Last updated: 29 September 2026
This policy explains how your personal data is processed when you use the KitchenIQ mobile app (the "App"). It is the information notice required by the EU General Data Protection Regulation ("GDPR") and the information notice under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK").
1. Data controller
- Company name: ZERO SOFTWARE SOLUTIONS BİLİŞİM YAZILIM DANIŞMANLIK İTHALAT VE İHRACAT LİMİTED ŞİRKETİ
- Address: Ehlibeyt mah Tekstilciler cd no:35/7 Çankaya/Ankara
- Personal data requests: kvkk@zss.ai
- Support: destek@zss.ai
- VERBİS (Turkish data controllers' registry): [VERBİS KAYIT NO / MUAFİYET]
- EU representative (Art. 27 GDPR): [AB TEMSİLCİSİ]
2. In short
- We do not sell your data, we do not use it for advertising, and we do not track you on other apps or websites.
- The App processes the data it needs to track your pantry and to prepare menus and shopping lists for you.
- Your allergies, your diet and your optional body information count as health data. We process them only with your explicit consent and only to suggest menus that are safe for you.
- For the AI features and receipt reading, some data is sent to service providers abroad (Section 6).
- You can delete your account from the App at any time (Section 8).
3. What data do we process?
3.1 Account information
Your email address, your name (optional), your password (stored only as an irreversibly encrypted "hash"; even we cannot see your password), your language preference and session information.
3.2 Preferences and health data
- Household size, number of servings, the meals you cook, your cooking habits, how you plan (weekly / day by day), units of measurement, notification settings, ingredients you dislike and cuisines you like.
- Special categories of personal data: your allergies; your diet (such as vegan, vegetarian, halal or kosher — some of these may also reflect religious beliefs); and, if you choose to provide them, your daily calorie/protein target and your age, gender, weight, height and activity level.
3.3 Pantry, menus and shopping
The items you add to your pantry (name, quantity, expiry date, storage location, whether it has been opened, your notes, and how it was added: manually, by barcode or from a receipt), your weekly and daily menus, your shopping lists, records of the dishes you cook and your ratings, your favorites, the recipes you liked or skipped, your leftovers and your event menus (number of guests, dietary restrictions, budget).
3.4 Receipt photos
When you scan a grocery receipt, the photo is processed to read the items. The text that is read and the list of items are stored in your account. The photo itself is deleted when you confirm the scan or when reading fails. Photos from scans you leave unfinished stay on the server's temporary disk for a short time, and the server is reset with every update.
3.5 Content you create
Recipes you add yourself and their photos. If you choose to share a recipe, the recipe, its photo and your name (if you have given one) are visible to other users. Your email address is never shown.
3.6 What you write to the AI
The texts you write to the AI assistant are sent to the service provider to generate a response. We do not store these texts.
3.7 Feedback
The feedback message you send from within the App, together with the app version, operating system version, device model and the name of the screen that was open at the time.
3.8 Notifications
Your device's notification key ("push token"), so that we can send you notifications. Notification texts may include the names of items in your pantry or dishes on your menu. You can turn off notifications in the app settings or in your device settings.
3.9 Usage and error logs
- Usage analytics: events about which features you use and when (e.g. "menu created", a scanned barcode). These records are linked not to your email address but to a random ID assigned to your account (they are pseudonymous); they are not anonymous.
- Error reports: when the App or the server runs into an error, technical details and device and operating system information; for server errors, also your account ID. Error reports do not include screenshots.
- Server logs: technical logs such as IP address and the time and address of requests, kept for security and debugging.
3.10 Data we do not collect
Location, contacts, your whole photo library (only the photo you select), microphone recordings, advertising ID (IDFA) and payment information. The App currently has no paid features and no in-app purchases.
4. For what purposes and on what legal basis?
| Purpose | Data | Legal basis |
|---|---|---|
| Creating an account, signing in, resetting your password | Account information | Entering into and performing the contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Pantry tracking, expiry reminders, menus and shopping lists | Preferences, pantry, menu and shopping data | Performing the contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Menus that suit your allergies and diet and match your nutrition targets | Allergies, diet, body information, nutrition targets | Explicit consent (GDPR Art. 9(2)(a); KVKK Art. 6(2)) |
| AI suggestions, recipe explanations and adaptations, receipt reading | The data listed in Section 6 | Performing the contract; for transfers abroad, see Section 6 |
| Sending notifications | Notification key, notification content | Performing the contract; the notification permission on your device |
| Finding errors, security, improving the App | Usage and error logs, server logs | Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Legal obligations and responding to requests | The relevant data, as far as necessary | Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
You can withdraw your explicit consent: you can delete or change your allergy, diet and body information at any time in Profile › Diet & Allergies. You can use the App without this information, but the allergen filter and planning based on your nutrition targets will not work.
Your data is assessed by automated systems only to prepare menu suggestions for you. This does not involve any decision that has legal effects on you or affects you in a similarly significant way.
5. Where is your data stored?
Our app server and database are hosted in Germany (Frankfurt, EU). The service providers in Section 6 process data on their own infrastructure.
6. Who do we share your data with?
We share your data only with the service providers (processors) below that we need to provide the service, and only as much as needed. We do not allow any of them to use your data for their own purposes.
| Service provider | Purpose | Data | Location |
|---|---|---|---|
| Fly.io | Server and database hosting | All data in the App | Germany (EU) |
| Cloudflare (R2) | File storage, database backups | Your recipe photos, backups | US-based, global infrastructure |
| Upstash | Temporary cache | Cache of suggestions personalized for you, daily notification counter | US-based |
| Anthropic | AI features | What you write to the AI; for explaining and checking menus: household size, diet, allergies, some items from your pantry and their expiry dates, the dishes on your menu; for explaining, adapting and translating recipes: recipe content (including recipes you create); for event menus: number of guests, dietary restrictions, budget. Your email address and name are not sent. | US |
| Google (Gemini API) | Reading receipt photos | Receipt photo | US |
| PostHog | Usage analytics | Usage events, your account's random ID | Germany (EU) |
| Sentry | Error reporting | Technical error details, device information, account ID for server errors | Germany (EU) |
| Expo (and Apple) | Delivering notifications, app updates | Notification key, notification text | US |
| Resend | Sending emails | Your email address, password reset code | US |
| Slack | Forwarding feedback to our team | Feedback message, device and version information, part of your account ID | US |
| Open Food Facts | Finding product names from barcodes | Barcode number only (contains no personal data) | France (EU) |
The App is distributed through the Apple App Store. Apple's own processing is governed by Apple's privacy policy.
Where the law requires it, data may be shared with authorized public authorities or courts, only to the extent requested.
Transfers abroad
Some of the providers above are located outside Turkey and the EU (in the US). These transfers are made with appropriate safeguards (standard contractual clauses and the providers' data processing agreements) under Chapter V of the GDPR and Article 9 of the KVKK.
7. How long do we keep your data?
- We keep your data for as long as your account is open.
- When you delete your account, your account information, preferences, health data, pantry, menus, lists, records, receipt scans and notification key are deleted from our live systems immediately and permanently. Recipes you created are unpublished and their photos are deleted.
- Usage analytics records are made anonymous by removing their link to your account.
- Database backups are kept for up to 30 days; after that, deleted data is also gone from the backups.
- Error reports and server logs are kept for a short time and are subject to the service providers' retention periods.
- Data that we are legally required to keep is kept for the period set by the relevant legislation.
8. Your rights
Under Articles 15–22 GDPR and Article 11 KVKK, you have the right to: find out whether your data is processed; ask for information and a copy; have your data corrected; have it deleted; restrict its processing; receive your data in a portable format; object to its processing; find out which third parties your data has been transferred to; withdraw your consent; object to a result against you that comes solely from analysis by automated systems; and claim compensation for damage caused by unlawful processing.
How to use your rights
- Correction: you can change your information and preferences in Profile.
- Account deletion: Profile › Delete Account (confirmed with your password).
- Other requests: write to kvkk@zss.ai from the email address registered to your account. We will handle your request free of charge within 30 days at the latest.
If you are not satisfied with our response to your request, you can file a complaint with the Turkish Personal Data Protection Authority (KVKK). If you live in the EU, you also have the right to complain to the data protection supervisory authority in your country.
9. Security
Data is sent between your device and our server over an encrypted connection (HTTPS/TLS). Passwords are stored in a form that cannot be reversed. Session keys are kept in your device's secure storage. Access to data is limited to authorized systems and people.
10. Children
The App is not designed for children under 16. We do not knowingly collect personal data from anyone under 16. If you notice such a case, let us know at kvkk@zss.ai and we will delete the account.
11. Changes
We may update this policy. We will announce important changes in the App. The current version is always on this page. The date at the top of the page is the date of the last update.
12. Contact
For questions: kvkk@zss.ai · ZERO SOFTWARE SOLUTIONS BİLİŞİM YAZILIM DANIŞMANLIK İTHALAT VE İHRACAT LİMİTED ŞİRKETİ, Ehlibeyt mah Tekstilciler cd no:35/7 Çankaya/Ankara
