Effective: April 27, 2026 · Last updated: August 31, 2026
Controller: Sparkwell Studios LLC (Alabama, USA), operating Tonebook. Contact: nestlingapp1@gmail.com
Tonebook is designed to be a private AI-assisted personal-color guide. We do not perform identity recognition, do not store face embeddings or other biometric identifiers, and do not use your photos for model training. Photos are used only to generate your color report; in Live AI mode the selfie is sent to our processor in-flight and is not retained by us. Sim mode never uploads it. Tonebook does process color samples derived from a face, which qualifies as biometric information under some state laws — see our Biometric Information Policy for the full disclosure. You can delete your saved data anytime in Settings.
For users in the EU, EEA, UK, and Switzerland, processing is performed under the lawful basis of your explicit consent (Article 6(1)(a) and Article 9(2)(a) where applicable). You give that consent the first time you enable Live AI mode in Settings, and you can withdraw it at any time by toggling Live AI off, deleting your data in Settings, or emailing the address above. Color analysis is provided on a non-discriminatory basis whether you consent or not — sim mode is fully functional offline.
Where data is transferred to processors in the United States (OpenAI, Supabase, PostHog, Sentry), the transfer relies on the Standard Contractual Clauses adopted by the European Commission, with each processor's published SCCs and data-processing addendum incorporated by reference.
| Data | When | Purpose |
|---|---|---|
| Selfie photo (you upload) | When you tap "Analyze my style" | Generate your AnalysisResult. In sim mode the photo never leaves your device. In live-AI mode — the default once you consent — the photo is sent to our Supabase edge function which calls OpenAI's vision API. We process it in transit and never store it. OpenAI does not train on it, and per their published API policy may retain it for up to 30 days for abuse monitoring before deleting it. |
| Derived colour result | Each live-AI analysis | Your season, undertone and a confidence score are stored on our servers against a random identifier the app generates on your device. Tonebook has no accounts and no login. If you give us an email address — for your report, or for reminders — it is stored against that same identifier; if you never give one, nothing here is linked to your name or email. If you buy the full report, its contents are cached against the same identifier. All of it is removed when you use Delete my data. |
| Onboarding answers | During first-run | Personalize your report copy. Stored locally in your device's UserDefaults. |
| Saved reports | Each generated analysis | Stored locally in your device's Application Support directory as Codable JSON. Never uploaded. |
| Anonymous product analytics | Throughout app use | Aggregate metrics (e.g., paywall_viewed, report_viewed) via PostHog. Opt-out anytime in Settings → Send anonymous analytics. |
| Crash reports | When the app crashes | Sent to Sentry to fix bugs. No PII. Opt-out applies. |
| App Store purchase receipts | When you buy | Verified by Apple's StoreKit + RevenueCat for entitlement gating. Standard Apple-mediated flow. |
| Service | Data sent | Purpose |
|---|---|---|
| Apple StoreKit / App Store | Purchase receipts | Subscription billing |
| RevenueCat | Anonymous user ID + entitlement state, and your email address if you gave us one | Subscription dashboard + cross-device entitlement sync. Delete my data clears the email address there; the purchase record itself is kept so you can restore what you paid for. |
| OpenAI (via our Supabase Edge Function, live-AI mode only) | Compressed selfie + onboarding profile JSON | Generate AnalysisResult. Subject to OpenAI's API data policy: not used for training. |
| Supabase | API requests | Edge Function hosting |
| PostHog | Anonymous event names + session ID | Product analytics. Opt-out in Settings. |
| Sentry | Crash stack traces | Crash debugging. Opt-out applies. |
| Disabled services | Nothing in this release | Virtual try-on and third-party product feeds are disabled in this release. Tonebook does not send photos to FASHN.ai or searches to Apify. |
For users in jurisdictions with formal data-rights frameworks (CCPA, GDPR, PIPEDA, etc.), the in-app delete-my-data flow is our Right-to-Erasure mechanism: it wipes everything held on your device and requests removal of the derived colour result, cached full report, email and referral records, and the linked PostHog person and events. If you gave Tonebook an email address, open the one-time confirmation link sent to that address to finish server deletion; without an email, server deletion completes automatically. Two things deliberately survive: a non-reversible unsubscribe-suppression record if you had opted out of email, and purchase history with Apple and RevenueCat so you keep what you paid for. The suppression record cannot be used to recover your email. Analytics erasure is queued to a trusted worker and the transient work order is deleted when complete. Offline or incomplete requests are retried automatically. Versions before 2.3.7 erased on-device data only; update and tap Delete my data again, or email nestlingapp1@gmail.com, to remove the older server-side copy. The confirmation email and the confirmation page are available in English, German, Spanish, French, Italian, Japanese, Korean, Brazilian Portuguese, and Simplified and Traditional Chinese; other languages are served in English.
The sections above describe the Tonebook iOS app. On tonebook.app, Vercel Web Analytics is active and PostHog web analytics is currently disabled:
The website sets no advertising or cross-site tracking cookies and currently sends no analytics events to PostHog.
Tonebook is intended for adults 18 and older. The app's first-run consent flow requires explicit confirmation that you are 18+. We do not knowingly collect data from minors.
We will update the "Last updated" date and post the new version at this URL. Material changes will be surfaced in-app on the next launch.
Email: nestlingapp1@gmail.com