FVAFragrance Visual AuthenticationReturn to site

Project policy

Privacy Policy

Effective August 15, 2026Policy version 2026-08-15-v3
Important: This is a practical pilot policy, not individualized legal advice or a promise that the operator is immune from claims. Qualified counsel should review it before paid operation or public publication of user-submitted images.

What this policy covers

This policy explains the current pilot’s handling of public visit metrics, access requests, profiles, invitation activity, reference photographs, bottle-check records, consent evidence, abuse controls, and administrative audit records.

Information collected

  • Public metrics: a random first-party browser identifier, visit timestamps, and visit count. Raw IP addresses are not placed in the visitor counter.
  • Traffic attribution: when available, the site temporarily stores standard campaign labels, the referring domain, and the first FVA page visited in first-party browser storage. The full external referring URL is not retained. Attribution is attached to an access request so the operator can measure which outreach efforts lead to participation.
  • Access requests: first and last name, email, display name, participation interests, community experience, potential bottle contributions, optional details, and the limited traffic attribution described above. The request form does not collect a phone number, address, ZIP or postal code, government ID, birthdate, or selfie.
  • Activated profiles: signed-in email, display name, private participant name, and activation time.
  • Contributions: bottle and packaging photos, fragrance details, optional production year and batch code, submission status, reviewer notes, and audit history.
  • Checks and credits: profile balance, credit ledger, selected fragrance details, and a completed-preview record. In the current check preview, selected photos remain in the browser and are not uploaded.
  • Security and consent: rate-limit fingerprints, block records, user-agent text, policy version, timestamp, and the action consented to. If optional Turnstile protection is enabled, the access-request process also handles its short-lived spam-check token and result.

Purposes and legal grounds

We use data to provide requested pilot functions, manage invitation-only access, prevent duplicate-email profiles and abusive activity, review and organize reference images, award credits, respond to requests, maintain security and auditability, and comply with law. Depending on applicable law, processing is based on your consent, performance of requested services, legitimate interests in operating and securing the pilot, and legal obligations.

Sharing and processors

FVA does not sell personal information, run behavioral advertising, or provide submitted photographs for unrelated generative-AI training. Data may be processed by infrastructure, authentication, email-delivery, and optional spam-protection providers needed to run the service; disclosed to authorized reviewers under role restrictions; or disclosed when lawfully required. Current infrastructure includes Cloudflare-hosted storage and database services, ChatGPT sign-in, and Resend email delivery. Cloudflare Turnstile is an optional spam-protection service and is used only when configured.

Photo handling and visibility

Contribution photos are stored in a private image vault and are accessible only to authorized reviewer roles. Accepted bottle-only references may later be displayed or used for comparison as described in the photo license. Contributors’ legal names, email addresses, and supply-chain information are not intended for public display. Do not include faces, people, home interiors, receipts, shipping labels, or other personal information in an image.

Retention

Local draft photos remain on the contributor’s device until submission, manual clearing, or browser-storage removal. Server upload drafts are marked to expire after seven days; operational cleanup and backups may not be immediate. Submitted photos, review records, accepted references, credit ledgers, consent evidence, and security records are retained while reasonably needed for the library, account integrity, disputes, audit, or legal obligations. We will refine and publish fixed deletion schedules before a paid launch. You may request deletion, but accepted-reference licenses, fraud-prevention records, backups, and legally required records may limit or delay deletion.

Security

We use private object storage, role-based access, single-use email-bound invitation codes, privacy-preserving spam checks, rate limits, and administrative audit records. Invited-email activation confirms control of the invited communication channel but does not establish a participant’s legal identity. No internet service can promise perfect security. Please report suspected access promptly and avoid submitting sensitive material.

Your choices and rights

You may ask to access, correct, export, restrict, object to, or delete information, or withdraw consent for future processing. Applicable law may provide additional rights and a right to complain to a regulator. Withdrawing consent does not invalidate earlier lawful processing and may prevent continued participation. Use the contact process and identify the email associated with the account.

International and children’s data

The pilot is operated in the United States. Service providers may process data in the United States or other locations. The contribution and account service is not offered to children; account activation requires confirmation that the user is at least 18.

Created by Jeff Harrington Jr. · © 2026 Fragrance Visual AuthenticationVisitors since counter launch —·Verified reference submissions —
TermsPrivacyPhoto licenseSubmission rulesCopyrightAccessibilityContact

Independent research pilot · Visual comparisons are informational and never guarantee authenticity · No affiliation with or endorsement by any fragrance house is claimed.