Tonebook

Privacy Policy

Tonebook for iOS

Effective: April 27, 2026 · Last updated: April 27, 2026

In one paragraph

Tonebook is designed to be a private AI personal-color coach. We do not perform facial recognition, do not store biometric identifiers, and do not use your photos for model training by default. Photos are used only to generate your color report and are deleted from our servers after processing in live-AI mode (default sim mode never uploads them at all). You can delete your saved data anytime in Settings.

What we collect

DataWhenPurpose
Selfie photo (you upload)When you tap "Analyze my style"Generate your AnalysisResult. In default mock mode the photo never leaves your device. In live-AI mode, the photo is sent to our Supabase edge function which calls OpenAI's vision API — the photo is processed in transit and not retained server-side.
Onboarding answersDuring first-runPersonalize your report copy. Stored locally in your device's UserDefaults.
Saved reportsEach generated analysisStored locally in your device's Application Support directory as Codable JSON. Never uploaded.
Anonymous product analyticsThroughout app useAggregate metrics (e.g., paywall_viewed, report_viewed) via PostHog. Opt-out anytime in Settings → Send anonymous analytics.
Crash reportsWhen the app crashesSent to Sentry to fix bugs. No PII. Opt-out applies.
App Store purchase receiptsWhen you buyVerified by Apple's StoreKit + RevenueCat for entitlement gating. Standard Apple-mediated flow.

What we DON'T do

Third-party services

ServiceData sentPurpose
Apple StoreKit / App StorePurchase receiptsSubscription billing
RevenueCatAnonymous user ID + entitlement stateSubscription dashboard + cross-device entitlement sync
OpenAI (via our Supabase Edge Function, live-AI mode only)Compressed selfie + onboarding profile JSONGenerate AnalysisResult. Subject to OpenAI's API data policy: not used for training.
SupabaseAPI requestsEdge Function hosting
PostHogAnonymous event names + session IDProduct analytics. Opt-out in Settings.
SentryCrash stack tracesCrash debugging. Opt-out applies.

Your rights

For users in jurisdictions with formal data-rights frameworks (CCPA, GDPR, PIPEDA, etc.), the in-app delete-my-data flow performs a complete erasure equivalent to a Right-to-Erasure request.

Data retention

Children

Tonebook is intended for adults 18 and older. The app's first-run consent flow requires explicit confirmation that you are 18+. We do not knowingly collect data from minors.

Changes to this policy

We will update the "Last updated" date and post the new version at this URL. Material changes will be surfaced in-app on the next launch.

Contact

Email: hello@tonebook.app


← All legal documents