Privacy Policy
This policy explains how your personal data is processed when you use the Gardo mobile app. It provides the information required by the EU General Data Protection Regulation (GDPR, Art. 13) and the Turkish Personal Data Protection Law No. 6698 (KVKK, Art. 10).
1. Controller
Controller: Sercan Saygın (EvraLabs), Kızılpınar Gültepe Mah. Saygın Sk. No: 8, Çerkezköy/Tekirdağ, Türkiye. Çerkezköy Vergi Dairesi, VKN 7550469513.
For any question about your personal data: support@evralabs.app
2. Data we process
- Account data: your email address; if you sign in with Apple or Google, the user identifier from that provider and your name if you share it.
- Preferences: app language, theme, city-level location (we never store your exact location; coordinates are rounded to about 10 km), your style preferences and colours or items you avoid.
- Modest-dress preference (optional): may reveal religious beliefs and is therefore treated as special-category data; processed only with your separate explicit consent and never used for analytics.
- Clothing photos: the photos you upload. Photo metadata (EXIF), including location, is removed on your device before upload. Faces in mirror photos are blurred on your device before upload.
- Wardrobe and outfit data: item attributes (category, colour, pattern, etc.), outfit suggestions, your likes and dislikes, and your wear history.
- Optional details: brand, price and notes you enter for items.
- Subscription status: the type and term of your subscription (Apple or Google takes the payment; we never receive your card details).
- Technical data: crash reports (without IP addresses or personal identifiers), security and abuse-prevention logs; analytics only if you allow them.
3. Purposes and legal bases
- Providing the service (account, wardrobe, outfit suggestions, subscription): performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Analysing photos with AI service providers and transferring them abroad: your explicit consent (GDPR Art. 6(1)(a), Art. 49(1)(a); KVKK Art. 5(1), Art. 9). If you withdraw consent, new photos can no longer be analysed.
- Modest-dress preference: your explicit consent (GDPR Art. 9(2)(a); KVKK Art. 6).
- Analytics and marketing emails: only with your consent.
- Security, abuse prevention and debugging: legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Legal obligations (e.g. requests from authorities): GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç).
4. Processing with AI
To recognise the items in your photo, the photo (with its background removed) is sent to our AI service providers. They process the data only on our behalf to provide the service and, under their terms, do not use data sent through their API to train their models. AI suggestions are for information only; no automated decisions with legal or similarly significant effects are made about you.
5. Recipients
- Supabase (database, file storage, authentication; servers in Frankfurt, Germany).
- Anthropic PBC (AI analysis of items and outfits; USA).
- Modal Labs (image processing: background removal, colour analysis; USA).
- Apple and Google (sign-in, in-app purchases).
- RevenueCat (subscription status management; USA).
- Sentry (crash reports, without personal identifiers).
- PostHog (usage statistics only if you allow them; servers in the EU).
- Email delivery provider (sending sign-in codes).
We do not sell your data or share it with third parties for advertising.
6. International transfers
Some providers are located in the USA. Transfers rely on your explicit consent (GDPR Art. 49(1)(a); KVKK Art. 9) and, where applicable, standard contractual clauses (EU Standard Contractual Clauses, KVKK standard contract).
7. Retention
- Account and wardrobe data: as long as your account exists.
- Original uploaded photos: at most 30 days, then deleted. Cut-out images of your items are kept until you delete the item or your account.
- When you delete your account, your data is deleted immediately and removed from backups within 30 days.
- Consent records: as long as your account exists, as proof of consent.
- Crash and security logs: at most 90 days.
8. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right not to be subject to solely automated decisions (GDPR Art. 15–22; KVKK Art. 11). You can withdraw any consent at any time in the app settings; this does not affect processing carried out before withdrawal.
- Download your data in the app with Settings → Download my data and delete it with Settings → Delete account (delete account).
- For other requests, email support@evralabs.app; we reply within 30 days.
- You can lodge a complaint with the data protection authority in your country or with the Turkish Personal Data Protection Authority.
9. Security
Data is encrypted in transit; each user can only access their own data (row-level security). Photos are kept in a private store and opened only through time-limited signed links. No secret keys are shipped inside the app.
10. Age limit
Gardo is for people aged 18 and over. If we learn that we hold data of someone under 18, we delete it.
11. Changes
We may update this policy. For important changes we inform you in the app and ask for your consent again where required.