Privacy
What we store, what we don't.
ScentScout is a small personal project. It doesn't need your name, your email or an account to do its job.
ScentScout+ and fragrance ratings
Purchase checks read your saved Passport, collection feedback and fragrance ratings on our server. Your confirmed hunt prompts, names, preferred, required and avoided notes, reference scents, seasons, occasions, bottle filters, budget, retailer results and check times are stored privately with your account. Daily retailer checks send only fragrance names and houses to the shopping provider, not your email, account ID or saved hunt text. You can pause or remove hunts in ScentScout+.
When you use the prompt tools, Lovable AI processes your question and the conversation you submit, relevant catalog descriptions, and evidence from your saved taste and collection needed to explain purchase advice. We do not automatically include your email, account ID, or full Passport in the model request. Details you type are part of the prompt. AI requests and answers are stored privately for delivery, expire after ten minutes, and are removed by an hourly cleanup. Request text is cleared when its answer is saved. Confirmed hunt prompts remain with the hunt until you remove it. Request counts are stored per member to limit usage. Lovable and its model provider may retain operational logs under their own policies. Manual bottle checks do not call this AI service.
Fragrance ratings stay private unless you turn on Scent Twins sharing. Joining lets participating ScentScout+ members see your public profile and ratings used to explain matches and discoveries. You can remove individual ratings or turn off matching in Account or Scent Twins. This does not make your private Passport or Wardrobe public.
Stripe processes subscription payments. We send your account email and an account reference to Stripe and store the linked customer ID, subscription status and billing-period dates to manage access. Payment-card details are handled by Stripe. Your active ScentScout+ badge is public; your billing records and complimentary-access reason are private.
Your quiz answers
The ten answers you give in Discover live in your browser's local storage. They are used to calculate the published base fit on your device and to prefill the quiz if you come back later. Your AI or Classic choice and discovery level are stored alongside them. When you choose AI, those fixed quiz choices are included in the bounded server ranking request described below. Classic matching does not make an AI request.
When you visit /results, your core answer tokens: things like climate, projection, budget and what to avoid: are placed in the URL as short codes so the page can rank the catalog and so a link is shareable. Because they are in the URL, those tokens travel in a normal HTTP request and can appear in whatever request logs the hosting and database providers keep under their own policies. Assume the URL you see is what those providers see.
Your optional free-text note is deliberately not placed in the URL, sent to any ScentScout table or added to any request ScentScout makes. It is written to your browser's local storage only, and is shown on /results only when the local answers still match the ones in the URL. Copying a results link to a friend never surfaces your note.
Anonymous feedback
The Results helpfulness and catalog-correction forms are anonymous and user-initiated. You choose to send it using the buttons on the results page or on a fragrance profile.
The site_feedback table contains only the following fields for each submission:
- the kind of feedback (results or catalog),
- for results feedback: whether it was helpful (yes / no) and, if not, a bounded reason from a short fixed list,
- for catalog feedback: the catalog fragrance ID being reported, a bounded reason from a short fixed list and an optional correction note (500 character cap),
- a server timestamp.
The feedback table does not contain your quiz answers, your free-text note, the result URL, search queries, IP address, user agent, referrer or any persistent cross-site identifier alongside feedback. Please don't include personal information in the optional correction note.
Public feedback access is insert-only. Submissions cannot be read back through the public API.
Scent Passport accounts
Accounts are optional. The quiz, results and browse experience never require one. You can only ever save a Scent Passport by explicitly pressing Save my Passport after taking the quiz.
When you choose to save, we use a separate authentication project to sign you in with an email magic link. That auth service stores the email address you sign in with. It is the only auth provider currently enabled.
A save link returns with a random one-time callback nonce so an old or load-only sign-in cannot authorize a Passport overwrite. The matching save intent stays in this browser for at most one hour. The nonce is not an email, account ID or auth token and is removed from the address bar after the Passport page opens, though it can appear in ordinary request logs used to deliver that page.
Your saved row in the private scent_passports table contains only:
- your fixed-choice quiz slugs (occasions, climate, familiar smells and so on),
- your AI or Classic preference and discovery level,
- derived dominant families and two 0 to 100 balance summaries (freshness, warmth),
- the catalog IDs of your current top matches,
- a schema version, quiz version and timestamps.
Your optional free-text note is never written to the Passport table. The Passport table does not contain your result URL, referrer, IP address or user agent. Row-level security restricts every read and write to your own row.
You can delete the saved row at any time by pressing Delete saved Passport on the Passport page. That is separate from clearing your browser-local quiz answers, which you do from your browser settings.
Member profiles and website reviews
Your Account page lets you claim a unique username and optionally add a display name, short bio and profile photo. These profile fields are public, including when shown beside a review and in the member directory. Your email, full saved Passport and Wardrobe remain private. Profile and review records use an account ID to link them; public records do not include your email.
Uploaded photos are cropped to a square and re-encoded as WebP in your browser before upload. We keep one current photo per account in public storage. Replacing it overwrites that object. You can remove the photo from Account; already cached copies may take time to disappear. Do not upload a photo you do not want other visitors to see.
Website reviews are separate from anonymous feedback. A signed-in member with a username can publish one review containing a 1 to 5 star rating, 20 to 1,200 characters of text and timestamps. Reviews, reviewer names and photos are public. The overall count and rating are calculated from those reviews. You can edit or delete your own review from Reviews. Only your account can edit your profile or review. Members can publicly like reviews and post replies of 2 to 600 characters. Likes link to a member account, and replies show the author's public profile and timestamp. Members can remove their own likes and replies. Moderators can delete reviews and replies, and a private moderation record retains the deleted content and moderator account ID. Deleting a review also removes its likes and replies. Public review and reply submissions are checked for profanity and hateful language before being published.
Scent result sharing is optional and off by default. From Account, you can publish a snapshot containing freshness and warmth scores, up to three scent families, up to six saved fragrance matches and quiz and sharing dates. This does not publish your full quiz answers, email or Wardrobe. A new quiz does not automatically update the public snapshot. Use Update from latest Passport to replace it or Stop sharing to remove it. Previously viewed or copied information may still exist outside ScentScout.
Match Feedback
Match Feedback is optional. When signed in, you can mark a fragrance as Interested, Tried it, Own it or Not for me from a result card or a fragrance page. Signals are private to your account and can be changed or cleared at any time.
Each saved row in the private fragrance_signals table contains only:
- your account user ID,
- the local ScentScout catalog ID of the fragrance,
- one of the four fixed signal values above,
- server timestamps.
The Match Feedback table does not contain free text, ratings, quiz answers, your optional note, a result URL, search terms, referrers, IP addresses, user agents or any external identifier. Row-level security restricts every read and write to your own rows.
If you are signed out and choose a signal, we park just that fragrance ID and signal in your browser and ask for a sign-in link so we can save it after you sign in. Nothing is written server-side until you complete that sign-in link.
When you are signed in and have marked at least one fragrance with Interested, Own it or Not for me, your Match Feedback adjusts the Results ranking within an asymmetric bounded range of −10 to +8 points on top of the base fit. The adjustment reads only structured catalog attributes: family buckets, notes, tags, personality, occasions, seasons and projection. Price, gender, product names, brand names, descriptions and any free text are never used. Taste Tuning runs locally in your browser. Raw Taste Tuning signals and numeric deltas are not included in an AI request, but their local effect can change which eligible candidates reach the shortlist before AI ordering.
Interested is a light boost, Own it a stronger boost and Not for me reduces similar scents. Tried it is treated as experience context only and contributes zero to ranking. Fragrances marked Own it stay taste references but are removed from new recommendations. Your quiz avoid picks stay absolute: no feedback can re-add anything you asked to avoid. Signed-out visitors and signed-in users with no qualifying signals receive the same base fits and eligible shortlist from the published scorer before AI ordering. A valid AI response may change the final display order.
Your Wardrobe at /wardrobe is a private view of the same fragrance_signals rows. It does not create a second collection table and only you can see it.
Scout a fragrance
The /scout page keeps typed search text in this browser; search terms never enter the URL. A direct Scout link may carry only a catalog ID to preselect that exact record. Opening the bare /scout route starts with a blank search.
The Request a missing fragrance form is anonymous and user-initiated. Nothing is sent until you press Request this fragrance. On submit we insert only the trimmed 2 to 160 character text you typed plus a timestamp into the same insert-only site_feedback table used elsewhere. Your search query, IP address, user agent, referrer, saved Passport and Match Feedback are never included. We do not ask for an email address.
The optional Live US price scout panel is click-to-run. Selecting a fragrance updates its catalog ID in the URL but does not run a price lookup. The browser calls the same-origin price endpoint only after you press Check live prices. When you press it, the only field sent to that endpoint is the selected catalog fragrance ID. Your typed search text, brand or fragrance name are never sent by the browser. The API key stays on the server. A short-window rate-limit uses an HMAC of your request IP, never the raw IP, as a counter key. Those counters do not contain search terms or raw identifiers.
AI ranking on Results
When you select AI matching before the quiz, Results uses Lovable AI to compare a fragrance shortlist with your quiz preferences and return the recommendation order. If you choose Classic matching, Results uses our fit order without requesting AI. The page waits for the response and checks it before revealing your matches. If AI is unavailable, invalid or rate limited, Results reveals a clearly labeled Classic ranking from the standard scorer instead. Base fit scores are calculated separately using the published preference weights.
The call happens on our server rather than in your browser. The request contains only two things: your ten fixed choice quiz answers as short slugs, and bounded facts about up to 12 catalog records rebuilt from our own data (family, notes, tags, seasons, occasions, projection, audience and coarse price band). Each candidate is identified by an opaque position token, never by its name, brand or catalog ID. The request contains no identity or raw account rows: no optional free text, email, name, account or user ID, auth token, referrer, analytics or session ID, saved Passport rows, Wardrobe history or raw Taste Tuning signals and deltas. It also excludes catalog descriptions, URLs, retailer data, exact prices and live prices. The candidate set can still reflect local Taste Tuning performed before the shortlist was built. ScentScout application code does not log AI request or response bodies.
The model returns only an ordering of the tokens we supplied. Every explanation you read is written locally from catalog data. The call has no browsing or retrieval tool, and its prompt instructs the model to use only the supplied facts rather than prestige, popularity or outside knowledge. Use is limited to three AI rankings per ten minutes and twenty per UTC day per caller, counted against a daily-rotating HMAC of a valid request IP rather than the IP itself, plus a site-wide daily cap. If a caller key cannot be established or the durable limit store is unreachable, no AI call happens. Quota rows older than two days are eligible for bounded maintenance cleanup; exact removal timing is not guaranteed.
When any limit or error is hit, Results falls back to the Classic scorer and says so. After a validated AI ranking or a Show another replacement in either mode, a versioned order snapshot may remain in this browser for up to one hour so Passport can offer the same matches. It includes an answer signature, catalog version, ordered catalog IDs, source, expiry, random nonce and, for signed-in results, a hashed local account binding. It does not store a raw user ID, email, free text or Taste Tuning rows. Passport revalidates it before saving; an expired or mismatched continuation requires review instead of silently saving a different Classic order.
Lovable AI processes the ranking call and the underlying model provider may keep operational logs under its own policies. Lovable's optional AI debugging setting can also retain request and response data when enabled. That provider-side handling is separate from ScentScout application logging.
Analytics and tracking
ScentScout ships a tiny privacy-safe analytics module. It records only a fixed 16-event list: quiz started, quiz completed, Passport saved, Wardrobe signal saved, Scout price check used, missing fragrance requested, auth completed, auth error, save error, home quiz clicked, home Scout clicked, Results Passport opened, Results Scout opened, AI rank used, AI rank fallback and AI rank rate limited. Each event carries up to four fields: the event name, the route pathname, a short random per-tab session ID and an optional fixed coarse error code used only for error events. It never stores query strings, fragrance IDs or names, emails, account IDs, quiz answers, Passport data, Wardrobe choices, raw searches, prices, retailer destinations, referrers, device fingerprints or raw error messages. There are no advertising pixels, no marketing analytics and no third-party trackers embedded in the site.
The hosting and database providers that run this site may keep operational and security logs: for example, ordinary HTTP access logs including request URLs, IP addresses and user agents: under their own policies. ScentScout does not read, join or profile users against those logs.
External search buttons open a neutral search on the target site (Amazon, FragranceX for availability; Fragrantica for reference research). What happens after you leave is up to that site.
Clearing your data
To wipe your saved quiz and any locally remembered feedback flags, clear this site's data in your browser's settings.