Privacy
Short version: we store what you tell us about your taste, we use it to make your recommendations, and you can take it or delete it whenever you like. We also count how the product is used, in a way that does not record what you type — and you can switch that off.
If you never sign in
Your answers are not saved to our servers. The guest flow keeps them in your own browser’s local storage. Your ratings are sent to our server only for as long as it takes to score them and write the explanations, and they are not stored afterwards.
Usage analytics are the exception, and we would rather say so plainly than bury it: unless you turn them off, we record that a visit happened and which screens it reached. That record contains none of your answers, none of the ratings you gave as a guest, and nothing you typed. The exact list is below.
If you create an account
We store:
- Your email address, so we can send sign-in links.
- Which fragrances you love, like, own, want or have ruled out, and why.
- Your stated preferences, including the optional smell self-screen.
- Recommendations we generated for you, and the feedback you gave afterwards.
Access is enforced in the database itself with row-level security, not just in application code. No other user can read your rows.
Usage analytics
We measure how the product is used so we can tell which parts work. It is our own first-party system — no Google Analytics, no advertising pixel, no third-party script of any kind. Nothing leaves our own database.
What we record
- Which events happened — a page was viewed, an onboarding step was completed, a recommendation was saved or rejected, an error occurred. Each is a fixed name from a list that lives in our source code, never free text.
- Which fragrance an action referred to, by its catalogue id.
- A random session id and browser id. Opaque, randomly generated, not derived from anything about you.
- Coarse device information— mobile, tablet or desktop; operating system and browser family; a viewport size bucket; your language (“en”, not “en-GB”).
- Where the visit came from — the domain of the referring site, and any campaign tags in the link you followed.
- Timings — how long a step took, how long a page took to load, how long an AI call took.
What we never record
- Your IP address. It is hashed with a secret that exists only on the server and never reaches the database, then truncated. The raw address is never written anywhere.
- What you type. A search records only how long the query was, as a bucket, and how many results it found — never the query itself. A note records only that a note exists.
- Your location. Not city, not region, not country. We do not collect it at all.
- Passwords, tokens, API keys, or anything from the sign-in form.
- Your full referring URL, which can carry someone else’s search terms.
- Anything used to fingerprint your device — no canvas, no font list, no exact screen size, no user-agent string.
How long we keep it
- Individual events: 180 days, then deleted automatically.
- Session records: 400 days.
- Daily totals — counts with nobody in them — are kept indefinitely, because “412 sessions on Tuesday” is not information about a person.
- Records of what our own administrators did: 730 days. That is a security log and is deliberately kept longer.
Deleting your account deletes your analytics too — those rows are tied to your account in the database and go with it, along with your profile, ratings, history and feedback.
If your browser sends a Do Not Track or Global Privacy Control signal, we treat that as an opt-out and never ask again.
Usage analytics
We count how the product is used — which screens people reach, how far the onboarding gets, whether a recommendation was saved. We never record what you type, your IP address, or your location. You can turn it off and it genuinely stops.
Turning this off also deletes the usage history already linked to your account. It does not affect your ratings, your collection or your recommendations.
AI processing
Your recommendations are chosen by our own scoring engine. We then send the selected fragrances and a summary of your preferences to Google’s Gemini API to write the explanations. We do not send your email address or any account identifier. If that call fails, you still get your five — written by the engine instead.
We record how long each call took, how many tokens it used and whether it failed. That record holds no part of your data — only the measurements.
Who else processes your data
We use three third parties, and no others:
- Vercel — hosting. Sees your requests and IP address, as any host does.
- Supabase — authentication and database. Holds your email, password hash and everything listed above. Your browser talks to it directly when you sign in.
- Google (Gemini API) — writes the explanation text only, from the data described above.
Product photographs are loaded directly from brand and retailer domains, so your browser contacts those sites when a recommendation shows a photo. They are not trackers we placed, but they are third-party connections and you should know about them.
Product images
Product photographs are discovered from official brand and authorised retailer sites and shown for identification, with their source recorded and attributed. We do not claim ownership of them. If you are a rights holder and want an image removed, contact us and we will remove it.
Your controls
From Settings you can download everything we hold about you as a single file, or delete your account. A deletion is immediate and permanent — it removes your profile, ratings, history, feedback and analytics. There is no soft-delete and no recovery window.
The analytics switch above works on its own, without deleting anything else. Turning it off stops collection immediately and deletes the usage history already linked to your account.
What we do not do
- We do not sell your data.
- We do not take commission on anything we recommend.
- We do not run advertising or third-party trackers.
- We do not build profiles for anyone outside ScentyAI.