Khzenti

Last updated 28 September 2026

Privacy Policy

Khzenti is a closet app. You photograph the clothes you own, and it picks outfits from them. That means we hold photographs of your clothes, and — only if you choose — one photograph of you.

This page says exactly what we hold, who else sees it, how long it stays, and how to take it back. We have tried to write it in plain words. If anything here is unclear, write to hello@khzenti.app and we will explain it.

On this page

  1. Who we are
  2. Who can use Khzenti
  3. What we hold
  4. Body photos
  5. Who we send your data to
  6. Where your data is stored
  7. Permissions on your phone
  8. What we do not do
  9. Friends, posts, and what other people see
  10. How long we keep things
  11. Deleting your account
  12. Getting a copy of your data
  13. Your rights
  14. Security
  15. Changes to this policy
  16. Contact

1. Who we are

Khzenti is made and run by one person, not a company. The operator is based in Lebanon.

Where the law requires a named data controller, that controller is Nasser Rafei, operating as Khzenti, in Lebanon. For anything to do with your data, including any of the requests described in section 13, write to hello@khzenti.app. That address reaches the operator directly.

We do not have a data protection officer, and we are not large enough to be required to appoint one.

2. Who can use Khzenti

Khzenti is for people aged 16 and over. If you are under 16, please do not create an account or add photographs.

We do not ask for your date of birth, so we cannot check your age. If you tell us that an account belongs to someone under 16, we will delete it and everything in it.

3. What we hold

Your account

  • Your email address, or your Apple sign-in. If you use Sign in with Apple and choose to hide your address, we only ever see Apple's private relay address. Apple also passes us your name the first time you sign in.
  • Your password, stored only as a cryptographic hash. We cannot read it, and neither can anyone with access to the database.
  • Your display name, your username if you set one, and the language you read the app in.

Your closet

  • The photographs you add.
  • The images we make from each photograph: a cut-out with the background removed, and a product-style "flat lay" shot generated by an AI model.
  • The tags an AI model reads from each photograph: category, colour, pattern, fabric, season, how formal it is, sleeve length, and which occasions it suits.
  • Any name or brand you type in yourself, and whether you marked it a favourite.

Outfits and wear history

  • The outfits you save or plan, their names, tags and occasions.
  • What you wore and on which day, both per outfit and per piece.
  • Any "fit pic" you take of yourself in an outfit.

Your body photo

Optional, and covered on its own in section 4.

Try-on renders

  • The generated images of clothes on your body photo, the intermediate image after each garment is added, and a cache of those intermediate images so a repeated outfit does not have to be rendered again.
  • One line per render: when it ran, what it cost, and which outfit or scanned item it was for.

Shop Scanner

  • The photograph you take of an item in a shop, and the cut-out made from it.
  • The tags read from it, the score, the buy-or-skip verdict, and which of your own pieces it would go with.

Friends and posts

  • Your username, who you are friends with, and friend requests you have sent or received.
  • Anyone you have blocked.
  • Posts you deliberately choose to share: the image, your caption, the occasion, and a plain description of the outfit by category and colour. We never attach the identity of the specific items from your closet to a post.
  • Reactions you leave, and any report you send us about a post.

Settings and preferences

  • A city, if you type one, and its coordinates, so we can show the weather. See section 7 for device location.
  • Your coverage preference, whether you wear menswear or womenswear, and your estimate of how many pieces you own.
  • Which of the example outfits you liked when you first opened the app, which we use to weight suggestions.

Streaks, invites and your render allowance

  • Your logging streak, your longest streak, and your device's time zone, which is how we know when your day ends.
  • Your invite code, and who invited you if you arrived through someone's code.
  • Your plan, how many renders you have left, and the record of each one.

Notifications

If you allow notifications, we store the push token your phone gives us, the platform, and your language, so the message arrives in the language you read.

Technical records

  • Our hosting provider records, for each sign-in session, the IP address and the device or browser identification it was made from. This is kept for security and to let you stay signed in.
  • Our server functions write short-lived diagnostic logs. These contain your account's internal identifier and temporary links to the images a request touched. They are not an activity profile, and they age out on our provider's schedule.

4. Body photos

This is the most personal thing Khzenti can hold, so it gets its own section.

It is optional

You never have to add a body photo. The whole app works without one: your closet, your daily outfit, saved outfits, the Shop Scanner, friends and posts all work with no photo of you at all. The only thing you cannot do is see clothes rendered on yourself, and there is a free preview that layers the cut-outs over a plain silhouette instead.

What it is used for

One purpose only: to show you what clothes would look like on you. We use it to generate try-on images, and to generate the plain-background version of yourself that those images start from. We do not use it for anything else. We do not use it to train AI models, ours or anyone else's. We do not use it for advertising, and we do not use it to recognise your face.

Nobody else sees it

Your body photo and everything derived from it is private to your account. It is never shown to your friends, it is never part of a post, and it is never used as a profile picture — profile pictures in Khzenti are initials only. The files sit in a private store that no other account can read.

What we keep

From one body photo we store the original, a cut-out of you with the background removed, a copy trimmed for rendering, and a framed copy sized so that renders come out head to toe. Deleting the photo removes all of them.

Where it is sent, and why

Making a try-on image is not something a phone can do. Your body photo is sent to three companies outside Lebanon, each for one step:

WhoStepWhat they receive
Google
Gemini API
Checking the photo is usable before you save it The photograph itself, with a question asking only whether a whole person is visible, whether the background is busy, whether it is too dark, and similar. The answer is seven yes-or-no values. Google is not told who you are.
Hugging Face
our own background-removal service, hosted there
Separating you from the room behind you A temporary link to the photograph, which the service opens to read it. The code is ours; Hugging Face provides the machine it runs on.
FASHN
United States
Generating the try-on image A temporary link to your body image and one to the garment image, and a short text description of the garment. FASHN is not told your name, your email, or anything else about you.

According to FASHN's terms, FASHN deletes the images it receives after 72 hours.

The temporary links we hand these services contain your account's internal identifier as part of the file path. It is a random identifier that means nothing outside Khzenti, but we would rather tell you it is there than describe the transfer as fully anonymous.

Deleting it

There is a one-tap delete on the body photo screen. It removes the photo and every file derived from it from our storage immediately. Renders you have already made are yours to keep or delete separately; deleting your whole account removes both.

What we cannot reach is a copy already held by the services above, which follows their own retention, and anything you have downloaded or shared yourself.

5. Who we send your data to

We use other companies to run Khzenti. None of them is paid to receive your data for their own purposes, and none of them is an advertising network. Here is each one and what it gets.

WhoWhat they doWhat they receive
Supabase Our database, sign-in, file storage and server functions. Everything in Khzenti lives here. Everything described in section 3.
Google
Gemini API
Reads the tags off a garment photo, writes the Shop Scanner's reasoning, generates the flat-lay product shot, and checks a body photo is usable. The image itself, and a question about it. Never your name, email, or account identifier.
FASHN
United States
Generates try-on images. Temporary links to your body image and a garment image, plus a text description of the garment.
Hugging Face Hosts the background-removal and segmentation service we wrote. Temporary links to garment photos, shop-scan photos, body photos and finished renders.
Apple Sign in with Apple; delivering notifications to iPhones; and, when paid plans go live, handling the purchase. Sign-in is between you and Apple: Apple gives us your email (or a relay address) and your name. For notifications, Apple carries the message text. For purchases, Apple handles the payment and tells us only that a subscription is active — we never see your card.
An email delivery service Sends the emails Khzenti has to send: confirming your address, resetting a password, an invite you asked us to send. Your email address and the contents of that email.
A push notification delivery service Passes notifications to Apple and Google for delivery to your phone. Your push token and the text of the notification. Where a notification is about a friend, that text contains their display name or username.
Open-Meteo Tells us today's weather so the outfit suits it. This one is called by your phone directly, not by our servers, so Open-Meteo sees your device's IP address along with the request. We send either your coordinates, rounded to about 100 metres, or the name of the city you typed. We never send anything about you or your clothes, and we do not store the location your phone reports.

We do not sell your personal information to anyone, and we do not share it for advertising. See section 8.

6. Where your data is stored

Your data is stored outside the Middle East. We want to state that plainly rather than bury it.

  • Your database records and all your images are held in Frankfurt, Germany, in our hosting provider’s central European region.
  • The try-on service is in the United States.
  • The AI tagging, background removal, email delivery and notification delivery services process data outside the Middle East as well, in the regions those providers operate.
  • The operator is in Lebanon and can reach the data in order to run and support the app.

If you are in the EEA or the UK, transfers out of Europe — for example to the try-on service in the United States — are made under the European Commission's Standard Contractual Clauses or an equivalent lawful transfer mechanism, and to Lebanon on the same basis.

If you are in Saudi Arabia or the UAE, your data is transferred outside your country to the places listed above, for the purpose of providing the app you asked for.

7. Permissions on your phone

Khzenti asks for four permissions, and only when the feature needs them. Saying no leaves the rest of the app working.

PermissionWhy
CameraTo photograph an item in a shop, to take your body photo, and to take a fit pic.
Photo libraryTo pick photos of your clothes. We read only the photos you pick; we never browse your library.
Location, while you are using the appTo look up today's weather. We ask once; if you say no we never ask again, and you can type a city instead. The location is used to make one weather request and is never stored on our servers.
NotificationsFor the evening reminder about your streak, friend requests, and reactions to your posts. We never ask on first launch.

The app reads your phone's motion sensor to show whether the camera is level while you take a body photo. Nothing from that sensor leaves your phone. Khzenti does not ask for your microphone, contacts, or calendar.

8. What we do not do

  • No advertising. There are no ads in Khzenti, and no ad network receives anything from it.
  • No advertising identifiers. We do not read your device's advertising ID, and we do not build or buy an advertising profile of you.
  • No session replay. We do not record your screen, your taps, or your typing.
  • No selling of personal information. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either.
  • No public profiles. There is no public page for a Khzenti user. Nothing you add is visible on the open internet.
  • No training on your photos. We do not use your photographs to train AI models.
  • No cookies on this page. This page and the Terms page set no cookies and run no analytics.

9. Friends, posts, and what other people see

Khzenti has no public feed. Sharing is off by default and opt-in for each outfit, one at a time.

  • Posts are visible to accepted friends only. Nobody else can see them, including people who have sent you a request you have not accepted.
  • Before you are friends with somebody, all they can see about you is your username and your display name. Your closet, your outfits, your city, your body photo, your renders and your fit pics are never visible to another user.
  • When you post, a friend sees the image you chose, your caption, the occasion, and a description of the outfit by category and colour. They do not see which items from your closet it was built from.
  • Blocking someone hides you from their search and them from yours. A blocked person is told the account cannot be found, not that they have been blocked.
  • Deleting a post removes its image and takes it out of every friend's feed. Deleting your account does the same for all of them at once.

10. How long we keep things

  • While your account exists, we keep what is in it. Khzenti is a record of your wardrobe, so nothing is deleted on a timer behind your back.
  • You delete things individually whenever you like: a garment, an outfit, a post, a render, your body photo.
  • Try-on renders are kept until you delete them or delete your account. They have no expiry, because you paid for them.
  • The feed shows the last 30 days. An older post stops appearing but is still yours until you delete it.
  • If you try Khzenti without creating an account, the temporary account and everything in it is deleted automatically after 7 days. Creating an account before then keeps it all.
  • A data export zip is deleted after 48 hours, and its download link stops working after 24.
  • Technical records — the session records and diagnostic logs in section 3 — age out on our hosting provider's retention schedule, which is days, not years.

11. Deleting your account

Profile → Your data → Delete account. You type the word delete to confirm, and the screen shows you the exact number of records and files that will go before you do.

What it removes: every image in every store — your closet, your body photo and everything derived from it, your renders, your scans, your fit pics, your posts — and then every database record across all 21 tables, and then your sign-in itself. It checks afterwards that nothing survived, and tells you so. Your posts disappear from every friend's feed at that moment. If someone joined through your invite code, they keep their own account, with the link to you erased.

What deletion cannot reach. We would rather list this than imply it does not exist:

  • A notification already delivered to a friend's phone.
  • Anything a friend has already saved or screenshotted.
  • Copies held by the services in section 5, which delete on their own schedules.
  • Our hosting provider's backups of the database, until those backups age out.
  • Diagnostic logs, until they age out.
  • An email we already sent you, which is in your inbox and in the sending service's records.
  • A paid subscription, if you have one. Deleting your Khzenti account does not cancel it, because only Apple can. Cancel it in your Apple account settings before deleting, or you will keep being billed for something you can no longer use.

12. Getting a copy of your data

Profile → Your data → Download my data builds a zip and gives you a private link, good for 24 hours. One export per day.

The zip contains a readable JSON file for each of the 21 tables that hold your records, and every image: your closet, your body photo, your renders, your posts, your fit pics and your scans. There is a manifest listing what is inside.

One honest gap. The export covers your closet, outfits, renders and social data. It does not yet include your account and sign-in records — your email address as we hold it, your Apple identity, and the session records described in section 3. If you want those too, email hello@khzenti.app and we will send them to you. We are working on putting them in the zip.

13. Your rights

Wherever you live, you can use the in-app buttons in sections 11 and 12, or email hello@khzenti.app. We answer within 30 days. We do not charge for this, and we will not treat you differently for asking.

If you are in the EEA or the UK (GDPR / UK GDPR)

You have the right to access your data, correct it, have it erased, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw any consent you have given. You can complain to your national data protection authority; in the UK that is the Information Commissioner's Office.

We rely on these legal bases:

  • Performing our contract with you — holding your closet, generating outfits, running your account. Without this there is no app.
  • Your consent — your body photo and the try-on renders made from it, your device location, and notifications. Each is optional, each is asked for separately, and you can withdraw any of them at any time by deleting the photo, refusing the permission, or turning notifications off. Withdrawing does not affect what was lawfully done before.
  • Our legitimate interests — keeping the service secure, preventing abuse, and reviewing reports about posts.

Your body photo is special category data under Article 9 to the extent it reveals information about you personally. We hold it on the basis of your explicit consent, given when you choose to add it, and for the single purpose in section 4. We do not use it for biometric identification.

Khzenti makes no automated decision that has a legal or similarly significant effect on you. The Shop Scanner's "buy" or "skip" is a suggestion about a jacket, not a decision about you, and you are free to ignore it.

If you are in California (CCPA / CPRA)

You have the right to know what personal information we collect and who we disclose it to, to a copy of it, to correct it, and to have it deleted. You can exercise all of these yourself in the app, or by email.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of, because it has never happened.

Your body photo, and the renders made from it, are sensitive personal information under the CPRA. We use them only to provide the try-on feature you asked for — which is a permitted purpose — and never to infer characteristics about you. That is already the limit the law lets you ask for, so there is no further limitation to request.

The categories in section 3 map to the statute's categories of identifiers, internet or network activity, geolocation, commercial information, and visual information. The purposes are in sections 3 to 5. We disclose personal information to the service providers in section 5 for those purposes, and to nobody else.

We will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights.

If you are in Saudi Arabia (PDPL)

Under the Personal Data Protection Law you have the right to be informed of how and why your personal data is collected, to access it, to obtain a copy of it in a readable form, to have it corrected or completed, and to request its destruction. Sections 11 and 12 are how you exercise the last two directly; email us for the rest. Your data is transferred and stored outside the Kingdom, as set out in section 6, so that the app can work. You may complain to the Saudi Data & AI Authority.

If you are in the UAE (PDPL)

Under Federal Decree-Law No. 45 of 2021 you have the right to ask what we hold and how it is processed, to receive your data in a structured, machine-readable form, to have it corrected or erased, to restrict or stop certain processing, and to object to processing carried out by automated means. Sections 11 and 12 cover copies and deletion; email us for anything else. Your data is transferred and stored outside the UAE, as set out in section 6.

14. Security

  • Every image store is private. Nothing is served from a public URL. Images reach your phone through links that expire, and only for your own account.
  • Access to every record is enforced by the database itself, row by row, against your signed-in identity — not by the app politely asking.
  • Everything travels over HTTPS.
  • Passwords are stored only as hashes. Nobody, including the operator, can read yours.
  • All keys for the AI and rendering services live on the server. None is in the app, so none can be extracted from your phone.

No system is perfect, and Khzenti is run by one person. If you find a security problem, please write to hello@khzenti.app before telling anyone else, and we will fix it and credit you if you would like.

If a breach ever affects your data and puts you at risk, we will tell you and the relevant authority as quickly as we can, and within the deadlines the law sets.

15. Changes to this policy

When we change this page, we change the date at the top. If a change actually matters — a new company receiving your data, a new purpose, anything narrowing your rights — we will tell you in the app before it takes effect, and where the law requires consent we will ask for it rather than assume it.

This page mentions only the services Khzenti uses today. If we add analytics or any other tool that sees your behaviour, it goes on this page before it goes in the app.

16. Contact

One address for everything, reaching the operator directly:

hello@khzenti.app

Khzenti · operated from Lebanon · see also the Terms of Service.