Privacy Policy
Controller. Horus Teknoloji ve Dijital Hizmetler A.Ş. ("Horus", "we"), Istanbul, Türkiye. Contact: hello@horusstudios.com.
This policy explains what PureScan collects, why, who it is shared with, and what you can demand from us. It covers the mobile app and this website.
1. The short version
- We collect the health details you enter (allergies, conditions, body metrics) and the products you scan. That is the whole point of the app: without them we cannot personalise a score.
- We do not sell your data, and we do not run advertising.
- We never share your health profile with brands, retailers or data brokers.
- You can export or delete everything, at any time, from the app.
2. What we collect
2.1 Account
The app first creates a pseudonymous device account so you can scan without an Apple or Google sign-in. If you later link Apple or Google, we receive a stable user identifier and, depending on what you allow, an email address. We never receive your password. If you use Apple's "Hide My Email", we only ever see the relay address.
2.2 Health and dietary profile (special category)
Allergies, chronic conditions (for example diabetes, hypertension, coeliac disease), dietary preference, height, weight, biological sex, age and activity level — all entered by you during onboarding, and for any family profile you create. Under GDPR Article 9 and KVKK Article 6 this is special-category / sensitive personal data, and we process it only on your explicit consent, which you give using the explicit consent control at the end of onboarding and can withdraw at any time by deleting your account.
2.3 Scan and usage data
Barcodes you scan, the timestamp, which profile the scan belongs to, whether you marked a product as consumed and in what quantity, your favourites, and photos of receipts you choose to scan.
2.4 Product usage events
Counts of what happens in the app: that a scan succeeded or found nothing, that the paywall was shown, that a purchase was started or restored, that a free-plan limit was reached. Each event carries your account identifier, a timestamp and a few short values such as food or cosmetic — never free text you have typed, and never anything from your health profile.
These answer product questions we would otherwise be guessing at: how many people complete a first scan, and whether the free plan's limits sit somewhere reasonable. They are stored in our own database and are not sent to an analytics company.
2.5 Products you tell us are missing
If you scan a barcode our catalogue does not have, you can send it to us — optionally with the product name and brand you can see on the packaging. We use these only to close gaps in coverage. Nothing is submitted unless you tap the button.
2.6 Technical data
Device model, OS version, app version, language, and a push notification token if you grant notification permission. Crash reports contain a stack trace and device state — they are configured to exclude personal identifiers and request bodies.
2.7 What we do not collect
We do not collect precise location, contacts, photos beyond the receipt images you explicitly capture, or advertising identifiers. The app contains no advertising SDK and no third-party analytics tracker — the usage events in 2.4 are recorded by us, in our own database, and are not shared with an analytics provider.
3. Why we process it, and on what legal basis
- Create and secure your account — account identifiers. Performance of a contract.
- Personalise product scores, allergen and diet warnings — health & dietary profile, scans. Explicit consent (GDPR Art. 9(2)(a) / KVKK Art. 6(3)).
- Show your history, favourites, weekly and monthly summaries — scan data. Performance of a contract.
- Read receipt photos to identify products — receipt images. Consent, per capture.
- Send reminders and report notifications — push token, activity dates. Consent (withdraw in system settings).
- Diagnose crashes and keep the app working — technical data. Legitimate interest.
- Manage subscriptions — account id, purchase status. Performance of a contract.
- Understand how the app is used and whether the free plan works — product usage events. Legitimate interest.
- Add products our catalogue is missing — barcode and any name or brand you send. Consent, per submission.
4. Processors we use
- Supabase — database, authentication and file storage; all account and scan data; EU.
- Eachlabs (each::sense) — AI summaries, chat replies and receipt text recognition; product details and receipt images, not your identity or health profile; EU / US.
- Adapty — subscription management; account id and purchase status; EU / US.
- Sentry — crash reporting; technical data; EU.
- Expo — push notification delivery; push token and message text; US.
- Apple / Google — sign-in and payment; handled under their own policies; global.
Where a processor is outside Türkiye or the EEA, transfers rely on Standard Contractual Clauses and, for KVKK, on your explicit consent or an equivalent safeguard. We do not transfer your health profile to the AI provider: prompts carry product information and your chosen language only.
5. Product data sources
Product information comes from Open Food Facts and Open Beauty Facts, community databases licensed under the Open Database License (ODbL); ingredient and nutrition text is reproduced from them. Cosmetic ingredient hazard data derives from open INCI datasets. When you scan a barcode we query these databases for that barcode. We send no personal data with the request.
6. How long we keep it
- Account and health profile — until you delete your account.
- Scan history and favourites — until you delete them or your account. Reaching a free-plan display limit hides older scans; it does not delete them.
- Receipt images — deleted immediately after text recognition completes, normally within seconds. They are never retained for training.
- Crash reports — 90 days.
- Notification delivery log — 30 days, to avoid sending duplicates.
Deleting your account erases all of the above within 30 days, except records we must keep for tax or accounting law (purchase records, typically 10 years in Türkiye), which are retained in isolation and not used for any other purpose.
7. Your rights
Under GDPR and KVKK you may: access your data; correct it; delete it; restrict or object to processing; receive it in a portable format; and withdraw consent at any time without affecting processing already carried out.
Account deletion and data export are available in the app under Profile → Account. You may also write to hello@horusstudios.com; we respond within 30 days. If you are unsatisfied you may complain to your local data protection authority, or in Türkiye to the KVKK.
8. Children
PureScan is not directed at children under 13 (under 16 in some countries), and we do not knowingly create accounts for them. A parent may create a family profile for a child; that profile holds only the details the parent enters and is controlled entirely by the parent's account.
9. Security
Data is encrypted in transit (TLS) and at rest. Database access is enforced row-by-row so one account can never read another's rows. Receipt images live in a private bucket reachable only through short-lived signed links. Access to production data is limited to staff who need it and is logged.
10. Not medical advice
PureScan provides general information about food and cosmetic products. Scores and warnings are calculated from public databases and published nutritional criteria. They are not a diagnosis, a treatment recommendation, or a substitute for advice from a qualified professional. Ingredient data can be out of date or incomplete — if you have an allergy, always read the physical package.
11. Changes
We will post any change here and, where it materially affects you, notify you in the app before it takes effect. Material changes to how we use health data will always ask for fresh consent.