Picipie Privacy Policy
Last updated: 05.08.2026
Version: 1.0
1. Data controller and contact
The data controller responsible for the Picipie app is Baret Bektaşiyan ("Picipie", "we"). Picipie is published under the name Barnat Labs.
- Email: barnatstudio@gmail.com
- Data subject requests: barnatstudio@gmail.com
You can send any data protection request to the address above; we reply through the same channel.
This policy was written for Turkish data protection law (KVKK No. 6698). Where the Turkish and English versions differ, the Turkish version prevails.
2. Scope
This policy covers the Picipie iOS and Android app, the in-app AI recipe generation, and the supporting services behind them. The app provides recipe suggestions, expiry-date reminders, a shopping list, nutrition and weight goal tracking, and optional account sync.
Picipie is not a medical device; it does not diagnose, treat, or give medical advice. Calorie, macro and recipe nutrition values are estimates. If you have an allergy, a chronic condition, are pregnant, have an eating disorder, or have specific dietary needs, consult a health professional.
3. What we process, and why
| Data category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, profile photo and user ID from your Google/Apple account | Sign-in, sync across devices, account management |
| Recipe and pantry data | Ingredients you enter, pantry items, quantity, category, expiry date, shopping list, favourites, scan history | Generating recipes, running the reminder and list features |
| AI inputs | The food/ingredient photo you choose, the ingredients you type, your dietary preferences and, if set, the calories you have left today | Recognising ingredients and suggesting recipes that fit you |
| Nutrition and goal data | Age, biological sex, height, weight, target weight, activity level, calorie/macro targets, water and meal entries | Providing the tracking and personalisation you opted into |
| Device and usage data | App interactions, app version, error and crash information, technical identifiers | Security, error detection, performance and product improvement |
| Notification preferences | Whether each reminder is on, and at what time | Scheduling local notifications |
| IP address | The IP address of the device making an AI request | Enforcing the guest (no account) daily allowance and the hourly rate limit; preventing abuse. Held in server memory for the day only, never stored permanently. |
| Usage counter | The daily AI request count and date attached to your account | Enforcing the daily allowance (dailyScans) |
| Server request logs | Per AI request: the model used, the number of text units (tokens) processed, duration, outcome, and a pseudonymised (cryptographically hashed) user identifier | Monitoring service cost and error rate. The log itself contains no photo, no ingredients and no recipe content. |
| Consent records | The scope you granted or withdrew, the date, and the version of the text you agreed to | Evidence of consent and preference management |
| Advertising data | The Google-assigned Advertising ID, approximate location (country/city level), device and ad interaction information | Only to show a rewarded ad you started and to verify the reward. Watching ads is never required; declining restricts nothing in the app. |
We access the camera and photo library only when you start choosing a photo or opening the camera. Picipie does not store photos permanently on its own backend; the photo you select is forwarded to the AI service described below for recipe analysis.
4. AI recipe generation and transfer to a third party
When you choose to use the AI feature, the photo you selected or the ingredients you typed are sent to the Google Gemini API to generate recipes. Your dietary preferences, and — only while personalised suggestions are on — the calories you have left today, may be included in the same request.
This transfer:
- happens only to complete the AI recipe request you started;
- is not used for ad targeting or the sale of data;
- is processed by the Picipie backend without the photo being stored, once the recipe result is produced;
- may be subject to Google's own terms and data processing conditions.
AI analysis is optional. If you do not consent, photo scanning and AI recipe generation are unavailable; the pantry, list and non-AI tracking features keep working. We recommend that photos not contain people, faces, health documents or unnecessary personal information.
4/A. Advertising
The app contains rewarded ads only: when your daily AI allowance runs out, you may watch a short video to earn one more. There are no banner or interstitial ads.
- Watching an ad is entirely optional. If you do not, nothing in the app is switched off; your allowance resets the next day.
- Ads are served by Google AdMob, which processes your advertising ID and similar data in order to show them.
- Users in the European Economic Area and the United Kingdom are shown Google's own consent form (UMP) before the first ad; you may decline personalised advertising, in which case non-personalised ads are shown.
- You can reset your advertising ID or turn off personalisation in your device settings (Android: Settings > Google > Ads).
- To verify that the reward was genuinely earned, Google sends a signed notification to our server. That notification carries only your user identifier and a transaction number; it carries no ad content and no personal data.
5. Who we share data with
We share data only with the following categories of service provider, for the stated function:
| Recipient / service provider | Purpose of transfer |
|---|---|
| Google Gemini API | The AI recipe and ingredient analysis you requested |
| Google Firebase Authentication and Firestore | Account, sign-in and optional cloud sync |
| Firebase Analytics and Crashlytics | App usage, performance, error and crash analysis |
| Google AdMob | Serving rewarded ads and verifying the reward server-side |
| Railway | Routing AI requests through a secure backend and operating the service |
| Competent public authorities | Where legally required |
These providers' servers may be located outside Türkiye. Transfers abroad are made within the framework of applicable legislation and appropriate security/transfer mechanisms. Each provider's current agreement, server location and transfer mechanism must be verified before release.
6. Legal bases
We process data on the basis that it is:
- directly related to the establishment or performance of a contract, in order to provide the features you requested and manage your account;
- a legitimate interest or legal obligation, for security, troubleshooting, abuse prevention and legal duties;
- your explicit consent, to the extent required for AI analysis and for nutrition/health data that may qualify as a special category.
Disclosure and explicit consent are presented separately; you can withdraw your consent at any time under Settings > Privacy. Withdrawal does not affect the lawfulness of processing carried out before it.
7. Retention
| Data | Retention approach |
|---|---|
| Account and synced app data | For as long as the account is active. A deletion request is processed immediately: the Firestore data tree and the identity account are deleted during the request |
| AI photos | Not stored permanently on the Picipie backend |
| Recipe/pantry/nutrition data | Until the user deletes it or the account is deleted |
| Server request logs | For as long as the hosting provider retains logs (7 days on the current plan), then deleted automatically |
| IP address (guest usage counter) | In server memory, for that day only; cleared when the server restarts or the day changes |
| Consent records | Until the account is deleted; required as evidence of explicit consent |
| Error and crash logs (Crashlytics) | For Firebase Crashlytics' default retention period |
| Local device data | When the user clears app data or removes it from the relevant feature |
Where there is a legal obligation, a dispute, or a need to prevent abuse, some data may be retained on a limited basis for the period permitted by legislation.
8. Security
We protect data with encryption in transit, access controls, per-user Firestore authorisation, server-side quota and rate limiting, and access logs where needed. Note that no method provides absolute security.
9. Account and data deletion
Users with an account can permanently delete it from inside the app via Settings > Account > Delete my account. Deletion covers the identity account, cloud-held recipe favourites and history, pantry data, nutrition records, the usage counter and consent records, and cannot be undone. For your security, you are asked to have signed in recently before deletion.
Deletion does not cover the technical request logs held by the hosting provider, which do not directly identify you; those are deleted automatically at the end of the retention period above. If you have a subscription, deleting your account does not cancel it automatically; it must be cancelled separately through the relevant store.
For data held locally on your device, signing out is enough; the on-device copies are cleared on sign-out.
10. Your rights
You can exercise your rights under Article 11 of KVKK No. 6698, and your rights under other applicable data protection legislation, via barnatstudio@gmail.com. You may need to provide information sufficient to verify your identity, along with a description of your request.
11. Children
Picipie is designed for adult users. We do not knowingly aim to collect data from anyone under 18. If you believe data belonging to a minor has been processed, please contact us.
12. Changes
We may update this policy when the service, the legislation, or our data processing practices change. We announce significant changes in the app or on this page, and ask for consent again where required.