Clothesline App, LLC 30714 26th Ave SW, Federal Way, WA 98023, United States
Last updated: 3 August 2026
Effective: 3 August 2026
Clothesline helps a parent work out what their child already has to wear, what they are short of, and what to buy first. To do that it stores information about your children. This page says exactly what, why, who else sees it, and how to get it back or get rid of it.
If anything here is unclear, ask us: privacy@clothesline.app
You must be 18 or older to create a Clothesline account. The account is yours; the children you add are not account holders and cannot sign in.
We collect information about children from you, the parent or guardian — not from the children themselves. By adding a child, you confirm you are their parent or legal guardian and that you consent to us handling their information as described here.
| What | Why we need it |
|---|---|
| Email address | To sign you in and to send password-reset emails |
| Password | Stored only as a scrypt hash with a random per-account salt — we never store or can read your actual password |
| Home postcode (5 digits) | To work out your local climate, so coat and layer counts are right. Optional — you can pick a climate from a list instead, which deletes the postcode |
| Season budget and term-start date | To tell you what is left to spend |
| What | Why we need it |
|---|---|
| First name | So the app can say whose wardrobe it is |
| Pronouns | To write about them correctly, and to search the right section when finding clothes |
| Age (4–14) and school year | To size garments and judge what a school expects |
| Body measurements — height, chest, waist, hip, inseam, shoe size and width | To judge whether a specific garment will fit |
| Fit notes and a brand + size that already fits | The most reliable sizing signal there is |
| Colour preferences and colours to avoid | To recommend things they will actually wear |
| School name | To match your school's dress code — see section 4, this is shared |
| Dress-code handbooks you upload (PDFs, photos, or text you paste) | To read the rules and check clothes against them |
| Photos of garments | To identify what a piece is and judge it against the rules |
| Garment names, colours, sizes, brands, prices and purchase dates | To track coverage and spending |
| Rough counts of clothes you own but haven't photographed | To make the gap maths right |
| Parcel tracking numbers you paste | To tell you where an order is |
| What | Detail |
|---|---|
Session cookie (cl_session) | Set at sign-in. HTTP-only, SameSite=Lax, Secure in production, expires after 30 days |
Active-child cookie (cl_child) | Remembers which child's wardrobe you were looking at. Expires after 1 year. Contains a numeric ID only |
| Browser storage | One localStorage key, holding your closet grid size (auto, large, small or list). Nothing else |
| Usage events | Server-side counts of actions — a handbook was read, a garment was checked, a list item was added. Names, ages, schools and photos are never part of these events |
| IP address | Used in memory only, to rate-limit sign-in and sign-up attempts. It is never written to our database |
We do not use any advertising network, tracking pixel, browser-fingerprinting library, session-replay recording, or payment processor. There is no cookie consent banner because we set no advertising or tracking cookies.
We handle this information to provide the service you asked for: judging clothes against your child's school rules, size and climate, and telling you what to buy.
If you are in the UK or EU, the legal bases we rely on are:
what you signed up for and cannot work without this data.
home postcode. You can withdraw it by deleting a child, clearing the postcode, or deleting your account.
basic usage counts to understand whether the product works.
This is the one thing most likely to surprise you, so it is here rather than buried.
When you add a school by name and we read its dress code, the school's name and the rules we extracted become available to every other Clothesline family at that school. That is deliberate: it means the next parent at your school does not have to upload the handbook again.
What crosses that boundary is only the school's name and the extracted rules. It does not include your name, your email, your child's name, your child's measurements, the original file you uploaded, its filename, or any notes you typed. The handbook text you paste stays private to your account.
A school's rules are recorded once. A later upload for the same school links to the existing entry rather than replacing it, so nobody can overwrite what your school's rules say.
Searching for a school requires being signed in.
We are a small operation and rely on other services. Each one below receives only what is listed.
| Company | What we send them | What for |
|---|---|---|
| Anthropic (Claude API) | Garment photos; handbook files and text; receipt text; and a profile line containing your child's first name, pronouns, height, waist, inseam, fit label, reference brand and size, climate and colour preferences | Reading handbooks, identifying garments, judging them against the rules |
| Fly.io | Everything — they host the application and the database | Hosting, in San Jose, California, USA |
| Resend | Your email address and the password-reset link | Sending password-reset emails |
| SerpApi | Search text that includes the child's gender word and clothing size (e.g. "girls' navy cardigan size 10"). No name, no measurements | Finding real products and prices |
| OpenWeb Ninja | The same search text | Finding real products and prices |
| Ship24 | Parcel tracking numbers you paste | Telling you where an order is |
| PostHog | An account identifier that is a salted SHA-256 hash — never your account number, name or email — plus event names and numeric counts | Understanding whether features are used |
We do not sell your personal information, and we do not share it for advertising or cross-context behavioural advertising. No advertising network receives anything from Clothesline.
Our code contains a dormant affiliate-link feature that would tag outbound retailer links for commission. It is switched off — no publisher account is configured, so links are passed through untouched and no affiliate network receives your clicks. If we ever turn it on, we will update this policy first.
| Data | Kept for |
|---|---|
| Your account, children, garments and handbooks | Until you delete them or delete your account |
| Session (staying signed in) | 30 days, then automatically deleted |
| Password-reset link | 1 hour, single use, then automatically deleted |
| Usage-limit counters | 7 days |
| Encrypted backups | 5 days. Deleted information can persist in backups for up to 5 days after you delete it |
Accounts nobody has opened for 24 months are deleted, after two warning emails sent about two months and one month beforehand. Signing in at any point resets the clock and cancels the warnings. Deleting the account removes everything listed in section 7.
We measure this from your last activity, not from when you signed up — checking in once a season is normal use, not a dormant account.
You can do the first two yourself, from Settings, without asking us:
details, every child, their rule sets, every garment including outgrown ones, your buy list, wardrobe counts, size references, saved outfits, your shopping list, and links to download each handbook you uploaded. Limited to 5 downloads per hour.
garments, buy list, wardrobe counts, size references, saved outfits, shopping list, sessions, reset tokens and usage events — and deletes the handbook files from disk. This cannot be undone. See the note in section 6 about backups.
You can also delete an individual child, which removes that child's rule sets, garments and uploaded handbooks.
To correct information, edit it in Settings. For anything else — including objecting to how we handle something, or asking us to restrict it — contact us at privacy@clothesline.app. We aim to respond within 30 days.
If you are in the UK or EU you have the right to complain to your data protection authority. If you are in California you have rights under the CCPA/CPRA, including the rights to know, delete, correct, and to opt out of sale or sharing — though as stated in section 5, we do not sell or share your information.
Specifically, here is what is in place:
cannot read your password.
Content-Security-Policy, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers.
SameSite=Lax, so it is not readable byscripts and is not sent from other sites.
provider**. We do not add a second layer of encryption on top of that.
it belongs to your household before returning anything.
or sent anywhere. Phone photos normally carry GPS coordinates; we remove them.
daily ceiling on how much analysis it can run.
One honest limitation: if a password-reset email fails to send, the error recorded in our server logs may include your email address. Those logs are held by our hosting provider and are not shared.
No system is perfectly secure, and we will not pretend otherwise.
We set two cookies, both strictly for making the app work:
| Cookie | Purpose | Lifetime |
|---|---|---|
cl_session | Keeps you signed in | 30 days |
cl_child | Remembers which child you were viewing | 1 year |
We use one localStorage entry to remember your preferred closet grid size.
We do not set advertising cookies, we do not track you across other websites, and we do not use fingerprinting. Session replay, autocapture, heatmaps and click tracking are all switched off in our analytics.
Clothesline exists to hold information about children, so this deserves its own section.
no account of their own.
app is directed at a child or invites a child to enter anything.
date of birth, only an age.
judge whether a garment will fit, and they are never shared with other families.
judging a garment (section 5).
Clothesline is hosted in San Jose, California, United States. Our processors (section 5) are US-based.
If you use Clothesline from outside the United States, your information is transferred to and stored in the US, which may not offer the same legal protections as your own country.
If we change this policy in a way that materially affects how we handle your information, we will email the address on your account before the change takes effect. Smaller corrections will be reflected in the "Last updated" date above.
If we discover a breach affecting your personal information, we will notify you by email without undue delay, and within 72 hours of confirming it, telling you what happened, what was affected, and what to do.
Clothesline App, LLC 30714 26th Ave SW, Federal Way, WA 98023, United States privacy@clothesline.app
This page is generated from our published policy. Last updated 3 August 2026.