Skip to content

Trunk app privacy policy

Last updated 27 August 2026

1. Who we are, and what this policy covers

Nima Project Ltd is the data controller for the Trunk app. We are a company registered in England and Wales, company number 13152926, with a registered office at 3rd Floor, 86-90 Paul Street, London EC2A 4NE. You can reach us at [email protected].

This policy covers the Trunk app. The thenimaproject.com website has its own privacy policy, which describes the cookies and the analytics on the website. The app loads none of that, so if you only use Trunk, the website policy tells you nothing about you. It is still the place we keep the shared parts — your rights, and how to complain — and this page links to it where that is the case.

What you agree to when you use Trunk is set out separately in the Trunk app terms.

Trunk is in closed alpha on Android, so some of what is described here is still moving. When it moves, this page changes with it.

2. The short version

  • There are no accounts. No name, no email address, no sign-up. Your trips, items and photographs live on your phone.
  • Photographs and voice recordings are processed, not stored. They go to our server, straight on to an AI provider, and are discarded in the same request.
  • Two services see technical data about the app: Sentry for crash reports, PostHog for which screens get opened. Both are named below, and neither receives your photographs, your item names or your file paths.
  • There is no advertising, no advertising identifier, and no tracking of you across other apps or websites.
  • Nothing is sold. We have no data to sell and no arrangement to sell it.

The rest of this page is the same thing said precisely, because a summary is not a disclosure.

3. Trunk has no accounts, and your trips stay on your phone

Trunk asks you for no name, no email address, no phone number and no password, because there is nothing to sign in to. We hold no account record about you, because no account exists.

Your trips, your bags, your items, your notes and every weight you correct are written to the app’s own storage on your device. There is no copy on a server for us to read, to lose or to be asked for.

Item photographs are part of that. When you keep an item Trunk has found, the small crop of that item is saved in the app’s own storage on your phone and deleted when you delete the item. It leaves the device for one purpose only: for the moment an outfit is being suggested, so that the suggestion is made from your actual clothes. That request is handled the same way as a scan — described in the next section — and nothing from it is kept on our side.

This cuts both ways and it is worth being plain about it: if you delete the app or lose the phone, your trips go with it, because there was never a second copy.

4. Photographs and voice recordings are processed, not stored

When you photograph your things, the picture goes to our server, straight to the AI provider that recognises what is in it, and is thrown away in the same request. It is never written to our disk, never written to a log, and never attached to an error report. Voice recordings work the same way: we transcribe what you said, add the items, and the recording is gone.

Who the AI provider is. We use OpenRouter, which routes the request to Google Gemini. They receive the photograph or the recording, and what you typed or said alongside it, for one purpose: recognising the items in a picture, and transcribing and translating what you said. We name them here because a privacy policy is where a processor has to be named.

A photograph of your things can contain more than your things. If a person, a document or an address is in the frame, it goes with the picture. That is one more reason the picture is not kept, but it is a reason to photograph what you are packing rather than the room it is in.

Outfit suggestions use the crops already on your phone. They are sent with that request, used to answer it, and discarded with it.

5. Crash reports

When Trunk crashes or hits an error, it sends a crash report to Sentry, a service run by Functional Software Inc. in the United States. We use it to find out that something broke, and where.

A crash report contains:

  • a stack trace — the technical trail of which piece of code failed
  • device metadata, such as the phone model, the operating system version and the version of Trunk you are running

Photographs, item names and file paths are scrubbed before a report is sent. A crash report will not tell us what you are packing.

Sentry is in the United States, so this is a transfer out of the UK and the EEA. Section 11 says what that means.

6. Analytics

Trunk sends product analytics to PostHog, run by PostHog Inc., on their EU region at eu.i.posthog.com. It tells us which parts of the app get used and which get abandoned.

What is sent:

  • screen names — which screen was opened
  • app lifecycle events — the app was opened, the app went to the background

What is not:

  • No screen contents are recorded. Session replay is switched off.
  • Taps are not captured. That is deliberate, and the reason is specific: the label on a tap would be the name of one of your items.
  • Nothing you photograph, say, type or pack.

7. Counting requests — the hashed IP address

Scanning, voice capture and outfit suggestions cost us money for every request, so our server has to count how many requests come from one caller. With no accounts, there is no user to count against.

So we count against the IP address, hashed. The address is turned into a one-way value, and it is that value the counter is kept against. It is pseudonymised technical data, it exists only to enforce the allowance and to stop the service being drained, and it is kept for the quota window and no longer.

We do not use it to build a profile, to work out where you are, or to recognise you across sessions beyond the window it is counting.

8. No advertising, and no tracking

Trunk carries no advertising. It does not read or use an advertising identifier, it does not track you across other apps or websites, and it takes part in no cross-app or cross-site profiling.

We do not sell, rent or share your data with anyone for their own purposes. The only third parties involved are the processors listed in section 10, each doing one job for us.

9. Purchases — there is nothing to buy yet

Trunk takes no payments today. There is no paid plan in the app, no payment we could take, and no payment processor involved.

When paid plans launch, Apple and Google will handle the billing. Trunk will never see your card. A purchase-entitlement service, RevenueCat, will be added at that point — and this page will name it as a processor before it goes live, not after.

10. Who else is involved

These are the only third parties that receive anything from Trunk. Each one processes on our instructions and for the single purpose named.

Third parties that process data for the Trunk app
ServiceWhat it does for usWhere
OpenRouter, routing to Google GeminiRecognising the items in a photograph, and transcribing and translating voice inputUnited States and other countries — see section 11
PostHogProduct analytics — screen names and app lifecycleEuropean Union (eu.i.posthog.com)
Sentry, run by Functional Software Inc.Crash reportingUnited States

Apple, Google and RevenueCat are not on this list, because payments are not live. They go on it when they are.

11. Sending data outside the UK and the EEA

Crash reports leave the UK and the EEA. Sentry is run by Functional Software Inc. and Trunk reports to their United States organisation, which was a deliberate decision across all our apps. If you are in the UK or the EU and Trunk crashes, the report about that crash is sent to the United States.

What is in it is the stack trace and the device metadata described in section 5. Photographs, item names and file paths are scrubbed before it is sent, so the transfer does not carry what you are packing.

Sentry’s data processing addendum, which we are party to, relies first on the EU–US Data Privacy Framework for transfers from Europe to the United States. If that framework is invalidated or does not apply, the addendum incorporates the European Commission’s Standard Contractual Clauses, Module Two, covering a controller sending data to a processor, which is the arrangement here. For data leaving the United Kingdom those clauses apply as amended by the UK Addendum, and for Switzerland the equivalents under the Swiss FADP.

A photograph or a recording sent for recognition is processed outside the United Kingdom and the European Economic Area. OpenRouter operates from the United States and may route a request to facilities in other countries, relying on the European Commission’s adequacy decisions where one covers the destination and on Standard Contractual Clauses where one does not. Google states that paid Gemini traffic may be stored transiently or cached in any country where Google or its agents run facilities.

Two things follow that are worth saying plainly. OpenRouter does not use what you send to train models, and does not keep image or audio files beyond the time needed to route the request, except where it must for abuse detection, security, billing or a legal obligation. Google does not use paid Gemini traffic to improve its products, and does not put it in front of human reviewers; it logs only what it needs to catch prohibited use, and only for a limited period. Neither of those is a promise we make on their behalf, and both are stated in their own terms, which they publish and can change.

PostHog processes in the European Union, so analytics is not a transfer out.

12. How long anything is kept

This covers the categories that belong to the app. The general retention rules are in our main privacy policy, so that there is one source of truth rather than two that can drift apart.

How long each category of Trunk data is kept
WhatHow long
Photographs and voice recordings sent for recognitionNot kept. Discarded inside the same request.
Item crops, trips, bags, items, notes and weightsOn your device, until you delete the item or delete the app. We never hold a copy.
Hashed IP address used to count requestsThe quota window only, then it goes.
Analytics events in PostHogThe retention configured on our PostHog project. We are confirming the exact period and will state it here rather than guess at it.
Crash reports in SentryThe retention configured on our Sentry project. Same again: we will state the period once it is confirmed.

13. Why we are allowed to do this

Under the UK GDPR and the EU GDPR we need a lawful basis for each thing we do. Ours, in plain terms:

  • Scanning and voice capture. We process the photograph or the recording because you asked us to, by pressing the shutter or the microphone. It is necessary to deliver the feature you chose to use.
  • Crash reports and request counting. Our legitimate interest in keeping the app working, finding out what broke, and stopping the service being drained by one caller.
  • Analytics. Our legitimate interest in knowing which screens people actually use, kept deliberately narrow — screen names and lifecycle only, with no screen contents and no taps.

If you would rather not be counted at all, email us and we will tell you how to stop it. We are also working on an in-app switch, the way barm already has one; when it ships, this paragraph changes with it.

14. Your rights

You have the rights the UK GDPR and the EU GDPR give you — access, correction, erasure, restriction, objection and portability — and how to use them is set out in our main privacy policy. We keep them there rather than repeating them here, so there is one set of words to keep correct.

There is one practical wrinkle worth knowing, and it is a consequence of having no accounts. We usually cannot identify you, and we hold almost nothing about you to give back or to erase. Your trips, items and photographs are on your phone: deleting them in the app, or deleting the app, is faster and more complete than asking us, because we have no copy to delete. If you do write to us and we genuinely cannot tell which data is yours, we will say so rather than guess.

If you are unhappy with how we have handled your data you can complain to a supervisory authority — in the United Kingdom the Information Commissioner’s Office, and in the EU the authority in the country you live in. We would rather you told us first, at [email protected], but that is your choice and not a condition.

15. Who can use Trunk

Trunk is not designed for children, and we do not knowingly process the data of a child below the age of digital consent where they live.

Under the GDPR that age is set by each country and it is not the same everywhere: 13 in the United Kingdom, 15 in Greece, 16 in Germany. Other countries set it somewhere between 13 and 16. Trunk ships in eight languages, so this is a real difference rather than a technicality.

If you are younger than the age that applies where you live, use Trunk only with a parent or guardian, who takes responsibility for how the app is used.

16. Changes to this policy

We will update this page when the app changes and when a processor changes its own terms or its position. The current version always lives at this address, with its date at the top.

Where a change materially affects you — a new processor, or a new category of data — we will tell you in the app before it takes effect.

17. How to reach us

Email: [email protected]. A person will answer.

Nima Project Ltd
Company number 13152926, registered in England and Wales
3rd Floor, 86-90 Paul Street, London EC2A 4NE

What you agree to when you use the app is in the Trunk app terms. The Trunk product page is at thenimaproject.com/trunk.