Privacy Policy
Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [LEGAL ENTITY] ("Olfify", "we", "us") collects, uses, and protects your personal data when you use the Olfify mobile app and related websites (together, the "Service"). Olfify is a global fragrance app; we aim to handle your data in line with widely recognized data-protection standards, including the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and Chile's Law No. 21.719.
If you do not agree with this Policy, please do not use the Service.
1. Who is responsible for your data
The data controller is [LEGAL ENTITY], contactable at privacy@olfify.com. For any privacy request, use that address.
2. What data we collect
We collect only what the Service needs to work. Specifically:
Account data (you provide it)
- Email address (required to create an account and for account-related email).
- Username, and an optional display name.
- Password — stored only as a salted hash; we never store or see your plain password.
- If you sign in with a third-party provider (e.g. Google), the basic profile information that provider returns.
Profile data (optional, you provide it)
- Profile picture (avatar), stored as an image file.
- Preferred fragrance genders (a personalization preference).
- Your chosen city. We store a reference to a city from a public geographic database — not your precise GPS location. The city is used to show local weather-based fragrance suggestions. We do not track your device's real-time location.
Content you create in the Service
- Your fragrance collection (fragrances you mark as owned or tried).
- Ratings (personal liking, longevity, projection, versatility) and written reviews.
- Daily-wear logs (what you record wearing, and when).
- Comments and other community contributions.
Data we derive
- A trust score, an "olfactory DNA" profile, reputation/level, and premium status — computed from your activity to power features of the Service.
Technical data (collected automatically)
- Error and crash diagnostics, so we can fix problems (see §4, Sentry).
- Product-usage analytics, to understand how the Service is used (see §4, PostHog). (In the current version the analytics SDK is present but collects little to no event data; this Policy discloses it because it is part of the Service.)
- Your IP address, processed by our content-delivery / security layer to protect the Service (for example, rate-limiting to prevent abuse). We do not use your IP address to build an advertising profile.
- Basic device and app information (e.g. app version, operating system) sent with error reports and API requests.
We do not knowingly collect special-category data (health, precise biometrics, etc.). Please don't put such data in free-text fields like reviews.
3. Why we use your data and our legal bases
| Purpose | Legal basis (GDPR terms) |
|---|---|
| Create and operate your account, authenticate you | Performance of a contract |
| Show and store your collection, ratings, reviews, daily-wear | Performance of a contract |
| Show local weather-based suggestions (chosen city) | Performance of a contract / consent |
| Fix bugs and keep the Service reliable and secure | Legitimate interest |
| Understand and improve how the Service is used | Legitimate interest / consent where required |
| Moderate content and enforce our Terms | Legitimate interest / legal obligation |
| Send account and transactional email | Performance of a contract |
Where we rely on consent, you can withdraw it at any time (this doesn't affect processing already carried out).
4. Who we share data with
We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract, for the purposes above:
- Error & crash reporting — Sentry (captures uncaught errors/crash diagnostics).
- Product analytics — PostHog (in the current version this collects little to no event data — see §2).
- Content delivery, storage & security — Cloudflare (edge/CDN and security, which processes your IP address to protect the Service) and Cloudflare R2 (image storage for avatars and fragrance images).
- Transactional email — Resend (verification and password-reset emails).
- Weather — OpenWeather, queried by your chosen city to power the weather-based fragrance suggestions. We send the city (or its coordinates), not information that identifies you.
- Application hosting — Render (runs the backend that serves the Service).
Authentication runs on our own backend (a self-hosted library, not a third-party login provider), so your credentials are not shared with an external auth service. We do not currently use any payment processor — the premium tier is granted manually today, with no in-app purchases; if paid subscriptions are added, this Policy will be updated to name the store/payment processors involved.
We may also disclose data if required by law, to protect our rights, or as part of a business transfer. Some providers are located outside your country; where we transfer personal data internationally, we rely on appropriate safeguards (such as the provider's standard contractual clauses).
5. How long we keep your data
We keep personal data for as long as your account is active. For accountability and integrity of the community, some records (accounts, reviews, comments) are first soft-deleted (hidden and deactivated) and then permanently removed on a schedule, or sooner on request. When you request deletion of your account, we permanently delete your personal data, except anything we must retain to meet a legal obligation.
6. Your rights
Depending on where you live, you have some or all of these rights:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate data (much of it you can edit in-app).
- Deletion — delete your account and personal data ("right to be forgotten").
- Portability — receive your data in a portable format.
- Objection / restriction — object to or limit certain processing.
- Withdraw consent — where processing is based on consent.
- Complain — to your local data-protection authority.
To exercise any right, contact privacy@olfify.com. We'll respond within the time limits the applicable law requires. We will not discriminate against you for exercising your rights.
7. Security
We use technical and organizational measures to protect your data — including hashed passwords, encrypted transport (HTTPS), access controls, input validation, and rate-limiting of sensitive and expensive operations. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
8. Children
The Service is not directed to children under 18, and is intended for users aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact privacy@olfify.com and we will delete it.
9. Advertising and tracking
The current version of the Service does not show third-party ads and does not track you across other companies' apps or websites for advertising. If this changes, we will update this Policy and, on iOS, request permission through Apple's App Tracking Transparency prompt before any such tracking.
10. Changes to this Policy
We may update this Policy. If we make material changes, we will notify you in-app or by email before they take effect. The "Last updated" date above shows the current version.
11. Contact
Questions or requests: privacy@olfify.com, [LEGAL ENTITY].