Skip to content
Back to home

Privacy Policy

Last updated: 24 March 2026

Privacy questions? privacy@scentgraph.app

1. Who We Are

ScentGraph ("the Service") is operated by ScentGraph Digital Pty Ltd (ACN 696 194 564, ABN 26 696 194 564), registered in Western Australia ("we", "us", "our", "ScentGraph"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Service at scentgraph.app and app.scentgraph.app.

ScentGraph Digital Pty Ltd works with ITBG Labs Pty Ltd on product development and technical infrastructure. ITBG Labs does not independently collect or control your personal data. ScentGraph Digital Pty Ltd remains the sole data controller for all information collected through the Service.

We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). For users in the EU/EEA/UK, we also comply with the General Data Protection Regulation (GDPR). For users in the United States, we align with California Consumer Privacy Act (CCPA) expectations.

2. Information We Collect

Account information

Email address, username, and display name when you create an account. You may optionally provide a bio, location, avatar, and social media handles.

Waitlist information

If you join our waitlist, we collect your email address, referral source, and any optional preferences you provide (experience level, goals). This data is used to notify you when the Service launches and to help us understand our audience.

Collection and activity data

Data you voluntarily provide: fragrance collection, reviews, ratings, wishlist items, Scent of the Day logs, notes, and preferences.

Usage data (essential)

Basic logging required to operate and secure the Service: authentication events, error logs, and page requests. This is necessary for the functioning of the Service and is processed under a legitimate interest basis.

Analytics data (optional, consent-based)

If you consent to analytics cookies, we may collect data about how you use the Service (pages visited, features used, session duration). We may associate analytics events with your account to improve features, understand retention, and perform cohort analysis. We use privacy-respecting tools (such as Plausible or similar) wherever possible. This data is never used to serve third-party advertisements.

AI-powered features

If you use the AI recommendation assistant, we collect and store the following data to provide personalized fragrance recommendations:

  • Conversation messages: Your full chat history with the AI assistant is stored in our database and retained indefinitely to improve your recommendation quality over time.
  • Taste preferences: Preferences you express during conversations (favourite notes, avoided accords, occasion preferences) are extracted and stored in your scent profile.
  • Recommendation feedback: When the AI recommends a fragrance, we track whether you responded positively, neutrally, or negatively to improve future suggestions.

When you send a message, your conversation context is sent to Anthropic (Claude) via Vercel AI Gateway for processing. We do not send your email address, password, or payment information to AI providers. Anthropic does not use your data to train their models under our data processing agreement.

You can delete your AI chat history and all associated data by deleting your account via Settings > Your Data. There is a 30-day grace period before permanent deletion.

Referral data

If you participate in our referral programme, we collect and store: referral codes used, referrer and referee relationships, qualification progress (collection activity and SOTD logs), reward status, and the IP address associated with referral sign-ups (for anti-fraud purposes). IP addresses used for referral deduplication are not linked to your browsing activity.

Device and browser data

Basic device information (browser type, operating system, screen resolution) for compatibility and performance.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Personalise your experience (recommendations based on your collection and graph)
  • Display your public profile, collection, reviews, and wishlist to other users
  • Send service-related communications (account verification, launch notifications, security alerts)
  • Send marketing communications where you have opted in (see Section 5)
  • Improve the Service through analytics where you have consented
  • Provide AI-powered fragrance recommendations and assistance
  • Operate referral programmes and prevent abuse
  • Process payments and manage subscriptions
  • Respond to support enquiries
  • Comply with legal obligations
  • Create anonymised and aggregated datasets for analytics, trend reporting, market insights, and research
  • Train, improve, and develop our recommendation algorithms, AI features, and machine learning models using anonymised and aggregated data (reviews, ratings, collection trends, and usage patterns)
  • Display sponsored content and personalised recommendations from brand partners (see Section 7)

We do not sell your personal information to third parties.

We may share anonymised and aggregated data (such as trend reports, audience insights, and market statistics) with brand partners and advertisers. This data cannot be used to identify individual users. If our practices around personal data change materially, we will provide clear notice and opt-out rights before any change occurs.

4. Legal Basis for Processing (EU/EEA/UK Users)

If you are located in the EU, EEA, or UK, we process your data under the following legal bases:

  • Contract: Processing necessary to provide the Service (account management, data storage, core features)
  • Legitimate interests: Essential logging, security, service improvements, and fraud prevention
  • Consent: Analytics cookies, marketing communications, and cross-promotional emails. You may withdraw consent at any time.

5. Marketing and Communications

Marketing emails (newsletters, product updates, data-driven roundups, cross-promotions) are opt-in only. You will only receive marketing from us if you have actively consented.

With your consent, we may use your contact details to inform you about other products and services operated by ScentGraph Digital Pty Ltd or closely related entities, provided these communications are reasonably related (e.g., apps and tools for productivity, analytics, or lifestyle).

You can unsubscribe from marketing at any time via the link in any email or through your account settings. Unsubscribing from marketing does not affect service-related communications (security alerts, account notifications).

6. Cookies and Tracking

Essential cookies

Required for the Service to function: authentication, session management, and security. These cannot be disabled while using the Service.

Analytics cookies (optional)

Enabled only with your consent via our cookie banner. Used to understand how the Service is used. When consented, analytics events may be associated with your account for product improvement and cohort analysis. We do not use analytics data to serve third-party advertisements.

Third-party cookies

We do not serve advertising cookies. However, if you click an affiliate link to a retailer, that retailer or their affiliate network may set cookies or use tracking identifiers to attribute sales. See Section 7 for details.

You can manage cookie preferences through the consent banner on our website or by contacting us.

7. Data Sharing and Third Parties

Service providers (sub-processors)

We use third-party providers to operate the Service. These providers process data on our behalf and are contractually bound to protect it. Our current sub-processors include:

  • Supabase Inc. (USA): Database hosting, authentication, and file storage
  • Vercel Inc. (USA): Application hosting and content delivery
  • Stripe, Inc. (USA): Payment processing and subscription management. Stripe processes your payment card details directly; we do not store card numbers on our servers. See Stripe's Privacy Policy.
  • Loops Inc. (USA): Transactional and marketing email delivery. We share your email address, username, and subscription status with Loops to send service communications and marketing emails you have opted into.
  • Anthropic PBC (USA): AI language model provider (Claude) used to power the recommendation assistant via Vercel AI Gateway. Your conversation context is sent to Anthropic for processing. They do not use your data to train models under our data processing agreement.
  • Upstash Inc. (USA): Rate limiting and caching infrastructure

We may update our sub-processors from time to time. Material changes will be reflected in this policy.

Other users

Your public profile, collection, reviews, and wishlist are visible to other ScentGraph users. Private notes remain private.

Affiliate partners and retailers

When you click an affiliate link on ScentGraph, the destination retailer or affiliate network may collect data via cookies or tracking identifiers to attribute sales. We do not share your ScentGraph account information, email address, or personal data with affiliate partners. The retailer's own privacy policy governs their data collection.

ITBG Labs

We work with ITBG Labs Pty Ltd on product development and technical infrastructure. Where necessary for these purposes, ITBG Labs may access data as a processor acting on our instructions. All such access is subject to this Privacy Policy and applicable data protection law. Anonymised and aggregated data (such as case study metrics) may be shared with ITBG Labs.

Advertising and brand partners

We may partner with fragrance brands and other companies to display sponsored content and personalised recommendations. We do not share your personal information with advertisers. Advertisers may select audience segments (e.g., "users interested in oud fragrances"), and we deliver content to matching users without revealing individual identities.

Where we use hashed or pseudonymised identifiers for audience targeting on third-party advertising platforms (such as lookalike audiences), we will only do so where you have provided consent or where permitted under applicable law. You may opt out of personalised advertising through your account settings.

Business transfers

In the event of a merger, acquisition, corporate restructuring, or sale of assets, your data may be transferred to the successor entity. We will notify you via email or in-app notification and the successor will be bound by this Privacy Policy until a new policy is published.

Legal requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

We do not sell personal information to third parties.

8. Data Storage and Security

Your data is stored using industry-standard cloud infrastructure with encrypted connections (HTTPS/TLS), row-level security policies, and secure authentication.

While we take reasonable precautions, no electronic storage method is 100% secure. We encourage you to use a strong, unique password.

9. International Data Transfers

ScentGraph is operated from Perth, Western Australia. We may store and process data in Australia, the United States, the European Union, and other locations where our service providers operate.

We take reasonable steps to ensure that recipients of personal data protect it consistently with this Policy and the Australian Privacy Principles. For EU/EEA/UK users, transfers are safeguarded using standard contractual clauses or equivalent mechanisms.

10. Your Rights

All users

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and associated data
  • Opt out of analytics cookies and marketing communications

Australian users (APPs)

  • Access and correction rights under Australian Privacy Principles 12 and 13
  • Right to complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs

EU/EEA/UK users (GDPR)

  • Right of access, rectification, and erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local supervisory authority

US users

  • You may contact us to request information about our data practices
  • You may opt out of marketing communications at any time
  • We do not sell personal information. If this changes, we will provide opt-out rights.

To exercise any rights, contact privacy@scentgraph.app.

11. Data Retention

We retain account data for as long as your account is active. If you delete your account, we will remove your personal information within 30 days, except where retention is required by law or for legitimate purposes (e.g., anonymised analytics data, aggregated datasets).

Anonymised and aggregated data that can no longer be linked to an individual is not subject to deletion requests and may be retained indefinitely for analytics, research, and product improvement.

Waitlist email addresses are retained until the Service launches and you have been notified. You may request removal at any time by emailing privacy@scentgraph.app.

If we permanently discontinue the Service, we will provide at least 30 days' notice and a reasonable window to export your data before deletion.

12. Children's Privacy

ScentGraph is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us and we will delete it.

13. Changes to This Policy

We may update this Policy from time to time. When we make significant changes, we will notify users through the Service or via email. The date at the top indicates when this Policy was last revised.

14. Contact

ScentGraph Digital Pty Ltd (ACN 696 194 564), Perth, Western Australia