Legal
Privacy Policy
This policy explains what Silloria collects, why, who we share it with, and what you can do about it. It covers silloria.com and our iOS and Android apps.
1. Who is responsible
Silloria is operated by Impresa Digital Marketing, LLC, which is the controller responsible for the personal information described in this policy.
Impresa Digital Marketing, LLC
539 W. Commerce St #6052, Dallas, TX 75208, United States
info@silloria.com
2. What we collect
Information you give us
- Account. Your email address and a password, or, if you sign in with Google, your email address and basic profile details from that account. We never see your Google password. Passwords are hashed by our authentication provider and we cannot read them.
- Profile. Username, display name, avatar, bio and any social links you choose to add.
- Wardrobe and taste. Fragrances you save, own, try or wish for, your personal ratings, wear logs and the preferences behind your recommendations.
- Community contributions. Reviews, ratings, votes, comments, reactions, follows and bookmarks.
- Creator uploads. Images and video you post, and the fragrances you tag in them.
- Messages. Direct messages you send other users. These are stored so they can be delivered and shown to you. They are not end-to-end encrypted, and staff may access them to investigate a report or a safety issue.
- Correspondence. What you send us by email.
Information collected automatically
- Device and browser. Device type, browser, viewport size, operating system, and whether you use the installed app.
- Usage. Pages viewed, searches, and interactions such as voting or saving. Search queries are stripped of email addresses and long numeric strings before they are sent to analytics.
- Log and technical data. IP address, request times and error reports, which our hosting and error monitoring providers process to keep the Service running and to diagnose crashes.
- Push tokens. If you enable notifications in the app, a device push token so we can deliver them.
- Voting without an account. If you vote before signing up, we set a cookie holding a random identifier so those votes are recognised as yours, and we keep a one-way scrambled form of your IP address for the day to stop the same person voting from an unlimited number of fresh browsers. The address itself is never stored, and neither is readable from your votes, which show only the choice you made. Sign up and the votes move to your account.
What we do not collect
We do not collect precise location, and we do not access your camera, microphone, contacts or calendar except where you actively pick a photo or video to upload.
3. Why we use it
- To run the Service: sign you in, store your wardrobe, show community data.
- To personalise what you see, such as recommendations and the For You feed, based on your wardrobe and stated preferences.
- To send you the notifications and digests described in section 6.
- To keep Silloria safe: detect and prevent abuse, spam, fake engagement and security incidents.
- To measure and improve the product, using aggregated usage patterns.
- To meet legal obligations and enforce our Terms.
Our legal bases
If you are in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR require us to tell you the legal basis for each use. Ours are:
- Performance of our contract with you, for creating and running your account, storing your wardrobe and collections, publishing what you post, and delivering direct messages.
- Our legitimate interests, for keeping the Service secure and free of abuse and fake engagement, understanding how the product is used so we can improve it, personalising your recommendations and feed, and sending you digests of activity on your own account. We have weighed these against your interests, and you can object at any time using section 12.
- Your consent, where we ask for it specifically, such as push notifications. You can withdraw it at any time without affecting what came before.
- Legal obligation, where we must keep or disclose information to comply with the law.
4. AI and your information
Most editorial writing on Silloria is generated by AI models working from our catalogue data, and reviewed by a person before it publishes. Our Terms of Service describe this in section 4.
Your personal information is not sent to those models. They receive fragrance data such as notes, accords, houses and launch years. We do not use your reviews, messages, photos or profile to train third-party AI models, and we do not sell or license your content for anyone else to train on.
We do use your own activity, such as your wardrobe and ratings, to rank what you see. That happens inside our systems and only affects your own feed and recommendations.
5. Cookies, local storage and analytics
We use a small number of browser storage items:
- Sign-in. Session tokens keep you logged in.
- Preferences. Theme and interface state, such as your sidebar and your local vote selections.
- Voting without an account. A cookie holding a random identifier, so the five votes you can cast before signing up are recognised as yours and are still there when you come back. It lasts six months, and it is cleared once those votes join an account.
- Analytics. PostHog records only the events we define, with click and keystroke autocapture switched off. Google Analytics sets its own cookies, typically named starting with an underscore and "ga", which last up to two years.
You can clear cookies and local storage in your browser at any time, which signs you out and resets preferences.
Global Privacy Control. If your browser sends a Global Privacy Control signal, we treat it as a decision and honour it wherever you are, not only in Europe. Analytics runs without storing anything on your device, Google Analytics does not load, and we do not record your session. You are not asked again, because you have already answered. If you later choose to allow those things yourself, that choice takes precedence, and you can change it back at any time.
If you are in Europe or the UK
We ask before storing anything that is not essential. Until you accept, Silloria runs without cookies: visitor numbers are counted from a short-lived identifier calculated on our server, nothing is written to your device, and Google Analytics does not load at all. Declining is a real choice, not a delay, and the site works exactly the same either way.
If you accept, two things start: Google Analytics loads, and we record how pages behave during your visit. You can change your mind at any time in your settings.
Session recording
A session recording captures how pages responded as you moved through them, so we can see what broke rather than guess. Everything you type is masked before it leaves your browser, and direct messages are never recorded at all: recording stops entirely on those pages rather than merely hiding the text.
Outside Europe and the UK, where consent is not required for this, recording is on by default and you can turn it off in your settings.
6. Email and notifications
We send service messages such as sign-in and security emails, and a batched digest of activity you have not already seen in the app, for example when someone follows you or replies to you. Digests are sent through our email provider.
Every digest carries an unsubscribe link and a List-Unsubscribe header, and you can turn them off at any time in your settings or from the link in the email without signing in. Service and security messages are not optional while you hold an account.
7. Affiliate links and retailer tracking
This section describes tracking we do not control, and we want to be direct about it.
Many retailer links on Silloria are affiliate links. When you follow one, the affiliate network and the retailer receive the fact that you arrived from Silloria, and they normally set their own cookies or identifiers so that a purchase can be attributed to us. That is how the commission described in our Terms is earned, and it means those companies can observe your activity on their own sites after you leave ours.
We use Amazon Associates, eBay Partner Network, CJ Affiliate, Rakuten Advertising and Impact. Impact's attribution script loads on our homepage, records an impression and can turn eligible retailer links into affiliate links. Their handling of your information is governed by their own privacy policies, not this one. We record that a link was clicked so we can see which retailers are useful. We do not display banner advertising on Silloria, and we do not upload your account details, email address or wardrobe to any of them.
8. Who else processes your information
We keep this list short on purpose. Each of these companies processes information on our instructions so that the Service works:
- Supabase: database, file storage and authentication.
- Vercel: website hosting and request logs.
- Google: sign in with Google, if you choose it.
- PostHog: product analytics.
- Google Analytics: website and marketing analytics. This runs on every page and is separate from sign in with Google.
- Google Fonts: typefaces, loaded from Google's servers, which means Google receives your IP address when a page loads.
- TIDAL: the music player embedded on some fragrance pages. It loads only where a track is shown, and TIDAL may set its own cookies when it does.
- Sentry: crash and error reporting, which receives your account identifier when you are signed in.
- Resend: sending email.
- Expo, Apple and Google: delivering push notifications to your device.
We may also disclose information if the law requires it, in response to valid legal process, or where we reasonably need to in order to protect the rights, safety or property of Silloria, our users or the public. If Silloria is ever involved in a merger, acquisition or sale of assets, account information may transfer as part of that, and we will tell you before it happens.
9. We do not sell your personal information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in United States privacy laws. We have never done so.
10. Public information
Some things you do on Silloria are public by design: your profile, reviews, ratings, comments, posts and public collections. Anyone can see them, including search engines. Your wardrobe and wear journal are private unless you turn sharing on. Direct messages are private between participants. Think before you post, and use your account settings to control what is visible.
11. Security and retention
We use encrypted connections, hashed passwords and row-level database access controls so that each account can reach only its own data. No system is perfectly secure and we cannot guarantee absolute security.
We keep your account information while your account exists. If you delete your account, we remove your personal data from our systems within 30 days, with two deliberate exceptions:
- Public reviews and replies are anonymised rather than deleted. They stay on the fragrance page with your name, avatar and profile link removed, so the community ratings other people rely on do not silently change. If you want a specific review gone entirely, delete it before you close your account.
- Aggregated and anonymised data that can no longer identify you may be kept indefinitely.
We may also keep limited records where we have to for legal, tax or security reasons. Full detail of what deletion removes and what it keeps is on our account deletion page.
12. Your choices and rights
We offer these to everyone, whatever the law where you live requires:
- Access. Ask for a copy of the personal data we hold about you.
- Correction. Ask us to fix anything inaccurate.
- Deletion. Delete your account yourself in settings, or ask us to.
- Portability. Get your data in a structured, machine-readable format.
- Objection and restriction. Ask us to stop or limit a particular use.
- Withdraw consent. Where we relied on consent, withdraw it at any time. That does not affect what we did before you withdrew it.
- Notification settings. Turn off digest emails and push notifications at any time.
Write to info@silloria.com and we will respond within 30 days. We will not treat you differently for exercising any of these.
If you are in the United Kingdom or the European Economic Area, the rights above are yours under the UK GDPR and the GDPR, and you also have the right to lodge a complaint with your national data protection authority. In the UK that is the Information Commissioner's Office. In the EEA it is the supervisory authority for the country where you live or work. You are welcome to raise it with us first, but you do not have to.
13. Where your information is held
Silloria is operated from the United States, and the providers in section 8 store and process information in the United States and other countries. If you use Silloria from outside the United States, your information will be transferred to and processed there, where privacy law may differ from your own.
For transfers of personal data out of the United Kingdom or the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are built into our agreements with the providers listed in section 8, together with the additional safeguards those providers apply. You can ask us for more detail about a specific transfer at info@silloria.com.
14. Children
Silloria is not for children. You must be at least 16 to hold an account, and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, write to info@silloria.com and we will delete it.
15. Changes to this policy
We may update this policy. If a change is material we will update the effective date above and give reasonable notice in the Service or by email. Older versions are available on request.
16. Contact
Questions, requests or complaints about privacy go to info@silloria.com.