Last updated: May 18, 2026
This Privacy Policy explains how this app ("Tona") collects, uses, and protects your information when you use the App.
Information We Collect
- Information you save in the app, such as shades saved to your profile, preferences, and optional profile details.
- Basic device and usage data, such as app version, device type, performance data, and crash reports.
- Photos you provide when using the skin-tone scan feature (see below).
How We Use Information
- To provide and improve app features.
- To maintain security, prevent abuse, and fix bugs.
- To analyze your skin tone and generate personalized foundation shade recommendations.
Third-Party AI Service OpenAI
When you use the skin-tone scan feature, we send your photo to OpenAI LLC ("OpenAI") via their API so that OpenAI can analyze your skin tone and return foundation shade recommendations.
- What is sent: The photo you take or select from your library.
- Who receives it: OpenAI LLC, a third-party AI service provider.
- Purpose: Skin-tone analysis and foundation shade matching only.
- Storage: Your photo is never stored by Tona. OpenAI processes it and returns a result; it is not retained or used to train OpenAI's models (see OpenAI's API data usage policy).
- Your consent: We ask for your explicit permission before sending any photo to OpenAI. You can decline at any time; doing so will prevent the scan feature from working.
- Equal protection: OpenAI's data handling practices provide the same or equivalent level of protection for your personal data as described in this policy. You can review OpenAI's privacy practices at openai.com/enterprise-privacy.
Sharing
We do not sell your personal information. We share information only when necessary:
- OpenAI LLC — your photo is shared with OpenAI for skin-tone analysis as described above. This sharing occurs only after you grant explicit in-app permission.
- Service providers — analytics, crash reporting, payment processing, and authentication providers that help operate the app, under appropriate confidentiality agreements.
- Legal obligations — to comply with applicable law or to protect rights, safety, and security.
Subscriptions
If you subscribe to Tona Pro, your payment is processed by Apple via In-App Purchase. We do not receive or store your payment card details. Subscription management, billing, and cancellation are handled through your Apple ID settings.
Data Retention
We keep information only as long as needed to provide the app or as required by law. Photos submitted for scanning are not stored at any point. You can request deletion of your account data as described below.
Your Choices
- You can edit or delete your saved shades within the app.
- You can withdraw consent for AI photo analysis at any time in your device Settings.
- You can request account or data deletion by contacting support.
Data Security
We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children
Tona is not intended for children under 13. We do not knowingly collect information from children under 13.
Changes
We may update this policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page.
Contact
For privacy questions or data requests, contact us at: support@riveora.com