Effective: 2 September 2026 — the date this rewritten policy takes effect. The first version of this policy was published on 14 February 2025.
Last updated: 19 September 2026 — private sharing between PV users, and the notifications that come with it, are described in Sharing with Another PV User. Sharing is the one feature that puts your perfumery data on our servers, and the sections around it have been corrected to say so.
This policy applies to Perfumers Vault 2, managed by M24 Media Ltd.
Perfumers Vault 2 ("the App") is made by M24 Media Ltd ("we", "us"). This page explains what the App keeps on your device, what leaves your device, what we store on our servers, and how to get a copy of your data or delete it. It describes version 2.0.3 of the App and this website.
Everything below describes version 2.0 and later, which changed how PV AI works and added optional accounts. If you are still on version 1.3, see Version 1.3 at the end — that version behaves differently and this policy would otherwise misdescribe it. Check your version at the bottom of Settings.
At a Glance
- Your formulas, materials, suppliers and batches live on your device. Nothing is uploaded on its own and we hold no copy. Two things leave only because you send them: content you hand to PV AI, and an item you share with another PV user. Both are covered below.
- You can use almost the whole App without an account. An account is required for two features: PV AI, and private sharing with another PV user.
- PV AI sends your request — including any formula or photo you attach — to our own server, which passes it to Google Cloud's Vertex AI. You buy nothing from Google. On iPhone, iPad and Mac you can sign in with Apple instead of Google; on Android, Google sign-in is the only option.
- If you sign in, we store a small account record, the notes PV AI saves from your chats, your AI usage counters, and — only if a request is blocked by our safety checks — a short excerpt of it.
- Private sharing is unlike everything else here: what you send — the formula, material, batch or library itself — is stored in our database, where you and the one person you sent it to are the only users who can read it. It stays there until one of you deletes it. Nobody can find your PV ID unless you hand it to them, and you can switch sharing off or block someone. See Sharing with Another PV User.
- Analytics is off until you answer the question at the end of setup. If you say no, nothing is collected.
- You can export your account data, and delete your account, from inside the App. The export covers your account record, your usage counters, your subscription status and everything PV AI has saved about you; ask us for anything it leaves out.
Data on Your Device
Everything you create in Perfumers Vault 2 is stored in a database on your device. That includes your categories, materials (with their synonyms, replacements, suppliers and safety data sheets), formulas with their revisions and history, making sessions and completed batches, the shopping cart, orders, custom odour profiles, the IFRA library you import, and PubChem structures the App has cached.
Also on the device: your settings, the company details you enter for PDF branding (name, address, logo), and your PV AI chat transcript. The chat transcript is kept in the device keystore — Keychain on Apple devices, Keystore-backed storage on Android — under a key tied to your account, and holds at most the newest 500 messages.
None of this is uploaded anywhere on its own. It leaves your device only when you make it leave: an iCloud backup, a file or PDF export, a QR code, a formula you hand to PV AI, or an item you send to another PV user — the last of these is the only one that leaves a copy with us, and it is described under Sharing with Another PV User.
iCloud Backup and Restore
Nothing syncs by itself. The App does not use Apple CloudKit and there is no automatic sync between your devices. Backing up is something you start, and it is described below.
On iPhone, iPad and Mac you can back up to your own iCloud from Settings > iCloud Backup. Tapping Backup Now writes a single JSON file, named perfumers_vault_backup_<timestamp>.json, into the App's own iCloud container (iCloud.com.m24media.pv2). Restore reads one back. The App keeps the three most recent backups and removes older ones.
It is entirely manual. There is no timer, no background upload, and nothing travels between your devices by itself — each device keeps its own database. The file contains your perfumery data; the imported IFRA library and cached PubChem images are left out to keep it small.
The backup goes into your iCloud account, not to us. We cannot see it or read it. To remove backups, delete the App's iCloud data in your device settings; that does not touch the data still on your device. For more information visit Apple's privacy policy.
Your Account
An account is optional, and it unlocks two things: PV AI, and private sharing with another PV user. Everything else works signed out — formulas, materials, categories, IFRA compliance checking, suppliers, orders, exports, QR codes, iCloud backup, the biometric lock, and buying or restoring a Pro subscription.
You sign in through Firebase Authentication with Sign in with Apple, offered on iPhone, iPad and Mac, or with Google, offered on every platform and the only option on Android. We do not offer passwords and never see one. From your sign-in we receive:
- A user ID created for this app. It does not identify you anywhere else.
- Your email address, as the provider gives it to us. With Sign in with Apple you can choose Apple's private relay address, in which case that is the only address we ever see.
- Your display name, if you allow it. Apple offers the name only the first time you authorise the App.
Signing in also links your subscription record to your account ID, so our server can confirm you have Pro before it runs an AI request. Your display name has a second use once you share: it is what the person you are sending to sees, and what their notification says. You can change it in your profile, and sharing works without one.
You can sign out at any time in Settings > Account > Manage your account, and delete the account from the same screen. Signing out does not cancel your subscription, and it does not delete anything on your device.
What We Store on Our Servers
Signing in is what creates a record on our servers. If you never sign in, there is no account record, no PV AI notes and no moderation log. Two things do not depend on signing in: analytics, if you turned it on (see Analytics), and your subscription record with RevenueCat (see Subscriptions).
Once you sign in, our Firebase project (Google Cloud) holds the following:
- Your account record. Your user ID, email address, display name, which platform you signed in from (iOS or Android), when the account was created and when it was last used. Our server adds to it: whether you currently have Pro and when that was last checked, your AI usage counters, and safety counters if any request of yours has been blocked. Only you and our administrators can read it.
- Anything you have shared, and the sharing that supports it. The items you have sent or received and their payloads, your PV ID, the contacts you have built up, the people you have blocked, your registered devices for notifications, and a timestamp used to space sends out. This is the one part of our database that holds your perfumery data, and Sharing with Another PV User sets out each piece of it.
- What PV AI remembers. Short notes the assistant has saved from your chats, stored under your account. See the section below — you can read, delete and switch these off.
- Moderation logs. Written only when a request is blocked by our safety checks, and they include a short excerpt of the blocked text. See "Safety Checks" below.
- An abuse ledger. AI usage counts, and a ban flag if an account has been banned for abuse. It is stored against a one-way cryptographic hash of your Apple or Google sign-in identifier rather than the identifier itself, and holds no name, no email and no message text. No app or user can read it.
- A deletion record. If you delete your account, we keep the former user ID and the date. See "Export & Deletion" for why.
- Subscription event receipts. A note that a particular subscription notification was handled, so a repeated delivery is not processed twice. These contain no user identifier and no purchase details.
- Operational logs. When something goes wrong, our service writes a diagnostic line recording the error and your user ID. It never contains your prompt, PV AI's reply, or anything from your formulas. These are technical logs, held by Google Cloud on our behalf.
Beyond that, we do not store your formulas, materials, suppliers, batches, chat transcripts, or any photo you send to PV AI. Those are on your device, and — for AI requests — pass through our server without being written down.
The exception is a share. When you send a formula, a material, a completed batch or your materials library to another PV user, that item's data is written to our database and stays there until one of you deletes it. Nothing is shared unless you send it, and a share is readable only by the two of you. Where the rest of this section describes data we hold about you, this is data you asked us to pass on. It is set out in full under Sharing with Another PV User.
Where this happens
Our AI service runs as Cloud Functions in Google Cloud's us-central1 region, in the United States, and the AI model it calls runs in the same region. If you are outside the United States, your PV AI requests are processed there. Google processes them for us under our Google Cloud agreement and its data processing addendum, both linked in the PV AI section below.
Account records, PV AI notes, moderation logs, the abuse ledger and deletion records are held in our Firebase project on Google Cloud. We are confirming the exact region that database sits in and will name it here.
Who can reach it
Access rules on our database allow you to read your own account record and your own PV AI memories, and to delete those memories. A share is readable by exactly two accounts, the sender's and the recipient's, and either of them can delete it. Everything else — moderation logs, the abuse ledger, deletion records, subscription receipts and operational logs — is closed to every app and every user, and is reachable only by our administrators. Every request from the App is also checked by Firebase App Check, which proves the request came from a genuine build of Perfumers Vault 2. App Check does not identify you.
We do not sell personal data, we do not share it for advertising, and there is no advertising in the App.
PV AI
PV AI is included with a Professional subscription. There is nothing to buy from Google, no API key to enter, and no charge from Google to you — we run the AI service and we pay Google for it. In version 1.3 you supplied your own Google API key and Google billed you directly; version 2.0 replaced that.
PV AI needs three things: a Pro subscription, a signed-in account, and your acceptance of the AI notice shown in PV AI Settings the first time. Every AI request is something you start — nothing is sent in the background.
How a request travels
The App sends your request to a Cloud Function we operate, in Google Cloud's us-central1 region. That function confirms you are signed in, that the request came from a genuine copy of the App, that your subscription is active, and that the request passes our safety checks and your usage allowance. It then adds our own instructions and — in chat — any notes PV AI remembers about you, and sends the result to Google Cloud Vertex AI, which runs Gemini models inside our own Google Cloud project. The answer returns by the same route.
The practical point: you have no contract with Google for this — we do. Google acts as our supplier, processing your request on our instructions under our Google Cloud agreement.
What is sent
Only what the feature you are using needs:
- Chat: your message. When you chat from inside a formula, up to six earlier messages from that conversation are sent with it for context.
- Formula advisory, AI generation and "inspired by": the contents of the formula you are working on.
- Material enrichment and synonyms: the material name and the details you have entered.
- Bottle Scanner: the photo you take or choose.
- AI formula import: the text, PDF or image you supply — or, if you paste a web address, the page or PDF the App downloads from it. Fetching a pasted address is a request from your device straight to that website, so that website sees your IP address; the App then sends what it downloaded to PV AI.
Before generation, the text of your request is also passed to a smaller Google model that answers one question — is this about perfumery? Requests that are not are refused, and cost you nothing.
What is not kept
We do not store your prompts or PV AI's replies. There are exactly two exceptions, both described in their own sections below: the short notes PV AI saves about you, and — if a request is blocked — an excerpt of the blocked text. Photos and PDFs you send are never written to our storage; the App has no file-storage service at all.
We do not use anything you send to PV AI to train AI models, we do not sell it, and we do not show it to other users.
Usage allowance
PV AI has a fair-use allowance, counted per account. The current default is 100 prompts in a rolling six-hour window; we can adjust it. The App shows how many you have left and when the window resets.
Reporting a reply
If PV AI produces something wrong or offensive, use the report action on the reply. It opens an email addressed to callum@m24media.com, our support address, with only that reply quoted (up to 2,000 characters). Nothing is sent until you send the email, and nothing else from your conversation is included.
Our AI supplier
PV AI runs on Google Cloud Vertex AI within our own Google Cloud project. Google's handling of that data is governed by our Google Cloud agreement, not by any consumer or developer Gemini terms — you are not a party to either. The AI notice inside the App still links Google's consumer terms and the Gemini API terms. That is out of date, we are correcting it, and the Google Cloud documents below are the ones that actually govern PV AI.
PV AI is optional. If you never sign in, no part of it runs and nothing is sent.
What PV AI Remembers
PV AI saves short notes about you from your chats so later answers fit your work — things like "sells in the EU and follows IFRA 51" or "avoids oakmoss absolute". Our server writes them; the App cannot. Each note is at most 500 characters and is stored under your account, and the notes are included in your later chats so the assistant has the context.
Memory is on by default. In Settings > Account > Manage your account you can:
- read every note PV AI has saved;
- delete any single note, or clear them all;
- turn memory off, after which nothing new is saved and nothing saved is used.
Notes are included in your data export, and are deleted when you delete your account. There is a cap on how many are kept per account; when it is full, the note you confirmed least recently makes room for a new one.
Safety Checks and Moderation Logs
Every PV AI request is checked on our server before it runs: against a blocklist, against the "is this perfumery?" classifier, and — on the way back — by Google's safety filters and the blocklist again.
When a request is blocked, we write one log entry. It contains the date and time, your user ID, up to the first 500 characters of the blocked text, which rule matched, and at which stage it was blocked. We keep these to stop deliberate abuse and to find false positives — perfumery chemistry legitimately trips generic safety filters, and we need to see when that happens.
Each entry carries a 90-day expiry and is removed when it expires; 90 days is the current setting and we can change it. Entries are deleted immediately if you delete your account. Only our administrators can read them; no app and no user can.
If a request is allowed, nothing is logged — no prompt, no reply, no excerpt. Repeated deliberate violations can lead to an account being disabled.
Subscriptions (RevenueCat)
We use RevenueCat to manage subscriptions across the App Store and Google Play. Payment itself is handled entirely by Apple or Google — we never see your card details, and we cannot charge you.
RevenueCat receives:
- The purchase receipt issued by the store.
- An app user ID. Before you sign in this is an anonymous ID RevenueCat generates; after you sign in it becomes your account's user ID, which is what lets our server check your Pro status.
- Standard technical details the store and RevenueCat's own SDK collect, such as app version and device type.
The App sends RevenueCat nothing else about you — no email address, no name, no formulas, no materials. Our server asks RevenueCat whether your account has Pro and stores the answer (a yes or no and an expiry date) on your account record. RevenueCat also notifies our server when a subscription changes, so that record stays current.
Third-Party Subscription Service
For how RevenueCat handles subscription data:
Manage or cancel your subscription in your Apple ID account settings (iPhone, iPad, Mac) or your Google Play account settings (Android). Your subscription belongs to that store account, not to your Perfumers Vault account — deleting your Perfumers Vault account does not cancel it.
Analytics
The App includes Google Analytics for Firebase, and it is switched off until you say yes.
- The measurement library ships disabled in both the iOS and the Android build, so nothing is collected when you first launch the App — not a first-open event, not a session, not an app-instance identifier.
- The last step of first-run setup asks whether you want to share anonymous usage data. The switch starts off. If you finish setup without touching it, the answer is no.
- You can change your mind at any time in Settings > Analytics.
If you turn it on, we collect screen views and a small set of events — app opened, mode selected, feature used, formula action, ingredient action, setup completed — plus one property recording whether you are in Hobbyist or Professional mode. Alongside these, Google's library collects the app version, device model, operating system version and two pseudonymous identifiers: a Firebase app-instance identifier and, on Apple devices, the identifier for vendor. The identifier for vendor is an ID Apple gives to our apps only — no other developer can see it — and it resets when you delete every app of ours from the device.
Analytics is never linked to your account: the App does not set a user ID for analytics. It carries no formula, material, supplier or chat content. The App does not ask permission to track you across other apps and services, and does not use the advertising identifier.
Data is processed by Google under their privacy policy. See Google's Privacy Policy and Firebase Privacy Information.
Crash reporting
The App contains no crash-reporting or performance-monitoring library. Apple and Google may pass us aggregated crash and usage reports through App Store Connect and Google Play Console, if you have allowed that in your device settings. Those reports are produced by the platform, not by us, and you can switch them off in your device's privacy or diagnostics settings.
PubChem Lookups
When you look up a material's chemistry, the App queries PubChem, the free chemical database run by the US National Center for Biotechnology Information. The request goes from your device straight to PubChem over HTTPS.
What is sent is the material name, CAS number or compound ID you are looking up, plus a fixed label identifying the app ("PerfumersVault/2.0"). No account information, no device identifier and no formula data is sent, and the request does not pass through our servers, so we never see your PubChem searches. Results, including structure images, are cached on your device.
Third-Party Database Service
PubChem is operated by the U.S. National Library of Medicine. For their data policies:
IFRA Import
The IFRA feature is a one-way download that you start. In Professional mode you confirm a dialog, and the App downloads a single published spreadsheet — the IFRA 51st Amendment Standards overview — from IFRA's website, then replaces the local IFRA table with its contents. If the download fails you can import the spreadsheet yourself.
Nothing about you is sent. There is no IFRA account, no per-material lookup, and no identifier in the request. The downloaded standards are stored on your device.
It is not a live feed. The library is a snapshot of the 51st Amendment and changes only when you import again.
Third-Party Regulatory Organization
Device Permissions
The App asks for four permissions, each only when you first use the feature that needs it:
- Camera — to scan a formula QR code and to photograph a bottle for PV AI to identify.
- Photo library — to read a QR code from a saved image and to choose a bottle photo.
- Face ID or fingerprint — for the optional lock on the App. Your biometric data never leaves your device; the operating system tells the App only whether the check passed.
- Notifications — asked the first time you switch notifications on in Settings, so we can tell you when another PV user has shared something with you. It is the only thing we notify you about: there is no marketing push. Decline it, or switch it off later, and sharing still works.
The App asks for nothing else. There is no location, microphone, device contacts, calendar or health permission, and no App Tracking Transparency prompt. The “contacts” in the sharing screen are PV users you have sent to, not your phone’s address book, which the App never reads.
How Long We Keep It
- Data on your device — until you delete it, or delete the App. We cannot reach it.
- iCloud backups — the three most recent, in your own iCloud, until you remove them.
- Your account record — until you delete your account. PV AI memories — until you delete them, delete your account, or 12 months after they were last saved or confirmed, whichever comes first.
- Shares you have sent or received — until you or the other party deletes the share, or either account is deleted. There is no automatic expiry. Your PV ID, contacts, block list and registered devices — until you delete the entry, switch notifications off, or delete your account.
- Moderation logs — 90 days, or immediately when you delete your account.
- AI usage counters, the copy that survives deletion — about one usage window past your last AI request, roughly seven hours at the current setting. If an identity has been banned for abuse, the ban is kept.
- AI usage counters, the copy the App shows you — held on your account record until you delete your account. It is a display copy of the counters above and has no separate expiry.
- Subscription event receipts — 30 days.
- Operational logs — kept by Google Cloud on our behalf under the log retention set on our project. We are confirming that period and will state it here.
- Deletion records — kept indefinitely. They hold a former user ID and a date, and exist so a late sign-in token or a late subscription event cannot recreate an account you deleted.
- Analytics — held by Google under our Firebase project's retention setting, if you turned analytics on.
Your Rights, Export and Deletion
Both controls are in the App, in Settings > Account > Manage your account. You do not need to email us for either.
Get a copy of your data
Export my data builds a JSON file holding your user ID, email, display name, which provider you signed in with, when the account was created, your avatar colour, your AI usage counters, your subscription status, the memory switch, every note PV AI has saved, and your AI-consent record. The file is handed to your device's share sheet, so you choose where it goes. It is not uploaded to us.
Your shares are not in that file, because you can already see them: the sharing screen lists everything you have sent and received, and anything you imported is in your own database. Ask us at admin@m24media.com if you want them as a file.
What the file leaves out. If a request of yours was blocked by our safety checks, the log entry for it — including the excerpt of your own text — is not in the export. Nor are internal fields on your account record, such as the platform you last signed in from, when you were last seen, and our safety counters, nor your sharing records as noted above. Email admin@m24media.com and we will send you a copy of both.
Delete your account
Delete account removes it. You will be asked to sign in again first if your session is more than a few minutes old, because deletion cannot be undone. We then delete, in order: every PV AI memory, every moderation log entry belonging to you, every share you have sent or received, your PV ID, your contacts, your block list, your registered devices, your send-spacing mark, your account record, and your sign-in itself. The App then erases the chat transcript and consent record for that account from your device, and unlinks your device from the subscription record held by RevenueCat.
What we deliberately keep, and why
Three things survive deletion. We are telling you plainly rather than leaving them out:
- The abuse-ledger entry. AI usage counts, and a ban flag if the account was banned. It is keyed to a one-way hash of your Apple or Google sign-in identifier, and contains no name, no email and no message text. Without it, anyone could reset their AI allowance — or shed a ban — simply by deleting the account and signing up again. An ordinary entry disappears about a usage window after your last AI request; only a banned one is kept.
- The deletion record. The former user ID and the date, so that a sign-in token or subscription event arriving late cannot bring the account back.
- Your subscriber record with RevenueCat, the service that manages subscriptions for us. Deleting your account unlinks your device from it, but the record keyed to your old account ID stays with RevenueCat. Email admin@m24media.com if you want it erased and we will ask RevenueCat to delete it.
What deletion does not touch
- Your formulas and materials. They stay on your device — with the exception of anything still sitting in a share, they were never on our servers, and we cannot delete them for you. Remove them in the App, or delete the App.
- What someone else imported from you. A formula another PV user imported from a share is in their database now. Deleting your account removes the share, not their copy, in the same way that deleting your sent mail does not empty anyone’s inbox. See Sharing with Another PV User.
- Your iCloud backups. They are in your iCloud account; remove them in your device settings.
- Your subscription. It belongs to your App Store or Google Play account. Cancel it there, or it will keep renewing.
- Operational logs. A diagnostic line that recorded an error against your user ID stays in our logging system until it ages out under that system's retention setting. It holds no prompt, no reply and nothing from your formulas.
Other requests
To correct information, to object to how we use it, or to ask a question we have not answered here, email admin@m24media.com. Depending on where you live you may also have the right to complain to your local data protection authority.
Children
Perfumers Vault 2 is a tool for perfumery work and is not directed to children. Our Terms of Use set a minimum age of 17. We do not knowingly create an account for a child, and we do not ask anyone’s age or collect anything designed to identify a child.
If you believe a child has created an account with us, email admin@m24media.com and we will delete it and everything held under it.
Third-party links
The App and this site link to other people's websites — suppliers, IFRA, PubChem, and the parcel carrier you choose when tracking an order. Opening a tracking link hands the tracking number you typed to that carrier's own site in your browser; the App does not make that request itself.
There is one place where the App does fetch from another website on your behalf. If you paste a web address into AI formula import, the App downloads that page or PDF directly from your device, so that website sees your IP address and knows the page was requested. What it downloads is then sent to PV AI in the usual way.
We are not responsible for the privacy practices of any site we link to, or of any site you ask the App to fetch. Please read their policies before using them.
Version 1.3
Version 2.0 changed how PV AI works and introduced accounts. If you have not updated yet, three parts of this policy do not describe your copy of the App. Your version number is at the bottom of Settings.
AI used your own Google API key
In version 1.3 you supplied your own Google Gemini API key, and the App stored it in your device's keystore. AI requests went from your device straight to Google using that key, so Google billed you directly for them and Google's own terms governed that use. We never saw the key, the requests or the answers, and we ran no AI service. Version 2.0 removed the key entirely: PV AI now runs through our service, is included with a Professional subscription, and Google no longer bills you.
There were no accounts
Version 1.3 had no sign-in and no account of any kind, so none of the server-side records described above exist for it: no account record, no PV AI notes, no usage counters and no moderation logs. There is correspondingly nothing to export or delete on our side, because we hold nothing. Your perfumery data lived on your device then exactly as it does now.
Analytics was on unless you turned it off
Version 1.3 enabled Google Analytics for Firebase by default and let you switch it off in Settings. Version 2.0 reversed that: nothing is collected until you answer the question at the end of setup. What the analytics library collects is the same in both versions and is described under Analytics.
Everything else in this policy — your data staying on your device, iCloud backup, subscriptions, PubChem, IFRA import and device permissions — applies to both versions.
Changes to this policy
We may update this policy as the App changes. When we make a material change we update the "Last updated" date above and describe what changed.
Contact
M24 Media Ltd is responsible for the data described on this page. For any question about it, or to make a request:
Email: admin@m24media.com
You can also delete your account and export your data yourself, without contacting us, from Settings > Account > Manage your account in the App. See Account Deletion for step-by-step instructions.