Your data is yours. This policy explains what we collect, why we collect it, and the control you have over it.
Effective August 5, 2026Fraghab is operated by FRAGHAB LLC, a Michigan limited liability company. For users in the European Economic Area, the United Kingdom, and Switzerland, FRAGHAB LLC is the data controller for the personal data described here.
This policy covers the Fraghab website at fraghab.com, the Fraghab iOS and Android apps, the House API, and the emails we send. The Fraghab browser extension is covered by its own extension privacy policy, because it handles data locally in your browser.
This policy is part of our Terms of Service. Reach us about anything on this page at [email protected].
Fraghab collects only the data necessary to provide the service. This includes:
What we do not collect. We do not collect your location unless you choose to set it as described above. We do not collect your contacts, photos beyond what you upload, biometric data, payment card or bank details, government identifiers, or any advertising identifier. We do not ask for special category or sensitive personal data, and you should not put it into a post, a listing, or a note.
Your data is used to operate and improve the Fraghab experience:
Fraghab does not use your personal data for advertising, does not sell it, and does not use it to train or develop its own AI or machine learning models. We do not use it for profiling that produces legal or similarly significant effects on you.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on these legal bases under Article 6 of the GDPR:
Where we rely on consent and you withdraw it, we stop that processing and delete the data it depended on, for example the stored calendar credentials when you disconnect a calendar.
Your data is stored in a managed database hosted by Turso, on servers located in the United States. All connections between the app and the database are encrypted. Passwords are hashed using industry-standard algorithms and are never stored or transmitted in plain text.
Access to production data is limited to the people who need it to run the service, and every query that touches your records is scoped to your authenticated account. Calendar credentials are held server-side only, are never sent to your browser, and are never written to logs.
We implement reasonable technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
Fraghab runs a partner program for fragrance houses. A house we have verified as the owner of its brand can see statistics about how Fraghab members engage with that brand only, so it can correct what is published about its fragrances and understand which of them people want.
What a verified house can see about its own brand:
What a verified house never receives:
How we keep this from identifying you. Houses receive counts and category breakdowns, never records. Every figure counts a group of members, and a figure is withheld entirely when fewer than five members make it up, so no number can be narrowed down to one person. Nothing we send carries an identifier, and we do not provide a geographic or demographic breakdown of any kind, because at our current size that could isolate an individual.
Our commitment. We publicly commit to maintain and use these statistics only in de-identified, aggregated form. We do not attempt to re-identify any member from them, and every verified house is contractually prohibited from attempting to re-identify anyone, or from combining what it receives with other data in order to do so. Because the statistics are de-identified and aggregated they are not personal information, so providing them is neither a sale nor a share of your personal data. Houses pay us nothing for them.
If you would rather not be counted. Email [email protected] and we will exclude your collection, wearings, and wishlist from these statistics. Nothing else about your account changes, and we will not treat you differently for asking.
Some surfaces are public by design. Anyone with the link can see them without a Fraghab account, and a search engine or another service may index, crawl, or cache them. Treat anything you put on these surfaces as published.
You choose whether to create a share link, publish a listing, or post a review. Deleting the content removes it from Fraghab, but we cannot recall a copy a third party already made, or a page a search engine already cached.
Your email address, password, collection cost data, wearing logs, calendar events, direct messages, and analytics are never published.
Nothing in this section is affected by the brand statistics described above. Where your collection, wearings, or wishlist contribute to one of those figures, they do so only inside an aggregate count that carries no identifier and cannot be traced back to you, and never as a record of yours.
You have full control over your data on Fraghab:
How to make a request. Email [email protected] from the address on your account, or tell us which account you are asking about. We may need to verify your identity before we act, and we will only ask for what is necessary to do that. We respond within 30 days, or 45 days where a US state law sets that period, and we will tell you if we need an extension the law allows. Using a right costs nothing, and we will never treat you worse for using one.
Authorized agents.You may use an authorized agent to make a request for you. We will ask for proof of the agent’s authority, and may still verify your identity directly.
If you disagree with our answer.Reply to our response and ask for an appeal. Someone who was not involved in the original decision will review it and answer you in writing within 45 days. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority, or with the UK Information Commissioner’s Office. If you are in the US, you may contact your state attorney general.
If you live in California, Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive privacy law, you have the rights described in "Your rights" above, and the following applies to the extent that law covers us.
Categories we collect.Identifiers such as your email address, username, and account id; internet or app activity such as the five product-analytics events, session records, and crash diagnostics; commercial information such as your listings, orders, and wishlist budget notes; visual content, meaning the images you upload; the content of your posts, messages, and reviews; and inferences drawn to produce a fragrance suggestion. Sources, purposes, and recipients are described in "What we collect", "How we use your data", and "Data sharing".
Sale, sharing and targeted advertising. We do not sell personal information, we do not share it for cross-context behavioral advertising, we do not use it for targeted advertising, and we do not profile you in furtherance of a decision that produces a legal or similarly significant effect. We have not done any of those things in the preceding twelve months. There is therefore no opt-out for you to exercise, and no "Do Not Sell or Share My Personal Information" mechanism is required.
De-identified information. The aggregate statistics we provide to verified fragrance houses are de-identified. We take reasonable measures to ensure they cannot be associated with any consumer, including withholding any figure made up of fewer than five members. We publicly commit to maintain and use them only in de-identified, aggregated form, we do not attempt to re-identify anyone from them, and we contractually require every recipient to do the same. De-identified information is not personal information under these laws, so providing it is neither a sale nor a share. Even so, you may ask us to leave your data out of these statistics entirely, as described in "Statistics we share with verified houses".
Sensitive personal information. We do not collect or process sensitive personal information as those laws define it, so there is nothing for you to limit. We do not knowingly sell or share the personal information of anyone under 16.
Retention and non-discrimination.We keep personal information as described in "Data retention". We will not deny you service, charge you a different price, or give you a lower quality of service because you used a privacy right.
Fraghab is operated from the United States, and our infrastructure providers store and process data in the United States. If you use Fraghab from outside the US, your personal data will be transferred to, stored in, and processed in the US, where privacy law differs from the law where you live.
For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where it applies, in our contracts with the providers listed in "Third-party services", or on another lawful transfer mechanism where one applies. You can request a summary of the safeguards in place by emailing [email protected].
By using Fraghab you understand that your data will be handled as described in this policy. Nothing here takes away a mandatory right you have under the law where you live.
Fraghab is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. Our Terms of Service require you to be 18 to hold an account on your own, or 13 with the consent and supervision of a parent or legal guardian, and 18 to buy or sell in the marketplace.
If we learn that we hold personal information from a child under 13, we will delete it and terminate the account. If you are a parent or guardian and believe your child has given us personal information, email [email protected] and we will act promptly.
Content you post in Group Therapy, including text posts, polls, reviews, reactions, and comments, is visible to other Fraghab users. Marketplace listings, storefronts, and library reviews are visible to anyone, as described in "What is public on Fraghab". Direct messages are visible only to you and the recipient.
Exercise discretion when sharing in community spaces. Do not include sensitive personal information, such as financial details or a physical address, in a public post, a listing, or a review. Fraghab is not responsible for information you choose to share publicly.
A message you sent stays in the recipient’s thread, and a quote of your post stays in the quoting post, even after you delete your copy or your account. That is how a conversation works, and we cannot remove someone else’s legitimate copy of what you sent them.
Fraghab relies on a limited set of third-party services to operate:
These providers process data only as necessary to deliver their respective services, act on our instructions where they are our processors, and are bound by their own privacy policies and by our contracts with them.
Fraghab lets you optionally connect a personal calendar so the app can match fragrance suggestions to what’s actually on your schedule. Connecting a calendar is never required to use Fraghab, and you can disconnect it at any time.
What we access. With your permission, Fraghab requests read-only access to your Google Calendar (events-only scope calendar.events.readonly), or reads a personal ICS feed URL or uploaded .ics file you provide. We read only the event titles and start and end times within the date range the app needs (today, or the week you are planning). We do not access attendees, locations, descriptions, attachments, conferencing links, or any other calendar field, and we never create, modify, or delete calendar entries.
How we use it.Calendar events are used solely to (a) display today’s events alongside your wearing log and dashboard, and (b) pre-fill the Weekly Planner with a suggested occasion per day, which is passed as context to the fragrance suggestion engine to generate a recommendation for you in that moment. This is inference only, used to deliver the user-facing feature. Google user data is never used to train, develop, or improve any artificial intelligence or machine learning models, and is never used for advertising, profiling, building user profiles for unrelated purposes, or sold or transferred to anyone for those purposes.
How we store it.For Google Calendar, the OAuth access and refresh tokens are stored server-side only. They are never sent to your browser and never written to logs. For a manual ICS feed URL, only the URL is stored and event contents are fetched on demand. For an uploaded .ics file, the file’s contents are stored so the app can read events from it. The upload is a static snapshot, removed when you disconnect or delete your account.
How to revoke and delete.Disconnect at any time in Profile, then Edit, then Your Calendar, which immediately deletes the stored tokens or feed URL. You can also revoke Fraghab’s access directly from your Google Account at myaccount.google.com/permissions. All calendar connection data is also removed if you delete your Fraghab account.
Limited Use.Fraghab’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Fraghab mobile apps sign in to the same account and store the same collection as the website, so everything above applies to them. This section covers what is specific to a phone.
What the apps send.Beyond what you type in, meaning your collection, wearings, wishlist, and community posts, the apps transmit exactly three things you did not type: the five product-analytics events listed below, a crash report if the app crashes, and ordinary session details (app version, platform, and your device’s time zone name).
Your time zone is not your location.The apps send a time zone name, for example "America/New_York", which is a regional setting on your device. It is used only to work out which day "today" is when you log a wearing. Setting a location is a separate, deliberate step: the apps never read your device’s location — if you want weather-aware suggestions, you type a city and the app saves that city’s approximate coordinates, as described in "What we collect". Skip it and everything except weather-based suggestions still works.
What the apps never ask for or collect. Your device’s location, the camera, your photo library beyond the individual pictures you pick, contacts, calendar, microphone, health, or financial data. Bottle and decant pictures come only through the system photo picker, which hands the app just the photos you select — the app cannot browse your library. There is no advertising, no advertising identifier, and no tracking of you across other companies’ apps or websites, so iOS never shows you a tracking permission prompt, because there is nothing to ask about. Fraghab does not sell your data or share it with data brokers.
Permissions. The Android app requests network access and, if you turn on the app lock, biometric unlock. The iOS app asks for Face ID only for that same lock, and only when you enable it. Choosing a bottle photo opens the system photo picker, which needs no permission of its own and shares only what you pick. Nothing else is requested — in particular, neither app ever requests the location permission.
Deleting your account from the app. Open Settings, then Danger zone, then Delete account, confirm with your password, and the account and everything in it, including the analytics events and crash-report association described here, is removed. You can also do it on the web at fraghab.com/account/delete, without signing in first.
When you ask for a fragrance suggestion, a weekly plan, buying guidance, or a natural-language search, the information needed to answer, such as your request and the relevant part of your collection or plan, is sent to Anthropic’s commercial API for processing and the result is returned to you. That API does not use inputs or outputs for model training by default. Fraghab does not use your data to train or develop its own models.
A suggestion is an inference produced to deliver a feature you asked for. It is not a decision about you, it has no legal or similarly significant effect, and it is not profiling for advertising. Nothing in Fraghab makes a decision about you by solely automated means within the meaning of Article 22 of the GDPR.
Do not type anything into an AI feature that you would not want processed by a third-party provider. AI output can be wrong, and the Terms of Service explain what you should and should not rely on it for.
Transactional email. We send the email the service needs to work: address verification, password resets, invite notifications, and notices about your account or these policies. You cannot opt out of these while your account is open, because they are part of providing the service.
Optional email.We occasionally send a product announcement, or invite you to a short research survey. You can opt out at any time by replying "unsubscribe" to the message, or by emailing [email protected]. Opting out of optional email does not affect transactional email.
What we measure, and what we do not. We do not track whether you open an email. There is no tracking image, invisible pixel, or read receipt in any message we send. What we do record is whether you followed a link: the links in an account or policy email route through fraghab.com first, so we can note that the link was used, when it was first used, and which page it led to, before sending you on to that page. The link carries a random one-time reference rather than your email address, so your address is never placed in a web address that could be logged by a network in between.
We use it only to judge whether a message reached people, and it is deleted with your account. If you would rather not be counted, open the plain link printed at the bottom of the email instead of the button, and nothing is recorded at all.
We never sell or rent your email address, never send third-party advertising, and never pass your address to a marketing list.
Your data is retained for as long as your account is active. When you delete your account, your personal data, including your collection, wearings, community posts, messages, listings, analytics events, and stored sessions, is removed from our live systems promptly, and in any case within 30 days.
What can outlast that.Copies may persist in routine encrypted backups until those backups age out. We may keep the limited data we are required or permitted to keep in order to comply with law, resolve a dispute, enforce our terms, or prevent fraud and abuse, and we keep it only as long as that purpose lasts. A direct message you sent stays in the recipient’s thread, and content a third party already copied or cached from a public surface may remain where we cannot reach it.
Two shorter clocks run regardless of your account: failed sign-in counters keyed to a network address are erased within fifteen minutes, and crash reports held by Sentry expire on that provider’s own retention schedule.
Aggregated or de-identified data that cannot reasonably be linked back to an individual may be retained indefinitely for service improvement. We do not attempt to re-identify it.
If a security incident affects your personal data, we will investigate, take steps to contain it, and notify you and the relevant authorities where the law requires, without undue delay. We will tell you what happened, what data was involved as far as we know it, and what you can do.
If you find a vulnerability in Fraghab, please report it to [email protected] rather than testing it against other users’ accounts. We will not pursue a good-faith researcher who reports privately and gives us a reasonable chance to fix the issue.
We may update this Privacy Policy from time to time. When we make material changes, we will notify users through the platform or by email and update the effective date at the top of this page. Continued use of Fraghab after changes take effect constitutes acceptance of the revised policy.
The "Effective" date at the top of this page indicates when this policy was last updated.
Fraghab is operated by FRAGHAB LLC, a Michigan limited liability company, which is the data controller for the purposes of this policy.
Questions about this Privacy Policy, a data request, or an appeal go to [email protected]. For anything else legal, including a copyright notice, see the contact section of our Terms of Service.
Our mailing address is FRAGHAB LLC, 4121 Deeside Dr, Brighton, MI 48116, United States.