Explicit Consent for Health Data Processing
Version: health-consent-2026-09-16-draft.6 · Effective: 21 July 2026 Status: In force — approved by legal counsel Last updated: 16 September 2026 — sharing my dietitian's program with the assistant added
This choice is separate from the KVKK Privacy Notice and is not preselected. I explicitly consent to Harun Yardımcı processing nutrition logs, calories/macros, weight and measurements, goals, water, allergies, diagnoses, medication/supplements, lab documents and HealthKit data that I enter or deliberately connect, for personalised wellness tracking, insights and reports, secure account sync, generating answers and drafts when I use AI features (described below), and authorised dietitian features only when I separately enable them.
My health data will not be used for advertising, cross-app tracking or sale. Dietitian sharing and research/model improvement are separable purposes and require additional specific choices where applicable. AI features and the international transfer they require are defined explicitly in the section below.
AI features and international transfer
When I ask the AI assistant a question, log a meal or water by typing, or send a meal photo for recognition, the content is sent through Harun Yardımcı's server to Google LLC's Gemini API, outside Türkiye, and processed there to produce the answer or logging draft:
- Assistant: my question; and, only if I turned on “Allow AI Assistant to use this profile” in my
health profile, my age, height, weight, diet preference, condition and allergy categories; and, only if I separately turned on “Let the assistant see my dietitian's program”, the eat and avoid lists and the calorie, protein and water targets of my dietitian's program running that week. The two options are independent and off by default.
- Typed logging: my sentence plus my device's local date, time and time zone.
- Photo recognition: my meal photo, with metadata including location removed on my device before
it leaves.
My name, e-mail, account identifier, medications, supplements, my dietitian's name and program note, and earlier messages are not sent. Google does not use this content or the responses to improve its products or train models; it may log them for a limited period only to prevent abuse and for legal obligations. My question, sentence and photo are not stored on Harun Yardımcı's server; the generated answer is kept against my account for 30 days so a repeated request is not processed twice, and is deleted when that period ends or when I delete my account. The AI never writes a record to my diary on its own; I confirm each draft.
Whether I use AI features is my choice. When I do not use them, my content is not sent to Google and the rest of the app keeps working. By giving this consent I accept that each time I use an AI feature I explicitly consent to the processing and international transfer described above.
My conversation with the assistant, typed-logging drafts and photo result cards are stored on my device only, in a protected area excluded from device backups, and are not sent to the server. I can delete this history at any time in Profile › “Clear AI chat history”; it is also deleted when I delete my account.
Audio recordings and lab document images are not retained after processing. Meal photos are the exception and are described below.
Meal photos
When I log a meal with a photo, the image is stored in a protected area on my device for 14 days from the day it was taken, and is deleted the next time I open the app after that period. Deleting the photo does not delete the meal — calories and macros stay in my diary. I can delete any photo individually at any time.
While sharing is on, photos are also uploaded to the server. With dietitian sharing off, a photo never leaves my device; once I enable nutrition sharing the image is also stored on Harun Yardımcı's server for the same 14-day period so my dietitian can see it. The dietitian views it through a short-lived link regenerated on each request, never a permanent one. Stopping or pausing sharing deletes the server-side images, and so does deleting my account.
Weekly check-in
When I prepare a weekly check-in for a dietitian, my progress photos (up to three angles), my weight and waist measurement, my mood, the private note for my dietitian and the log-adherence preview calculated on the device are stored on my device only, in a protected area marked to be excluded from device backups. This content is not sent to Harun Yardımcı's server and does not reach my dietitian; there is no transfer of check-in content. Metadata is removed from my photos when they are saved.
When a new week starts the previous week's photos are deleted from my device, and replacing a photo deletes the old one. Remaining drafts are deleted when I delete my local drafts or my account. The 14-day period for meal photos does not apply to check-in photos: they are deleted by the events above, not by a timer.
Dietitian sharing
Sharing is off by default and is turned on only when I choose to connect to a dietitian, through a separate confirmation. Once on:
- I choose what is shared. Categories (nutrition logs, weight, water, health profile, lab
results, HealthKit) are toggled individually; a category that is off is never sent.
- The dietitian sees the last 28 days. The window is fixed server-side; neither the dietitian
nor the app can widen it.
- Connecting also makes my previous 28 days visible. Sharing is not forward-only, and I accept
this knowingly before connecting.
- Stopping sharing also hides the past. Pausing or revoking closes the dietitian's access
immediately, including records they could previously see.
- The dietitian cannot edit or delete my records; they can only view them.
My sharing consent is recorded on the server and access is verified there on every request; the preference on my device alone grants nothing. A stop decision I make while offline takes effect on my device immediately and reaches the server as soon as a connection is available.
Withdrawal
I may withdraw consent at any time in privacy settings or via privacy@geteatwell.app. Withdrawal stops future consent-based processing and may disable health-dependent features; it does not require account deletion. Limited records required by law may be retained separately.