KVKK Privacy Notice
Last Updated: August 13, 2026
Which law applies to you
This is CORIA's disclosure text under Turkey's Personal Data Protection Law No. 6698 (KVKK). If you are in Turkey, this is the notice that applies to you.
If you are in the European Union or the EEA, the General Data Protection Regulation (GDPR) is the regime that applies to you. The same processing is described in our Privacy Policy, which sets out your rights under GDPR. Privacy Policy
1. Data Controller
Under the Personal Data Protection Law No. 6698 ("KVKK"), your personal data may be processed by CORIA as the data controller within the scope described below.
Data Controller: CORIA
Contact: privacy@coriaapp.com
Website: coriaapp.com
2. Processed Personal Data
The following personal data is processed within the scope of the CORIA app:
Identity Information
- Email address
- Username
- Profile photo (optional)
- Authentication credentials (encrypted)
Usage Data
- Scanned product barcodes
- Scan history
- Favorite products
- Dietary preferences and allergen information
- AI chat history
Technical Data
- Device information
- IP address
- App usage metrics
- Error logs (crash logs)
Permission-Based Data
- Camera: For barcode scanning (required)
- Location: For regional product recommendations (optional)
- Biometric: To confirm changes to your allergen settings on devices that support it (optional)
- Gallery Access: To select product photos from gallery (optional)
3. Processing Purposes
Your personal data is processed for the following purposes:
- Provision of app services
- User account creation and management
- Providing personalized product recommendations
- Providing allergen warnings
- Management of paid features, if and when they are offered
- Fulfilling legal obligations
4. Legal Basis
Your personal data is processed based on the following legal grounds under Article 5 of KVKK:
- Existence of your explicit consent
- Being necessary for the establishment or performance of a contract
- Fulfilling the data controller's legal obligation
- Being mandatory for our legitimate interests
5. Data Transfers
Your personal data may be transferred to the following parties:
- Supabase: Authentication and data storage (EU servers)
- OpenAI: AI product analysis and AI chat, including the text of chat messages (United States)
- RevenueCat: Subscription management (United States)
- Sentry: Crash and error diagnostics (United States)
- Firebase Cloud Messaging: Push notification delivery (United States)
- Google Analytics: optional website traffic measurement only if configured and after consent; no pre-consent analytics loading or events (United States)
- Google Sign-In: Optional login with a Google account (United States)
- Google Fonts: Typeface delivery (United States)
- Contentful: Website editorial content (European Union)
- Axiom: Application and request log storage (United States)
- Resend: Account and service email delivery (United States)
- Open Food Facts: Product lookup by barcode (European Union)
- ipapi.co: Approximate country detection from IP address (United States)
- AI training data: Only with your opt-in consent (United States)
- Vercel BotID Basic: Protected-form bot detection using request, browser and network signals (United States and Vercel subprocessor locations)
- Legal authorities: When legally required
Cross-border data transfers are carried out with necessary security measures under Article 9 of KVKK.
6. Your Rights
Under Article 11 of KVKK, you have the following rights:
- Learning whether your personal data is processed
- Requesting information if processed
- Learning the purpose of processing and whether it is used appropriately
- Knowing third parties to whom data is transferred domestically or abroad
- Requesting correction if incomplete or incorrectly processed
- Requesting deletion under the conditions set out in Article 7 of KVKK
- Requesting notification of correction and deletion to third parties
- Objecting to a result that arises against you through analysis of processed data exclusively by automated systems
- Claiming compensation for damages due to unlawful processing
7. How to Apply
You may apply through the following methods to exercise your rights:
Email: privacy@coriaapp.com
Applications will be concluded within 30 days, as required by KVKK and GDPR.
Data Protection Authorities
If you believe your rights have been violated, you can contact:
Turkey: Personal Data Protection Authority (KVKK) — www.kvkk.gov.tr (opens in a new tab)
EU: your local Data Protection Authority
This disclosure text was updated on August 13, 2026.