Last updated: · App not yet released
KVKK Notice
Not ready to publish — draft
This document must not be published before the company's official registration details (legal name, address, MERSİS number, tax number) are filled in. The fields below are shown as blank / “—” until a lawyer reviews this draft and the real registration data is entered.
This notice is prepared by Cookrange, in its capacity as data controller, under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and the accompanying Communiqué on the Procedures and Principles to Be Followed in Fulfilment of the Disclosure Obligation, to inform people whose personal data is processed through the Cookrange mobile app and the cookrangeapp.com website ("Cookrange", the "Service").
1. Identity of the Data Controller
Under KVKK, your personal data is processed by the company identified below, acting as data controller ("Data Controller"), for the purposes and to the extent explained in this notice.
| Trade name | Cookrange |
|---|---|
| Registered legal name | [to be added] |
| Address | [to be added] - Antalya, Türkiye |
| MERSİS number | [to be added] |
| Tax office / number | [to be added] / [to be added] |
| KVKK data controller representative | [to be added] |
| KEP (registered email) address | [to be added] |
| contact@cookrangeapp.com |
2. Personal Data Processed
Through your use of the Service, personal data in the following categories may be processed:
- Identity and contact: name/display name, email address, date of birth, gender, authentication identifier.
- Account data: username, hashed password, account creation/sign-in records.
- Health and nutrition data (special category): height, weight, body composition, activity level, allergy/dietary preferences, meal and exercise logs, performance and sleep data - treated as special-category personal data under KVKK Art. 6.
- Location data: your approximate device location only while you actively use a location-based feature ("gyms near me"); this location is processed on your device only and is not stored on our servers.
- Gym presence detection data (background, separate and explicit-consent-gated):only if you separately turn this feature on for a gym you are a member of - your entry/exit time and the gym's name; your coordinates are never sent to or stored on our servers. See Section 8.
- Tiered progress-sharing data (only at the tier you grant): if you explicitly grant it for a specific gym/coach relationship, only the data included at the tier you chose - never your raw weight history. See Section 9.
- Gym check-in data: entry/exit timestamps at partner gyms.
- Community/squad data: profile visibility, shared progress, in-app messaging, where applicable.
- Technical and usage data: device/OS/browser information, in-app event logs, cookie identifiers (see Cookie Policy).
- Marketing communication preferences: email/SMS/push consent status (see Marketing Consent).
- Payment/subscription data (Premium): subscription status and billing records; card numbers and other direct financial identifiers are not stored on Cookrange's own systems and are handled by the payment provider or app store.
- Administrator access records (Cookrange administrators only): if your account has been given access to the Cookrange administration panel, a record of that access is kept: whether the account is currently an administrator, the role it was given, any individual permissions added to or removed from that role, whether the access is active or suspended, and when it last changed. The legal ground is legitimate interest (Art. 5/2-f); the record is kept for as long as the account exists and is deleted with the account (see Section 7). If your account has never been given administrator access, no such record exists for you.
3. Purposes of Processing
Your personal data is processed for the following purposes:
- Creating your account, authenticating you, and managing your account;
- Generating AI-supported nutrition/training recommendations and personalised programmes;
- Providing product features such as gym check-in, progress analytics and streak tracking;
- Enabling your interaction with other users in community/squad features;
- Creating and managing your waitlist entry;
- Responding to customer support requests;
- Sending marketing communications where you have given separate explicit consent (see Marketing Consent);
- Securing the Service and preventing abuse or fraud;
- Administering the Service: deciding who may reach the administration panel and what they may do there;
- Meeting legal obligations (e.g. e-commerce, tax and consumer-protection law);
- Statistical/analytical evaluation to develop and improve the product (see Cookie Policy - analytics cookies activate only once you consent).
4. Legal Grounds for Processing (KVKK Art. 5/6)
Your personal data is processed on the following legal grounds under KVKK Article 5:
- Establishment/performance of a contract (Art. 5/2-c): account creation, delivering the Service.
- Compliance with a legal obligation (Art. 5/2-ç): record-keeping duties arising from tax, e-commerce and consumer-protection law.
- Legitimate interest (Art. 5/2-f): service security, fraud prevention, core product analytics, authorising access to the administration panel.
- Explicit consent (Art. 5/1): marketing communications, and the special-category data covered by Art. 6 (for example, processing nutrition/health data to generate personalised recommendations) - obtained separately and explicitly for each.
Your special-category personal data (health and nutrition data) is, as a rule, processed on the basis of your explicit consent under KVKK Art. 6/2; this consent is obtained separately during the relevant in-app step (onboarding).
Withdrawing consent for health data means leaving the Service. Every output Cookrange produces - a calorie target, a meal plan, progress tracking - depends on this data; once consent is withdrawn, no usable service remains. For that reason, turning this consent off in the in-app Consent Center routes you into the account-deletion flow: your account is queued for deletion and stays recoverable for 30 days. Your right to withdraw consent is never restricted in any way - only its consequence is stated plainly. You can download a copy of your data from within the app before withdrawing (Settings › Privacy › Export my data). Consents you have given for other purposes (marketing, analytics, location, notifications, AI processing, cross-border transfer) are independent of this one and can be withdrawn individually without affecting your account.
5. Recipients of Data and Purpose of Transfer
Limited to the purposes above, your personal data may be transferred to the following recipient groups:
- Domestic: competent public authorities, where legally required; partner gyms we work with (for check-in verification only, on a limited-data basis).
- Abroad: hosting (Vercel), database/authentication (Firebase/Google Cloud) andAI generation (OpenRouter, Inc. - United States) services may be hosted on servers located abroad. When you use AI features, your body measurements, goals, allergy and dietary constraints (health-data in nature) and, for meal-photo analysis, the photo itself are transferred to OpenRouter; this transfer relies on your explicit consent, is shown to you separately before the transfer takes place inside the app, and does not happen if you decline. These transfers take place within the framework of KVKK Art. 9 and the Personal Data Protection Board's current rules on cross-border transfer (Standard Contract / adequacy decision, etc.). See the Sub-Processors page for the current list.
docs/LEGAL-REVIEW.md.6. Method of Collection
Data is collected electronically through the mobile app - during sign-up, onboarding, content creation and general use - by automated and partly automated means.
7. How Long We Keep Your Data
Under KVKK Art. 10 we disclose retention periods here. General principle: personal data is kept for as long as its processing purpose applies, or until you delete your account - whichever comes first. The specific exceptions and periods below sit on top of that principle.
- Your account and profile data; special-category health/nutrition data; food and exercise logs; favourites; AI history; XP/badge records; consent records; and the access log - everything tied to your account is kept only while your account is active. Using Settings → Delete Account schedules deletion and your account stays recoverable for30 days. Nothing is deleted the moment you ask: you are signed out on every device and your profile is hidden from everyone, but your data is left exactly as it is. During that window you can sign back in and cancel the deletion with a single button; no password is asked for, and the account comes back complete. When the window ends, a daily automated job erases this data - including your Firebase authentication record and any images you uploaded - server-side and irreversibly.
- A gym's or coach's own operational records - your membership, your check-in/exit history (Section 8), your weekly community-score contribution - belong to that gym/coach/community, not to you, and are not currently subject to a separate, coded automatic deletion period; they may remain on the gym's/coach's side after you delete your account. To request deletion of these records, contact contact@cookrangeapp.com - we assess the request under KVKK Art. 7 / GDPR Art. 17.
- Operational logs are deleted on a fixed schedule, independently of your account status: the detailed record of each AI request (model, tokens, cost) after90 days; your activity and sign-in history after 180 days; a report that has already been handled after 2 years. Aggregate counts and costs are kept with no link back to you; a report that has not yet been reviewed is never deleted on a timer.
- A report of a chat message carries a short excerpt of that one message. If you report a message, the app captures a length-capped preview of it (up to 120 characters) into your report, so our moderation team can assess what was actually sent. We do not otherwise have standing access to your conversations; this excerpt exists only because you, the reporter, chose to report that one message, and it is retained on the same 2-year schedule as the rest of the report above.
- Coach/gym progress summaries (Section 9) are kept on our server for amaximum of 7 days and then deleted automatically; changing or fully revoking your sharing tier deletes it immediately instead, without waiting out that window.
- Financial records (subscription/commission accruals) are kept for the period required by applicable tax/accounting law. A gym's own accounting record of a commission earned through you continues to be kept on the gym's side even if you delete your account - only the record attributing that earning to you is deleted with your account.
- Content you share with another user (for example, a chat message): the other party's copy is part of their own record, so deleting your account does not automatically delete it for them. You can delete your own posts/comments in the app at any time, or as part of account deletion.
- Location data: as explained in Section 2, live location used for "gyms near me" is never stored on our servers. See Section 8 for gym-presence entry/exit event retention.
- Administrator access records: kept for as long as the account exists, with no separate timer of its own. Withdrawing someone's administrator access marks the record suspended rather than removing it - so it stays clear who held which permission and until when - and it is erased with the rest of the account's data when the account itself is deleted.
For any data category not listed separately above, the general principle at the top of this section applies: kept while your account is active, until you delete it.
8. Gym Presence Detection (Automatic Check-In) - Full Explanation
Section 2 introduces this feature briefly; because it is gated by its own separate, explicit consent, it is explained fully here.
- What triggers it: only once you are a member of a gym andhave separately turned this feature on for that gym - entering its location boundary and staying there for a confirmation period ("dwell"; merely walking past does not trigger it) may create an automatic check-in, and the record closes when you leave. If exit information never reaches us for any reason (the app closing, the phone powering off), a visit left open is automatically closed by the system after at most 4 hours as a safety measure.
- Data processed: only your entry/exit time, the visit's duration, and the gym's name - your coordinates (latitude/longitude) are never sent to or stored on our servers at any stage; this follows from the app's design (location is never transmitted to the server for this feature at all), not merely a policy promise.
- Consent mechanism: a separate consent purpose, off by default. It is never granted automatically at sign-up; you can only turn it on through its own non-skippable screen explaining, step by step, what it does, what is stored, what is never stored, who can see it, its legal basis and how to turn it off. Even after granting this, you must separately turn it on for each individual gym - the general consent only unlocks the feature; it never starts tracking any gym on its own.
- How many gyms at once: because of the device operating system's background boundary-monitoring capacity, at most 3 gyms can be tracked for automatic check-in at the same time.
- Who can see it: the gym owner sees only your "currently inside" status, at the level of the member list; additionally, if you allow it (a separate toggle you can turn off at any time), mutual friends who are also members of the same gym may receive a notification that you've arrived - this notification never contains your location, only that you're "at this gym", is limited to reasonable hours of the day, and you can separately mute any specific friend from these notifications.
- Server-side verification: before a check-in record can be created, your membership, the gym's own setting for this feature, your general consent, and your per-gym permission are all re-verified server-side on every single event - none of it relies on your device's own claim. A repeat check-in at the same gym is not opened within 10 minutes of your last exit (rate limiting).
- How to withdraw: the moment you turn this consent off in the Consent Center, our server stops creating any new entry/exit record for you - re-verified server-side on every request, not only at initial setup. To also stop your device from continuing to monitor that gym's boundary in the background, we recommend additionally turning off automatic check-in for that specific gym from the gym's own screen, or revoking the "Always" location permission at the OS level.
9. Tiered Progress Sharing (Coach/Gym Access)
A gym owner or your coach can see a limited summary of your progress only if you explicitly grant it. This is a 4-tier system:
- Tier 0 - Off (default): the starting state for every gym/coach relationship; no data is shared or generated until you decide otherwise.
- Tier 1 - Attendance: your check-in frequency, current streak, and last visit.
- Tier 2 - Attendance + adherence: adds your logging regularity (plan-adherence percentage, where data exists).
- Tier 3 - Attendance + adherence + weight trend: adds only your weight'sdirection and approximate magnitude (e.g. "trending slightly down") - your raw weight history or any single weight value is never shared through this path.
You grant, raise, lower, or revoke (with one tap) this permission separately for each gym/coach relationship (Settings → Consent Center → Progress Sharing); granting it for one gym never carries over to another gym or to your coach.
- How it's generated: when a summary is requested, our server re-verifies, every time, that the requester is genuinely your gym's owner or your active coachand checks the tier you've granted; without that verification, or while your tier is 0, no data is returned. The same requester can generate at most one summary per member per day.
- AI: if you also have AI-processing and cross-border-transfer consent, the summary is written using AI; otherwise a template narrative is built only from the permitted numeric fields, with no AI call - your AI consent is never bypassed through this path.
- Retention: a generated summary is kept on our server for amaximum of 7 days and deleted automatically; changing or revoking your tier deletes it immediately instead.
- Access log: in a log tied to your account, you can see who viewed a summary about your progress, and when. This log remains as a historical record even if you later revoke that relationship's tier; it is deleted, with the rest of your account data, when you delete your account.
- Invitation: a gym/coach may send you a one-time, informational notification for a relationship you have not shared with yet ("want to share your progress?") - this notification never grants access to any data by itself.
10. Your Rights as a Data Subject (KVKK Art. 11)
Under KVKK Article 11, by applying to the Data Controller you have the right to:
- Learn whether your personal data is processed, and request information if so;
- Learn the purpose of processing and whether your data is used in line with that purpose;
- Know the third parties, at home or abroad, to whom your data is transferred;
- Request correction of incomplete or inaccurate data;
- Request erasure or destruction of your data where the conditions of KVKK Art. 7 are met;
- Request that the two actions above be notified to the third parties your data was transferred to;
- Object to a result against you arising solely from automated analysis of your data;
- Claim compensation where you have suffered damage due to unlawful processing.
To exercise these rights, contact contact@cookrangeapp.com, or use theData Subject Request page; you can also export your data (Settings → export your data) or delete your account (Settings → Delete Account) from within the app. Requests are concluded within the statutory period (maximum 30 days), free of charge, unless the request itself requires a cost, in which case the Board's published fee schedule may apply.