i · The promise
Your closet.
Your call.
Here's exactly what Denzl reads, stores, and shares. Your photos and wardrobe stay private by default, and your order mail is read only if you connect it. Plain language. No vague clauses.
ii · What we collect
What Denzl handles.
From you, directly
Name, city, age group, body measurements (optional), shopping preferences, and any delivery address you choose to save. You choose what to share.
The photos you add
Wardrobe pieces you photograph, an optional selfie for try-on, and any photos you choose to import from Google Photos. Stored privately, tied to your account, with camera location stripped. Private by default: nothing is public unless you put it on your passport.
Your Ask words
The text of what you ask and what Denzl answers. It powers your conversation history and continuity; selected likely failures may also enter the bounded, access-logged product-improvement review described below.
From your Gmail (only if you connect it)
Order-confirmation emails only. We extract product name, brand, size, colour, price, order date, platform. That's it.
While Denzl helps you shop (only if you turn it on)
On external merchant pages opened from Denzl, the app may keep the merchant host, canonical public product URL, product name, brand, price, public stock and size signals, a coarse journey stage such as product, bag, address or checkout, and which version of the Denzl app the journey came from, so a problem you report can be traced to the build you were running. Shopping observations keep no query string, cookie, password, form value, card detail, CVV, PIN, OTP value, SMS content, UPI credential, issuer page or payment URL. A sensitive observation can say only that the journey reached payment and whether one standard OTP field is present. When you explicitly submit a Denzl size-and-quantity picker, the existing partner-checkout route processes that selection only to create or resolve the merchant cart.
Your device location (only when you tap “Use my location”)
Denzl sends your precise latitude and longitude to Google Maps Platform's Geocoding API to turn them into city, state and PIN code. Google acts as our sub-processor for that one lookup. Denzl does not write the coordinates to your account, database, analytics or logs; it may keep the lookup in process memory for up to five minutes to avoid repeating the same request. The city, state or PIN is saved only if you then submit the Denzl form.
What we do NOT collect
Personal mail, attachments, contacts, drafts, sent mail, general browsing history, passwords or payment credentials. We don't read anything that isn't an order confirmation from a known brand, and external-shopping observation is limited to the consented Denzl shopping window described above.
iii · How Gmail access works
Read-only. Always.
Google user data we access
Denzl accesses your Google user data through the Gmail API using a single OAuth scope: gmail.readonly (read-only access to Gmail messages). The only Google user data Denzl reads is the content of order-confirmation emails sent to your Gmail address by online retailers, used solely to identify and display your own purchase history inside Denzl. Denzl does not access any other Gmail data (personal mail, attachments, contacts, drafts, sent mail, or labels) and does not access any other Google service or Google account data.
OAuth scope · gmail.readonly
Read-only. Denzl can never send mail, delete mail, or modify your inbox in any way.
Senders we read from
We search for confirmation mail from these senders only:
Subject patterns we match
"order confirmation", "order placed", "your order", "thank you for your purchase", "order details". If a mail doesn't match these patterns from a known sender, we skip it.
What happens to email content
We parse the mail to extract structured data (product, brand, size, price, date). The raw HTML is never stored. Once parsed, the email content is discarded.
Google API Services Limited Use Disclosure
Denzl's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Denzl does not use Gmail data to train, improve, or develop AI/ML models. Gmail data is used solely to identify and display your purchase history within the Denzl app.
iv · How community signals work
What stays private.
What gets shared.
Your purchases are never visible to other members
Nobody sees what you bought, where you bought it, or how much you paid. Individual purchase data is never shared.
Signals are anonymous and aggregated
Cohort signals like "3 men your build bought this" are generated from aggregated data across multiple members. Minimum threshold of 3. Signals only appear when 3+ members match. This prevents any individual from being identified.
You contribute, you benefit
Your anonymised data helps generate signals for others. In return, you see signals generated from everyone else. The more men join, the sharper everyone's signals get.
v · Data protection
How we protect it.
Encryption in transit
Every connection is encrypted with TLS 1.2 or higher (HTTPS). This covers traffic between you and Denzl, and every request Denzl makes to the Gmail API to read your data. No data, including Google user data, is ever transmitted in plaintext.
Encryption at rest
Your data is stored in Google Cloud SQL (PostgreSQL, Mumbai region) and is encrypted at rest. Gmail OAuth refresh tokens, the most sensitive data we hold, are additionally encrypted at the application layer with AES-128 before they are written, and are never exposed in logs or API responses.
Access controls
Production secrets and API keys live in Google Cloud Secret Manager, never in source code or the repository. Access to the production database and infrastructure is restricted through Google Cloud IAM and limited to the operator.
Data minimisation
Email content is processed in memory to extract structured fields only (product, brand, size, price, date, order ID). Raw email HTML is never written to disk or to the database, and is discarded immediately after parsing.
Where your data lives
Google Cloud SQL PostgreSQL (Mumbai region). Application hosted on Google Cloud Run, same region. Product images on Cloudflare R2 (CDN). No Gmail content is stored on any of them.
Photos you capture
When you photograph a piece of your wardrobe in the app, we store that image privately, tied to your account. Your photo is served only to you: never on the public CDN, never shown to other members. Camera metadata (EXIF, including any location) is stripped before storage. The photo is kept while your account is active and is permanently deleted when you delete your account. Receipt photos are read for their text and not stored as images.
Denzl reads each wardrobe photo with AI to pick out the piece's details (type, brand, colour), and may generate a clean product-style image of the garment. If you choose to show a piece on your public passport, other members see the brand's catalog image or that generated product image of the garment. Your original photo is never public. Nothing is on your passport unless you put it there.
Selfies and try-on
Adding a selfie is optional. If you add one, we store it privately and use it for exactly one thing: generating your own try-on images, shown only to you. Other members never see your selfie or your try-on renders. Remove your selfie whenever you want; it is permanently deleted with your account. If you try Denzl without an account, your selfie and its render are deleted automatically on a short schedule.
AI processing of photos
The photo features above run on AI services acting on our instructions: Google Cloud Vertex AI, Replicate and OpenRouter. Photos are sent to them over encrypted connections only to produce the result (reading garment details, generating a clean image or try-on). We store only the outputs, privately, as described above.
The live try-on mirror works the same way with one difference: while the mirror is on, your camera video streams to Decart, another AI service acting on our instructions, solely to show the garment on you. It runs only after you start it, for a few seconds at a time. Denzl stores none of that video, and it ends the moment the mirror closes.
Your Ask conversations
When you talk to Denzl in Ask, we keep the text of what you asked and what Denzl answered, tied to your account. We keep it so you can read past conversations and the stylist can pick up where you left off. No other member sees it.
Account participation also helps improve Denzl. When automated quality checks find a likely Ask failure, we may copy that turn’s words into a separate, access-logged review store. An authorised Denzl reviewer can read what you asked and what Ask answered so we can verify the problem and fix it. The reviewer view excludes your account identifiers. A review copy is kept for at most 90 days and is never copied into GitHub, Linear, Slack, logs, or a coding agent.
This access-logged improvement review currently covers the text record only, including speech after it is transcribed. It does not use Gmail, Google Photos, raw audio, or camera frames. Any separate camera-frame retention active during a test is disclosed before you press Start and is not readable through this reviewer store. If the review data classes materially change, we will update this notice and its recorded version before collecting them.
During early testing there is one exception: members in the test group may have a few photos from their sessions kept so the styling can improve, held privately, shown to nobody, and deleted with the account like everything else.
Tap Clear history in Ask whenever you want to erase the conversation record. To stop future product-improvement review and delete eligible review copies already collected, use You → Account → Stop product improvement. Everything is also deleted with your account.
Google Photos import (optional)
Importing from Google Photos is optional. If you use it, Denzl opens the Google Photos Picker API with a single read-only scope: photospicker.mediaitems.readonly. You hand-pick the exact photos inside Google's own picker, and Denzl receives only the photos you pick. Denzl can never browse, list, or search your photo library, and never sees a photo you did not pick.
Denzl reads the clothing in each photo to find the garments, then stores the photos and the garment crops privately, tied to your account and EXIF-stripped, the same as any wardrobe capture. We do not request or store refresh tokens for this access, so every import is a fresh consent by you. Photos of you wearing clothes are never shown to anyone. Photos and crops you do not keep are deleted when you finish reviewing them, and everything imported is deleted if you delete your account.
Denzl's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Photos data is used solely to build your own private wardrobe inside Denzl and is never used to train, improve, or develop AI/ML models.
Push notifications (mobile app)
If you turn on notifications in the Denzl app, your device gives us a push token: an anonymous address for your phone, not a name or number. We store it tied to your account only to send the alerts you asked for, and delivery runs through Google's Firebase Cloud Messaging (Android) acting on our instructions. Turn notifications off in the app or your device settings anytime; the token is deactivated, and it is permanently deleted when you delete your account. We never use the token for ads, and we never use it to follow you across other apps or sites.
External shopping assistant (mobile app)
If you turn it on, Denzl opens merchant pages in a separate in-app browser with the merchant origin always visible. The app can read public product metadata and visible stock or size signals, show each reversible checkout action, and offer a button to fill standard delivery fields from an address you saved with Denzl. Your saved address is encrypted at the application layer and is sent only after you approve sharing it with that merchant for that session.
Denzl does not copy merchant cookies, passwords or payment details, and cannot press Verify, final pay or place order. Public HTTPS checkout redirects can remain in the same in-app browser, but a different origin receives no observation or assistance unless it was explicitly admitted for that merchant. On Android, Google Play services may show a one-time consent prompt for one matching OTP SMS; if you approve it, native code fills the identified OTP field and immediately drops the message/code. Denzl requests no inbox-wide SMS permission. On iOS, Apple's Security Code AutoFill lets you tap the code suggestion. OTP values and message text never reach Denzl's server, model, logs or history, and Denzl never submits them. Public product signals are freshness evidence only; Denzl rechecks the brand's official source before changing its Catalog.
Shopping history receipts are kept for up to 30 days. Use You → Shopping assistant → Clear shopping history at any time; turning the assistant off stops future observation. The consent, saved address and history are included in your data export and deleted with your account.
Email we send you
When Denzl sends you an email, we record whether it was opened and which link in it you clicked. Opens are measured with a single invisible 1×1 image; clicks are measured by routing links through a redirect on denzl.co that forwards you straight to where you were going. We do this to know whether what we send is worth sending, and to notice delivery problems early.
What we keep is the engagement, not the content: the email, the time, and the link. We do not read your replies, we do not scan your inbox for this, and this has nothing to do with the Gmail receipt access described above. It is never sold, never used for ads, and never used to follow you across other apps or sites.
Emails you need in order to use your account carry no open pixel: signing in, confirming a deletion, telling you a connection broke. We do not think it is our business whether you opened a deletion confirmation.
Open figures are approximate by nature: some mail apps, including Apple Mail with Mail Privacy Protection on, load that image for you whether or not you read the message. We treat opens as an upper bound, not a fact about you.
Use Unsubscribe or Manage emails at the foot of any lifecycle email to stop them. The record is tied to your account and is deleted when you delete your account.
No ads. No selling data.
We don't sell, rent, or share your data with advertisers or third parties. We don't show ads. We don't do affiliate marketing. Your data powers your personal experience, anonymous community signals, and the bounded product-improvement review described above.
vi · Your rights · DPDP Act
What you can ask for.
Export your data
Go to You → Download my data, or hit /api/account/export directly. You'll get a single JSON file covering everything Denzl stores against your account: purchases, reviews, declared sizes, follows, preferences, notifications. Sensitive auth tokens (passwords, OAuth refresh) are explicitly excluded.
Delete everything
Go to You → Delete account. All your data (purchases, profile, preferences, Gmail tokens, scan history, wardrobe photos) is permanently deleted immediately. Your data is also removed from future cohort signal aggregations.
Disconnect Gmail anytime
Go to You → Connected accounts → Disconnect. We revoke our Google OAuth access, delete your refresh token, and stop reading your mail immediately.
Data retention
We retain your account data while your account is active. If you delete your account, all personal data is permanently removed within 24 hours. Product-improvement review copies expire after 90 days and are deleted sooner if you stop participating or delete your account. Anonymised, aggregated cohort signals (which cannot identify you) may persist.
DPDP Act compliance
We comply with India's Digital Personal Data Protection Act (2023): explicit consent before collecting data, purpose limitation (data used only for stated purposes), data minimisation (we collect only what's needed), and the right to erasure.
vii · Contact & Grievance Officer
Talk to us.
Privacy questions or data requests
Email [email protected].
Grievance Officer · DPDP Act
Bharat Jilledumudi · [email protected]
Grievances acknowledged within 48 hours and resolved within 30 days.
Registered entity
Nyusta Technologies, Bangalore, India.
Last updated · September 2026 · Terms of use →