Haftra LogoHaftraPrivacy
  • Home
  • Guides
  • Support
EN
  • Türkçe
  • English (US)
  • English (UK)
  • Deutsch
  • Español
  • Français
  • العربية
SECURITY & TRANSPARENCY

Privacy Policy

Effective: 26 July 2026 · Last updated: 8 September 2026

The short version

  • You can use Haftra without an account. In that mode no health data ever leaves your device.
  • With an account your records are backed up to a private space only you can read. Progress photos still stay on the device.
  • No ads, no tracking, no third-party analytics. The app contains no advertising or third-party analytics SDK of any kind.
  • We do not sell, rent or share your data for marketing.
  • Your progress photos are never uploaded, under any circumstances.
  • A meal photo is sent only when you choose to scan it (Haftra+), is used for the estimate and is not kept. The only thing that stays is the figure you accept.
  • You can permanently delete your account and every record from inside the app.

1. Using Haftra without an account

On first launch you can choose to continue without creating an account. In that mode your injections, weight, side effects, blood glucose readings, daily tracking and settings are stored only in your phone's own storage. That data is never transmitted to us or to any server. Deleting the app deletes it.

2. Data processed when you create an account

If you want your records backed up across devices, or you want to use the anonymous community feature, you can create an account with Apple or with an email address. Only then is the following processed: your e-mail address, to create your account and verify sign-in; your name and gender selection, both optional, to greet you and to give body composition readings context; and your health records, meaning injections, weight, blood glucose, side effects, meal notes (including the protein and calorie estimates you accept), daily tracking and treatment settings, so they can be backed up and synced.

These records are protected in the database by row-level security: technically, only your own session can read your own rows. No other user can query your records.

Progress photos are never uploaded. Even with an account they stay on your device only; they are not part of the backup.

3. Sign in with Apple

When you sign in with Apple, Apple sends us only a user identifier scoped to our app and an email address. That identifier is generated for Haftra alone, so it cannot be used to track you across apps.

  • If you choose Hide My Email, the address we receive is an Apple-generated alias and we have no access to your real one.
  • Apple does not send us your name, your device model, or any other Apple account information.

4. Technical data kept for session security

Our authentication layer records your IP address and a client identifier containing your app version and operating system version each time you sign in, so we can spot unauthorised attempts to reach your account.

  • It contains no device model and no device identifier; the app never reads such an identifier from your phone.
  • It is never used for profiling, advertising or analytics, and is not linked to your health records.
  • It is deleted automatically after a limited period.

5. The Health app

With your permission, Haftra reads the weight, blood glucose and body fat measurements you select from the Health app, so you do not have to re-enter what your smart scale or glucose app already recorded.

  • Haftra never writes to the Health app; it only reads.
  • You can revoke this at any time in Settings › Health › Data Access & Devices.
  • Health app data is never used for advertising or marketing; Apple prohibits this outright.

6. Anonymous community signals

If you choose to share a side effect with the community, its name, severity and date are recorded alongside your medication.

  • The community screen shows counts and average severity only; nobody can see individual entries.
  • A side effect does not appear until at least 3 different people have reported it.
  • Other users cannot see your identity, your email, or any of your other records.
  • Only the medication name, the symptom name, a severity from 1 to 5, and the date rounded to the day are sent.
  • You can remove all of your community reports from Settings.

To be explicit: your report is stored in the database linked to your account identifier. This is necessary; otherwise one person could skew a summary by reporting the same symptom over and over. The anonymity comes not from the row being identity-free but from that table granting no read access to any user.

7. Progress photos

Progress photos are stored on your device only, with file protection enabled. Even with an account, these photos are not synced, not uploaded, and cannot be seen by us.

8. Estimates from a meal photo (Haftra+)

With Haftra+ you can photograph a meal and get a protein and calorie estimate. It runs only when you tap "Photograph your plate"; the app never reaches for your camera or your library on its own, and you can always log a meal by hand instead.

  • What is sent: a downscaled copy of the photo you took or chose, and your account's session credential (to confirm the request is yours and that you subscribe to Haftra+). No other health record, note or name is attached to the request.
  • Where: the photo first reaches our server in the European Union (Supabase), which passes it to Google's Gemini API to produce the estimate. The model is confined to identifying the food on the plate and estimating portion, calories and protein; it answers no other question.
  • What is not kept: the photo. No copy is retained on your device, on our server, or stored on our behalf at Google; once the answer is produced the request is over. Google processes the request under its own API terms.
  • What is kept: a monthly scan count tied to your account (to enforce the quota; a number, nothing else), and the protein and calorie figure you accept, as part of the meal note. Those figures are backed up like any other health record and deleted with your account.
  • An estimate is not a measurement; you can correct every figure before saving, and what you write is what is saved.

9. Reminders

Injection, hydration and weigh-in reminders are scheduled on your phone and fire on your phone. We do not use remote (push) notifications, so we hold no notification token for you, and your reminder times are never sent to a server in order to be delivered.

10. PDF and CSV exports

The doctor summary (PDF) and the data export (CSV) are generated on your device and never pass through our servers. The file goes only where you send it.

11. Who your data is shared with

We do not sell your data and we do not share it with anyone for marketing. We use three service providers, each processing data on our behalf and only for its own job.

Supabase

Authentication and database infrastructure. When you create an account, your email address, your name, your health records and the side-effect reports you share are held in a PostgreSQL database managed by Supabase and hosted in the European Union (Frankfurt, eu-central-1). Supabase processes this data solely to provide the service.

So we can see where the app is hard to get through, we record short, fixed event names against your account, such as onboarding_reached_dose or injection_logged. The name, the time it happened and the app version are all that is stored. What is never stored: your dose, your weight, your symptoms, your notes, your blood glucose, or any text you typed yourself. If you use Haftra without an account, no events are recorded at all. Deleting your account deletes them too.

We may have to disclose data where legally compelled, for example a court order. If such a request arrives we will inform you, unless the law forbids it.

Google (Gemini API)

Only for the meal-photo estimate, and only when you scan a photo. The one thing Google receives is the downscaled copy of the photo; not your identity, your email, your account or any other record. Details in section 8.

RevenueCat (subscription status)

Haftra+ purchases are handled by Apple's and Google's stores; RevenueCat keeps track of which of your devices the subscription is valid on. It receives your account identifier and the purchase receipt issued by the store; not your health records, your name or your email. When you request a photo estimate, your subscription is verified server-side against this record.

Meta (advertising measurement)

If you installed the app after seeing an Instagram or Facebook ad, the fact that the install happened is reported to Meta, so we can tell whether the ad worked. It goes through Apple's SKAdNetwork, in aggregate.

What is not sent: your advertising identifier (IDFA), your health records, your weight, your dose, your symptoms, your purchases, and when or how long you use the app. Meta's automatic event logging is switched off; the install itself is the only signal that leaves.

Because we do not read the advertising identifier, the app never asks you for tracking permission. That is why you have never seen Apple's tracking prompt in Haftra.

Beyond that, no crash-reporting, tracking or third-party analytics service is used.

12. Retention and deletion

  • Without an account your records live only on your device, so removing the app deletes them.
  • With an account, Settings › Permanently delete account removes your account, your email, your name, every backed-up health record, the meal-scan counter and every community report from the database.
  • This is irreversible, requires no approval from us, and takes effect immediately.
  • If you leave your account in place, your records are retained until you delete them.

13. Exercising your rights

Depending on where you live, you may have rights under the GDPR and Turkey's Law No. 6698 (KVKK) to access, correct, delete, restrict the processing of, and port your data. For access and deletion the app itself is the fastest route. For anything else, write to destek@haftra.app.

14. Children

Haftra is intended for tracking a prescribed treatment and is not designed for users under 18. We do not knowingly collect data from anyone under 18.

15. Changes to this policy

If we update this policy we will change the date on this page, and we will notify you in the app for any significant change. You can request the previous version from the support address.

16. Contact

For anything privacy-related: destek@haftra.app

Medical notice. Haftra is not a medical device. It does not diagnose, treat or recommend any dose, and it does not replace a healthcare professional.

© 2026 Haftra. All rights reserved.

Made by yigitech.dev.

Back to home