Privacy Policy
Last Updated: August 13, 2026
Introduction
CORIA values your privacy and data security. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the CORIA mobile app and website.
CORIA is a product-scanning app. It reads a barcode and reports what the product contains — allergens, animal-derived ingredients, and estimated environmental impact — measured against preferences you set. It does not give medical, dietary or legal advice.
This policy complies with Turkey's Personal Data Protection Law (KVKK) and the European Union General Data Protection Regulation (GDPR).
Data Controller
Data Controller: CORIA
- Contact: privacy@coriaapp.com
- Website: https://coriaapp.com
As the data controller under KVKK and GDPR, we are responsible for processing your personal data. Use the contact information above to exercise your rights or ask questions.
Data We Collect
We collect the following categories of personal data when you use CORIA:
1. Account Information
- Email address
- Username
- Profile photo (optional)
- Authentication credentials (encrypted)
2. Usage Data
- Scanned product barcodes
- Product scanning history
- Favorite products list
- Allergen and dietary preferences (vegan, gluten-free, etc.)
- AI chat history
3. Technical Data
- Device information (model, operating system)
- IP address
- App usage metrics (analytics)
- Error logs (crash logs)
4. Permission-Based Data
- Camera: For barcode scanning (required)
- Location: For regional product recommendations (optional)
- Biometric: To confirm changes to your allergen settings on devices that support it (optional)
- Gallery Access: To select product photos from gallery (optional)
How We Use Your Data
We use your personal data for the following purposes:
1. App Functionality
- Barcode scanning and product recognition
- AI-powered vegan analysis
- Personalized product recommendations
- Allergen warnings and dietary compliance checks
2. User Experience
- Account management and authentication
- Saving your preferences (allergens, language, region)
- Storing scanning history and favorite products
- Regional product recommendations (if location permission granted)
3. Security and Fraud Prevention
- Confirming allergen setting changes (biometric check)
- Unauthorized access detection
- Spam and abuse prevention
Third-Party Services
CORIA shares data with the following third-party services:
Supabase (Authentication, Database)
- Purpose: User authentication, data storage
- Location: European Union (EU servers)
- Privacy: supabase.com/privacy (opens in a new tab)
OpenAI (AI Product Analysis)
- Purpose: AI-powered vegan analysis
- Location: United States
- Data: Product information from your scans, and — when you use the AI chat — the text of the messages you send. Your account identifier is not sent.
- Privacy: openai.com/policies/privacy-policy (opens in a new tab)
RevenueCat (In-App Purchases)
- Purpose: Premium subscription management
- Location: United States
- Privacy: revenuecat.com/privacy (opens in a new tab)
Sentry (Error Monitoring)
- Purpose: Crash and error diagnostics for the app, the website and the backend
- Location: United States
- Data: Error messages, stack traces, device and browser type, and a pseudonymous session identifier. Scrubbed of message bodies, tokens and identifiers before sending.
- Privacy: sentry.io/privacy (opens in a new tab)
Firebase Cloud Messaging (Push Notifications)
- Purpose: Delivering push notifications to your device
- Location: United States
- Data: A device registration token and the notification payload. No scan history or profile data.
- Privacy: firebase.google.com/support/privacy (opens in a new tab)
Google Analytics (Website Analytics)
- Purpose: Aggregate website traffic measurement
- Location: United States
- Data: Page views and anonymised IP, only if Google Analytics is configured. The Google Analytics script, cookies and events are not loaded or sent before you grant analytics consent.
- Privacy: policies.google.com/privacy (opens in a new tab)
Google Sign-In (Optional Login)
- Purpose: Signing in with a Google account, if you choose to
- Location: United States
- Data: Your Google account email and name, only when you use this login method.
- Privacy: policies.google.com/privacy (opens in a new tab)
Google Fonts (Typography)
- Purpose: Loading the typefaces the app and site are set in
- Location: United States
- Data: Your IP address, as with any request for a file from another server.
- Privacy: policies.google.com/privacy (opens in a new tab)
Contentful (Content Management)
- Purpose: Storing and serving editorial content shown on the website
- Location: European Union
- Privacy: contentful.com/legal/privacy-notice (opens in a new tab)
Axiom (Log Storage)
- Purpose: Storing application and request logs for diagnostics
- Location: United States
- Data: Request metadata and application events, redacted of message bodies, tokens and personal identifiers before sending.
- Privacy: axiom.co/privacy (opens in a new tab)
Resend (Transactional Email)
- Purpose: Sending account and service emails
- Location: United States
- Data: Your email address and the content of the message we send you.
- Privacy: resend.com/legal/privacy-policy (opens in a new tab)
Open Food Facts (Product Database)
- Purpose: Looking up product information by barcode
- Location: European Union
- Data: The barcode you scan. No account identifier is sent.
- Privacy: world.openfoodfacts.org/privacy (opens in a new tab)
ipapi.co (Country Detection)
- Purpose: Detecting your country to show regional pricing and local retailers
- Location: United States
- Data: Your IP address is sent over HTTPS to determine country-level location; the result is approximate.
- Privacy: ipapi.co/privacy (opens in a new tab)
AI Training Data (Opt-In Only)
- Purpose: Improving CORIA's analysis quality, only if you switch this on
- Location: United States
- Data: If and only if you opt in, the text of your AI chat messages and the product analyses they relate to are stored and may be used to improve our models. This is off by default, you can withdraw at any time, and withdrawal stops future collection.
- Privacy: openai.com/policies/privacy-policy (opens in a new tab)
Vercel BotID Basic (Bot Protection)
- Purpose: Refusing automated contact and newsletter form submissions
- Location: United States and other locations used by Vercel's subprocessors
- Data: Request, browser and network signals used to validate a protected form submission. CORIA calls BotID before reading the contact or newsletter body, so those form fields are not sent to BotID by this integration.
- Privacy: vercel.com/legal/privacy-notice (opens in a new tab)
All third-party services use GDPR-compliant Standard Contractual Clauses (SCC) for data protection.
Your Rights (GDPR & KVKK)
Under KVKK and GDPR, you have the following rights:
Right to Access
Learn what personal data we process about you.
Email privacy@coriaapp.com — there is no in-app data view; we answer access requests by email.
Right to Rectification
Correct inaccurate or incomplete data.
App → Profile → "Edit Profile"
Right to Erasure ("Right to be Forgotten")
Permanently delete your account and all data.
App → Profile → "Delete Account"
Right to Data Portability
Receive your data in JSON format.
Email privacy@coriaapp.com
Note: All data requests are processed within 30 days as required by KVKK and GDPR.
Security Measures
The measures below are what CORIA and its providers actually operate:
- Transport Encryption: Traffic between the app, our website and our backend uses HTTPS, including country detection through ipapi.co.
- Storage Encryption: Your data is stored by Supabase, which encrypts data at rest. We inherit this from Supabase rather than implement it ourselves.
- Password Security: Passwords are handled by Supabase Auth and are stored as one-way hashes. CORIA never receives or stores your password.
- Biometric Confirmation: On devices that support it, saving your allergen settings requires a fingerprint or face check. This is a confirmation step for that screen, not a login method.
- Error and Log Monitoring: Crashes are reported to Sentry and application logs are stored in Axiom, both with message bodies, tokens and personal identifiers removed before sending.
Children's Privacy
CORIA is not intended for children under 13 years old. We do not knowingly collect personal data from children under 13.
If you become aware that a child under 13 is using our app, please contact us immediately at privacy@coriaapp.com and we will delete the account and all associated data within 7 days.
Policy Changes
We may update this Privacy Policy from time to time. Significant changes will be communicated through:
- In-app notification
- Email to registered users
- Updated "Last Updated" date on this page
Continued use of the app after changes constitutes acceptance of the updated policy.
Contact Us
For questions about this privacy policy or your data:
Email: privacy@coriaapp.com
Website: coriaapp.com/contact
Response time: General questions within 5 business days, data requests within 30 days (KVKK/GDPR requirement)
Data Protection Authorities
If you believe your privacy rights have been violated, you can contact:
This privacy policy was last updated on August 13, 2026. For questions, contact privacy@coriaapp.com