Effective: April 27, 2026 · Last updated: September 9, 2026
Controller: Sparkwell Studios LLC (Alabama, USA), operating Tonebook. Contact: nestlingapp1@gmail.com
Tonebook is designed to be a private AI-assisted personal-color guide. We do not perform identity recognition, do not store face embeddings or other biometric identifiers, and do not use your photos for model training. Photos are used only to generate your color report; in Live AI mode the selfie is sent to our processor in-flight and is not retained by us. Sim mode never uploads it. Tonebook does process color samples derived from a face, which qualifies as biometric information under some state laws — see our Biometric Information Policy for the full disclosure. You can delete your saved data anytime in Settings.
For users in the EU, EEA, UK, and Switzerland, processing is performed under the lawful basis of your explicit consent (Article 6(1)(a) and Article 9(2)(a) where applicable). You give that consent the first time you enable Live AI mode in Settings, and you can withdraw it at any time by toggling Live AI off, deleting your data in Settings, or emailing the address above. Color analysis is provided on a non-discriminatory basis whether you consent or not — sim mode is fully functional offline.
Where data is transferred to processors in the United States (OpenAI, Supabase, PostHog, Sentry), the transfer relies on the Standard Contractual Clauses adopted by the European Commission, with each processor's published SCCs and data-processing addendum incorporated by reference.
| Data | When | Purpose |
|---|---|---|
| Selfie photo (you upload) | When you tap "Analyze my style" | Generate your AnalysisResult. In sim mode the photo never leaves your device. In live-AI mode — the default once you consent — the photo is sent to our Supabase edge function which calls OpenAI's vision API. We process it in transit and never store it. OpenAI does not train on it, and per their published API policy may retain it for up to 30 days for abuse monitoring before deleting it. |
| Derived colour result | Each live-AI analysis | Your results and cached report are linked to a pseudonymous product-data identifier. Tonebook does not require a named account or an email/password for its core experience. An anonymous authenticated installation can secure backend requests without identifying you by name. Purchase restoration uses a separate purchase identity. Deletion is a request whose server and provider completion must be verified; local deletion alone is not proof. |
| Onboarding answers | During first-run | Personalize your report copy. Stored locally in your device's UserDefaults. |
| Saved reports | Each generated analysis | Stored locally in your device's Application Support directory as Codable JSON. Never uploaded. |
| Anonymous product analytics | Throughout app use | Aggregate metrics (e.g., paywall_viewed, report_viewed) via PostHog. Opt-out anytime in Settings → Send anonymous analytics. |
| Crash reports | When the app crashes | Sent to Sentry to fix bugs. No PII. Opt-out applies. |
| App Store purchase receipts | When you buy | Verified by Apple's StoreKit + RevenueCat for entitlement gating. Standard Apple-mediated flow. |
| Service | Data sent | Purpose |
|---|---|---|
| Apple StoreKit / App Store | Purchase receipts | Subscription billing |
| RevenueCat | Anonymous user ID + entitlement state, and your email address if you gave us one | Subscription dashboard + cross-device entitlement sync. Delete my data clears the email address there; the purchase record itself is kept so you can restore what you paid for. |
| OpenAI (via our Supabase Edge Function, live-AI mode only) | Compressed selfie + onboarding profile JSON | Generate AnalysisResult. Subject to OpenAI's API data policy: not used for training. |
| Supabase | API requests | Edge Function hosting |
| PostHog | Anonymous event names + session ID | Product analytics. Opt-out in Settings. |
| Sentry | Crash stack traces | Crash debugging. Opt-out applies. |
| Disabled services | Nothing in this release | Virtual try-on and third-party product feeds are disabled in this release. Tonebook does not send photos to FASHN.ai or searches to Apify. |
Delete my data clears local content and requests deletion of linked server data and removable provider data. Server and provider work remains pending until verified; an offline, failed or unproved request is not complete. Possession of an email address or knowledge of a purchase identifier alone does not establish ownership of an old installation. If the installation cannot prove ownership, contact nestlingapp1@gmail.com for the available independent verification or support path. Email-only subscriptions have a separate verified-mailbox scope. Purchase history needed to restore purchases and limited suppression records may remain. Suppression records prevent unwanted contact or recreation of erased data; they are not a recovery credential.
The sections above describe the iPhone app. The browser analyzer is a separate service: after you choose analysis, your resized image is sent through Tonebook's Vercel endpoint to OpenAI. It does not require an account or email and does not add the upload to a photo library. The photo-free quiz uses your answers instead. Provider processing and retention are separate from the optional website analytics described below.
The website does not set advertising or cross-site tracking cookies. The same choice controls both analytics services. Both stay off when the preference cannot be saved or a browser privacy signal applies, and neither runs on excluded sensitive routes or queries. Necessary storage, such as your consent preference and the analyzer's abuse-prevention cookie, is separate.
Tonebook is intended for adults 18 and older. The app's first-run consent flow requires explicit confirmation that you are 18+. We do not knowingly collect data from minors.
We will update the "Last updated" date and post the new version at this URL. Material changes will be surfaced in-app on the next launch.
Email: nestlingapp1@gmail.com