Privacy Policy

Version 2 · Effective 28 September 2026 · Last updated 30 September 2026

This policy explains what personal data the Tabakta mobile app processes, why, on what legal basis, who receives it, and your rights. It also serves as the information notice required by Turkish Law No. 6698 (KVKK) and, where applicable, the GDPR.

1. Controller

The data controller is Lalettayin. Contact: destek@tabakta.app.

2. Data we process

Usage analytics and session recordings: When you sign in to your account, usage analytics and session recordings are collected to improve the app. This setting is on by default, and the sign-in screen says so. Which screens you open and what you do (such as adding a meal) are sent to PostHog, a few basic events also go to Firebase Analytics, and your sessions may be recorded in PostHog. In a recording, on-screen text, what you type and photos are hidden, and the fields that show your weight, e-mail and name are always hidden. The screen layout and drawings such as charts can be visible. Network requests and app logs are not recorded. Health values such as your weight, calories, nutrient values and the food names you type are not sent to analytics. If the app crashes, a crash report is sent to Firebase Crashlytics: the stack trace at the moment of the crash (which line of code it crashed on), the device model and OS version, the app version and build number, the Firebase installation ID and the environment. Crash reports contain no user ID, e-mail, name or health data. We send usage events and recordings with a random ID created on your device, not with your account ID. You can turn this off at any time in Settings → Account actions → Data permissions: collection stops right away, no crash reports are sent and crash reports waiting on your device are deleted; what was already sent is not deleted.

Food search: Search is always online. The text you search for and your language are sent to our server to search the food database. If you are signed in, the request also carries your session, but we do not save your search text to your account.

Advertising ID: On Android, while "Usage analytics and session recordings" is on (the default after sign-in), Google Firebase Analytics may collect your device's advertising ID for measurement. It is not collected while that setting is off. We do not use the advertising ID to show you ads or to target you. You can reset or delete it in your Android settings. On iOS we do not access the advertising ID and do not ask for tracking permission (App Tracking Transparency).

We do not access your contacts, location or microphone. We show no ads and never sell your data.

3. Purposes

4. Legal bases

5. Recipients and international transfers

We share data only with the processors that help us run the service, and only as far as needed: Supabase on AWS (database, authentication, storage of photos and PDF reports, server functions, food search — EU, Frankfurt); Google Gemini API (AI analysis of meal photos and descriptions; when we send the photo or description we leave out your account ID, name and e-mail and add only your goal and language — EU/US); Google Firebase (remote configuration each time the app opens, without asking first — the device details it receives are listed in section 2; basic measurement, on Android including the advertising ID, and Crashlytics crash reports for app stability (contents in section 2), only while usage analytics is on, which is the default after sign-in — EU/US, Crashlytics US); PostHog (product analytics, session recordings and crash reports, only while usage analytics is on, which is the default after sign-in — EU, Frankfurt); Resend (sign-in code and report e-mails — US); RevenueCat, Inc. (subscription purchase and verification: your account ID and purchase history; never your e-mail, name or health data — US); Apple and Google (sign-in and app stores, which take subscription payments; Apple Health / Health Connect data stays on your device and is not sent to them by us).

Some of these providers are outside Türkiye and the EEA. Transfers rely on your explicit consent and on data processing agreements and standard contractual clauses with the providers. We do not share your data with anyone else unless the law requires it.

The transfer to RevenueCat is necessary to provide your subscription and relies on the same safeguards described above. If we grant free Premium to an account for testing or review, that account's ID is also sent to RevenueCat.

6. Retention

7. Security

Data is encrypted in transit with TLS; row-level access rules on the server let each user reach only their own records. Your profile photo, meal photos and PDF reports are not public. Session credentials are kept in your device's secure storage (Keychain / Keystore). No system is perfectly secure; in case of a breach we make the notifications the law requires.

8. Your rights and withdrawing consent

You may ask whether we process your data, request access, correction, deletion, restriction or portability, object to processing, and learn who received your data.

9. Children

Tabakta is not for children under 13. If you are under 18 you may use the app only with the consent of a parent or guardian. If we learn we hold data of a child under 13, we delete it.

10. Changes

We may update this policy. For material changes we inform you in the app and, where needed, ask for your consent again. The current version is always on this page.

11. Food data sources

Meal search draws on these open food databases, which we credit as their licences require: