Security

Your closet, held carefully.

Wardrobe photographs sit somewhere between diary and passport - personal, specific, and private. Aadornly handles them the way it would want its own closet handled.

Encrypted at rest and in transit

All wardrobe photographs and catalogue data are stored in encrypted object storage (AES-256) and travel over TLS 1.2 or higher between your device and Aadornly.

Visible only to you

Photographs and closet records are scoped to the account that uploaded them. No other user, employee, or partner sees your closet without an explicit support request from you.

Regional storage

Accounts registered in India are stored in India-region infrastructure. Non-India accounts sit on the nearest supported region.

Access is minimised

A small on-call engineering group can access production systems with hardware key MFA. Every access event is logged and reviewed monthly.

Delete means delete

A closet delete removes photographs and derived records within 30 days across primary storage, backups, and search indices.

Never sold, never advertised on

Aadornly does not sell closet data or use photographs for ad targeting. Gap suggestions are not sponsored and do not carry affiliate revenue.

What is kept, and why

The data table.

A short and honest map of what Aadornly stores, why it exists, and how long it stays.

Data
Wardrobe photographs
Retention
Retained while the account is active. Deleted within 30 days of account or item deletion.
Purpose
Digitising the closet, generating combinations, and displaying items in the app.
Data
Closet catalogue records
Retention
Retained while the account is active. Exportable at any time.
Purpose
Ranking outfits, computing gap suggestions, and answering occasion queries.
Data
Preference signals
Retention
Retained while the account is active. Resettable in a single action.
Purpose
Bending suggestions toward the outfits you actually save and wear.
Data
Auth and billing
Retention
Retained per applicable tax and finance regulations after account closure.
Purpose
Login, subscription management, invoicing, and support.
Compliance

Where we are, honestly.

We do not overclaim certifications. This page reflects the current posture; it will be updated as controls are formalised.

DPDP Act (India), 2023

Aadornly follows the principles of the Digital Personal Data Protection Act - purpose limitation, consent, and user rights - and provides export and deletion controls to every account.

GDPR-aligned handling

Even outside the EU, we apply GDPR-style controls to closet data: minimum necessary collection, encryption, right to access, right to delete.

SOC 2 - roadmap

A SOC 2 Type I audit is planned once the customer footprint requires it. We will publish the report here when it lands. We do not display any badge we have not earned.