Privacy Policy
WisoCare is designed privacy-first. This policy explains what data we collect, why we process it, who we share it with, and how you can exercise your rights.
Data Controller
Alp Kurbetci (app developer)
Contact: info@wisocare.com
Data We Collect
Below are the categories of data we collect and the service/technology that processes them:
- Account info (optional): Email, display name, provider (Apple/Google/password). Only stored if you create an account. (Firebase Authentication)
- Skin analysis metrics: CIELAB color values, z-scores, Fitzpatrick type, zone masks (numeric). No photos ever leave your device. (OpenAI API + local MMKV)
- Profile & health information: Your name, age range, gender, skin type, allergies, medications you take, pregnancy status, menstrual/reproductive-cycle data (last period date, cycle phase), self-reported skin-condition tendencies (sensitivity, acne/rosacea/atopic/eczema-prone), goals, lifestyle answers (smoking, alcohol, water, sleep, etc.). Stored on your device; if you sign in, backed up (encrypted) to your account together with your analysis history. Relevant health details are also sent to OpenAI for personalized recommendations. (MMKV encrypted + Firebase Firestore, Europe + OpenAI)
- Products & routine: Names and active ingredients of products you add, your morning/evening routine steps and completion history. Product names are sent to OpenAI for clash/recommendation checks; the full set is backed up to Firestore if you sign in. (OpenAI + Firebase Firestore)
- Cloud backup: If you create an account, your full profile, analysis/health history, products and routines are backed up as JSON to Google Cloud Firestore (Europe / eur3 region, not the US). Images are never included. You can turn cloud backup off in Settings. (Firebase Firestore)
- Usage behavior: Anonymized events (app_open, login, analysis_complete) tied only to a random device-level ID, plus basic context (app language). No account ID and no skin data are attached. (Google Analytics 4)
- Crash reports: Stack traces, OS version, app version, anonymized device type. No personally identifiable information. (Sentry)
- Advertising identifiers (iOS IDFA): Collected only if you grant App Tracking Transparency consent. Otherwise non-personalized ads are shown. (Google AdMob, Meta)
- Ad-conversion events (marketing measurement): To measure the results of our ad campaigns, event signals (app opened, trial started, subscribed; purchase value and currency) are sent to Meta. No photos or skin data are ever sent. With your ATT consent these events are linked to your advertising identifier (IDFA); this constitutes tracking in Apple's sense. (Meta / Facebook App Events)
- Location (optional): Your GPS coordinates never leave your device; only the resolved city name (text) and weather data (temperature, humidity, UV) are processed. These are sent to WeatherAPI.com for the weather and to OpenAI to adapt recommendations to your climate. You can decline; analysis continues and you can enter your city manually. · WeatherAPI.com + OpenAI
- AI content: A JSON summary of your skin metrics, your survey/profile answers (age, gender, skin type, allergies, medicines, pregnancy/cycle, skin condition tendencies, lifestyle), the names of the products in your routine and the ones you scan, your city and the current weather if you allow location, the chat messages you write to Wiso and your free-text notes are sent to OpenAI to produce personalised recommendations. No photo is sent. · OpenAI
- Face & image data: To analyze your skin the app detects facial landmarks (face geometry) and a skin-region mask on your device using on-device machine learning (MediaPipe). Used only to locate skin areas and compute the numeric metrics above. Photos, the facial-landmark mesh and the skin mask never leave your device; only a few derived quality/pose numbers (head angle, skin-area coverage ratio) are included in the metrics sent to OpenAI. (On-device + OpenAI for derived quality numbers)
Product scanning (Premium): If you scan a barcode or photograph a product's ingredient list, the barcode and the photo are processed only on your device (Apple Vision / Google ML Kit on-device text recognition); the photo is not stored, not uploaded, and is deleted as soon as processing ends. The ingredient list you confirm (ingredient names) is saved to your routine and may be stored with your profile backup. In addition, if you have an account we keep a record of each scan: which ingredients we recognized, which ones we could not (including the text fragments we failed to read), how much of the list we could read, and whether you saw the incomplete-reading warning and chose to continue. We keep this so we can document what we showed you if a problem comes up later; your photo is never uploaded under any circumstance. This record is tied to your account and is deleted when you delete it.
In addition, if you fully confirmed a list that you scanned from the label yourself or typed in, we save the product name, brand, barcode, the recognised ingredient names and a random installation-specific id to our shared product database. That random id exists only to count "how many different devices reported the same list"; no user id is stored, the record is not linked to your account, and it contains no unreadable raw text and no photo. Lists we found by searching the web are not sent to this pool (they are not your own reading). This contribution is on by default; you can turn it off in Settings, and nothing is sent from that moment on.
If we cannot find the product any other way, with your explicit consent we can search the web for its ingredient list by sending the product name to OpenAI's web search service; this permission is asked separately, the only thing sent is the product name (no photo, no barcode, no skin data), and any list found is shown together with its source. Product data may come from Open Beauty Facts (ODbL). · On-device processing; MMKV + Firestore (backup and scan record). On Android, Google ML Kit sends its own operational metrics (diagnostics such as version, error codes and processing time) to Google; your image and the recognized text are not sent.
- Chatting with Wiso: Messages you write to Wiso in the app are sent to OpenAI together with a summary of your skin analysis and your profile so it can answer in context. No photo is sent. If you do not give AI permission, or turn it off in Settings, chat never reaches the cloud and falls back to on-device answers. Your chat history is stored encrypted on your device only and is not included in the cloud backup; it is cleared if you delete the app, choose "Delete All Data", or delete your account. · OpenAI + local MMKV
Face & Image Data
When you take a selfie for analysis, the app uses on-device machine learning (MediaPipe) to detect facial landmarks (face geometry) and a skin-region segmentation mask. This processing happens entirely on your device. Your photo and the facial landmarks are never uploaded and never shared with anyone; only numeric metrics are extracted from your photos, which are held in your device's private temporary folder while that happens and deleted completely once every photo has been processed. We retain only the resulting numeric metrics (such as color values and redness/pigmentation scores); we never retain your photo or facial geometry. A few derived quality/pose numbers (head angle, skin-area coverage) are included in the metrics sent to OpenAI, but the photo, the landmark mesh and the skin mask themselves never leave the device. Face data is not used for identification, authentication, or biometric matching.
AI Processing & Data Sharing (OpenAI)
To build your personalised analysis and routine, the app sends the following to OpenAI, a third-party AI provider whose servers are in the USA: numerical skin metrics; your survey and profile answers (skin type, age range, goals, lifestyle answers, your free-text notes); your health information (your allergies, the medicines you take, your pregnancy status, your menstrual cycle, the skin condition tendencies you report); the names of the products in your routine and the ones you scan; if you allow location, your city and the current weather (temperature, humidity, UV); and the chat messages you write to Wiso. No photo and no facial geometry is sent. This data is gathered from your in-app input and your on-device analysis and is used only to produce skincare recommendations. Before any data is sent we ask for your explicit consent in the app; you can decline and still use routine tracking, and you can withdraw your consent at any time in Settings. OpenAI processes this data under its API data policy, which provides equivalent protection: data sent via the API is not used to train OpenAI's models, and international transfers are protected by Standard Contractual Clauses (SCC) or equivalent safeguards.
Health Information & Sources
Skin and ingredient guidance in the app is informational and educational only; it is not medical advice and not a diagnosis. Recommendations are based on published dermatology guidance, and the app links to credible sources (such as the American Academy of Dermatology, DermNet, NHS, the U.S. FDA, NIH/MedlinePlus, and ACOG) in its in-app "Sources & References" section, including next to the specific ingredients recommended. Always consult a dermatologist for diagnosis or treatment.
Processing Purposes
- To provide and improve the skin analysis service
- To authenticate you (with your optional account), back your data up to the cloud and restore it when you change devices
- To parse the ingredient lists of products you scan and compare them against the allergies and sensitivities you have declared
- To document what we showed you in a scan: which ingredients we recognised, which we could not, and whether you saw the incomplete-reading warning and chose to continue
- To grow our shared product database from the ingredient lists users confirm
- To detect and fix errors and performance problems
- To show ads on the free tier where applicable (none on premium)
- To meet legal obligations
Legal Basis
- Performance of a contract (KVKK art. 5/2-c, GDPR Art. 6(1)(b)): Processing necessary to provide the skin analysis and product scanning service.
- Explicit consent (KVKK art. 5/1, GDPR Art. 6(1)(a)): Location, advertising identifiers, personalised AI recommendations, searching the web for a product name.
- Explicit consent for health data (KVKK art. 6, GDPR Art. 9(2)(a)): Your allergies, the medicines you take, your pregnancy status, your menstrual cycle and the skin condition tendencies you report are special category personal data. They are processed and sent to OpenAI solely on the explicit consent you give on the consent screen shown before analysis. If you do not give that consent, this data is not sent and you can keep using routine tracking without it. You can withdraw your consent at any time in Settings.
- Legitimate interest (KVKK art. 5/2-f, GDPR Art. 6(1)(f)): Crash reports, product development, and contributions to the shared product database. A contribution record is not linked to your account and contains no photo and no unreadable raw text; it is precisely because the payload is this limited that we rely on legitimate interest. You have the right to object to this processing: turning the contribution off in Settings is treated as your objection, and nothing is sent from that moment on.
Third-Party Service Providers
The following providers may process your data. Review each one's privacy policy:
- Google (Firebase Authentication, Analytics, Cloud Firestore: encrypted cloud backup of profile/analysis/health history, Europe/eur3 region): https://policies.google.com/privacy
- Google AdMob (advertising): https://policies.google.com/technologies/ads
- Apple (Sign in with Apple): https://www.apple.com/legal/privacy/
- OpenAI (AI analysis): https://openai.com/privacy
- Google ML Kit (Android, on-device text recognition): Your image and the recognized text are not sent to Google; ML Kit only sends its own operational metrics (version, error codes, processing time). · https://policies.google.com/privacy
- Sentry (error reporting): https://sentry.io/privacy/
- WeatherAPI.com (weather): https://www.weatherapi.com/privacy.aspx
- RevenueCat (subscription / entitlement status): https://www.revenuecat.com/privacy
- Meta (Facebook) App Events (ad-conversion measurement; event signals and IDFA with ATT consent, no photos or skin data): https://www.facebook.com/privacy/policy
International Transfers
Your cloud backup (Firebase Firestore) is stored in the Europe (eur3) region and is not transferred to the US. Other third-party providers (OpenAI, Google Analytics/AdMob, Sentry, Apple, Meta, WeatherAPI) may operate servers in the United States. Transfers are protected under Standard Contractual Clauses (SCC) or equivalent mechanisms where required by GDPR. Where consent is required (e.g., Türkiye under KVKK Art. 9), processing relies on your explicit consent.
Data Retention
- Data on your device (profile, analysis history, chat history): Until you delete your account or remove the app.
- Cloud backup (Firebase Firestore): Until you delete your account or turn cloud backup off in Settings; in both cases the cloud copy is permanently deleted.
- Previous profile archive: If a different profile is restored onto the same account, the previous cloud copy that would be overwritten is kept as an archive record so you can get your old data back. It is deleted when you delete your account.
- Scan records: Records of the product scans you confirmed are kept for as long as your account exists and are deleted when you delete it.
- Account information (Firebase): Permanently deleted within 30 days if you delete your account.
- Usage analytics (Google Analytics 4): Anonymous, 14 months.
- Error logs (Sentry): 90 days.
Children
WisoCare is not designed for users under 16. To produce personalised advice the app processes health data (your allergies, the medicines you take, pregnancy status, menstrual cycle) and relies on your explicit consent to do so. Under GDPR Art. 8 the valid age for consent-based online services ranges from 13 to 16 depending on the country, and is 16 in many European countries; that is why we set the floor at 16. If you are under 16, please do not use the app. If we find that we have collected data from a user under 16, it is deleted immediately.
Your Rights
Under GDPR Art. 15-21 (and KVKK Art. 11 for Turkish users) you have the right to:
- Know what data we process
- Request correction
- Request deletion (right to be forgotten)
- Object to processing
- Receive your data in a portable format
- Object to automated decisions
Application: info@wisocare.com. We respond within 30 days.
Security Measures
- On-device storage is AES encrypted (MMKV)
- The cloud backup is encrypted server-side on Google infrastructure (Europe); only the authenticated account owner can access it
- Firebase Auth tokens are kept in the system keychain
- All network traffic uses HTTPS
- Photos are written only to the app's private temporary folder and deleted as soon as the analysis or scan ends; they are never uploaded. If you interrupt the three-phase capture, the frames already taken are kept in that same temporary folder for at most 30 minutes so you can resume, and are deleted when that window expires or the analysis completes.
Policy Changes
We may update this policy from time to time. Material changes will be announced via in-app notification or email. The last updated date is always at the top of this page.
Contact
For questions or to exercise your GDPR/KVKK rights:
Email: info@wisocare.com
We respond within 30 days as required by KVKK.