This Privacy Policy explains how the Koza application ("the App"), developed and published by Kılınç Labs, collects, processes, stores, and protects your personal data.
Continued use of the App indicates that you have read and accepted this policy. If you do not accept this policy, please do not use the App.
Koza is an AI-powered baby tracking and mother's health application intended for parents aged 18 and over. The App provides baby feeding, sleep, diaper, growth, vaccination, and milestone tracking; mother's health tracking (mood, weight, postpartum recovery, postnatal depression screening); and AI-powered daily insights, weekly reports, and a question-and-answer assistant.
Location data, contact lists, photo library, and device identifiers are strictly not collected.
The following baby data is manually entered into the App by the parent or legal caregiver:
Baby and mother's health data (including feeding, sleep, growth, vaccinations, illnesses, mood, depression screening) is classified as "sensitive personal data" under Article 6 of the Turkish Data Protection Law (KVKK) and as "special categories of personal data" under the EU General Data Protection Regulation (GDPR). This data is processed only with the user's explicit consent, obtained via the AI Usage Consent screen during onboarding, and can be withdrawn at any time (see Section 9).
The collected data is processed solely for the following purposes:
Your data is not used for advertising purposes, not shared with third-party advertising networks, not sold, and not shared for marketing purposes.
Your personal data is processed under the following legal bases of the Turkish Personal Data Protection Law No. 6698 (KVKK):
We use the following third-party providers to deliver the app's services. These providers can only access data as necessary for the service and are subject to their own privacy policies.
All third-party providers listed below — especially the AI service provider Google — are contractually obligated to provide protection equal to or greater than that defined in this Privacy Policy. Kılınç Labs only works with providers meeting these security standards.
Infrastructure and data storage provider. All user data is stored on Supabase infrastructure. Row Level Security (RLS) ensures each user can only access their own data.
AI service provider used for daily insights, weekly reports, the Q&A assistant, and nutrition suggestions. Koza accesses the Google Gemini API through a paid Tier 1 plan. Under this plan, transmitted data is not used by Google for model training and is not subject to human review.
The following data is sent to the Gemini service:
Your email address, payment information, or account credentials are strictly never transmitted to Gemini. Transmitted data is used solely to process your request.
Subscription and purchase management provider. User identifiers and App Store / Google Play purchase information are processed.
OAuth providers used for registration and sign-in. Each provider's own privacy standards apply.
Application distribution infrastructure provider.
Error and crash reporting provider. Only anonymous error metadata is transmitted; personal data or health data is strictly not shared.
Supabase, Google Gemini, RevenueCat, and Sentry servers are located in the United States. Your data is therefore transferred abroad. This transfer is carried out under Article 9 of the KVKK, and the necessary technical and administrative measures are taken.
Your data is stored as long as your account is active. Account deletion is permanent and cannot be undone.
When the "Delete Account" action is performed, all the following data is permanently deleted:
On first use, you are asked to give explicit consent for sharing your data with the Google Gemini AI service (AI Usage Consent screen). The app's core AI features (daily insight, weekly report, Q&A assistant, milestone evaluation) depend on this consent.
To withdraw consent:
After the account is deleted, data previously transmitted to Google Gemini is deleted according to Google's own retention policy (on the paid Tier 1 plan, data is not used for model training).
If notification permission is granted, the following notification types become active; each can be turned on or off individually from the app settings:
Until permission is granted, no push token is recorded and no notifications are sent.
Koza is intended only for parents or legal caregivers aged 18 and over. The app uses baby and young child data for tracking purposes; however, this data is entered not by the child but by the legal parent or caregiver.
The app does not collect personal data directly from individuals under the age of 18 under COPPA and KVKK. Users acknowledge, when creating a registration, that they are over 18 years of age and that the baby data they enter is within their parental/caregiver authority.
If you notice that a child has accidentally registered, please contact koza.ai@proton.me; the account will be deleted immediately.
Under the Personal Data Protection Law, you have the following rights:
You can send your requests to koza.ai@proton.me. Requests are resolved no later than 30 (thirty) days from the date of application.
The accuracy of health data entered into the app (feeding times, sleep durations, illness symptoms, temperature readings, etc.) is the user's responsibility.
Insights, suggestions, and EPDS feedback produced by the AI are for informational purposes only; they do not constitute medical diagnosis, treatment, or medication recommendations. For any decisions regarding your baby's or your own health, always consult a pediatrician, gynecologist, or relevant healthcare professional.
Kılınç Labs cannot be held responsible for the consequences of health decisions made based on AI outputs produced from incorrectly or incompletely entered data.
If a high-risk level is detected in the postnatal depression screening test (EPDS), the app will direct you to the following resources. This is not medical advice; it is provided to encourage you to seek professional support:
The user is obliged to provide accurate, complete, and up-to-date registration information. The confidentiality of account login information (Apple ID, Google account) is entirely the user's responsibility. If you detect unauthorized access to your account, report it immediately to koza.ai@proton.me.
Kılınç Labs reserves the right to update this Privacy Policy without prior notice. Important changes are announced via in-app notification or registered email address. Continued use of the app after changes means you accept the updated policy.