Privacy Policy

Last updated: February 24, 2026

1. What types and categories of data we collect, process and use?

We collect, process, and use personal and non-personal data.

1.1 Personal and non-personal data

The term "personal data" is defined by the General Data Protection Regulation (GDPR) and the Turkish Law on the Protection of Personal Data (KVKK No. 6698). You can think of your personal data as any data that allows you to be identified or that can be correlated to you. On the other hand, "non-personal" data cannot be correlated to any specific person. By removing identifiable parts from and anonymizing personal data, personal data may be converted into "non-personal data."

1.2 Data we collect, process and use

We collect, process and use three types of data:

  • data you provide to us voluntarily,
  • data we receive when you use our Services, and
  • data we receive from third parties.

Typically, we collect, process and use the following categories of data:

  • Identity Data: Your name, surname, and username.
  • Contact Data: E-mail address.
  • Profile Data: Your workout goals, dietary preferences, weight, height, age, and gender.
  • Health & Nutrition Data: Information about meals logged, calorie consumption, macronutrients (carbs, protein, fat), and diet plans generated.
  • Voice Data: Audio recordings provided when you use the "Voice-Log" feature to dictate meals.
  • Technical Data: Your IP address, operating system, browser type, device model, and other relevant information regarding your internet connection to ensure proper use of the EatLog application.
  • Usage Data: Which screens you visit, your clickstream, transaction history, and subscription status (Free, Weekly, Monthly, Annual).
  • Content Data: Photos of food plates you upload for analysis.

1.3 Photo & Camera Data (Plate Analyzer)

Our Services use artificial intelligence algorithms to provide you with nutritional analysis of your food.

  • Food Analysis: When you use the "Photo-based Plate Analyzer," we collect the images you upload via your camera or camera roll. These images are processed to identify food items and estimate portion sizes/calories.
  • Facial Recognition: We do not use facial recognition technology. Our AI is trained to recognize food, not people. If a person appears incidentally in a photo of food, we do not process their identity.
  • Storage: We store these photographs securely on our servers (hosted by Supabase) to provide you with your history and to improve our AI models.
  • Consent: We obtain your explicit permission before accessing your camera or photo library. You may revoke this permission at any time in your device settings.

2. How is data collected?

Personal data is collected by us only if you provide such data to us on your own initiative by choosing to use our Services.

2.1 Login

You may create an EatLog user account through our login system. To register, you must provide us with at least your e-mail address and a password.

2.2 Adding information to your user profile

EatLog enables you to provide us with additional information, such as your weight goals and dietary habits. If you create a diet log, we will receive information about which foods you consume.

2.3 Enabling access rights to your device

For you to be able to use EatLog to the full extent, we will need certain access rights to your smartphone:

  • Camera/Photos: Required for the Photo-based Plate Analyzer and profile photos.
  • Microphone: Required for the Voice-Log feature to record meal descriptions.
  • Notifications: Used to send meal reminders or diet plan updates.

3. What are our legal bases for processing of your data?

We process your data in accordance with the GDPR (EU) and KVKK (Turkey).

  • Performance of Contract (GDPR Art. 6.1.b / KVKK Art. 5.2.c): To provide the diet tracking, AI analysis, and subscription features you requested.
  • Legitimate Interest (GDPR Art. 6.1.f / KVKK Art. 5.2.f): To improve our app security, fix bugs, and analyze user trends to build better features.
  • Consent (GDPR Art. 6.1.a / KVKK Art. 5.1): For optional features like marketing newsletters or accessing sensitive device permissions (Camera/Microphone).
  • Legal Obligation (GDPR Art. 6.1.c / KVKK Art. 5.2.ç): To comply with tax laws and consumer protection regulations.

4. What do we use your data for (purposes of processing)?

We collect, process and use data for the following purposes:

  • To provide, operate, and maintain the EatLog app;
  • To process your subscription payments (Weekly, Monthly, Annual);
  • To provide personalized diet plans and calorie reports;
  • To convert your voice notes into text for meal logging;
  • To analyze photos of food to extract nutritional data;
  • To respond to your support inquiries;
  • To detect and prevent fraud or abuse.

5. How long and where are data stored?

Your personal data will be stored for as long as necessary to provide the Service. If you delete your account, we will erase or anonymize your personal data within a reasonable timeframe (usually 30 days), unless legal retention periods (e.g., for tax purposes) require longer storage.

6. Cookies and Tracking

We use standard tracking technologies to understand how users interact with our app. This helps us see which features (like the Plate Analyzer) are most popular. You can manage your cookie preferences in your device settings.

7. Transfer of data to third parties

We do not sell your data. We transfer data to third-party service providers only when necessary to operate the app (e.g., database hosting, payment processing).

8. Data processing – third-party services and partners

Below is the description of the key third-party services we use:

8.1 Google Analytics / Firebase

We use Google services to analyze user behavior and improve the app. Data collected includes device type, session duration, and feature usage. IP addresses are anonymized where possible.

8.2 Supabase

We use Supabase (Supabase, Inc.) as our backend-as-a-service provider.

  • Purpose: Supabase hosts our database, manages user authentication (login/signup), and stores user-uploaded media (such as food photos and profile pictures).
  • Data Security: Supabase encrypts data in transit (using TLS) and at rest (using AES-256).
  • Location: Data is stored on servers secured by Supabase. If you are an EU user, we strive to utilize EU-based regions where applicable.
  • Privacy: For more information on how Supabase handles data, please visit: https://supabase.com/privacy.

9. Data security

We maintain state-of-the-art measures to guarantee data security (SSL/TLS encryption). However, no mobile application is 100% secure. You are responsible for keeping your password confidential.

10. Changes to this Privacy Policy

We may update this policy as our app evolves. We will notify you of significant changes through the app or via email.

11. Your Rights

Under GDPR and KVKK (Article 11), you have the right to:

  • Learn whether your personal data is processed;
  • Request information if your personal data has been processed;
  • Learn the purpose of processing and whether it is used appropriately;
  • Request correction of incomplete or incorrect data;
  • Request deletion or destruction of your personal data;
  • Object to the occurrence of a result against you by analyzing the data exclusively through automated systems (e.g., objecting to an AI-generated diet plan if you believe it is harmful);
  • Request compensation for damages in case you incur damages due to unlawful processing.

12. Contact details of the Data Controller

For any privacy-related questions or to exercise your rights, please contact:

Enes Öztekin
Address: KARAPINAR BELDESİ YUKARI ÇUKUR MAH. TEMENLER ÇUKUR CAD. NO: 49 ÇAYCUMA / ZONGULDAK 67975, Türkiye
Email: [email protected]

Website Cookies

This section applies to the eatlog.app website only; tracking technologies inside the mobile app are described in section 6 above.

We use four cookie categories. Essential cookies are required for the site to work and rely on our legitimate interest (GDPR Art. 6(1)(f)); they do not require consent. Analytics, marketing and functional cookies are set only with your explicit consent (GDPR Art. 6(1)(a) and ePrivacy Directive Art. 5(3)). Until you consent, these cookies are not written and the corresponding scripts — including Google Analytics — are never executed in your browser.

You can withdraw your consent at any time, without giving reasons, by clicking “Cookie Settings” in the site footer. Withdrawal does not affect processing carried out lawfully before it.

Your choice is stored in your browser under the name eatlog_cookie_consent and is asked again after 180 days. To meet our obligation to demonstrate consent (GDPR Art. 7(1)) we also keep a record of your decision on our server, consisting of a random consent identifier, the categories you selected, the text version and your truncated IP address; this record is kept for 24 months.

Essential Cookies

Required for core site functionality such as page routing, language selection and security. These cannot be turned off.

Analytics Cookies

Help us understand how visitors use the site so we can improve it. Includes Google Analytics.

Marketing Cookies

Used to measure campaign performance and show more relevant ads.

Functional Cookies

Remember your choices, such as preferred language or interface settings.

This category does not currently set any cookies on this site.

Transfers to third parties: Analytics and marketing cookies are set by Google Ireland Limited (and its affiliate Google LLC). Data may therefore be transferred to the United States on the basis of the EU–US Data Privacy Framework and/or Standard Contractual Clauses. Fonts and images used on the site are served from our own servers; unless you consent, the page sends no request to any third-party server.

Server-side logs: Clicks on app store links and blog page views are recorded for statistical purposes. These records store your IP address in truncated form (last segment zeroed), use no cookies, and are deleted after 12 months. The legal basis is our legitimate interest in measuring the use of our service (GDPR Art. 6(1)(f)).