Abstract production environment representing a privacy-first local workflow.
WardrobeDraft

Privacy-first listing preparation.

WardrobeDraft keeps photos and listing drafts on your device by default. Cloud services are used only when you explicitly choose them.

Effective 2 October 2026

Privacy policy for the WardrobeDraft browser extension.

01

Controller and contact

WardrobeDraft is provided by Andreas Boehler, Freiburg im Breisgau, Germany. Full legal provider information is available in the legal notice.

For privacy requests, use the contact form or .

02

What WardrobeDraft does

WardrobeDraft turns clothing photos into editable marketplace listing drafts. It supports local folder import, optional Google Drive import, photo grouping and rotation, optional AI analysis, bulk editing, exports, and user-confirmed preparation of Vinted listing or repost forms.

WardrobeDraft does not sell personal data, does not use advertising trackers, and does not use product photos or listing content for advertising or unrelated profiling.

03

Data stored locally

Imported photos, thumbnails, grouping information, listing drafts, titles, descriptions, item attributes, prices, queue state, settings and export preferences are stored in the browser profile on the user's device. API keys are stored in local extension storage only when the user enables and configures the corresponding provider.

Local information can be removed by deleting items in WardrobeDraft, clearing the extension's site data, or uninstalling the extension. Uninstalling or clearing browser data may permanently remove locally stored drafts.

04

Local folders and photos

WardrobeDraft reads only files the user explicitly selects through the browser's folder picker. Selecting a folder does not automatically start an AI request or upload the photos to WardrobeDraft's account service.

Image processing such as thumbnails, grouping, rotation and ZIP export is performed in the browser unless the user explicitly starts an AI feature configured to use a cloud provider.

05

Optional AI providers

In local Ollama mode, AI requests are sent only to an Ollama server running on 127.0.0.1 or localhost on the user's device.

If the user selects OpenAI, Google Gemini, Anthropic Claude or OpenRouter and starts an analysis, resized image previews, the analysis prompt and relevant draft context are sent directly from the extension to that selected provider. WardrobeDraft does not send the request to unselected AI providers. The selected provider processes data under its own terms and privacy policy.

AI output is a suggestion. Users must review titles, descriptions, prices, categories and condition details before using them.

06

Optional Google Drive import

When the user explicitly imports a supported Google Drive folder, WardrobeDraft uses the supplied folder information to request the selected images from Google. Imported images are then stored in the local extension database. Importing does not start AI analysis.

Publicly shared folders can be accessed without a personal Google sign-in. If private Drive access is added in a future release, this policy will be updated before that feature is enabled.

WardrobeDraft's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Google API data is used only to provide the user-requested Drive import feature and is not used for advertising, profiling or unrelated purposes.

07

Vinted assistance and permissions

Access to a Vinted country domain is optional and requested only when the user starts the Vinted assistant. WardrobeDraft uses that permission to transfer the selected locally prepared photos and listing fields into the visible Vinted selling form.

WardrobeDraft does not read Vinted passwords, authentication cookies or payment details. Standard mode leaves the final publish action to the user. If the user explicitly enables automatic publishing and confirms a queue, the assistant may submit those visible forms and pauses when the site requires manual review or verification.

Vinted is an independent service. Users remain responsible for their listings and for complying with Vinted's rules and applicable law.

08

Account and subscription data

The Free plan can be used without an account. If a user signs in, the WardrobeDraft account service processes the email address, a one-time sign-in code, an opaque session token, subscription status, session timestamps and security/rate-limit information. Product photos, listing drafts and inventory records are not sent to the account service.

The account API is hosted on Cloudflare Workers and uses Cloudflare D1 for account, session and entitlement records. One-time sign-in emails may be delivered through Resend. Technical request data such as IP address, timestamp and request metadata may be processed for delivery, security, rate limiting and abuse prevention.

09

Payments through Stripe

Paid subscriptions are completed on Stripe-hosted pages. Stripe processes payment and billing data under its own privacy policy. WardrobeDraft receives only the identifiers and subscription status required to activate and manage Pro access. The extension and the WardrobeDraft account service do not receive or store full card details.

Billing records may be retained as required by tax, accounting and commercial law. Users can manage or cancel an active subscription through the Stripe customer portal when billing is available.

10

Browser permissions

Storage keeps drafts and settings locally. Downloads creates user-requested CSV or ZIP exports. Side panel displays the WardrobeDraft workspace. Scripting is used only on a Vinted domain for which the user granted optional access. Network permissions allow the explicitly configured account service, local Ollama, selected AI providers, Google Drive import and user-authorized Vinted assistance.

WardrobeDraft does not use permissions to monitor unrelated browsing activity.

11

Retention and deletion

Local drafts and photos remain on the user's device until the user deletes them, clears extension data or uninstalls WardrobeDraft. Completed or skipped local upload and repost queue entries are removed from the active queue.

One-time sign-in codes expire after ten minutes. Account sessions are time-limited. Account and billing records are retained only as long as required to provide the service, resolve disputes, prevent abuse and comply with legal obligations. A user may request account deletion through the contact route listed above.

12

Security

WardrobeDraft uses transport encryption for production account and cloud-provider requests, hashed session tokens on the account service, expiring sign-in codes, rate limits and restricted cross-origin access. No system can guarantee absolute security, so users should protect their browser profile, API keys and marketplace accounts.

13

International processing

Cloudflare, Stripe, Resend and a user-selected AI provider may process data in countries outside the user's place of residence. Their applicable safeguards and privacy notices govern that processing. Users who do not wish to send photos to a cloud AI provider can use the non-AI workflow or local Ollama mode.

14

Your rights

Depending on applicable law, users may have rights to access, correct, delete, restrict or receive personal data, and to object to certain processing or withdraw consent. EU and EEA users may also complain to a competent data protection authority.

Most product content is stored locally and can be deleted directly in the extension. Requests concerning account or subscription data can be submitted through the contact form.

15

Changes to this policy

This policy will be updated when WardrobeDraft's features, providers or processing activities materially change. The effective date at the top identifies the current version. The general website privacy policy is available in German.