Zum Dokument springen
Lettuce
FunktionenSo funktioniert’sBlogSupportHerunterladen
Deutsch
EnglishDeutschFrançaisEspañolItalianoTürkçe

Datenschutzrichtlinie

Zuletzt aktualisiert am 17. September 2026

Dieses rechtliche Dokument ist derzeit auf Englisch verfügbar.

This Privacy Policy explains what personal data the Lettuce mobile app ("Lettuce", the "App") and the related Lettuce services collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It supplements the Lettuce Terms of Service, which govern your use of the service.

Lettuce is operated by Hüseyin Alperen Yucal, a sole proprietorship established in Türkiye. "Lettuce" and "Elevic" are brand names used for our products and services; Elevic is not a separate legal entity at this time.

1. Who is responsible for your data

  • Controller: Hüseyin Alperen Yucal (sole proprietor), Türkiye
  • Registered address: Caferağa Mah. Soner Sok. 36/5 Kadıköy / İstanbul Türkiye
  • Email: support@elevic.co
  • Website: lettuce.elevic.co

We decide what data Lettuce collects and why, which makes us the controller of your personal data wherever you use the App. Data protection laws differ by country; section 17 sets out the specific disclosures that apply in Türkiye, the EU/EEA and the UK.

2. What data Lettuce collects

Each feature collects only what it needs to work. Most data in Lettuce is data you enter yourself; the rest is generated by the App or received from a service you connect.

2.1 Account data

  • Email address and password if you register with email. Authentication is handled by Google Firebase Authentication: your password is stored and verified by Firebase and is never visible to us.
  • Sign in with Apple or Google Sign-In identifiers if you use them. If you use Apple's Hide My Email, we only receive the private relay address.
  • A Firebase user ID, which is the identifier that links your records across our systems.
  • Display name and, optionally, a profile photo.

Profile photos are stored in an Amazon S3 bucket that is readable by anyone who has the exact file URL. The URL is not published or listed anywhere, but it is not password protected — please do not upload a photo you would not be comfortable sharing by link.

2.2 Profile and goal data

  • Date of birth or age, sex, height, current weight, goal weight, activity level and goal pace.
  • Calorie, macronutrient (protein, carbohydrate, fat), water, step and fasting targets calculated from those inputs, or set by you.
  • Language, region, time zone and app appearance preferences.

2.3 Nutrition and daily tracking data

  • Meals, foods, portion sizes, favorites, recent items and the times you logged them.
  • Daily and historical calorie, macro, water, weight, sleep, step and workout records.
  • Text you type into food search, which is sent to our own food search server to return results.

2.4 AI meal scan data

  • Photos you take or select for a meal scan, and text descriptions of meals you type.
  • Your language preference and device country, sent with the request so the estimate and the food names match your region.
  • The food items and estimated nutrition values returned by a scan, which may be cached for your account even if you do not save them to your meal log.
  • Stored scan photos and related details, including the scan time, image format and a scan reference linked to your account. Photos may be retained even if recognition fails or you do not save a meal.
  • Relevant food details from AI results you previously saved to your meals, including your corrections, used to recognise the same food in later scans.

Section 5 describes how meal-scan photos are handled in detail.

2.5 Fasting data

  • Fast start and end times, the fasting protocol you selected, and your fasting history.
  • The fasting stage shown in the App, which is calculated from elapsed time only (see section 6).

2.6 Health and fitness data from your device

Only if you grant permission, Lettuce reads from and writes to Apple Health (iOS) or Health Connect (Android):

  • Read: steps, weight, height and hydration records.
  • Write: weight, height, hydration, nutrition and active energy records you create in Lettuce.

You can revoke this permission at any time in your device settings, and Lettuce will keep working without it. Health data obtained through Apple Health or Health Connect is never used for advertising, never sold, and never shared with third parties for their own purposes.

2.7 Progress and streak data

  • Streak counters, badges, levels and achievement records generated from your activity in the App.

2.8 Subscription data

  • Subscription status (free, trial, active, expired), plan, renewal or expiry date and store transaction identifiers, managed through RevenueCat.
  • Your Firebase user ID is used as the RevenueCat customer identifier, and your email address and display name are synced to RevenueCat so we can find your subscription when you contact support.

All payments are processed by the Apple App Store or Google Play. We never see or store your card, bank or billing details.

2.9 Notification data

  • An Expo push token, your platform (iOS/Android) and a device identifier, stored so we can send push notifications to the right device.
  • Your notification preferences (which reminders are on and at what times).

2.10 Device, usage and diagnostic data

  • App platform, version, build, application identifier and environment; operating system name/version; device type, model, manufacturer and whether it is a physical device; device language, region and timezone; selected app language and appearance. We use this context for compatibility, feature configuration and product analytics.
  • App opens, screen names, onboarding progress, sign-in method, paywall visits, purchase interactions, use of meal-logging and fasting features, and AI scan performance/error categories. Analytics includes event timestamps, session identifiers and a generated installation identifier. Section 8 describes account-linked properties and how to turn analytics off.
  • IP address, which our servers and service providers process as part of internet requests, including for security and abuse prevention. PostHog may also derive approximate country, region, city and related geographic properties from the request IP for product analytics and configuration.
  • Crash reports and error data, including stack traces and the actions leading up to an error.

2.11 Support data

  • Messages, attachments and support tickets you send us in the App or to support@elevic.co, and our replies.
  • Feedback you submit through the in-app feedback form, which may include a screenshot if you attach one.

3. Why we use your data

  • To create, authenticate and manage your account.
  • To calculate your calorie and macro targets and run the core tracking features: meals, fasting, water, weight, sleep, steps and workouts.
  • To produce AI meal-scan estimates from your photos or text, reuse relevant foods you previously saved, and maintain a private record of submitted scan images for image-history features when available.
  • To sync your data across your devices and keep it available offline.
  • To run streaks, badges and other progress features.
  • To manage Lettuce Pro subscriptions, free trials and access to premium features.
  • To send the reminders and notifications you have enabled. Promotional push notifications about Pro offers are a separate, optional choice, off by default. If you opt in, paywall visits may trigger these offers. You may opt out in Settings → Notifications. We record the consent version and timestamp and recheck your choice before sending a queued offer.
  • To answer support requests.
  • To monitor performance, diagnose crashes, prevent abuse and keep the service secure.
  • To configure compatible features for your app version, device and language, understand how features are used, improve onboarding and purchases, and investigate account-related support issues.
  • To comply with legal, accounting and tax obligations.

4. Why we are allowed to process it

  • Your consent — for health and wellness data: nutrition, fasting, weight, sleep and activity records, meal photos, and anything read from Apple Health or Health Connect. You can withdraw consent at any time by revoking the permission, turning the feature off, or deleting your account.
  • To provide what you signed up for — account creation, the core tracking features, sync across devices, and subscription management. Without this data the App cannot work.
  • Our legitimate interests — security, abuse prevention, crash diagnostics, feature configuration, account-related support and product improvement through the analytics described in section 8, where applicable law permits this basis. You can object to usage analytics by turning it off in Settings, or contact us about other processing based on legitimate interests.
  • Legal obligations — accounting, tax and other records we are required to keep.

Section 17 maps these to the legal bases named in Turkish and EU/UK law.

5. How AI meal scan handles your photos

AI meal scan is a Lettuce Pro feature. When you scan a meal, the photo (or your text description) is sent over an encrypted connection to our AI service, which forwards it to an AI provider to identify the food items and estimate their nutrition values. Before any AI processing, the App asks for separate, affirmative permission and describes the providers that may process text and photos, including optional fallbacks. You may decline and use non-AI tracking. Withdraw this permission in Settings → Privacy → AI data sharing. Your choice, the disclosure version and a device timestamp are saved only on your device for the signed-in account. The choice is not sent to our servers or synced between devices. Signing out clears it; using another device or clearing App data requires permission again. Updated disclosures require renewed permission.

  • AI providers depend on the enabled configuration. Google Gemini is the primary provider. OpenAI and Anthropic may process text as fallbacks when configured, and photos only when image fallback is enabled. The permission screen identifies these possible recipients before sharing; it does not retrieve the current server configuration. Adding a provider outside this disclosed list requires an updated App disclosure and renewed permission before that provider receives your data.
  • We store scan photos privately. The image submitted to the scan service is stored in private Amazon S3 storage, with a scan reference linked to your account. These photos are not publicly accessible and are not displayed in the current App. We retain them to maintain your scan record and support image-history features when available. A photo is archived only after a successful, nonempty scan, even if you do not save its results. Storage can fail independently of recognition, so we do not guarantee a complete photo archive. See section 11 for retention and deletion.
  • New nutrition cache entries are linked to your account. We cache generated food descriptions and nutrition values so your later scans can reuse them. These records are personal data, not an anonymous shared cache. They are separate from the meal records you choose to save.
  • Saved-meal memory uses your own records. When you scan, we may compare the recognised food with relevant AI foods you previously saved, including your corrections. Food names, descriptions, brands and food references from those records may be sent to an AI provider for matching. A match can reuse the saved food's nutrition values while estimating the current portion separately. We do not use another user's meal records or photos as your saved-meal memory.
  • AI providers also process submitted content. Their handling of inputs and outputs, including retention and any use to improve their services, is governed by the applicable service terms and data processing arrangements. Google's rules distinguish paid and unpaid API services; see the Gemini API terms. We do not add your name, email address or Firebase account ID to scan prompts, but photos, text and saved food details can still contain personal information. Do not include unrelated personal or sensitive information in a scan.
  • Results are estimates. AI portion and nutrition estimates can be wrong. Review and adjust them before saving.

Saved-meal memory does not analyse your fasting, sleep, water or activity history for periodic insights. If you use AI chat when available, messages, conversation history, profile and tracking records provide context to the enabled text providers. Chat is subject to the same explicit, versioned permission. Withdrawing permission stops future AI requests; it cannot recall data already sent to a provider or erase records you chose to save.

6. How fasting stages work

The fasting stage, timer and related information shown in the App are calculated from the times you enter. They are an educational timeline based on elapsed time and do not measure, confirm or predict what is happening in your body. They are not a medical measurement (see section 15).

7. Who we share data with

We do not sell or rent your personal data. We share only what a provider needs to perform its function for us, under a data processing agreement where required:

  • Amazon Web Services (AWS) — hosting, databases, file storage and application logs for the Lettuce backend. Receives: all data stored in your account.
  • Google Firebase Authentication — sign-in and account credentials. Receives: email, password hash, sign-in provider identifiers, sign-in metadata.
  • Google (Gemini API) — AI meal recognition and nutrition estimation and saved-food matching. Receives: meal photos, meal or food descriptions, locale context, and relevant saved food names, descriptions, brands and food references. We do not add your Firebase account ID, email address or display name to scan prompts.
  • OpenAI, Anthropic — fallback text processing when the primary AI provider fails. Receives: meal or food descriptions, locale context, and relevant saved food details used for matching. This can include text derived from an image scan, even when the photo itself is processed only by Google.
  • Our food search server (self-managed Typesense on a third-party hosting provider) — food search results. Receives: search terms and country.
  • RevenueCat — subscription and entitlement management. Receives: Firebase user ID, email, display name, store transaction and subscription status.
  • Apple App Store, Google Play — payment processing, subscriptions, refunds. We receive transaction and subscription status from them; they never send us your payment details.
  • Expo (push notification service) — delivery of push notifications. Receives: push token and notification content.
  • PostHog — product analytics and feature configuration. Receives account identifiers and properties, app/device context and usage events described in sections 2.10 and 8. Our backend also evaluates registered feature flags using your Firebase user ID and backend environment.

We may also disclose data where we are legally required to (for example to a competent authority acting under applicable law), or where necessary to establish, exercise or defend legal claims.

8. Product analytics, feature configuration and advertising

Product analytics. We use PostHog (US) to understand feature use, improve onboarding, purchases and reliability, and investigate account-related support issues. Analytics is enabled by default. You can turn it off in Settings → Privacy → Usage analytics without losing app features. This stops future analytics events from that device and clears its pending event queue; the preference is kept when you sign out. There is no separate analytics consent prompt. Where permitted, we rely on legitimate interests for this processing, subject to applicable law and your right to object.

Before sign-in, events use a generated identifier stored on your device. After sign-in, PostHog links activity to your Firebase user ID and receives your email and display name, email-verification status, anonymous-account status, sign-in providers, account creation and last sign-in times, onboarding completion/version, and subscription loading/access/product/renewal/expiration status. App/device/localization properties are described in section 2.10. Signing out resets the analytics identity on the device. This collection is account-linked personal data, not anonymous analytics.

Events include screen names, app lifecycle, onboarding steps, feature-flag exposure, paywall and purchase activity, whether meal logging or fasting was started, and AI scan input type, provider, timing, counts and error categories. We do not send health answers or records, fasting regimen/duration, meal contents/dates, nutrition values, photos, scan text/results, authentication tokens or raw scan error messages in these analytics events. General feature activity still indicates use of meal and fasting features. We do not record screens or automatically capture touches.

Feature configuration. PostHog also configures platform-specific presentation and compatible rollouts. These requests use app/device context and a generated identifier, or your account identifier while identified. Configuration remains available after analytics is turned off, using a reset identifier and app/device context. Our backend separately evaluates registered flags with Firebase user ID and backend environment. These evaluations do not include health records. Device region and timezone come from settings, not GPS. PostHog uses standard IP-based enrichment to derive approximate geographic properties for analytics and configuration. This does not use device GPS or request precise location permission.

Turning analytics off does not automatically erase previous provider records; the retention and deletion terms in sections 11–13 apply. Contact support to request deletion. Promotional subscription notifications require the separate Promotions opt-in in Settings → Notifications; enabling analytics does not enable those messages. Older versions may have different collection behavior.

No advertising SDKs. Lettuce contains no advertising or ad-attribution SDKs. We do not collect the iOS advertising identifier (IDFA) or the Android advertising ID, we do not track you across other companies' apps and websites, and we do not sell or share your data for advertising or targeted advertising purposes. If we advertise Lettuce, that happens on the advertising platform's side using aggregate campaign data provided by the App Store or Google Play, not by tracking you inside the App.

9. International transfers

We and our providers operate internationally, and most of the services listed in section 7 are based in the United States. Your data is therefore stored and processed outside your country, including in the United States, whichever country you use Lettuce from. We rely on the contractual and technical safeguards offered by those providers, and on the transfer mechanisms described in section 17 where local law requires a specific one.

10. Subscriptions, trials and payments

Lettuce Pro is sold as an auto-renewing subscription through the Apple App Store or Google Play. Purchases, free trials, renewals, cancellations and refunds are handled by the store, under the store's terms. We receive the subscription status and transaction identifier needed to unlock premium features; we never receive your card or bank details. Pricing and cancellation terms are described in the Terms of Service and in your store account.

11. How long we keep your data

  • Account and tracking data — kept while your account exists, so your history stays available to you.
  • Meal scan photos and scan references — kept while your account exists, including photos from successful scans whose results you did not save. Empty or failed scans are not archived. Deleting a meal does not automatically delete its scan photo. Account deletion removes stored scan photos and their references; you may also contact us to request deletion under section 13.
  • New account-linked AI nutrition cache entries — expire for reuse 30 days after creation and are removed through database expiry processing, which may complete later. Food snapshots you saved to your meals remain with those meals until you delete them or your account. Deleting a saved meal stops it being used as saved-meal memory; it does not by itself remove separately cached nutrition data.
  • Support tickets and emails — kept while your account exists and deleted with it; email correspondence may remain in our mailbox for a reasonable period afterwards.
  • Diagnostic and analytics data — retained by our providers according to their retention settings, and used only in the ways described above.
  • Server logs — retained for a limited period for security and troubleshooting.
  • Accounting and tax records — kept for the period required by applicable law, even after account deletion.

When you delete your account in the App (Profile → account settings), we delete your profile, targets, meal, fasting, water, weight, sleep, step and workout records, streak and achievement data, push tokens, support tickets and profile photo, stored scan photos, scan references and account-linked AI nutrition cache entries from our database and file storage, and we delete your Firebase authentication user. This also removes older AI food records that our systems can identify as linked to your account; a hashed food reference does not by itself make a record anonymous. We begin deletion when you request it. A network or service failure can interrupt the process, in which case you may need to retry or contact support. Completed deletions cannot be undone. In-app deletion does not automatically erase all copies held by other providers: subscription customer and transaction records, analytics and diagnostic records, provider logs and legally required records may remain under the retention practices described above. Contact us under section 13 to request deletion of data held by those providers where the law permits. A subscription bought through a store must be cancelled in that store separately.

12. Security

Data is transmitted over encrypted (HTTPS/TLS) connections and stored on managed AWS services with encryption at rest. Access to private account data requires a verified Firebase token, and premium features are verified server-side. Public website and food-catalogue endpoints do not require an account. Scan-photo storage is private; profile-photo URLs have the separate access rules described in section 2.1. Access to production systems is limited to the operator. On your device, your data is stored in the App's private storage. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Your rights

Wherever you live, you can ask us to:

  • tell you whether we hold data about you, and what we do with it;
  • give you a copy of your data, in a portable format;
  • correct data that is wrong or incomplete;
  • delete your account and the data it contains;
  • stop or limit a particular use, including withdrawing a consent you gave earlier;
  • tell you which providers received your data;
  • explain any decision reached by automated means, and object to it.

You can delete your account and its data yourself in the App at any time, and turn off individual permissions such as health access or notifications in your device settings. For anything else, email support@elevic.co. We reply within one month, and sooner where the law requires it. If we cannot act on a request, we will tell you why.

Depending on where you live you may have further rights and a way to complain to a regulator — see section 17.

14. Children

Lettuce is intended only for adults aged 18 or older. Do not create an account or use Lettuce if you are under 18. We do not knowingly collect personal data from people under 18. If you are a parent or guardian and believe someone under 18 has provided us with personal data, contact support@elevic.co and we will delete it once identified.

15. Health disclaimer

Lettuce provides general wellness information and personal tracking, not medical advice or care. It is not intended to diagnose, treat, cure, prevent or monitor any disease or medical condition, and is not intended for use as a medical device. Using Lettuce, its AI features or support does not create a doctor-patient, dietitian-client or other clinical relationship. We do not provide clinical supervision, monitor your records for medical danger, or offer an emergency response service.

Food identification, ingredients, portion sizes, nutrition values, targets, fasting stages and other automated outputs may be inaccurate or unsuitable for you, including when based on a meal you previously saved or corrected. They cannot establish whether a food is safe for an allergy, intolerance or medical condition, and must not be used to decide medication doses or replace prescribed treatment or a clinician's dietary instructions.

Consult a qualified health professional before changing your diet, fasting, weight or exercise routine, especially if you are pregnant or breastfeeding, take medication, or have or have had an eating disorder or another medical condition. Never disregard professional advice or delay seeking care because of anything shown in Lettuce. In an emergency, contact your local emergency services. You remain responsible for your choices about diet, fasting, exercise and health.

To the fullest extent permitted by applicable law, we disclaim responsibility for health decisions and consequences arising from reliance on the App's estimates or information, subject to the limitations and mandatory-rights exceptions in sections 3 and 17 of the Terms of Service. Nothing in this notice excludes liability that the law does not allow us to exclude.

16. Cookies and the Lettuce website

The lettuce.elevic.co website does not use advertising or analytics cookies and does not track visitors. The App stores preferences and your synced data locally on your device so it works offline; this local storage is cleared when you delete the App.

17. Regional disclosures

Türkiye

Lettuce is operated from Türkiye, so Law No. 6698 on the Protection of Personal Data ("KVKK") applies to our processing. Hüseyin Alperen Yucal is the data controller (veri sorumlusu) named in section 1, and this policy also serves as the disclosure notice required by article 10 of the KVKK. The legal bases in section 4 correspond to explicit consent under article 6 for special-category health data, article 5/2-c (necessary for a contract), article 5/2-f (legitimate interests) and article 5/2-ç (legal obligation). Transfers abroad, described in section 9, are made in accordance with article 9. In addition to the rights listed in section 13, article 11 gives you the right to request that corrections or deletions be notified to third parties, and to claim compensation for damage caused by unlawful processing. Requests are answered within 30 days, and you may complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).

European Economic Area and United Kingdom

Because we offer Lettuce to people in the EU/EEA and the UK, the GDPR and the UK GDPR apply to that processing. The legal bases in section 4 are consent for health data (articles 6(1)(a) and 9(2)(a)), performance of a contract (article 6(1)(b)), legitimate interests (article 6(1)(f)) and legal obligation (article 6(1)(c)). Transfers outside the EEA and UK, described in section 9, rely on Standard Contractual Clauses or another mechanism permitted under chapter V, together with our providers' own safeguards; we will provide a copy of the relevant safeguards on request. Beyond the rights in section 13 you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent without affecting processing carried out beforehand. You may lodge a complaint with your national supervisory authority.

Everywhere else

If you use Lettuce elsewhere, the practices described in this policy apply to you in full, along with any rights your local law gives you. We do not sell or share personal data for advertising or targeted advertising, and we do not use it to build cross-context behavioural profiles.

18. Changes to this policy

We may update this Privacy Policy as the service, our providers or legal requirements change. If a change is significant, we will notify you in the App or by another appropriate channel before it takes effect. The "last updated" date shown with this document indicates the current version.

19. Contact

  • Lettuce / Elevic — operator: Hüseyin Alperen Yucal, Türkiye
  • Address: Caferağa Mah. Soner Sok. 36/5 Kadıköy / İstanbul Türkiye
  • Email: support@elevic.co
  • Website: lettuce.elevic.co

Folge Lettuce

Instagram ↗Facebook ↗YouTube ↗
Blog
© 2026 Elevic. Alle Rechte vorbehalten.Nutzungsbedingungen · Support