01Plain-language summary
We take pictures of product labels with your camera, extract the text on your device, and match the ingredients against public databases. Your profile (skin type, allergens, diet, avoid list) is sensitive data, so we use it only with your explicit consent — it syncs to our EU servers when you're signed in, and stays on your device when you're not. We don't sell your data, we don't share it with brands, and we don't tie analytics back to your identity. If you want it gone, we delete it on request.
ingreview is built and operated by Berkay, operating under the name "ingreview" ("we", "us"). This Privacy Policy explains what data we collect when you use our mobile apps and website ("the Service"), why we collect it, and what you can do about it. The controller is based in Türkiye, so the authoritative framework is the Turkish Personal Data Protection Law (KVKK, Law No. 6698); for users in the EU/EEA we also apply the EU General Data Protection Regulation (GDPR), and we honor comparable rights (e.g. CCPA/CPRA) elsewhere. For Turkish users the in-app Aydınlatma Metni is the authoritative notice.
02Who we are
The data controller for the Service is Berkay, operating under the name "ingreview", based in Ankara, Türkiye. You can reach us at privacy@ingreview.app. For Turkish users, the authoritative notice under the KVKK (Law No. 6698) is the in-app Aydınlatma Metni.
03What we collect
We try to collect as little as possible. Below is the complete list.
Information you give us
| Category | Examples | Where stored |
|---|---|---|
| Profile (special category) | Skin type, food allergens, diet, avoid-list, life-stage modes | Our EU servers (encrypted), only with your explicit consent (açık rıza) — or on-device only if you use the app without signing in |
| Account | Email, display name (only if you create an account) | Our servers (encrypted at rest) |
| Profile photo (optional) | The avatar you pick for your profile. It is the only image the app uploads. | Supabase Storage (EU). Publicly readable by anyone who has the URL; replaced when you change it, deleted with your account. |
| Scans | The label text recognised from the picture you take, the parsed ingredient list, your edits. Label scans are never uploaded: the text is read on your device, and the picture itself stays only in a temporary file managed by your phone's operating system, which the app neither keeps nor uploads. | On your device by default. Optional cloud sync. |
| Ratings & reports | Star ratings, sensitivity tags, optional review text | Our servers — your user ID is replaced with a rotating anonymous token before aggregation |
Information collected automatically
- Device data: OS version, app version, language, time-zone — used to keep the app working and route the right content.
- Crash & performance: Crash traces sent to Firebase Crashlytics, with no account identifier attached (reports are grouped under a random, app-install-scoped Firebase installation id) — opt-in and off by default. Nothing is sent unless you turn crash reporting on in Settings.
- Aggregate scan counts: "Product X was scanned 412 times this week" — never tied to a user.
What we do not collect
- Contacts, photos from your camera roll (except ones you explicitly pick), microphone, precise location, calendar, browsing history.
- Advertising identifiers, cross-app tracking IDs, fingerprints. (The random, app-install-scoped ids our processors use are listed with each processor below.)
- Behavior outside the app.
04Why we use it
We use each category of data only for the purpose listed below, on the lawful basis stated.
| Purpose | Lawful basis (KVKK / GDPR) |
|---|---|
| Read the label in front of your camera and return ingredient analysis | Contract performance |
| Personalize results against your profile (allergens, skin type, life-stage) | Explicit consent (açık rıza) — special-category / health data |
| Improve our ingredient dictionary (aggregated only) | Legitimate interest |
| Fix crashes and bugs (Firebase Crashlytics) | Consent — opt-in, off by default; you can revoke any time |
| Measure feature usage (PostHog) | Consent — opt-in, off by default; you can revoke any time |
| Send the optional weekly digest | Consent (you can revoke any time) |
| Bill Premium subscriptions | Contract performance · legal obligation |
05Who we share with
We don't sell your data and we don't share it with brands or advertisers. Period. We do share with the processors below, each bound by a Data Processing Agreement (GDPR Art. 28). This is the complete list. A build check in our repository holds it to five things: every processor named here must also be named in both in-app notices; each processor's entry here and in both notices must state the same categories of data it receives; any processor SDK on the check's own vendor list that ships in our code must be named here; every processor named here must still be present in our code; and no page, script or stylesheet on this website may load anything from a third-party host unless that host is declared against one of the processors above. Two limits, stated plainly: the vendor list is maintained by hand, so the check would not recognise a vendor nobody has taught it about; and the website scan reads the addresses written in our files, so an address assembled while a page is running is invisible to it. It is a backstop against these texts drifting from what we actually run — not a proof.
| Processor | What we send, and why | How long | Where |
|---|---|---|---|
| Supabase | Hosting, authentication and our database: your account email and display name, the optional profile avatar you upload, the profile and scan records you sync, your community ratings and reports. | Account lifetime; deleted within 30 days of account deletion. | EU (Frankfurt). US-incorporated vendor, EU-resident data. |
| Google Gemini | The recognised label text and the product category, so the model can normalize and explain the ingredients. We send label text only — not your identity, not your profile, not the photo. | Sent per request; we keep only the returned analysis. | Google. May be processed outside Türkiye / the EU under standard contractual clauses. |
| OpenRouter, routing to Cerebras then Groq | The same payload as Gemini, and only when the Gemini call fails. Same rule: label text and product category, nothing about you. | Sent per request; we keep only the returned analysis. | US-based. Standard contractual clauses. |
| PostHog | Product usage analytics — opt-in, off by default. Feature-usage events from a closed property allow-list (counts, enums, flags), plus the lifecycle and device/app properties the SDK attaches itself. No account identifier is sent; events group under a random per-install id the SDK generates by itself, which is reset when you sign out or withdraw consent. That id is still an online identifier, so we treat it as personal data. No health or sensitivity data. Lawful basis: consent. | Held while analytics is on; capture stops the moment you turn it off in Settings. | EU (eu.i.posthog.com). |
| Firebase Crashlytics | Crash traces plus the app version, OS version and device model, so we can fix what broke. Opt-in, off by default, and no account identifier is attached; reports carry only a random, app-install-scoped Firebase installation id. Lawful basis: consent. | Up to 90 days. | Google. May be processed outside Türkiye / the EU under standard contractual clauses. |
| Adapty | Subscription state, the store transaction identifiers, and a random profile id Adapty creates for this app install when the app starts (not your account id, not an advertising id; Adapty's advertising-id collection is off, and it is configured not to record your IP address — like any server it still receives the connection's address in transit), to validate App Store / Play Store receipts and know whether Premium is active — which is why a profile exists for every install, including ones that never subscribe. Apple and Google process the payment itself; we never see your card details. | Life of the subscription record. For an install that never subscribes, Adapty holds only the random profile id, under its standard retention, which we do not extend. | Vendor default, not EU-pinned. Standard contractual clauses. |
| Resend | Transactional email — sign-in links, password resets, and email you asked for. Receives your email address, your display name and the content of that email. | As long as Resend needs to deliver and log the message. | Vendor default, not EU-pinned. Standard contractual clauses. |
| Upstash Redis | Rate-limit counters, so one caller cannot exhaust a shared quota. Holds a counter keyed by your user id — or, when you are not signed in, by a hash of the forwarding IP, and for an unsubscribe link by a hash of that link's token. These hashes are pseudonymous, not anonymous: they can be matched back to an IP address or a token. No request content. | 60 seconds — the key expires with the rate-limit window. | Vendor default, not EU-pinned. Standard contractual clauses. |
| Vercel | Hosts ingreview.app — the website, not the mobile app. Sees ordinary web request logs: IP address, user agent, the page requested. | Short-lived request logs; we do not export them or join them to an account. | Vendor default, not EU-pinned. Standard contractual clauses. |
| Apple & Google (the stores) | Deliver the app via the App Store and Play Store and process subscription payments under their own privacy policies. | Per Apple's and Google's own terms. | Per Apple's and Google's own terms. |
Google ML Kit reads the label text, and it runs entirely on your device — nothing is sent to ML Kit servers, which is why it is not in the table above. Open Food Facts / Open Beauty Facts are open databases we import product information from; we send them no personal data. The product pictures in the catalogue come from those imports, under their own licences and attribution. The app uploads exactly one kind of image: the optional profile avatar you choose, which is stored in Supabase Storage (EU). Label scans are never uploaded. If a photo-contribution feature ever ships, this notice is updated before it does.
We also disclose data when legally required (subpoena, court order).
06Where it lives & how long
- On your device. Profile, recognised label text, and scan history live on your phone until you delete them or uninstall the app. Label scans are never uploaded: the camera image stays only in a temporary file managed by your phone's operating system, which the app neither keeps nor uploads.
- Images. The optional profile avatar you choose is the only image the app uploads. It is held in Supabase Storage (EU) as a single object per account, is publicly readable by anyone who has its URL, is replaced when you upload a new one, and is deleted with your account within 30 days.
- On our servers. Account email and Premium status are retained while your account is active, then deleted within 30 days of cancellation. Aggregated, anonymous ratings persist indefinitely.
- Backups. Encrypted backups expire after 30 days.
07Your rights
You can exercise any of the rights below by emailing privacy@ingreview.app or via Settings → Privacy & data in the app.
- Access — receive a copy of everything we hold tied to your account.
- Rectification — fix anything that's wrong.
- Erasure — delete your account and all associated data. The step-by-step routes, and the exact list of what is deleted and what is kept without your identity attached, are on the Delete your account page.
- Erasure — what it cannot reach — the random install ids held by Adapty, Firebase Crashlytics and PostHog are not tied to your account, so deleting the account does not remove them or the records filed under them; those stay with each vendor until its retention period runs out. Reinstalling the app only creates a new id; turning crash reporting or analytics off in Settings stops any further data being sent.
- Portability — export your scan history as JSON.
- Object — tell us to stop processing for any legitimate-interest purpose.
- Restriction — freeze processing pending a dispute.
- Withdraw consent — turn off the digest or revoke any consent at any time.
- Lodge a complaint — in Türkiye, with the Kişisel Verileri Koruma Kurumu (KVKK); in the EU/EEA, with your local supervisory authority.
California residents: under the CCPA / CPRA, you also have the right to know, delete, correct, and opt out of "sharing" — which we do not do, but the right exists anyway.
08Children
Ingreview is rated 4+ on the App Store and PEGI 3 on Google Play. We do not knowingly collect data from children under 13 (or under 16 in the EU). Baby and Toddler safety modes in our app are designed for parents and caregivers to use — not for children to operate directly. If you believe a child has created an account, email privacy@ingreview.app and we will delete it.
09International transfers
Your account and profile data are stored in the EU (Frankfurt). Some processors — in particular the AI providers that analyze scanned label text — may process that text outside Türkiye / the EU under appropriate safeguards (e.g. Standard Contractual Clauses and the cross-border transfer conditions of KVKK Art. 9 and GDPR Chapter V).
10Changes to this policy
If we make a material change, we'll notify you in-app and by email (if you have an account) at least 14 days before it takes effect. Older versions are archived and available on request.
11Contact
Berkay, operating under the name "ingreview"
Ankara, Türkiye
Email: privacy@ingreview.app