OOTD

Privacy Policy개인정보처리방침

Last updated 18 September 20262026년 9월 18일 개정

The short version. Your face is found and covered on your phone. The original photo never leaves your device. We never build or keep a face template, faceprint, or any other biometric identifier. What we upload is the already-covered picture.

1. Who we are

OOTD is run by an independent developer. For anything in this policy, write to rrhlrmrr@gmail.com.

Under the GDPR we are the controller of the personal data described here.

2. How faces are handled

This is the part most people care about, so it comes first.

  1. You pick a photo. It stays on your phone.
  2. An on-device model (Google ML Kit Face Detection) looks for faces. It runs entirely on your phone and never sends the photo anywhere.
  3. Each face it finds is pixelated in place. The result is a new image.
  4. Only that covered image is uploaded. The original is never sent to us and we never store it.
  5. Once the covered image reaches our server, Google Cloud Vision checks it again for any face we missed and for sexual or violent content. A post stays out of the feed until that check passes.

Biometric identifiers

We do not collect, capture, store, sell, lease, trade, or otherwise profit from biometric identifiers or biometric information, including face geometry, as those terms are used in the Illinois Biometric Information Privacy Act (740 ILCS 14) and comparable laws in Texas and Washington.

Face detection tells us where a face sits in a picture. It produces rectangles and nothing else. It does not measure identity, does not produce a template that could match one person to another, and nothing it computes is written to disk or transmitted. The rectangles exist only long enough to draw pixels over them, then they are gone.

The same holds for the server check: Google Cloud Vision returns a bounding box and a confidence score, which we use once to decide whether a post can go live. Google processes that image as our service provider and does not use it to train its models.

3. What we hold

Account
Email address, and a Google or Apple account identifier if you signed in that way. Passwords are stored only as a hash and we never see them.
Profile
Nickname, date of birth, country, city, gender, height, bio, style tags, the contact handles you choose to publish, and your matching preferences (who you want to see, age range, what you are here for).
Posts
The covered photo, a caption, style tags, and any garment details you chose to add — category, brand, price, and link. All of those details are optional.
Activity
Which outfit you picked in each head-to-head, who you liked or passed on, your matches, and anyone you blocked or reported.
Device
A push notification token, whether the device is Android or iOS, and the language you read in. This is what lets us tell you about a match.
Purchases
Whether a subscription is active, handled by RevenueCat. We never see your card. Apple and Google take the payment and only tell us whether it went through.
Logs
Our hosting provider keeps request logs, including IP address, for a short period to keep the service running and to catch abuse.

We do not run advertising and we do not sell or share personal data for advertising.

4. Why we hold it

Under the GDPR, each purpose rests on one of these grounds.

5. What other people see

Your covered photos, nickname, city, style tags, bio, and any garment details you added are visible to other signed-in members. Your date of birth is not shown; only your age is.

Your contact handles are shown to one person only: someone you matched with. A match happens when you both liked each other's outfits. There is no chat inside OOTD by design, so a match simply hands over the handles you already chose to publish. Anything that happens on WhatsApp, Instagram, or anywhere else is outside our service and this policy.

Your ratings and who you liked or passed on are never shown to anyone.

6. Who else processes your data

Each of these acts as our processor under a data processing agreement. Where data leaves the European Economic Area or the United Kingdom, the transfer rests on the European Commission's Standard Contractual Clauses.

7. How long we keep it

8. Deleting your account

Open the app, go to your profile, and choose to delete your account. Your photos are removed from storage and your account and profile are removed from our database. This cannot be undone.

Posts already rated by others leave anonymous counters behind in the rating history. Those rows carry no identifier that points back to you.

9. Your rights

If the GDPR or the UK GDPR applies to you, you may ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Write to rrhlrmrr@gmail.com and we will answer within one month. You may also complain to your national supervisory authority.

If you are in Korea, you hold the equivalent rights under the Personal Information Protection Act and may bring a dispute to the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).

If you are in California, you may ask what we collected, ask us to delete it, and ask us to correct it. We do not sell or share personal information as the CCPA uses those words, and we will not treat you differently for exercising a right.

If you are in Illinois, Texas, or Washington, section 2 sets out our position on biometric law.

10. Age

You must be 16 or older to use OOTD. Matching is closed to anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, write to us and we will remove it.

11. Security

Traffic is encrypted in transit. Row-level security in our database means one member cannot read another member's private rows. Photo storage is scoped so that only the uploader can write to their own folder. No system is perfect, and we will tell you and the relevant authority if a breach puts you at risk.

12. Changes

If we change this policy in a way that matters, we will tell you in the app before the change takes effect. The date at the top always shows the current version.

짧게 말하면. 얼굴은 여러분 휴대폰 안에서 찾아 가립니다. 원본 사진은 기기를 떠나지 않습니다. 얼굴 특징값이나 얼굴 식별 정보를 만들지도 보관하지도 않습니다. 서버로 올라가는 것은 이미 가려진 사진뿐입니다.

1. 운영자

OOTD 는 개인 개발자가 운영합니다. 이 방침에 관한 문의는 rrhlrmrr@gmail.com 으로 보내 주십시오.

개인정보 보호책임자는 OOTD 운영자이며 연락처는 rrhlrmrr@gmail.com 입니다.

2. 얼굴을 다루는 방식

가장 많이 물어보시는 부분이라 먼저 적습니다.

  1. 사진을 고릅니다. 사진은 휴대폰에 그대로 있습니다.
  2. 기기 안의 모델(Google ML Kit Face Detection)이 얼굴을 찾습니다. 전부 휴대폰에서 돌고 사진을 어디로도 보내지 않습니다.
  3. 찾은 얼굴을 그 자리에서 모자이크로 덮습니다. 새 이미지가 만들어집니다.
  4. 가려진 이미지만 올라갑니다. 원본은 저희에게 오지 않고 저희는 보관하지 않습니다.
  5. 가려진 이미지가 서버에 닿으면 Google Cloud Vision 이 놓친 얼굴이 있는지, 선정적이거나 폭력적인 내용이 있는지 다시 봅니다. 이 검사를 통과해야 피드에 올라갑니다.

생체인식정보

저희는 얼굴 특징값을 비롯한 생체인식정보를 수집하거나 저장하거나 판매하거나 대여하거나 거래하지 않으며 그것으로 이익을 얻지 않습니다. 미국 일리노이주 생체정보보호법(740 ILCS 14)과 텍사스주·워싱턴주의 같은 취지 법률에서 쓰는 뜻 그대로입니다.

얼굴 검출이 알려 주는 것은 사진 어디에 얼굴이 있느냐뿐입니다. 결과는 사각형 좌표이고 그게 전부입니다. 누구인지 재지 않고, 한 사람과 다른 사람을 견줄 수 있는 특징값을 만들지 않으며, 계산한 값을 저장하거나 전송하지 않습니다. 좌표는 그 위에 모자이크를 그릴 동안만 있다가 사라집니다.

서버 검사도 같습니다. Google Cloud Vision 은 사각형과 확신 점수를 돌려주고, 저희는 그것을 게시 여부를 정하는 데 한 번 쓰고 버립니다. 구글은 저희의 수탁자로서 처리하며 그 이미지를 자사 모델 학습에 쓰지 않습니다.

3. 저희가 가진 것

계정
이메일 주소, 구글이나 애플로 가입했다면 그 계정 식별자. 비밀번호는 해시로만 저장하고 저희는 원문을 볼 수 없습니다.
프로필
별명, 생년월일, 국가, 도시, 성별, 키, 소개, 스타일 태그, 공개하기로 고른 연락처, 매칭 선호(보고 싶은 상대·나이대·목적).
게시물
가려진 사진, 설명, 스타일 태그, 그리고 적기로 한 옷 정보(품목·브랜드·가격·링크). 옷 정보는 전부 선택입니다.
활동
대결에서 고른 옷, 좋아요와 넘김, 매칭, 차단과 신고 기록.
기기
푸시 알림 토큰, 안드로이드인지 iOS 인지, 읽는 언어. 매칭을 알려 드리는 데 씁니다.
결제
구독이 유효한지 여부. RevenueCat 이 처리합니다. 저희는 카드 정보를 보지 않습니다. 결제는 애플과 구글이 받고 저희에게는 성공 여부만 옵니다.
접속 기록
호스팅 업체가 IP 주소를 포함한 요청 기록을 짧은 기간 남깁니다. 서비스를 돌리고 악용을 잡는 데 씁니다.

광고를 하지 않으며 광고를 위해 개인정보를 팔거나 제공하지 않습니다.

4. 처리 근거

5. 남에게 보이는 것

가려진 사진, 별명, 도시, 스타일 태그, 소개, 적어 둔 옷 정보는 로그인한 다른 이용자에게 보입니다. 생년월일은 보이지 않고 나이만 보입니다.

연락처는 매칭된 상대 한 사람에게만 보입니다. 서로의 옷차림에 좋아요를 눌렀을 때 매칭됩니다. OOTD 안에는 채팅이 없습니다. 일부러 넣지 않았습니다. 매칭되면 공개하기로 고른 연락처를 건네줄 뿐입니다. 그 뒤 인스타그램이나 카카오톡에서 벌어지는 일은 저희 서비스 밖이고 이 방침이 미치지 않습니다.

어떤 옷을 골랐는지, 누구를 좋아하고 넘겼는지는 누구에게도 보이지 않습니다.

6. 처리를 맡기는 곳

모두 위탁 계약을 맺은 수탁자입니다. 유럽경제지역이나 영국 밖으로 나가는 이전은 유럽연합 집행위원회의 표준계약조항에 따릅니다.

7. 보관 기간

8. 계정 지우기

앱의 프로필에서 계정 삭제를 고르시면 됩니다. 사진은 저장소에서 지워지고 계정과 프로필은 데이터베이스에서 지워집니다. 되돌릴 수 없습니다.

이미 남들이 평가한 게시물은 평가 기록에 익명 수치만 남습니다. 그 줄에는 여러분을 가리키는 식별자가 없습니다.

9. 권리

개인정보 보호법에 따라 열람, 정정, 삭제, 처리 정지를 요구하실 수 있습니다. rrhlrmrr@gmail.com 로 보내시면 법이 정한 기간 안에 답합니다.

분쟁이 생기면 개인정보분쟁조정위원회(kopico.go.kr, 1833-6972), 개인정보침해신고센터(privacy.kisa.or.kr, 118), 대검찰청 사이버수사과, 경찰청 사이버수사국에 도움을 청하실 수 있습니다.

GDPR 이나 영국 GDPR 이 적용되는 곳에 계시면 사본 요청, 정정, 삭제, 처리 제한, 반대, 이동권을 행사하실 수 있고 감독기구에 민원을 넣으실 수 있습니다.

캘리포니아에 계시면 무엇을 수집했는지 묻고 삭제와 정정을 요구하실 수 있습니다. CCPA 가 말하는 뜻의 판매나 공유는 하지 않으며, 권리를 행사했다고 다르게 대하지 않습니다.

일리노이·텍사스·워싱턴에 계시면 2항에 생체정보법에 관한 저희 입장을 적어 두었습니다.

10. 나이

만 16세 이상만 쓰실 수 있습니다. 매칭은 만 18세 미만에게 열리지 않습니다. 아동의 정보를 알면서 수집하지 않습니다. 아동 계정을 발견하시면 알려 주십시오. 지우겠습니다.

11. 보안

통신 구간은 암호화합니다. 데이터베이스의 행 수준 보안 때문에 한 이용자가 다른 이용자의 비공개 데이터를 읽을 수 없습니다. 사진 저장소는 올린 사람만 자기 폴더에 쓸 수 있게 막혀 있습니다. 완벽한 시스템은 없습니다. 유출이 이용자에게 위험이 될 경우 이용자와 관계 기관에 알리겠습니다.

12. 변경

중요한 내용을 고칠 때는 시행 전에 앱에서 알려 드립니다. 맨 위 날짜가 현재 판입니다.