This Privacy Policy describes how the Icerio application
(pure-check.vercel.app and any future
official domains) collects, processes and protects your personal data.
The service is developed in the Republic of Turkey and operated in
compliance with both Law No. 6698 on the Protection of Personal
Data (KVKK) and the European Union General Data Protection
Regulation (GDPR — EU 2016/679).
1. Data Controller
Under KVKK and GDPR, the data controller is the natural person identified
below. This section will be updated when a legal entity (company) is
incorporated.
- Data controller: Mete Eren Aslan
- Contact email: aslanmeteeren@gmail.com
- Address: İzmir, Türkiye
2. What We Collect
2.1. Account & identity data
- Email address (required for registration — stored via Supabase Auth).
- Display name (for personalised greeting only; not strictly required).
- Gender (optional; only used for greeting personalisation).
- OAuth basic profile (Google, Apple) when you sign in via providers.
2.2. Health and preference data
To produce personalised scan results we collect, during onboarding:
- Skin type (dry, oily, sensitive, etc.)
- Allergies (gluten, peanuts, parabens, etc.)
- Category of interest (food)
Important: Some of this information may qualify as
special-category personal data under KVKK Art. 6 and GDPR Art. 9.
It is processed solely on the basis of your explicit consent, used only
for service provision, never shared with third parties for advertising,
and never sold.
2.3. Scanning & usage data
- Product photos you upload — processed in-memory for OCR only,
not persisted, deleted after processing.
- Barcode numbers you scan.
- Ingredient lists you enter manually.
- Your scan history (results, dates, product names).
- Your comparison results.
2.4. Device and technical data
- IP address (used briefly for rate limiting and abuse prevention; not
stored long-term).
- Browser type, language preference, theme (light/dark).
- Cookies and local-storage keys — see Section 8.
3. Purposes & Legal Bases
| Purpose | Legal basis |
| Service delivery: scanning, results, history, comparison |
Performance of contract — KVKK 5/2(c); GDPR 6/1(b) |
| Personalisation: skin/allergy alerts, greeting |
Explicit consent — KVKK 5/1, 6/2; GDPR 6/1(a) and 9/2(a) |
| Security, fraud and abuse prevention |
Legitimate interest — KVKK 5/2(f); GDPR 6/1(f) |
| Service improvement, anonymous analytics |
Consent / Legitimate interest — KVKK 5; GDPR 6/1(a)/(f) |
| Compliance with legal obligations |
Legal obligation — KVKK 5/2(ç); GDPR 6/1(c) |
4. Third-Party Processors
The following infrastructure providers act as data processors under
signed Data Processing Agreements (DPAs). They have no right to use your
data for purposes other than providing the contracted service.
- Vercel, Inc. (USA) — Hosting and serverless API.
Scan requests transit Vercel functions; Vercel does not persistently
store scan content.
Privacy policy.
- Supabase Inc. (EU/USA) — Account, profile and
history database. EU regions are preferred.
Privacy policy.
- Google LLC — Gemini API (USA) — Photos you upload
are sent to the Gemini API for OCR. Google contractually commits not
to use paid-API content for model training.
Gemini API Terms.
- Open Food Facts (open-data community — France) —
Only the barcode number is sent during lookup; no personal data.
Terms.
- Sentry (Functional Software, Inc. — USA) — Error
tracking. Only technical error messages are logged, not tied to your
identity.
- PostHog, Inc. (EU/USA) — Anonymous product
analytics. Account identifiers are hashed and not directly linked to
you.
These processors may involve international data transfers. We rely on
the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses
(SCCs) and supplementary technical safeguards.
5. Retention Periods
- Account & history: for as long as your account is
active. After deletion, fully removed within 30 days.
- Uploaded photos: processed for OCR then
not retained; removed from servers immediately.
- Device and error logs: up to 30 days.
- Scan history: retained while you keep your account;
you may delete entries individually.
- Backups: full deletion from backups completes
within 90 days.
6. Data Transfers
- Beyond the processors listed in Section 4, your data is
not sold, rented, or shared.
- We may disclose data when legally required (court order, public
prosecutor's request, etc.).
- In the event of a merger or acquisition, your data may be
transferred to the acquiring party; you will be notified in advance
and given the option to delete your account.
7. Your Rights
Under KVKK Art. 11 and GDPR Arts. 15-22 you have the right to:
- Access your data and receive a copy.
- Have inaccurate or incomplete data corrected.
- Request erasure (right to be forgotten — GDPR Art. 17).
- Restrict processing.
- Object to processing.
- Data portability — receive your data in a structured
format (GDPR Art. 20).
- Not be subject to decisions based solely on automated processing.
- Withdraw consent at any time.
- Seek redress for damages.
Submit requests to
aslanmeteeren@gmail.com.
We will respond within 30 days. You also have the right
to lodge a complaint with your local supervisory authority — in Türkiye
the
Personal Data Protection Authority (KVKK),
in the EU your national Data Protection Authority.
Account deletion: You can permanently delete your
account in-app via "Profile → Settings → Delete My Account". It starts
immediately; full removal from backups completes within 30 days.
8. Cookies & Local Storage
The application primarily uses localStorage; traditional
tracking cookies are minimal.
- Strictly necessary (no consent required): session
token, language (
language), theme (theme),
username (userName), daily quota counters
(geminiRemaining, compareRemaining).
- Preferences: allergies, skin type, category
choices (stored locally on your device).
- Analytics (PostHog) — explicit consent: requested
on first launch; may be declined.
- Advertising cookies: NOT USED.
9. Data Security
- All traffic is encrypted via TLS 1.2+ (HTTPS).
- Database encrypted at rest with AES-256.
- Passwords hashed with bcrypt (Supabase Auth).
- API keys held only server-side as environment variables.
- Access restricted to the data controller and contracted processors.
- In case of a confirmed personal-data breach we will notify the KVK
Authority and affected users within 72 hours.
10. Children's Privacy
Icerio is not intended for users under 16. If we
learn that a child under 16 has registered without verifiable parental
consent, the account will be deleted. If you believe a child has an
account with us, please contact us.
11. Policy Changes
Material changes to this policy will be announced via in-app
notification and email to your registered address. The effective date
at the top of this page always reflects the current version. Continued
use of the service after a change constitutes acceptance of the
updated policy.
Legal notice: This document is a general informational
privacy notice prepared by the service provider; it does not constitute
legal advice. We strongly recommend a review by a KVKK / GDPR specialist
or a qualified lawyer before going to production. Once a legal entity is
incorporated, the data-controller information in this document must be
updated accordingly.