KVKK Privacy Notice
Version: notice-2026-07-26-draft.4 · Effective: 21 July 2026 Status: In force — approved by legal counsel Last updated: 16 September 2026 — sharing your dietitian's program with the assistant and anonymous usage analytics (TelemetryDeck) added
Under Turkish Personal Data Protection Law No. 6698 (“KVKK”), Harun Yardımcı, at Esentepe Mah. Anadolu Cad. And Pastel Sitesi B3/84, Kartal/İstanbul, Türkiye, is the data controller for EatWell. Contact: privacy@geteatwell.app; registered e-mail: —. This notice is informational and is not consent. Health data consent is requested separately.
We may process identity and contact data; account and security records; nutrition, weight, water, goals and other health/fitness data (and, if you allow it, a health-profile summary for the assistant: age, height, weight, diet preference, condition and allergy categories); user content, including assistant questions and answers, typed meal/water sentences and the drafts made from them, meal photos sent for recognition, corrections, weekly check-in drafts that stay on the device and the AI chat history that stays on the device; App Store transaction and entitlement data; limited device diagnostics; and versioned legal-choice records. Purposes include operating accounts, providing requested tracking and reports, delivering purchases, synchronisation, security, support and compliance.
Data is collected through app forms and actions, device permissions, Apple/Firebase identity providers, App Store notifications and secure service logs. Processing relies, as applicable, on contract performance, legal obligation, establishment or protection of rights, legitimate interests that do not override fundamental rights, and separate explicit consent for special-category data.
Only necessary data may be shared with hosting, identity, e-mail, push, support and payment processors, competent authorities and professional advisers. Health data is not used for advertising. Firebase authentication data may be processed outside Türkiye only after a valid KVKK Article 9 transfer mechanism and required notifications are in place. Health data is not sent to Firebase Auth.
A dietitian you connect to is a separate recipient, and the transfer rests solely on your explicit, category-level consent. Without consent no health record reaches a dietitian. With consent: only the categories you leave enabled are transferred; the dietitian sees the last 28 days through a window fixed server-side; connecting also makes your previous 28 days visible, which is stated on the connect screen before you connect; pausing or revoking closes access immediately, including records previously visible; and the dietitian cannot edit or delete your records. Authorisation is verified against the server-side sharing record on every request — the preference on your device alone grants nothing.
The anonymous usage analytics provider is a separate recipient. To understand and improve how the app is used, based on our legitimate interest (KVKK Art. 5/2-f), usage events such as screen changes, action results and session information are transferred to TelemetryDeck GmbH (Germany, EU). Name, e-mail, account identifier, text you write, photos and health values are not transferred; a random identifier generated for the device is one-way hashed on the device and not linked to your account. Because this transfer leaves Türkiye it is subject to KVKK Art. 9. You can turn it off any time with the “Anonymous analytics” switch in Profile › Privacy.
The AI provider is a separate recipient. When you use the AI assistant, typed meal/water logging or meal-photo recognition, the content is sent through our server to Google LLC's Gemini API and processed only to produce the answer. What is sent: for the assistant, your question and — only if “Allow AI Assistant to use this profile” is on — a profile summary (age, height, weight, diet preference, condition and allergy categories) and — only if the separate “Let the assistant see my dietitian's program” option is on — the eat and avoid lists and the calorie, protein and water targets of your dietitian's program running that week (both options are independent and off by default); for typed logging, your sentence plus your device's local date, time and time zone; for recognition, the meal photo, with metadata including location removed on your device before it leaves. Your name, e-mail, account identifier, medications, supplements, your dietitian's name and program note, earlier messages and AI chat history are not sent. Written requests containing an e-mail address, a password or a long number sequence such as a card number are blocked before reaching the provider. Under the paid (billed) API terms Google does not use this content or the responses to improve its products or train models; it may log them for a limited period only to detect and prevent abuse and for legal obligations. The Gemini API runs on infrastructure outside Türkiye; this transfer is subject to the cross-border transfer rules of KVKK Article 9.
Weekly check-in content is transferred to no recipient. Progress photos, measurements, mood and the note are sent to no one, your dietitian included; they do not leave your device (see retention below).
Active account data is retained while the service is used or until deletion. On account deletion the server-side content (meal/water/weight records, notification inbox, device registrations, sharing links) is deleted. The draft operational targets are 30 days for deletion from operational copies and encrypted backup rotation, and 90 days for content-free security/audit events, subject to the final legal retention schedule.
Audio and lab document images are not retained after processing. Meal photos are the exception: they are kept in a protected area on the device for 14 days from the day they were taken and deleted the next time the app is opened after that. Deleting a photo does not delete the meal. While dietitian sharing is off, photos do not leave the device; with nutrition sharing on the image is also stored server-side (cloud object storage, the same 14 days, swept daily) and is shown to the dietitian through a short-lived link regenerated per request, never permanent access. Stopping or pausing sharing, and deleting the account, all delete the server-side images. The sharing record is kept for the life of the link; revoking closes access immediately and account deletion removes the record itself.
Weekly check-in drafts are kept on the device only. Progress photos, weight/waist measurements, mood, the note and the log-adherence preview calculated on the device are held in a protected local area, marked to be excluded from device backups and not sent to the server; photo metadata is removed on save. When a new week starts the previous week's photos are deleted from the device, and a replaced photo is deleted the moment it is replaced; remaining drafts are deleted when local drafts or the account are deleted. The 14-day period for meal photos does not apply to this content.
AI requests. Your question, sentence, the photo sent for recognition and the profile summary are not stored on our server and are not kept once the answer is produced. The generated answer (the assistant's reply, the food names, amounts and calories of a meal draft, the recognition result) is kept on the server against your account for 30 days so that a repeated request is not processed or charged twice, and is deleted when that period ends or when the account is deleted. If you turn on “Share my corrections” when editing a recognition result, your corrections (without the photo) are kept until account deletion to improve recognition.
The AI chat history is kept on the device only. Your conversation with the assistant, typed-logging drafts and photo result cards (with a small preview image) are stored in a protected area reserved for your account, marked to be excluded from device backups and not sent to the server. The newest 300 items are kept. Preview images are deleted after the same 14 days as meal photos; the card text stays. You can delete the history in Profile › “Clear AI chat history” or from the chat menu, and it is deleted when the account is deleted. Meals you added to your diary are not affected.
You may exercise KVKK Article 11 rights via privacy@geteatwell.app, — or Esentepe Mah. Anadolu Cad. And Pastel Sitesi B3/84, Kartal/İstanbul, Türkiye using sufficient identity-verification information. Do not send unnecessary health data with a request.