Privacy Policy
1. Who we are
Scentprint is a mobile application operated by Kossai Ghanmi, an individual based in Cairo, Egypt. Kossai is the data controller for the personal information described in this policy — the person who decides why and how it is processed.
Scentprint is offered to individuals worldwide — wherever you are, you're welcome to use it, and we don't block access by country. Some jurisdictions apply data-localisation or regulatory regimes that are difficult for infrastructure like ours (hosted with Google Cloud/Firebase and Cloudflare) to fully satisfy from outside their borders, so we can't guarantee this policy meets every country's specific domestic requirements. If local law where you are restricts access to services like this one, you're responsible for complying with it.
Contact us about privacy at support@scentprint.app.
This policy explains what we collect, why, who we share it with, how long we keep it, and the rights you have. We've written it in plain language rather than legalese.
2. The short version
- We collect what we need to run a fragrance collection app: your account details, the fragrances you add, how you wear them, and the photos you take of bottles.
- We do not use GPS and do not request location permission. For weather-based Ritual suggestions, the App estimates a city-level position from your phone's time zone setting and sends that estimate to our weather provider. You can switch this off in Profile → Settings → Weather for rituals, and nothing is sent at all — see section 3E.
- The App shows ads, supplied by Google AdMob, to keep it free. Your collection, wear history, journal, mood entries, skin type, birth year, gender and taste profile are never used to target them and are never shared with any advertising network — see section 3F. We do not sell your personal data.
- Photos you scan are sent to a third-party AI service to identify the bottle. The photo itself stays on your device — we do not upload it to our servers. The only images we store in the cloud are the profile picture and profile background you choose to set.
- If the label you scan carries a barcode, the App sends only that barcode number, directly from your phone, to Open Beauty Facts — a free public product database — to look up the brand and product name. See section 3C.
- You can delete your account permanently from inside the App. To request a copy of your data, email us (see section 15).
3. What we collect
A. Account and profile
- Email address and password if you register directly. Passwords are handled by Google Firebase Authentication; we never see or store your password ourselves.
- Google account identifier and email if you sign in with Google.
- Display name, bio, profile picture and profile background, if you add them.
- Birth year and gender, if you provide them when setting up your profile. Both are optional — you can skip that step or leave the fields blank — and you can change or clear them at any time in your profile. We store them with your account so we can tailor fragrance suggestions, which often differ by age group and by how fragrances are traditionally marketed. We do not use your birth year to verify your age (see section 11) and we do not share either field with advertisers.
- An anonymous session identifier. An account is required to use Scentprint. Before you sign in, the App creates a short-lived anonymous session purely so it can obtain a security token for our servers — it holds no personal data and gives no access to the App. Once you sign in, it is replaced by, or linked to, your account.
B. Your fragrance collection and activity
- The fragrances you add, your ratings, purchase dates, personal notes, favourites and how often you use each one.
- Wear sessions — when you wore something, your rating and any note, and the weather conditions at the time.
- Reflections and journal entries — including how a fragrance affected your mood, mood tags, free-text observations, the setting you noted (for example “work” or “home”), and season.
- Onboarding quiz answers — three questions about the styles, occasions and intensity you prefer.
- Skin type and skin chemistry preferences, if you set them. These stay on your device and are not uploaded.
- An inferred taste profile — the App works out which families, notes and contexts you seem to prefer, from what you add and rate.
- The situation behind each of those learning moments — when the App learns something from a wear, a stamp or a suggestion you turned down, it records what you had selected at the time: mood, occasion, focus, the weather reading, the time of day and the season. This is how suggestions can improve for the situation you are actually in rather than only for what you like in general. This log stays on your device — it is not part of the cloud backup of your taste profile — and it is erased when you delete your account.
- Custom blends and collections you create.
A note on mood and skin data. We use these only to personalise fragrance suggestions. We do not use them for any health purpose, we do not build a health profile from them, and we do not share them with anyone for health-related purposes. If you would rather not record mood, simply leave those fields blank — the App works without them.
C. Photos and camera
- When you scan a bottle, the App uses your camera. The camera is only active while you are on the scan screen.
- The photo you capture is: (1) saved on your device, where it stays — it is not uploaded to our cloud storage, and your collection keeps only the file path to it; and (2) sent through our server to a third-party AI service to identify the bottle. We do not keep a copy on our servers once the result comes back; what the AI provider may do with it is described in the callout at the end of section 5.
- Catalogue images are loaded from wherever they live. The product photos you see in the catalogue are not ours and are not copied onto our servers — the App links to them, so your device loads each one directly from the site that hosts it, usually the brand's own. That site sees your IP address and the image requested, exactly as if you had opened the page yourself.
- Profile pictures are different. The profile picture and profile background you set are uploaded to your private folder in our cloud storage, so they appear on any device you sign in on. They are deleted with your account.
- Before a photo leaves your device for AI processing, we strip its embedded metadata, including any location tag the camera may have recorded.
- Barcodes. If the label in view carries a barcode, the App reads it on your device and sends only the barcode number — directly from your phone, not through our servers — to Open Beauty Facts, a free public product database, which returns the brand and product name so the scan can be matched to a fragrance. Nothing else is sent with it: no photo, no account identifier, no part of your collection. Because the request leaves your phone directly, Open Beauty Facts sees your device's IP address, as any website you open would; it does not receive anything that identifies you to it as a Scentprint user beyond that.
- You can also choose a picture from your gallery for your profile. The App uses the Android photo picker, so it only ever receives the specific image you select — it has no access to the rest of your photos.
D. Diagnostics and usage
- Crash reports (Firebase Crashlytics) — device model, operating system version, app version, and the technical state at the moment of a crash.
- Usage events (Firebase Analytics) — for example that a scan was attempted or succeeded, that a blend was created, or that an account deletion was started. These help us find what is broken and what people actually use.
- Notification token (Firebase Cloud Messaging) — so we can send you the reminders you have turned on.
- App integrity check (Google Play Integrity) — confirms requests come from a genuine, untampered copy of the App, to prevent abuse of our servers.
- Identifiers generated by these Google services are tied to your app installation, not to you personally, and are reset when you delete your account.
E. What we do NOT collect
- Precise or GPS location. The App never requests device location permission and never reads GPS, Wi‑Fi, or cell-tower location. For weather-based Ritual suggestions, we estimate a city-level position from your phone's time zone setting (for example, a phone set to the Cairo time zone is treated as roughly Cairo's coordinates) and send that estimate to our weather provider, Open-Meteo, to fetch the current temperature and conditions — not your real-time position. This estimate is not stored on our servers or linked to your account; only the resulting reading (for example “Rainy, 18°C”) is saved with a wear session. You can turn it off in Profile → Settings → Weather for rituals: no position is derived and nothing is sent to the weather provider. Ritual suggestions keep working — they simply follow time of day and season instead of the weather.
- Contacts, calendar, microphone, health or fitness data, or body sensors.
- Phone number, postal address or payment details beyond what Google Play itself handles for the Supporter Pack purchase — we never see your card details.
- Your photo library. We never request broad photo or storage permission.
- Sale of your personal data. We never sell it. We also never share your collection, wear history, journal, mood entries, skin type or taste profile with advertising networks — advertising in the App (section 3F) does not use any of that.
F. Advertising
Scentprint is free, and we use advertising to keep it that way. Ads are supplied by Google AdMob.
- Advertising ID. To request and measure an ad, the Google Mobile Ads SDK may read your device's advertising ID — a resettable identifier Android provides for this purpose — along with coarse technical details such as device type, language and the fact that an ad was shown or tapped.
- What ads are never based on. We do not give advertisers your collection, wear history, journal entries, reflections, mood entries, skin type, birth year, gender or inferred taste profile. None of that leaves our systems for advertising, and none of it is used to target an ad to you.
- Your choice. In the EEA, the UK and anywhere else the law requires it, we show Google's consent form before any ad is requested, and we follow the choice you make there. You can change or withdraw it later from the same screen.
- Resetting or removing the identifier. On Android you can reset your advertising ID, or delete it entirely, in Settings → Privacy → Ads. Deleting it stops personalised advertising on your device across all apps.
- Timing. Advertising is controlled by a server-side switch, so it may be off in the version you are using and switched on later without an update to the App. This policy describes advertising as it works whenever it is on.
- Supporter Pack. Purchasing the Supporter Pack is optional and unlocks cosmetic items; it is not required to use any feature.
4. Why we use it, and our legal basis
If you are in the EEA or UK, the UK/EU General Data Protection Regulation requires us to name a legal basis for each use.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | So you can sign in and keep your collection | Performance of a contract |
| Store your collection, wear history and journal | This is the core function of the App | Performance of a contract |
| Scan and identify bottles using AI | You asked us to identify a bottle | Performance of a contract |
| Look up a scanned barcode with Open Beauty Facts | You asked us to identify what you scanned | Performance of a contract |
| Generate suggestions from your taste profile | To personalise recommendations | Performance of a contract |
| Record mood and skin preferences | To refine suggestions | Consent — these fields are optional and you may leave them blank |
| Record birth year and gender | To tailor fragrance suggestions | Consent — these fields are optional and you may skip or clear them |
| Send notifications you enabled | Reminders you asked for | Consent — withdraw any time in settings |
| Crash reports and usage analytics | To fix bugs and improve the App | Legitimate interests — keeping the App working |
| Integrity checks, rate limits, abuse prevention | To protect our servers and users | Legitimate interests — security |
| Moderation and abuse reports | To keep users safe | Legitimate interests, and legal obligation where applicable |
| Show and measure ads | To keep the App free to use | Consent where required (EEA/UK and similar) — collected through Google's consent form; otherwise legitimate interests in funding the App |
Where we rely on consent, you can withdraw it at any time; that does not affect processing already carried out. Where we rely on legitimate interests, you can object — see section 9.
5. Who we share it with
We do not sell your personal data. We use the following service providers, who process data on our instructions:
| Provider | What it handles | Where |
|---|---|---|
| Google Firebase (Authentication, Firestore, Storage, Analytics, Crashlytics, Cloud Messaging) | Your account, profile, collection sync, your profile picture and background, crash and usage data, notifications | Google data centres, mainly United States |
| Google Gemini (Google AI) | Primary processor for bottle-scan photos and advisor questions — receives the photo (or your question and shelf list) to identify the bottle or generate a response | Google infrastructure |
| Cloudflare (Workers, Workers AI, D1) | Our server layer: Workers AI is the fallback processor for bottle photos and advisor questions when Gemini is unavailable; also serves the fragrance catalogue and holds limited usage records tied to your account identifier | Cloudflare's global network |
| Google Play Integrity | Verifies the App is genuine | |
| Image and catalogue lookup services | Receive only a brand and product name to find a product image or details — never your personal data | Various |
| The websites that host catalogue images (usually the brand's own site) | We do not copy product images onto our servers — we link to them, so your device fetches each image directly from whoever hosts it. Those sites see your device's IP address and which image was requested, as any website you open would. They receive nothing else: no account, no collection, no identifier of ours | Various, worldwide |
| Open Beauty Facts (Open Food Facts association) | Receives only the number of a barcode you scan, sent straight from your phone, and returns the brand and product name. No photo, account identifier or collection data is sent; because the request comes from your device, it sees your IP address | Open Food Facts’ infrastructure, France |
| Open-Meteo | Receives a city-level position estimated from your phone's time zone (not your real location, and not stored by us) to return current weather for Ritual suggestions | Open-Meteo's infrastructure |
| Google AdMob | Serves and measures the ads in the App. Receives your device's advertising ID and basic ad-delivery data — never your collection, journal, mood, skin type or taste profile. Google acts as an independent controller for this data; see Google's policy | Google infrastructure |
We may also disclose data where we are legally required to — for example in response to a valid order from a competent authority — or where necessary to protect the rights and safety of our users or the public. If the App is ever transferred to another owner, your data may transfer with it; we will tell you first.
Important, and worth reading. When you use the scan or advisor features, the content you submit — the photo, and for the advisor, your question and shelf list — is sent to Google Gemini (Google's AI service) to identify the bottle and generate a response. If Gemini is unavailable, the same request is sent instead to Cloudflare Workers AI as a fallback, under Cloudflare's own terms. Either way, your submission is processed by a third-party AI service outside Scentprint to produce the result you see.
We currently use Google's free Gemini API tier (no Google Cloud billing account is attached to our key). Under Google's terms for the free tier, Google may use the content you submit — your bottle photo, or your advisor question — to develop and improve Google's own products and services, including training AI models, and a human reviewer may access it for safety and quality purposes. This is different from Google's paid API tier, where Google commits not to use customer content this way; if we move to a paid tier in future, we will update this paragraph to reflect that stronger commitment.
6. International transfers
We are based in Egypt, and our service providers operate globally. This means your personal data is transferred outside your country — including to the United States and other countries whose data protection laws may differ from your own.
For users in the EEA and UK: Egypt has not been the subject of an adequacy decision. Where we transfer data internationally we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) as incorporated into our providers' terms, together with the technical safeguards described in section 7. You can ask us for more detail using the contact address above.
7. How we protect your data
- All traffic between the App and our servers is encrypted in transit (HTTPS/TLS).
- Data stored with Firebase and Cloudflare is encrypted at rest by those providers.
- Access rules restrict your data so that only your signed-in account can read or write it.
- Requests to our servers require a valid authentication token and are rate-limited.
- Our logging deliberately strips email addresses, keys and tokens before anything is recorded, and this is enforced automatically in our build process.
- Photo metadata is removed before images are sent for AI processing.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the relevant regulator without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify you without undue delay where the breach is likely to result in a high risk to your rights, as the law requires.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, profile (including birth year and gender), collection, wear history, journal | Until you delete your account |
| Bottle photos you take | Kept on your device until you delete the item, the app data or the app itself — we hold no copy |
| Profile picture and background | In our cloud storage until you replace them or delete your account |
| Server-side usage records | Until you delete your account |
| Crash reports | Up to 90 days (Firebase Crashlytics default) |
| Analytics events | Up to 14 months |
| Abuse and moderation reports you file | Retained after account deletion — see below |
| Optional deletion feedback note | Retained after account deletion, without identifying you |
| Deletion audit record | Retained to prove we honoured your request |
9. Deleting your account and your data
You can delete your account at any time: Profile → Privacy & Settings → Delete Account, or from our account deletion page. For your security we may ask you to sign in again first.
What is deleted: your login credentials; your profile and everything under it (collection, blends, journal, wear history, taste profile); and everything in your storage folder (your profile picture and background) together with the usage records on our servers. The photos you took of your own bottles were never on our servers; they go when you delete the app or its data.
What we keep, and why: abuse or moderation reports filed against your account (so safety records survive an abuser deleting their own account), your optional deletion feedback note (kept without identifying you), and a minimal record that the deletion happened. This is permitted under GDPR Article 17(3) and Google Play's deletion policy.
Want a copy first? The App does not currently have a self-service export button. Email us (section 15) before deleting and we will send you a copy of your data.
10. Your rights
Depending on where you live, you may have the right to: access your data; correct it; delete it; export it in a portable format; object to or restrict certain processing; and withdraw consent. You will never be treated differently for exercising a right.
Most of these you can do yourself in the App. For anything else, email support@scentprint.app and we will respond within 30 days.
If you are in the EEA or UK
You have the rights above under the GDPR / UK GDPR, and you may complain to your national data protection authority. We would appreciate the chance to resolve it first.
We have not appointed an EU or UK representative under GDPR / UK GDPR Article 27. Whether our processing is small-scale enough to qualify for the Article 27(2) exemption, or whether a representative should be appointed before an EU/UK launch, is a question we are having reviewed by counsel.
If you are in California or another US state
You may request the categories and specific pieces of personal information we have collected, request deletion or correction, and opt out of “sale or sharing.” We never sell your personal information. Serving personalised ads through Google AdMob may count as “sharing” for cross-context behavioural advertising under the CCPA/CPRA. You can opt out at any time by resetting or deleting your advertising ID in Settings → Privacy → Ads — deleting it stops personalised advertising on your device across every app, and works wherever you are. Separately, where Google's consent framework applies to you, Profile → Settings → Ad privacy choices reopens Google's form so you can change the answer you gave it; that screen only appears for users Google's framework covers, which is why it is not the mechanism we rely on here. You may use an authorised agent. We will not discriminate against you — for example by denying features or charging a different price — for exercising any of these rights. Contact us at the address above.
If you are in Washington State, Nevada or Connecticut
Some of what you can optionally record in the App — how a fragrance affected your mood, and your skin type — may fall within the broad definition of “consumer health data” under the Washington My Health My Data Act and similar laws. See our separate Consumer Health Data Privacy Notice, which explains what we collect, how it is used, and how to exercise your rights. Requests under those laws run on a statutory 45-day clock (extendable once by a further 45 days) rather than the 30 days below.
If you are in Egypt
You have rights of access, correction, withdrawal of consent and deletion under Egypt's Personal Data Protection Law No. 151 of 2020 and its Executive Regulations, exercisable through the contact address above. You may also complain to the Personal Data Protection Centre.
Other countries
If you are in Brazil, Canada, Saudi Arabia, the UAE or elsewhere, you have equivalent rights of access, correction and deletion under your local law, exercisable through the same contact address. Users in Quebec may contact our privacy officer at the address in section 1.
11. Children
Scentprint is for users aged 16 and over, worldwide. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe someone under 16 has given us personal data, contact us at support@scentprint.app and we will delete it.
12. Automated decisions
The App generates fragrance suggestions automatically from your collection and preferences. These are recommendations only — they have no legal or similarly significant effect on you, and there is no automated decision-making of the kind that would require additional safeguards under GDPR Article 22.
13. Do Not Track and tracking signals
Scentprint is a mobile app: it has no browser, sets no cookies and does no cross-site tracking, so browser signals such as Do Not Track and Global Privacy Control never reach us and there is nothing for us to apply them to. We never sell personal information. Where the App serves personalised ads, you can opt out by resetting or deleting your advertising ID in Settings → Privacy → Ads — deleting it stops personalised advertising across every app on your device — and, where Google's consent form applies to you, by changing your answer in Profile → Settings → Ad privacy choices.
13a. This website, and the waitlist
Sections 1–13 describe the Scentprint mobile app. This section covers scentprint.app, the website you are reading now, which is a separate thing.
The website sets no cookies. None — not analytics, not advertising, not "essential" ones. It loads no third-party scripts, no third-party fonts and no tracking pixels; the fonts are served from our own domain. There is no consent banner because there is nothing to consent to. If that ever changes, this section changes first and a banner appears with it.
What the waitlist collects. If you choose to join the waitlist, we store:
- the email address you type;
- the date and time you submitted it;
- your browser's preferred-language header (e.g.
en-GB), so a launch email can be in a language you read; - a record of your consent — the exact wording you agreed to and its version — because we have to be able to show that you agreed, not just claim it.
Why, and our legal basis. Consent (GDPR Art. 6(1)(a)), given by ticking the box. Nothing is pre-ticked and the form will not submit without it.
What we will send. One email, when Scentprint becomes available on Google Play. No newsletter, no offers, no "we thought you'd like". If we ever wanted to send anything else, we would ask you again first.
We do not keep your IP address. To stop one person or a script flooding the form, we store a short one-way fingerprint derived from the connection — a hash that cannot be reversed into an address — together with a count and a timestamp. It is deleted automatically as the hour rolls over. Your actual IP is never written down.
Who else sees it. Nobody. The list lives in our own database at Cloudflare, our hosting provider, who process it on our behalf and do not use it. It is not shared, sold, rented, or uploaded to any mailing or advertising service.
How long we keep it. Until the launch email has been sent, or until you ask us to remove you — whichever comes first. After launch the list is deleted.
Getting off the list. Email support@scentprint.app and say "remove me from the waitlist". We delete the row, and you will not be asked why. You have the same rights over this data as in section 10, and you do not need an account to use them.
Children. The waitlist is not for under-16s. Please do not submit an address if you are younger.
14. Changes to this policy
If we make a material change, we will update the date above and tell you in the App or by email before it takes effect. Please check back from time to time.
15. Contact us
- Privacy: support@scentprint.app
- Support: support@scentprint.app
- Based in: Kossai Ghanmi, Cairo, Egypt
We aim to respond within 30 days.