Privacy Policy
Last updated 11 August 2026
The short version
This summary is here to be read. The sections below are the binding detail.
- There is no sign-up. We never ask for your name, your email or your date of birth. The App creates a random anonymous account for you, and that is who you are to us.
- The photos you scan are uploaded to our servers and passed to AI models run by other companies, which is how the App identifies an item and estimates its value. Keep people and personal information out of your photos.
- Sharing a find makes it public.If you share a scan with the community, its photo, identification and estimated value are visible to other users, and your display name can appear on leaderboards. Scans you don’t share stay in your own collection.
- We measure how the App is used and bought — scans, onboarding, subscription events — to improve it.
- The App shows no ads. We do measure which of our ads brought people in. iOS asks your permission first, and you can say no.
- We do not sell your data.
- You can ask us to delete your data. Email hello@aiapps.games.
1. Who we are
AI Apps Yazılım Hizmetleri ve Reklam Faaliyetleri Anonim Şirketi (“AI Apps & Games”, “we”, “us”), a company registered in Türkiye, is the data controller for the personal data described here. This policy covers the mobile app Deckard (the “App”). It does not cover our other apps, or any third-party service you reach from the App.
Contact us about privacy at hello@aiapps.games.
2. There is no sign-up, and what that means
The App has no registration form and no login screen. The first time you use it, an anonymous account is created for you automatically: a random identifier with no name, email or phone number attached, plus a credential stored securely on your device. It is not derived from your identity and tells us nothing about who you are.
We use it to keep one person’s scans, collection, shared finds and analytics together. Because it is persistent and tied to you, we treat it as personal data and give it the protections described here.
The credential lives on your device: if you delete the App, erase your device or move to a new one, it may be lost, and we may then have no way to connect you to your old account — which also means its data is no longer identifiable to us as yours.
3. What we collect
We collect the following, and nothing else. We do not collect your name, email address (unless you put it in a support message), postal address, phone number, date of birth, precise location, contacts, health data, or payment card details.
a. Data you give us
- Photos you scan — the pictures you take with the camera, or choose from your photo library, to have an item identified and valued. They are uploaded to our servers for analysis. The App asks for camera or photo library permission only for this, and never touches either otherwise. Photograph the item, not people — anything in the frame is uploaded.
- Display name — a collector name shown with your shared finds and on leaderboards. The App generates a neutral one for you; if you change it, do not put personal information in it.
- Community activity— finds you choose to share, and likes and bookmarks you place on other people’s finds.
- Support messages— if you contact us through the App’s support option: what you write, your account identifier, and diagnostic details about your device and app version, plus anything you choose to attach. Anything you volunteer in the text — including your email address — we also receive.
b. Data the App generates as you use it
- Identifiers — your anonymous account identifier; device identifiers provided by iOS (the vendor identifier, and the advertising identifier only if you allow tracking, see section 6).
- Scan results — what the AI identified in each photo: item name, product line, year, variant, category, estimated value range, rarity and condition reads, and the running totals of your collection.
- Product interaction — events such as app opened, onboarding steps, scan started and completed, paywall viewed, trial started, subscription events, shares, likes and badge progress.
- Purchase history — your subscription status and whether a purchase succeeded, was cancelled or failed. Apple processes the payment; we see the outcome, never your card.
- Device and diagnostics — device model, operating system version, app version, language and region, plus crash reports, performance data and error logs.
4. Why we use it, and our legal basis
For users in the EEA, the UK and Türkiye, the table below states the legal basis we rely on under the GDPR and, in Türkiye, the KVKK.
| What we do | Data used | Legal basis |
|---|---|---|
| Identify and value your items, and keep your collection | Photos, scan results, account identifier | Performance of our contract with you (the Terms of Use) |
| Run the community feed and leaderboards | Shared finds, display name, likes, bookmarks, badge progress | Performance of our contract — you choose what to share |
| Moderate shared content | The shared find itself | Our legitimate interest in keeping the community feed free of abusive or unlawful content, and complying with app store rules |
| Manage your subscription and deliver what you bought | Account identifier, purchase history | Performance of our contract |
| Answer support requests | Message, attachments, account identifier, device diagnostics | Performance of our contract; our legitimate interest in helping users |
| Fix crashes and improve performance | Crash reports, performance and diagnostic data | Our legitimate interest in an app that works |
| Analyse and improve the App | Account identifier, product interaction, purchase events | Our legitimate interest in understanding how the App is used and improving it |
| Prevent abuse and keep the service working | Account identifier, usage data, rate-limit counters | Our legitimate interest in secure, fairly shared services |
| Measure our advertising across other apps and sites | Advertising identifier, account identifier, install and purchase events | Your consent, given through the iOS tracking prompt. Withdraw it at any time (section 6) |
| Meet legal, tax and accounting duties, and handle disputes | Transaction records, correspondence | Compliance with a legal obligation; establishing or defending legal claims |
Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override them — largely because the data is tied to a random identifier rather than to your identity. You can object at any time (section 10).
We do not use your data to make decisions about you with legal or similarly significant effects, and we do not build advertising profiles about you. The automated judgements the App makes are about your items — what a toy is and what it might be worth — and about whether shared content is allowed in the community feed.
5. Your photos, and the AI that reads them
Scanning is the App’s core feature, so it deserves its own section.
- When you scan an item, the photo is uploaded to our servers (hosted on Supabase) and passed to a third-party AI model reached through OpenRouter, a service that routes requests to model providers. The model returns the identification and value estimate you see.
- OpenRouter and the model provider handle the photo under their own terms and retention rules, which we do not control. We send the photo and the scan request — not your device identifiers and not anything else about you.
- Photos and scan results are stored with your account so your collection persists. Scans you do not share are not shown to other users.
- What is in the frame gets uploaded. Photograph items, not people or documents. If a photo containing something personal ends up on our servers, email us and we will delete it.
6. Tracking, advertising and the iOS prompt
The App contains no advertising. We show you no ads and we sell no ad space. But we do advertise the App elsewhere — including on Meta and Google platforms — and we measure whether those ads work; otherwise we cannot tell where to spend.
For that measurement, iOS shows you the App Tracking Transparency prompt. Your answer is entirely up to you and the App works identically either way:
- If you allow it, the App may access your device advertising identifier (IDFA) and share it, with install and purchase events, with our attribution and advertising partners, so that a subscription can be linked to the ad that brought you in.
- If you decline, the advertising identifier is not accessed and no cross-app tracking takes place. We still receive privacy-preserving install reports from Apple’s SKAdNetworkand Apple’s own attribution service, which are aggregated by Apple and do not identify you or your device.
You can change your mind at any time in iOS Settings → Privacy & Security → Tracking, which withdraws or grants that consent for the App. Turning off Allow Apps to Request to Track declines it for every app.
7. Who we share it with
We do not sell your personal data, and we do not share it with anyone to advertise their own products to you. We use the following providers to run the App. Each gets only what it needs and is bound to use it only for us.
| Provider | What for | What it receives |
|---|---|---|
| Apple | App Store distribution, payments, install attribution | Your purchases and payment details (as data controller, under Apple’s own policy); aggregated SKAdNetwork reports |
| Supabase | Hosting our database, photo storage, accounts and server code | Account identifier, photos, scan results, collection, display name, community activity |
| OpenRouter and the AI model providers it routes to | Identifying and valuing scanned items (section 5) | The photo and scan request only — nothing that identifies you |
| RevenueCat | Managing and validating the subscription | Account identifier, device identifiers, purchase events; the advertising identifier only if you allowed tracking |
| Mixpanel | Product analytics — how the App is used | Account identifier, device identifiers, product interaction and purchase events |
| Luciq (formerly Instabug) | Support messages, bug reports, crash reporting | Your message and any attachments, account identifier, device and diagnostic data |
| Meta and Google | Measuring our own ad campaigns — only with your tracking consent (section 6) | Advertising identifier, install and purchase events; otherwise only aggregated, privacy-preserving reports |
We may also disclose personal data:
- where we are legally required to, or to respond to a valid request from a public authority — we check that requests are lawful and proportionate before complying;
- to establish, exercise or defend legal claims, or to enforce our Terms of Use;
- to protect the rights, safety or property of users, the public or us — for example when investigating abuse;
- to a buyer or successor if we are involved in a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.
8. International transfers
We are based in Türkiye and our providers operate internationally, including in the United States. Using the App therefore involves transferring your data outside your own country, including outside the EEA, the UK and Türkiye, to countries whose data protection laws may differ from your own.
Where we transfer data out of the EEA or the UK, we rely on appropriate safeguards — normally the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), or an adequacy decision where one applies. For transfers from Türkiye we rely on the mechanisms permitted by the KVKK, including your explicit consent or an approved undertaking where required. Write to hello@aiapps.games for details of the safeguards that apply to a particular transfer.
9. How long we keep it
| Data | Kept for |
|---|---|
| Photos, scan results and your collection | For as long as your account exists, or until you ask us to delete them |
| Shared finds, display name, community activity | For as long as we run the community features, or until you unshare them or ask us to delete them |
| Analytics and product interaction events | For as long as they are useful for improving the App, reviewed periodically and deleted when they are not |
| Crash and diagnostic data | Until the issue is resolved and no longer useful |
| Support messages | While we handle your request and for a reasonable period after, in case you write again |
| Purchase and transaction records | As long as tax, accounting and consumer law require — in Türkiye normally ten years |
10. Your rights, and how to use them
Depending on where you live, you have some or all of these rights: access a copy of your data; rectify it if it is wrong; erase it; restrict or object to how we use it, including profiling and direct marketing; portability; withdraw consent at any time without affecting what we did before; and complain to a regulator.
How to make a request
Email hello@aiapps.games, or write to us through the support option in the App’s settings — a message sent from inside the App carries your account identifier with it, which is the surest way for us to find your records. We will respond within the time the law allows — one month under the GDPR, thirty days under the KVKK — and we may extend that where a request is complex, telling you why.
An honest limitation. Because the App has no login, your anonymous account is the only key we hold. We can only act on a request where we can reasonably satisfy ourselves the account is yours — most easily, a request made from the device that holds it. If you have already deleted the App and its credential is gone, we may have no way to find your records or connect them to you — which is also the reason they are not readily identifiable to us in the first place.
Deleting your data
- On our servers: contact us as above and we will delete your account, photos, scans, collection, shared finds and analytics records, and instruct our providers to do the same. We will keep what the law requires us to keep — transaction records for tax, for example — and may keep a minimal record that you asked, so that the request is honoured.
- On your device: deleting the App removes it and its local data from your device, but does not by itself delete the data already on our servers, and does not cancel an active subscription — cancel that in your Apple Account settings.
Complaints
Please raise it with us first — hello@aiapps.games — and we will try to fix it. You can also complain to your supervisory authority: in Türkiye, the Personal Data Protection Authority (KVKK, kvkk.gov.tr); in the EEA, the data protection authority where you live, work, or where the issue arose; in the UK, the Information Commissioner’s Office (ICO).
11. If you live in California or another US state
Over the past twelve months we have collected the categories of personal information described in section 3: identifiers (account, device and advertising identifiers), commercial information (subscription purchases), internet or other electronic network activity (product interaction events, diagnostics), and audio, electronic or visual information (the photos you scan, and anything you attach to a support message). We collect it from you and from your device, for the purposes in section 4, and disclose it to the providers in section 7.
We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. Sharing your advertising identifier with our attribution partners so we can measure our own campaigns may count as “sharing” for cross-context behavioural advertising under California law. Declining the iOS tracking prompt opts you out of that entirely — that is the opt-out mechanism, and it is offered to every user up front. You can also change it later in iOS Settings → Privacy & Security → Tracking.
You have the right to know, delete, and correct your personal information, to opt out of sharing, and not to be discriminated against for exercising those rights — the App works exactly the same either way. Exercise them via hello@aiapps.games. An authorised agent may act for you with written proof.
12. Children
The App is a paid, subscription-based product for collectors. It is not directed to children, and we do not knowingly collect personal data from anyone under 13 — or under the higher digital age of consent that applies where you live, up to 16 in parts of the EEA.
We do not ask for age or identity, so we cannot detect a child by their data alone. If you are a parent or guardian and believe your child has provided us with personal data, email hello@aiapps.games— ideally from the device the child used, via the support option in the App’s settings — and we will delete it promptly.
13. Security
We take reasonable technical and organisational measures to protect your data: transport encryption to our servers and providers, per-user access rules on our database so one user cannot read another’s private scans, rate limits on our server functions, restricted access to production systems, and reputable providers with their own security programmes.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant authority and affected users as the law requires.
14. Changes to this policy
We will update this policy when the App or the law changes. The current version always lives at this address, dated at the top. If a change is material — a new purpose, a new category of data, a new recipient — we will take reasonable steps to tell you before it takes effect, and will ask for your consent where the law requires it.
15. Contact
AI Apps Yazılım Hizmetleri ve Reklam Faaliyetleri Anonim Şirketi
Privacy enquiries: hello@aiapps.games
In-app: the support option in the App’s settings