Effective July 26, 2026
Stef's Closet is a personal space. What's in your closet, how you like to dress, and the looks we style for you are nobody's business but yours - and we built the service around that idea. This policy explains, in plain language, exactly what we collect, why, and what we will never do with it.
Stef's Closet (stefscloset.com) is operated by Mount Brands LLC, a Virginia limited liability company ("we," "us"). For anything in this policy, contact us at privacy@stefscloset.com or by mail at Mount Brands LLC, PO Box 304, Thornburg, VA 22565, United States. Mount Brands LLC is the data controller for personal information handled through the service.
Only to run the service: keeping you signed in, storing and displaying your closet, generating styling suggestions and imagery you ask for, sending the account emails the service needs (confirming your email, resetting a password), notifying you about your own closet (new looks unlocking, an issue being ready), billing paid subscriptions, metering AI usage, and keeping the service secure. We do not use your data for advertising, we do not build marketing profiles, and we do not sell or share your email address with anyone for their own marketing.
The closet-activity notifications are optional and on by default - turn them off anytime from Settings, or with the unsubscribe link at the bottom of any such email. The account emails (confirming your email, resetting a password) always send, since the service can't work without them. Our emails contain no tracking pixels and no read receipts - we can't tell whether you opened them, and that's intentional.
Everything else in this policy is the default, and the default is private. The Style Board is the one place your content can become public, and that only ever happens when you choose it, one look at a time. You are never opted in, there is no switch that makes your closet public, and your closet stays private by default for as long as you have an account.
When you publish a look, the public card shows only:
A public card never shows your real name, your email, prices, purchase dates, retailers, which pieces you own versus wish for, your private notes, or any account detail. The handle you pick for the board is kept separate from your login identity.
You can un-share a look at any time. When you do, we remove the public copy immediately - the card and its images come down straight away, with no waiting period. We cannot recall a screenshot someone already took, so please share only what you are comfortable being seen. Deleting your account removes all of your public board content along with everything else.
The styling features are powered by AI providers acting on our instructions:
Both providers process this data solely to deliver the feature you requested. Under our API agreements, neither provider uses your data to train their AI models. Your account identity is not shared with them - requests carry wardrobe and styling context, not your email or name.
| What | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in. Strictly necessary; set only when you log in. | Up to 30 days |
| Browser local storage | Remembers small interface preferences on your device (dismissed tips, scroll position). Never sent to us. | Until you clear it |
That is the complete list. There are no third-party cookies, no analytics cookies, and no advertising cookies - which is why you don't see a cookie banner here. The visit counting described in the next section is deliberately cookieless, and stores nothing on your device.
So we can tell whether anyone is finding us, we count visits to our public pages only: this site's front page, these policy pages, and any look someone has chosen to share to the Style Board. The signed-in app is not measured at all - your closet, your items, your looks and every page behind the login are excluded by design, not by setting.
Most of that counting is done with Plausible, open-source analytics software that we run ourselves on our own server, served from stefscloset.com. (The Style Board keeps a couple of counts of its own; those are described further down.) It is not a third-party service: no analytics company receives your visit, and there is no advertising network involved anywhere in it.
For a page view it records the page address, the site that referred you if any, and your browser, operating system and rough screen size. It also records how long the page was open and in front of you, and how far down it you scrolled - that is how we tell a page people actually read from one they bounce off. It also works out which country your visit came from, using an offline country database and your IP address. That is as precise as it gets: no region, no state, no city, and nothing closer. Your IP address is not stored in the process - see below.
It sets no cookie and stores nothing on your device, and it cannot follow you to any other website. It is not, however, completely blind to a repeat visit, and we would rather spell that out than imply otherwise. Your IP address is never stored. It is combined with your browser details into a one-way hash, using a secret that is thrown away and replaced every day, so that two page views a few minutes apart count as one visitor rather than two. Within a single day that hash does link your visits together; once the secret rotates, it cannot connect them to anything you do the next day. The hash cannot be turned back into an IP address.
We have deliberately turned off that tracker's optional extras: it does not record which links you click, it does not record file downloads, and it tags no custom events.
Separately from the tracker above, the Style Board counts a few things itself, so that someone who shares a look can see it was seen. We would rather describe this plainly than let the section above imply it doesn't happen.
When you open a shared look through a share link, we record one deduplicated visit against that link, and add one to the visit count its author sees. As with the tracker, your IP address is not stored - it is combined with your browser details and the current date into a one-way hash, and only that hash is kept, purely so the same person opening a link twice counts once.
There is one honest difference from the tracker, and it is worth stating carefully rather than glossing. The tracker's daily secret is thrown away, which is what makes an old visit impossible to trace back. The secret behind these share counts is not thrown away - it is long-lived. The date is mixed into the hash, so each day produces a different value and these rows are never joined up across days in our analytics. But because we still hold that secret, the design does not make cross-day recognition impossible the way the tracker's discarded secret does: someone holding both the secret and a known address and browser could recompute the daily values. We don't do that, it isn't what the counter is for, and we would rather tell you the limit of the guarantee than imply one we can't back.
The board also has a "Recreate this look" feature that is currently switched off. While it is off, clicks on the shop links under a shared look are not recorded. If we switch it on, those clicks will be counted against the look - so that an author can see which pieces drew interest - and we will say so here before that happens rather than after.
These board counts are part of how the sharing feature works, so the tracker opt-out below does not disable them. If you would rather not be counted at all, don't open share links; the board itself is readable without one.
We should be straightforward about one thing: because we host the tracker ourselves and serve
it from our own domain, the blocklists used by tracker-blocking extensions generally will not
catch it. If you would rather not be counted, you can switch it off permanently for your browser
by opening your browser's developer console on this site and running
localStorage.plausible_ignore = "true". Nothing on the site breaks if you do, and we
will not try to detect or undo it. Note that this covers the page-view tracker only, not the
board counts described just above.
We never sell personal information, and we never share it for advertising. Data goes only to the service providers that make the product work, under contracts limiting them to that job:
| Provider | Role | What they handle |
|---|---|---|
| Anthropic | AI styling | Wardrobe details, garment photos, style-profile context |
| AI imagery | Garment photos, styling prompts, your generated avatar | |
| Stripe | Payments | Email, subscription status, payment details (card data stays with Stripe) |
| Resend | Email delivery | Your email address and the emails we send you |
| Hostinger | Hosting | Runs our servers (United States) |
Charges on your card statement appear as STEFSCLOSET.COM, the site name.
Beyond that, we would disclose data only if legally required (a valid legal demand), or as part of a business transfer in which the new operator remains bound by this policy. If we ever received a legal demand for user data, we would notify the affected user unless legally prohibited from doing so.
Our servers are located in the United States. If you use the service from outside the US (including the EEA, UK, or Switzerland), your data is transferred to and processed in the US. Our providers offer recognized transfer safeguards (such as EU standard contractual clauses) for data originating in those regions.
Your data is kept while your account exists. When you delete your account, your records and photos are erased immediately, and the encrypted backups they appeared in are rotated out within 14 days. Payment records are retained by us and by Stripe as long as tax and accounting law requires. Brief technical logs age out on a rolling basis.
You don't need to email anyone to exercise the two big ones:
Depending on where you live, you also have legal rights to access, correct, delete, or receive a portable copy of your personal information, to restrict or object to certain processing, and to withdraw consent where processing is based on consent.
If you're in the EEA, UK, or Switzerland (GDPR): our legal bases are performance of our contract with you (running the service), legitimate interests (security and abuse prevention), and consent where we ask for it. You may lodge a complaint with your local supervisory authority, though we'd appreciate the chance to resolve concerns first.
If you're in California (CCPA/CPRA) or another US state with a privacy law: you have the rights to know, correct, and delete, and the right to opt out of the sale or sharing of personal information - we do not sell or share personal information as those laws define it, and we honor these rights for every user regardless of whether a particular law technically applies to us. We will never treat you differently for exercising them.
To exercise any right, use the in-app tools or email privacy@stefscloset.com from your account's email address (that's how we verify it's you). We respond within 30 days. If we decline a request, you may appeal by replying to our response.
All traffic is encrypted in transit (TLS). Passwords are hashed with argon2. Your photos are served only to your own authenticated session - there are no public photo URLs. Access to production systems is restricted and key-based. No internet service can promise perfection, but if a breach ever affected your data we would notify you promptly, as the law requires and because you'd deserve to know.
Stef's Closet is for adults. You must be 18 or older to use it, and we do not knowingly collect information from anyone under 18. If we learn we have, we delete it.
If we change this policy in a way that matters, we'll update the date above and, for significant changes, tell you in the app or by email before the change takes effect. We will never quietly weaken the commitments on this page.
privacy@stefscloset.com
Mount Brands LLC · PO Box 304, Thornburg, VA 22565, United States