Privacy Policy
Effective date: July 31, 2026 · Last updated: August 12, 2026
This Privacy Policy describes how Hailey Morgan, a sole proprietor operating ClosetU (“ClosetU,” “we,” “us”), collects, uses, and shares personal information when you use the ClosetU mobile application (the “App”) and our website at closetu.app (the “Site”). Most of this policy describes the App, because that is where nearly all personal information is handled. Section 1.2 and Section 12 describe the Site.
ClosetU is a secondhand marketplace for college students. Right now it is open only to students at California Polytechnic State University, San Luis Obispo, who sign up with a calpoly.edu email address.
ClosetU does not process payments. Buyers and sellers arrange payment directly between themselves, off the platform. We do not collect, receive, or store payment card details, bank information, or payment history of any kind.
If you have questions or want to exercise your rights under this policy, contact us at privacy@closetu.app.
1. Information we collect
We collect only the information needed to run the marketplace.
1.1 Personal information you provide
Account information
- Email address. Your college calpoly.edu email. Used to verify eligibility, authenticate you, and send account and security messages.
- Password. Stored only as a salted cryptographic hash. We never see or store your plaintext password.
- Display name / username. The name shown on your listings and messages.
- Avatar photo. An optional profile image you upload.
- Bio. An optional short text about you (up to 160 characters) shown on your public profile to other signed-in users.
- Shopping preference. An optional womenswear / menswear default you set for your feed. You can change or clear it at any time.
- Interests. Style tags you pick during onboarding, used to personalize your feed.
Listing content
- Photos, titles, descriptions, prices, sizes, brand, color, tags, and categories you post when selling an item.
- A general pickup area you select from a preset list, such as a housing complex or campus zone. This is a coarse locality label, not a precise address or map pin. The specific place you actually meet is arranged in chat and is not stored as location data.
Messages
- When you send or receive a message in ClosetU, we store the message content, the sender and recipient, and the timestamp. Messages are stored on our servers (Supabase) so they can be delivered in real time and remain available on your other devices. Messages are not end-to-end encrypted and may be read by ClosetU staff when responding to abuse reports or complying with legal process. Because payment is arranged directly between you and the other user, please do not share sensitive information such as a Social Security number or full payment card details in messages.
Reports. When you report a listing, message, or user, we store the reason you selected, any context you write, and who filed the report.
Consent records. When you accept our Terms at signup, and when you acknowledge the meetup safety notice, we record that acceptance. See Section 1.2.
Student verification. We check that your email address ends in calpoly.edu and that you can receive a code sent to it. We do not verify enrollment, identity, or age beyond that.
1.2 Information collected automatically
- Consent records, including your IP address. When you accept the Terms or acknowledge the meetup safety notice, we store a record containing your user ID, which document version you accepted, the exact wording shown on your screen, the time of acceptance, and the IP address the request came from. The IP address and timestamp are recorded by our server, not supplied by the App. These records exist so that we can later show what a specific person agreed to and when, and they are retained for as long as they may be needed for that purpose (see Section 4). They are not used for tracking, profiling, advertising, or location inference.
- Device push token. A push-notification token issued by Apple Push Notification service and relayed via Expo Push. Used only to deliver notifications you have permitted.
- IP address and technical logs. Captured by our hosting providers for security, abuse prevention, and debugging: Supabase for the App's backend, and Vercel for the Site. These are ordinary web server logs recording the IP address, the browser or device user agent, and the resource requested. Retained for up to 30 days. This is separate from the consent records described above.
- Usage analytics (first-party only). How you use the App: screens you view, in-app actions such as searches performed (we record that a search happened and its filter settings, not the search text), and listings you view or like. Each record includes your user ID (or no user ID at all if you are browsing without an account, see below), a per-session identifier, the app version, and the device platform. This data is collected by our own code, stored only on our own servers (Supabase), and is never sent to an advertising or analytics company. We use it to understand which features work and where the App loses people, as described in Section 2.
- Error and crash reports. When something in the App fails, we log what operation failed, an error code and message, the screen you were on, and your user ID. These logs are stored only on our own servers and are used to find and fix bugs. They never include message content or passwords.
Device location. With your permission, the App reads your device's location on your device only, to center the exchange map and show you nearby listings. Your coordinates are never transmitted to us and are never stored on our servers. We request foreground location only and do not track your location in the background. You can disable location at any time in iOS Settings, then Privacy & Security, then Location Services, then ClosetU. With location off, the map simply centers on the Cal Poly campus.
Precise geolocation is Sensitive Personal Information under California law (location within a radius of approximately 1,850 feet, per Cal. Civ. Code section 1798.140). Because we never receive or retain it, there is nothing for us to use, disclose, or limit. See Section 7.
Browsing without an account. You can browse public Listings without creating an account. If you do, we collect no account information about you, because there is none. We receive only the ordinary technical logs described above and first-party usage analytics records that carry no user ID: a random per-session identifier, the app version, and the device platform. We cannot tie those records to you. People browsing without an account cannot see seller usernames, profiles, or pickup areas.
1.3 Information from third parties
We do not receive personal information about you from any third party. We do not use data brokers, identity providers, social logins, or enrichment services.
1.4 Information we do NOT collect
- Payment information of any kind. No card numbers, no bank details, no billing addresses, no transaction amounts, no purchase history. Payment happens directly between users and never touches ClosetU.
- We do not collect your contacts, calendar, health data, browsing history in other apps, or your advertising identifier (IDFA).
- We do not use analytics or advertising SDKs that track you across other companies' apps or websites.
- We do not record audio or video. Listing and profile photos are still images only.
- We do not receive or store your device's precise location.
- We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising.
2. How we use your information
- Providing the service. Showing you listings, running the marketplace, delivering messages and notifications, and moderating content.
- Trust and safety. Verifying that a signup address is a calpoly.edu address, preventing spam and fraud, enforcing our Terms, and responding to abuse reports.
- Proving consent. Retaining the consent records described in Section 1.2 so we can establish what a user agreed to and when, if that is ever disputed.
- Improving the App. Using the first-party usage analytics and error reports described in Section 1.2 to understand how features are used, measure where flows lose people, and fix bugs and crashes. This analysis stays inside ClosetU. It is never used for advertising or shared with data brokers.
- Communicating with you. Account, security, and service emails and push notifications. We do not send marketing email.
- Legal compliance. Responding to lawful requests and resolving disputes.
3. How we share your information
We share personal information only with the following service providers, and only to the extent needed for them to provide their service to us. Each is bound by a written data processing agreement.
| Provider | Purpose | Where data is processed | Their privacy policy |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, real-time messaging, Edge Functions | United States | supabase.com/privacy |
| Vercel, Inc. | Hosting for the closetu.app website | United States | vercel.com/legal/privacy-policy |
| Resend, Inc. | Transactional email | United States | resend.com/legal/privacy-policy |
| 650 Industries, Inc. (Expo) | App build (EAS Build), over-the-air updates (EAS Update), push-notification relay (Expo Push) | United States | expo.dev/privacy |
| Apple Inc. | Delivery of push notifications via Apple Push Notification service | United States | apple.com/privacy |
No payment processor. ClosetU does not use a payment processor, because we do not process payments. If we introduce payments in a future release, we will update this policy and notify you before that change takes effect.
In addition to the specific providers named above, we may share information with categories of service providers necessary to run the service: cloud hosting, database and storage, email delivery, error monitoring, security and fraud prevention, and professional advisors (legal and accounting). When we add or change a provider in one of these categories, we will update this policy at our next scheduled revision.
We may also disclose information (a) with your consent, (b) to comply with law or a lawful request, (c) to protect the rights, safety, or property of ClosetU, our users, or the public, or (d) in connection with a merger, sale, or similar business transaction, in which case users will be notified.
4. Data retention
- Account data (email, username, avatar, interests): while your account is active.
- Listings: until you delete them, or your account is closed.
- Messages: while your account and the counterparty's account are active. On account deletion your messages are anonymized rather than deleted, because the other party still needs their own history.
- Consent records (including the IP address and the wording you were shown): retained for as long as they may be needed to establish what you agreed to, and in any event for at least the period of the applicable statute of limitations. These records are append-only. They cannot be edited, and they are deleted only when your account is deleted.
- Reports and moderation records: retained while needed to enforce our Terms and to identify repeat violations.
- Operational logs (IP addresses and request logs held by our hosting provider): up to 30 days.
- Usage analytics and error reports: linked to your account while it is active. When you delete your account, your user ID is removed from these records, leaving only anonymous records. See Section 5.
- After account deletion: see Section 5.
5. Account deletion
You can delete your account at any time from Settings, then Delete Account inside the App. Deletion is immediate, cannot be undone, and is processed in four buckets:
- Hard-deleted. Your own data: listings, listing photos, saved items, avatar, and interest preferences.
- Anonymized and retained. Data another user depends on: the messages in your conversations, so the other user keeps their own record. Your name and other identifiers are removed from these records.
- Anonymized tombstone. A placeholder profile row is kept so references from the retained records still resolve, showing a deleted user rather than a broken reference.
- De-identified. Usage analytics and error reports have your user ID removed at deletion time, leaving only anonymous records that can no longer be connected to you.
Your consent records are deleted along with your account.
Because ClosetU never holds money, there is nothing financial to settle before deletion, and deletion is never blocked.
If you want your account permanently deleted but cannot sign in to do it yourself, email privacy@closetu.app.
6. App permissions
- Camera. To take photos of items you are listing for sale.
- Photo Library. To select existing photos for your listings or profile avatar.
- Location (When In Use). To center the exchange map near you on your device. Your coordinates are not sent to us. We do not request background location.
- Notifications. To send you alerts about new messages and activity on your listings.
You can revoke any of these at any time in iOS Settings, then Privacy & Security, and in Settings, then ClosetU, then Notifications. Revoking a permission may disable the associated feature.
7. Your California privacy rights (CCPA / CPRA)
If you are a California resident, you have the following rights:
- Right to Know. Request the categories and specific pieces of personal information we have collected about you over the last 12 months.
- Right to Delete. Request deletion of your personal information, subject to legal exceptions.
- Right to Correct. Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing. We do not sell your personal information or share it for cross-context behavioral advertising. There is nothing to opt out of, but you can confirm this election at any time.
- Right to Limit Use of Sensitive Personal Information. We do not collect, receive, retain, or disclose any Sensitive Personal Information. Device location is read on your device and never transmitted to us, so there is no sensitive-information use for you to limit. You can still revoke the location permission at any time in iOS Settings.
- Right to Non-Discrimination. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised any of these rights.
- Right to Appeal. If we decline a request under any of the rights above, you may appeal by replying to our decision email. We will respond to appeals within 45 days and, if we deny the appeal, provide the reasons and the contact information for the California Privacy Protection Agency.
How to exercise your rights. Email privacy@closetu.app from the address associated with your ClosetU account. We will respond within 45 days as required by California law. To verify your identity, we may ask you to confirm information already on your account. You may designate an authorized agent to submit a request on your behalf, with written proof of authorization.
Categories of personal information collected in the last 12 months, mapped to California statutory categories:
| Statutory category | Examples in ClosetU |
|---|---|
| Identifiers | Email, username, user ID, device push token, IP address recorded with a consent record |
| California customer records categories | Name |
| Commercial information | Listings you created, items you liked or saved |
| Internet or other electronic network activity | IP address in operational logs, in-app usage analytics (screens viewed, searches performed, listings viewed or liked), error logs |
| Geolocation data | None. Device location is read on your device and never transmitted to us |
| Visual information | Avatar, listing photos |
| Inferences | Interest tags |
We do not collect financial information, payment card information, biometric information, government identifiers, or precise geolocation.
Sources: directly from you; from your device (push token); and from your use of the App (usage analytics, error logs, IP address at request time).
Purposes: providing the service, security, proving consent, improving the App, and legal compliance. See Section 2.
Disclosures for a business purpose: shared with the service providers listed in Section 3. We have not sold or shared personal information in the preceding 12 months.
8. Do Not Sell or Share My Personal Information
ClosetU does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We do not have a “Do Not Sell or Share” link because there is no sale or sharing to opt out of. If this ever changes, we will update this policy and provide a clear opt-out mechanism before any change takes effect.
9. Age requirements
ClosetU is intended for users 18 years of age or older who are enrolled at a participating university. We do not knowingly collect personal information from anyone under 18. Our email check limits signups to individuals with a college-issued email address, but it does not verify age. If we learn that a user is under 18, we will delete their account and any personal information we have collected.
The App is not directed to children, and we do not knowingly collect personal information from children under 13 as defined by the Children's Online Privacy Protection Act.
10. Security
We protect your information with:
- Encryption in transit (TLS 1.2 or higher) between the App and our servers.
- Encryption at rest on Supabase-managed Postgres and Storage.
- Row Level Security policies scoped to each user's own data.
- Passwords stored only as salted hashes, never in plaintext.
- Append-only consent records that cannot be edited or deleted by any user, including us, short of deleting the account.
No security control is perfect. If you suspect an issue with your account, email privacy@closetu.app immediately.
11. International users
ClosetU is intended for use only in the United States, and specifically at California Polytechnic State University, San Luis Obispo. If you access the App from outside the United States, your information will be transferred to and processed in the United States by the providers listed in Section 3.
12. Cookies and tracking technologies
The Site. Our website at closetu.app sets no cookies, runs no analytics, tag manager, advertising pixel or third-party script, serves its own fonts rather than loading them from a font provider, and has no forms, logins or other place to enter personal information. The only record it produces is the server log described in Section 1.2. We also honour Do Not Track and Global Privacy Control signals, which is straightforward for us because we do not track visitors across sites in the first place.
The App. The ClosetU mobile App does not use browser cookies. The App uses local device storage (React Native's AsyncStorage) solely for app functionality: session tokens, user preferences, and cached content. We do not use tracking pixels, cross-app advertising identifiers, or third-party analytics SDKs. The only usage measurement in the App is the first-party analytics described in Section 1.2, collected by our own code and stored on our own servers.
13. User-generated content and user-to-user interactions
Listings, messages, and profile content are created by users. Listing photos, titles, descriptions, prices, and details are visible to anyone using the Service, including people who have not created an account. Your username, profile (including your bio and avatar), and general pickup area are shown only to signed-in users. Messages are visible only to the two people in the conversation.
To keep the marketplace safe:
- You can block any user from their profile or from a conversation.
- You can report a listing, message, or user through the report button on their content.
- We review reports within 24 hours and remove content or accounts that violate our Community Guidelines.
Because payment and the in-person handoff happen entirely between users, ClosetU has no record of what was paid or what changed hands. See our Terms of Service for what that means for you.
See our Community Guidelines and Terms of Service for full details.
14. Changes to this policy
We may update this policy from time to time. The “Effective date” and “Last updated” fields at the top will always reflect the latest revision. If we make a material change, such as a new category of data collected, a new purpose, or a new third-party disclosure, we will notify you in the App and, when possible, by email or push before the change takes effect.
Introducing payments would be a material change, and we will notify you before it takes effect.
This policy is reviewed at least every 12 months.
15. Contact us
Email: privacy@closetu.app