Privacy Policy
This policy explains what personal data the Tabakta mobile app processes, why, on what legal basis, who receives it, and your rights. It also serves as the information notice required by Turkish Law No. 6698 (KVKK) and, where applicable, the GDPR.
1. Controller
The data controller is Lalettayin. Contact: destek@tabakta.app.
2. Data we process
- Account: e-mail address or Sign in with Apple / Google identifier, account ID, optional name, username and profile photo.
- Profile and goals: gender, date of birth, height, weight, goal weight, goal and weekly pace, workout frequency, calorie and macro goals, language and unit preferences.
- Health-related data (special category): the meals you log and their nutrition values, meal photos, weigh-ins, water intake; if you connect Apple Health / Health Connect, your steps, active energy and weight.
- Usage and device: each time the app opens, to fetch its settings and without asking first: device model, OS and app version, language and region setting, time zone and an ID created for this installation. After you sign in, while "Usage analytics and session recordings" is on (it is on by default): screen and action events, session recordings and crash reports (see below). Server error and security logs (including IP address) are kept for a limited time.
- Communications: feature requests, complaints and support messages you send, and the e-mail address you give for report delivery.
- Subscription and purchase data: if you buy or restore Premium: your account ID, the product, the store (App Store / Google Play) and storefront country, purchase, renewal and cancellation history, subscription status and end date, app and SDK version, platform and IP address. We never see card or payment details; the store takes the payment.
Usage analytics and session recordings: When you sign in to your account, usage analytics and session recordings are collected to improve the app. This setting is on by default, and the sign-in screen says so. Which screens you open and what you do (such as adding a meal) are sent to PostHog, a few basic events also go to Firebase Analytics, and your sessions may be recorded in PostHog. In a recording, on-screen text, what you type and photos are hidden, and the fields that show your weight, e-mail and name are always hidden. The screen layout and drawings such as charts can be visible. Network requests and app logs are not recorded. Health values such as your weight, calories, nutrient values and the food names you type are not sent to analytics. If the app crashes, a crash report is sent to Firebase Crashlytics: the stack trace at the moment of the crash (which line of code it crashed on), the device model and OS version, the app version and build number, the Firebase installation ID and the environment. Crash reports contain no user ID, e-mail, name or health data. We send usage events and recordings with a random ID created on your device, not with your account ID. You can turn this off at any time in Settings → Account actions → Data permissions: collection stops right away, no crash reports are sent and crash reports waiting on your device are deleted; what was already sent is not deleted.
Food search: Search is always online. The text you search for and your language are sent to our server to search the food database. If you are signed in, the request also carries your session, but we do not save your search text to your account.
Advertising ID: On Android, while "Usage analytics and session recordings" is on (the default after sign-in), Google Firebase Analytics may collect your device's advertising ID for measurement. It is not collected while that setting is off. We do not use the advertising ID to show you ads or to target you. You can reset or delete it in your Android settings. On iOS we do not access the advertising ID and do not ask for tracking permission (App Tracking Transparency).
We do not access your contacts, location or microphone. We show no ads and never sell your data.
3. Purposes
- Creating your account, managing your session and syncing your data across devices.
- Calculating your personal calorie and macro plan; providing meal, weight and water tracking.
- Analysing a meal photo or description with AI to estimate nutrition values.
- Letting you buy, restore and manage Premium, and verifying your subscription to unlock the AI features (photo analysis, "Tarif et", "Düzelt") for Premium members.
- Scheduling offer notifications on your device, only if you turn on "Kampanya bildirimleri" (off by default).
- Searching the food database: search is always online; the text you type is sent to the online catalog (our server).
- Preparing and e-mailing a PDF summary when you ask; sending transactional e-mails such as sign-in codes.
- Exchanging data with Apple Health / Health Connect and sending reminders, when you allow it.
- Keeping the app secure and working, updating its settings remotely and fixing errors; studying usage statistics, session recordings and crash reports to improve the product (unless you turned this off).
- Meeting legal obligations and answering your requests.
4. Legal bases
- Explicit consent (KVKK art. 6; GDPR art. 9(2)(a)) for health-related data. Your consent is recorded when you sign in to your account and can be withdrawn at any time (section 8).
- Performance of a contract for account, profile and sync data, and for the subscription and purchase data needed to sell, verify and manage Premium. This does not depend on the usage analytics setting.
- Legitimate interests (KVKK art. 5/2-f; GDPR art. 6(1)(f)) for security, abuse prevention, error logs and the app fetching its settings each time it opens (remote configuration).
- Legitimate interests (KVKK art. 5/2-f; GDPR art. 6(1)(f)) for usage analytics, session recordings and crash reports that help us improve the app. On by default after you sign in; no health values are sent to them. Turn it off at any time in Settings → Account actions → Data permissions.
- Legal obligation where the law requires.
5. Recipients and international transfers
We share data only with the processors that help us run the service, and only as far as needed: Supabase on AWS (database, authentication, storage of photos and PDF reports, server functions, food search — EU, Frankfurt); Google Gemini API (AI analysis of meal photos and descriptions; when we send the photo or description we leave out your account ID, name and e-mail and add only your goal and language — EU/US); Google Firebase (remote configuration each time the app opens, without asking first — the device details it receives are listed in section 2; basic measurement, on Android including the advertising ID, and Crashlytics crash reports for app stability (contents in section 2), only while usage analytics is on, which is the default after sign-in — EU/US, Crashlytics US); PostHog (product analytics, session recordings and crash reports, only while usage analytics is on, which is the default after sign-in — EU, Frankfurt); Resend (sign-in code and report e-mails — US); RevenueCat, Inc. (subscription purchase and verification: your account ID and purchase history; never your e-mail, name or health data — US); Apple and Google (sign-in and app stores, which take subscription payments; Apple Health / Health Connect data stays on your device and is not sent to them by us).
Some of these providers are outside Türkiye and the EEA. Transfers rely on your explicit consent and on data processing agreements and standard contractual clauses with the providers. We do not share your data with anyone else unless the law requires it.
The transfer to RevenueCat is necessary to provide your subscription and relies on the same safeguards described above. If we grant free Premium to an account for testing or review, that account's ID is also sent to RevenueCat.
6. Retention
- Account, profile and diary data and your profile photo: while your account exists. When you delete your account or withdraw your consent, all server records and files (profile photo, meal photos, PDF reports) are deleted; removal from backups takes at most 30 days.
- Meal photos: deleted from the server when the analysis ends. Photos whose analysis did not complete or that belong to no meal are deleted automatically within hours.
- PDF reports: the download link in the e-mail works for 3 days. The report file is deleted from the server shortly after the link expires.
- Deleting your account or withdrawing consent does not cover: e-mails already sent to you, feature requests already forwarded to our team, and usage data sent while analytics was on.
- Server error and security logs: up to 90 days. Support correspondence: up to 2 years after the request is closed.
- Subscription and purchase records: while your account exists; when you delete your account they are deleted with it and we ask RevenueCat to delete its record (if RevenueCat does not answer, the request is queued and retried until done). Subscription event logs are kept up to 90 days.
- If a store subscription is still active when you delete your account, the store keeps renewing it — cancel it in the App Store or Google Play. Each renewal briefly re-creates a purchase record at RevenueCat, which we delete again. To recognise those renewals we keep a pseudonymised identifier — a hash of the deleted account number and no other data — for up to 13 months, or 60 days past the subscription's last known end if that is later, and then erase it. It is pseudonymised, not anonymised: whoever holds the original account number can match it.
7. Security
Data is encrypted in transit with TLS; row-level access rules on the server let each user reach only their own records. Your profile photo, meal photos and PDF reports are not public. Session credentials are kept in your device's secure storage (Keychain / Keystore). No system is perfectly secure; in case of a breach we make the notifications the law requires.
8. Your rights and withdrawing consent
You may ask whether we process your data, request access, correction, deletion, restriction or portability, object to processing, and learn who received your data.
- Delete your data: in the app, Settings → Account actions → Delete my account. Your account, all your server records and files, and the records and photos on your device are deleted. If you are offline or the deletion fails, nothing is deleted and the app tells you. If you cannot open the app, write to destek@tabakta.app from your account's e-mail address.
- Withdraw consent: your account rests on your explicit consent for your health data, so withdrawing it means deleting your account. Settings → Account actions → Data permissions → Withdraw consent and delete my account opens the "Delete my account" screen; when you type DELETE and confirm, your account, all your server records and files and the records on this device are deleted. An active subscription is not cancelled by the deletion; cancel it in the App Store or Google Play. If you are offline, the deletion does not start and the app tells you. If the deletion on the server fails, the app tells you and nothing is deleted.
- Other permissions: turn off usage analytics and session recordings on the same Data permissions screen, and Health app and notification permissions in your device settings, at any time. Withdrawal does not affect earlier lawful processing.
- Other requests: write to destek@tabakta.app; we answer free of charge within 30 days. You may also complain to the Turkish Personal Data Protection Authority (KVKK) or, in the EU/EEA, to your local data protection authority.
9. Children
Tabakta is not for children under 13. If you are under 18 you may use the app only with the consent of a parent or guardian. If we learn we hold data of a child under 13, we delete it.
10. Changes
We may update this policy. For material changes we inform you in the app and, where needed, ask for your consent again. The current version is always on this page.
11. Food data sources
Meal search draws on these open food databases, which we credit as their licences require:
- Open Food Facts — Open Database License (ODbL 1.0)
- USDA FoodData Central — public domain
- ANSES Ciqual — Licence Ouverte / Etalab
- UK CoFID — Open Government Licence v3 (OGL v3), Crown copyright