ℹ️ Este documento legal está actualmente disponible solo en inglés mientras se revisan las traducciones. La versión en inglés es la vinculante.
Who we are
Skinora (the "Service", "we", "us") — the Skinora mobile app and skinora.io — is operated by Halil Hilmi Karar, an individual software developer based in Türkiye, publishing under the developer name "Digital Sails". He is the data controller for personal data processed through the Service. See the Imprint for contact details.
Because we offer the Service to users in the European Union, the EU General Data Protection Regulation (GDPR) applies to those users, alongside the Turkish Personal Data Protection Law No. 6698 (KVKK).
What data we collect
We collect and process the following categories:
- Account data — name, email (from Google/Apple sign-in), user ID, preferred language.
- Facial images and skin analysis — selfies you upload for skin scans, and AI-derived skin metrics (acne, redness, pores, texture, hydration, oil, wrinkles, dark circles, melanin, skin type). We treat these as special-category data (GDPR Article 9; KVKK Article 6). See our Biometric Notice.
- Product data — product labels you scan, ingredient lists, barcodes, photos of packaging.
- Routine and chat data — routine choices, logs, streaks, messages sent to the AI coach.
- Optional lifestyle data — sleep, activity, and similar wellness metrics, only if you opt in to Apple Health / Google Fit sync.
- Device and usage data — device model, OS version, app version, crash logs, feature-level analytics.
- Payment data — subscriptions are billed by Apple App Store or Google Play. We never receive your card details; we receive only transaction confirmations needed to activate Premium.
Legal bases for processing
Under GDPR Articles 6 and 9 (and the corresponding KVKK provisions), we rely on:
- Contract — to provide the core app features you request.
- Explicit consent — for facial image analysis and optional lifestyle data sync. Consent is collected in the app before first use of these features, recorded with its version and timestamp, and you may withdraw it at any time (in the app or by emailing privacy@skinora.io).
- Legitimate interests — service analytics, security, abuse and fraud prevention.
- Legal obligation — tax and accounting records, responses to lawful requests.
Third-party processors
We use a small number of service providers to operate Skinora:
- DigitalOcean (Frankfurt, Germany — EU) — hosting of our servers and database.
- Google Firebase — image storage, push notifications, sign-in infrastructure.
- AILab — performs the AI skin analysis on images you submit for scanning. The image is transmitted for analysis and the resulting metrics are returned. Face scanning is strictly opt-in.
- OpenAI (USA) — processes chat messages you send to the AI coach and certain analysis tasks. Per OpenAI's API terms, API data is not used to train their models.
- Apple / Google — sign-in and subscription billing.
International transfers
Our primary hosting is in the EU (Frankfurt). Some processors operate outside your country (for example OpenAI in the USA, and AILab's analysis infrastructure). Where personal data is transferred internationally, we rely on the safeguards available under GDPR (such as Standard Contractual Clauses committed to by the processor) and KVKK, and — for facial images — on your explicit consent collected before your first scan. If you do not consent, the face scan feature simply stays off; the rest of the app remains usable.
Retention
We retain data only as long as needed:
- Facial images (scan photos and overlays): deleted automatically 90 days after your last scan, and in any case when you delete your account. Derived skin scores are kept so your trends keep working while your account is active.
- Chat history and routine data: until you delete them or your account.
- Crash logs and analytics: up to 13 months.
- Billing and transaction records: as long as required by applicable tax and commercial law (up to 10 years under Turkish law).
Account deletion is available in the app; deletion requests are also honored via privacy@skinora.io.
Your rights
Under GDPR and KVKK you have the right to: access your data, correct inaccuracies, delete your data, restrict or object to processing, data portability, and withdraw consent at any time. To exercise these rights, email privacy@skinora.io — we respond within 30 days.
You may also lodge a complaint with the Turkish Personal Data Protection Authority (kvkk.gov.tr) or, if you are in the EU/EEA, with your local data protection supervisory authority.
Children under 16
Skinora is not intended for users under 16, and we do not knowingly collect data from children. If you believe a child has signed up, please contact us at privacy@skinora.io and we will remove the account.
Security
All traffic is encrypted in transit (TLS). Images are stored in access-controlled cloud storage; API access requires authenticated tokens; administrative access is restricted and logged. No system is perfectly secure — keep your device and sign-in accounts (Google/Apple) protected.
Changes to this policy
We may update this policy. Material changes will be announced in the app before taking effect. The "Last updated" date above shows the current version.
Contact
Data & privacy requests: privacy@skinora.io
General contact: hello@skinora.io