ORIGINS
Get Origins

ORIGINS APPLICATION — PRIVACY POLICY

Back to Origins Last Updated: February 2026

ORIGINS APPLICATION — PRIVACY POLICY

Okan Atabağ ("Developer", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you use the Origins mobile application ("App").

This policy complies with:

  • General Data Protection Regulation (GDPR) — European Union
  • Turkish Personal Data Protection Law No. 6698 (KVKK) — Republic of Turkey
  • California Consumer Privacy Act (CCPA) — State of California, USA
  • Other applicable data protection laws

1. DATA CONTROLLER

Okan Atabag acts as the Data Controller for all personal data processed through the App.

Contact Information: Email: okiata@gmail.com

For KVKK-related inquiries: Veri Sorumlusu: Okan Atabağ E-posta: okiata@gmail.com

2. PERSONAL DATA WE COLLECT

2.1. Data You Provide Directly:

  • Photographs/images uploaded for ancestry analysis (Selfies)

2.2. Data Collected Automatically:

  • Device information (device type, operating system)
  • Anonymous usage analytics
  • App crash reports
  • Google Play / App Store purchase tokens (for subscription/payment verification)

2.3. Data We Do NOT Collect:

  • Names, email addresses, or phone numbers
  • Location data
  • Contact lists
  • Biometric data (facial recognition templates are NOT stored; images are processed transiently for visual analysis)

2.4. Face Data Collection and Usage

Our application utilizes mathematical facial detection technology (via Google ML Kit on-device API) strictly in real-time to locate the user's face within the camera frame (bounding box coordinates) and ensure it is properly aligned for a portrait photo.

  • Data Collected: The app does not collect, store, or transmit your actual "face data" (such as facial geometry, biometric face prints, depth data, or landmarks). It only temporarily processes real-time facial bounding box coordinates in memory to assist with framing your photo.
  • Use of Data: This temporary detection is used solely to provide a real-time visual guide (an alignment overlay) and auto-capture the photo when a face is centered.
  • Data Sharing: Face data (bounding box coordinates) is never shared with any third party. The facial detection processing happens entirely offline on your local device.
  • Data Retention: The facial detection coordinates are processed in real-time and are instantly discarded in memory once the camera frame is processed. No face data is retained or stored anywhere on the device or remote servers. Only the final captured photo is utilized by the application.

3. HOW WE USE YOUR DATA

3.1. Uploaded photographs are used SOLELY for:

  • Analyzing facial features via AI (Google Gemini) to estimate phenotypical origins.
  • Displaying results to you within the App.

3.2. We DO NOT use your photos to train AI models or for any purpose other than the immediate analysis requested by you.

4. DATA PROCESSING AND STORAGE

4.1. Image Analysis:

  • Your photo is transmitted securely via HTTPS to our backend (Firebase Functions) and then to Google Gemini AI for analysis.
  • We do NOT store your raw photos on our backend servers.
  • Analysis requests are protected with Firebase App Check and anonymous Firebase Authentication.

4.2. Local Storage:

  • For your convenience, the app saves your analysis results and the associated photo LOCALLY on your device's storage.
  • You can delete this history at any time via the "Clear History" button in the app.

4.3. Limited Server-Side Records (Cost/Abuse Protection):

  • To prevent abuse and control service costs, we store a limited server-side record in Cloud Firestore that may include:
    • analysis result JSON,
    • request metadata (e.g., mode, timestamps),
    • hashed/idempotency identifiers.
  • These records are retained for a limited period (currently about 30 days) and then removed via TTL policy.
  • Purchase entitlement checks are performed server-side via RevenueCat API.

5. THIRD-PARTY SERVICES

We verify that our third-party service providers are compliant with GDPR/KVKK:

  • Google Gemini AI (Analysis)
  • Google Firebase Functions / Firestore / App Check / Authentication (secure request handling, abuse prevention, limited metadata storage)
  • RevenueCat (Payment Processing)
  • Google Firebase (Analytics/Crashlytics)

6. YOUR RIGHTS (GDPR / KVKK / CCPA)

You have the right to:

  • Access your data (local app history and, where applicable, limited backend records).
  • Delete your data (using the in-app "Clear History" feature for local data; contact us for backend record requests).
  • Withdraw consent (by uninstalling the app or deleting history).

7. CONTACT US

For any privacy-related questions: Email: okiata@gmail.com

Read this in another language