Privacy Policy
WisoCare is designed privacy-first. This policy explains what data we collect, why we process it, who we share it with, and how you can exercise your rights.
Data Controller
Alp Kurbetci (app developer)
Contact: info@wisocare.com
Data We Collect
Below are the categories of data we collect and the service/technology that processes them:
- Account info (optional): Email, display name, provider (Apple/Google/password). Only stored if you create an account. (Firebase Authentication)
- Skin analysis metrics: CIELAB color values, z-scores, Fitzpatrick type, zone masks (numeric). No photos ever leave your device. (OpenAI API + local MMKV)
- Profile & health information: Your name, age range, gender, skin type, allergies, medications you take, pregnancy status, menstrual/reproductive-cycle data (last period date, cycle phase), self-reported skin-condition tendencies (sensitivity, acne/rosacea/atopic/eczema-prone), goals, lifestyle answers (smoking, alcohol, water, sleep, etc.). Stored on your device; if you sign in, backed up (encrypted) to your account together with your analysis history. Relevant health details are also sent to OpenAI for personalized recommendations. (MMKV encrypted + Firebase Firestore, Europe + OpenAI)
- Products & routine: Names and active ingredients of products you add, your morning/evening routine steps and completion history. Product names are sent to OpenAI for clash/recommendation checks; the full set is backed up to Firestore if you sign in. (OpenAI + Firebase Firestore)
- Cloud backup: If you create an account, your full profile, analysis/health history, products and routines are backed up as JSON to Google Cloud Firestore (Europe / eur3 region, not the US). Images are never included. You can turn cloud backup off in Settings. (Firebase Firestore)
- Usage behavior: Anonymized events (app_open, login, analysis_complete) tied only to a random device-level ID, plus basic context (app language). No account ID and no skin data are attached. (Google Analytics 4)
- Crash reports: Stack traces, OS version, app version, anonymized device type. No personally identifiable information. (Sentry)
- Advertising identifiers (iOS IDFA): Collected only if you grant App Tracking Transparency consent. Otherwise non-personalized ads are shown. (Google AdMob, Meta)
- Ad-conversion events (marketing measurement): To measure the results of our ad campaigns, event signals (app opened, trial started, subscribed; purchase value and currency) are sent to Meta. No photos or skin data are ever sent. With your ATT consent these events are linked to your advertising identifier (IDFA); this constitutes tracking in Apple's sense. (Meta / Facebook App Events)
- Location (optional): GPS coordinates never leave your device; only the city name (string) and weather data (temperature, humidity, UV) are processed. You can deny; analysis continues. (WeatherAPI.com)
- AI content: A JSON summary of your skin metrics, your survey/profile answers (age, gender, skin type, allergies, medications, pregnancy/cycle, skin-condition tendencies, lifestyle) and the free-text notes you write are sent to OpenAI to generate recommendations. This is an identifiable health and lifestyle profile. No photos are sent. (OpenAI)
- Face & image data: To analyze your skin the app detects facial landmarks (face geometry) and a skin-region mask on your device using on-device machine learning (MediaPipe). Used only to locate skin areas and compute the numeric metrics above. Photos, the facial-landmark mesh and the skin mask never leave your device; only a few derived quality/pose numbers (head angle, skin-area coverage ratio) are included in the metrics sent to OpenAI. (On-device + OpenAI for derived quality numbers)
Face & Image Data
When you take a selfie for analysis, the app uses on-device machine learning (MediaPipe) to detect facial landmarks (face geometry) and a skin-region segmentation mask. This processing happens entirely on your device. Your photo and the facial landmarks are never uploaded, never shared with anyone, and never written to disk; they exist only in memory during the few seconds of analysis and are deleted immediately afterward. We retain only the resulting numeric metrics (such as color values and redness/pigmentation scores); we never retain your photo or facial geometry. A few derived quality/pose numbers (head angle, skin-area coverage) are included in the metrics sent to OpenAI, but the photo, the landmark mesh and the skin mask themselves never leave the device. Face data is not used for identification, authentication, or biometric matching.
AI Processing & Data Sharing (OpenAI)
To generate your personalized analysis and routine, the app sends a JSON summary of your numeric skin metrics, your survey and profile answers (skin type, age range, gender, allergies, medications, pregnancy status, menstrual-cycle phase, self-reported skin conditions, goals, lifestyle answers), your product names and your free-text notes to OpenAI, a third-party AI provider with servers in the United States. This constitutes an identifiable health and lifestyle profile. No photos and no raw facial geometry (landmark mesh or mask) are ever sent; only a few derived quality/pose numbers. This data is collected from your in-app inputs and your on-device analysis, and is used solely to produce your skincare recommendations. We ask for your explicit consent inside the app before any data is sent; you can decline and still use routine tracking. OpenAI processes this data under its API data policy, which provides equivalent protection: data submitted via the API is not used to train OpenAI's models, and international transfers are covered by Standard Contractual Clauses (SCC) or equivalent safeguards.
Health Information & Sources
Skin and ingredient guidance in the app is informational and educational only; it is not medical advice and not a diagnosis. Recommendations are based on published dermatology guidance, and the app links to credible sources (such as the American Academy of Dermatology, DermNet, NHS, the U.S. FDA, NIH/MedlinePlus, and ACOG) in its in-app "Sources & References" section, including next to the specific ingredients recommended. Always consult a dermatologist for diagnosis or treatment.
Processing Purposes
- To provide and improve the skin analysis service
- To authenticate you (via optional account) and sync across devices
- To detect and fix errors and performance issues
- To show ads in the free tier where applicable (none in premium)
- To comply with legal obligations
Legal Basis
- Performance of contract (GDPR Art. 6(1)(b)): Processing necessary to deliver the skin analysis service.
- Explicit consent (GDPR Art. 6(1)(a)): Location, advertising identifiers, personalized AI suggestions.
- Legitimate interest (GDPR Art. 6(1)(f)): Crash reports, product improvement.
Third-Party Service Providers
The following providers may process your data. Review each one's privacy policy:
- Google (Firebase Authentication, Analytics, Cloud Firestore: encrypted cloud backup of profile/analysis/health history, Europe/eur3 region): https://policies.google.com/privacy
- Google AdMob (advertising): https://policies.google.com/technologies/ads
- Apple (Sign in with Apple): https://www.apple.com/legal/privacy/
- OpenAI (AI analysis): https://openai.com/privacy
- Sentry (error reporting): https://sentry.io/privacy/
- WeatherAPI.com (weather): https://www.weatherapi.com/privacy.aspx
- RevenueCat (subscription / entitlement status): https://www.revenuecat.com/privacy
- Meta (Facebook) App Events (ad-conversion measurement; event signals and IDFA with ATT consent, no photos or skin data): https://www.facebook.com/privacy/policy
International Transfers
Your cloud backup (Firebase Firestore) is stored in the Europe (eur3) region and is not transferred to the US. Other third-party providers (OpenAI, Google Analytics/AdMob, Sentry, Apple, Meta, WeatherAPI) may operate servers in the United States. Transfers are protected under Standard Contractual Clauses (SCC) or equivalent mechanisms where required by GDPR. Where consent is required (e.g., Türkiye under KVKK Art. 9), processing relies on your explicit consent.
Data Retention
- On-device data (profile, analysis history): Until you delete your account or uninstall.
- Cloud backup (Firebase Firestore): Until you delete your account or turn off cloud backup in Settings; in both cases the cloud copy is permanently deleted.
- Account info (Firebase): Permanently deleted within 30 days of account deletion.
- Analytics: Anonymized, 14 months (Firebase default).
- Crash logs: 90 days (Sentry default).
Children
WisoCare is not designed for users under 13. If you are under 13, please do not use the app. If we discover we have collected data from a child under 13, we will delete it immediately.
Your Rights
Under GDPR Art. 15-21 (and KVKK Art. 11 for Turkish users) you have the right to:
- Know what data we process
- Request correction
- Request deletion (right to be forgotten)
- Object to processing
- Receive your data in a portable format
- Object to automated decisions
Application: info@wisocare.com. We respond within 30 days.
Security Measures
- On-device storage is AES-encrypted (MMKV)
- Cloud backup is encrypted at rest on Google infrastructure (Europe); only the authenticated account owner can access it
- Firebase Auth tokens stored in the system keychain
- All network traffic uses HTTPS
- Photos are never written to disk; deleted from memory after analysis
Policy Changes
We may update this policy from time to time. Material changes will be announced via in-app notification or email. The last updated date is always at the top of this page.
Contact
For questions or to exercise your GDPR/KVKK rights:
Email: info@wisocare.com
We respond within 30 days as required by KVKK.