Legal
FreshMate Privacy Policy
Last updated: August 12, 2026
FreshMate("App", "Service", "we", "us", "our") values your privacy. This Privacy Policy and KVKK Disclosure Notice ("Policy") explains, under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") Article 10 and — for users in the European Economic Area / United Kingdom — the General Data Protection Regulation ("GDPR"), what personal data we process when you use the FreshMate app, for what purposes, on what legal bases, with whom it may be shared, how long it is retained, and what rights you have.
Except where processing relies on explicit consent (see §9), this Policy is not a consent form on its own; it fulfills our disclosure obligation under KVKK Art. 10.
1. Identity of the Data Controller
| Field | Information |
|---|---|
| Business name | FreshMate |
| App package identifiers | iOS: com.freshmate.ios · Android: com.freshmate.app |
| Contact (including KVKK/GDPR requests) | support.thedynamicstudios@gmail.com |
| Website | https://www.thedynamicstudios.com/en/apps/freshmate |
FreshMate acts as the data controller for personal data processed under this Policy.
2. Personal Data We Collect and Categories
2.1 Identity and Contact Data (Account Information)
A registered account is required to use FreshMate's core features (inventory tracking, synchronization, household sharing); guest or anonymous use is not supported.
When creating an account or signing in, one of the following methods may be used:
Email and password
- Email address
- Password (stored only in a secure, one-way hashed form; we never see your plaintext password)
- Display name and optional profile information you provide
Sign in with Apple / Sign in with Google (optional)
- Identity token provided via Apple or Google authentication
- Email address (Apple may not share your email if you use "Hide My Email", or may provide a relay address)
- Display name (Apple may provide this only on first authorization; Google profile name)
Authentication is provided via Supabase Auth (PKCE-based session management, password reset, Apple/Google signInWithIdToken). You do not need to create a password when signing in with Apple or Google; those providers' own privacy policies also apply.
2.2 App Content and Usage Data
- Product name, category, expiration date, storage location (fridge/freezer, etc.), line price and currency
- Whether a product has been opened, opening date, and PAO (period after opening) duration
- Recurring product settings and consumption cycles
- Household name, invite code, membership information, and member role (owner / editor / viewer)
- Travel Mode preferences
- Search, filtering, and in-app preference settings (language, theme)
This data is stored on Supabase (PostgreSQL) linked to your account. If you enable household sharing, invited members may view or (if editor/owner) modify shared inventory according to their role; viewer members can only read.
2.3 Camera, Photo, and Receipt Image Data (OCR)
When you use receipt scanning, with your permission we access your device camera or photo gallery. Alternatively, you may manually paste receipt text (no camera/gallery access required in that case).
- On-device processing: Text recognition is performed on your device using Google ML Kit. In production builds with default configuration, receipt images are not sent to our servers or third-party OCR servers.
- Scanned receipt images may be held temporarily on your device; only product information (text) you approve is saved permanently.
- Our infrastructure may include a server endpoint for receipt parsing (
parse-receiptEdge Function); the production receipt OCR flow does not use this endpoint and does not transfer receipt images. Manually pasted text is also processed with on-device parsers. - Receipt data is not used for advertising or profiling.
2.4 Purchase and Subscription Data
Premium subscriptions (freshmate_pro_month, freshmate_pro_year) are sold through the Apple App Store or Google Play. We use RevenueCat to verify your subscription status.
Data we receive from RevenueCat/stores: subscription status (active/expired/trial), product identifier, transaction metadata. We never receive or store your full card number or financial details.
2.5 Notification and Communication Data
With your consent, we use OneSignal (with Firebase Cloud Messaging as the delivery channel on Android) for expiration reminders and service-related notifications. Push delivery requires a device push token and subscriber record. You can turn off notifications in device settings or in the app.
2.6 Analytics and Crash Data — Production Builds Only
Only in production app builds (not development/test builds), we use Firebase Analytics and Firebase Crashlytics (Google Firebase project freshmate-1689e):
- Feature usage statistics (e.g., adding products, completing OCR, viewing paywall)
- Device model, OS version, app version, anonymized crash logs (stack traces)
This data is not used for personalized advertising and does not include sensitive content such as receipt images or passwords.
2.7 On-Device Local Storage
The app uses the Hive local database on your device for caching and some preferences (theme, language, freemium counters). This data is cleared at the device level when the app is uninstalled or your account is deleted.
2.8 Support and Communication Records
When you contact us by email, we retain your message and contact details for a reasonable period to respond and improve service quality.
2.9 Automatically Collected Technical Data
The app and our infrastructure providers (Supabase, Firebase) may automatically process technical data such as IP address, device/OS information, app version, and session timestamps for security, debugging, and service continuity.
3. Purposes of Processing Personal Data
Your personal data is processed for the following purposes:
- Creating, verifying, and managing your account
- Synchronizing your inventory and household data across devices
- Providing receipt scanning (OCR) and product suggestion features
- Applying free-tier (freemium) limits and providing premium features
- Sending expiration reminders and notifications you request
- Verifying subscription status via RevenueCat and ensuring billing integrity
- Measuring app performance, diagnosing and fixing errors (production only)
- Monitoring compliance with terms of service, detecting and preventing abuse (including freemium/security bypass attempts)
- Fulfilling legal obligations, responding to legal requests, and protecting our rights
- Responding to support requests
We do not sell your personal data. We do not use your inventory content for third-party advertising.
4. Legal Bases for Processing
4.1 Turkey (KVKK Art. 5)
- Performance of a contract (Art. 5/2-c): Account creation, inventory sync, subscription management
- Legal obligation (Art. 5/2-ç): Accounting, financial records, legal request processes
- Legitimate interest of the data controller (Art. 5/2-f): Security, fraud/abuse prevention, analytics and product development (limited by balancing test)
- Explicit consent (Art. 5/1): Push notification permission and — where platform rules require — camera/gallery access (see §9)
4.2 EEA/UK Users (GDPR)
- Contract (Art. 6/1-b): Providing the Service
- Legitimate interest (Art. 6/1-f): Security, analytics, product improvement
- Consent (Art. 6/1-a): Notifications and, where required, camera access
5. Recipients of Personal Data and Transfer Purposes
To provide the Service, your data may be shared with the following service providers (processors), limited to the stated purposes:
| Provider | Role | Data transferred/processed | Location |
|---|---|---|---|
| Supabase | Authentication, database, Edge Functions | Account, profile, inventory, household data | EU/US (per provider infrastructure) |
| RevenueCat | Subscription/entitlement management | User ID, purchase/transaction tokens, subscription status | US |
| Apple / Google | In-app purchases, store infrastructure | Payments per their own policies | US / Global |
| Firebase (Google) | Analytics and crash reporting (prod only) | Device/app identifiers, usage events, crash logs | US/Global |
| OneSignal | Push notification delivery | Device token, subscriber ID, notification preferences | US |
| Google ML Kit | On-device OCR | No off-device transfer in default mode | On device |
Each provider processes your data only on FreshMate's behalf and under our instructions, within their privacy/security commitments. Where data is transferred abroad (Supabase, Firebase, RevenueCat, OneSignal, Apple, Google), appropriate safeguards under KVKK Art. 9 and related regulations (standard contractual clauses, adequacy decisions, or your explicit consent) apply.
Except as required by law, your personal data is not sold or rented to third parties for marketing.
6. How Personal Data Is Collected
Your data is collected electronically through in-app forms (registration, profile, adding products), device permissions (camera/gallery, notifications), automatic technical logging (via SDKs), and — where applicable — support emails.
7. Retention Periods
| Data category | Retention period |
|---|---|
| Account and inventory data | While your account is active |
| After account deletion | The Settings → Delete Account flow triggers server-side deletion; your authentication record and linked profile/inventory data are removed from Supabase. Disaster recovery backups may be retained for up to 30 days. |
| Analytics/crash logs | Per Firebase default/configured retention (typically 14–26 months, aggregated and anonymized) |
| Store purchase records | Per Apple/Google/RevenueCat policies and legal (tax/accounting) obligations |
| Support correspondence | Reasonable period after resolution, up to 2 years |
When the retention period ends or the processing purpose ceases, data is deleted, destroyed, or anonymized.
8. Data Subject Rights
8.1 Your Rights Under KVKK Article 11
Under KVKK Art. 11, you may request to:
- Learn whether your personal data is processed
- Request information if it has been processed
- Learn the purpose of processing and whether it is used accordingly
- Know third parties to whom data is transferred domestically or abroad
- Request correction if processed incompletely or inaccurately
- Request deletion/destruction when KVKK Art. 7 conditions are met
- Request notification of correction/deletion to third parties
- Object to a result against you arising solely from automated processing
- Claim compensation for damage due to unlawful processing
8.2 Additional Rights Under GDPR (EEA/UK Users)
Access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent are also provided under GDPR. You retain the right to lodge a complaint with a supervisory authority.
8.3 How to Exercise Your Rights
To exercise your rights, contact support.thedynamicstudios@gmail.com in writing. We may ask you to verify your identity. Requests are handled free of charge within 30 days under KVKK Art. 13 (fees per the Board tariff may apply if the process incurs separate cost).
In-app: edit profile (Settings), delete account (Settings → Delete Account), disable notifications (device settings/in-app).
9. Processing Requiring Explicit Consent
For the following, separate explicit consent is obtained at the time of the action (permission prompt/consent screen):
- Push notification permission (iOS/Android system prompt)
- Camera and/or photo gallery access (for receipt scanning, system prompt)
You may revoke these permissions anytime in device settings; revocation may limit the related feature (notifications, OCR) but does not affect your account.
10. Children's Privacy
FreshMate is not directed at children under 13 (or 16 where applicable in the EEA) and does not knowingly collect personal data from them. If you believe a child has provided data to us, contact support.thedynamicstudios@gmail.com; we will delete it promptly.
11. Data Security
We apply the following technical and organizational measures:
- TLS encryption in transit
- Supabase Row Level Security (RLS)— each user accesses only their own and household members' data
- Hardened authorization for server-side (service-role) operations with JWT verification — e.g., account deletion (
delete-accountendpoint); receipt OCR images are not sent to the server in production (see §2.3) - No hardcoded secrets in production app binaries; keys injected at build time
- R8/ProGuard obfuscation on Android; Dart obfuscation (
--obfuscate) on production iOS builds - Server-side controls preventing client tampering of critical fields such as premium/subscription status (database triggers)
No transmission or storage method is 100% secure; absolute security cannot be guaranteed despite reasonable measures. If a breach affecting personal data is detected, we will notify data subjects and/or authorities (including the Turkish Personal Data Protection Authority) as required by KVKK and GDPR.
12. International Data Transfers
Our providers (Supabase, Firebase, RevenueCat, OneSignal, Apple, Google) may process your data outside Turkey (including the United States). Transfers rely on appropriate safeguards under KVKK Art. 9 (adequacy decisions, standard contractual clauses, undertakings) and, for GDPR, Standard Contractual Clauses (SCCs) or equivalent tools.
13. Policy Changes
This Policy may be updated from time to time. The current version is always published at https://www.thedynamicstudios.com/en/apps/freshmate/privacy (EN) and https://www.thedynamicstudios.com/tr/apps/freshmate/privacy(TR), with an updated "Last Updated" date. Material changes may also be communicated via in-app notice or email. Continued use after an update means you accept the updated Policy.
14. Contact
FreshMate
Email: support.thedynamicstudios@gmail.com
Website: https://www.thedynamicstudios.com/en/apps/freshmate
For subscription management, cancellation, and refund requests, use Apple (Settings → Apple ID → Subscriptions) or Google Play (Play Store → Subscriptions) directly; we cannot refund charges made through the stores.
Terms: Terms of Service