Legal

Privacy policy.

Your data is yours. This policy explains what we collect, why we collect it, and the control you have over it.

Effective June 3, 2026
01

What we collect

Fraghab collects only the data necessary to provide the service. This includes:

  • Account information — email address, username, and password (stored as a secure hash, never in plain text)
  • Profile data — optional avatar image and display preferences
  • Collection data — fragrance names, brands, notes, accords, ratings, bottle sizes, and other metadata you enter
  • Wearing logs — dates, fragrances worn, occasion, weather conditions, and personal ratings
  • Connected calendars (optional) — if you connect Google Calendar, a personal ICS feed URL, or an uploaded .ics file, the event titles and start/end times within the date range the app needs, plus the access credentials or file contents required to read them (stored securely server-side, never shown to you or written to logs)
  • Wishlist items — target fragrances, priority levels, and budget notes
  • Layering combos — fragrance pairings, spray zone maps, and combo ratings
  • Community content — Group Therapy posts, polls, poll votes, reviews, reactions, and comments
  • Direct messages — private messages and shared images between users
  • Follow relationships — which users you follow and who follows you
02

How we use your data

Your data is used exclusively to provide and improve the Fraghab experience:

  • Display your collection, wearings, wishlist, and combos within the app
  • Generate personalized insights — most worn fragrances, seasonal trends, weather-based suggestions
  • Read your connected calendar (read-only) to show today's events while you log a wearing and to pre-fill your Weekly Planner with a suggested occasion for each day
  • Power community features — showing your posts, polls, and reviews to other users
  • Deliver direct messages between you and other users
  • Send transactional emails — account verification, password resets, and invite notifications
  • Improve the platform based on aggregate, anonymized usage patterns

We do not use your data for advertising, profiling, training or developing AI or machine learning models, or any purpose unrelated to the Fraghab service.

03

Data storage & security

Your data is stored in a managed database hosted by Turso. All connections between the app and the database are encrypted. Passwords are hashed using industry-standard algorithms and are never stored or transmitted in plain text.

We implement reasonable technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of electronic transmission or storage is 100% secure.

04

Data sharing

Fraghab does not sell, rent, or trade your personal data to third parties. Period.

Your data may be shared only in these limited circumstances:

  • Infrastructure providers — services necessary to host and operate Fraghab (database, email delivery, file storage)
  • Legal requirements — if required by law, regulation, or valid legal process
  • Aggregate analytics — anonymized, non-identifiable usage data may be used to improve the platform
05

Cookies & sessions

Fraghab uses a single session cookie for authentication. This cookie identifies your logged-in session and is essential for the app to function. It contains no tracking data and is not shared with third parties.

We do not use third-party tracking cookies, analytics pixels, or advertising trackers. Your browsing behavior within Fraghab is not monitored or sold.

06

Your rights

You have full control over your data on Fraghab:

  • Access — view all your data directly within the app at any time
  • Correction — update your profile, collection, and any other personal data through the app
  • Export — request a complete export of your data by contacting us
  • Deletion — request full account and data deletion at any time; deletion is completed within 30 days
  • Withdrawal — you may stop using Fraghab at any time by closing your account
07

Community content

Content you post in Group Therapy — including text posts, polls, reviews, reactions, and comments — is visible to other Fraghab users. Direct messages are visible only to you and the recipient.

Exercise discretion when sharing in community spaces. Do not include sensitive personal information (financial details, physical addresses, etc.) in public posts. Fraghab is not responsible for information you choose to share publicly.

08

Third-party services

Fraghab relies on a limited set of third-party services to operate:

  • Turso — database hosting and data storage
  • Proton Mail — transactional email delivery (verification, password reset, invitations)
  • Vercel — application hosting and deployment
  • Google Calendar API — only if you choose to connect Google Calendar; used for read-only access to your events (see “Connected Calendars & Google User Data” below)

These providers process data only as necessary to deliver their respective services and are bound by their own privacy policies.

09

Connected calendars & Google user data

Fraghab lets you optionally connect a personal calendar so the app can match fragrance suggestions to what’s actually on your schedule. Connecting a calendar is never required to use Fraghab, and you can disconnect it at any time.

What we access. With your permission, Fraghab requests read-only access to your Google Calendar (events-only scope calendar.events.readonly), or reads a personal ICS feed URL or uploaded .ics file you provide. We read only the event titles and start/end times within the date range the app needs (today, or the week you are planning). We do not access attendees, locations, descriptions, attachments, conferencing links, or any other calendar field, and we never create, modify, or delete calendar entries.

How we use it.Calendar events are used solely to (a) display today’s events alongside your wearing log and dashboard, and (b) pre-fill the Weekly Planner with a suggested occasion per day, which is passed as context to the fragrance suggestion engine to generate a recommendation for you in that moment. This is inference only, used to deliver the user-facing feature. Google user data is never used to train, develop, or improve any artificial intelligence or machine learning models, and is never used for advertising, profiling, building user profiles for unrelated purposes, or sold or transferred to anyone for those purposes.

How we store it.For Google Calendar, the OAuth access and refresh tokens are stored server-side only — they are never sent to your browser and never written to logs. For a manual ICS feed URL, only the URL is stored and event contents are fetched on demand. For an uploaded .ics file, the file’s contents are stored so the app can read events from it; the upload is a static snapshot, removed when you disconnect or delete your account.

How to revoke and delete. Disconnect at any time in Profile → Edit → Your Calendar, which immediately deletes the stored tokens or feed URL. You can also revoke Fraghab’s access directly from your Google Account at myaccount.google.com/permissions. All calendar connection data is also removed if you delete your Fraghab account.

Limited Use. Fraghab’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10

Data retention

Your data is retained for as long as your account is active. If you request account deletion, all personal data — including your collection, wearings, community posts, and messages — will be permanently removed within 30 days.

Anonymized, aggregate data that cannot be traced back to an individual may be retained indefinitely for service improvement purposes.

11

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify users through the platform. Continued use of Fraghab after changes take effect constitutes acceptance of the revised policy.

The “Effective” date at the top of this page indicates when this policy was last updated.

12

Contact

Questions about this Privacy Policy or your data? Reach out to us at [email protected].