# Privacy Policy
_Last updated: 2026-04-30._
## Who we are
`Agentcore LTDA` operates the Muse Edit mobile app and supporting
backend services. Contact: `privacy@agentcore.app`.
## What we collect
- **Account & profile**: pronouns, gender expression preference, style
words, and the events you typically dress for. Pronouns and expression
are optional.
- **Closet content**: photos of garments you upload, automatic image
tags (category, dominant color, formality), and any notes you write.
- **Look review content**: mirror selfies you upload for feedback,
ratings, and free-text comments you submit.
- **Generated content**: outfit suggestions, captions, and share cards
produced from your inputs.
- **Device & app metrics**: anonymous diagnostics (crash logs, latency,
feature usage). No advertising IDs are collected.
We do not collect biometric identifiers, contacts, location, or
microphone data.
## How we use your data
- Generate styling suggestions and social copy from your closet, brief,
and preferences.
- Improve product quality via aggregated, de-identified analytics.
- Support requests and abuse investigation.
We do not sell your personal data and do not use it for cross-app
behavioral advertising.
## Payments
Subscriptions are processed through Apple StoreKit and your Apple
Account. We can read subscription entitlement status needed to unlock app
features, but we do not collect or store full payment card details.
## AI providers
Some requests may be routed to third-party AI providers to generate
styling suggestions or review looks. We send only the content needed
to provide the requested feature, such as structured closet tags, your
text brief, or an image you explicitly upload for review. Provider
data is governed by the provider's privacy terms; we do not authorize
provider-side training on your content.
## Storage and retention
- Closet items, saved looks, and uploads are stored as long as your
account exists.
- Look review photos are kept for 30 days unless you save them as part
of a look.
- Diagnostics are kept for up to 90 days.
- You can delete all of your data at any time via Perfil → Apagar
conta e dados, which calls `DELETE /v1/users/me` and removes your
records.
## Your rights (GDPR / LGPD)
You can exercise the following rights at any time by emailing
`privacy@agentcore.app`:
- access a copy of your data
- correction of inaccurate data
- erasure ("right to be forgotten")
- portability (machine-readable export — `GET /v1/users/me/export`
returns a single JSON with everything we hold for you)
- restriction or objection to processing
- withdrawal of consent
LGPD-specific: data processed under legitimate interest (analytics) and
consent (closet uploads, look reviews). Controller: `Agentcore LTDA`.
## Security
- TLS in transit; encryption at rest in our cloud storage.
- Access to production data restricted to engineers on the on-call
rotation.
- Quarterly access review and incident response runbook.
## Children
The app is rated 13+ on iOS and "Teen" on Google Play. We do not
knowingly process data from children under 13.
## Changes
We will publish material changes to this policy at least 14 days before
they take effect, in-app and at our public URL. The current version is
always available at `https://api-production-4a83.up.railway.app/privacy`.