.com (subject “Analytics objection”); you can also reset or delete your Android Advertising ID from Android settings to unlink advertising identifiers from your device. Analytics data is in any case deleted automatically after 14 months (see section 9).

Push notifications (Firebase Cloud Messaging): the App may use Firebase Cloud Messaging (FCM) to send you transactional/service push notifications — e.g. confirmation of an action, security alert, communications about your subscription: necessary for the Service to function, processed on the basis of performance of contract/legitimate interest (GDPR Art. 6.1.b/f — see section 5). These do not require separate consent, but remain subject to the Android 13+ system “Notifications” permission (section 4.4): if you deny it, you will not receive any notification.

To deliver notifications, the App registers a unique device token with Firebase Cloud Messaging (see sections 4.2 and 6), retained as described in section 9.

14. Cookies and Tracking Technologies

Chroma Closet is a native Android mobile application and does not use cookies. The integrated third-party services (Firebase, AdMob) may use cookie-like identifiers (e.g. Android Advertising ID — AAID) subject to the consent preferences described in section 13. You can reset or disable the AAID from Android settings: Settings > Google > Ads.

15. Automated Decisions and Recommendations

The App uses automated processes for the following features:

  • AI garment classification (TFLite on-device): the App automatically suggests a garment’s category, subcategory, and colour from its photo. This classification takes place entirely on the device and can be corrected manually by the user at any time.
  • Outfit compatibility score: the App automatically calculates a colour-harmony affinity score between the garments in an outfit based on the user’s colour season. This score is purely indicative.
  • Outfit suggestions: the App automatically generates suggested garment combinations based on the user’s wardrobe and preferences.

None of these processes produces legal effects or decisions that significantly affect the individual within the meaning of GDPR Art. 22. All suggestions and scores are indicative and the user retains full control over their own choices. No behavioural profiling for commercial purposes is carried out other than the personalised advertising described in Section 13, which is subject to consent where required by applicable law and can be disabled by the user at any time.

16. Changes to This Policy

We reserve the right to update this Policy to reflect legislative, technical, or operational changes. The current version is always available within the App and at https://nicastro.in/en/legale/chroma-closet-privacy-policy/ : we invite you to review it periodically. The date of the last update is always shown at the top of the document. Continued use of the App following any change constitutes acceptance of the updated version.

17. Governing Law and Jurisdiction

This Policy and any dispute relating to the processing of personal data by the Data Controller are governed by Italian law, in compliance with applicable European regulations (in particular the GDPR).

For any dispute concerning the interpretation, validity, or performance of this Policy, the Court of Trieste (Italy) has exclusive jurisdiction, unless mandatory provisions of the law applicable in the user’s country of residence provide otherwise.

Users residing in the European Union retain in any event the right to lodge a complaint with the supervisory authority of their country of residence under GDPR Art. 77, regardless of the contractual jurisdiction indicated.

18. Contact

For any questions, requests to exercise your rights, or complaints:

Data Controller Sara Nicastro Trieste (Italy) Email: saranicastro.sn@gmail.com

We will respond to all requests within 30 days of receipt.


Policy drawn up in compliance with: EU Regulation 2016/679 (GDPR) · UK GDPR · California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA) · Children’s Online Privacy Protection Act (COPPA) · Lei Geral de Proteção de Dados (LGPD, Brazil) · Personal Information Protection Law (PIPL, China) · Personal Data Protection Act (PDPA, Thailand 2019 and Singapore 2012) · Australian Privacy Principles — Privacy Act 1988 (Australia) · PIPEDA/Consumer Privacy Protection Act (Canada) · Protection of Personal Information Act (POPIA, South Africa) · Act on the Protection of Personal Information (APPI, Japan) · Personal Information Protection Act (PIPA, South Korea) · Federal Law No. 152-FZ on Personal Data (Russian Federation) · Digital Personal Data Protection Act (DPDP, India 2023) · Federal Act on Data Protection (FADP, Switzerland)

This Policy has been drawn up by the Data Controller for informational purposes. For complex legal questions or verification of compliance in specific jurisdictions, consultation with a legal professional specialised in privacy law is recommended.

Facondia Lab by nicastro.in

Android apps that make everyday things lighter.

Subscribe to the newsletter · RSS feeds
Apps Chroma ClosetElephantSteampunk Morse CodePark Pin All applications
Books Too Many Clothes, Nothing to WearMeal Prep for GF+DF Athletes All books
Resources Resources
Authors Alice FabrisAnna Ferro Authors
Legal documents Site privacy policy Cookie policy All documents Cookie preferences
© 2026 Facondia Lab · All rights reserved.