Privacy Policy
Perfume collection and morning pick – Privacy Policy · Deutsche Zusammenfassung · Terms of Use
Privacy Policy
The short version: Scentary needs no account, shows no advertising and contains no analytics SDK. Your collection, diary, ratings, notes, wishlist, bottle photos and settings live in a local database on your phone. When you scan a shelf, ask for the morning pick or use a Pro feature, the data needed for that request is processed by our Cloudflare Worker and by Anthropic. The weather comes from Open-Meteo. An optional profile for friends is stored on our server. Subscriptions run through Apple, Google and RevenueCat.
Who is responsible
Leon Mons, operating Scentary under the Fruhji brand, Ziegeleistraße 1, 49086 Osnabrück, Germany. Contact: scentary@aiphotocleaner.app.
What stays on your device
- Your collection, diary (which fragrance you wore on which day), ratings, notes, wishlist and settings are stored in a local database on your device.
- Bottle photos that the app crops from a scan or that you pick from the camera or the photo library are stored in the app's documents folder on your device. They are never uploaded.
- The city for the weather is stored as its name and coordinates. The app never requests the device location.
- "Delete all data" in the app removes all of this, cancels the reminder and deletes the optional profile (see below).
What is sent, and to whom
- Shelf scan. The photo you scan is sent over an encrypted connection to our Cloudflare Worker, which forwards it to Anthropic's Claude API for recognition and returns the recognised bottles. Fruhji does not write the photo to its database, cache, quota store or application logs. Recognised brands and fragrance names that are not yet in the catalogue are added to the shared catalogue as fragrance data; this contains no personal data. Anthropic normally deletes commercial API inputs and outputs within 30 days; longer storage can apply where law, policy enforcement, a separate agreement or an explicitly used persistent feature requires it. Anthropic states that commercial API data is not used for model training by default.
- Text search. If you search for a fragrance the catalogue does not know, the search text is sent to our Worker and to Anthropic to create the entry. The resulting catalogue entry is stored as fragrance data, not linked to you.
- Morning pick. The names of the fragrances in your collection, the occasions you chose, the season, the current weather (if you set a city) and the app language are sent to our Worker and to Anthropic to generate the suggestion and its reason. No photo and no diary text are included.
- Pro features (blind-buy risk, dupes). The name of the fragrance in question and, for blind-buy risk, the fragrances in your collection are sent to our Worker and to Anthropic. Dupe answers are cached per fragrance and language, not per user. Wardrobe gaps are computed on your device from your shelf and send nothing.
- Weather. The app requests the current weather for the coordinates of your chosen city directly from Open-Meteo (api.open-meteo.com) and looks cities up at geocoding-api.open-meteo.com. Open-Meteo receives your IP address and the coordinates; no key and no account are involved. See Open-Meteo's terms and privacy information.
- Technical request data includes your IP address, a pseudonymous app user ID (also used by RevenueCat), app/platform details and daily quota counts. These data protect the service, verify Pro access and limit AI costs. Per-user quota counters expire after 48 hours; per-route daily totals contain no user identifier.
- Purchases are processed by Apple's App Store or Google Play and by RevenueCat, our subscription-management provider. RevenueCat processes the pseudonymous app user ID, products, transactions and entitlement status. Fruhji does not receive your payment-card details.
Optional profile for friends
You can create a profile to share your shelf with friends. This is optional; every other function works without it. When you create a profile, the following is stored on our Cloudflare server: a handle, a display name, an invite code, a hashed access token, the fragrances on your shelf, one entry per day saying which fragrance you wore, and the friendships you accepted. No email address, no phone number and no password are collected. People who accept your invite code (and whose code you accept) see your handle, display name, shelf and daily wears; nobody else does. There is no public directory and no search for people.
"Delete all data" in the app deletes the profile on the server (handle, display name, invite code, token, shelf, wears and friendships) and then removes it from your device. If the server cannot be reached at that moment, the local data is still removed; email scentary@aiphotocleaner.app and we delete the remaining server-side profile.
What we do not do
- No email collection, no contact upload, no phone-book access.
- No advertising, no ad identifiers, no third-party analytics or tracking SDKs.
- No sale or sharing of personal data with data brokers.
- No access to the device location.
Camera, photos, notifications, sharing and shop links
- Camera and photo library are used only when you start a scan or choose a bottle photo. The permission can be withdrawn in the system settings at any time.
- The morning reminder is scheduled locally on your device; no push-notification server is involved.
- Share cards (today's fragrance, your month) are rendered on your device and handed to the system share sheet. The destination you choose receives the image under its own terms.
- "Where to buy" opens a retailer's search page (for example Douglas, Parfumdreams or Notino) in your browser. Some of these links are affiliate links via Awin; if you buy there, Fruhji may receive a commission. The retailer and Awin process your visit under their own privacy policies. Scentary sells nothing itself.
AI processing and your consent
What is sent: for a shelf scan the photo you choose; for the morning pick and the Pro features the fragrances on your shelf with your ratings and recent wear dates, the occasions you chose, season and weather; for a catalogue search the text you typed; in every case the app language and a pseudonymous, app-generated user ID used for quotas and Pro access. No name, no contacts, no exact location.
Who receives it: our Cloudflare Worker forwards the data to Anthropic PBC (USA), whose Claude API recognises bottles and writes suggestions. Anthropic processes it as our processor under its Commercial Terms and Data Processing Addendum, which commit it to protection equal to this policy, and does not use these inputs to train its models.
Why: solely to recognise bottles, suggest a fragrance, assess blind-buy risk and dupes, and complete the catalogue. Photos are not stored by Fruhji; the results stay on your device.
Your consent: since version 1.0.4 the app asks for your permission before the first photo, shelf or search text is sent, and sends nothing if you decline; the morning pick then comes from an on-device rule. You can withdraw the consent at any time under You, AI processing; the app will then ask again before the next hand-off.
Service providers
We use Cloudflare (request processing, catalogue and profile storage, quotas), Anthropic (recognition and suggestions), Open-Meteo (weather), RevenueCat (subscription status), Apple/Google (payments and the share destination you select) and, when you tap a shop link, the retailer and Awin. Each receives data only for the relevant function. See Anthropic's retention information, Cloudflare's privacy policy, Open-Meteo's terms and RevenueCat's privacy policy.
Legal bases
Processing requested app functions, the optional profile and subscriptions is necessary to provide the service or perform the contract (Article 6(1)(b) GDPR). Security, fraud prevention and proportionate quota controls are based on our legitimate interests (Article 6(1)(f) GDPR). Camera, photo library and notification permissions are used only after your choice and can be withdrawn in system settings.
Your rights
You can delete local app data in the app ("Delete all data") or by deleting the app. This does not automatically delete a server-side profile, store purchase records or provider-side technical records. For access, deletion or other requests under the GDPR (or other applicable privacy laws), contact us at scentary@aiphotocleaner.app. You also have the right to complain to a competent data-protection authority.
Children
Scentary is not directed at children under 16 (or the applicable minimum age in your country) and does not knowingly collect data from them.
Changes
If we change how data is handled, we will update this page and the "last updated" date below.
Deutsche Zusammenfassung
Verantwortlich: Leon Mons (Fruhji), Ziegeleistraße 1, 49086 Osnabrück, scentary@aiphotocleaner.app.
Auf dem Gerät: Sammlung, Tagebuch, Bewertungen, Notizen, Wunschliste, Flaschenfotos, Einstellungen sowie Name und Koordinaten der gewählten Stadt liegen lokal. Die App fragt nie den Gerätestandort ab. „Alle Daten löschen“ entfernt alles davon.
Was gesendet wird: Beim Scannen geht das Foto verschlüsselt über unsere Cloudflare-Serverfunktion an Anthropic; Fruhji speichert das Foto nicht, nur erkannte Marken und Duftnamen kommen als Duftdaten in den gemeinsamen Katalog. Für den Morgenvorschlag und die Pro-Funktionen Blind-Buy-Risiko und Dupes gehen Duftnamen, gewählte Anlässe, Jahreszeit, Wetter und App-Sprache an Anthropic, kein Foto und kein Tagebuchtext; Garderobenlücken werden auf dem Gerät berechnet. Anthropic löscht kommerzielle API-Ein- und Ausgaben in der Regel binnen 30 Tagen und nutzt sie standardmäßig nicht zum Modelltraining. Das Wetter holt die App direkt bei Open-Meteo für die Koordinaten der eingetippten Stadt. Technische Angaben (IP-Adresse, pseudonyme App-User-ID, Plattform, Tageszähler mit 48 Stunden Laufzeit) sichern den Dienst. Käufe laufen über Apple, Google und RevenueCat; Zahlungsdaten erhalten wir nicht.
KI und Zustimmung: Seit Version 1.0.4 fragt die App vor dem ersten Senden von Foto, Regal oder Suchtext um deine Zustimmung und nennt, was an wen geht: über unsere Cloudflare-Serverfunktion an Anthropic PBC (USA), die nach ihren Commercial Terms und dem Data Processing Addendum zu gleichwertigem Schutz verpflichtet ist und diese Eingaben nicht zum Training verwendet. Ohne Zustimmung wird nichts gesendet; unter Du, KI-Verarbeitung kannst du sie jederzeit zurückziehen.
Profil für Freunde (freiwillig): Handle, Anzeigename, Einladungscode, gehashtes Zugriffstoken, die Düfte deines Regals, ein Eintrag pro Tag und deine Freundschaften liegen auf unserem Cloudflare-Server. Keine E-Mail, kein Passwort. Nur Freunde mit gegenseitig angenommenem Einladungscode sehen Regal und Tagebuch. „Alle Daten löschen“ in der App löscht das Profil auch auf dem Server; falls der Server dabei nicht erreichbar war, genügt eine E-Mail.
Sonstiges: Kamera und Fotomediathek nur beim Scannen oder Auswählen eines Flaschenfotos. Die Morgenerinnerung ist eine lokale Mitteilung. Teilen-Karten entstehen auf dem Gerät. „Wo kaufen“ öffnet die Suche eines Händlers im Browser, teils als Awin-Partnerlink mit Provision für Fruhji. Keine Werbung, kein Analyse-SDK, kein Datenverkauf. Rechtsgrundlagen sind Art. 6 Abs. 1 lit. b und f DSGVO. Auskunft, Löschung und Beschwerde bei einer Aufsichtsbehörde stehen dir zu.
Fruhji · Last updated: September 16, 2026