Last updated: · App not yet released
Privacy Policy
Not ready to publish — draft
This document must not be published before the company's official registration details (legal name, address, MERSİS number, tax number) are filled in. The fields below are shown as blank / “—” until a lawyer reviews this draft and the real registration data is entered.
1. Introduction and Scope
This Privacy Policy explains how personal data is collected, used, stored, shared and protected through the Cookrange mobile app and the cookrangeapp.com website ("Cookrange", the "Service"). Cookrange is headquartered in Turkey and targets the Turkish market first, with the European Union and the United States as secondary markets. Accordingly, this policy is written to reflect both Turkey's Law No. 6698 on the Protection of Personal Data ("KVKK") and the EU's General Data Protection Regulation ("GDPR", Regulation (EU) 2016/679). Users in Turkey are additionally covered by the mandatory Turkish-languageKVKK Disclosure Notice; this policy complements rather than replaces it.
2. Who We Are (Data Controller)
| Trade name | Cookrange |
|---|---|
| Registered legal name | [to be added] |
| Address | [to be added] — Antalya, Türkiye |
| MERSİS number | [to be added] |
| contact@cookrangeapp.com |
For the purposes of this policy, Cookrange acts as "data controller" under GDPR and "veri sorumlusu" under KVKK.
3. Personal Data We Collect
- Account data: name, email address, date of birth, gender, hashed password.
- Application data (coaches and gyms only): the phone number you verify when you apply to coach or to list a gym. Verifying it attaches the number to your Cookrange account as a sign-in method, and it is stored on your application so we can reach you about it. If you never apply, we never ask for it.
- Health and nutrition data: height, weight, body composition, allergy/diet preferences, meal logs, training and performance data, sleep data.
- Gym check-in data: check-in/check-out timestamps at partner gyms.
- Community/squad data: profile visibility, shared progress, in-app messaging (where applicable).
- Technical/usage data: IP address, device/OS/browser information, in-app event logs, cookie identifiers.
- Support communications: messages you send us via support requests or forms.
- Marketing preferences: your email/SMS/push consent status.
- Payment/subscription data (Premium): subscription status and billing records; card details are handled by the payment provider or app store, not stored on Cookrange servers.
- Administrator access records (Cookrange administrators only): if your account has been given access to the Cookrange administration panel, we keep a record of that access: whether the account is currently an administrator, the role it was given, any individual permissions added to or removed from that role, whether the access is active or suspended, and when it last changed. If your account has never been given administrator access, no such record exists for you.
4. How We Collect It
- Directly from you: during sign-up, onboarding, the waitlist form, in-app use, and support requests.
- Automatically: through cookies and similar technologies while you use the app/site (see the Cookie Policy).
- From third parties: partner gyms (for check-in verification), and — only with your explicit permission — wearables or health platforms we may integrate with in the future.
5. Purposes and Legal Basis
The table below summarizes, for each processing purpose, the corresponding legal basis under GDPR and KVKK. Category-specific exact retention periods will be added once our data retention and disposal policy is finalized (see section 10).
| Processing Purpose | GDPR Legal Basis (Art. 6/9) | KVKK Legal Basis (Art. 5/6) |
|---|---|---|
| Account creation and providing the Service | Performance of a contract (Art. 6(1)(b)) | Performance of a contract |
| Personalized nutrition/training recommendations (health data) | Explicit consent (Art. 9(2)(a)) | Explicit consent (special category data) |
| Service security and fraud prevention | Legitimate interest (Art. 6(1)(f)) | Legitimate interest |
| Administering the Service: deciding who may reach the administration panel and what they may do there | Legitimate interest (Art. 6(1)(f)) | Legitimate interest |
| Legal/tax/consumer-law obligations | Legal obligation (Art. 6(1)(c)) | Legal obligation |
| Marketing communications | Consent (Art. 6(1)(a)) | Explicit consent |
| Product analytics and improvement (post-consent) | Consent or legitimate interest | Explicit consent / legitimate interest |
6. Cookies and Similar Technologies
Alongside strictly-necessary cookies, the site/app may use analytics and marketing cookies or SDKs that only activate once you've given consent. See the full inventory and consent mechanism (Google Consent Mode v2) in our Cookie Policy.
7. Sharing and Sub-Processors
We share personal data with hosting, database and (in the future) email/analytics sub-processors only to the extent needed to run the Service. These providers may not use your data for their own marketing purposes. See our current Sub-Processorslist. We may also disclose data to competent public authorities where legally required.
8. Sponsored Products Layer
As one way of funding the free tier, Cookrange may show sponsored suggestions from brand partners (e.g. protein powder, protein bars) in certain meal/snack slots — these are always labeled "Sponsored" and are never a pre-selected default. Matching which product fits which slot runs entirely on your device; no personal data identifiable to you is transferred to brand partners. Brand partners only receive aggregate, de-identified counts (impressions and discount-code redemptions) reported in cohorts of at least 1,000 accounts. Accepting a sponsored suggestion, or muting/declining a brand, is stored as a preference record tied to your account, subject to the general retention rules described in section 10. Redeeming a discount code you accept happens directly in the brand's own store — any payment or delivery data you provide in that transaction is governed by that brand's own privacy policy, not Cookrange's; Cookrange is not a party to that sale. See theSponsored Products page for the system's full rule set.
9. International Transfers
Although Cookrange is headquartered in Turkey, our hosting and database infrastructure (Vercel, Firebase/Google Cloud) and our AI provider OpenRouter, Inc. (US) may run on servers outside Turkey and outside the EU. When you use the AI features, your body metrics, goals, allergies and dietary restrictions — and, for meal-photo analysis, the photograph itself — are transferred to OpenRouter. That transfer relies on your explicit consent, and the app shows you what is being sent before it is sent. You can decline and keep using Cookrange. Transfers from Turkey rely on KVKK Art. 9 and the relevant transfer mechanisms recognized by the Turkish Personal Data Protection Board (e.g. Standard Contract); transfers from the EU rely on GDPR Chapter V (Standard Contractual Clauses, adequacy decisions where applicable). The final contractual basis for these transfers will be confirmed once data processing agreements with each provider are finalized (seedocs/LEGAL-REVIEW.md).
10. Retention Periods
We keep personal data for as long as needed for the purpose it was collected, and for any statutory limitation periods that apply. When you delete your account, your data is deleted or anonymized within a reasonable period, except where we are legally required to keep it. Exact, category-by-category retention periods will be added to this policy once our data retention and disposal policy is finalized.
Your weight and water-intake records never reach our servers. Both are stored only on your own phone, encrypted. That is why they do not appear in the copy we send you on request, and why deleting your account leaves no server-side copy of them to erase — removing the app from your phone takes the encryption key with it and makes them unreadable. You can delete individual entries from inside the app. Your height, body composition, allergy and dietary preferences, and your meal and workout records are different: those are held on our servers and are subject to the rules in this section.
Four categories already expire on a fixed schedule, whether or not your account is still active, and they are deleted automatically by a daily job: the detailed record of each AI request - the model used, the token counts and the cost - after 90 days; your activity and sign-in history after 180 days; IP addresses recorded in the past after 1 year (see below); and a report that has already been dealt with after2 years. Aggregate totals are kept with nothing linking them to you. A report still waiting to be reviewed is never deleted on a timer.
A report of a chat message carries a short excerpt of that one message. If you report a message in a chat, the app captures a length-capped preview of that message (up to 120 characters) into your report, so our moderation team can assess what was actually sent - before this, a message report named only the chat, the message and the account, with no way to review the content. We do not otherwise have standing access to your conversations: this excerpt exists only because you, the reporter, chose to report that one message, and it is retained on the same 2-year schedule as the rest of the report above.
IP addresses. Cookrange records your IP address each time you sign in.Purpose: account-takeover, fake-account and misuse investigation. Legal basis: legitimate interest (KVKK Art. 5/2-f, GDPR Art. 6/1-f). Retention:one year from the date it was recorded, then deleted automatically. The copies inside sign-in history records are already deleted with those records at 180 days, which is sooner.
Your IP address is never asked of a third party. It is read from the request your app makes to our own server; it is not sent to any other service, and no service is consulted to obtain it. Between 27 August 2026 and 2 September 2026 no IP address was collected at all, so sign-ins in that window have no record of one.
This website additionally processes a visitor's IP address transiently to rate-limit the waitlist, contact and invite forms against abuse. That value is held only in the server's memory for a short window; it is never written to any database and never added to any record.
Conversations are an exception to that, and we want to say so plainly. A conversation belongs to both people in it. When you delete your account, the messages you sent and the photos and voice messages attached to them remain in the other person's chat history - otherwise we would be deleting their own record of an exchange they were part of. The legal basis for this retention is legitimate interest (KVKK Art. 5/2(f), GDPR Art. 6(1)(f)), not a legal obligation to keep it.
It is not kept indefinitely: it is deleted when the other person deletes the message, or when they delete their own account. If you want a particular message gone before you delete your account, you can delete it from within the chat - that removes its photo and audio files from our servers too. Your profile photo, your post images and your application documents are still deleted in full when you delete your account.
Administrator access records. If your account has been given access to the Cookrange administration panel, we keep a record of that access. Purpose:deciding whether an account may reach the administration panel at all, and which parts of it.Legal basis: legitimate interest (KVKK Art. 5/2-f, GDPR Art. 6/1-f).Retention: for as long as the account exists; there is no separate timer on this record. Withdrawing someone's administrator access marks the record suspended rather than removing it - so it stays clear who held what and until when - and it is erased along with everything else when the account itself is deleted. The record also names the administrator who granted or last changed the access, which is that person's personal data rather than yours.
11. Data Security
We apply reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, alteration or disclosure (encryption in transit, access controls, least-privilege principle). No system is completely secure, and we cannot guarantee absolute security.
12. Children's Privacy
Because Cookrange processes health and nutrition data, the Service is not directed at, and we do not knowingly collect data from, individuals under 16. If we learn that someone under 16 has provided us with personal data, we will delete it within a reasonable time. (This 16-year threshold is an assumption reflecting GDPR Art. 8's 13–16 range left to member states' discretion and KVKK's guardian-consent principle for those lacking legal capacity — the exact threshold will be confirmed during legal review.)
13. Your Rights
Depending on where you live, you may exercise the following rights:
- Access: request a copy of the data we hold about you,
- Rectification: request correction of inaccurate or incomplete data,
- Erasure: request deletion of your data ("right to be forgotten", GDPR Art. 17 / KVKK Art. 7),
- Portability: receive your data in a structured, commonly used format (GDPR Art. 20),
- Objection: object to processing based on legitimate interest (GDPR Art. 21),
- Restriction: request that processing be restricted in certain circumstances (GDPR Art. 18),
- Withdraw consent: withdraw consent for consent-based processing at any time, from the Consent Centre in the app. Each purpose is separate and withdrawing one does not affect the others. Health data is the exception, and we say so plainly: every calculation Cookrange makes starts from it, so withdrawing that consent leaves no usable service behind and is treated as a request to close your account. Doing so schedules deletion and your account stays recoverable for 30 days. Your right to withdraw is not restricted - only its consequence is stated up front, and you can download a copy of your data first.
To exercise these rights, see our Data Subject Request page. Users in Turkey have the equivalent rights under KVKK Art. 11, detailed in theKVKK Disclosure Notice.
14. Complaints and Supervisory Authorities
Turkey: if you believe your KVKK rights have been violated, you must first apply to us as the data controller; if your request is rejected, insufficiently addressed, or not answered within the statutory period, you may lodge a complaint with the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
European Union: under GDPR Art. 77, you may lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement (for example Ireland's Data Protection Commission, Germany's relevant state authority, or France's CNIL).
15. US Residents (CCPA)
California residents have rights under the California Consumer Privacy Act ("CCPA", as amended by the CPRA), including the right to know what personal information is collected, to request deletion, to opt out of the "sale" or "sharing" of personal information, and to not be discriminated against for exercising these rights. Cookrange does not sell personal information for monetary consideration within the meaning of the CCPA. You can submit requests via ourData Subject Request page.
16. Changes to This Policy
We may update this policy from time to time. For material changes, we may additionally notify you in-app or by email. The current version is always published on this page with the "Last updated" date shown at the top.
17. Contact
Questions about this policy can be sent to contact@cookrangeapp.com.