TDS

Legal

FreshMate Privacy Policy

Last updated: August 12, 2026

FreshMate("App", "Service", "we", "us", "our") values your privacy. This Privacy Policy and KVKK Disclosure Notice ("Policy") explains, under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") Article 10 and — for users in the European Economic Area / United Kingdom — the General Data Protection Regulation ("GDPR"), what personal data we process when you use the FreshMate app, for what purposes, on what legal bases, with whom it may be shared, how long it is retained, and what rights you have.

Except where processing relies on explicit consent (see §9), this Policy is not a consent form on its own; it fulfills our disclosure obligation under KVKK Art. 10.

1. Identity of the Data Controller

FieldInformation
Business nameFreshMate
App package identifiersiOS: com.freshmate.ios · Android: com.freshmate.app
Contact (including KVKK/GDPR requests)support.thedynamicstudios@gmail.com
Websitehttps://www.thedynamicstudios.com/en/apps/freshmate

FreshMate acts as the data controller for personal data processed under this Policy.

2. Personal Data We Collect and Categories

2.1 Identity and Contact Data (Account Information)

A registered account is required to use FreshMate's core features (inventory tracking, synchronization, household sharing); guest or anonymous use is not supported.

When creating an account or signing in, one of the following methods may be used:

Email and password

  • Email address
  • Password (stored only in a secure, one-way hashed form; we never see your plaintext password)
  • Display name and optional profile information you provide

Sign in with Apple / Sign in with Google (optional)

  • Identity token provided via Apple or Google authentication
  • Email address (Apple may not share your email if you use "Hide My Email", or may provide a relay address)
  • Display name (Apple may provide this only on first authorization; Google profile name)

Authentication is provided via Supabase Auth (PKCE-based session management, password reset, Apple/Google signInWithIdToken). You do not need to create a password when signing in with Apple or Google; those providers' own privacy policies also apply.

2.2 App Content and Usage Data

  • Product name, category, expiration date, storage location (fridge/freezer, etc.), line price and currency
  • Whether a product has been opened, opening date, and PAO (period after opening) duration
  • Recurring product settings and consumption cycles
  • Household name, invite code, membership information, and member role (owner / editor / viewer)
  • Travel Mode preferences
  • Search, filtering, and in-app preference settings (language, theme)

This data is stored on Supabase (PostgreSQL) linked to your account. If you enable household sharing, invited members may view or (if editor/owner) modify shared inventory according to their role; viewer members can only read.

2.3 Camera, Photo, and Receipt Image Data (OCR)

When you use receipt scanning, with your permission we access your device camera or photo gallery. Alternatively, you may manually paste receipt text (no camera/gallery access required in that case).

  • On-device processing: Text recognition is performed on your device using Google ML Kit. In production builds with default configuration, receipt images are not sent to our servers or third-party OCR servers.
  • Scanned receipt images may be held temporarily on your device; only product information (text) you approve is saved permanently.
  • Our infrastructure may include a server endpoint for receipt parsing (parse-receipt Edge Function); the production receipt OCR flow does not use this endpoint and does not transfer receipt images. Manually pasted text is also processed with on-device parsers.
  • Receipt data is not used for advertising or profiling.

2.4 Purchase and Subscription Data

Premium subscriptions (freshmate_pro_month, freshmate_pro_year) are sold through the Apple App Store or Google Play. We use RevenueCat to verify your subscription status.

Data we receive from RevenueCat/stores: subscription status (active/expired/trial), product identifier, transaction metadata. We never receive or store your full card number or financial details.

2.5 Notification and Communication Data

With your consent, we use OneSignal (with Firebase Cloud Messaging as the delivery channel on Android) for expiration reminders and service-related notifications. Push delivery requires a device push token and subscriber record. You can turn off notifications in device settings or in the app.

2.6 Analytics and Crash Data — Production Builds Only

Only in production app builds (not development/test builds), we use Firebase Analytics and Firebase Crashlytics (Google Firebase project freshmate-1689e):

  • Feature usage statistics (e.g., adding products, completing OCR, viewing paywall)
  • Device model, OS version, app version, anonymized crash logs (stack traces)

This data is not used for personalized advertising and does not include sensitive content such as receipt images or passwords.

2.7 On-Device Local Storage

The app uses the Hive local database on your device for caching and some preferences (theme, language, freemium counters). This data is cleared at the device level when the app is uninstalled or your account is deleted.

2.8 Support and Communication Records

When you contact us by email, we retain your message and contact details for a reasonable period to respond and improve service quality.

2.9 Automatically Collected Technical Data

The app and our infrastructure providers (Supabase, Firebase) may automatically process technical data such as IP address, device/OS information, app version, and session timestamps for security, debugging, and service continuity.

3. Purposes of Processing Personal Data

Your personal data is processed for the following purposes:

  1. Creating, verifying, and managing your account
  2. Synchronizing your inventory and household data across devices
  3. Providing receipt scanning (OCR) and product suggestion features
  4. Applying free-tier (freemium) limits and providing premium features
  5. Sending expiration reminders and notifications you request
  6. Verifying subscription status via RevenueCat and ensuring billing integrity
  7. Measuring app performance, diagnosing and fixing errors (production only)
  8. Monitoring compliance with terms of service, detecting and preventing abuse (including freemium/security bypass attempts)
  9. Fulfilling legal obligations, responding to legal requests, and protecting our rights
  10. Responding to support requests

We do not sell your personal data. We do not use your inventory content for third-party advertising.

4. Legal Bases for Processing

4.1 Turkey (KVKK Art. 5)

  • Performance of a contract (Art. 5/2-c): Account creation, inventory sync, subscription management
  • Legal obligation (Art. 5/2-ç): Accounting, financial records, legal request processes
  • Legitimate interest of the data controller (Art. 5/2-f): Security, fraud/abuse prevention, analytics and product development (limited by balancing test)
  • Explicit consent (Art. 5/1): Push notification permission and — where platform rules require — camera/gallery access (see §9)

4.2 EEA/UK Users (GDPR)

  • Contract (Art. 6/1-b): Providing the Service
  • Legitimate interest (Art. 6/1-f): Security, analytics, product improvement
  • Consent (Art. 6/1-a): Notifications and, where required, camera access

5. Recipients of Personal Data and Transfer Purposes

To provide the Service, your data may be shared with the following service providers (processors), limited to the stated purposes:

ProviderRoleData transferred/processedLocation
SupabaseAuthentication, database, Edge FunctionsAccount, profile, inventory, household dataEU/US (per provider infrastructure)
RevenueCatSubscription/entitlement managementUser ID, purchase/transaction tokens, subscription statusUS
Apple / GoogleIn-app purchases, store infrastructurePayments per their own policiesUS / Global
Firebase (Google)Analytics and crash reporting (prod only)Device/app identifiers, usage events, crash logsUS/Global
OneSignalPush notification deliveryDevice token, subscriber ID, notification preferencesUS
Google ML KitOn-device OCRNo off-device transfer in default modeOn device

Each provider processes your data only on FreshMate's behalf and under our instructions, within their privacy/security commitments. Where data is transferred abroad (Supabase, Firebase, RevenueCat, OneSignal, Apple, Google), appropriate safeguards under KVKK Art. 9 and related regulations (standard contractual clauses, adequacy decisions, or your explicit consent) apply.

Except as required by law, your personal data is not sold or rented to third parties for marketing.

6. How Personal Data Is Collected

Your data is collected electronically through in-app forms (registration, profile, adding products), device permissions (camera/gallery, notifications), automatic technical logging (via SDKs), and — where applicable — support emails.

7. Retention Periods

Data categoryRetention period
Account and inventory dataWhile your account is active
After account deletionThe Settings → Delete Account flow triggers server-side deletion; your authentication record and linked profile/inventory data are removed from Supabase. Disaster recovery backups may be retained for up to 30 days.
Analytics/crash logsPer Firebase default/configured retention (typically 14–26 months, aggregated and anonymized)
Store purchase recordsPer Apple/Google/RevenueCat policies and legal (tax/accounting) obligations
Support correspondenceReasonable period after resolution, up to 2 years

When the retention period ends or the processing purpose ceases, data is deleted, destroyed, or anonymized.

8. Data Subject Rights

8.1 Your Rights Under KVKK Article 11

Under KVKK Art. 11, you may request to:

  • Learn whether your personal data is processed
  • Request information if it has been processed
  • Learn the purpose of processing and whether it is used accordingly
  • Know third parties to whom data is transferred domestically or abroad
  • Request correction if processed incompletely or inaccurately
  • Request deletion/destruction when KVKK Art. 7 conditions are met
  • Request notification of correction/deletion to third parties
  • Object to a result against you arising solely from automated processing
  • Claim compensation for damage due to unlawful processing

8.2 Additional Rights Under GDPR (EEA/UK Users)

Access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent are also provided under GDPR. You retain the right to lodge a complaint with a supervisory authority.

8.3 How to Exercise Your Rights

To exercise your rights, contact support.thedynamicstudios@gmail.com in writing. We may ask you to verify your identity. Requests are handled free of charge within 30 days under KVKK Art. 13 (fees per the Board tariff may apply if the process incurs separate cost).

In-app: edit profile (Settings), delete account (Settings → Delete Account), disable notifications (device settings/in-app).

9. Processing Requiring Explicit Consent

For the following, separate explicit consent is obtained at the time of the action (permission prompt/consent screen):

  • Push notification permission (iOS/Android system prompt)
  • Camera and/or photo gallery access (for receipt scanning, system prompt)

You may revoke these permissions anytime in device settings; revocation may limit the related feature (notifications, OCR) but does not affect your account.

10. Children's Privacy

FreshMate is not directed at children under 13 (or 16 where applicable in the EEA) and does not knowingly collect personal data from them. If you believe a child has provided data to us, contact support.thedynamicstudios@gmail.com; we will delete it promptly.

11. Data Security

We apply the following technical and organizational measures:

  • TLS encryption in transit
  • Supabase Row Level Security (RLS)— each user accesses only their own and household members' data
  • Hardened authorization for server-side (service-role) operations with JWT verification — e.g., account deletion (delete-account endpoint); receipt OCR images are not sent to the server in production (see §2.3)
  • No hardcoded secrets in production app binaries; keys injected at build time
  • R8/ProGuard obfuscation on Android; Dart obfuscation (--obfuscate) on production iOS builds
  • Server-side controls preventing client tampering of critical fields such as premium/subscription status (database triggers)

No transmission or storage method is 100% secure; absolute security cannot be guaranteed despite reasonable measures. If a breach affecting personal data is detected, we will notify data subjects and/or authorities (including the Turkish Personal Data Protection Authority) as required by KVKK and GDPR.

12. International Data Transfers

Our providers (Supabase, Firebase, RevenueCat, OneSignal, Apple, Google) may process your data outside Turkey (including the United States). Transfers rely on appropriate safeguards under KVKK Art. 9 (adequacy decisions, standard contractual clauses, undertakings) and, for GDPR, Standard Contractual Clauses (SCCs) or equivalent tools.

13. Policy Changes

This Policy may be updated from time to time. The current version is always published at https://www.thedynamicstudios.com/en/apps/freshmate/privacy (EN) and https://www.thedynamicstudios.com/tr/apps/freshmate/privacy(TR), with an updated "Last Updated" date. Material changes may also be communicated via in-app notice or email. Continued use after an update means you accept the updated Policy.

14. Contact

FreshMate
Email: support.thedynamicstudios@gmail.com
Website: https://www.thedynamicstudios.com/en/apps/freshmate

For subscription management, cancellation, and refund requests, use Apple (Settings → Apple ID → Subscriptions) or Google Play (Play Store → Subscriptions) directly; we cannot refund charges made through the stores.

Terms: Terms of Service