Privacy Policy
Orrique makes a fragrance journaling app. This policy explains what data the app and our help center handle, why, and your rights over it.
Last updated: 21 July 2026
The easiest way to reach us is the in-app support (Settings, then Help and Support) or the contact form. You can also email support [at] orrique.com.
The short version
Section titled “The short version”- Your fragrance journal stays on your device and, if you turn on sync, in your own private iCloud account. We cannot see it.
- When you contact support, your name, email, and message are encrypted on your device so only Orrique support can read them.
- We do not sell your data, show ads, or use third-party advertising or analytics trackers.
Your journal data
Section titled “Your journal data”The fragrances, diary entries, photos, notes, and settings you create live on your device. First setup selects and recommends iCloud Sync, while On This Device remains available beside it. For a new journal, the visible storage choice becomes active when setup finishes or Skip Setup is chosen, after Orrique prepares the storage successfully. When a previous setup is found, iCloud becomes active before Welcome Back so restored preferences are not replaced by fresh defaults. With iCloud Sync active, the journal is also stored in your own private iCloud database, controlled by your Apple Account. We have no access to that private journal. Deleting an item in the app removes that item and, when iCloud Sync is on, syncs the deletion to your other devices. Deleting the app removes only that device’s local copy. A Local Only journal is gone with the app unless you exported a backup. An iCloud-synced journal remains in your private iCloud and returns when you reinstall with the same Apple Account.
Full backup files are different from private iCloud Sync. A full backup is an unencrypted file containing the complete journal, including notes, prices, and photos. It is not a plain text document, but anyone with the file may be able to extract its contents. Before export, Orrique warns you and asks you to continue. Keep backup files only in a private location you trust.
Support requests
Section titled “Support requests”When you contact support, we collect your name, email, and message to answer you.
- In the app (signed in to iCloud): your name, email, and every message are encrypted on your device before they are sent, so only Orrique support can read them. They are stored in Apple’s CloudKit. Replies come back inside the app.
- On the help center (without iCloud): your name, email, and message are encrypted in your browser to Orrique’s support key, relayed through our help-center host (Cloudflare), which cannot read their contents, and stored in Apple’s CloudKit. We reply by email from our support address.
When the device is locked, support reply notifications use generic text instead of decrypting the conversation into the notification. The rich-preview key is available only while the device is unlocked.
Alongside a request we also store, unencrypted, some non-sensitive details to help us triage: the request’s status and dates, your app version, device OS, language, the help page you came from, and a random per-install identifier. These are not used to identify you beyond handling your request.
Apple may make performance or diagnostic reports available on your device after a crash, hang, slow launch, high CPU use, or unusual disk writes. Orrique never uploads these reports automatically. When a useful report is available, the in-app support form can show an Include diagnostics switch that is off by default. If you turn it on, the encrypted attachment can include Apple’s report and a short app-event trail. That trail excludes fragrance names, journal text, searches, support messages, URLs, and record identifiers. The attachment follows the same access and retention rules as the rest of the support conversation.
Lawful basis (GDPR): handling your request (a contract, and our legitimate interest in providing support).
Retention: we keep a support conversation until your request is resolved and then delete it within 30 days, and in any case within one year. You can delete a conversation yourself in the app at any time. Deletion removes the conversation and its related messages, receipts, notifications, encrypted attachments, and support keys.
Orrique Pro
Section titled “Orrique Pro”Orrique Pro is sold through the App Store. Apple handles payment; we receive only whether your subscription is active, never your payment details.
Optional features you turn on
Section titled “Optional features you turn on”Some features ask your permission and use data only with it: local weather on a diary entry (your location), logging how a scent makes you feel (Apple Health “State of Mind”), attaching bottle photos (your photo library), and Calendar sync for your scent diary and upcoming occasion ideas (your calendars). Calendar Planning reads event titles, dates, and location text when provided on your device. Its weather-aware suggestion sheet uses your current device area when location is already allowed, not the calendar event location. Its mood intent score is not read from Apple Health, and it is not saved unless you later save a diary log. When weather appears, Orrique labels the source. If Apple Weather is unavailable, Orrique rounds your coordinate to two decimal places, roughly a one-kilometer area, before sending it to Open-Meteo. Open-Meteo says its API logs may retain the approximate coordinate and IP address for up to 90 days for maintenance and troubleshooting. The precise coordinate is not stored in your journal or sent to Open-Meteo. You can turn these features off in Settings or the system permission controls.
Fragrance lookup and catalog research can use web search. When you deliberately choose a web-search control, Orrique sends the displayed fragrance, note, or brand query to Google and loads the results in an in-app browser. A bottle lookup or curator research task can also send a public fragrance query to DuckDuckGo, then request the public result pages needed to extract source-backed catalog facts. Those services and source sites receive the query, IP address, and ordinary web-request information, and an in-app browser may use their cookies. Orrique does not add diary text, support messages, or your Orrique journal history to the query. It does not receive a Google account identity or build an advertising profile from the results. Reusable extracted catalog research may stay in a device-local cache for up to 30 days.
In a fresh full setup, the visible Share performance data control begins on and can be turned off before you continue. If left on, it becomes active only after the full Share performance data? disclosure and an explicit Agree and share action. Continue without sharing leaves it disabled and continues setup. Review choices cancels the disclosure without changing or advancing anything. An untouched Skip Setup does not enable it. A returning device asks separately with Share both, Performance only, Open without sharing, and Keep reviewing actions, then requires the same disclosure before performance sharing becomes active. Existing installations otherwise keep their saved choice. When performance sharing is on, Orrique uploads one creator-private raw summary per fragrance containing any available rating, longevity, projection, sillage, sprays per wear, bottle size, price per mL, and currency. A dupe vote contains the two fragrance keys and your closeness choice. These rows are stored in the CloudKit public database because they feed shared features, but raw fragrance and dupe votes are readable only by the creator and the trusted aggregation path. Other app users receive only aggregate snapshots, and Orrique does not show a community result until enough people contributed. Raw rows do not contain diary text, wear dates, photos, your name, or your email.
The separate Help complete the catalog control also begins on in a fresh full setup and can be turned off before you continue. If left on, it becomes active only after the Community guidelines disclosure and an explicit Agree and contribute action. When on, objective fragrance and bottle details you add can be submitted as a public-catalog candidate for curator review. A submission cannot directly overwrite the approved catalog. Turning the control off stops future catalog suggestions without changing your private Collection record.
Each fragrance and each dupe pair uses a different one-way pseudonym. This prevents the raw rows from exposing one stable account-wide identifier across the catalog. Turning sharing off stops future automatic fragrance summaries. In Settings, under Privacy, Delete past stats and dupe votes removes your raw contributions. Public aggregate snapshots can take time to refresh after raw deletion.
The Apple Watch companion does not read your private iCloud journal directly. It keeps a small local cache sent by the paired iPhone. Commands such as logging a wear are queued to the iPhone through Apple’s WatchConnectivity service, and the iPhone performs the journal save. The Watch labels a new log as queued until that bridge delivers it.
Who processes your data
Section titled “Who processes your data”- Apple handles iCloud and CloudKit (storage and sync), the App Store (subscriptions), and iCloud Mail (our support address).
- Cloudflare hosts our help center, relays encrypted support submissions that it cannot read, and supports Account Owner catalog enrichment using public fragrance facts.
- Open-Meteo supplies fallback weather. It receives only a two-decimal approximate coordinate from Orrique and may retain API logs containing that area and the request IP address for up to 90 days.
- Google, DuckDuckGo, and public source websites handle a web search or public catalog lookup only when the related fragrance lookup or research feature runs, as described above.
We do not sell your data. Orrique sends only the feature-specific information described above to the service needed for that feature.
Your rights
Section titled “Your rights”Depending on where you live (including the EU and UK under GDPR, and California under CCPA), you can access your data, correct it, delete it, restrict or object to processing, get a portable copy, and withdraw consent. In the app you can view, export, and delete your support conversations directly. You can also turn off community sharing and delete past raw stats and dupe votes. For anything else, contact us through the app or the help center and we will respond. You may also complain to your local data protection authority.
Security
Section titled “Security”Support content is encrypted on your device and readable only by Orrique support. Catalog curators cannot access it. The app authenticates replies, status changes, and Seen receipts before accepting them. Your journal, when synced, is protected by your Apple Account. No system is perfectly secure, but we design to minimize what is collected and who can read it.
Children
Section titled “Children”Orrique is not directed to children under 16, and we do not knowingly collect their data.
International transfers
Section titled “International transfers”Apple and Cloudflare operate globally; your data may be processed in other countries, protected by the encryption and safeguards described above.
Changes
Section titled “Changes”We will update this page when our practices change and revise the date above.
To get in touch, use the in-app support, the contact form, or email support [at] orrique.com.