Last updated: August 5, 2026
1. Data collected: Email address and name for your account; the photos and dream texts you submit for readings; optionally the name, gender, birth year and relationship status of the people you request readings for; if you signed up via another user's invite, the referral link between the two accounts; technical logs required to operate the service; and, only if you separately agree, the photos and symbol corrections kept for AI training (section 15); the satisfaction rating you give a reading (liked / disliked), used only to measure interpretation quality.
2. Purpose: Your data is used only to create your readings, manage your account and improve the service. Your data is not sold to third parties for advertising.
3. Photos and dream texts: They are sent to the AI provider to generate the reading and are NOT stored on our servers afterwards; only the reading itself is cached. Your reading history is kept encrypted on your device, and a backup tied to your account is stored on our servers — so your history follows you when you change phones. The backup holds only the interpretation text, NO PHOTOS; deleting your account deletes the backup too. The single exception is the training contribution you separately and explicitly agree to (section 15) — unless you agree, none of your photos remain on our servers.
4. People profiles: Details of the people you request readings for (name, gender, birth year, optional relationship status) are stored only on your device; they are sent to the server only while generating a reading and are not saved there.
5. Your rights: You have the right to access, correct and delete your data. You may withdraw any explicit consent you have given — including the training contribution — at any time. Deleting your account permanently removes your account data. Use the in-app contact channels for requests.
6. Children and age limit: The service is not directed to persons under 18 and they are not permitted to use it. We do not knowingly collect data from persons under 18; if we identify such data, we delete the account and associated personal data.
7. Account deletion: You can request permanent deletion of your account at any time from Profile > Delete my account, or from our web page if you have uninstalled the app. After your request, your account is permanently deleted in 15 days; signing in again during that time cancels the request automatically and your account stays exactly as it is — this keeps a mistake or a compromised session from turning into an irreversible deletion. Once the wait is over, deletion cannot be undone: your account, sign-in records and personal data are removed from the server, while usage statistics may be kept with every link to your identity removed (anonymised). If you contributed to training, your contribution records are deleted too, and any photo no other user has consented to is removed from the server.
8. Retention: If you do not sign in for 180 days (about six months), your account and data are deleted automatically; you are warned by e-mail beforehand. If you registered without verifying your e-mail and never verify it within a short window, your account is deleted automatically too, so it can never permanently block someone else's real address. Accounts holding unused tokens are subject to the same period. Photos kept under the training contribution are retained for as long as your consent stands and the model-development purpose continues; if you withdraw consent or delete your account, your contribution is removed. Satisfaction ratings are kept for at most 24 months. We also collect crash reports and basic usage statistics (which screens are used, which kind of reading, photo and symbol counts, duration) through Google Firebase; this is only for fixing the app — your name, e-mail, photos and reading texts are NOT sent as part of it. Ads are served through Unity Ads. Using your advertising ID to personalise them depends on YOUR EXPLICIT CONSENT; you are asked before the first rewarded ad and can withdraw at any time under Profile > Account and Privacy. Without consent, ads are shown without personalisation and you still earn your reward.
9. Legal basis: We process your data on these legal grounds: contract performance (to create your account and provide the service), your explicit consent (for the optional details about the people you request readings for and, if given, for the training contribution), compliance with legal obligations, and our legitimate interest in keeping the service secure and working (fraud/abuse prevention, basic statistics).
10. Additional rights for users in the European Economic Area, the UK and similar regimes: in addition to the rights in §5, you also have the right to restrict processing, to receive your data in a portable format, to object to processing, and to withdraw consent at any time. If you believe a request of yours was not properly handled, you may lodge a complaint with your country's data protection authority (in Türkiye, the Personal Data Protection Authority; in EU countries, the relevant national supervisory authority).
11. International data transfers: Your photos and dream texts are sent to Google's AI infrastructure (Gemini) solely to generate the reading, your app diagnostics and basic usage statistics go to Google Firebase, and your e-mails are sent through our SMTP provider; these providers may process data on servers outside your own country. These transfers rely on European Commission adequacy decisions or on the providers' Standard Contractual Clauses (SCCs) or equivalent safeguards. These transfers happen only for the purposes described above and under each provider's own data-protection commitments.
12. Third-party services we use: Google Gemini for AI interpretation; Google Sign-In if you choose to sign in with your Google account; Google Firebase for crash reports and basic usage statistics; Unity Ads for advertising; our SMTP provider for sending e-mail. If you choose Google Sign-In, an identity token is shared with Google to verify your account, and your name/e-mail are obtained from Google.
13. How things are stored on your device: Sensitive items like your session token and saved person profiles are kept in your device's encrypted secure storage (Android Keystore-backed); your reading history is kept in that same encrypted store; non-sensitive counters like your daily reading allowance are kept in plain local app preferences.
14. Data breach notification: If we detect a breach that could affect the security of your personal data, we will notify you and/or the competent authority as required by applicable law, within a reasonable time.
15. Contributing to AI training (entirely optional):
(a) What it is: To build our own image-analysis model, we keep reading photos and the symbol corrections you make. The purpose is to make readings more accurate over time.
(b) It is OFF BY DEFAULT and is NOT required to use the app. If you do not agree, none of your photos remain on our servers, no feature is restricted, and no price changes. This consent is requested separately from, and in addition to, accepting the Terms of Service.
(c) There are two separate paths: (1) One-off contribution — if you submit the "fix the symbols" screen after a reading, only that reading's photos and that correction are kept. (2) Ongoing contribution — if you enable it on the Profile screen, the reading photos you send are kept while it stays on. You can turn either off at any time.
(d) Palm reading photos are NEVER retained: an image of your palm is special-category personal data, close in nature to biometric data (KVKK art. 6; GDPR art. 9). Palm photos are therefore never kept for training — not even with your consent. Your palm photo is discarded once the reading has been produced, and it falls entirely outside the training contribution. The training contribution covers coffee reading photos only.
(e) Withdrawing consent: You can turn it off at any time on the Profile screen. Turning it off stops FUTURE contributions. If you want contributions you already made to be deleted, deleting your account is enough: your contribution records are removed and any photo no other user has consented to is deleted from the server.
(f) What is kept, what is not: Kept — the photo itself, the reading type, the symbols you marked or corrected, the date of consent and the version of the consent text. Not kept — your name, your e-mail address, person profiles, and identifying details tied to the reading text.
(g) Sharing: Training data is never sold or shared with third parties; it is used solely to train our own model.
16. Data controller and contact: The controller of your personal data is Handan Öztürk. Address: Kizilay Mh. Menekse 2 Cd. Munire Kuloglu Ishani No:35 D:30, 06420 Cankaya/Ankara, Türkiye. For data protection, access, correction, objection and deletion requests: info@bakfal.com. Requests are answered within thirty days at the latest.
17. Automated processing: Your readings are generated fully automatically. This is not a decision producing legal effects concerning you or similarly significantly affecting you; it is entertainment content. Decisions that genuinely affect you, such as suspending your account, are made by human review rather than automatically.
18. United States state privacy laws: Under California (CCPA/CPRA) and similar state laws, we DO NOT sell your personal information and DO NOT share it for behavioural advertising. You have the rights to know, access, correct and delete, and not to be discriminated against for exercising them; send requests to info@bakfal.com.
19. Device permissions, notifications and purchase records: The camera and photos are accessed only when you take or select a reading photo. For dream dictation, the microphone is used only after you tap the microphone button; we do not receive or store the audio, but the Android/Google speech-recognition service on your device may process it under its own terms. If you allow notifications, Firebase Cloud Messaging creates a device notification token and we link it to your account solely to deliver notifications; it is removed on sign-out, account deletion or when the provider reports it invalid. When you buy tokens, the product identifier and Google Play purchase token/receipt data are processed by Google Play and our server to verify the purchase, credit your balance and prevent fraud; we never receive card or bank details. Reading text on your device is kept in encrypted storage, while coffee thumbnails are kept as app-private files excluded from Android backup for at most the latest 20 records. Sign-in and security logs are retained while the account exists for security and are removed or de-identified when the account is deleted.