Privacy Policy
This policy explains how your personal data is collected, used and protected when you use the Etika mobile app (the “App”). By using the App you accept this policy.
1. Data controller
The App is provided by COMCE (“we”, “us”). For anything related to privacy, our single point of contact is destek@etikaapp.com.
2. Data we process
Account information
When you sign in with Google or Apple, the authentication service may share your name, email address and (to the extent the provider shares it) profile photo. You never create a password. Signing in is optional — you can use the App as a guest.
Profile and preferences
Your allergies, food sensitivities, additive/ingredient preferences and nutrient threshold settings are stored so the App can show warnings that apply to you. When you are signed in these preferences are linked to your account; as a guest they stay on your device only.
Scans, searches and product data
The barcodes you scan or search for and the related product information (name, brand, ingredients, nutrition values, allergen/additive labels, image address, etc.) are used to provide the App’s core function. Catalog data is served from our own database.
Most viewed products (anonymous counting)
To build shelves such as “Most viewed this week” on the search screen, the barcodes of products you scan or open from search are added to daily totals without being linked to your identity. Along with the barcode and the date, the server receives the random installation number described under Technical data below — even when you are signed in, your account, email address or persistent device number is not sent. The installation number only ensures that the same device counts the same product once per day: the server does not keep the number itself but an irreversible digest made with a secret key and the date, which cannot be matched from one day to the next and is deleted after two days. What remains is only the total “how many devices viewed this product on this day”; it does not reveal who viewed what, and products viewed by only a few devices are not shown in rankings. Products you open from favorites, history or a list are not counted.
Missing barcode reports
When you scan a barcode that is not in the catalog, the barcode number may be stored on our servers (without being linked to your identity) so we can track which products are missing.
Adding a product (user contribution)
When a barcode is not in the catalog you may send us one photo of the product. This is entirely optional, starts only when you confirm it, and does not require signing in.
When you submit, the following is stored on our servers: the barcode you scanned and the single photo you took. The photo is not public; it stays in a moderation area visible only to us and is used to identify the product while we add it to the catalog. The product details (name, brand, ingredients, nutrition values) are entered by us and come from our own sources, not from your submission.
For moderation and abuse prevention, your account email address (if you are signed in), device model, operating system version and an installation number generated by the App are attached to the submission. This information is not published and is visible only to us. Submissions that are not reviewed are deleted within 60 days.
Missing nutrition value (unscored product)
If a product cannot be scored only because a single nutrition value (saturated fat, salt or sugars) is missing, the app may ask you for that value. Answering is optional and does not require an account. When you send it, we store the barcode, the single number you typed and, if you choose, one photo of the nutrition table, together with — as with product reports — your email address (if signed in), device model, operating system version and install number. The value is not written to the product until we approve it; once approved it becomes part of the product's nutrition table. The photo is not public and is deleted within 60 days; decided reports are deleted after 90 days.
Etika points
If you are signed in, each contribution we approve (a missing product or missing nutrition value report) is credited to your account as Etika points, which can be exchanged for time-limited Etika+ at a set threshold. For this we keep a record of point movements linked to your account (date, points, type of contribution) and the end date of any Etika+ obtained with points. This record is never published and is deleted together with your account. No points are kept for guest use.
Favorites
Products you favorite (barcode and a product summary) are stored against your account. As a guest they stay on your device only.
Shopping lists
Shopping lists you create (list name, the barcode and product summary of each item, quantities) are stored against your account and synced across your devices. As a guest they stay on your device only. The list average score and the alternatives suggested to you are calculated on your device; those results are not sent to the server. Your lists are permanently deleted when you delete your account.
If you choose to share a list, a random link is generated for it and anyone holding that link — signed in or not — can see the list name, its items and quantities, and can copy the list into their own account. Your identity is not shared: the link does not reveal your name, email or account. The link shows the current state of the list, so if you change the list, people opening the link see the new version. You can stop sharing at any time from the App and the link immediately stops working (lists already copied stay with the person who copied them). Sharing is off by default and only you can start it.
A signed-in user who opens the link can also choose to join the list (a shared list). A member sees the list name and items with you and can edit it: add or remove products, change quantities and tick items off; they see your changes too. To make this work, which account joined which list is stored on the server. You are only shown how many people joined your list; the member's name or email is not shown to you, and your identity is not shown to them. Up to five people can join a list. When you stop sharing, members are removed from the list; a member can also leave at any time. Deleting your account deletes your lists and your memberships.
Scan history
Products you scan (barcode, a product summary and the time of the scan) are kept in your history. As a guest, your history stays on your device only. When you sign in, it is also stored on our servers linked to your account and synced across your devices; the history you built before signing in is moved to your account at that moment. There is no limit on the number of entries; scanning the same product again updates its date instead of adding a new entry, and the number of separate times you scanned it is counted (the shelf of products you view often reads this number on your device). You can delete entries one by one or clear the whole history in the app, and deletions reach your other devices too. When you sign out, the copy on the device is deleted; the copy on the server stays with your account.
Local cache and offline catalog
For faster startup and offline use, product information may be cached temporarily on your device, and offline catalog files may be downloaded through our content delivery network.
Camera and photos
The camera is used to read barcodes; the camera image is not stored or transmitted — only the decoded barcode number is processed.
Beyond that, a photo is uploaded in three cases, and only with your confirmation:
- When you report a missing product, the single photo you take is used for moderation only, is not public, and is deleted within 60 days.
- When you report an error on an existing product, any photo you attach is used for moderation only, is not public, and is deleted within 60 days of the review being completed.
- When you send a missing nutrition value for an unscored product, the optional photo of the nutrition table is used only to verify the value, is not public, and is deleted within 60 days.
For error reports you can take the photo with the camera or pick it from your gallery; for missing-product reports the photo is taken with the camera. In both cases, sending a photo is never required.
Technical data
Technical data such as device type, operating system version and session information may be processed to operate and secure the App and to troubleshoot problems.
When you submit a product or an error report, the device model, operating system version and a random installation number generated by the App on your device are attached to the report. This number is not an advertising identifier and does not identify you; it exists to prevent abuse (unlimited reports from one device) and to group reports, and it disappears when you uninstall the App.
To grant a promotional free usage period (the launch gift) once per device, a separate and persistent device number is used: on iOS a random number kept in the app’s keychain, on Android the app-specific installation number generated by the operating system. Unlike the one above, this number stays the same even if you delete and reinstall the App; its only purpose is to avoid granting the same gift twice to the same device. Only an irreversible hash of it is sent to the server, never the number itself. It is not an advertising identifier, does not identify you, cannot be read by other apps and is not used to track you across apps. It resets when you factory reset your device.
Crash reports and usage measurement
If the App closes unexpectedly or an error occurs, the technical detail of the error (stack trace), device model, operating system version and app version are sent to Firebase Crashlytics and Sentry. These records exist only to find and fix bugs. No screenshot is taken, and your user id, email address, IP address, the barcodes you scanned and your sensitivity selections are not included. Only technical tags such as app language, whether you are signed in and your subscription status are attached. To understand how an error happened, the Sentry record also lists the names of the last few steps taken in the App just before it (which screen opened, whether a scan produced a result, and similar); these are the same events as the usage measurement described below and, like it, contain no barcodes, search text or personal information.
We also measure, in aggregate, which parts of the App are used, via Google Analytics for Firebase: which screens open, whether a scan produced a result, whether a search came back empty, and similar events. This measurement does not include the barcodes you scan, your search text, your allergy and sensitivity selections or your email address. It is not used for advertising and we do not track you across apps.
Notifications
With your permission the App may send you notifications (new features, products added to the catalog, campaign announcements, support replies). Notifications are delivered via Firebase Cloud Messaging in two forms:
- To groups: your device is subscribed only to broad topics such as app language and subscription status. Your identity is not used for these sends.
- To you only: if you are signed in and have granted notification permission, your device's notification identifier (a token issued by Firebase) is stored together with your account. This lets us send a notification that concerns only you (for example a reply to your support request) to your device alone. The record is used solely to deliver notifications, is not shared with third parties, and is deleted in three cases: when you sign out, when you turn notifications off, and when you delete your account.
In-app announcement cards work the same way: a card may be general or written for your account only, and a card written for you cannot be read by another user. These cards do not require notification permission. You can turn notifications off at any time from Profile → Notifications in the App or in your device settings; doing so also deletes the device record.
3. Why we use this data
- To create your account and let you sign in
- To fetch product information and provide scores and analysis
- To show personal warnings based on your sensitivities
- To sync your favorites, shopping lists, scan history and preferences across devices
- To detect missing products and improve the catalog
- To publish products you contribute so other users can find them
- To develop, secure and troubleshoot the App
- To detect and fix crashes and to measure feature usage in aggregate
- To send notifications and in-app announcements if you allowed them
4. Third-party services
The App may work with the following providers:
- Google / Apple — sign-in (OAuth) authentication
- Supabase — secure storage of account, profile, favorites, shopping list, scan history and product catalog data
- Cloudflare — website hosting and delivery of product images and offline catalog files (cdn.etikaapp.com)
- RevenueCat — only when an in-app subscription is purchased; verifying subscription status and recognising it across devices
- Apple App Store / Google Play — subscription payment and billing; your card details never reach us
- Google Firebase — crash reports (Crashlytics), aggregate usage measurement (Analytics) and notification delivery (Cloud Messaging)
- Sentry — monitoring of technical errors and crashes (hosted in the European Union)
These providers’ servers may be located outside Türkiye; to provide the service, your personal data is transferred abroad within the meaning of Turkish data protection law (KVKK) — Supabase and Cloudflare: EU/US; Sentry: EU; Google, Apple and RevenueCat: US.
Each provider’s own privacy policy applies. Etika does not currently send live product queries to third-party open food databases (e.g. Open Food Facts).
5. Advertising and data sales
Etika shows no advertising. We do not sell or rent your personal data to third parties for marketing. We use no advertising SDK and do not track you across apps. The only measurements we do are the aggregate usage and crash measurement and the anonymous counting of most viewed products described above; positions on shelves are not for sale.
6. Retention
Your data is kept while your account is active. You can delete your account yourself from Profile → Delete account in the App; your account record, favorites, shopping lists, scan history and sensitivity settings are permanently deleted at that moment (scan history both from the server and from your device). The action cannot be undone and you do not need to send us a request.
Product and error reports you submitted are kept unlinked from you (your email address is removed from the record). Moderation photos are deleted from the server within 60 days. A product added to the catalog thanks to your report stays in the catalog — that is general information about the product, not your personal data, and it comes from our own sources rather than from your photo. Guest scan history and the local cache can also be removed by clearing the App’s data on your device. The daily totals of most viewed products are not linked to anyone, so deleting your account does not change them; they are deleted after 100 days. The device identifier (token) stored for notifications is deleted when you sign out, when you turn notifications off, or when you delete your account; tokens that have become invalid are dropped from the record when a send is attempted.
If you cannot use the App, see Account and data deletion.
7. Security
We use encrypted connections (HTTPS) and industry-standard safeguards to protect your data. Please remember that no method of transmission over the internet is 100% secure.
8. Your rights
Under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to access your data, to have it corrected or erased, to restrict processing and to object to processing. Write to destek@etikaapp.com; we respond to requests within 30 days at the latest.
9. Children’s privacy
The App is not directed at children under 13. We do not knowingly collect personal data from anyone under 13.
10. Medical disclaimer
Etika is for information only; it is not a substitute for medical advice, diagnosis or treatment. Product information comes from catalog sources and may be incomplete, incorrect or out of date. For serious allergies or health conditions, check the packaging label and consult a health professional. The App does not detect cross-contact traces.
11. Changes to this policy
We may update this policy from time to time. For significant changes we update the date above. The current text is always published at etikaapp.com/en/privacy.
12. Contact
For privacy questions: destek@etikaapp.com