Privacy Policy and Notice on Personal Data
Last Updated: June 29, 2026
At Longerix Labs ("we", "us", or "our"), we deeply value the security and privacy of the personal data we process through the LensEat mobile application ("App"). This Privacy Policy and Notice explains how we collect, use, store, and share your personal data, and how you can exercise your privacy rights under the Personal Data Protection Law No. 6698 ("KVKK") in Turkey, the General Data Protection Regulation ("GDPR") in the European Union, and US state privacy laws (including CCPA/CPRA).
1. Data Controller
For the purposes of applicable data protection laws, the data controller is:
- Entity: Longerix Labs
- Contact Email: longerixlabs@gmail.com
---
2. Data We Process, Purposes, and Legal Bases
To provide you with the services in our App, we process the following categories of data:
| Personal Data Category | Specific Data Points | Purpose of Processing | Legal Basis (KVKK / GDPR / US) |
| :--- | :--- | :--- | :--- |
| Identity & Account Information | Name, email address, password, user ID | Account creation, user authentication, and profile management | Performance of a Contract (KVKK Art 5/2-c, GDPR Art 6/1-b) |
| Sensitive Personal Data (Health) | Age, height, weight, gender, physical activity level, nutritional goals, dietary preferences, health conditions/allergies | Calculation of personalized calorie, macro, and micronutrient targets | User's Explicit Consent (KVKK Art 6/2, GDPR Art 9/2-a) |
| Visual & Voice Data | Meal photos, voice inputs (when using voice commands) | Image/voice scanning to detect food items and estimate portion sizes | User's Explicit Consent (KVKK Art 5/1 & 6/2, GDPR Art 9/2-a) |
| Integrated Health App Data | Steps count, exercise logs, active calories burned (synced from Apple HealthKit / Google Health Connect) | Daily calorie balance and target tracking | User's Explicit Consent (KVKK Art 6/2, GDPR Art 9/2-a) |
| Device & Usage Data | IP address, device model, operating system, in-app usage analytics | Optimization of App performance, troubleshooting, security | Legitimate Interests (KVKK Art 5/2-f, GDPR Art 6/1-f) |
---
3. Cross-Border Data Transfers
In order to provide our cloud-based and AI services, we work with service providers located outside of your home country:
- Google Firebase: User authentication, the Firestore database infrastructure, and analytics are hosted on Google's cloud servers.
- Anthropic (Claude AI): Uploaded meal photos and descriptive texts are securely sent via API to Anthropic's servers for nutritional and portion analysis. No identifying information (such as your name or email) is shared with Anthropic.
Since the servers of these service providers are primarily located in the United States (US), your data is transferred internationally.
- Under KVKK (Turkey): The transfer of sensitive health and visual data is based on the Explicit Consent you grant in the App.
- Under GDPR (European Union): Transfers are secured through Standard Contractual Clauses (SCCs) approved by the European Commission, along with appropriate technical safeguards.
---
4. Data Retention and Security
Your personal data is retained for as long as you maintain an active account with the App.
- We secure your data using industry-standard encryption protocols (SSL/TLS, encryption at rest) within Firebase's secure cloud infrastructure.
- Account Deletion: You can request the permanent deletion of your account and all associated personal data (photos, health logs, profile information, fasting history, and preferences) at any time. To do this, go to Settings > Delete Account inside the App. Alternatively, you can request account deletion by emailing us at longerixlabs@gmail.com. Upon request, all data is permanently and irreversibly deleted from our servers within 30 days. (Local photo copies on your physical device are deleted when you uninstall the App).
---
5. Your Privacy Rights
A. Your Rights Under KVKK Article 11 (Turkey)
Users residing in Turkey may contact Longerix Labs to:
- Learn whether their personal data is being processed,
- Request information if their personal data has been processed,
- Learn the purpose of data processing and whether it is used appropriately,
- Know the third parties to whom personal data is transferred (domestically or abroad),
- Request correction of incomplete or inaccurate data,
- Request deletion or destruction of personal data under KVKK Article 7 conditions,
- Request notification of corrections or deletions to third parties to whom data was transferred,
- Object to negative outcomes resulting from automated systems,
- Claim compensation for damages arising from unlawful processing.
B. Your Rights Under GDPR (European Union)
Users residing in the EEA/UK have the following rights:
- Right to Access & Portability: Request a copy of your data and transfer it to another service in a structured format.
- Right to Rectification & Erasure: Request the correction of inaccurate data or the permanent deletion of your data.
- Right to Restrict Processing & Object: Object to or restrict the processing of your data under certain conditions.
- Withdraw Consent: Withdraw consent at any time for consent-based activities (e.g., health and visual data processing).
- Lodge a Complaint: Lodge a complaint with your local data protection authority.
C. Your Rights Under US State Privacy Laws (CCPA/CPRA)
US residents (including California) have the following rights:
- Right to Know & Access: Request to know what categories of personal data we collect, use, and share.
- Right to Delete & Correct: Request deletion or correction of your personal data.
- Right to Opt-Out of Sale/Sharing: Request that we do not "sell" or "share" your personal data. LensEat does NOT sell your personal data or share it with third parties for targeted advertising.
- Right to Non-Discrimination: Receive equal service and pricing even if you exercise your privacy rights.
---
6. Children's Privacy
LensEat is not intended for use by children under 13 years of age (or under 16 in certain EU jurisdictions). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data without parental consent, please contact us immediately so we can delete it.
---
7. Contact and Requests
To exercise any of your rights or ask questions regarding this Privacy Policy, please email us at longerixlabs@gmail.com. We will respond to your requests within 30 days, free of charge.
---
8. Cookies, Identifiers, and Tracking Technologies
LensEat is a mobile application and does not use traditional browser cookies. However, we use the following device-level identifiers and analytics technologies:
- Firebase Analytics: Anonymous usage data is collected to measure user behavior and app performance (e.g., screens visited, error rates). This data is not linked to your personal identity.
- Firebase Crashlytics: Anonymous crash reports are collected to detect and fix app crashes.
- Device Identifiers: For guest users (who have not created an account), an anonymous device ID is generated locally to store app data. This identifier is not linked to any personally identifiable information.
We do NOT use advertising identifiers (IDFA, GAID) and do NOT share any identifiers with advertising networks.
---
9. Data Breach Notification
In the event of a security incident involving unauthorized access to, disclosure of, or destruction of your personal data:
- Under GDPR: We will notify the relevant supervisory authority (Data Protection Authority / DPA) within 72 hours of becoming aware of the breach.
- Under KVKK: We will notify the Turkish Personal Data Protection Authority (KVKK Kurulu) and affected individuals as soon as possible.
- Affected users will be notified by email at longerixlabs@gmail.com as soon as the breach has been confirmed.
---
10. Special Handling of Health Data
Your sensitive health data (weight, height, BMI, medical conditions, allergies, health history) is treated with the highest level of protection:
- This data is processed only to the extent you voluntarily enter or authorize syncing from health platforms.
- Your health data is never disclosed to insurance companies, employers, government agencies, or advertising platforms.
- Users with clinical conditions (diabetes, eating disorders, chronic diseases, etc.) are strongly advised to consult a qualified healthcare professional before following any App recommendations. Longerix Labs cannot be held responsible for health outcomes resulting from reliance on in-app suggestions.
---
11. Data Portability and Export Format
To exercise your right to data portability under GDPR Article 20, your personal data will be provided to you in the following structured, machine-readable format:
- Profile data, nutrition history, and health data: JSON format
- Requests can be submitted to longerixlabs@gmail.com. Data will be prepared and delivered within 30 days.
---
12. Competent Data Protection Authority (EU/EEA)
Users residing in the European Union or EEA may lodge a complaint about our data processing practices with their local supervisory authority (DPA). The full list of EU DPAs is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en. We encourage you to contact us first at longerixlabs@gmail.com, as we are committed to resolving privacy concerns amicably.