Privacy Policy

Effective date: 27 September 2026

This policy explains what personal data the Grafta mobile app collects, why we process it, who we share it with, and how you can exercise your rights. Turkish version: Gizlilik Politikası.

1. Data controller

Dode Yazılım (“we”) develops Grafta and acts as the data controller.
Privacy and data requests: iletisim@dodeyazilim.com
General support: destek@dodeyazilim.com

2. Data we collect

CategoryContentsSource
AccountUser ID; if you link an account, email address, display name and profile image (if any)Guest session (anonymous ID); optional Google or Apple sign-in
PhotosHair, beard, mustache and eyebrow photos you upload for analysis; recovery diary, Check-in and care task photos; symptom photos you send to your clinic; operation passport documents; hairline drawingsYour uploads
Analysis & contentHair loss stage assessment, graft estimate, AI preview and 12-month progress images, diary notes, symptom logs, procedure date, goalsIn-app usage
Community contentPosts and comments you share, your reports and blocksIf you use the community feature (not available in the current version)
Care & progressDaily care task completions, streak counter, quiz and learning progressIn-app usage
Purchase dataCredit pack purchase history, credit transactions and remaining credit balanceVia RevenueCat, through the App Store / Google Play
Technical dataDevice model, OS version, app version, language, crash reports, aggregated usage events, push tokenAutomatic
Location (optional)Only if you allow it on the Clinics ▸ Find screen: your device's approximate location (precise location is never requested), used to sort nearby clinics by distance and center the map. It is processed on your device; it is not sent to our servers, analytics or crash reports, and it is not stored. To draw the map, map tiles for the area on screen are downloaded from OpenFreeMap; these requests reveal the area being viewed (approximate location) and your IP address.Device location permission (you can turn it off in Settings at any time)
Clinic requests & messagesOnly if you send a consultation request to a clinic or connect with your clinic: your name, contact details (email, phone or WhatsApp), your messages, and only the analysis photos and hair designs you choose to shareWith your explicit consent

We never see your payment details. All purchases are processed by the App Store or Google Play. Your card number and billing address stay with Apple/Google — we only receive which credit pack you bought and the transaction record (e.g. whether it was refunded).

3. Why we process your data

Legal bases

Under GDPR Art. 6 (and Turkey’s KVKK Art. 5) we rely on: performance of a contract (to deliver the service to you), consent (photo uploads, sharing with a clinic, push notifications, optional analytics), and legitimate interests (security, abuse prevention, troubleshooting). You can withdraw consent at any time.

4. Your photos and AI processing

Photos you upload are stored in private, non-public storage scoped to your account. No other user can access them; access rules are enforced at the database level.

Exception — community posts (the community feature is not available in the current version; this applies once it is): photos and captions you choose to share in the community are shown to other users. Before a post becomes visible to others it is automatically screened through fal.ai for objectionable content (nudity, violence, hate speech, advertising, contact details, etc.); posts that break the rules are not published and stay visible only to you. You can delete your post at any time.

For analysis, your photos are transmitted temporarily to fal.ai (model: Anthropic Claude). To generate previews and the 12-month progress, your photo is sent to OpenAI; if OpenAI is unavailable, to fal.ai as a backup (ByteDance Seedream), and to fal.ai (Meta SAM) to mask the hair area so your face stays unchanged. This happens only during an operation you initiate; the providers use the data only to process the request and do not use it to train models. OpenAI may keep API data for up to 30 days for abuse monitoring.

A preview changes only the hair, beard, mustache or eyebrow area; your face and the rest of the photo stay as they are. Every generated preview image passes an automatic safety check before it is shown to you. An image that fails is not stored and the credit spent is refunded to your balance; after several rejections in a short time (3 in 30 minutes) preview generation pauses for a while. If the check cannot run, the image is never shown unchecked and the credit is refunded as well.

We do not use photos for identity verification or biometric identification. Deleting a photo in the app also deletes it from storage.

5. Who we share data with

We do not sell your data and do not share it for advertising. We rely on the following providers to operate the service:

ProviderPurposeData shared
SupabaseDatabase, authentication, photo storageAccount, content and photos (servers in Australia, Sydney)
OpenAIGenerating preview and 12-month progress images (primary image-editing provider), the hair coach, message translation in clinic conversations, content screening of text sent to these two features, and safety screening of AI-generated preview images before they are shownFor the coach, your question and conversation context; for translation, only the text of the translated message; for preview and 12-month progress generation, your photo and the chosen style; for image screening, the generated preview image (US servers; OpenAI does not use API data to train models and may keep it for up to 30 days for abuse monitoring)
fal.aiAI analysis and community content screening (model: Anthropic Claude via fal.ai); backup generation of preview and 12-month progress images when OpenAI is unavailable (model: ByteDance Seedream via fal.ai); masking the hair area to be edited so your face stays unchanged (model: Meta SAM via fal.ai); a backup NSFW check of generated preview images when OpenAI is unavailable; fallback for the coach and message translation when OpenAI is temporarily unavailable (model: OpenAI GPT-4o mini via fal.ai)Photo and text input during the operation (temporary); when the fallback is used, the coach question and conversation context or the text of the translated message
RevenueCatVerifying and recording in-app purchasesAnonymous customer ID, purchase records
Apple / GoogleSign-in, payments, notification deliveryAccount identifier, purchase record
SentryCrash and error reportingTechnical error records (EU servers)
PostHogProduct analyticsUsage events (EU servers)
ExpoPush notification deliveryDevice push token
ResendSending transactional emails (e.g. clinic requests and clinic notifications)Email address and email content; in a clinic request, your name, contact details and message (US servers)
CloudflareHosting and serving our websites (CDN), form security (Turnstile)Technical request logs (including IP address) and browser signals from the security check (global network)
OpenStreetMap Foundation (Nominatim)Turning a clinic's business address into a map location in the clinic panelThe business address the clinic types in the panel; the request goes from our server, your IP address is not sent
Browser push services (Google FCM, Mozilla, Apple, Microsoft)New request and message notifications for clinic panel staff only (if staff turn them on)The browser's push subscription address and keys; notifications never contain patient names or message text
OpenFreeMap and unpkgServing the clinic map tiles and the map library (MapLibre)The map area shown on screen (approximate location) and technical request data (including IP address); not linked to your account
Clinics you chooseOnly if you send a consultation request or connect with your clinicYour name, contact details, messages, and only the photos and designs you choose to share

Some providers are located outside Türkiye and the EU (e.g. the United States and Australia). Such transfers are covered by standard contractual clauses and the providers’ data processing agreements.

6. Sharing with clinics

Your diary, analyses and photos are yours by default. A clinic can only see them if you choose to share them in a request, or turn on sharing after you connect with your clinic. You can withdraw sharing in the app at any time: new access stops immediately; a link to an image already open at the clinic stays valid for at most 5 more minutes. Copies the clinic saved earlier cannot be recalled. Once you connect with your clinic, it can prepare a care plan for you and message you.

Per-clinic sharing and leaving a clinic. Sharing is set separately for each clinic: the “Share my diary” switch on the clinic card lets you choose which clinic can see your diary and analyses. When you choose “Leave clinic”, that clinic can no longer see your diary, photos or analyses; the record and notes the clinic kept about you (alias, graft count, technique, note) are deleted, and your personal care plan copy is archived. Past messages stay in the clinic's panel as a record; after you leave, neither side can send new messages. To reconnect with the same clinic, you need a new invite code from the clinic.

Clinic reviews. Clinic reviews and ratings are not available in this version; Grafta does not collect or publish user reviews of clinics.

Message translation. When you or the clinic tap “Translate” under a message, only the text of that message is sent to OpenAI (our AI processing provider; if OpenAI is temporarily unavailable, to fal.ai as a fallback, model: OpenAI GPT-4o mini) for translation. The translation is not stored; it is shown with a “Machine translation” label, and the original should be checked before any medical decision. No message is sent to the provider unless a translation is requested. Photos and attachments of the message are not sent.

Content screening of coach questions and messages to be translated. Before a reply or translation is generated, the question you write to the coach and any message to be translated are first checked for sexual content, content involving minors, self-harm methods, and violence or weapons: first against a word list on our server, then with OpenAI’s moderation service and an OpenAI classification model. Only the text is checked; no photos are sent. A question that does not pass is not answered and does not count toward your daily limit (a rejection by the AI provider's own safety system does count); the question text is not stored — only the time and category of the rejection (e.g. “sexual”) are kept, linked to your account. After several rejections in a short time (3 in 30 minutes) the coach stops accepting new questions for a while. These records are deleted when you delete your account. If the screening service cannot be reached, the question is never sent unchecked; the coach is temporarily unavailable instead. If a question mentions thoughts of self-harm, the coach does not penalize it; it shows a support card pointing to local emergency services and findahelpline.com.

7. Retention and deletion

8. Your rights

Under GDPR (and KVKK Art. 11) you have the right to:

Send requests to iletisim@dodeyazilim.com; we respond within 30 days at the latest. You can delete your account immediately, without waiting, using “Delete my account and data” in the app.

9. Security

All traffic is carried over encrypted connections (HTTPS/TLS). Your photos are held in private storage protected by row-level access rules, so only you can reach your data. That said, no system can be guaranteed 100% secure.

10. Children

Grafta is not directed at children under 13 and we do not knowingly collect their data. If you are under 18, use the app only with the consent of a parent or guardian. If we learn that we have collected data from a child under 13, we delete it without delay.

11. Medical disclaimer

Grafta is not a medical device or healthcare service. Analyses, estimates and previews in the app are informational only and do not replace diagnosis, treatment or a physician’s advice.

12. Changes

We may update this policy from time to time. We will notify you in the app about material changes. The effective date at the top reflects the latest update.

13. Contact

Privacy and data requests: iletisim@dodeyazilim.com
Support: destek@dodeyazilim.com