Your Fragrance Companion

Privacy Policy

Last updated: July 28, 2026

1. Who we are

Scentprint is a mobile application operated by Kossai Ghanmi, an individual based in Cairo, Egypt. Kossai is the data controller for the personal information described in this policy — the person who decides why and how it is processed.

Scentprint is offered to individuals worldwide — wherever you are, you're welcome to use it, and we don't block access by country. Some jurisdictions apply data-localisation or regulatory regimes that are difficult for infrastructure like ours (hosted with Google Cloud/Firebase and Cloudflare) to fully satisfy from outside their borders, so we can't guarantee this policy meets every country's specific domestic requirements. If local law where you are restricts access to services like this one, you're responsible for complying with it.

Contact us about privacy at support@scentprint.app.

This policy explains what we collect, why, who we share it with, how long we keep it, and the rights you have. We've written it in plain language rather than legalese.

2. The short version

3. What we collect

A. Account and profile

B. Your fragrance collection and activity

A note on mood and skin data. We use these only to personalise fragrance suggestions. We do not use them for any health purpose, we do not build a health profile from them, and we do not share them with anyone for health-related purposes. If you would rather not record mood, simply leave those fields blank — the App works without them.

C. Photos and camera

D. Diagnostics and usage

E. What we do NOT collect

F. Advertising

Scentprint is free, and we use advertising to keep it that way. Ads are supplied by Google AdMob.

4. Why we use it, and our legal basis

If you are in the EEA or UK, the UK/EU General Data Protection Regulation requires us to name a legal basis for each use.

What we doWhyLegal basis
Create and run your accountSo you can sign in and keep your collectionPerformance of a contract
Store your collection, wear history and journalThis is the core function of the AppPerformance of a contract
Scan and identify bottles using AIYou asked us to identify a bottlePerformance of a contract
Look up a scanned barcode with Open Beauty FactsYou asked us to identify what you scannedPerformance of a contract
Generate suggestions from your taste profileTo personalise recommendationsPerformance of a contract
Record mood and skin preferencesTo refine suggestionsConsent — these fields are optional and you may leave them blank
Record birth year and genderTo tailor fragrance suggestionsConsent — these fields are optional and you may skip or clear them
Send notifications you enabledReminders you asked forConsent — withdraw any time in settings
Crash reports and usage analyticsTo fix bugs and improve the AppLegitimate interests — keeping the App working
Integrity checks, rate limits, abuse preventionTo protect our servers and usersLegitimate interests — security
Moderation and abuse reportsTo keep users safeLegitimate interests, and legal obligation where applicable
Show and measure adsTo keep the App free to useConsent where required (EEA/UK and similar) — collected through Google's consent form; otherwise legitimate interests in funding the App

Where we rely on consent, you can withdraw it at any time; that does not affect processing already carried out. Where we rely on legitimate interests, you can object — see section 9.

5. Who we share it with

We do not sell your personal data. We use the following service providers, who process data on our instructions:

ProviderWhat it handlesWhere
Google Firebase (Authentication, Firestore, Storage, Analytics, Crashlytics, Cloud Messaging)Your account, profile, collection sync, your profile picture and background, crash and usage data, notificationsGoogle data centres, mainly United States
Google Gemini (Google AI)Primary processor for bottle-scan photos and advisor questions — receives the photo (or your question and shelf list) to identify the bottle or generate a responseGoogle infrastructure
Cloudflare (Workers, Workers AI, D1)Our server layer: Workers AI is the fallback processor for bottle photos and advisor questions when Gemini is unavailable; also serves the fragrance catalogue and holds limited usage records tied to your account identifierCloudflare's global network
Google Play IntegrityVerifies the App is genuineGoogle
Image and catalogue lookup servicesReceive only a brand and product name to find a product image or details — never your personal dataVarious
The websites that host catalogue images (usually the brand's own site)We do not copy product images onto our servers — we link to them, so your device fetches each image directly from whoever hosts it. Those sites see your device's IP address and which image was requested, as any website you open would. They receive nothing else: no account, no collection, no identifier of oursVarious, worldwide
Open Beauty Facts (Open Food Facts association)Receives only the number of a barcode you scan, sent straight from your phone, and returns the brand and product name. No photo, account identifier or collection data is sent; because the request comes from your device, it sees your IP addressOpen Food Facts’ infrastructure, France
Open-MeteoReceives a city-level position estimated from your phone's time zone (not your real location, and not stored by us) to return current weather for Ritual suggestionsOpen-Meteo's infrastructure
Google AdMobServes and measures the ads in the App. Receives your device's advertising ID and basic ad-delivery data — never your collection, journal, mood, skin type or taste profile. Google acts as an independent controller for this data; see Google's policyGoogle infrastructure

We may also disclose data where we are legally required to — for example in response to a valid order from a competent authority — or where necessary to protect the rights and safety of our users or the public. If the App is ever transferred to another owner, your data may transfer with it; we will tell you first.

Important, and worth reading. When you use the scan or advisor features, the content you submit — the photo, and for the advisor, your question and shelf list — is sent to Google Gemini (Google's AI service) to identify the bottle and generate a response. If Gemini is unavailable, the same request is sent instead to Cloudflare Workers AI as a fallback, under Cloudflare's own terms. Either way, your submission is processed by a third-party AI service outside Scentprint to produce the result you see.

We currently use Google's free Gemini API tier (no Google Cloud billing account is attached to our key). Under Google's terms for the free tier, Google may use the content you submit — your bottle photo, or your advisor question — to develop and improve Google's own products and services, including training AI models, and a human reviewer may access it for safety and quality purposes. This is different from Google's paid API tier, where Google commits not to use customer content this way; if we move to a paid tier in future, we will update this paragraph to reflect that stronger commitment.

6. International transfers

We are based in Egypt, and our service providers operate globally. This means your personal data is transferred outside your country — including to the United States and other countries whose data protection laws may differ from your own.

For users in the EEA and UK: Egypt has not been the subject of an adequacy decision. Where we transfer data internationally we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) as incorporated into our providers' terms, together with the technical safeguards described in section 7. You can ask us for more detail using the contact address above.

7. How we protect your data

No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the relevant regulator without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify you without undue delay where the breach is likely to result in a high risk to your rights, as the law requires.

8. How long we keep it

DataRetention
Account, profile (including birth year and gender), collection, wear history, journalUntil you delete your account
Bottle photos you takeKept on your device until you delete the item, the app data or the app itself — we hold no copy
Profile picture and backgroundIn our cloud storage until you replace them or delete your account
Server-side usage recordsUntil you delete your account
Crash reportsUp to 90 days (Firebase Crashlytics default)
Analytics eventsUp to 14 months
Abuse and moderation reports you fileRetained after account deletion — see below
Optional deletion feedback noteRetained after account deletion, without identifying you
Deletion audit recordRetained to prove we honoured your request

9. Deleting your account and your data

You can delete your account at any time: Profile → Privacy & Settings → Delete Account, or from our account deletion page. For your security we may ask you to sign in again first.

What is deleted: your login credentials; your profile and everything under it (collection, blends, journal, wear history, taste profile); and everything in your storage folder (your profile picture and background) together with the usage records on our servers. The photos you took of your own bottles were never on our servers; they go when you delete the app or its data.

What we keep, and why: abuse or moderation reports filed against your account (so safety records survive an abuser deleting their own account), your optional deletion feedback note (kept without identifying you), and a minimal record that the deletion happened. This is permitted under GDPR Article 17(3) and Google Play's deletion policy.

Want a copy first? The App does not currently have a self-service export button. Email us (section 15) before deleting and we will send you a copy of your data.

10. Your rights

Depending on where you live, you may have the right to: access your data; correct it; delete it; export it in a portable format; object to or restrict certain processing; and withdraw consent. You will never be treated differently for exercising a right.

Most of these you can do yourself in the App. For anything else, email support@scentprint.app and we will respond within 30 days.

If you are in the EEA or UK

You have the rights above under the GDPR / UK GDPR, and you may complain to your national data protection authority. We would appreciate the chance to resolve it first.

We have not appointed an EU or UK representative under GDPR / UK GDPR Article 27. Whether our processing is small-scale enough to qualify for the Article 27(2) exemption, or whether a representative should be appointed before an EU/UK launch, is a question we are having reviewed by counsel.

If you are in California or another US state

You may request the categories and specific pieces of personal information we have collected, request deletion or correction, and opt out of “sale or sharing.” We never sell your personal information. Serving personalised ads through Google AdMob may count as “sharing” for cross-context behavioural advertising under the CCPA/CPRA. You can opt out at any time by resetting or deleting your advertising ID in Settings → Privacy → Ads — deleting it stops personalised advertising on your device across every app, and works wherever you are. Separately, where Google's consent framework applies to you, Profile → Settings → Ad privacy choices reopens Google's form so you can change the answer you gave it; that screen only appears for users Google's framework covers, which is why it is not the mechanism we rely on here. You may use an authorised agent. We will not discriminate against you — for example by denying features or charging a different price — for exercising any of these rights. Contact us at the address above.

If you are in Washington State, Nevada or Connecticut

Some of what you can optionally record in the App — how a fragrance affected your mood, and your skin type — may fall within the broad definition of “consumer health data” under the Washington My Health My Data Act and similar laws. See our separate Consumer Health Data Privacy Notice, which explains what we collect, how it is used, and how to exercise your rights. Requests under those laws run on a statutory 45-day clock (extendable once by a further 45 days) rather than the 30 days below.

If you are in Egypt

You have rights of access, correction, withdrawal of consent and deletion under Egypt's Personal Data Protection Law No. 151 of 2020 and its Executive Regulations, exercisable through the contact address above. You may also complain to the Personal Data Protection Centre.

Other countries

If you are in Brazil, Canada, Saudi Arabia, the UAE or elsewhere, you have equivalent rights of access, correction and deletion under your local law, exercisable through the same contact address. Users in Quebec may contact our privacy officer at the address in section 1.

11. Children

Scentprint is for users aged 16 and over, worldwide. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe someone under 16 has given us personal data, contact us at support@scentprint.app and we will delete it.

12. Automated decisions

The App generates fragrance suggestions automatically from your collection and preferences. These are recommendations only — they have no legal or similarly significant effect on you, and there is no automated decision-making of the kind that would require additional safeguards under GDPR Article 22.

13. Do Not Track and tracking signals

Scentprint is a mobile app: it has no browser, sets no cookies and does no cross-site tracking, so browser signals such as Do Not Track and Global Privacy Control never reach us and there is nothing for us to apply them to. We never sell personal information. Where the App serves personalised ads, you can opt out by resetting or deleting your advertising ID in Settings → Privacy → Ads — deleting it stops personalised advertising across every app on your device — and, where Google's consent form applies to you, by changing your answer in Profile → Settings → Ad privacy choices.

13a. This website, and the waitlist

Sections 1–13 describe the Scentprint mobile app. This section covers scentprint.app, the website you are reading now, which is a separate thing.

The website sets no cookies. None — not analytics, not advertising, not "essential" ones. It loads no third-party scripts, no third-party fonts and no tracking pixels; the fonts are served from our own domain. There is no consent banner because there is nothing to consent to. If that ever changes, this section changes first and a banner appears with it.

What the waitlist collects. If you choose to join the waitlist, we store:

Why, and our legal basis. Consent (GDPR Art. 6(1)(a)), given by ticking the box. Nothing is pre-ticked and the form will not submit without it.

What we will send. One email, when Scentprint becomes available on Google Play. No newsletter, no offers, no "we thought you'd like". If we ever wanted to send anything else, we would ask you again first.

We do not keep your IP address. To stop one person or a script flooding the form, we store a short one-way fingerprint derived from the connection — a hash that cannot be reversed into an address — together with a count and a timestamp. It is deleted automatically as the hour rolls over. Your actual IP is never written down.

Who else sees it. Nobody. The list lives in our own database at Cloudflare, our hosting provider, who process it on our behalf and do not use it. It is not shared, sold, rented, or uploaded to any mailing or advertising service.

How long we keep it. Until the launch email has been sent, or until you ask us to remove you — whichever comes first. After launch the list is deleted.

Getting off the list. Email support@scentprint.app and say "remove me from the waitlist". We delete the row, and you will not be asked why. You have the same rights over this data as in section 10, and you do not need an account to use them.

Children. The waitlist is not for under-16s. Please do not submit an address if you are younger.

14. Changes to this policy

If we make a material change, we will update the date above and tell you in the App or by email before it takes effect. Please check back from time to time.

15. Contact us

We aim to respond within 30 days.