Privacy Policy
This Privacy Policy explains how Doribleg Trade Ltd (“we”, “us”) processes personal data when you use the Tonelle website and mobile apps (together, the “Service”). We designed Tonelle so that we process as little personal data as possible: we do not store your photos, we do not require an account, and your results are kept on your own device.
This policy applies to users in the European Economic Area (EEA) and elsewhere. If you are in Türkiye, please also read our KVKK Privacy Notice (Aydınlatma Metni).
01. Who is responsible for your data
The controller of your personal data is Doribleg Trade Ltd, Suite 10550, 5 Brayford Square, London E1 0SG, United Kingdom (registration no. 17049929).
For any privacy question or request, contact us at privacy@tonelleapp.com.
02. What data we process
- Facial image (selfie): the photo you take or upload for analysis. Because it shows your face, we treat it with the protection given to special categories of data, even though we never use it to identify you.
- Analysis results: derived information such as undertone, skin depth, contrast, face and eye shape, colour season and suggested shades. These are generated from your photo and stored only on your device.
- Questionnaire answers: skin type, eye colour, occasion, budget and experience level, sent together with your photo to tailor results.
- Anonymous app user ID: a random identifier created on your device, used only to check whether you have an active Premium subscription.
- Purchase and subscription status: whether a subscription or one-time purchase is active, its product, and renewal dates. Payment details are handled by Apple or Google; we never see your card details.
- Technical data: IP address, browser or device type, operating system, and request timestamps, used for security, rate limiting and troubleshooting.
- Communications: your email address and message if you contact us.
We do not ask for your name, email or phone number to use the Service, and we do not rate or score your appearance.
03. Why we process it and on what legal basis
| Analysing your facial image to determine your colouring and colour season, and (Premium) generating makeup previews on your photo | Your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)). You give it by ticking the consent box before the analysis; you can withdraw it at any time. |
|---|---|
| Providing the Service you requested, including personalised recommendations from your questionnaire answers and unlocking Premium features | Performance of a contract (Art. 6(1)(b)). |
| Checking your subscription status through RevenueCat with your anonymous app user ID | Performance of a contract (Art. 6(1)(b)). |
| Keeping the Service secure, preventing abuse and fraud, rate limiting and fixing errors | Our legitimate interests in operating a safe and reliable service (Art. 6(1)(f)). |
| Answering your messages and requests | Performance of a contract or our legitimate interests (Art. 6(1)(b) or (f)). |
| Keeping records required by tax, accounting or consumer protection law | Compliance with legal obligations (Art. 6(1)(c)). |
If you do not give explicit consent, we cannot analyse your photo. You can still browse the website and read about the Service.
04. How your photo is handled
- Your photo is reduced in size on your device and sent over an encrypted connection (HTTPS) to our server.
- Our server forwards it to our AI provider to create your analysis or makeup preview, and discards it as soon as the request finishes, typically within seconds.
- We do not write your photo to any database, file storage or log.
- We instruct our AI providers not to use your photo to train their models and choose provider settings that minimise or disable data retention where available.
- Makeup previews generated for you are returned to your device and are not stored by us.
05. Data stored on your device
The website stores your latest analysis results, your anonymous app user ID and your language preference in your browser’s local storage or in a strictly necessary cookie (tonelle_locale). Your photo is never stored there. You can delete this data at any time with “Delete my data” on the results page or by clearing your browser data.
We currently do not use advertising or analytics cookies. If we introduce them, we will ask for your consent first where required.
06. Who we share data with
We use carefully selected service providers (processors) who act only on our instructions under data processing agreements:
| Vercel Inc. (USA; servers in the EU, Frankfurt) | Website and API hosting; receives technical data and transiently the photo in transit. |
|---|---|
| Google LLC (Gemini API, USA) | Performs the colour and skin analysis of your photo and creates the makeup previews. On the paid API tier your data is not used to train models. |
| Paddle.com Market Ltd (United Kingdom) | Processes website purchases as Merchant of Record: payment, invoicing, tax and refunds. |
| RevenueCat, Inc. (USA) | Manages subscription status linked to your anonymous app user ID. |
For website purchases Paddle, and for in-app purchases Apple Inc. (App Store) and Google LLC (Google Play), process your payment details as independent controllers under their own privacy policies. Your card details never reach us.
We may disclose data to authorities where required by law. We never sell your personal data.
07. International transfers
Some of our providers are located in, or may access data from, the United States or other countries outside the EEA. Where a country does not have an adequacy decision, we rely on the EU–US Data Privacy Framework (where the provider is certified) or on the European Commission’s Standard Contractual Clauses (GDPR Art. 46(2)(c)), together with additional safeguards such as encryption in transit and not storing photos. You can request a copy of the relevant safeguards from us.
08. How long we keep data
| Facial image | Not stored by us. Discarded when the analysis or preview request ends. |
|---|---|
| Analysis results | Only on your device, until you delete them. |
| Technical logs (without photos) | Up to 30 days, unless needed longer to investigate a security incident. |
| Rate-limiting counters (IP address or app user ID) | Up to 1 hour. |
| Subscription records (RevenueCat) | While your subscription is active and as required by law afterwards. |
| Support emails | Up to 2 years after the conversation ends. |
09. Automated processing
The analysis is performed automatically by AI. It produces cosmetic suggestions only and does not make decisions that have legal or similarly significant effects on you (GDPR Art. 22). AI-generated images are clearly labelled as such.
10. Your rights
Depending on where you live, you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing, including processing based on legitimate interests;
- data portability;
- withdraw your consent at any time, without affecting processing carried out before withdrawal;
- lodge a complaint with a data protection authority, in particular in the EU country where you live or work.
To exercise your rights, email privacy@tonelleapp.com. Because we do not store photos or accounts, most of your data is on your device and you can delete it yourself. We will reply within one month.
11. Age limit
The Service is intended for people aged 16 and over. We do not knowingly process data of children under 16. If you believe a child has used the Service, contact us and we will help remove any data.
12. Security
We use encryption in transit, strict access controls, minimal data collection and no storage of photos to protect your data. No system is completely secure, but we work to keep risks as low as possible.
13. Changes to this policy
We may update this policy when the Service or the law changes. We will show the date of the latest version at the top of this page and, for significant changes, inform you in the app or on the website.