Last updated: 1 October 2026
At Maude we believe your data belongs to you. This policy explains what information the app uses, who it is sent to, why, and how to delete all of it. No jargon, and nothing that flatters the reality.
Everything you create in Maude is written to your phone first, and your wardrobe stays readable with no network. The copy happens later: it goes up to our servers for one reason only, to get your wardrobe back if you change device. This happens even without an account — the copy is then attached to the anonymous identifier created at first launch.
What lives on your phone, and has a copy going up:
What never leaves your phone: the body landmarks that the cut-out read from your photos — the position of shoulders, hips and ankles — are removed before anything is sent; the outfit computed for today, the caches, the queue of photos waiting and your sign-in token do not go up.
What goes up, and what we do with it, is set out in § 5. Your data is also included in your phone's backups (iCloud or Google, for example) if you have enabled them.
The Trip module is switched off in this version. Your trips, suitcases and cabin checklists stay on your phone and are no longer uploaded to our servers. Whatever was uploaded before 20 September 2026 stays there, and goes when you delete your account or your identifier.
On first launch, the app creates an anonymous identifier for your phone. You type nothing, and you are not prompted: it is a plain number, with no email, no name, no password. It exists for one reason — the artificial intelligence features go through our servers, and calls have to be counted to cap usage and prevent abuse. Without it, we would have to demand an account before letting you try the app at all.
What it holds: a number, a creation date, and the technical record of your AI calls described in § 4. Nothing that identifies you — we cannot tell who you are from it, nor recognise you from one device to another. This number is not your wardrobe: it is the key your online backup is filed under, and the key your AI calls are counted against (§ 5).
It lives on your device: uninstalling the app makes it unusable, and reinstalling creates a new one, unrelated to the previous.
An account can be created with an email address, or with an Apple or Google account depending on the sign-in methods available on your phone. It is optional: the app works without one, item recognition included. It exists to recognise you from one device to another.
What the account holds, and nothing else: your email address (or the identifier provided by Apple or Google), an internal identifier, and, if your provider passes it to us at sign-in, your first name. The account itself holds only that. Your online backup is filed separately, under this same identifier (§ 5).
Both the anonymous identifier and the account are hosted with Supabase, on infrastructure located in the European Union (Paris).
To make certain features work, the app talks to technical providers (processors under the GDPR). Here is the complete list, what is sent to them, and why.
| Provider | What is sent | Why |
|---|---|---|
| Anthropic (Claude) | The photo you submit for recognition; a text description of your wardrobe, with the day’s weather and the chosen occasion, for style write-ups and outfit suggestions. | Recognise the garment, write your style analysis, put outfits together. |
| Supabase | Your anonymous identifier, and your account if you created one (email or Apple/Google identifier); the technical record of your AI calls; the photo being processed, temporarily — either from a scan on devices without on-device cut-out, or the photos waiting to be cut out during a clean-up of your wardrobe images (§ 5 bis). | Host the account, route AI calls without ever exposing our keys inside the app, keep the photo while our cut-out service processes it. |
| OVHcloud | Your email address, and the email we send you — the one confirming your address when you create an account, or the one letting you choose a new password. Only if you create an account with an email address. | Deliver those emails to your inbox. |
| Google Cloud | The photo to be cut out — from a scan on devices without on-device cut-out, and those of a clean-up of your images (§ 5 bis). Our cut-out service, hosted on Google Cloud (Cloud Run, in Belgium), downloads it from Supabase for the time of the processing and sends back the image of the garment alone. | Cut the garment out of a worn-outfit photo. |
| RunPod | The image of an item you ask a render for, with its category (top, bottom…) — only when you ask. | Compute the render of the item on a neutral background. |
| Open-Meteo | A location rounded to two decimal places (about one kilometre) — yours, or that of the city of an appointment in your calendar (§ 5 ter) —, or the name of a destination city. See § 5 c) for versions earlier than 12 September 2026. | Fetch the matching weather forecast. |
| Sentry | Error and crash reports: device type, OS version, app version, technical context of the error, and the addresses of the network requests that preceded it, from which any coordinate is stripped before sending. No account identifier is attached. And, for about one measurement in ten, performance data: durations (app start-up, network requests), whose addresses are cleaned in the same way — no content, no account identifier. | Spot and fix failures and slowdowns in the app. |
| RevenueCat | Your subscription status, and your Maude identifier — anonymous, or your account's. We pass it on so that our servers can check that your Club is active. | Verify your subscription and credit the renders included in the Club. |
| Apple · Google | Payment and subscription management. And, separately, a location rounded to two decimal places (about one kilometre), sent to Apple’s or Google’s geocoding service, depending on your phone. | Take and renew the subscription — we neither receive nor store your payment details. And name the city shown next to the weather. |
| DuckDuckGo | What you type in the shop browser’s bar when it is not a website address (§ 5 quinquies). | Show you the results of your search. |
And, with no data about you: the texts and illustrations of the looks are written and drawn by Anthropic and by Google (Gemini) from template outfits, never from yours.
When you use automatic recognition, the photo is sent to our artificial intelligence provider (Anthropic) to identify the garment, its colour and its characteristics. It is used for that analysis only. Maude keeps no copy of the photo on its servers: what the app keeps is the identified item, on your phone. Under Anthropic's terms of use, content submitted through its API is not used to train its models. You can also add a garment by hand, without using recognition at all.
On devices that cannot cut the photo up locally, the image passes through our servers (Supabase, European Union) for the duration of the processing. It is deleted automatically around 15 minutes after it is uploaded, and at most 20, whether the processing succeeded or not.
To write your style analysis or suggest an outfit, the app sends Anthropic a text description of items in your wardrobe (categories, colours, materials, cuts), the day’s weather (temperatures to the nearest degree and sky conditions — not your location), the occasion for the day if you chose one (work, sport…) and, where relevant, what you wrote about your day. No photo is attached to these calls.
To suggest a suitable outfit and anticipate the weather on your trips, the app sends a location to Open-Meteo (or a destination city). It is not retained by Maude, and no identifier goes with it. You can decline location access: the app keeps working, without the daily weather.
What exactly is sent, and since when. That location is rounded to two decimal places — about one kilometre: your exact position does not leave your phone. This rounding was introduced on 12 September 2026; versions installed before the update that carries it still send the position as the phone reports it. In both cases it goes to two places only — Open-Meteo for the forecast, and your phone’s geocoding service (Apple or Google) to name the city shown alongside it — and it is never sent to our servers. That name is derived from the rounded position: it may point to a neighbouring town.
The weather for an appointment. If you have allowed calendar access and one of today's appointments takes place in a different city from the one you are in, the app asks Open-Meteo for that city's weather: only its coordinates, rounded the same way, are sent. The city is recognised on your phone, from a list built into the app; neither the address nor the title of the appointment is sent (§ 5 ter).
If you subscribe to Club Maude, payment and subscription management are handled by Apple through the App Store on iPhone, or by Google through Google Play on Android, and the status is relayed by RevenueCat. Maude neither receives nor stores your payment details. Renewal and cancellation are managed in your Apple account or Google account settings.
Here is everything that lives on our servers:
You can change or withdraw these permissions at any time in your phone's settings.
When you scan your clothes, Maude crops a piece out of each photo to use as the item's thumbnail. On many items, that crop still shows your face, your hands, or the garment you were wearing on top.
Maude can go back over those photos and keep only the garment. This only happens if you ask for it, from your wardrobe, and never on its own.
Exactly what it does: it re-reads, in your photo library, the photos your clothes were extracted from — those only — and uploads them to our service to be cut out. They are processed one at a time, and each one takes a few minutes: for a whole wardrobe, it can take several hours. You don’t need to keep the app open: it collects the images the next time you open it.
Two different things then live on our service, and they do not stay for the same length of time:
What comes back to your phone is the image of the garment alone.
Maude never writes to your photo library, never browses it in the background, and uses it for nothing else.
If you decline this permission, the app works exactly as before: you can still re-photograph an item on its own from its detail screen.
If you allow it, Maude reads your calendar on your phone, so that your outfit takes your day into account — a dinner, a work meeting.
What is read: for today's appointments only, their title and time, to understand the occasion, and their place, to recognise the city where they happen.
What is never read: attendees and notes.
You can decline or withdraw this access at any time, from your Profile or in your phone's settings: the app then works without taking your calendar into account.
If you turn on the morning reminder, Maude suggests your outfit with a notification, once a day. This notification is scheduled on your phone: no server sends it, no notification identifier is created or transmitted, and we cannot send you any others. It contains no data about you. You can turn it off at any time from your Profile or in your phone's settings.
To add an item seen in an online shop, Maude opens the shop’s website in a built-in browser. The website sees your visit like any other visit: its own terms and cookies apply. If you type something other than an address, your search goes to DuckDuckGo.
On the product page, Maude reads on your phone the name, brand, price and images the website points to; the image you choose is downloaded to your phone, then follows the same path as a photo (§ 3 a). Maude sends the website no data about you.
The infrastructure hosting your account and image processing is located in France. The company operating it, Supabase Inc., is established in the United States.
The cut-out service runs on Google Cloud, in Belgium; the company Google is headquartered in the United States.
OVHcloud, which delivers our emails, is established in France: those emails are sent from servers located in the European Union.
Anthropic, RunPod, Sentry, RevenueCat and DuckDuckGo are also established in the United States, and the data described above is processed there. These transfers rely on the European Commission's standard contractual clauses, as provided for in those providers' terms.
Under the UK General Data Protection Regulation (UK GDPR) and the EU GDPR, you have the right to access, rectify, erase, restrict and object to the processing of your data, as well as the right to data portability.
What you can do yourself, right now:
The anonymous identifier can also be deleted from the app, with no account and without writing to us: Profile → "Delete my identifier". Your identifier and the record of your AI calls are then erased from our servers, immediately. Your online backup goes with it: your wardrobe, trips and suitcases will exist only on this phone. Nothing is erased from the device — you keep everything, but you will no longer find it on another one. A new identifier, with no history, is created so that recognition keeps working.
For any other request about your data, write to us at contact@solvia-app.fr. You also have the right to lodge a complaint with your supervisory authority — the ICO in the United Kingdom (ico.org.uk), the CNIL in France (cnil.fr).
We may update this policy to reflect changes to the app or to regulation. The "last updated" date appears at the top of this document. We will let you know within the app of any material changes.