Privacy Policy

Last updated: 23 September 2026

The short version

MyOlfy shows no advertising on its pages and sells no data. A single third-party script is loaded — the Google tag, which serves both Google Ads and Google Analytics, which tells us whether our advertising campaigns bring visitors and whether they then click a buy link; which pages are viewed and how you arrived. Until you accept, it is FORBIDDEN FROM WRITING anything into your browser: no cookie is set, no identifier follows you from page to page, and Google receives only an aggregate measurement. If you accept, the tag then sets the cookies described below. It is the site's only third-party script, and there is no other.

Twelve technical items may nonetheless be written into your browser, and none of the twelve is a cookie: a tab identifier used to count page views, which dies when you close the tab; your "recently viewed" history; your latest searches; a marker recording that you played the trial round of the mini-game, written only if you play it; the three entries of your scent-profile draft, written if you start the welcome flow (the third if you then choose to create an account); a marker that avoids counting a lost welcome flow twice, written once if you are signed in with a recent account; the guided discovery offered to you without an account, written only if you launch it; your refusal of the invitation to Pro, written only if you close it; your reading position on the subscription page, written when you leave or reload it; and the question to olfIA you leave pending when you go off to subscribe. Your history, your searches, the two markers, your refusal and your reading position never leave your browser; the draft and the offered discovery are transmitted only to compose what you ask for, and nothing of them is kept without an account; the pending question is put to olfIA again only if you come back as a subscriber. The reading position and the pending question disappear when you close the tab.

Six cookies do exist, but none of them appears unless you act: a two-letter one if you pick your delivery country, a one-letter one if you answer the question about audience measurement, and the sign-in cookie if you sign in to an account. Further cookies are added to them, written by the Google tag, and only if you have accepted it. They are described below, alongside the other twelve items.

Creating an account changes the picture: your e-mail address, your username and your reviews are then stored on our servers, and your reviews are public under your username.

The rest of this page sets out, one processing activity at a time, what the data is for, the legal ground it rests on, and how long it is kept.

What is written into your browser

Eighteen items in total may be written into your browser by this site, never one more. Twelve of them are not cookies and are written as you browse, without anyone asking you anything: the tab identifier on the very first page, the "recently viewed" history when you open a perfume page, your latest searches when you run one, the mini-game marker when you play the trial round, the three entries of your scent-profile draft when you start the welcome flow (the third if you then choose to create an account), the lost-flow marker when, signed in with a recent account, you have nothing to pick up, the offered guided discovery when you launch it without an account, your refusal of the invitation to Pro when you close it, your reading position when you leave or reload the subscription page, and the question to olfIA when you go off to subscribe from its bubble. The other six, which are cookies, appear only if you choose to make them appear.

A tab identifier (olfy_sid), held in sessionStorage. It is a random value, written on the very first page and without any action from you. It travels with each page view sent to our servers and lets us link together the pages read within a single tab — that is what tells a ten-page visit apart from ten one-page visits. It disappears when the tab is closed and cannot recognise you from one visit to the next. Purpose: the audience measurement described below. Legal ground: our legitimate interest in knowing how our own site is used (Article 6(1)(f) GDPR).

Your "recently viewed" history (olfy_recent), your latest searches (olfy_recent_searches) and the mini-game trial marker (olfy_quiz_demo), held in localStorage. Neither is ever sent to our servers, and neither is tied to an account: they exist purely so that something can be displayed in your own browser. The first two can be emptied at any moment with a "Clear" button — one in the "recently viewed" section, one in the menu that lists your latest searches, where entries can also be removed one by one. Only the last six searches are kept, and a new one pushes out the oldest. None of the three expires automatically; clearing this site's data in your browser removes them. Purpose: displaying the "recently viewed" section, letting you return to a search you have already run, and knowing that the trial round has already been played. Legal ground: none of these ever leaves your browser and each serves only the feature you are using; in so far as they fall within the Regulation at all, they rest on our legitimate interest in making those features work (Article 6(1)(f) GDPR), which you can object to by clearing them.

Your scent-profile draft (olfy.olfactory.draft) and the names of the perfumes it cites (olfy.olfactory.draft.noms), held in localStorage, written when you start the welcome flow — the perfumes you say you love, the one you dislike, those you own, the intensity and the accords you pick. Without an account, they leave your browser in one case only, at your request: when you launch the offered guided discovery, the draft is sent to our servers for the time it takes to compose three suggestions, then forgotten — nothing of it is stored, neither the draft, nor the suggestions, nor anything that identifies you. If you create an account or are signed in, the draft is carried into the log described below, and cleared from your browser. A third entry goes with it, the "pick up on return" mark (olfy.olfactory.draft.import), also in localStorage, which holds only "1": it is set if you choose to create an account at the end of the flow, makes your draft be carried into your account when you come back signed in, and is cleared with it. Without an account it has no automatic expiry; clearing this site's data in your browser removes it. Purpose: letting you go through the flow and a first discovery without an account, and find your answers again if you interrupt it. Legal ground: nothing sent to us without an account is kept, and composing a discovery you ask for is the performance of what you request (Article 6(1)(b) GDPR); carrying the draft into your account falls under the same contract.

The guided discovery offered to you without an account (olfy.olfactory.guest-discovery), held in localStorage, written only if you launch it: the starting perfume or, failing that, your profile, the direction and occasion you chose, and the three suggestions exactly as they were shown to you, with their explanations, and the ones you mark to try. It is sent nowhere: it serves to show it to you again if you come back, for thirty days (after that, the screen offers you a new one), and to replay it into your account if you create one — it is then cleared from your browser. Without an account it has no automatic expiry; clearing this site's data in your browser removes it. Purpose: letting you find your discovery again and keep it if you create an account. Legal ground: none is needed while nothing is transmitted to us; replaying it into your account falls under the contract described below (Article 6(1)(b) GDPR).

The lost-flow marker (olfy.olfactory.draft-lost), held in localStorage, which holds only "1": it is set once per browser, if you are signed in with a recent account and this browser keeps neither a draft nor a discovery to pick up. It serves to count only once, in the measurement of actions described below, a welcome flow started and then lost — and that action is counted only if your scent profile is empty. It is sent nowhere and has no automatic expiry; clearing this site's data in your browser removes it. Purpose: knowing how many welcome flows are lost at the moment of creating an account, without counting the same one twice. Legal ground: our legitimate interest in improving that flow (Article 6(1)(f) GDPR).

Your refusal of the invitation to Pro (olfy_pro_invite_refus), held in localStorage, which holds only "1": it is set only if you close the invitation shown under a perfume page after you have viewed several, and serves to stop showing it to you. It is sent nowhere and has no automatic expiry; clearing this site's data in your browser removes it, and the invitation may then come back. Purpose: respecting your refusal. Legal ground: this item never leaves your browser and serves only to respect your choice; in so far as it falls within the Regulation at all, it rests on our legitimate interest in not asking again what you have declined (Article 6(1)(f) GDPR).

Your reading position on the subscription page (olfy_lecture_plus), held in sessionStorage, written at the moment you leave or reload that page, if you had scrolled down to its story: the page's address, and either the moment of the story you were looking at with four indications of how it was laid out on your screen, or how far you were from the end of the story — nothing else. It is sent nowhere: it serves to put you back in the same place if you reload the page or return to it with your browser's Back or Forward buttons, and it is cleared as soon as it has served, and in any case when you close the tab. Purpose: not losing your place — without it, some browsers, Safari on iPhone among them, put you back in the wrong place on this page, whose story changes height when it animates. Legal ground: this item never leaves your browser and serves only the page you are reading; in so far as it falls within the Regulation at all, it rests on our legitimate interest in making that page work (Article 6(1)(f) GDPR), which you can object to by clearing this site's data in your browser.

The question to olfIA you leave pending (olfy_reprise_olfia), held in sessionStorage, written only when, having reached the limit of questions offered without a subscription, you click to subscribe from olfIA's bubble: the text of your last question, five hundred characters at most, the address of the page where you asked it, a fingerprint of your sign-in session if you were signed in, or of the one you sign in to afterwards, and the time you left it. It is sent nowhere while you are not a subscriber, and the page address only serves to take you back there. If you come back as a subscriber in the same tab within thirty minutes, the site takes you back to that page once, as soon as your subscription is confirmed on your return to the subscription page, and olfIA reads it there and clears it: it receives it as if you had just asked it — the question then follows the processing described below. If you leave the subscription page before your subscription is confirmed there, or if you have switched language in the meantime, olfIA picks it up on the next page where its bubble appears, once your subscription is confirmed. Beyond thirty minutes, it does not ask it again. It is only picked up in the sign-in session where you left it — or, if you left it while not signed in, in the first session the page sees afterwards: another sign-in, a sign-out or an expired session clears it as soon as the page knows, and every question asked to olfIA carries this fingerprint to our server, which refuses to handle it unless it is the current session's — a pending question never passes from one account to another. This fingerprint is a code computed by our servers that changes with each sign-in: it cannot be used to sign in, no one but us can link it to your account, and our server neither keeps it nor passes it on. The question is also cleared the moment you click “Sign out”. It disappears in any case when you close the tab. Purpose: sparing you from typing your question again after subscribing. Legal ground: the performance of what you ask of us (Article 6(1)(b) GDPR).

Your delivery country (olfy_ship_to): a two-letter cookie, set only when you explicitly pick your country in the "Where to buy" section. The automatic detection described below sets no cookie whatsoever. It expires on its own after one year. Purpose: remembering your choice so we need not ask again on every page. Legal ground: your consent, given through that explicit choice (Article 6(1)(a) GDPR) — the cookie exists only if you act, and you withdraw that consent at any time by picking another country or clearing the cookie in your browser settings.

Your answer about audience measurement (olfy_choix): a one-letter cookie, set only when you answer the question shown at the bottom of the page. Until you answer it does not exist — and audience measurement stays switched off: we count nothing before asking you. It expires on its own after one year. Purpose: remembering your answer so we need not ask again. Legal ground: your consent (Article 6(1)(a) GDPR) — you withdraw it at any time by clearing the cookie from your browser settings, which returns you to the state before the question.

Your sign-in session (a cookie named sb-…-auth-token), set by the authentication library at the moment you sign in, never before. Its properties: site-wide scope, sameSite "lax", readable by page code, a maximum lifetime of four hundred days, and splitting across several numbered cookies when its value is long. It is what keeps you signed in; without it, signing in is impossible. Legal ground: performance of the service contract you asked for (Article 6(1)(b) GDPR).

A conversion-measurement cookie, written by the Google tag and only for visitors who have accepted it. Contrary to what one usually assumes of an advertising tracker, it is not set on a Google domain but on OURS: the reference Google publishes files this family of cookies — their names begin with _gcl_ — under “set from the partner domain”, and gives them a lifetime of ninety days. Purpose: tying a visit, and where applicable a click on a buy link, to the advertising campaign that brought you here. Legal ground: your consent (Article 6(1)(a) GDPR). Two audience-measurement cookies, written by the same Google tag and likewise only for visitors who have accepted it: their names begin with _ga, they are set on OUR domain, and Google gives them a lifetime of two years. Purpose: recognising your browser from one page to the next and from one visit to the next, so that visitors are counted rather than page loads, and so that we can see how you arrived. They are not used to identify you by name, and we match them against no account. Legal ground: your consent (Article 6(1)(a) GDPR). You withdraw that consent by clearing this site's cookies from your browser settings, which switches the tag off along with them. We report here what Google documents publicly; the exact names set depend on the route by which you arrived, and we do not guarantee them on Google's behalf.

Beyond those eighteen items: the only third-party script loaded is the Google tag, which serves both Google Ads and Google Analytics, and it is forbidden from writing anything until you have accepted it, no remote font is fetched while you browse — fonts are downloaded when the site is built and then served from our own domain — and the site uses neither IndexedDB nor a service worker.

One exception deserves to be named rather than left to be discovered. On the page that confirms your e-mail address, your browser talks directly to our authentication provider, which then sets a technical anti-bot cookie — on ITS domain, not on ours. We neither set it nor have access to it. It appears on no ordinary reading page of the site.

Your account, profile and contributions

An account stores your e-mail address and your password, the latter hashed by our authentication provider and never readable by us. Your profile may hold, if you fill it in, a username, a country and up to three favourite accords. Your wardrobe records, bottle by bottle, the perfumes you declare owning, wanting, having tried or having finished, with for each one the date you shelved it, the fill level, a personal rating, a personal note, a size and a purchase date if you provide them, plus a log of the days you wore it and, if you say so, the occasion of that wear. You may also declare, bottle by bottle, the occasions you keep it for — “I mostly wear it in the evening” — which makes it rank higher in the daily advice at those moments. Public are: your username, your level, your points total and the NUMBER of bottles you own, shown next to your reviews — level and points are computed from your contributions and your mini-game rounds, and are never stored as such. Your country, your favourite accords and the CONTENTS of your wardrobe — which perfumes, what level, what rating, what wear log, which declared occasions — stay private: they never leave your account. Only the number of bottles owned is visible to others, never which ones. Your profile also holds your subscription status — free or Pro — which we set ourselves and which you cannot change; it stays private and never appears next to your reviews. If you take out the Pro plan, your profile also holds nine billing references: the customer identifier the payment provider assigns to us, your subscription's identifier, its status, the date it began, its renewal date, the date up to which it is paid for, whether or not you have asked for it to stop, and — if you cancel — the reason you tick in its portal, together with the label the provider attaches to that cancellation. The start date is only used to know when to send you the usage tips message. These nine items are written by our server from what the provider reports to it — never by you, never from your browser — and they stay private. One thing alone is made public: the fact that your Pro subscription is active. A “Pro” badge then sits next to your username beside your reviews, your posts and your comments; it disappears when the subscription ends, and no badge is shown for an account without a subscription. The reason FOLLOWS the subscription: if you change your mind, it goes back to empty.

Your contributions are stored and tied to your account: your reviews — overall rating, longevity, projection, position on the feminine-to-masculine scale, written comment — published publicly under your username; your posts in the community space — layerings and discussions —, their comments and your votes on other people's, also published under your username, except that the list of who voted what is never public and is visible to you alone; and your mini-game rounds, of which we keep the perfume drawn, the options you were offered, the number of correct answers and the date played.

Your points and your level are stored nowhere. They are recalculated from your contributions at the moment they are displayed, which keeps them from drifting away from reality.

As soon as you shelve, rate or wear a perfume, your account also keeps a log of those reactions — a perfume you own or want, like or that is not for you, wore on a given day, an accord you say you love or avoid, a merchant offer you open —, each with its date and the gesture that produced it; what your wardrobe, your wear log, your reviews and your favourite accords already said is carried over into it. From that log we compute your scent profile: the accords you love and those you avoid, a maturity level, a summary. We keep a copy of it so as not to recompute it on every page; that copy is rebuilt entirely from the log — plus the one thing it keeps as you declared it, the intensity you pick during calibration (discreet, balanced or assertive) — and does not exist without the log. Your guided discoveries are recorded there in the same way — the starting perfume or, failing that, your profile, the direction and occasion you chose, the context of the moment (the season and the time of day; the delivery country is used to pick the offers shown but is not recorded), the three suggestions with the computed reasons that selected them, a few counters of the computation itself (how many perfumes were examined, how many were set aside and why, the constraints loosened to find the three, and, for each of the three suggestions, whether our partners had an offer for it at the time of the computation — yes, no, or “unknown” when your delivery country is not known; that fact does not record your country), and what you say about them. To this is added, to bound the free plan, a count of your discoveries per day — your account and the time, nothing else — written by our servers only; and a count of the same shape of the explanation writings requested from the model each day (one a day on the free plan), which bounds the cost of that feature. For a Pro subscriber, your account also records what we suggested to you each day — the catalogue perfume of “For you today”, with the computed reason that selected it, the context of the moment (the season, the time of day, the occasion, and the temperature read if the weather was) and what you say about it; those rows are written by our servers, you only change your answer, and you can delete them. And, once a month, a snapshot of your scent profile — its summary, its maturity level, the number of reactions it rested on and, from October 2026, the strength we measured for each of the six accords shown by your profile's figure — is kept to show you how your taste evolves from one month to the next; you can delete those snapshots. Every week, our servers also compose two selections of catalogue perfumes for you — “Your weekly selection” and “Outside your comfort zone” —, each with, for every perfume, the computed reason that selected it, and the moment you opened it; you can delete them. When a month is over and you open it, our servers also compose a recap of that month — the number of your wears, your most-worn perfume, your brand of the month and, when you wore enough perfumes for it to mean something, your dominant accords, a personality label computed from those accords, the size of your rotation, your favourite occasion, your discovery of the month and how your taste evolved; it is composed the same way over a year, without a page for now. You can delete those recaps. If you share a recap, the image is made on your device and goes out through your phone's own means: we never receive it, keep no copy of it, and do not know that you shared it. Your home page also records what its “Made for you” row showed you — the perfume, the computed reason and its rank, day by day —, so as to measure whether our recommendations are followed; those rows are written by our servers, you can delete them, and they are removed after 90 days by the same daily purge. Finally, two preference boxes — the evening reminder and the Sunday digest — record your choice; they are unticked by default, and no message is sent on that account for now: ticking the box records your choice and nothing else. All of this stays private and never leaves your account; deleting the account erases it with the rest.

Purpose: providing the service you asked for — an account, a profile, a wardrobe, the ability to publish reviews, to write in the community space and to play. Legal ground: performance of that contract (Article 6(1)(b) GDPR). Retention: for as long as the account exists; this data is deleted when you ask for your account to be deleted. There is one exception, the “Made for you” log described above: that one does not serve to provide you with the service but to MEASURE whether our recommendations are followed. Its legal ground is therefore our legitimate interest in knowing whether what we suggest is of use to you (Article 6(1)(f) GDPR), you may object to it by writing to us, and it is deleted after 90 days without waiting for your account to be deleted.

Audience measurement

We count page views, and we do it with as little data as we can. The table that records them has exactly five columns: a row identifier, the path of the page viewed, the tab identifier described above, the domain of the site that sent you here — reduced to the bare domain, without the rest of the address — and a timestamp. No IP address, no user agent, no country.

We also keep a tally of page views per day and per country. It is an aggregate: it holds no identifier and no page path, it relates to no one in particular, and it cannot be attached to any visit.

A second table records a few specific actions, and nothing else: the offer page was seen, a plan was picked, a checkout was opened, a frequently asked question was unfolded, the steps of the welcome flow — the calibration of your scent profile, the perfumes you add to your wardrobe —, the opening of a merchant offer, your guided discoveries and your reactions, the days you log wearing a perfume — and the occasion you add or change on it —, your daily discovery cap being reached, the opening of the advice and selections on your personalised home page, and your setting one of those suggestions aside with a “not for me”. It has seven columns: a row identifier, the name of the action, the place on the site it came from, the tab identifier described above, your account when the action concerns one, a timestamp, and a context reduced to a few words drawn from a closed list — the language, your plan, the maturity level of your scent profile, the step or status concerned, the kind of reaction concerned, the partner whose offer was opened, the discovery direction chosen. The action names and the possible places form two closed lists, written into the database itself: nothing else can be stored there. No IP address, no content, no full page address.

For the welcome-flow, scent-adviser, wear-log and personalised-home actions only, your account identifier is added — because the question it answers is «how many people fill their wardrobe and their profile», and a tab is not a person. Subscription-flow actions are never attached to an account: the list of actions that are is closed, written into the code, and the recording route reads your session for those only. If you delete your account, that identifier is erased from these rows, which then point to no one.

These actions follow exactly the same rule as page views: until you have answered the question at the bottom of the page, your browser records nothing. Two rows are exceptions because they come not from your browser but from our own servers, and they point to no one: the actual departure to a merchant — the partner's name, and nothing else: no account, no tab identifier (that column then carries a fixed marker), no country — and the daily cap on discoveries offered to visitors without an account being reached, one row per day at most. Purpose: to know what is actually used, and where journeys break off. Legal ground: our legitimate interest in understanding how our own site is used (Article 6(1)(f) GDPR). Retention: the same as page views, applied by the same automatic purge.

Purpose: knowing what people actually read, so we can decide what to improve. Legal ground: our legitimate interest in understanding the use of our own site (Article 6(1)(f) GDPR). The balancing against your privacy rests not on a declaration but on concrete choices: no cookie, no IP address, no user agent, an identifier that dies with the tab, and no cross-referencing with your account. You may object to this processing by writing to us.

Retention: 6 months for the detailed page views. That limit is not merely announced here: an automatic task runs every day and deletes older rows. The period is defined in a single place in the code — the very place the purge applies — and an automated check fails if this page announces a period the purge does not apply, or if a period the purge does apply is not announced here. The per-day, per-country tally, which relates to no one, is kept with no time limit.

Delivery country and retailer clicks

So that we only offer you retailers who genuinely ship to where you are, and so that displayed amounts appear in the matching currency, our hosting provider derives a country code from your connection and passes it to us in a technical header. Our code neither reads nor stores your IP address, and no third-party geolocation service is called. This country is not attached to page views: the analytics table has no country column at all. Legal ground: our legitimate interest in not sending you to a retailer who will not deliver to you (Article 6(1)(f) GDPR).

When you click through to a retailer, however, we record a row containing a row identifier, the perfume concerned, the retailer, a timestamp, the offer identifier — and the country. This deserves to be said plainly, because it is the one exception: at that specific point, the country is stored row by row. The column intended for a session identifier exists in that table but is left empty, so these clicks are linked to no browsing history.

Purpose: measuring how the links we publish are used and, once affiliation exists, reconciling commissions. Paid links exist today on part of the catalogue. Legal ground: our legitimate interest in measuring and funding the service (Article 6(1)(f) GDPR). Retention: 24 months, which is the commission reconciliation window; the same daily task removes older rows.

If the derived country is wrong — a virtual private network, travel, living abroad — you can correct it yourself from the "Where to buy" section of any perfume page. That choice, and only that choice, sets the two-letter cookie described above; you can replace it by picking another country, or remove it from your browser settings.

What that click sets off elsewhere deserves to be said. A retailer link does not take you straight to the shop: it first passes through the affiliate platform that runs the partnership, which then places cookies on ITS own domain — three of them today, one of which lives two years — so that any purchase can be traced back to the site that sent you. The destination shop places its own in turn, for its own operation such as language or basket. We place none of these, we have no access to them, and none of it happens unless you click. The destination address also carries our publisher identifier and the site name: that is exactly what makes attribution possible, and it is visible in your address bar. Because these cookies are set by third parties on their own domains, they fall under their own privacy policies; you can refuse or delete them from your browser settings, like any third-party cookie, without preventing the shop from working.

Weather, for MyOlfy Plus subscribers

If you subscribe, the home page suggests a bottle from your wardrobe with the current weather in mind, and the subscription page shows you the same card again. To do that we read the approximate position our host already attaches to your visit — the same place as the delivery country above — and we ROUND IT to a grid of roughly twenty-five kilometres before using it. If the host gives no position we fall back on the centre of your country; if it gives no country, or a country we cannot place, the card simply is not shown.

That rounded coordinate is written nowhere: not in the database, not in a log, not in the page served to you. What is held in memory is the weather itself — a temperature and a sky — for the grid square and for the current hour, never for you; a forecast from any other hour is dropped on the very next request.

The forecast comes from the Norwegian Meteorological Institute (api.met.no), which publishes its data under a Creative Commons Attribution 4.0 licence. It is the only recipient of that request, and it receives nothing but the rounded coordinate: not your identity, not the page you are reading, not the contents of your wardrobe. Legal ground: performance of the service contract you asked for (Article 6(1)(b) GDPR).

If you do not subscribe, the request is still made in two cases, and two only. On the subscription page, if you have an account, where the first scene shows you the bottle the card would pick today from YOUR wardrobe: it needs the current weather for that, and it is only shown to people who are not already subscribers. And on the home page one day in seven, if you have an account, where the card of the day is shown to you as an example. Legal ground in both cases: our legitimate interest in showing you what we sell before you pay for it (Article 6(1)(f) GDPR). Outside those two screens, none of these requests is made.

The examples that illustrate the subscription page read nothing about you — not the weather where you are, not your account —, with one exception: the temperature unit they display (°C or °F) follows your country, determined as described above for the delivery country. They are calculated by the site's real features on a sample wardrobe of real bottles from our catalogue. What is composed in them, and what the caption under each example says: that someone owns these bottles (full, never worn, unrated), that they marked some of them as loved in the profile quiz, the day (a rainy autumn morning for the card of the day, an autumn evening for the discoveries and "For you today") and, for how tastes evolve, that they went from some of these bottles to all of them from one month to the next. The perfumes shown are real. If you have an account, some scenes show you your own data instead of the example — your wardrobe, your scent profile, your discoveries, your pick of the day — read for you alone, as on the pages where they live: nothing is written there or passed on to anyone.

Scanning a barcode

When you scan a bottle, the camera image is decoded on your own device: no photo is sent or kept. Only the digits printed under the bars reach us, just long enough to look up the matching perfume. They are neither stored nor tied to you.

Scanning leaves no trace by itself, whether you are signed in or not. We used to keep, for each member, the list of perfumes they had scanned; that library was removed from the site on 4 September 2026 and the matching records were deleted. Whatever you want to keep, you put in your wardrobe yourself — and if, after a verdict, you confirm "I own it and I love it", that gesture, and it alone, puts the bottle in your wardrobe and writes in your taste log a line that says it came from the scan.

If that code doesn't match any perfume yet, you can tell us which one it belongs to. We then keep the code and the perfume you picked, so that a person can check it before linking the two. If you are signed in, that suggestion is tied to your account so we can credit you points once it is validated; otherwise it stays anonymous. Either way, no IP address or session id is recorded.

The e-mails we send

We send the e-mails an account requires, starting with the confirmation of your address. They are not optional: without address confirmation, the account does not work. Purpose: making the account possible and secure. Legal ground: performance of the contract (Article 6(1)(b) GDPR).

We also send a daily mini-game reminder, but only if you ticked the corresponding box — it is unticked by default. When you do, we keep that box and the date of the last message sent, so as not to write to you twice, for as long as the account exists. Legal ground: your consent (Article 6(1)(a) GDPR). You may withdraw it at any time by unticking the box, with no reason to give; withdrawal stops the reminders and does not affect messages already sent.

If you subscribe to Pro, we write to you at the moments that concern your subscription: when you sign up, in the two days before a free trial ends, on each payment, when a payment is declined, on cancellation, when access ends, and — for a yearly subscription — a little over a month before it renews, as a reminder that the renewal can be declined. Those messages depend on no box: they announce a charge, a date or the end of an access, and withholding them would amount to hiding a debit from you. On top of them there is a single message of a different nature — two usage tips sent within the week after you start — which you can stop in one click from the unsubscribe link inside it, or from the matching box on your profile.

So as not to write the same thing twice, we keep a send log: your account identifier, the name of the message, the reference of the subscription or invoice concerned, and the date sent. It holds neither the content of the message, nor your e-mail address, nor any open or click tracking — we measure neither. This log is deleted along with your account. Legal ground: performance of the subscription contract (Article 6(1)(b) GDPR) for the messages that accompany it, and our legitimate interest in not cluttering your inbox (Article 6(1)(f) GDPR) for the log itself.

If you cancel, a screen offers you, before you reach the provider's portal, to write what would have made you stay. The field is optional: writing nothing has no consequence, and the cancellation goes through exactly the same. If you do write, we keep your text and your account identifier — nothing else, neither the e-mail address nor the cancellation date. That text is read only by the publisher, it is published nowhere, and it disappears with your account. Legal ground: our legitimate interest in understanding why the service does not suit you (Article 6(1)(f) GDPR).

Finally, we send a message when you reach a new level tier, again only if you ticked the matching box, offered at sign-up and changeable from your profile — unticked by default, at sign-up as anywhere else. It tells you what that tier unlocks and what the next one opens. When you do, we keep that box and the HIGHEST TIER ALREADY ANNOUNCED, so as not to congratulate you twice for the same one, for as long as the account exists. That marker is not your score: your points and level are still recalculated on demand and never stored. Legal ground: your consent (Article 6(1)(a) GDPR), withdrawable at any time by unticking the box.

No newsletter, no marketing. The technical delivery of e-mails is handled by the provider Resend, whose processing region is Ireland.

Automated moderation and levels

Before anything is stored, reviews and usernames pass through automated moderation that can refuse publication. A refused text is never stored, and therefore never visible.

Here is how it works, since you are entitled to know. It compares your text against a word list, whole word by whole word, after neutralising the commonest spelling dodges; it rests on no profiling whatsoever: neither your behaviour, nor your profile, nor your history, nor your level plays any part in the verdict. No person intervenes before that refusal: the decision is taken by the program alone, at the moment you submit your text. Its consequence is single and immediate — the text is not published — and nothing else reaches you: no suspension, no penalty, no mark left on your account.

The refusal is shown to you immediately, and you can amend your text and try again — the most direct remedy there is, and your contribution comes back to you rather than being lost. If you believe a refusal is unjustified, write to us: your message is read by the publisher, that is, by a person and not by the program. That is how human intervention, the expression of your point of view and the contesting of the decision are obtained. This is therefore automated processing within the meaning of Article 22 GDPR; we take the view that it produces neither legal effects nor similarly significant ones, your text remaining in your hands and open to correction, but we would rather set out that reasoning than settle it silently.

No other automated decision producing legal effects or significantly affecting you is taken about you. Your level, which governs the right to vote and to comment, is recalculated from your contributions and is never stored. Purpose of the mechanism: limiting abuse and fake reviews. Legal ground: our legitimate interest in protecting content quality and the members themselves (Article 6(1)(f) GDPR).

The artificial-intelligence features

Four features of the site were written to rely on Anthropic's programming interface: the OlfIA advisor, which you write messages to; the automatic translation of review comments; the reading of a bottle's label from a photo you take yourself; and the writing of a guided discovery's explanations — for a visitor without an account (their offered discovery), for a free account (one writing a day, that of its discovery) and for a subscriber (no cap). When one of these features is active, only the item concerned is sent — your message, the review text, the photo you have just taken, or the facts of a discovery: the names of the three perfumes chosen and of the starting perfume, their accords, the direction you chose, among those accords the ones your profile likes and the ones that are new to it, the family a perfume shares with the starting one, the mention that none of the accords you avoid is in it when that is the case, the season, the time of day and the occasion you chose — never your e-mail address, never your browsing history, never your identifier. Each written explanation is kept in a cache that carries only the perfume, the role, the language, a fingerprint of the facts that produced it, the model used and the number of tokens consumed — with nothing that identifies you: two members with the same facts receive the same text.

Two exceptions. The first concerns Pro subscribers only: when you ask OlfIA Pro a question, a BOUNDED summary of your wardrobe travels with your message — without it the adviser could not take into account what you already own. That summary carries the NUMBER of bottles you own, at most a hundred of them — their brand, their name and, since 10 September 2026, the page our catalogue gives them (the page identifier, its accords, seasons and occasions as we describe them), nothing of what you say about them —, your dominant accords, the seasons your bottles cover and, for those where you declared it, the occasion you keep the bottle for. It NEVER carries your personal ratings, your notes, your fill levels, bottle sizes, purchase dates, your wear log, your wishlist, or any identifier. The second, since 10 September 2026, concerns every signed-in member, free or Pro: the readable summary of your scent profile travels with your question — at most three accords you love, three you avoid, your intensity preference, your favourite seasons, your signature and the name of your maturity level — never the reaction log itself, nor the numeric vector of your profile, nor the count of your signals. A Pro subscriber also sends the perfumes their latest guided discoveries suggested, with what they said about them (to try — a perfume you mark that way also joins your wishlist —, tried and liked, tried and not for you, not interested), at most thirty. A visitor without an account sends their message and nothing else, exactly as before. The same exception applies to the writing of a subscriber's guided-discovery explanations: it receives, on top of the discovery's facts, the same bounded list of owned bottles (brand and name, at most a hundred) and the perfumes their latest discoveries suggested, with what they said about them (to try, tried and liked, tried and not for them, not interested) — at most thirty. A free account and a visitor without an account send the discovery's facts and nothing else.

The OlfIA advisor, review translation, label reading from a photo and the writing of a guided discovery's explanations are active today. Legal ground: our legitimate interest in providing the feature you have just asked for (Article 6(1)(f) GDPR) — nothing is sent without an action on your part. Our provider publicly documents that images sent to it are ephemeral, deleted once processed, and not used to train its models; we report that documentation, we do not guarantee it in its place. The retention policy for text is a separate matter and falls under the transfer safeguards discussed below.

The advisor, when it runs, keeps a count of the questions asked per session identifier, in order to bound the use and the cost of that feature; the same table keeps a GLOBAL count, with no identifier of any kind, of the calls made to the model each day by all the artificial-intelligence features described above — advisor messages, photo readings, explanation writings —, which switches those features off when the day exceeds the measure of the previous ones. Legal ground: our legitimate interest in protecting the service from abuse (Article 6(1)(f) GDPR). Retention of that counter: 30 days, applied by the same automatic purge as the two periods above. Since 10 September 2026, the advisor also measures, for each question from a member, how many perfumes of the catalogue it set aside from the selection it shows the model and why (a bottle you own, a perfume you set aside during a discovery, a perfume very close to a bottle you own, an accord your profile avoids) — your tier (free account or subscriber) and numbers, with no identifier, kept 6 months by the same purge — to check that this selection does not close in too much. Since 11 September 2026 it measures, in the same way, the SIZE of what is sent to the model for each question — your tier, the number of tokens sent and received, and how many of your bottles travelled with the question, still with no identifier and kept 6 months — in order to watch its cost. The guided discovery offered to visitors without an account is bounded the same way, by a global count of the discoveries composed per day: one timestamped row per discovery, with no identifier of any kind, which relates to no one — a visitor's profile is composed in memory for the duration of the response and is stored nowhere. Same legal ground, same 30-day retention, same purge. Each explanation writing also leaves a measurement row with no identifier of any kind — the tier (visitor, free account, subscriber), the tokens consumed, whether it was served from the cache or by the model, and the labels the revalidation refused —, kept 6 months, to follow the cost and the quality of that feature; the alert it may raise on our side is likewise a row without identifier, kept 6 months.

Who processes this data for us, and where

Your reviews and your username are public: they appear on the site and are visible to everyone. This is the only case in which what you write travels beyond our technical providers.

Apart from that, your data is disclosed only to the technical providers the site needs in order to run, each acting on our behalf. Vercel Inc. hosts the site; the functions that build the pages run in Frankfurt, Germany. Supabase Inc. provides the database and authentication; the database at rest is hosted with Amazon Web Services in Ireland. Resend delivers e-mail, also from Ireland. Anthropic provides the OlfIA advisor, review translation, label reading from a photo and the writing of a guided discovery's explanations. Cloudflare sits in the technical chain of some of these providers. The Norwegian Meteorological Institute supplies the forecast described above, and it is OUR SERVER that queries it: your IP address never reaches it, and it receives nothing but a coordinate rounded to roughly twenty-five kilometres. Stripe, Inc. processes subscription payments. When you subscribe, it is ITS page that collects your banking details: your card number never passes through our servers and we never see it — none of our pages carries a payment field. It receives your e-mail address, your payment method, and the billing name and address if you provide them; on our side we keep only the references described above. Google finally receives what its tag reports, and two cases must be told apart. If you have NOT accepted: the page being viewed, in aggregate form, with no cookie and no identifier following you — Google cannot tie two of your visits together. If you HAVE accepted: added to that are how you arrived and an identifier that recognises your browser from one visit to the next, together with the fact that a buy link was clicked. It receives this on two counts: audience measurement and advertising. It is the only recipient of this kind, and there is no other recipient at all: we do not sell or rent any data.

Vercel, Supabase and Anthropic are companies subject to the law of the United States, even where the servers they allocate to us stand in Europe: your data may therefore be accessible from the United States. We treat this as a disclosure of data abroad, and the country of destination to be stated under Article 19 of the revised Swiss Federal Act on Data Protection is the United States of America, alongside Germany and Ireland where the servers are located. Stripe, Inc. is likewise subject to the law of the United States, and that is where your payment data is held. The same applies to Google, to which the tag reports an aggregate measurement from the moment you arrive, and more than that if you have accepted it.

We will not claim on this page that those transfers are covered by any particular safeguard until we have documented it provider by provider. As things stand we can therefore assert neither that an adequacy decision covers these disclosures, nor that a set of standard contractual clauses has been signed and filed for each of these providers. The applicable safeguards — standard contractual clauses, an adequacy decision, a certification — have to be gathered and named at this very spot. We would rather flag the work still outstanding than copy out a reassuring formula.

Article 13(1)(f) GDPR and Article 19(4) of the Swiss Federal Act require those safeguards to be named here and a means of obtaining a copy of them to be given to you. That means is the following: write to contact@myolfy.com, and you will receive a copy of the safeguards actually in force or, failing that, the exact state of this work on the date of your request. As soon as they are in place they will be named in this section, and the date at the top of the page will change.

How long we keep what

A summary of the periods stated in the sections above: detailed page views, 6 months; retailer clicks, 24 months; the OlfIA advisor usage counter, 30 days; the global count of guided discoveries composed for visitors without an account, 30 days; the explanation writer's measurements and alerts, with no identifier, 6 months; the measure of the perfumes set aside from the selection shown to the OlfIA advisor, with no identifier, 6 months; the measure of the size of what is sent to the OlfIA advisor, with no identifier, 6 months; what the “Made for you” row of your home page showed you, 90 days; the per-day, per-country view tally, no time limit, because it relates to no one. The first eight are applied by an automatic daily purge, and not merely announced on this page.

Account, profile, wardrobe and wear log, reviews, community posts and comments, mini-game rounds, reaction log, scent profile, guided discoveries, daily suggestions, weekly selections, recaps and monthly snapshots of the scent profile are kept for as long as the account exists, and deleted when you ask for the account to be deleted. The delivery-country cookie exists only if you chose a country: you can change that choice, or clear the cookie from your browser.

Apart from these periods and the lifetime of the sign-in cookie stated above, no other period is announced on this page. If some new category of data were to be collected, its retention period would be added here before the collection began.

What you must provide, and what is optional

Reading the site requires no account, no address and no form. You are asked one question, at the bottom of the page: the one about audience measurement. You may answer no, or not answer at all — either way the site stays fully readable, and nothing is counted.

To create an account, the e-mail address and the password are indispensable — without them no account can exist or be secured, and sign-up fails. That is a contractual requirement, not a statutory one. To publish a review, a username is required: there has to be a displayable identity next to the text, and we refuse to put a fragment of an e-mail address there instead.

Everything else is optional: country, favourite accords, wardrobe and wear log, the daily reminder box, the level-up notice box. Leaving them blank has no consequence other than doing without the matching features — the country in your profile, for instance, is what picks the retailers who ship to you when you have made no explicit choice.

The country your hosting provider derives is not up to you; the explicit choice that corrects it is optional.

Your rights, and how to use them

You have the right to access your data, to have it rectified, to have it erased, to obtain restriction of its processing, to object to the processing we base on our legitimate interest — audience measurement, country derivation, retailer clicks, advisor quota, measurement of our recommendations — and to receive the data you provided in a machine-readable format so you can take it elsewhere (portability).

Where processing rests on your consent — which is the case for the daily mini-game reminder, the level-up notice and the delivery-country cookie — you may withdraw it at any time, as easily as you gave it, without affecting what was done before the withdrawal. Audience measurement rests on our legitimate interest instead (see its section): the right that applies there is the right to object, and the banner lets you exercise it in one click.

Some of these rights are exercised directly, without writing to us, which is by far the quickest route: your profile can be read and edited at any time from your account; your wardrobe can be edited bottle by bottle, emptied, and its wear log cleared, from the "My wardrobe" page; your review can be edited and deleted from the perfume page itself; your posts and comments can be deleted from the page they live on, and your posts also from "My posts" on your profile — deleting a post takes its comments and votes with it; the reminder and level-up boxes can be unticked; the "recently viewed" history and your recent searches are emptied with one button in your browser; your delivery country can be changed, or left unset.

For everything else — full access, portability, restriction, objection, deletion of the account and its data, and a copy of the safeguards framing disclosures abroad — write to contact@myolfy.com. Deleting the account removes the account, the profile, the wardrobe and its wear log, the reaction log, the scent profile, the guided discoveries, the daily suggestions, the weekly selections, the recaps and the profile snapshots, what the “Made for you” row showed you, the reviews, the community posts and comments, and the mini-game rounds; if a Pro subscription is running, it is cancelled immediately with the payment provider, so that nothing further is charged. We answer within the one-month period the Regulation provides.

One point about objecting to the audience measurement is worth making: it rests on no cookie and on no data that identifies you. Closing the tab is enough to make the tab identifier disappear, and clearing this site's data in your browser removes it too.

Complaining to a supervisory authority

If you consider that your data is not being handled lawfully, you may lodge a complaint with a supervisory authority, whether or not you have raised the matter with us. Writing to us first is not a precondition, but it is usually the fastest way to get something fixed.

As the site is published from Switzerland, the competent Swiss authority is the Federal Data Protection and Information Commissioner.

If you live in the European Union or the European Economic Area, you may approach the data protection authority of your own country: that of your habitual residence, of your place of work, or of the place where you believe the infringement occurred.

What this site does not do

These statements were checked against the code; they are not intentions. No advertising is displayed on our pages, no data is sold or rented, and no social network button or embed appears. One advertising tracker exists — the Google tag, which serves both Google Ads and Google Analytics — and it is loaded for every visitor, but it writes nothing until you have accepted; once you have, it sets its own cookies — on OUR domain, not on Google's, as explained above.

Affiliate links are live on some perfume pages (ANITA & ZAHA, Amazon, FragranceNet, MicroPerfumes). They are marked as such on the page where they appear, and the affiliate disclosure page gives the detail.

Changes to this text

This policy describes how the site actually behaves as at the date shown at the top of the page. The rule we hold ourselves to is a simple one: if the behaviour of the site changes, this text changes with it, and never the other way round. Any new feature processing data not described here will be added to this page before it goes live — the artificial-intelligence features, described on this page before they were switched on, are the working example of that rule.

The date of the latest revision appears at the top of this page. We do not quietly alter a statement while leaving the date untouched. The date shown at the top is the one that counts: it is written in a single place, and this sentence does not repeat it.

Who is responsible for your data

The controller is Dewis Sauteur, a private individual resident in Switzerland, who publishes myolfy.com. A person, not a company, is therefore accountable for your data under the GDPR and under the Swiss Federal Act on Data Protection. For any question, and to exercise your rights: contact@myolfy.com.

No data protection officer has been appointed. The site is run by one person, none of the data described on this page falls within the special categories of Article 9 GDPR, and its audience measurement is cut back to plain counting: the conditions that would make such an appointment mandatory do not appear to be met. Your requests therefore reach the publisher directly, at the address above.

No representative in the European Union under Article 27 GDPR has been appointed to date. The site is bilingual and does address visitors in the Union, so we would rather write this down than leave it unsaid. The point is still to be settled, and this page will state the outcome.

The sections below are organised by processing activity. For each one you will find, in the same place, what we do, with which data, on which legal ground, and for how long.

This site uses cookies. Learn more