Pura

Privacy Policy

Effective date: 17 August 2026

The short version

Your profiles and your scan history are stored on your device, not on our servers. To analyse a label, the photograph and the relevant profile entries are sent to OpenAI, which returns the analysis. We do not store photographs on a server. We collect anonymous usage analytics through PostHog, and free text you have written is never sent to analytics. Subscriptions are sold by Apple and their status is tracked through RevenueCat. On this website, separately from the app, we use Google Analytics, and only if you agree to it first. We do not sell your data and we do not use it for advertising.

This policy covers both the Pura app and the pura.to website. They collect different things, so they are described separately: the app first, then the website.

The rest of this page is the detail, written to meet the requirements of the EU and UK General Data Protection Regulation (GDPR) and Turkey's Law No. 6698 on the Protection of Personal Data (KVKK).

Who is responsible for your data

The data controller, which is also the "veri sorumlusu" under KVKK, is:

Asli Dane Kartal
hello@pura.to

If you have any question about this policy or about your data, that email address is the right place to send it.

What data we handle, and why

Profiles you create

To personalise a scan, you set up a profile: allergies, health conditions, lifestyle preferences and anything you type into your own avoid list. You can create separate profiles for family members. Some of this is health data, which both the GDPR and KVKK treat as a special category needing extra protection.

Profiles are stored on your device. We do not upload them to our servers and we cannot browse them. When you run a scan, the profile entries relevant to that scan are sent to OpenAI along with the photograph, so that the analysis can be personalised to you.

Why: to provide the core function of the app.
Legal basis: your explicit consent to the processing of health and other special category data, under Article 9(2)(a) GDPR and Articles 5(1) and 6(2) KVKK, given when you create a profile. Performance of our contract with you under Article 6(1)(b) GDPR covers the rest. You can withdraw consent at any time by deleting the profile or the app.

Photographs of labels

When you scan, the photograph is sent to OpenAI's API to be read and evaluated. We do not store photographs on a server. If the app keeps a copy or a thumbnail with your scan history, that copy is on your device.

Please try to frame only the label. If you photograph something else by accident, for example a face or a document, that image is sent for analysis in the same way, so it is worth taking a moment to check the frame.

Why: to read the ingredients and evaluate them against your profile.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR, together with your explicit consent where the scan is evaluated against health data, Article 9(2)(a) GDPR and Article 6(2) KVKK.

Scan history

The results of your scans, and when they happened, are stored on your device so you can look back at them. We do not receive a copy.

Why: so you can find products you have already scanned.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR, and Article 5(2)(c) KVKK.

Anonymous usage analytics

We use PostHog to understand how the app is used in aggregate: which screens are opened, which features are used, whether a scan succeeded or failed, crashes and errors, plus technical information such as app version, device model, operating system version, language and approximate country. This is tied to a random identifier, not to your name or your email.

Free text you have written is never sent to analytics. That means your avoid list entries, your profile notes, your photographs and the content of your scan results stay out of it.

Why: to see which features work, to find and fix bugs, and to decide what to build next.
Legal basis: our legitimate interest in maintaining and improving the app, Article 6(1)(f) GDPR, or your consent where your device or local law requires it, Article 6(1)(a) GDPR and Article 5(1) KVKK. You can object at any time, see "Your rights" below.

Subscriptions

Pura Premium is sold and billed by Apple. We never see your payment card, your billing address or your full Apple ID. We use RevenueCat to tell us whether a subscription is active, which product was bought, when it renews and whether it has been cancelled or refunded, linked to an anonymous app user identifier and to the receipt Apple issues.

Why: to unlock the features you paid for, to prevent abuse of the free scan, and to keep proper records of transactions.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR, and compliance with our legal obligations, Article 6(1)(c) GDPR, mirrored by Articles 5(2)(c) and 5(2)(ç) KVKK.

Messages you send us

If you email us, we hold your email address and whatever you write, so we can reply.

Why: to answer you and keep a record of the exchange.
Legal basis: our legitimate interest in responding to users, Article 6(1)(f) GDPR, and Article 5(2)(f) KVKK.

This website

Everything above is about the Pura app. The pura.to website is separate and much simpler.

If you do nothing

No analytics cookies are set. The site asks before it sets any, and until you answer, Google Analytics is loaded with every consent signal switched off. Nothing is written to your device.

If you agree

We use Google Analytics 4 to count visits and see which pages people actually read, so we know what is worth writing next. It sets cookies on your device, typically named _ga and _ga_<id>, which usually last up to two years and let Google tell a returning visitor from a new one. It records the pages you view, roughly where in the world you are, and what kind of device and browser you use. We have IP anonymisation switched on.

Why: to find out whether anything we write is reaching anyone.
Legal basis: your consent, Article 6(1)(a) GDPR and Article 5(1) KVKK, given through the banner before any cookie is set. You can withdraw it at any time using the "Cookies" link at the bottom of every page, which costs you nothing and changes nothing else about the site.

If you decline

No cookies are set and nothing is stored on your device. We should be straight about one thing though: Google Analytics still sends Google a cookieless signal that a page was viewed. That is how Google's consent mode works, and it is not something we can switch off while using the product at all. It cannot be tied to you across visits, and we see only aggregate counts. If that is not good enough for you, a content blocker will stop it completely and we will not think less of you for using one.

Advertising

Google's advertising signals are switched off permanently, not just until you consent. We do not advertise and we do not build audiences, so there is nothing for us to ask you for.

Hosting

The site is hosted by Vercel, which processes ordinary server request logs, including IP addresses, in order to serve pages and to protect the service from abuse. That happens for every visitor and does not depend on consent, because a server cannot answer a request without knowing where to send the answer.

Legal basis: our legitimate interest in running and securing the site, Article 6(1)(f) GDPR, and Article 5(2)(f) KVKK.

Who your data is shared with

We do not sell your personal data, we do not rent it, and we do not use it for advertising or for training our own models. It goes to the following service providers, which act as processors on our behalf and are only allowed to use it to provide their service to us.

We may also disclose data if the law requires it, for example a valid order from a court or a competent authority, or where it is necessary to establish, exercise or defend legal claims. If our business is ever transferred to someone else, data may transfer with it, and we will tell you before that happens.

Transfers outside your country

The providers listed above are based in the United States and may process data there or in other countries. This means personal data may be transferred outside the European Economic Area, the United Kingdom and Turkey.

For transfers from the EEA and the UK, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or on an adequacy decision where one applies, under Chapter V of the GDPR. For transfers from Turkey, we rely on your explicit consent under Article 9 of KVKK, or on another transfer mechanism recognised by KVKK where one is available. You can ask us for details of the safeguards in place at the contact address above.

How long data is kept

Security

Keeping profiles and scan history on your device is the main protection: what is not collected cannot leak from us. Data in transit is encrypted with TLS. Our providers are bound by data processing agreements and by their own security commitments. No system is perfectly secure, so please also protect your device with a passcode and keep iOS up to date.

Automated processing

The analysis you see is generated automatically by an AI model. It is informational, it does not produce legal effects for you and it is not used to make any decision about you, such as pricing or eligibility. It is not a substitute for professional advice, and the limits of what it can see are explained in our Terms of Use.

Children

Pura is not intended for children to use on their own, and we do not knowingly collect personal data from children directly. A parent or guardian can create a profile for a child within their own account, and is responsible for the information they enter there. If you believe a child has provided us with personal data, please contact us and we will delete it.

Your rights

Under the GDPR and under Article 11 of KVKK you have the right to:

These rights are free to exercise. We will respond within 30 days, as KVKK requires, and in any case within one month, as the GDPR requires. We may need to ask you something to confirm the request comes from you.

How to delete your data

Because your profiles and your scan history live on your device, you are in direct control of most of it:

For anything held on our side, including analytics tied to your installation, subscription records that are not needed for legal reasons, and any email correspondence, write to hello@pura.to with the subject "Data deletion request" and tell us what you want removed. We will confirm when it is done.

Complaints

If you are not satisfied with how we have handled your data, please tell us first so we can try to fix it.

You also have the right to complain to a supervisory authority. In the EEA, that is the data protection authority of the country where you live or work. In the UK, it is the Information Commissioner's Office. In Turkey, you should first apply to us in writing under Article 13 of KVKK, and if we do not answer within 30 days or you are not satisfied with our answer, you may lodge a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 30 days of our response and in any case within 60 days of your application.

Changes to this policy

If we change what we do with data, we will update this page and change the effective date at the top. If a change is material, we will tell you in the app before it takes effect, and where the change requires your consent we will ask for it.

Contact

hello@pura.to