Tonebook

Biometric Information Policy

BIPA · CUBI · CCPA-CPRA

Effective: May 2, 2026 · Last updated: August 31, 2026

Controller: Sparkwell Studios LLC (Alabama, USA), operating Tonebook.

Why this page exists

This page satisfies the publicly available retention schedule requirement of the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and the California Consumer Privacy Act / Consumer Privacy Rights Act (CCPA/CPRA) treatment of facial geometry and undertone as biometric / sensitive personal information.

What Tonebook captures

Tonebook captures and processes the following from a selfie you choose to upload:

These reads are derived computationally and are used solely to determine your color season (one of 12) and to generate your palette, hair, and makeup recommendations.

How the processing happens

In sim mode no photo leaves your device. Once you consent to Live AI it becomes the default, and you can switch back to sim mode any time in Settings → Privacy. In Live AI mode your selfie + onboarding answers are sent through our Supabase Edge Function to OpenAI's image-vision API for inference. OpenAI does not use the image for model training and, under its published API policy, may retain it for up to 30 days for abuse monitoring before deletion. Tonebook never stores the raw selfie or any face embedding on our servers.

Disabled services. Virtual try-on and third-party product feeds are disabled in this release. Tonebook does not send photos to FASHN.ai or searches to Apify.

What Tonebook keeps and for how long

DataStoredRetention
Raw selfieOn your device only (Photos library if you tap Save)Until you delete it
Face embedding / geometryNever stored. Processed in-flight only.0 (never persisted)
Derived data: season name, undertone label, confidence scoreTonebook server (Supabase, US-East-1), stored against a random identifier the app generates on your device. Tonebook has no accounts; if you supply an email address it is stored against that same identifier, otherwise nothing here is linked to your name or emailUntil you use Delete my data
Cached full report (if purchased)Tonebook server (Supabase, US-East-1), same random identifierUntil you use Delete my data
Closet items (optional)Your device (App Group container)Until you delete each item, or use Delete my data
Style Check log entriesYour deviceUntil you delete each entry, or use Delete my data

What Tonebook does not do

Your rights

Under BIPA, CUBI, and CCPA/CPRA, you have the right to:

How to delete your data

  1. In Tonebook: Settings → Delete my data — immediately removes all device-local data and requests deletion of the derived result, cached report, email/referral records and linked analytics. If you supplied an email, open the one-time confirmation link we send; without an email, server deletion completes automatically.
  2. By email: nestlingapp1@gmail.com — request access, correction, deletion or written confirmation.

A non-reversible email-suppression record may survive only to honor an earlier unsubscribe, and Apple/RevenueCat purchase history survives so purchases remain restorable. Neither is used for color analysis, advertising or identity recognition.

Disclosure on data we receive from third parties

We do not receive biometric data from any third party. The selfie comes from you, and only you, via the iOS Photos library or camera capture.

Updates to this policy

We will post any material changes here at tonebook.app/biometric with a new effective date. We will not retroactively expand processing scope on existing user data — any expansion requires a fresh consent gate inside the app.

Contact

Questions or to exercise any of the rights above: nestlingapp1@gmail.com. Postal address available on written request to the same email.


This policy is provided in good faith and reflects our actual practices as of the effective date. It is not legal advice and does not waive any rights you may have under federal, state, or local law.