Kelvia.

Data Protection Notice

Last updated: September 2026

WHAT THIS TEXT IS FOR

This is the data protection notice required by article 10 of Turkish Personal Data Protection Law no. 6698 (KVKK): what is processed, for which purpose, on which legal ground, who it is passed to, and what rights you have. A notice and a consent are two different things, and they are deliberately two separate texts — here you read what happens, and you give your consent separately, on the screen that appears before your first scan. The privacy policy tells the same story in more everyday language; this does not replace it, it stands beside it.

WHO IS RESPONSIBLE

The data controller is İbrahim Melikşah Köse, an individual developer in İstanbul, Türkiye; there is no company behind Kelvia. This is also the address you write to about anything below.
İbrahim Melikşah Köse
Fındıklı Mahallesi, İpek Sokak, Meriçlife Sitesi 25-45C, Kat 2, Daire 21
Maltepe / İstanbul, Türkiye
melberlabs@gmail.com

WHAT NEVER LEAVES YOUR PHONE

Your onboarding answers, your skin profile, your scan history, your routine, your progress photos and your consent record are stored on this device only. We have no server that holds them and no account system; we cannot look at them, copy them, or bring them back. Everything below is about the moments when some of that data does leave the phone, during a scan.

THE FACE SCAN

Processed: the photo you take, the answers to the four opening questions (age range, main goal, routine experience, sensitivity), and the language the analysis should be written in. The purpose is to have what the photograph appears to show read back to you as a skin reading. Your face photo, the skin findings the reading produces, and your sensitivity answer are health data — special categories of personal data under article 6 of the law — and the only legal ground for processing them is your explicit consent. Without that consent the scan never starts, and the rest of the app keeps working.

THE PRODUCT SCAN

Processed: the photo of the product's label, your skin profile (skin type, concerns and their 1-5 severities), your four answers, the names of the products in your routine along with their known actives, and the language. The purpose is to read the label and assess how the product fits your profile and whether it clashes with your routine. The profile that travels with it carries health data, so the legal ground here is again your explicit consent. The score you see is not set by the model: it is calculated on your phone, from the ingredient list that was read and from your profile.

SEARCHING FOR A PRODUCT BY NAME

When you type a product's name instead of photographing it, what is processed is the text you typed and the language. The purpose is to find that product's publicly published ingredient list on the web. The list found is shown to you first; if you confirm it, the same product analysis described above runs, with the confirmed ingredient list in place of a photo. The text you type is never used to identify a person. The legal ground is performance of the service you asked for under the terms of use (article 5/2(c)).

THE ANONYMOUS DEVICE IDENTIFIER

The app generates a random identifier for itself the first time it runs and sends it with every analysis request. Its only purpose is applying the daily scan limit and preventing abuse of the service. It is not derived from your phone's hardware and it is not linked to your name, email or Apple ID. The legal ground is the controller's legitimate interest (article 5/2(f)). Because it is kept in the Keychain it survives deleting and reinstalling the app — a deliberate choice, since otherwise every reinstall would hand out a fresh quota. "Delete all my data" replaces it with a new one.

USAGE ANALYTICS

If analytics are enabled in this build, the app reports which screens are opened and which actions are taken — for example that a product scan finished, together with its verdict and score. These events carry no photo, no skin finding, none of your onboarding answers, no product name, no search query and no free text. They are sent under the anonymous identifier above. The purpose is seeing where the app works and where it is abandoned, and the legal ground is legitimate interest. The one derived value in the list is the match score; it is a single number about a product, and your profile cannot be reconstructed from it.

WHEN YOU WRITE TO US

The feedback link in Settings and the feedback card on a result screen open a draft in your phone's email app. If you send the draft, your email address and what you wrote reach us, and are used only to understand the problem and answer you; if you do not send it, it goes nowhere. The "did this feel right" buttons on a result screen produce nothing but the anonymous analytics event above — free text never enters analytics under any circumstances. The legal ground is the legitimate interest in answering your message.

WHO IT IS PASSED TO

A scan request passes through two places in turn: the Cloudflare, Inc. infrastructure our server runs on, and Google's Gemini API, which produces the analysis. On the Cloudflare side the request is relayed without being written down anywhere. At Google's end we are on the paid tier, whose terms say Google will not use what is sent to improve its products, and under which no human reviewer reads it. A log is kept only for abuse monitoring, for a limited period — up to 55 days by default. Analytics events go to TelemetryDeck, a privacy-focused analytics service in Germany. Nothing is passed to anyone else: no ad network, no data broker, no partner.

Separately, if you have iCloud Backup switched on, the app's on-device data goes into your own backup. That is not a transfer we make; the backup is between you and Apple, and we cannot reach it.

TRANSFER ABROAD

All three recipients above are outside Türkiye: Cloudflare and Google in the United States, TelemetryDeck in Germany. Today these transfers rest on your explicit consent, and the consent screen names the recipients. Article 9 of the law may additionally require a safeguard mechanism for transfers that are regular and ongoing. This is the one unfinished item in this notice and it is left open on purpose: the mechanism will be set as [the standard contract published by the Board / the mechanism our lawyer determines], and this passage will be updated when it is. We do not write down things we do not yet know.

HOW IT IS COLLECTED

All of it is collected directly from you, through the app, electronically and by automated means; we collect nothing about you from any other source. A photo is re-encoded on your phone before it is sent, which strips the metadata a camera embeds — including where and when the picture was taken. Your location never enters the request.

HOW LONG IT IS KEPT

What is on your phone stays until you delete it; "Delete all my data" in Settings removes all of it at once. The photo, profile and routine that reach our server during an analysis are never written to a disk or a log, and once the request ends nothing is left. Two things do stay on the server. The first is the daily limit counter: an irreversible digest of the device identifier and a number, which expires by itself after about twenty-five hours. The second is the name-search cache: its key is a simplified form of the product name you typed and its value is that product's publicly published ingredient list; it expires by itself after seven days and is never tied to which device searched for it. Retention of analytics events follows TelemetryDeck's own practice.

AGE

Kelvia is for people aged 18 and over. The limit rests on your own statement; there is no identity check.

YOUR RIGHTS

Under article 11 of the law you have the right to: learn whether your personal data is processed; request information about it if it is; learn the purpose and whether it is used in line with that purpose; know the third parties it is passed to at home or abroad; have it corrected if it is incomplete or wrong; have it erased or destroyed; require that a correction or erasure be notified to the third parties it was passed to; object to a result reached against you solely through automated analysis; and claim compensation if you suffer loss because it was processed unlawfully. You can also withdraw your explicit consent at any moment; withdrawing does not retroactively invalidate processing already carried out.

HOW TO APPLY

Writing to the email address above is enough. Your request is answered within thirty days at the latest. If the answer does not satisfy you, you can complain to the Personal Data Protection Board.

IF THIS TEXT CHANGES

If something the app does with data changes, this text changes and the date above is updated. If the change touches what you consented to — for instance if a different provider takes over the analysis — the old consent is not carried over; the app asks again before your next scan.

MOST OF YOUR RIGHTS ARE ALREADY IN YOUR HANDS

This text is long, but what we hold about you is short. Almost all of your data sits on your own phone, which is why you can exercise most of the rights above without asking us for anything — from Settings, yourself, immediately: edit your answers, turn off photo storage, withdraw analysis permission, and delete everything with one tap.