Privacy Policy

Tone & Fit is designed with your privacy in mind. Here's how we handle your data.

Effective Date: May 8, 2026

Information Collection

Tone & Fit does not require account creation. We do not collect your name, phone number, or any other personally identifying information beyond what is described below.

The data we may collect during your use of the app is limited to:

Your selfie photo, used solely to perform color analysis (see "Face Data Collection and Use" below).
Your email address, only if you choose to provide it after your first free scan in order to extend your free-scan allotment (see "Email Collection" below).
Anonymous purchase identifiers managed by Apple and RevenueCat, used to track your one-time purchase entitlement.

Face Data Collection and Use

Tone & Fit uses your selfie photo to perform AI-driven color analysis (skin tone, undertone, contrast, and seasonal palette identification). This is the only purpose for which your face data is collected.

Storage on your device

Your scan photo and analysis results are stored locally on your device in secure local storage. Face data is retained on your device only until you take a new scan (which replaces the previous one), reset the app, or delete the app. You can delete all stored face data at any time by deleting the app from your device or by contacting us at the email address below.

Server-side processing

When you take a scan, your photo is transmitted to our backend (hosted on Cloudflare Workers), which acts as a relay only — your face data is NOT retained, persisted, logged, or stored on our servers in any form. The photo is forwarded to Google's Gemini API for visual analysis, and only the categorical results (e.g. "Soft Summer", "cool undertone") are returned and stored on your device. The image itself is discarded server-side as soon as the relay completes.

Third-party sharing

We share your face data only with Google's Gemini API, and only for the purpose of performing color analysis. Per Google's published Gemini API data policy for paid usage, API inputs (including images) are not used to train Google's models, and may be retained by Google for up to 24 hours for abuse monitoring before being permanently deleted. We do not share your face data with any other third party.

We do not sell, rent, or otherwise share your face data with advertisers, data brokers, analytics providers, or any other parties.

Retention summary

On our servers (Cloudflare Workers): not retained at all (relay only).
On Google's servers (Gemini API): up to 24 hours for abuse monitoring, then permanently deleted; never used to train models.
On your device: until you take a new scan, reset the app, or delete the app.

Email Collection

If you choose to provide your email address after your first free scan in order to extend your free-scan allotment, your email is stored on our backend (Cloudflare KV, a key-value storage service) for the sole purpose of remembering that you have extended your free allotment.

We do not share your email with advertisers, data brokers, marketing partners, or any other third party. We do not use your email to send you marketing communications unless you separately opt in. You can request deletion of your email at any time by contacting us at the email address at the bottom of this policy.

Data Usage & Storage

Your color analysis results are stored locally on your device so you can access them later. These results never leave your device unless you choose to share them.

We do not link your analysis results to any user identity on our servers. We do not use your data for marketing, profiling, or any purpose other than what is described in this policy.

Third-Party Services

The app uses the following third-party services:

Google Gemini API — for AI-driven color analysis of your selfie photo. Per Google's published API data policy for paid usage, inputs are not used for model training and may be retained up to 24 hours for abuse monitoring before deletion. See Google's Gemini API terms.
Cloudflare Workers — for hosting our backend relay. Cloudflare may collect basic request metadata (such as IP addresses) for security and abuse-prevention purposes; we do not retain your photos or face data on Cloudflare. See Cloudflare's privacy policy.
RevenueCat — for managing in-app purchases. RevenueCat may collect anonymous purchase data and a per-device identifier. See their privacy policy.
Apple App Store — for processing payments. Apple's standard terms apply.

We do not sell, rent, or share your data with any other third parties.

Children's Privacy

Tone & Fit does not knowingly collect any information from children under the age of 13. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.

Policy Updates

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated effective date. We encourage you to review this policy periodically.

Questions?

If you have any questions or concerns about this Privacy Policy, please contact us at:

viral.b.tandel@gmail.com