ValueLens · Last updated: 20 July 2026
Contents: 1. Who We Are (Data Controller) · 2. Scope; Our Philosophy · 3. At a Glance · 4. Data We Process · 5. Purposes & Legal Bases · 6. AI Processing & Service Providers · 7. International Data Transfers · 8. Retention · 9. Security · 10. Your Rights — EEA/UK (GDPR) · 11. Your Rights — Türkiye (KVKK) · 12. Your Rights — California (CCPA/CPRA) · 13. Children · 14. Third-Party Links & the App Store · 15. Do Not Track & Ad Identifiers · 16. Changes to This Policy · 17. Contact & Exercising Rights
The data controller (under the GDPR) and “veri sorumlusu” (under Turkish Law No. 6698, “KVKK”) for personal data processed in connection with the ValueLens app is:
Ümit Üregün (ValueLens)
Email: info@tenisify.app
This Policy explains what we process when you use the App, why, and your rights. ValueLens is designed for data minimization: no account, no advertising or tracking SDKs, no sale of personal data, and your collection stays on your device.
(a) Scanned images. When you scan, the photo (and your optional category choice and app language) is transmitted to our backend and to our AI provider to generate the identification and estimate. We advise photographing collectibles only — please do not include identifiable people or personal documents in scans; if you do, you are responsible for that content.
(b) Collection data. Saved items, notes, and totals are stored locally on your device and are not uploaded to us.
(c) Purchase entitlements. Apple processes purchases; the App verifies entitlements via Apple’s StoreKit. We do not receive your name, card, or billing details.
(d) Technical & security logs. Our server may temporarily record request metadata (such as timestamps, technical status, truncated identifiers, and IP address as part of standard transport) strictly for security, abuse prevention, and troubleshooting. Such logs are kept short-term (up to 30 days unless needed for an ongoing security investigation) and are not used for profiling.
(e) Camera permission. Used only to capture photos you choose to scan; nothing is captured without your action.
What we do not collect: no account, no contact lists, no precise location, no advertising identifiers, no cross-app tracking.
We process data to: (a) provide the identification service you request — performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)); (b) secure and protect the service against abuse — legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)); (c) comply with legal obligations where applicable (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)); and (d) where required for cross-border transfer or otherwise, on the basis of your explicit consent, which you may withdraw at any time (KVKK Arts. 5(1), 9).
To generate Results, scanned images are transmitted to: (a) our backend server (request relay, security); and (b) our AI service provider — currently and primarily Google LLC (Gemini API) — which processes the image to produce the identification. Google’s processing is governed by its own terms and documentation — see Google’s Gemini API terms. To keep the service reliable and sustainable, we may add or switch AI providers from time to time (for example, during outages or commercial changes); any provider we use processes your images solely to deliver this feature. Our providers act as processors/recipients and are not authorized by us to use your images to identify you. We do not use your images to train our own models.
Our servers and providers (including Google) may be located outside your country, including outside Türkiye and the EEA. Where required (including under KVKK Art. 9 and GDPR Chapter V), transfers take place on the basis of your explicit consent given when you initiate a scan, and/or other lawful transfer mechanisms available under applicable law (such as adequacy decisions or standard contractual clauses used by our providers). If you do not consent to such transfers, please do not use the scan feature.
Scanned images are processed transiently to produce a Result and are not stored by us in an image library or used for profiling. Security logs are short-lived as described in Section 4(d). Your collection remains on your device until you delete items or uninstall the App. Aggregate, non-identifying technical statistics may be kept for service planning.
We use appropriate technical and organizational measures, including transport encryption (HTTPS) and access controls on our backend. No system is perfectly secure; to the maximum extent permitted by law, we cannot guarantee absolute security, and you use the service at your own discretion.
If you are in the EEA or UK, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time (without affecting prior processing). You may lodge a complaint with your local supervisory authority. Because we do not maintain accounts or a server-side archive of your images, many rights are satisfied automatically; for anything else, contact us (Section 17).
Under KVKK Article 11, you may: learn whether your personal data is processed; request information; learn the purpose and whether data is used accordingly; know the third parties to whom data is transferred domestically or abroad; request rectification, erasure, or destruction (KVKK Art. 7); request notification of such actions to transferees; object to results produced exclusively by automated analysis to the extent provided by law; and claim damages for unlawful processing. Applications may be sent to our contact address (Section 17) pursuant to the Communiqué on Application Procedures; you also have the right to complain to the Personal Data Protection Board (KVKK Kurulu).
We do not “sell” or “share” personal information as defined by the CCPA/CPRA, and we do not use sensitive personal information to infer characteristics. California residents have rights to know, delete, correct, and non-discrimination; contact us to exercise them.
The App is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us and we will address it.
The App may link to third-party pages (e.g., these policies, Google’s terms). Apple’s processing of your App Store account and payments is governed by Apple’s own privacy policy. We are not responsible for third parties’ practices.
The App does not respond to “Do Not Track” signals because it does not track you across apps or websites, and it does not use advertising identifiers.
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above; where required by law, we will provide additional notice or seek consent.
For questions about these terms:
Email: info@tenisify.app
© 2026 Ümit Üregün (ValueLens). All rights reserved.