Version 2026-10-26 · Effective October 3, 2026
Privacy Policy
- Rewear is a private closet. What you add stays private unless you choose to share it.
- We collect what you give us and the technical data needed to run Rewear and keep it secure. There are no analytics, advertising or tracking scripts.
- We do not sell your personal information and do not share it for advertising.
- Service providers (Google Cloud, SendGrid and Google) handle data for us. Your data is stored in the United States.
- You can download your data and delete your account in Settings at any time. Questions and requests: support@rewear.fit.
This summary is a guide; the full text below is what applies.
Rewear Reverie
Rewear Reverie is the name of Rewear's picture and reading features: try-ons, Rewear's looks shown on a mannequin, flat lays, and reading order emails and colour analysis photos. Each one is described below, with what is sent and when, and only works while it is turned on.
Rewear Reverie uses Google Gemini on Google Cloud (Vertex AI) to process the photos and emails described below. Google may process them outside the United States. Rewear does not use them to train models, and Google does not use them to train its models.
Rewear Reverie try-on
Your photo's background is blurred on Rewear's own servers before the photo and the selected garment pictures are sent to Google (Gemini on Google Cloud Vertex AI) so Rewear Reverie can make the picture. Google may process them outside the United States; Rewear stores your data in the United States. We ask for first-use consent and confirmation for every render. No face or body measurements are recorded. Use only your own photo, alone; members must be 13 or older, with guardian agreement under 18.
Each member can request up to 3 try-ons in any hour and 10 in a day (UTC). The first 3 each day are made in high quality and later ones may be made in standard quality, with a lighter Google Gemini image model; a result made in standard quality says so. Rewear also limits how many try-ons it makes in a day across all members. When that limit is reached your request waits, with its photo held encrypted, until capacity returns, for at most 24 hours. Requests that fail do not count against your limits.
The sanitized input is held encrypted while queued and processed. Deletion is scheduled when processing ends and a sweeper removes expired inputs after 24 hours. Storage or scheduler failures can delay erasure; failed deletions are retried. Every finished picture is kept automatically in your private try-on library, grouped by the look it shows, until you delete it, all pictures of a look, all of them or your account. It is never public, and Rewear staff cannot see it in the app unless you choose to share it with the Rewear team, as described below. Withdrawing consent cancels pending work and deletes saved results. Account exports include results, never temporary input photos.
Download and sharing each require additional consent. Sharing sends a file through your device; Rewear creates no public link. Deletion cannot recall files already downloaded, exported or shared outside Rewear. Infrastructure administrators can access stored images and uploads across Rewear, even where application access is limited to you. Backup copies may remain until the applicable backup retention period expires; we do not promise immediate backup erasure.
If you are 18 or older and agree separately, you can keep one photo of yourself as your default for try-ons. It is sanitised, encrypted and kept privately in your account, read only by your own try-on requests, and never public or shown to Rewear staff in the app. Replace or delete it at any time in Settings. It is deleted when you withdraw try-on consent or delete your account, and after 12 months without use, with an email a month before. It is included in account exports. Deleting it does not delete try-on pictures already made from it.
So you are not charged a try-on for a picture you already have, each result records a coded identifier of the photo that made it and the pieces chosen. The identifier is a keyed code computed from the cleaned photo in memory; the photo itself is not kept for this, and the code cannot be matched to a photo without Rewear's secret key. It is deleted with the result.
You can mark any try-on picture, with your photo or on a mannequin, as a good or bad result, and after a bad result choose reasons and add a short note. Rewear keeps your mark, the reasons, the note and when you gave them, with details copied from the picture (with your photo or on a mannequin, its quality, the number of steps it took and the pieces in it), so staff can see which pictures go wrong without seeing them. Feedback is kept with the picture and deleted when you delete the picture or your account; withdrawing try-on consent deletes your pictures and their feedback. Feedback never gives back a try-on. It is included in account exports.
After marking a picture as a bad result, you can choose to share that one picture with the Rewear team by pressing "Share this picture with the Rewear team"; nothing is shared by the mark itself. Only Rewear staff who run try-on can then view it, only to fix the problem, and every view is recorded. Sharing ends when you stop sharing, delete the picture, withdraw try-on consent or delete your account, and after 90 days at most. A shared picture is never used to train models and never sent to anyone outside Rewear.
Results carry a Rewear mark and a Rewear Reverie label. SynthID survival after applying the mark has not been verified. We do not claim valid Google-signed content credentials for modified images. Output may change appearance or clothing details and does not establish fit.
With Rewear Reverie's mannequin try-on, pictures of the pieces you choose (your own piece photos or catalog photos) are sent to Google (Gemini on Google Cloud) to show them on a mannequin; no photo of you is used. It needs no try-on consent and is open to every member. Swimwear, underwear, sleepwear and lingerie are shown on a mannequin only.
Mannequin pictures count toward the same try-on limits, are kept in your private try-on library, grouped by look, until you delete them, are included in account exports and are deleted with your account. Downloading or sharing one needs no additional consent, because no person is shown.
Who we are
Rewear (rewear.fit, the Rewear apps and the Brand Portal) is operated by Peek House LLC ("Rewear", "we", "us"). This policy explains what personal information we collect, why, who handles it, how long we keep it and the choices and rights you have.
Rewear is offered in the United States. This policy is written for US members and includes the disclosures California law requires.
Questions and privacy requests: support@rewear.fit.
What we collect
Identifiers: your name, email address, account number, and the handle on your public profile if you create one. Your IP address is recorded with your browser sessions and in server logs.
Sign-in information: your password, stored as a one-way hash, and, if you turn it on, your two-factor authentication key, stored encrypted, and recovery codes, stored in a form that cannot be read back. If you sign in with Google, the Google account id.
What you add to your closet: pieces and their details, photos, prices you paid, purchase dates, notes, tags, sizes, outfits, wear history, plans, wishlists, receipts and listings. All of it is optional.
You can also tell us which departments to suggest pieces from (Women's, Men's or both). We use this only to choose catalog suggestions and ideas for you; it is private, never shown to others, and never changes your closet.
Style information you choose: your colour season and style preferences. Rewear does not work these out from a photo of you; you pick them.
Location: the city you type for weather and, only if you choose current location, the city your device is in. Your browser asks your permission first; the position is rounded to about a kilometre, used once to find the city and not stored. Location data inside photos is removed on upload.
Usage and device information: the pages and API addresses your browser or app requests, the time you were last active, browser type, and the device name you give when the app signs in. Retailer and listing link clicks are recorded without your identity.
We collect this from you, from your browser or app, from Google if you use Google sign-in, and from a brand only if you give that brand permission to send your purchase receipts.
The only sensitive personal information we collect is your account sign-in information. We use it only to sign you in and keep your account secure.
How we use it
To run Rewear: your closet, outfits, suggestions, sharing, listings, notifications and the other features you use.
To keep Rewear and its members safe: signing you in, preventing abuse and fraud, rate limits, reviewing reports and enforcing the Terms.
To produce totals, such as how many closets hold a product. Totals never identify you.
To run optional features you turn on, such as email import, weather or reading a receipt photo.
To contact you about your account and send the notifications you choose.
To meet legal obligations.
Outfit suggestions and colour guidance come from fixed rules over what you saved. Automated moderation scores only order the staff queue. No decision with legal or similarly significant effects is made about you automatically.
Rewear uses no analytics service, advertising or tracking scripts. If that changes, this policy will say so first and you will be told in advance.
Your account
An account holds your name, your email address, a password and a timezone. An account created with Google has no password until you set one in Settings, under Account.
You verify your email address before you can use the closet. Two-factor authentication with an authenticator app is available in Settings, under Account. It sends no text message and uses no outside service.
When you create an account, and whenever you agree to a new version of the Terms and this policy, the time and the versions are recorded.
A small number of Rewear staff can see account information when they need to: to help you, review reports and keep Rewear secure. Staff actions are recorded in an audit log.
Sign in with Google
You can sign in, or create an account, with a Google account.
When you use Google sign-in, Rewear asks Google only for your name, your email address, whether Google has verified that address, and a Google account id. It does not ask for access to your Gmail, contacts, calendar or files.
Rewear keeps the Google account id, the email address Google reported when you connected, and the date. It does not store the tokens Google issues and does not contact Google on your behalf afterwards. A Google account whose email address Google has not verified cannot be used to sign in.
When Google sign-in is added to an existing account, you are told in the app and by email. You can disconnect Google in Settings, under Connected accounts, once your account has a password.
Email import
Connecting Gmail directly is not enabled on this platform at the moment. Outlook and Apple Mail cannot be connected directly. Forwarding your order emails (see Forwarded emails) does not use a mailbox connection. The rest of this section describes the Gmail connection when it is turned on.
Connecting Gmail uses Google's read-only Gmail permission. That permission allows reading the mailbox. The search Rewear runs does not narrow what Google grants.
Connecting does not start a scan. A scan runs only when you start it. It covers the number of days you choose, from 1 to 365, and fetches at most 100 messages whose subject contains order, purchase or receipt, leaving out spam and trash. There is no scheduled background scanning.
With a Gmail connection, email bodies and headers are read in memory while product details are taken from them. They are not stored. Product photos are handled as described in Product photos from order emails; no product link, tracking pixel or attachment in an email is fetched while the email is read.
Mailbox access tokens, the mailbox address and message identifiers are stored encrypted. Disconnecting a mailbox removes its access tokens from Rewear straight away, cancels unfinished imports and then asks Google to revoke access. If Google cannot confirm, the app tells you to remove Rewear in your Google Account permissions.
If you record interest in Outlook or Apple Mail, no mailbox is connected and no mailbox password is asked for or stored.
Product details found by an import wait in Review. Nothing is added to your closet until you approve it. Details you have not reviewed are deleted after 7 days. You can choose a shorter period for your own account in Settings, under Connected accounts.
Forwarded emails
Each member can have a private Rewear address at in.rewear.fit. Mail sent to it is received by SendGrid, a Twilio company, which passes it to Rewear.
Rewear does not connect to your mailbox for this. It receives only the messages that you, your mail filters or rules, a retailer or anyone else send to your Rewear address, and the files you upload.
Mail from any sender is read for orders. When a message is a forward, the original messages inside it are read. Product details found go to Review like any import, and nothing is added to your closet until you approve it. Product photos are handled as described in Product photos from order emails; links and attachments in the mail are not fetched or opened while the mail is read, and the mail is never forwarded anywhere.
You can block the sender of any message you see under Imports. Mail from a blocked sender is dropped without being read for orders or kept. Rewear stores a blocked sender only as a keyed hash of the address with a shortened form of it (its first letter and domain) so you can find it in your list and unblock it. To limit unwanted mail, each address accepts at most 50 messages an hour and 300 a day; mail over the limit is dropped and only counted. You can make a new address at any time, after which mail to the old one is refused.
SendGrid's sender checks (SPF and DKIM) are recorded with each message to help us diagnose problems. They do not decide whether mail is read, except that Gmail's forwarding confirmation code is shown only when the message is signed by Google.
A received message is stored encrypted only until it has been read, and at most 24 hours.
Mail that is not an order, such as a retailer's "verify your email" message or Gmail's forwarding confirmation, is shown only to you, with its sender, subject and text, stored encrypted for 7 days and then deleted. You can delete it sooner. If someone puts your Rewear address on a retailer account, such mail could include sign-in or account recovery links; only you see it, and you can block the sender or make a new address.
After a message is read, Rewear keeps its outcome and the sender's domain for your import history, without its subject or text, and a keyed hash of the sender's address for 30 days so you can block that sender from the history.
You can upload .eml files, or a Google Takeout .mbox file of up to 500 MB. The .mbox file is received in encrypted parts and split into messages on our servers. Only messages that look like orders, by their subject or because they come from a retailer our team approved, are read for products; for the others only the sender and subject are looked at, and they are deleted without being imported. Uploaded mail is deleted once read, and every part of an upload within 24 hours.
Your Rewear addresses and your blocked senders (in their shortened form) are in your data download. Deleting your account deletes them with any messages and uploads.
How order emails are read
When an order email (forwarded, uploaded or from a connected mailbox) has no order markup and no retailer rule we already trust, Rewear Reverie reads it: its text and layout are sent to Google Cloud Vertex AI (Gemini) to read the order details, under Google Cloud's data processing terms. Only what is needed is sent: the sender's domain, the subject and a cleaned copy of the email, without images, link addresses or email addresses, with your account name replaced, and shortened. Other text in the email, such as a delivery address, is sent as it appears. Nothing is sent for retailers marked as not selling clothing, or for emails read by a retailer rule we trust, except a small random share (about 2%) checked against Vertex AI to confirm the rule still works.
Rewear learns how each retailer lays out its emails so it can read later emails without sending them anywhere. What it keeps for that is the layout, the rule's selectors and counts, never the text of your emails, your name, address, order numbers or items.
Rewear recognises shipping, delivery, return, cancellation and marketing emails so that the same piece is not added twice and pieces you did not buy are not suggested. From shipping, delivery, return and cancellation emails it keeps only the order's new status, not their content. A return can suggest removing a piece from your closet; nothing is removed unless you do it.
Pieces found this way go to Review like any import, and nothing is added to your closet until you approve it. Import history shows how each email was read: read by Rewear Reverie, retailer rule or order markup.
Product photos from order emails
When an order email shows a product photo next to an item, Rewear's servers download that photo once, after the email is read. The retailer's server sees a request from Rewear (identified as RewearBot), not from you, and the address is requested without its tracking parameters.
Data stored inside the photo, such as camera details, is removed. Tracking pixels, logos and images outside the item's line are skipped. Product page links, attachments and other images are never fetched while your email is read.
When you approve the piece, the photo becomes its photo. You can use it wherever you use your own photos, except in a resale listing, and you can replace or remove it.
Product details from imports (name, brand, category, colour, product photo, style number, SKU, barcode number, product link and retailer) may create or add to public catalog entries after review by Rewear staff or the brand, or automatically once staff have approved both the brand and the website that confirmed the details. Never the price you paid, the size you bought, the order date, the quantity, anything you typed or changed, or anything that identifies you. The style number, SKU, barcode number and product link read from your email are kept privately with your piece.
A product link that becomes part of a catalog entry is public catalog data. Some hours later, not at the time of your import, RewearBot may read that product page like any public product page, following the site's robots.txt, to complete the entry. Nothing about you is sent.
Signed-in members can flag a photo. Brands and rights holders can ask for a photo to be removed with the takedown form at /takedown. A removed photo is deleted wherever it is used, including your pieces and shared looks, and is not downloaded again; you are told if your pieces lost a photo.
A takedown request (the sender's contact details, statements and the addresses given) is kept for 3 years after the decision, as the record of the notice. Flags you made are kept without your identity or your words if you delete your account.
Weather and city search
Weather forecasts are available on this platform.
You choose a home city by typing its name. You can instead choose current location: then, with your browser's permission, Rewear checks which city this device is in once a day, and you can set a different city for one day on Today.
For current location, your device's position, rounded to two decimal places (about a kilometre), is sent once to the Google Geocoding API to find the city it is in, and is not stored. Rewear keeps only that city, as it keeps a saved city, and only for that day.
The city name you type is sent to Google, to the Google Geocoding API. Forecasts come from the Google Weather API and are requested with the city-centre coordinates, rounded to two decimal places. Google receives no name, email address or account identifier from Rewear.
Your saved city is stored encrypted with your account: its name, region, country, timezone, Google's place ID and its coordinates. The same is stored for a city set for one day, the city your device was in today and your three most recent one-day cities. The coordinates are renewed from Google before they are 30 days old, or removed. One-day and device cities are deleted once their day has ended. Cached forecasts are deleted before they are 24 hours old.
Weather shown in Rewear is marked "Source: Includes weather data from Google". Forgetting your saved city removes it and its cached forecast. It is part of your data download.
Visitors without an account can try an outfit idea for a city. The city they type, or, only if they press "Use my location" and their browser allows it, their position rounded to two decimal places (about a kilometre), is sent to Google to find the city and its forecast. The answer is not linked to anyone: it is shared by all visitors and kept only briefly (a city up to 29 days, a position's city one day, a forecast three hours). To prevent abuse, lookups are counted per network address under a one-way code made from it, for an hour. No cookie is added for this.
Photos and sharing
Photos of your pieces are kept in private storage and are not served from a public address. They are shown to you when you are signed in, and to a friend while a piece is on loan to them. They stay private unless you choose to share one on its product page.
You can share your own photo of a piece on its product page in Rewear's catalog, one photo at a time, when the piece is linked to a product you confirmed. Photos copied from a retailer, the catalog or another member cannot be shared. A shared photo is shown only to signed-in members, with your display name if your profile is Public and as "Rewear member" otherwise. It is never shown to visitors without an account, on public pages or to search engines. Other members can report it, and photos reported by three members are hidden until Rewear staff decide. Turning sharing off, deleting the photo or the piece, unlinking or changing the product, or deleting your account takes it off the product page at once. Your shared photos are listed in your data download.
Location and other data a camera stores inside a photo are removed when the photo is uploaded, and again whenever a photo is copied to be shared.
Rewear measures the main colour of each piece's main photo (or of its cutout or flat lay, once you choose one) on its own servers, with a fixed rule and no outside service, so the Builder can show pieces in a colour season. The colour is kept with the piece, private like the photo, is never shown to anyone else, and is deleted with the photo, the piece or your account.
Outfits are private unless you share them. When you share an outfit, its name, any caption you write, and a copy of the photo of each visible piece are published for the audience you chose: Public, Anyone with the link, or Friends. Only me keeps it to you.
A caption on a shared look (up to 300 characters) is public to everyone who can see the look. It is separate from your outfit notes, which stay private and are never copied into it. Making the look private deletes its caption, a member's own version of the look (Rewear this look) never copies it, and it is in your data download.
When a shared look is reported, its name and caption as the reporter saw them are kept with the report as evidence, even if you edit them later, until the look or your account is deleted, as with reported comments. Staff can remove just a caption; you still see it, are told, and can appeal once.
You can set your profile to Public or Private, and block people, in Settings under Privacy.
Your profile is Public or Private. On a Private profile your name, photo, bio and counts stay visible so people can find you; your looks, collections and listings are for the followers you approve. Someone who asks to follow you is not told if you decline.
A look shared with Anyone with the link can be opened by anyone who has its address, including people without an account. It is never shown on your profile, in feeds or in search, or offered to search engines. Resetting the link ends access through the old address.
You can mute someone: their looks and activity leave your feeds and notifications. Muting is private; they are not told.
You can choose the audience new looks start with. Your follow requests, mutes and that choice are included in your account export.
If you allow it, another member can rewear a look you shared: save their own version of it as an outfit. The photos of the pieces they copy are copied into their closet. When you delete your account, those copies are removed from their closets: the copied pieces keep their names and details but lose the photo.
Photos and reports read by Google Cloud
When you add a receipt and press "Read this photo", that photo is sent to Google Cloud Vision to find its text. Only the picture is sent, scaled down and without camera data: no name, email address or account identifier. The copy made for reading is deleted straight after. The lines found fill in the form, and nothing is saved until you have checked them and saved the receipt.
When you add a piece from photos and press "Suggest details", the first photo is sent to Google Cloud Vision to suggest a category, colour and brand. Photos are not sent when you upload them, only when you ask. The copy made for this is deleted straight after, and a suggestion is filled in only when you choose to use it.
When content is reported, the reported content is sent to Google Cloud for an automated score: a comment's text, a profile's display name, handle and bio, or a shared look's name and caption as reported and its published piece photos, once for each version of the look. Who reported it, the reason and the details they gave are not sent. The score and its categories are shown to staff and order the queue of reports. The score of a report never hides content; staff decide every report.
When you share a photo of a piece on its product page, and again if you replace that photo, it is sent to Google Cloud Vision before anyone else sees it, scaled down and without camera data, your name, email address or any account identifier. Vision's SafeSearch rates how likely it is to show adult, violent, racy, spoof or medical content, and the ratings are kept with the shared photo. A photo very likely to show adult or violent content is not shown; one likely to show adult, violent or racy content, or very likely racy, waits for Rewear staff; anything else is shown. A photo that could not be checked is never shown until it is checked or staff decide.
Google processes what is sent under Google Cloud's terms, as a service provider to Rewear, and does not use it to train its models.
Color analysis from a photo
Color analysis can suggest a colour season from a selfie or a photo you upload. It is optional: you can always choose your season yourself, and no photo is taken or sent unless you start it.
Before the camera or file picker opens, Rewear explains what happens and asks you to agree. Your agreement is recorded with the date and the version of that explanation. You can withdraw it on the Color analysis page.
When you send a photo, it is scaled down in your browser, stripped of camera data on our server and sent to Google Cloud Vertex AI (Gemini) so Rewear Reverie can read your skin undertone, how light or dark your hair, skin and eyes are, the contrast between them and how soft or clear your colouring is. Only the picture is sent: no name, email address or account identifier.
The photo is analysed in memory and then discarded. It is not stored in Rewear's storage, database or logs, and no copy is kept. Like any upload it may pass through a temporary file on the server while it arrives; Rewear deletes that file as soon as the photo has been read.
No facial geometry is measured or kept. Rewear does not compute face measurements, face templates or any other biometric identifier, and does not use the photo to identify you. Google is instructed to assess colour only and not to describe or measure your face.
Only the result is stored with your account: the suggested season, the four characteristics and how confident the reading was, any photo quality problem, the model and its version, and the date. Rewear keeps your 10 most recent results. A suggestion changes nothing until you confirm it or choose another season.
You can delete your photo results on the Color analysis page at any time. They and your consent records are in your data download, and deleting your account removes them.
Google processes the photo under Google Cloud's terms, as a service provider to Rewear, and does not use it to train its models.
Cutouts and standardized product photos
Each of your piece photos gets a cutout automatically: a copy with the background removed, which looks clean on outfit boards. It is made when you add or replace a photo (photos you added earlier are done gradually), so it is ready when you want it. Your closet and outfits keep showing the original unless you choose the cutout, and you are not notified. Rewear staff also make cutouts of catalog product photos; your own photos are never catalog photos.
For a cutout, each photo is scaled down to at most 1,024 pixels, stripped of camera data and sent to Rewear's own background-removal service, an open-source model that Rewear runs on its own Google Cloud servers in the United States. It is not sent to Google Gemini. Only the picture is sent: no name, email address, account identifier or piece details. The service keeps nothing: it returns the cutout and forgets the photo.
The model only marks which pixels belong to the subject; the colours are your photo's own. Rewear cleans the edges and compares the result with your original. If it does not match, it is not used: you see both and choose.
You can also ask for a Reverie flat lay of a piece photo: a new picture of the piece laid out flat on white, made by Rewear Reverie with a Google Cloud Vertex AI image model (Gemini) from your photo. Nothing is sent unless you press "Make flat lay" on that photo. With the photo, prepared the same way, Rewear sends only the piece's category and colour (for example "shirts & blouses, blue"), never its name, notes or anything else you wrote; for a catalog photo, staff send the product's name and category. A flat lay is a new picture, so details may differ from your piece: Rewear only checks its background, size and colours, and it is kept and shown only if you choose it. If you discard it, it is deleted. Flat lays count towards a daily limit and are never used as photos in a resale listing.
A cutout, Reverie flat lay or standardized photo is an extra version: your original photo is kept and never changed, and you choose which one your closet and outfits show. The versions are stored privately next to the original, with the date, the model used and the result of Rewear's checks.
A photo's cutout, Reverie flat lay and standardized versions are deleted with it: when you replace or remove the photo, delete the piece or delete your account. When a photo is removed after a report or takedown, its versions are removed everywhere too and cannot be made again.
Each member can make up to 50 cutouts a day and 20 Reverie flat lays; over that, a request waits until the next day (UTC). Automatic cutouts do not count towards it.
Visually similar pieces
To find pieces that look alike, Rewear measures photos on its own servers with an open-source image model (Marqo-FashionSigLIP) that Rewear runs on its own Google Cloud servers in the United States. No photo is sent to Google Gemini for this. The measurement is a list of numbers that describes how the photo looks; it is kept with the photo and deleted with it.
For this, a photo is scaled down to at most 1,024 pixels and sent without camera data: only the picture, with no name, account identifier or other details. The service keeps nothing: it returns the numbers and forgets the photo.
Only the product photos of Rewear's public catalog are measured. Photos of your own pieces, outfits, listings and anything else you upload are not measured.
Retailer links
Rewear may earn a commission when you buy through a retailer link. This is stated where the links are shown.
When you follow a retailer link, the click is recorded without your member ID, IP address, email address or referring page.
Some retailers work with Rewear through Awin, an affiliate network. A link to one of them goes first to Awin (awin1.com), which records the click and sends you on to the retailer. Rewear tells Awin only an anonymous click identifier, which part of Rewear the link was on (such as a product page or a look) and the retailer page you are going to. Your browser tells Awin that you came from rewear.fit, but not which page. Links to other retailers go straight to the retailer, and only the product SKU and an anonymous identifier are sent.
Like any website you visit, Awin sees your IP address and browser details. It may set cookies on awin1.com to credit a purchase to Rewear: Awin lists one for the retailer, typically kept 30 days, and a browser identifier kept one year. Awin decides how that data is used, under its privacy policy (https://www.awin.com/us/privacy; its cookies are listed at https://privacy.awin.com/). Awin has no opt-out page: you can block or delete cookies for awin1.com in your browser, or contact Awin at global-privacy@awin.com.
When a purchase is credited, Awin tells Rewear the anonymous click identifier, the order value, the commission and its status. It does not tell Rewear who you are, your address or what you bought. Rewear uses this only to count sales and commission for each retailer link.
Click records are removed after 180 days. A monthly count of clicks for each retailer link is kept after that. It holds no member ID, session, IP address or other identifier.
A second click on the same retailer link within 30 minutes is recorded but not counted. The time of your last counted click on each link is kept in your browser session on the server, not with the click record.
When you save a piece from another shop's page, for example with the app's share button, the page address is stored with the piece as it was sent. Rewear does not visit that address or fetch anything from it. It is removed when you delete the piece.
Notifications
Notifications appear inside the app. They are also emailed to your account address, through SendGrid, for the kinds you choose in Settings, under Notifications. Each kind can be emailed immediately, in a daily digest at about 8am in your account timezone, or not at all.
Every notification email has a link that turns that kind of email off with one click, without signing in.
Account emails are always sent and cannot be turned off: password reset links, the notice that Google sign-in was added, two-factor authentication turned off by staff, moderation and listing removal decisions, suspension and appeal decisions, and a notice to your previous address when the account email address changes. While an account is suspended, only account emails are sent.
SendGrid receives your email address and the text of each email. Rewear records which notices were emailed and when. That record is in your data download and is removed when you delete your account.
If you allow notifications in the Rewear phone app, the push token your phone gives the app is stored encrypted, to deliver notifications once push is connected. While push is not connected nothing is sent to it. The token is removed when you sign out of the app, when you remove the device in Settings and when you delete your account.
Invitations
When you invite a friend by email, Rewear stores the address and any note you add, both encrypted, with a keyed hash of the address, the invitation link, its status and dates. SendGrid receives the address and the email. The email says who invited them and that it is not a mailing list; your own email address is not included.
The address and note are removed as soon as you revoke or remove the invitation, and otherwise 30 days after the last email if your friend has not joined, or 30 days after they join. The invitation itself stays, without them, so a referral is still credited.
Brand team invitations store the address encrypted, with a keyed hash and the invitation link. They are deleted 30 days after they were made if still pending, or 30 days after they were accepted or revoked.
Every invitation email has a one-click "Don't send me invitations" link. It stops invitations from every member. Only a keyed hash of the address is kept for this, until the person allows invitations again. Daily sending counts are deleted after 2 days.
Your invitations are in your data download. Deleting your account removes them and revokes your pending brand team invitations.
Listings
A listing you create is public. It shows only what you entered on the listing: its title, description, category, condition, size, asking price, the photos you chose and the links you added. The photos are copies made when you save the listing.
What you paid for a piece, when you bought it, your notes, your tags and your wear history are never shown on a listing. If your profile is Private or Friends, your listings show "a member" instead of your handle, unless you choose to show your handle.
Staff reviewing a listing see an account number. They do not see your name, email address or handle, or the piece in your closet. Rewear does not visit or check the links you add to a listing.
When someone follows a link on a listing, the click is recorded without a member ID, IP address or referring page. Click records are removed after 180 days.
Brands
Brands see totals, such as how many closets hold their products, and never who you are. Managing a brand never gives access to a member's closet.
If you give a brand permission to send your purchase receipts, the receipts it sends wait in your Review and nothing is added until you approve it. You can withdraw the permission at any time.
To show that you control a brand's domain, you can publish a DNS TXT record or ask for a six-digit code at an address at that domain. The code is sent through SendGrid and stored only in a form that cannot be read back. The address is kept, encrypted, for at most about an hour after the code expires or the claim is closed.
Cookies and storage on your device
Rewear sets a session cookie that keeps you signed in and a security cookie that protects forms against forged requests. If you choose "Keep me logged in on this device", a further cookie keeps you signed in on that browser until you sign out.
Your browser also keeps a few display choices, such as light or dark appearance and whether the side menu is open. They stay on your device and are not sent to us.
Rewear's own pages set no advertising, analytics or third-party tracking cookies and load no Awin scripts. A retailer link that goes through Awin can lead Awin to set its own cookie on awin1.com, as described under Retailer links. Because we do not sell or share personal information or track you across other sites, there is nothing for a browser's "Do Not Track" or Global Privacy Control signal to turn off.
Who we share it with
We do not sell your personal information and do not share it for cross-context behavioural advertising, and have not done so in the past 12 months.
Google Cloud hosts Rewear: the application, the database, your photos and files, and server logs, in the United States (region us-central1).
SendGrid, a Twilio company, delivers our emails and, while forwarding is turned on, receives the mail sent to members' Rewear addresses.
Google provides sign-in with Google, the Google Maps Platform services behind weather and city search, and the Google Cloud Vision, Natural Language and Vertex AI (Google Gemini, used by Rewear Reverie) services described above, each only when it is turned on and only as described in this policy.
Google Workspace carries our own email, including messages you send to support@rewear.fit.
These providers handle data on our behalf under contracts with them and may not use it for their own purposes.
Awin, an affiliate network, receives the click details described under Retailer links when you follow a retailer link that goes through it. Awin is not one of the providers above: it uses that data for its own purposes, to credit sales and run its network, under its own privacy policy.
Other members see only what you share with them. Brands see totals only.
We may disclose information when the law requires it, to protect the safety of members or others, or to enforce the Terms. If Rewear is sold or merged, your information would pass to the new operator under this policy, and you would be told first.
Where it is stored
Your data is stored in the United States, in Google Cloud's us-central1 region.
How long we keep it
Your account and what you add to it are kept until you delete them or delete your account.
Import details you have not reviewed: 7 days. Retailer and listing click records: 180 days. Cached weather forecasts: less than 24 hours.
Forwarded and uploaded mail: deleted once read, and at most 24 hours after it arrived. Messages that are not orders: 7 days. Upload files: 24 hours. The keyed hash of a sender's address in your import history: 30 days.
Browser sessions end after 120 minutes without activity and are then deleted, unless you chose to stay logged in.
Server logs and error reports: 30 days. Database backups: daily, each kept 7 days, plus 7 days of point-in-time recovery. Deleted photos and files: recoverable by us for 7 days, then gone.
Your data and deleting your account
You can download your data from Settings, under Account, as a JSON file or CSV files. A ZIP file with photos and import history is offered where the server supports it. The download leaves out passwords, two-factor keys and recovery codes, mailbox connections and device sessions.
You can delete your account from Settings, under Account, by confirming your password. An account created with Google sets a password there first. Deletion takes effect immediately: the account and the records that belong to it, including pieces, photos, outfits, shared looks, wear history, imports, listings, mailbox connections, Rewear forwarding addresses and forwarded mail, are removed, and your photos are deleted from storage.
A small number of records are kept without your identity: usage counts for referral codes, the review history of brand claims with contact details removed, reports you made with their details removed, and staff audit records.
Copies in backups, logs and deleted-file storage expire on the schedule above. They are not restored except to recover from a failure, and then deleted accounts are not brought back.
Your privacy rights
You can ask to know what personal information we hold about you and how we use and disclose it, to get a copy, to correct it and to delete it. Most of this you can do yourself: edit in the app, download in Settings, delete your account in Settings.
California residents have these rights under the California Consumer Privacy Act, including the right to know the categories and specific pieces of personal information collected, the right to delete, the right to correct, and the right to opt out of sale or sharing and to limit the use of sensitive personal information. We do not sell or share personal information and use sensitive personal information only to sign you in and secure your account, so there is nothing to opt out of or limit. Residents of other states with privacy laws can make the same requests.
To make a request, email support@rewear.fit from the address on your account, or tell us that address. We confirm it is you by asking you to reply from that address or to sign in. We answer within 45 days. An authorised agent can act for you with your signed permission; we may still ask you to confirm your identity.
We will not treat you differently for using these rights. If we decline a request, we explain why, and you can appeal by replying to that answer.
Children
Rewear is not directed at children under 13, and you must be at least 13 to have an account. If you are under 18, you need a parent's or guardian's permission. If we learn that an account belongs to a child under 13, we delete it. Parents can contact support@rewear.fit.
Members aged 13 to 17 may use mannequin try-ons, which use no photo of anyone. A try-on with their own photo needs a parent's or guardian's agreement.
Security
Rewear uses HTTPS, stores passwords as one-way hashes, encrypts mailbox tokens, push tokens and saved cities, keeps photos in private storage and offers two-factor authentication. No system is perfectly secure. If a breach affects your personal information, we will tell you as the law requires.
Changes to this policy
The version and effective date are at the top of this page. Before a material change takes effect, we tell you by email and in the app at least 30 days ahead. Other changes take effect when posted. When a new version needs your agreement, the app asks for it the next time you use Rewear.
Contact
Peek House LLC, privacy questions and requests: support@rewear.fit.
See also Terms of Service.