Privacy policy
Last updated: 7 October 2026
Developer: Abdullah Ak Contact: destek@neyimkaldi.com
Neyim Kaldı is an Android app for keeping track of the groceries and household items you have at home, their expiry dates and your shopping list. You don't need an account. The app has no server of its own, and your records are never sent to the developer.
Your records stay on your phone. Some features, however, send data off the phone while they run: adding items by photo, the chat, recipes, online orders, barcodes and exchange rates. Below we list what is stored where and what is sent where.
This is a translation of the Turkish policy. If the two differ, the Turkish text applies.
Stored on your phone
| Data | Where | How it is protected |
|---|---|---|
| Items, purchases, expiry dates, shopping list, stock changes, prices, store names, rooms, online order records | The app's database | Encrypted with SQLCipher. Its password is generated randomly and stored encrypted with a key in the Android Keystore. |
| Item photos | The app's own folder, as downsized JPEGs | Not encrypted like the database. They live in Android's app-private storage, which other apps cannot read. |
| Product images of orders waiting for your approval | The app's own folder, temporary | If you approve the order they become item photos, if you dismiss it they are deleted. Unapproved ones are deleted after 60 days at the latest. |
| A photo you have just taken with the camera | The app's cache, temporary | Other apps cannot read it. |
| Settings, daily AI counter, exchange rate table | The app's settings files | Other apps cannot read them. |
| The e-mail address and IMAP server you connect | The app's settings file | Other apps cannot read it. |
| Your e-mail app password | The app's settings file | Encrypted with AES-256-GCM using a separate key in the Android Keystore. |
| Chat and recipe results | In memory, only while the app is open | Not saved. They are gone when the app closes. |
Keystore keys cannot be exported from the app and are kept in hardware on phones that support it. So even if the database file is copied to another phone, it cannot be opened there.
Android's automatic backup is turned off for this app. Your records are not included in Google Drive backups and are not transferred when you switch phones. The way to move your records is the app's own backup (see "Backups" below).
What leaves your phone
Google Gemini (AI)
When you use the features below, the request goes to Google's Gemini API over HTTPS. The result comes back to the phone and never reaches the developer.
| Feature | Data sent |
|---|---|
| Add by photo | The photo of the items and the names of items already saved at home (up to 200) |
| Add by receipt | The photo of the receipt and saved item names |
| Household item photo | The photo of a room, wardrobe or shelf, the household item categories and saved item names |
| Expiry date reading | The photo of the package |
| Adding by voice or text | The text you said or typed ("3 milk, 2 bread") and saved item names. No audio recording is sent, see below. |
| Recipe suggestions and weekly menu | Names and quantities of the food at home (up to 80) |
| "What do I have at home?" chat | Your question, the last 6 questions and answers in the same session, a summary of the items at home (name, quantity, category, room, place in the room, expiry date, warranty end, estimated days left) and the shopping list |
| Online orders, e-mail route | The text of the order e-mail, the sender's name and domain, subject and date. If there is an e-Arşiv XML invoice: the item lines, seller name, invoice and order number and date (buyer details are not sent). If there is no XML invoice, up to two PDF attachments as they are. Saved item names. |
| Online orders, screen reading route | The text of the order screen in the grocery app and saved item names. No screenshot is sent. |
| Online orders, share route | The screenshots you share or select (as they are), the invoice PDF (as it is), text and saved item names. To locate the product images in the screenshots, the same images may be sent again in a second request. |
Photos are downsized and re-saved before they are sent. EXIF data such as location is dropped from the file in the process.
Hiding personal information. E-mail text, screen reading text and shared text are scanned on the phone before they go to Gemini. E-mail addresses, phone numbers, IBANs, card numbers, Turkish ID and tax numbers, links, name lines such as "Sayın ..." or "Alıcı:", and address blocks are removed. The scan uses patterns and may not catch every format. Nothing is hidden in the screenshots and PDFs you share. If your name and address appear in an image or invoice, they are sent too.
Technical information sent with each request. Each request includes the app's package name and the fingerprint of its signing certificate. Google checks these so that the API key can only be used from this app. No account, advertising ID or device ID is sent. Google receives the request from your phone's IP address.
What Google does with this data. The content sent is subject to Google's Gemini API terms and privacy policy. The app uses the free tier of the Gemini API. On this tier Google may use the content and responses to improve its own products, and the content may be read by human reviewers.
There is a daily limit on AI requests: 10 for your own requests and 20 for reading online orders. The counter is kept on the phone.
Speech recognition
The microphone button opens Android's voice input. Your speech is turned into text by the speech recognition service on your phone (Google on most phones). Neyim Kaldı does not record audio and does not ask for the microphone permission. Only the resulting text reaches the app, and that text goes to Gemini as described above. How the speech recognition service handles your voice depends on that service's terms.
Barcodes: Open Food Facts
The barcode is read from the photo on the phone (Google ML Kit, see below). Then only the barcode number is sent to Open Food Facts, which returns the product's name and brand. The request also includes the app's name. Nothing else is sent.
Exchange rates: frankfurter.dev
If you want to see the price chart on the item details in Euro or Dollar, the rates for missing days are fetched from frankfurter.dev (European Central Bank reference rates). The request contains only the date range and currency codes. Fetched rates are stored on the phone, after which only missing days are requested.
Grocery image servers
Product images in order e-mails are downloaded only from these domains and their subdomains, over HTTPS and up to 2 MB: migros.com.tr, migrosone.com, getir.com, getirapi.com, trendyol.com, trendyolgo.com, dsmcdn.com. Images on other servers are not downloaded and redirects are not followed. While downloading, that server sees your phone's IP address.
Your e-mail server (IMAP)
If you connect your e-mail for online orders:
- Your address, app password and IMAP server are used only to connect to your own e-mail provider. The connection is encrypted (IMAPS, port 993) and the server's identity is verified.
- The app searches for e-mails with Migros, Getir or Trendyol in the sender or subject. Those whose subject looks like an order or invoice e-mail are downloaded (up to 15 MB). The content of other e-mails is not downloaded.
- The first time, the last 7 days are scanned, after that only new mail. Scanning happens every 3 hours and when you open the app (if 30 minutes have passed since the last check).
- The mailbox is only read. E-mails are not marked as read and nothing is deleted or sent.
- The "Remove" button on the online orders screen deletes your address, server and password from the phone.
Google ML Kit
Barcode reading runs on the phone, and photos do not leave the phone because of ML Kit. According to Google, the ML Kit library may send diagnostic and usage information about its own operation (such as phone model, Android version, app version, API usage and performance) to Google.
What you share
When you share the shopping list, it goes to the app you pick (for example WhatsApp). Where you save a backup file is also your choice (see below).
Screen reading (accessibility service)
Screen reading is one way of bringing in online orders. It is off by default. Before you turn it on, the app shows a notice explaining what is read and where it goes. Even if the service is turned on directly from Android settings, it reads no screen until you accept this notice in the app.
- Android passes the service events only from these apps: Getir (com.getir), Migros (com.inomera.sm), Trendyol Go (com.trendyol.go) and Trendyol (trendyol.com). This list is fixed inside the app (res/xml/siparis_ekran_servisi.xml).
- While one of these apps is open, it reads the text on the screen. The text is kept only in memory.
- If the text does not look like an order detail, it goes nowhere and is dropped when you leave the screen. If it does, personal information is hidden as described above and the rest goes to Gemini. At most 8 requests are sent per hour.
- On Android 11 and later it takes a screenshot to get product images. The product images are cropped on the phone and saved to a temporary folder at up to 400 pixels. The screenshot itself is not saved and is not sent anywhere.
- It does not touch the screen, click, type or change other apps' settings.
- No screen text is written to the app's logs, only the type of result ("new order, 12 items"). In the release build these log lines are removed from the code as well.
- You can turn it off at any time in Settings → Accessibility.
Permissions
| Permission | Why |
|---|---|
| Internet (INTERNET) | Gemini, Open Food Facts, exchange rates, grocery images and the e-mail connection |
| Notifications (POST_NOTIFICATIONS) | Running low, expiry date, budget, warranty and order notifications. Notifications are created on the phone. |
| Biometrics (USE_BIOMETRIC) | If you want, the app asks for your fingerprint or screen lock when it opens. Fingerprint and face data never reach the app, Android does the check. |
| Binding to the accessibility service (BIND_ACCESSIBILITY_SERVICE) | Only so that Android can bind to the screen reading service. You turn the service on yourself. |
The app does not ask for camera, microphone, location, contacts or file permissions. Photos are taken with the phone's own camera app, and photos are picked with Android's picker.
Ads and analytics
There are no ad, analytics or crash reporting libraries in the app. No usage information is collected. Apart from the ML Kit exception described above, no library sends data on its own.
Backups
- With Report → Backup you save all your records (items, purchases, shopping list, stock changes, prices, rooms, online order records and item photos) to a single ZIP file. You choose where to save it (Downloads, Google Drive, SD card and so on).
- You can put a password on a manual backup. A password-protected backup is encrypted with AES-256-GCM. A backup without a password can be opened by anyone who finds the file.
- If you turn on automatic backup, a backup is written to the folder you chose every week and the last 4 are kept. Automatic backups have no password.
- If the folder you chose is a cloud folder, the backup goes to that service under your own account.
- Your e-mail address and app password are not included in backups.
Security
- The app never uses unencrypted (HTTP) connections. All connections are HTTPS or IMAPS.
- The database is encrypted with SQLCipher, and its password and your e-mail password are protected with Android Keystore keys.
- If you want, you can turn on the app lock and the screenshot block in Settings → Security.
Retention and deletion
- The records on your phone stay until you delete them. You can delete items, purchases and rooms one by one in the app.
- Records in the online order history cannot be deleted one by one in the app. Traces kept for repeated content or content that is not an order are deleted automatically after 90 days.
- If you uninstall the app, or choose Neyim Kaldı → Storage → Clear data in Android settings, the database, photos, settings and your e-mail details are deleted from the phone. You need to delete backups saved elsewhere yourself.
- The developer cannot delete data sent to Gemini, Open Food Facts or the exchange rate service, because it never reaches the developer. That data is kept according to the terms of the service concerned.
Children
The app is not directed at children.
Changes
If this policy changes, the current version is published at the same address and the date at the top changes.
Contact
For questions or requests: destek@neyimkaldi.com