01

Who we are and what this covers

Fraghab is operated by FRAGHAB LLC, a Michigan limited liability company. For users in the European Economic Area, the United Kingdom, and Switzerland, FRAGHAB LLC is the data controller for the personal data described here.

This policy covers the Fraghab website at fraghab.com, the Fraghab iOS and Android apps, the House API, and the emails we send. The Fraghab browser extension is covered by its own extension privacy policy, because it handles data locally in your browser.

This policy is part of our Terms of Service. Reach us about anything on this page at [email protected].

02

What we collect

Fraghab collects only the data necessary to provide the service. This includes:

  • Account information: email address, username, and password (stored as a secure hash, never in plain text). If you sign in with Google or Apple, we receive your email address and a stable account identifier from that provider instead of a password — plus your name from Google. Apple may forward a private-relay address that hides your real email; we treat it as your email address
  • Contact messages: your name, email address, selected topic, and the message you choose to send through our contact form
  • Profile data: optional avatar image and display preferences
  • Optional private details, only if you choose to add them in profile settings: your birth year (we store the year, never a computed age) and your gender identity, which includes a "prefer not to say" option. They are used for one thing — tuning suggestions toward collectors near each other's age and of each other's gender identity, and only when both people have disclosed the detail in question; choosing "prefer not to say" is saved as your answer but counts as not disclosing, so it is matched with no one. This tuning runs in both directions: your details tune your own suggestions and, only while your scent passport is public, help tune other members' suggestions in the same way. Neither detail is ever shown on your profile, passport, reviews, community posts, or anywhere another member can see, and you can clear either at any time
  • Collection data: fragrance names, brands, notes, accords, ratings, bottle sizes, and other metadata you enter
  • Wearing logs: dates, fragrances worn, occasion, weather conditions, and personal ratings
  • Location, only if you choose to set it: on the web you may allow the browser's location prompt, and the coordinates it reports are saved to your account; in the mobile apps you type a city and that city's approximate, city-level coordinates are saved — the apps never read your device's location. Your saved location weights suggestions by your local weather, measures the conditions you record on a wear test (the reading is reduced to a coarse temperature and condition band before it is stored — the coordinates and exact figures are not kept), and places your pin on the community world map
  • Connected calendars (optional): if you connect Google Calendar, a personal ICS feed URL, or an uploaded .ics file, the event titles and start and end times within the date range the app needs, plus the access credentials or file contents required to read them (stored securely server-side, never shown to you or written to logs)
  • Wishlist items: target fragrances, priority levels, and budget notes
  • Layering combos: fragrance pairings, spray zone maps, and combo ratings
  • Community content: Group Therapy posts, polls, poll votes, reviews, reactions, and comments
  • Marketplace data: your listings with their photos, size variants, quantities, prices and shipping fee, your storefront settings, your cart, offers you send or receive, trade proposals with the bottles and decants each side puts up and any cash added, order records with the prices agreed and the paid, shipped and received flags the two of you set yourselves, any carrier and tracking number a seller entered, watchlist and wanted-board entries, seller and buyer reviews, and reports you file or that are filed about you
  • A delivery address, if you save one at checkout: a name, street lines, city, region, postal code and country. One reusable copy on your account, plus a snapshot on each order so a later edit never rewrites where an already-shipped parcel went. The counterparty on that order can read it, because they cannot post to you without it
  • Direct messages: private messages and shared images between users
  • Follow relationships: which users you follow and who follows you
  • Product analytics: a fixed set of five app events (app opened, signed in, collection viewed, suggestion requested, wearing logged) recorded against your account, with counts and short labels only, never free text
  • Email link clicks: when we email you about your account or these policies and you follow a link in it, we record that you followed it, when you first did, and which of the linked pages it was. We do not track whether you opened the email, and we place no tracking image in any message we send
  • Crash diagnostics: if the mobile app crashes, the error, your device model, OS version, and the app release, identified by your numeric account id only
  • Session and device details: the browser or app identifier of each signed-in session, the app version and platform, and your device's time zone name so "today" is correct for you
  • Limited security data: the network address a failed sign-in attempt came from, kept briefly to rate-limit password guessing

What we do not collect. We do not collect your location unless you choose to set it as described above. We do not collect your contacts, photos beyond what you upload, biometric data, payment card or bank details, government identifiers, or any advertising identifier. We do not ask for special category or sensitive personal data, and you should not put it into a post, a listing, or a note. The optional birth year and gender identity described above are profile details you volunteer by an explicit choice in settings — never inferred, never required, never a condition of any feature — and you may leave them unset, answer with “prefer not to say,” or clear either at any time.

Scanning a bottle does not send us the photo. When you add a bottle by photographing its label, the text is read out of the picture on your own device — in your browser on the web, and by the phone’s own text recognition on iPhone and Android. Only the words recovered from the label are sent to us, and only to look up matching entries in the fragrance database. The photo is never uploaded, no image is stored, and the text read off the label is used for that one lookup and not kept.

Marketplace payment details are never collected. A delivery address is, if you save one. Fraghab does not process payments for the marketplace, so we never receive or store a card number, a bank account, a payment-app handle, or any payment credential, and we run no identity or bank verification on a seller. That has always been true and still is.

A delivery address is different, and an earlier version of this policy described it wrongly. It said no order record holds an address. That stopped being true when checkout began collecting one, and we are correcting it here rather than leaving it to be discovered. What actually happens: if you save a delivery address at checkout, we store one reusable copy of it on your account — a name, street lines, city, region, postal code and country — and we copy it onto each order you place, so that editing it later never rewrites where a parcel that already shipped was sent. A trade snapshots BOTH members’ addresses on the one order, because a trade ships in both directions. The seller can read the address on their own order, because they cannot post you anything without it. You can change the saved copy from your marketplace dashboard at any time, and deleting your account deletes it — though not the copy already on a counterparty’s order, which is theirs, and not anything you typed into a message thread yourself. If a real name or a payment detail needs to change hands, you still send that directly to the other user, usually in your message thread, and "Community content" explains what that means for you.

03

How we use your data

Your data is used to operate and improve the Fraghab experience:

  • Display your collection, wearings, wishlist, and combos within the app
  • Generate personalized insights: most worn fragrances, seasonal trends, weather-based suggestions
  • Read your connected calendar (read-only) to show today's events while you log a wearing, and to pre-fill your Weekly Planner with a suggested occasion for each day
  • Power community features, showing your posts, polls, and reviews to other users
  • Run the marketplace: publishing your listings and storefront, keeping cart and order records, and showing seller reviews
  • Deliver direct messages between you and other users
  • Send transactional emails: account verification, password resets, and invite notifications
  • Respond to contact messages you send us
  • Understand which features are used, and diagnose crashes, so the apps get better. See "The iOS & Android apps" below for exactly what is recorded
  • Produce aggregate, de-identified statistics about how members engage with a fragrance brand, and provide those statistics to that brand when we have verified it owns the brand, so it can keep its catalog accurate. What a house does and does not receive is set out in full in "Statistics we share with verified houses"
  • Keep the service safe: preventing abuse, detecting fraud and scams, enforcing our terms, and counting a failed sign-in attempt against the network address it came from for up to fifteen minutes, purely to rate-limit guessing
  • Comply with law, and respond to a valid legal request

Fraghab does not use your personal data for advertising, does not sell it, and does not use it to train or develop its own AI or machine learning models. We do not use it for profiling that produces legal or similarly significant effects on you.

04

Our legal bases

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on these legal bases under Article 6 of the GDPR:

  • Performance of a contract, Article 6(1)(b): creating and running your account, storing and displaying your collection, delivering messages, publishing your listings, and sending transactional email. Without this we cannot provide the service
  • Consent, Article 6(1)(a): connecting a calendar, uploading an avatar or an .ics file, and receiving optional product announcement emails or a research survey. You can withdraw consent at any time, which does not affect processing already carried out
  • Legitimate interests, Article 6(1)(f): keeping the service secure, preventing fraud and abuse, rate-limiting sign-in attempts, diagnosing crashes, understanding which features are used so we can improve them, producing the aggregate, de-identified brand statistics described in "Statistics we share with verified houses" so that the catalog members rely on is accurate, and enforcing our terms. We balance these against your rights, and you may object as described in "Your rights"
  • Legal obligation, Article 6(1)(c): responding to a lawful request, and keeping records we are required to keep

Where we rely on consent and you withdraw it, we stop that processing and delete the data it depended on, for example the stored calendar credentials when you disconnect a calendar.

05

Data storage & security

Your data is stored in a managed database hosted by Turso, on servers located in the United States. All connections between the app and the database are encrypted. Passwords are hashed using industry-standard algorithms and are never stored or transmitted in plain text.

Access to production data is limited to the people who need it to run the service, and every query that touches your records is scoped to your authenticated account. Calendar credentials are held server-side only, are never sent to your browser, and are never written to logs.

We implement reasonable technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

06

Data sharing

Fraghab does not sell, rent, or trade your personal data to third parties. Period. We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding twelve months.

Your data may be shared only in these limited circumstances:

  • Infrastructure providers: the services necessary to host and operate Fraghab, listed in "Third-party services" below. They act as our processors, handle data only on our instructions, and are bound by contract
  • Anthropic: when you request an AI-powered suggestion, the information needed to produce that suggestion, such as your request and relevant collection or planning context, is sent to Anthropic's API for processing. We use Anthropic's commercial API, which does not use inputs or outputs for model training by default
  • OpenAI, for subtitles you ask to generate: when you choose Generate from video in the Overlay Studio, the sound of the part of your clip you trimmed to is sent, in short segments, to OpenAI's API to be transcribed, and the timed words come back to you as captions to review. The picture never leaves your device, nothing is sent unless you start it, and we do not keep the sound or the transcript on our servers; the captions are saved only in your studio, once you accept them. For this OpenAI acts as our processor, and its API does not use that sound for model training by default
  • OpenAI, if you connect the ChatGPT app: the collection rows, catalog search results, and write confirmations that the assistant asked for travel to OpenAI, which holds them as its own controller rather than as our processor. This happens only after you approve it on a Fraghab consent screen, and "The ChatGPT app & connected assistants" below lists exactly what leaves and how to revoke it
  • Crash reporting: if the mobile app crashes, the diagnostic report goes to Sentry, our error-monitoring provider, carrying your numeric account id but never your username, email, or any content you wrote
  • Our email provider, for moderation alerts: when you report another user's content, the report — your username, the reason, anything you wrote, and what or whom it is about — is delivered to our own moderation address through the transactional email provider listed below, so it can be reviewed inside the 24-hour window the Terms commit to. It goes to us, never to the person reported, and "Community content" below describes the flow in full
  • Other users: the parts of your account you choose to publish or send, described in "What is public on Fraghab" and "Community content" below
  • A buyer or seller you transact with: your username, the order details, and whatever you choose to send them yourself, such as a delivery address, a real name, or a payment handle. They receive that from you directly, not from us, and once they have it they hold it independently. They are not our processor, we cannot control, retrieve, correct, or delete what they hold, and a request to us cannot reach it
  • Verified fragrance houses: aggregate, de-identified statistics about that house's own brand. These carry no identifier and no individual record, they cannot be narrowed down to one member, and the house is contractually barred from trying. "Statistics we share with verified houses" below sets out exactly what a house does and does not receive
  • Legal requirements: if required by law, regulation, subpoena, or other valid legal process, or where we believe in good faith that disclosure is necessary to protect the rights, safety, or property of a user, of the public, or of Fraghab. Where we may lawfully tell you, we will
  • A business transfer: if Fraghab is involved in a merger, acquisition, financing, reorganization, or sale of assets, your data may transfer as part of that transaction. The recipient stays bound by this policy, or gives you notice before any material change

Product analytics are not shared with anyone. They are recorded by Fraghab, stored in Fraghab’s own database, and, because they are recorded against your account so we can tell one person’s usage from another’s, they are personal data, not anonymous statistics. They are deleted with your account.

07

Statistics we share with verified houses

Fraghab runs a partner program for fragrance houses. A house we have verified as the owner of its brand can see statistics about how Fraghab members engage with that brand only, so it can correct what is published about its fragrances and understand which of them people want.

What a verified house can see about its own brand:

  • How many members own its fragrances, and how many bottles in total
  • How many times its fragrances have been logged as worn, and by how many members
  • How many members have its fragrances on a wishlist, and which of them are most wanted
  • How its fragrances break down across the seasons and occasions members record
  • Reviews of its fragrances that members chose to publish in the public library, which are already public on this site

What a verified house never receives:

  • Your username, email address, account id, or any other identifier
  • Your location, country, or any demographic detail
  • Anything you paid, or any cost or valuation you recorded
  • Your wearing logs themselves, your private notes, your messages, or any other free text you wrote
  • Any ability to ask about a named member, or to receive a list of members

How we keep this from identifying you. Houses receive counts and category breakdowns, never records. Every figure counts a group of members, and a figure is withheld entirely when fewer than five members make it up, so no number can be narrowed down to one person. Nothing we send carries an identifier, and we do not provide a geographic or demographic breakdown of any kind, because at our current size that could isolate an individual.

Our commitment. We publicly commit to maintain and use these statistics only in de-identified, aggregated form. We do not attempt to re-identify any member from them, and every verified house is contractually prohibited from attempting to re-identify anyone, or from combining what it receives with other data in order to do so. Because the statistics are de-identified and aggregated they are not personal information, so providing them is neither a sale nor a share of your personal data. Houses pay us nothing for them.

If you would rather not be counted. Email [email protected] and we will exclude your collection, wearings, and wishlist from these statistics. Nothing else about your account changes, and we will not treat you differently for asking.

08

What is public on Fraghab

Some surfaces are public by design. Anyone with the link can see them without a Fraghab account, and a search engine or another service may index, crawl, or cache them. Treat anything you put on these surfaces as published.

  • Shared wishlist and gift registry links, at the token URL you generate and share
  • Scent passport pages, at your username
  • Marketplace listing pages and seller storefront pages, including the listing text, photos, size variants, prices, shipping fee, your username, and your seller and buyer reviews
  • Wanted-board posts, including the fragrance you are looking for, your budget note, anything you write in the details, and your username
  • Written reviews you publish in the public library
  • Group Therapy posts, polls, and comments, which are visible to other signed-in Fraghab users

You choose whether to create a share link, publish a listing, or post a review. Deleting the content removes it from Fraghab, but we cannot recall a copy a third party already made, or a page a search engine already cached.

Your email address, password, collection cost data, wearing logs, calendar events, direct messages, and analytics are never published.

Nothing in this section is affected by the brand statistics described above. Where your collection, wearings, or wishlist contribute to one of those figures, they do so only inside an aggregate count that carries no identifier and cannot be traced back to you, and never as a record of yours.

09

Cookies & sessions

Fraghab uses a single session cookie for authentication. This cookie identifies your logged-in session and is essential for the app to function. It contains no tracking data and is not shared with third parties. A small number of additional first-party cookies or local storage entries hold your own preferences, such as your theme and view mode.

We do not use third-party tracking cookies, analytics pixels, or advertising trackers, so there is no consent banner to click and nothing to opt out of. Your browsing behavior within Fraghab is not monitored or sold. Because we do not track you across sites and do not sell or share personal information, there is no cross-site tracking for a Do Not Track or Global Privacy Control signal to switch off, but we will honor such a signal wherever the law requires it.

The mobile apps use no cookies at all. They hold a sign-in token in your device’s own encrypted storage (the iOS Keychain or the Android Keystore), which is cleared when you sign out or delete your account.

10

Your rights

You have full control over your data on Fraghab:

  • Access: view all your data directly within the app at any time, or ask us for a copy
  • Correction: update your profile, collection, and any other personal data through the app
  • Export and portability: request a complete export of your data by contacting us
  • Deletion: delete your account yourself at any time in Settings, then Danger zone, then Delete account, or on the web at fraghab.com/account/delete. Deletion is completed as described in "Data retention"
  • Restriction and objection: ask us to restrict processing, or object to processing we carry out on the basis of a legitimate interest
  • Withdraw consent: disconnect a calendar, or opt out of an optional email, at any time
  • No automated decisions: we do not make decisions about you by solely automated means that produce a legal or similarly significant effect

How to make a request. Email [email protected] from the address on your account, or tell us which account you are asking about. We may need to verify your identity before we act, and we will only ask for what is necessary to do that. We respond within 30 days, or 45 days where a US state law sets that period, and we will tell you if we need an extension the law allows. Using a right costs nothing, and we will never treat you worse for using one.

Authorized agents. You may use an authorized agent to make a request for you. We will ask for proof of the agent’s authority, and may still verify your identity directly.

If you disagree with our answer. Reply to our response and ask for an appeal. Someone who was not involved in the original decision will review it and answer you in writing within 45 days. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority, or with the UK Information Commissioner’s Office. If you are in the US, you may contact your state attorney general.

11

US state privacy rights

If you live in California, Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive privacy law, you have the rights described in "Your rights" above, and the following applies to the extent that law covers us.

Categories we collect. Identifiers such as your email address, username, and account id; internet or app activity such as the five product-analytics events, session records, and crash diagnostics; commercial information such as your listings, orders, and wishlist budget notes; visual content, meaning the images you upload; the content of your posts, messages, and reviews; and inferences drawn to produce a fragrance suggestion. Sources, purposes, and recipients are described in "What we collect", "How we use your data", and "Data sharing".

Sale, sharing and targeted advertising. We do not sell personal information, we do not share it for cross-context behavioral advertising, we do not use it for targeted advertising, and we do not profile you in furtherance of a decision that produces a legal or similarly significant effect. We have not done any of those things in the preceding twelve months. There is therefore no opt-out for you to exercise, and no "Do Not Sell or Share My Personal Information" mechanism is required.

De-identified information. The aggregate statistics we provide to verified fragrance houses are de-identified. We take reasonable measures to ensure they cannot be associated with any consumer, including withholding any figure made up of fewer than five members. We publicly commit to maintain and use them only in de-identified, aggregated form, we do not attempt to re-identify anyone from them, and we contractually require every recipient to do the same. De-identified information is not personal information under these laws, so providing it is neither a sale nor a share. Even so, you may ask us to leave your data out of these statistics entirely, as described in "Statistics we share with verified houses".

Sensitive personal information. We do not collect or process sensitive personal information as those laws define it, so there is nothing for you to limit. We do not knowingly sell or share the personal information of anyone under 16.

Retention and non-discrimination. We keep personal information as described in "Data retention". We will not deny you service, charge you a different price, or give you a lower quality of service because you used a privacy right.

12

International users & transfers

Fraghab is operated from the United States, and our infrastructure providers store and process data in the United States. If you use Fraghab from outside the US, your personal data will be transferred to, stored in, and processed in the US, where privacy law differs from the law where you live.

For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where it applies, in our contracts with the providers listed in "Third-party services", or on another lawful transfer mechanism where one applies. You can request a summary of the safeguards in place by emailing [email protected].

By using Fraghab you understand that your data will be handled as described in this policy. Nothing here takes away a mandatory right you have under the law where you live.

13

Children's privacy

Fraghab is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. Our Terms of Service require you to be 18 to hold an account on your own, or 13 with the consent and supervision of a parent or legal guardian, and 18 to buy or sell in the marketplace.

If we learn that we hold personal information from a child under 13, we will delete it and terminate the account. If you are a parent or guardian and believe your child has given us personal information, email [email protected] and we will act promptly.

14

Community content

Content you post in Group Therapy, including text posts, polls, reviews, reactions, and comments, is visible to other Fraghab users. Marketplace listings, storefronts, and library reviews are visible to anyone, as described in "What is public on Fraghab". Direct messages are visible only to you and the recipient.

Exercise discretion when sharing in community spaces. Do not include sensitive personal information, such as financial details or a physical address, in a public post, a listing, or a review. Fraghab is not responsible for information you choose to share publicly.

What you send a buyer or seller leaves our reach. Completing a marketplace sale normally means giving the other person a delivery address, a name, and a way to pay or be paid. You send that to them directly. Fraghab does not collect, store, or verify any of it for an order, so the other user is the only one holding it, they hold it independently of us, and they are responsible for it under the law that applies to them. We cannot see what they do with it, cannot get it back, and cannot delete it on your behalf — deleting your Fraghab account does not remove it from their records, their inbox, or a shipping label they already printed. Send only what the transaction actually needs, and be deliberate about it.

A message you sent stays in the recipient’s thread, and a quote of your post stays in the quoting post, even after you delete your copy or your account. That is how a conversation works, and we cannot remove someone else’s legitimate copy of what you sent them.

Reports and moderation. If you report another user’s content, or someone reports yours, the report, the reason, and any detail written in it go to our moderation queue and are read by the people who run the service. We may share the substance of a report with the person it concerns so they can respond, and we keep a record of what was reported and what we did about it, as described in section 6 of the Terms.

Your username travels with the report. A report identifies you as the person who filed it, so that moderators can tell one complaint from a campaign. Inside Fraghab that identity is shown only in the moderation queue, which only moderators can open — we do not show the person you reported who reported them, and no screen reveals it to other users.

Reports are also sent to us by email. So that a report can be reviewed inside the 24 hours the Terms commit to, filing one also sends it to our moderation address through our transactional email provider. That email carries your username, the reason you chose, anything you wrote in the report, and what or whom it is about. The provider is our processor and is named in "Third-party services"; it handles the message to deliver it and for no other purpose. The address it is sent to is one of our own moderation mailboxes, never the person you reported. If you would rather not have your own words travel this way, pick a reason and leave the detail box empty — the reason, the target, and your username still reach the queue.

15

Third-party services

Fraghab relies on a limited set of third-party services to operate:

  • Turso: database hosting and data storage
  • Vercel: application hosting and deployment
  • Cloudflare: DNS, content delivery, and security filtering in front of the app. Handles request metadata such as network address and user agent in order to route traffic and block abuse
  • Proton Mail: transactional email delivery (verification, password reset, invitations, and the moderation alert that carries a report to us — see "Community content")
  • Anthropic: AI processing for suggestions, planning, and natural-language search, through the commercial API (see "Data sharing")
  • OpenAI, in two separate roles. As our processor, it transcribes the sound of a video when you ask the Overlay Studio to generate subtitles (see "Data sharing"). And only if you connect the ChatGPT app, it is an independent controller of what you tell ChatGPT and of what our connector returns to it — not our processor in that role (see "The ChatGPT app & connected assistants" below)
  • Sentry: crash and error diagnostics for the iOS and Android apps only. Receives the error, your device model, OS version, app release, and your numeric account id (see "The iOS & Android apps" below)
  • Google Sign-In: only if you choose to sign in with Google. We receive your email address, name, and Google account identifier in order to create or match your account
  • Sign in with Apple: only if you choose to sign in with Apple. We receive your Apple account identifier and an email address — which may be Apple's private-relay address — in order to create or match your account. We ask Apple for nothing beyond that
  • Google Calendar API: only if you choose to connect Google Calendar, used for read-only access to your events (see "Connected calendars & Google user data" below)

These providers process data only as necessary to deliver their respective services, act on our instructions where they are our processors, and are bound by their own privacy policies and by our contracts with them.

16

Connected calendars & Google user data

Fraghab lets you optionally connect a personal calendar so the app can match fragrance suggestions to what’s actually on your schedule. Connecting a calendar is never required to use Fraghab, and you can disconnect it at any time.

What we access. With your permission, Fraghab requests read-only access to your Google Calendar (events-only scope calendar.events.readonly), or reads a personal ICS feed URL or uploaded .ics file you provide. We read only the event titles and start and end times within the date range the app needs (today, or the week you are planning). We do not access attendees, locations, descriptions, attachments, conferencing links, or any other calendar field, and we never create, modify, or delete calendar entries.

How we use it. Calendar events are used solely to (a) display today’s events alongside your wearing log and dashboard, and (b) pre-fill the Weekly Planner with a suggested occasion per day, which is passed as context to the fragrance suggestion engine to generate a recommendation for you in that moment. This is inference only, used to deliver the user-facing feature. Google user data is never used to train, develop, or improve any artificial intelligence or machine learning models, and is never used for advertising, profiling, building user profiles for unrelated purposes, or sold or transferred to anyone for those purposes.

How we store it. For Google Calendar, the OAuth access and refresh tokens are stored server-side only. They are never sent to your browser and never written to logs. For a manual ICS feed URL, only the URL is stored and event contents are fetched on demand. For an uploaded .ics file, the file’s contents are stored so the app can read events from it. The upload is a static snapshot, removed when you disconnect or delete your account.

How to revoke and delete. Disconnect at any time from Integrations, then Google Calendar — or from Profile, then Edit, then Your Calendar — either of which immediately deletes the stored tokens or feed URL. You can also revoke Fraghab’s access directly from your Google Account at myaccount.google.com/permissions. All calendar connection data is also removed if you delete your Fraghab account.

Limited Use. Fraghab’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

17

The ChatGPT app

Fraghab publishes a ChatGPT app, so you can ask ChatGPT to read your collection, add to it, correct an entry, build a shelf or a layering combo, log what you wore and read back what you have worn, see your wishlist and put something on it, find the best current price on something already there, ask what to wear today, or have it pack your fragrances for a trip, without leaving the conversation. It works over the open Model Context Protocol at fraghab.com/api/mcp, and the same endpoint is open to any other assistant that speaks that protocol. Connecting one is entirely optional, it is never required to use Fraghab, and nothing happens until you sign in on a Fraghab consent screen and press Allow.

The recipient is OpenAI, and it is not our processor. When you connect the ChatGPT app, OpenAI is an independent controller of the conversation it holds. Everything below flows to OpenAI’s servers, is retained under OpenAI’s privacy policy and your ChatGPT account settings, and is outside our reach. We cannot retrieve, correct, or delete what OpenAI holds, and a request to us cannot reach it. If you connect a different assistant, the same is true of whoever operates it. Do not connect an assistant unless you are content for that provider to hold your collection.

What this app can do. It can read your bottles and decants with their remaining ml, ratings, wear counts and last-worn dates, or one entry in full; your shelves and your layering combos; your wearing history; and your wishlist with the prices the last retailer scan found, and it can search the fragrance catalog. It can ask the app’s own suggestion engine what you should wear today, and build a day-by-day packing list for a trip from your own bottles. It can add a bottle or decant, or a whole list of them at once; change details on one you already have, or on several in one step; mark one a favourite; archive one and restore it; set a decant’s verdict; turn a decant into a full bottle; set a single field across many entries at once; create and rename shelves and move bottles on and off them; create and edit layering combos; log a wearing, or a whole combo, deducting the sprayed ml; correct a wearing that was logged wrong; record how a fragrance performed on a day you wore it; add to your wishlist, one item or a list, and run the retailer price search; move a bottle back to the wishlist; mark a wishlist item bought; and queue a full bottle of a decant you liked. The Claude connector described below can do the same things; the two run on one set of tools.

It cannot delete anything. No tool removes a bottle, a decant, a wearing, a wishlist item, a shelf, a combo, or your account. Archiving is the closest it comes, and archiving is reversible — the entry leaves your collection view and can be restored. Deleting is done by you, in the app.

Editing can overwrite, and some of it cannot be undone. Changing a field replaces what was there, clearing one empties it, and logging a wearing subtracts millilitres that we do not keep a prior copy of. We mark every tool of that kind so the assistant knows to ask you first, but the record we keep is the one after the change. An edit only replaces the fields the assistant actually names — we read your entry first and put the rest back — so asking it to change a rating does not blank your notes.

What leaves Fraghab through the connector. Only what the tool you invoked returns:

  • Your collection rows: for every bottle and decant, its id, name, house, concentration, bottle or decant size, remaining ml, your rating, whether it is a favourite, a decant's verdict, how many times you have worn it, and the date you last wore it. This is the same read the collection page uses, capped at 200 items per side per call
  • One entry in full, when you ask about it: everything above plus its note pyramid and accords, the perfumer and release year, the price you paid, your written notes, the seasons and occasions you tagged, the shelves it sits on, whether it is running low, and its wear figures — first and last worn, wears per month, cost per wear and per ml, value remaining, and its last five wearings
  • Your wearing history, over the range you ask about: each wearing's date, its occasion, your note, the sprays per fragrance, and the bottles or decants worn — newest first, in pages
  • Your wishlist: each item's name, house, priority, the size and price you noted, your target price, the link you saved, whether it has artwork, your wishlist budget, and the best offer the last retailer scan found for it — price, shop, size and when. Items you marked bought only when you ask for them
  • Suggestions and packing lists: entries from your own collection ranked by the app's engine, each with the reasons it scored, the daily pick, the forecast used (temperature, condition, season) and the engine's short explanation; for a trip, the destination as we located it and each day's forecast, pick and alternatives
  • Your shelves and layering combos: each shelf's name and which bottles sit on it, and each combo's name, rating, the fragrances layered in it, how often it has been worn and when it was last worn
  • Search results: the fragrances matching a search, with house, concentration, perfumer, release year, scent notes and accords, each flagged for whether it is already in your collection — which discloses part of your collection too. As in the app's own add-a-fragrance search, these come from the house catalog and from entries other members have catalogued, carrying no indication of who owns them and none of the private notes, ratings, prices, or quantities those members recorded
  • Confirmation of a write: the id of the entry, wearing, wishlist item, shelf or combo just created or changed, its name, and whether artwork was found for it
  • Price results, when you ask for a price on a wishlist item you name: how many live offers came back, the cheapest one and the shop selling at it, whether that is at or below the target price you set, and how many of your 25 daily price scans are left. The offers themselves are retailer listings, not anything about you — and this is the only tool that reaches outside Fraghab to produce them, which the next paragraph sets out in full
  • Nothing else. No tool lists your profile, your email address, your location itself, your community posts, or your marketplace activity, and none returns an identifiable member's collection. Your numeric account id is taken from the token, never from anything ChatGPT says, so an assistant cannot name whose collection it is reading or writing

Three of these tools reach outside Fraghab. Asking an assistant for the best price on a wishlist item runs the same retailer search the price button in the app runs: we query fragrance retailers’ own sites, some directly and some through a third-party scraping service that fetches the page on our behalf. What goes out is the fragrance name and its house — the words on the bottle, and nothing about you. Not your name, your email address, your account id, your IP address, your collection, the rest of your wishlist, the target price you set, or the fact that the request came from ChatGPT rather than from the website. Each search spends one of the 25 price scans your account gets each day, replaces the offers stored on that wishlist item with the fresher ones, and, if the item has no picture yet, may give it one. Asking what to wear today fetches the forecast for the location saved on your account from the weather provider the app itself uses — the latitude and longitude go out, and nothing else; with no saved location the app’s default location is used instead, so nothing about you goes out at all. Asking for a trip packing list sends the destination you named to a geocoding provider, fetches that place’s forecast the same way, and then runs the planner the app’s own trip page runs, which passes the entries it is choosing between — their names, houses, notes and how they have performed for you, never your name or account — to the AI provider named in “AI features & automated decisions” below, and spends one of the limited daily planner runs your account gets. The only other thing that leaves our systems is the search for a picture, described next.

Pictures: our catalog first, then a search we run ourselves. When an assistant adds a fragrance, we look in Fraghab’s own Library first — the images members have already catalogued — matched on the name and house. If nothing is catalogued we go looking, because most of what is worth adding has never been catalogued here: we request the page a public perfume reference site publishes for that name and house, and if that does not produce a picture we run the same retailer search the price button runs. What goes out is the fragrance name and its house — the words on the bottle — and nothing about you: not your name, your email address, your account id, your IP address, your collection, or the fact that an assistant asked rather than you. A picture that comes back is copied onto our own storage and its background removed, so nothing on your entry points at anybody else’s server. We never fetch a picture from an address an assistant supplies — no tool will accept one — and a bottle we cannot find simply arrives without a picture, as it always has.

What travels the other way. Whatever you type into ChatGPT reaches OpenAI first — that is where the conversation lives — and the assistant then sends us only the fields a tool takes, such as the words you are searching for, a fragrance name and house, a concentration, a size, a price you paid, a rating, a date, a spray count, seasons and occasions, scent notes, a perfumer, a shelf or combo name, a body zone and spray count for a layering step, a wishlist priority or link, any note you asked it to save, and — for a suggestion or a trip — an occasion or mood, your timezone, a destination and travel dates. A bottle or decant added this way is stamped as having come from ChatGPT, so you can tell it from one you typed yourself.

What a connection grants. The consent screen lists the permissions in plain words and you approve them as a set. Four permissions cover the whole tool set: collection:read to read your collection in summary or in full, your shelves and combos, your wearing history and your wishlist, to search the catalog, and to ask for a suggestion or a packing list, collection:write to add, edit, archive, organise and mark as bought, wearings:write to log a wearing and to correct one, and wishlist:write both to add a wishlist item and to run the retailer price search described above — the one capability here that leaves Fraghab. Granting it grants both; there is no way to allow the add and withhold the search. A permission the connection was not granted is refused at our end, not merely left uncalled.

Changing your password revokes every connector token. This is a mechanism, not a promise. Each Fraghab account carries a version number that increments on every password change, and that number is stamped into every connector credential we issue. Both the access token, which lasts one hour, and the longer-lived refresh token behind it are checked against your account’s current version on every single call — a database read each time, deliberately, so a changed password takes effect at once rather than after the token expires. Change your password and every assistant connected to your account stops working immediately and must ask for your permission again. Deleting your account erases the stored authorization codes and refresh tokens with everything else.

Because the connector reaches an AI assistant, everything in “AI features & automated decisions” below applies as well, and section 19 of the Terms covers connected services. Fraghab also publishes a connector for Claude at its own address; it is a separate connection with its own consent screen, and “The Claude connector” below covers it.

18

The Claude connector

Fraghab publishes a connector for Claude at a different address — fraghab.com/api/mcp/claude — over the same open Model Context Protocol. Since 18 August 2026 it offers the same tools as the ChatGPT app: everything the section above describes it can do, this can do, and everything that section says about what leaves Fraghab, what cannot be deleted, what an edit overwrites, where pictures come from, and what the four permissions grant is true of this connector word for word. Connecting it is entirely optional, it is never required to use Fraghab, and nothing happens until you sign in on a Fraghab consent screen and press Allow.

It is a separate connection from the one above. Approving the ChatGPT app does not approve this, and approving this does not approve that. The credential issued for one address is refused at the other, deliberately: each is approved on its own consent screen and each is revoked on its own, so ending one leaves the other running.

The recipient is Anthropic, and it is not our processor. When you connect Claude, Anthropic is an independent controller of the conversation it holds. Everything the section above lists as leaving Fraghab flows to Anthropic’s servers instead of OpenAI’s, is retained under Anthropic’s privacy policy and your Claude account settings, and is outside our reach. We cannot retrieve, correct, or delete what Anthropic holds, and a request to us cannot reach it. Do not connect it unless you are content for Anthropic to hold your collection.

What travels the other way. Whatever you type into Claude reaches Anthropic first — that is where the conversation lives — and the assistant then sends us only the fields a tool takes, exactly as listed in the section above. A bottle or decant added through this connector is stamped as having come from Claude rather than from ChatGPT, so you can tell which assistant added it, and both from one you typed yourself.

Changing your password revokes every connector token. The mechanism is the one described in the section above and it covers this connector identically: every credential carries your account’s password version, that version is re-read from the database on every single call, and changing your password stops every connected assistant at once. Removing the connector in Claude ends it from that side. Deleting your account erases the stored authorization codes and refresh tokens with everything else.

Because this connector reaches an AI assistant, everything in “AI features & automated decisions” below applies as well, and section 19 of the Terms covers connected services.

19

The iOS & Android apps

The Fraghab mobile apps sign in to the same account and store the same collection as the website, so everything above applies to them. This section covers what is specific to a phone.

What the apps send. Beyond what you type in, meaning your collection, wearings, wishlist, and community posts, the apps transmit exactly three things you did not type: the five product-analytics events listed below, a crash report if the app crashes, and ordinary session details (app version, platform, and your device’s time zone name).

  • Analytics events: app opened, signed in, collection viewed, suggestion requested, wearing logged. That is the whole list; the app cannot send any other event
  • What travels with an event: counts, yes or no flags, and short fixed labels only. Free text is stripped on our servers before the event is stored, so a fragrance name or a note you wrote can never end up in analytics
  • Crash reports: the error and where it happened, your device model, OS version, and the app release. Sent to Sentry (see "Third-party services"), tagged with your numeric account id and nothing else
  • Deliberately excluded from crash reports: screenshots, a copy of the screen's contents, anything you typed into the console, and the query part of any web address. Screen names are recorded; screen contents are not
  • Session details: the app version and platform, an identifier for each signed-in session, and your device's time zone name

Your time zone is not your location. The apps send a time zone name, for example "America/New_York", which is a regional setting on your device. It is used only to work out which day "today" is when you log a wearing. Setting a location is a separate, deliberate step: the apps never read your device’s location — if you want weather-aware suggestions, you type a city and the app saves that city’s approximate coordinates, as described in "What we collect". Skip it and everything except weather-based suggestions still works.

What the apps never ask for or collect. Your device’s location, your photo library beyond the individual pictures you pick, contacts, calendar, microphone, health, or financial data. Bottle and decant pictures come only through the system photo picker, which hands the app just the photos you select — the app cannot browse your library. The camera is asked for in one place and for one purpose: scanning a bottle label to add it to your collection, and only at the moment you tap to take that photo. Decline it and every other way of adding a bottle still works. That photo is read on the device and is never uploaded to us — see section 2. There is no advertising, no advertising identifier, and no tracking of you across other companies’ apps or websites, so iOS never shows you a tracking permission prompt, because there is nothing to ask about. Fraghab does not sell your data or share it with data brokers.

No payments pass through the apps. The apps are free, contain no in-app purchases and no subscriptions, and take no payment of any kind. Marketplace items are physical goods that one user ships to another — in a trade, that both users ship to each other — and any money owed, whether a purchase price or cash added to even out a trade, is paid directly between the two of them outside the app, so no payment detail is entered into the app, sent to us, or handled by Apple or Google. See section 8 of the Terms.

Reporting and blocking in the apps. Every screen that shows another user’s content — a post, a comment, a listing, a wanted post — carries a report control, and you can block a user from their profile at any time. Blocking hides their content from you and stops them contacting you, and your blocked list is under Settings. We review reports within 24 hours and remove content and eject users as described in section 6 of the Terms. A report filed in an app raises the same immediate alert and lands in the same moderation queue as one filed on the web — there is no slower path for a report that came from a phone.

Permissions. The Android app requests network access and, if you turn on the app lock, biometric unlock. The iOS app asks for Face ID only for that same lock, and only when you enable it. Both ask for the camera the first time you scan a bottle label, and for nothing else. Choosing a bottle photo opens the system photo picker, which needs no permission of its own and shares only what you pick. Nothing else is requested — in particular, neither app ever requests the location permission.

Deleting your account from the app. Open Settings, then Danger zone, then Delete account, confirm with your password, and the account and everything in it, including the analytics events and crash-report association described here, is removed. You can also do it on the web at fraghab.com/account/delete, without signing in first.

20

AI features & automated decisions

When you ask for a fragrance suggestion, a weekly plan, buying guidance, or a natural-language search, the information needed to answer, such as your request and the relevant part of your collection or plan, is sent to Anthropic’s commercial API for processing and the result is returned to you. That API does not use inputs or outputs for model training by default. Fraghab does not use your data to train or develop its own models.

When you ask the Overlay Studio to generate subtitles from a video, the sound of the part you trimmed to is sent to OpenAI’s API, which transcribes it; the words and their timings come back as captions for you to review and edit before anything is saved. The picture stays on your device. That API does not use the sound or the transcript for model training by default, and we keep neither on our servers.

A suggestion is an inference produced to deliver a feature you asked for. It is not a decision about you, it has no legal or similarly significant effect, and it is not profiling for advertising. Nothing in Fraghab makes a decision about you by solely automated means within the meaning of Article 22 of the GDPR.

Do not type anything into an AI feature that you would not want processed by a third-party provider. AI output can be wrong, and the Terms of Service explain what you should and should not rely on it for.

21

Emails we send

Transactional email. We send the email the service needs to work: address verification, password resets, invite notifications, and notices about your account or these policies. You cannot opt out of these while your account is open, because they are part of providing the service.

Optional email. We occasionally send a product announcement, or invite you to a short research survey. You can opt out at any time by replying "unsubscribe" to the message, or by emailing [email protected]. Opting out of optional email does not affect transactional email.

What we measure, and what we do not. We do not track whether you open an email. There is no tracking image, invisible pixel, or read receipt in any message we send. What we do record is whether you followed a link: the links in an account or policy email route through fraghab.com first, so we can note that the link was used, when it was first used, and which page it led to, before sending you on to that page. The link carries a random one-time reference rather than your email address, so your address is never placed in a web address that could be logged by a network in between.

We use it only to judge whether a message reached people, and it is deleted with your account. If you would rather not be counted, open the plain link printed at the bottom of the email instead of the button, and nothing is recorded at all.

We never sell or rent your email address, never send third-party advertising, and never pass your address to a marketing list.

22

Data retention

Your data is retained for as long as your account is active. When you delete your account, your personal data, including your collection, wearings, community posts, messages, listings, analytics events, and stored sessions, is removed from our live systems promptly, and in any case within 30 days.

What can outlast that. Copies may persist in routine encrypted backups until those backups age out. We may keep the limited data we are required or permitted to keep in order to comply with law, resolve a dispute, enforce our terms, or prevent fraud and abuse, and we keep it only as long as that purpose lasts. A direct message you sent stays in the recipient’s thread, and content a third party already copied or cached from a public surface may remain where we cannot reach it.

Marketplace records specifically. An order is a shared record between two people, so the counterparty’s copy of it — what was bought, what was agreed, and when — stays in their order history after you delete your account, in the same way a message you sent stays in their thread. A review you wrote about someone else stays on their profile. The address snapshot on their copy of the order stays with it, for the same reason: it is part of a record of a transaction that was theirs as well as yours. We may also keep a report you filed or that was filed about you, and the moderation action taken on it, for as long as we need it to keep the marketplace safe and to enforce a ban. Anything you sent a counterparty yourself, such as a payment handle typed into a message, was never ours to delete and is covered in "Community content".

Two shorter clocks run regardless of your account: failed sign-in counters keyed to a network address are erased within fifteen minutes, and crash reports held by Sentry expire on that provider’s own retention schedule.

Aggregated or de-identified data that cannot reasonably be linked back to an individual may be retained indefinitely for service improvement. We do not attempt to re-identify it.

23

Security incidents

If a security incident affects your personal data, we will investigate, take steps to contain it, and notify you and the relevant authorities where the law requires, without undue delay. We will tell you what happened, what data was involved as far as we know it, and what you can do.

If you find a vulnerability in Fraghab, please report it to [email protected] rather than testing it against other users’ accounts. We will not pursue a good-faith researcher who reports privately and gives us a reasonable chance to fix the issue.

24

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify users through the platform or by email and update the effective date at the top of this page. Continued use of Fraghab after changes take effect constitutes acceptance of the revised policy.

The "Effective" date at the top of this page indicates when this policy was last updated.

25

Contact

Fraghab is operated by FRAGHAB LLC, a Michigan limited liability company, which is the data controller for the purposes of this policy.

Questions about this Privacy Policy, a data request, or an appeal go to [email protected]. For anything else legal, including a copyright notice, see the contact section of our Terms of Service.

Our mailing address is FRAGHAB LLC, 4121 Deeside Dr, Brighton, MI 48116, United States.