Privacy Policy

Effective date: 4 August 2026

This policy explains what personal data the Grafta mobile app collects, why we process it, who we share it with, and how you can exercise your rights. Turkish version: Gizlilik Politikası.

1. Data controller

Dode Yazılım (“we”) develops Grafta and acts as the data controller.
Privacy and data requests: iletisim@dodeyazilim.com
General support: destek@dodeyazilim.com

2. Data we collect

CategoryContentsSource
AccountEmail address, display name and profile image (if any), user IDGoogle or Apple sign-in, or email sign-up
PhotosHair/beard photos you upload for analysis, recovery diary photos, hairline drawingsYour uploads
Analysis & contentHair loss stage assessment, graft estimate, AI preview images, diary notes, operation date, goalsIn-app usage
Community contentPosts and comments you share, your reports and blocksIf you use the community feature
Care & progressDaily care task completions, streak counter, badges, quiz and learning progressIn-app usage
Subscription dataSubscription status, purchase history, remaining credit balanceVia RevenueCat, through the App Store / Google Play
Technical dataDevice model, OS version, app version, language, crash reports, aggregated usage events, push tokenAutomatic
Clinic enquiryOnly if you choose to contact a clinic: your contact details and analysis summaryWith your explicit consent

We never see your payment details. All purchases are processed by the App Store or Google Play. Your card number and billing address stay with Apple/Google — we only receive whether your subscription is active.

3. Why we process your data

Legal bases

Under GDPR Art. 6 (and Turkey’s KVKK Art. 5) we rely on: performance of a contract (to deliver the service to you), consent (photo uploads, sharing with a clinic, push notifications, optional analytics), and legitimate interests (security, abuse prevention, troubleshooting). You can withdraw consent at any time.

4. Your photos and AI processing

Photos you upload are stored in private, non-public storage scoped to your account. No other user can access them; access rules are enforced at the database level.

To generate analyses and previews, your photos are transmitted temporarily to fal.ai, our AI processing provider. This happens only during an operation you initiate; photos are not permanently retained by the provider and are not used to train models.

We do not use photos for identity verification or biometric identification. Deleting a photo in the app also deletes it from storage.

5. Who we share data with

We do not sell your data and do not share it for advertising. We rely on the following providers to operate the service:

ProviderPurposeData shared
SupabaseDatabase, authentication, photo storageAccount, content and photos (EU servers)
fal.aiAI analysis and preview generationPhoto and text input during the operation (temporary)
RevenueCatSubscription state managementAnonymous customer ID, subscription status
Apple / GoogleSign-in, payments, notification deliveryAccount identifier, purchase record
SentryCrash and error reportingTechnical error records (EU servers)
PostHogProduct analyticsUsage events (EU servers)
ExpoPush notification deliveryDevice push token
Partner clinicsOnly if you submit an enquiryYour contact details and analysis summary

Some providers are located outside Türkiye and the EU (e.g. the United States). Such transfers are covered by standard contractual clauses and the providers’ data processing agreements.

6. Sharing with clinics

Your diary, analyses and photos are yours by default. A clinic can only see this information if you explicitly submit an enquiry and approve the sharing. You can withdraw that approval from within the app at any time.

7. Retention and deletion

8. Your rights

Under GDPR (and KVKK Art. 11) you have the right to:

Send requests to iletisim@dodeyazilim.com; we respond within 30 days at the latest. You can delete your account immediately, without waiting, using “Delete account” in the app.

9. Security

All traffic is carried over encrypted connections (HTTPS/TLS). Your photos are held in private storage protected by row-level access rules, so only you can reach your data. That said, no system can be guaranteed 100% secure.

10. Children

Grafta is not directed at children under 13 and we do not knowingly collect their data. If you are under 18, use the app only with the consent of a parent or guardian. If we learn that we have collected data from a child under 13, we delete it without delay.

11. Medical disclaimer

Grafta is not a medical device or healthcare service. Analyses, estimates and previews in the app are informational only and do not replace diagnosis, treatment or a physician’s advice.

12. Changes

We may update this policy from time to time. We will notify you in the app about material changes. The effective date at the top reflects the latest update.

13. Contact

Privacy and data requests: iletisim@dodeyazilim.com
Support: destek@dodeyazilim.com