Privacy Policy
The short version
Your profiles and your scan history are stored on your device, not on our servers. To analyse a label, the photograph and the relevant profile entries are sent to OpenAI, which returns the analysis. We do not store photographs on a server. We collect anonymous usage analytics through PostHog, and free text you have written is never sent to analytics. Subscriptions are sold by Apple and their status is tracked through RevenueCat. On this website, separately from the app, we use Google Analytics, and only if you agree to it first. We do not sell your data and we do not use it for advertising.
This policy covers both the Pura app and the pura.to website. They collect different things, so they are described separately: the app first, then the website.
The rest of this page is the detail, written to meet the requirements of the EU and UK General Data Protection Regulation (GDPR) and Turkey's Law No. 6698 on the Protection of Personal Data (KVKK).
Who is responsible for your data
The data controller, which is also the "veri sorumlusu" under KVKK, is:
Asli Dane Kartal
hello@pura.to
If you have any question about this policy or about your data, that email address is the right place to send it.
What data we handle, and why
Profiles you create
To personalise a scan, you set up a profile: allergies, health conditions, lifestyle preferences and anything you type into your own avoid list. You can create separate profiles for family members. Some of this is health data, which both the GDPR and KVKK treat as a special category needing extra protection.
Profiles are stored on your device. We do not upload them to our servers and we cannot browse them. When you run a scan, the profile entries relevant to that scan are sent to OpenAI along with the photograph, so that the analysis can be personalised to you.
Why: to provide the core function of the app.
Legal basis: your explicit consent to the processing of health and other special category data, under Article 9(2)(a) GDPR and Articles 5(1) and 6(2) KVKK, given when you create a profile. Performance of our contract with you under Article 6(1)(b) GDPR covers the rest. You can withdraw consent at any time by deleting the profile or the app.
Photographs of labels
When you scan, the photograph is sent to OpenAI's API to be read and evaluated. We do not store photographs on a server. If the app keeps a copy or a thumbnail with your scan history, that copy is on your device.
Please try to frame only the label. If you photograph something else by accident, for example a face or a document, that image is sent for analysis in the same way, so it is worth taking a moment to check the frame.
Why: to read the ingredients and evaluate them against your profile.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR, together with your explicit consent where the scan is evaluated against health data, Article 9(2)(a) GDPR and Article 6(2) KVKK.
Scan history
The results of your scans, and when they happened, are stored on your device so you can look back at them. We do not receive a copy.
Why: so you can find products you have already scanned.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR, and Article 5(2)(c) KVKK.
Anonymous usage analytics
We use PostHog to understand how the app is used in aggregate: which screens are opened, which features are used, whether a scan succeeded or failed, crashes and errors, plus technical information such as app version, device model, operating system version, language and approximate country. This is tied to a random identifier, not to your name or your email.
Free text you have written is never sent to analytics. That means your avoid list entries, your profile notes, your photographs and the content of your scan results stay out of it.
Why: to see which features work, to find and fix bugs, and to decide what to build next.
Legal basis: our legitimate interest in maintaining and improving the app, Article 6(1)(f) GDPR, or your consent where your device or local law requires it, Article 6(1)(a) GDPR and Article 5(1) KVKK. You can object at any time, see "Your rights" below.
Subscriptions
Pura Premium is sold and billed by Apple. We never see your payment card, your billing address or your full Apple ID. We use RevenueCat to tell us whether a subscription is active, which product was bought, when it renews and whether it has been cancelled or refunded, linked to an anonymous app user identifier and to the receipt Apple issues.
Why: to unlock the features you paid for, to prevent abuse of the free scan, and to keep proper records of transactions.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR, and compliance with our legal obligations, Article 6(1)(c) GDPR, mirrored by Articles 5(2)(c) and 5(2)(ç) KVKK.
Messages you send us
If you email us, we hold your email address and whatever you write, so we can reply.
Why: to answer you and keep a record of the exchange.
Legal basis: our legitimate interest in responding to users, Article 6(1)(f) GDPR, and Article 5(2)(f) KVKK.
This website
Everything above is about the Pura app. The pura.to website is separate and much simpler.
If you do nothing
No analytics cookies are set. The site asks before it sets any, and until you answer, Google Analytics is loaded with every consent signal switched off. Nothing is written to your device.
If you agree
We use Google Analytics 4 to count visits and see which pages people actually read, so we know what is worth writing next. It sets cookies on your device, typically named _ga and _ga_<id>, which usually last up to two years and let Google tell a returning visitor from a new one. It records the pages you view, roughly where in the world you are, and what kind of device and browser you use. We have IP anonymisation switched on.
Why: to find out whether anything we write is reaching anyone.
Legal basis: your consent, Article 6(1)(a) GDPR and Article 5(1) KVKK, given through the banner before any cookie is set. You can withdraw it at any time using the "Cookies" link at the bottom of every page, which costs you nothing and changes nothing else about the site.
If you decline
No cookies are set and nothing is stored on your device. We should be straight about one thing though: Google Analytics still sends Google a cookieless signal that a page was viewed. That is how Google's consent mode works, and it is not something we can switch off while using the product at all. It cannot be tied to you across visits, and we see only aggregate counts. If that is not good enough for you, a content blocker will stop it completely and we will not think less of you for using one.
Advertising
Google's advertising signals are switched off permanently, not just until you consent. We do not advertise and we do not build audiences, so there is nothing for us to ask you for.
Hosting
The site is hosted by Vercel, which processes ordinary server request logs, including IP addresses, in order to serve pages and to protect the service from abuse. That happens for every visitor and does not depend on consent, because a server cannot answer a request without knowing where to send the answer.
Legal basis: our legitimate interest in running and securing the site, Article 6(1)(f) GDPR, and Article 5(2)(f) KVKK.
Who your data is shared with
We do not sell your personal data, we do not rent it, and we do not use it for advertising or for training our own models. It goes to the following service providers, which act as processors on our behalf and are only allowed to use it to provide their service to us.
- OpenAI receives the photograph of the label and the relevant profile entries, in order to produce the analysis. Its handling of API data, including how long it retains it, is governed by OpenAI's own API data policies and by the data processing terms we have with it.
- PostHog receives the anonymous usage analytics described above.
- RevenueCat receives subscription and purchase status information.
- Apple handles the sale, the billing and the distribution of the app, as an independent controller under its own privacy policy. Apple's App Store may also report anonymised or aggregated data to us about downloads and purchases.
- Google receives website analytics data, and only from visitors who have agreed to it. Google acts as an independent controller for some of this under its own privacy policy. This applies to the website only, never to anything from inside the app.
- Vercel hosts the website and processes server request logs, including IP addresses, in order to serve it.
We may also disclose data if the law requires it, for example a valid order from a court or a competent authority, or where it is necessary to establish, exercise or defend legal claims. If our business is ever transferred to someone else, data may transfer with it, and we will tell you before that happens.
Transfers outside your country
The providers listed above are based in the United States and may process data there or in other countries. This means personal data may be transferred outside the European Economic Area, the United Kingdom and Turkey.
For transfers from the EEA and the UK, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or on an adequacy decision where one applies, under Chapter V of the GDPR. For transfers from Turkey, we rely on your explicit consent under Article 9 of KVKK, or on another transfer mechanism recognised by KVKK where one is available. You can ask us for details of the safeguards in place at the contact address above.
How long data is kept
- Profiles and scan history: kept on your device until you delete them, or until you delete the app. We hold no copy, so there is nothing on our side to expire.
- Photographs: not stored on a server by us. Retention on OpenAI's side is governed by its API data policies.
- Usage analytics: kept only for as long as we need them to understand how the app is used and to find faults, and then deleted or aggregated so that they can no longer be linked to a single installation. If you want to know the retention period currently set, ask us and we will tell you.
- Subscription records: kept for as long as your subscription is active and afterwards for as long as tax, accounting and consumer law require us to keep transaction records.
- Emails you send us: kept for up to 24 months after the conversation ends, unless we need them longer for a legal claim.
- Website analytics: the Google Analytics cookies typically last up to two years on your device, and you can clear them at any time from your browser or by declining through the "Cookies" link at the bottom of any page. Reports on Google's side are retained according to the period configured in that product.
Security
Keeping profiles and scan history on your device is the main protection: what is not collected cannot leak from us. Data in transit is encrypted with TLS. Our providers are bound by data processing agreements and by their own security commitments. No system is perfectly secure, so please also protect your device with a passcode and keep iOS up to date.
Automated processing
The analysis you see is generated automatically by an AI model. It is informational, it does not produce legal effects for you and it is not used to make any decision about you, such as pricing or eligibility. It is not a substitute for professional advice, and the limits of what it can see are explained in our Terms of Use.
Children
Pura is not intended for children to use on their own, and we do not knowingly collect personal data from children directly. A parent or guardian can create a profile for a child within their own account, and is responsible for the information they enter there. If you believe a child has provided us with personal data, please contact us and we will delete it.
Your rights
Under the GDPR and under Article 11 of KVKK you have the right to:
- learn whether your personal data is being processed and, if so, to request access to it and information about it;
- ask for inaccurate or incomplete data to be corrected;
- ask for your data to be deleted, and to ask us to notify third parties of that deletion;
- ask us to restrict processing, or to object to processing based on our legitimate interests, including the analytics described above;
- receive the data you gave us in a portable, machine readable format, and to have it transmitted to another controller where technically feasible;
- withdraw your consent at any time, without affecting the lawfulness of what was done before you withdrew it;
- object to the results of any analysis carried out solely by automated means, where that analysis produces a result against you;
- claim compensation for damage arising from unlawful processing.
These rights are free to exercise. We will respond within 30 days, as KVKK requires, and in any case within one month, as the GDPR requires. We may need to ask you something to confirm the request comes from you.
How to delete your data
Because your profiles and your scan history live on your device, you are in direct control of most of it:
- Delete a single profile, or a single scan, inside the app.
- Delete the app from your iPhone to remove all profiles and scan history stored on the device. This does not cancel a subscription, which you cancel in your Apple ID settings.
- Turn off analytics collection in the app's settings, where that option is offered, or write to us and ask us to stop.
For anything held on our side, including analytics tied to your installation, subscription records that are not needed for legal reasons, and any email correspondence, write to hello@pura.to with the subject "Data deletion request" and tell us what you want removed. We will confirm when it is done.
Complaints
If you are not satisfied with how we have handled your data, please tell us first so we can try to fix it.
You also have the right to complain to a supervisory authority. In the EEA, that is the data protection authority of the country where you live or work. In the UK, it is the Information Commissioner's Office. In Turkey, you should first apply to us in writing under Article 13 of KVKK, and if we do not answer within 30 days or you are not satisfied with our answer, you may lodge a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 30 days of our response and in any case within 60 days of your application.
Changes to this policy
If we change what we do with data, we will update this page and change the effective date at the top. If a change is material, we will tell you in the app before it takes effect, and where the change requires your consent we will ask for it.