Privacy Policy
Tone and Fit is a privacy-first AI color analysis app. There is no account and no login. Your selfie is analysed and discarded, never stored. We do keep two things: anonymous usage events, and, only if you choose to give them, the details described below.
Sections
TL;DR
- No account and no login. An email address is optional, and only if you ask for extra scans.
- Your selfie is sent over an encrypted connection to our analysis service and on to Google's Gemini API, which performs the color analysis. See How your photos are handled.
- We never store your photo. It is processed in memory for your request and discarded — we keep no copy and cannot retrieve it afterwards.
- Usage analytics are our own, not Apple's or Google's. The app sends events to our Cloudflare Worker, tagged with an ID the app generates on first launch. That ID is not your advertising ID and not a hardware identifier. See Analytics.
- If you ask for extra scans you may give us an email address, and optionally a first name, birth year and gender. That is the only personal data we store. See Email and profile details, including how to have it deleted.
- If you join the Android launch list on this website, we store your email address, and a first name and a few survey answers only if you give them. It is used to send your launch email and code. See Android launch list.
- If you choose to connect a TikTok account inside the app to share your color season, that connection follows TikTok's strict OAuth flow and we do not store any TikTok credentials on our servers.
What we collect
Usage analytics, collected by us
The app sends usage events to our own backend, a Cloudflare Worker, and they are stored in Cloudflare KV. Each event carries:
- an app-generated ID, created the first time you open the app and stored on your device. It is not your advertising ID, not your Apple ID or Google account, and not a hardware identifier, so it cannot be matched to you across other apps;
- a session id and a timestamp;
- the app version, the platform, your device model name (for example "Pixel 8" or "iPhone 15"), and the operating system name and version;
- the event name and its properties, for example which screen you opened or that a scan finished.
Events never contain your photo, and they are not attached to the email details below. Deleting the app removes the app-generated ID; a fresh install creates a new one.
Email and profile details (optional)
If you want more scans than the free allowance, the app offers to take an email address before a re-scan. You may also, entirely optionally, give a first name, a birth year and a gender. We store these in Cloudflare KV together with your colour season, how many scans you have used, and a truncated prefix of your IP address.
The truncated IP prefix exists only to catch abuse of the free-scan allowance. It is deliberately too coarse to locate you and is never used for location, advertising or profiling. We do not share any of this with advertisers, data brokers or marketing partners.
To have it deleted, email viral.b.tandel@gmail.com from the address you gave us, and we will delete the record within 30 days.
Email (if you contact us)
If you email us at viral.b.tandel@gmail.com for support or feedback, we store the contents of that email and your email address so we can reply. We do not add it to a marketing list. We delete support emails after 12 months.
What we do not collect
We do not collect any of the following from the app:
- Your name, birth year or gender, unless you choose to give them with the optional email step above
- Your email address, unless you give it for extra scans or write to us
- Your phone number
- Your precise location. Clarity, described below, derives an approximate country from your IP address and nothing finer
- Your contacts
- Your social media handles
- Your photos or any biometric data extracted from them — the photo is sent for analysis and discarded, never kept or filed against you
- Your color season, unless you used the optional email step, in which case it is stored with that record. Otherwise your profile stays on your device.
- Your advertising ID, or any hardware identifier that could be cross-referenced with other apps
How your photos are handled
When you take or upload a selfie for color analysis, in the app or in the web color tool, this is what happens to it:
- The photo is resized on your device, then sent over an encrypted connection (HTTPS) to our analysis service, a Cloudflare Worker.
- The Worker passes it to Google's Gemini API, which performs the color analysis and returns the result. Google processes the image under the Gemini API terms.
- Neither we nor our Worker write the photo to storage — it is processed in memory for your request and discarded. We keep no copy and cannot retrieve it afterwards.
- The web tool additionally runs a local analysis engine inside your browser; if the AI service is unreachable, your result comes from that local engine and the photo never leaves your device at all.
- In the app, saved color profiles are stored on your device. They are included in your device's own backups if you have those switched on, under that platform's backup encryption.
- Photos are never used for advertising, never sold, never used to train our own models, and never attached to analytics events.
Corrections: an earlier version of this page said the analysis ran entirely on device and that no part of the photo left your phone. That was never accurate for the AI analysis, and it was corrected in August 2026. In September 2026 we also corrected the analytics section: it previously credited Apple's App Analytics, when in fact the usage events described above are collected by us through our own Cloudflare Worker. The promises that have not changed: the photo is processed for your request and discarded, never stored, never reused.
Analytics and crash reports
Our funnel analytics are first-party. The app posts events to our Cloudflare Worker and we store them in Cloudflare KV; the fields are listed under Usage analytics, collected by us.
From app version 1.3.3 the app also includes Microsoft Clarity, a session replay SDK, so we can see how screens are scrolled and where people tap and fix confusing layouts. The app's Clarity project runs in strict masking mode: every image and every piece of text on screen is replaced by a placeholder in the recording, so your photo, your color season and anything you type are never part of a replay. Clarity receives the same app-generated ID our own events carry, your device model and operating system version, the names of the screens you visited and the events above (names only, without their properties), and your approximate country derived from your IP address. Microsoft processes this under the Microsoft privacy statement. We use no other third-party analytics SDK: no Firebase, no Mixpanel, no Amplitude, and no advertising SDKs.
Whichever store you installed from, Apple or Google, that store also gives us its own anonymous, aggregate install and crash statistics. Those are produced by the store, not by us, are not linked to you, and are governed by that store's own privacy policy.
No analytics event and no crash report contains your photo or the analysis of it.
TikTok integration
If you choose to use the optional TikTok integration to share your color season as a TikTok video or photo carousel:
- You will be redirected to TikTok's official OAuth login page within Safari or the TikTok app.
- TikTok asks for your permission to grant Tone and Fit limited access to your account: specifically the ability to upload a video or photo to your TikTok content.
- TikTok returns to our app a short-lived access token that lets us upload one piece of content on your behalf.
- Tone and Fit immediately uses that token to upload your content via TikTok's official Content Posting API.
- The token is discarded after use. We do not store it on our servers (we have no servers).
- If we obtain a refresh token (which TikTok issues for repeat-use flows), it is stored only on your device's encrypted keychain. It is never transmitted to us or any third party.
The TikTok integration is entirely optional. The core color analysis features work without it. You can disconnect TikTok at any time from inside the app or by revoking access in your TikTok account settings.
The TikTok integration uses these scopes:
- user.info.basic: required by TikTok to confirm the OAuth grant; gives us your TikTok display name only
- video.upload: lets us upload a single video to your drafts/inbox for you to publish manually
- video.publish: once approved, lets us auto-publish to your public feed (only with your explicit per-post consent)
The web color tool and its email lists
Your photo. The free color analysis tool on this site first measures your coloring in your browser, then sends the photo over an encrypted connection to our Cloudflare Worker, which passes it to Google's Gemini API for the AI analysis. The photo is processed in memory for that one request and discarded: neither we nor our Worker write it to storage, we keep no copy, and we cannot retrieve it afterwards. If the AI service is unreachable, your result comes from the in-browser engine alone and the photo does not leave your device. See How your photos are handled.
Correction (August 2026): this section previously said the tool analyzed your photo entirely in your browser and invited you to confirm it in the Network tab. That described an earlier, browser-only version of the tool and was wrong once the AI analysis shipped. The promise that we never store it is unchanged.
The email feature described next is not currently enabled: the tool's result screen does not ask for an address, and nothing is collected or stored. This section describes how it will work if we switch it on.
Your email address, only if you give it to us. On the tool's result screen you may choose to enter an email address. It goes onto one of two separate lists, and never both:
- "link" (desktop visitors): we send you one transactional email containing the App Store link, and nothing else. The address is deleted within 30 days of that send.
- "android-waitlist" (Android visitors): we keep the address until the Android version launches, send you one email when it does, and delete the address within 30 days of that email.
Either way you get the link or launch email without ticking anything. The separate checkbox for occasional color tips is unticked by default, is optional, and is the only thing that would ever put you on a marketing list. We also store which list you joined, the season the tool gave you, your platform, and the time, so we can send the right email and answer a deletion request. The form is protected by Cloudflare Turnstile, which checks that a human submitted it; Cloudflare's handling of that check is covered by Cloudflare's privacy policy. Email is sent through Resend.
Unsubscribe or delete at any time: email viral.b.tandel@gmail.com with the address you used and we will remove it within 7 days.
Android launch list
The Android page on this website lets you join a list to hear when Tone & Fit launches on Google Play. It is separate from the app and from the web color tool.
What we store when you join. Your email address, which is the only required field. Your first name, only if you type it. Whether you ticked the optional box for occasional color tips, which is unticked by default. The website page you came from, the name of the site that referred you (for example "google.com", never the full link or your search), any campaign tags in the link you followed, the two-letter country Cloudflare reports for your connection, and the time you joined. We do not store your IP address with the record.
The optional questions. After you join you may answer how you found us, whether you know your color season, what you would use the app for, and which phone brand you use, and you may type which features you would like to see and which beauty or style apps you use most. Please do not put anything sensitive in those two boxes; we read them only to decide what to build. Every question can be skipped, and skipping changes nothing about your place on the list or your launch code.
What we use it for. We send you one email when the Android app is live on Google Play, containing your launch code for free access to Premium features. If you ticked color tips, we may also send occasional tips, each with an unsubscribe link. The survey answers help us decide what to build first. We do not sell, rent or share your details with advertisers.
Where it is kept. In a database hosted by Supabase, reached only by our website's server code with a key that never reaches your browser. The form is served through Cloudflare, which sees ordinary request data such as your IP address for security.
How long. Until we send the launch email, then we delete the record within 90 days of that email. If you opted into color tips, we keep your email address and first name until you unsubscribe or ask us to delete them.
Leave the list or delete your details at any time: email viral.b.tandel@gmail.com from the address you used and we will delete the record within 7 days.
Analytics on this website
This website, separate from the app, uses three measurement tools:
- Google Analytics and the Google Ads tag: page views, clicks on our buttons, and whether a visit led to an App Store visit. We do not upload your email address or any other identifier to them.
- Microsoft Clarity: heatmaps and session replays, which show how pages are scrolled and where people tap, so we can fix confusing layouts. Clarity masks text by default, we mark the sign-up form so anything typed there is masked as well, and we do not run Clarity on the colour analysis tool page, where your own photo is on screen. Microsoft processes this under the Microsoft privacy statement.
These tools set their own cookies or local storage in your browser. If your browser sends a Global Privacy Control signal, we do not load Clarity at all. You can also block all three with any tracker-blocking extension or private browsing; nothing on this site stops working without them.
Third-party services
We use these third parties strictly to deliver the app:
- Google Gemini API: performs the colour analysis on the photo our Worker relays to it. Google processes it under the Gemini API terms; inputs are not used to train Google's models, and Google may retain them briefly for abuse monitoring before deletion.
- Cloudflare: runs our backend Worker and stores our analytics events and the optional email records in Cloudflare KV. Cloudflare also sees ordinary request metadata such as IP addresses for security and abuse prevention.
- Microsoft Clarity: heatmaps and session replays on this website, as described in Analytics on this website, and from app version 1.3.3 in the app with strict masking, as described in Analytics and crash reports. Not used on the colour analysis tool page.
- Supabase: hosts the database behind the Android launch list on this website. It holds only the details described in Android launch list.
- RevenueCat: manages purchases, using anonymous purchase data and a per-device identifier.
- Apple App Store and Google Play: distribute the app and handle purchases on their platform. Each store's own privacy policy applies to that interaction.
- TikTok (only if you use the TikTok integration): see above.
We do not share, sell, or rent any data to advertisers, brokers, or marketing platforms. We have no advertising SDKs in the app.
Children's privacy
Tone and Fit is intended for users 13 and older, whichever store you installed it from. We do not knowingly collect any personal information from children under 13. If you believe a child has provided us with information, contact us and we will delete it promptly.
Your rights
We hold very little about you: anonymous usage events, the optional email record if you created one in the app, and your Android launch list entry if you joined it on this website. If you are an EU/UK resident exercising rights under GDPR/UK-GDPR, or a California resident exercising rights under CCPA, here is how the rights apply:
- Right to access: email us and we will send you the optional email record we hold, if you created one. Usage events carry only the app-generated ID, so we cannot tie them to a person on request.
- Right to deletion: email viral.b.tandel@gmail.com and we will delete your email record, including the colour season, scan count and truncated IP prefix stored with it, within 30 days. Android launch list entries are deleted within 7 days of your request. Uninstalling the app removes everything held on the device, including the app-generated analytics ID.
- Right to portability: your color profile and saved palettes can be exported from inside the app at any time as a PDF or CSV.
- Right to opt out of "sale" of personal information: we do not sell any personal information.
- Right to non-discrimination: you receive identical service regardless of which privacy choices you make.
Changes to this policy
If we materially change this policy, we will update the "Last updated" date at the top and post a brief description of the change on the app's release notes. The version of this policy in effect when you used the app applies to that use.
Contact
Questions, concerns, deletion requests, or requests under any privacy law:
Viral Tandel (Founder, Tone and Fit)
Email: viral.b.tandel@gmail.com