Neyim Kaldı

Privacy policy

Last updated: 7 October 2026

Developer: Abdullah Ak Contact: destek@neyimkaldi.com

Neyim Kaldı is an Android app for keeping track of the groceries and household items you have at home, their expiry dates and your shopping list. You don't need an account. The app has no server of its own, and your records are never sent to the developer.

Your records stay on your phone. Some features, however, send data off the phone while they run: adding items by photo, the chat, recipes, online orders, barcodes and exchange rates. Below we list what is stored where and what is sent where.

This is a translation of the Turkish policy. If the two differ, the Turkish text applies.

Stored on your phone

Data Where How it is protected
Items, purchases, expiry dates, shopping list, stock changes, prices, store names, rooms, online order records The app's database Encrypted with SQLCipher. Its password is generated randomly and stored encrypted with a key in the Android Keystore.
Item photos The app's own folder, as downsized JPEGs Not encrypted like the database. They live in Android's app-private storage, which other apps cannot read.
Product images of orders waiting for your approval The app's own folder, temporary If you approve the order they become item photos, if you dismiss it they are deleted. Unapproved ones are deleted after 60 days at the latest.
A photo you have just taken with the camera The app's cache, temporary Other apps cannot read it.
Settings, daily AI counter, exchange rate table The app's settings files Other apps cannot read them.
The e-mail address and IMAP server you connect The app's settings file Other apps cannot read it.
Your e-mail app password The app's settings file Encrypted with AES-256-GCM using a separate key in the Android Keystore.
Chat and recipe results In memory, only while the app is open Not saved. They are gone when the app closes.

Keystore keys cannot be exported from the app and are kept in hardware on phones that support it. So even if the database file is copied to another phone, it cannot be opened there.

Android's automatic backup is turned off for this app. Your records are not included in Google Drive backups and are not transferred when you switch phones. The way to move your records is the app's own backup (see "Backups" below).

What leaves your phone

Google Gemini (AI)

When you use the features below, the request goes to Google's Gemini API over HTTPS. The result comes back to the phone and never reaches the developer.

Feature Data sent
Add by photo The photo of the items and the names of items already saved at home (up to 200)
Add by receipt The photo of the receipt and saved item names
Household item photo The photo of a room, wardrobe or shelf, the household item categories and saved item names
Expiry date reading The photo of the package
Adding by voice or text The text you said or typed ("3 milk, 2 bread") and saved item names. No audio recording is sent, see below.
Recipe suggestions and weekly menu Names and quantities of the food at home (up to 80)
"What do I have at home?" chat Your question, the last 6 questions and answers in the same session, a summary of the items at home (name, quantity, category, room, place in the room, expiry date, warranty end, estimated days left) and the shopping list
Online orders, e-mail route The text of the order e-mail, the sender's name and domain, subject and date. If there is an e-Arşiv XML invoice: the item lines, seller name, invoice and order number and date (buyer details are not sent). If there is no XML invoice, up to two PDF attachments as they are. Saved item names.
Online orders, screen reading route The text of the order screen in the grocery app and saved item names. No screenshot is sent.
Online orders, share route The screenshots you share or select (as they are), the invoice PDF (as it is), text and saved item names. To locate the product images in the screenshots, the same images may be sent again in a second request.

Photos are downsized and re-saved before they are sent. EXIF data such as location is dropped from the file in the process.

Hiding personal information. E-mail text, screen reading text and shared text are scanned on the phone before they go to Gemini. E-mail addresses, phone numbers, IBANs, card numbers, Turkish ID and tax numbers, links, name lines such as "Sayın ..." or "Alıcı:", and address blocks are removed. The scan uses patterns and may not catch every format. Nothing is hidden in the screenshots and PDFs you share. If your name and address appear in an image or invoice, they are sent too.

Technical information sent with each request. Each request includes the app's package name and the fingerprint of its signing certificate. Google checks these so that the API key can only be used from this app. No account, advertising ID or device ID is sent. Google receives the request from your phone's IP address.

What Google does with this data. The content sent is subject to Google's Gemini API terms and privacy policy. The app uses the free tier of the Gemini API. On this tier Google may use the content and responses to improve its own products, and the content may be read by human reviewers.

There is a daily limit on AI requests: 10 for your own requests and 20 for reading online orders. The counter is kept on the phone.

Speech recognition

The microphone button opens Android's voice input. Your speech is turned into text by the speech recognition service on your phone (Google on most phones). Neyim Kaldı does not record audio and does not ask for the microphone permission. Only the resulting text reaches the app, and that text goes to Gemini as described above. How the speech recognition service handles your voice depends on that service's terms.

Barcodes: Open Food Facts

The barcode is read from the photo on the phone (Google ML Kit, see below). Then only the barcode number is sent to Open Food Facts, which returns the product's name and brand. The request also includes the app's name. Nothing else is sent.

Exchange rates: frankfurter.dev

If you want to see the price chart on the item details in Euro or Dollar, the rates for missing days are fetched from frankfurter.dev (European Central Bank reference rates). The request contains only the date range and currency codes. Fetched rates are stored on the phone, after which only missing days are requested.

Grocery image servers

Product images in order e-mails are downloaded only from these domains and their subdomains, over HTTPS and up to 2 MB: migros.com.tr, migrosone.com, getir.com, getirapi.com, trendyol.com, trendyolgo.com, dsmcdn.com. Images on other servers are not downloaded and redirects are not followed. While downloading, that server sees your phone's IP address.

Your e-mail server (IMAP)

If you connect your e-mail for online orders:

Google ML Kit

Barcode reading runs on the phone, and photos do not leave the phone because of ML Kit. According to Google, the ML Kit library may send diagnostic and usage information about its own operation (such as phone model, Android version, app version, API usage and performance) to Google.

What you share

When you share the shopping list, it goes to the app you pick (for example WhatsApp). Where you save a backup file is also your choice (see below).

Screen reading (accessibility service)

Screen reading is one way of bringing in online orders. It is off by default. Before you turn it on, the app shows a notice explaining what is read and where it goes. Even if the service is turned on directly from Android settings, it reads no screen until you accept this notice in the app.

Permissions

Permission Why
Internet (INTERNET) Gemini, Open Food Facts, exchange rates, grocery images and the e-mail connection
Notifications (POST_NOTIFICATIONS) Running low, expiry date, budget, warranty and order notifications. Notifications are created on the phone.
Biometrics (USE_BIOMETRIC) If you want, the app asks for your fingerprint or screen lock when it opens. Fingerprint and face data never reach the app, Android does the check.
Binding to the accessibility service (BIND_ACCESSIBILITY_SERVICE) Only so that Android can bind to the screen reading service. You turn the service on yourself.

The app does not ask for camera, microphone, location, contacts or file permissions. Photos are taken with the phone's own camera app, and photos are picked with Android's picker.

Ads and analytics

There are no ad, analytics or crash reporting libraries in the app. No usage information is collected. Apart from the ML Kit exception described above, no library sends data on its own.

Backups

Security

Retention and deletion

Children

The app is not directed at children.

Changes

If this policy changes, the current version is published at the same address and the date at the top changes.

Contact

For questions or requests: destek@neyimkaldi.com