LEGAL

Privacy Policy

Last Updated: July 22, 2026

1. OVERVIEW & LEGAL OPERATOR

Lutro ("LUTRO", "we", "us", or "our") is operated by Nafiz Atilla Okan, an individual developer based in Türkiye.

We process personal data to provide the Lutro mobile application, deliver subscriptions, operate the Exhibition gallery, secure the service, and maintain reliability. This Privacy Policy explains our practices under applicable law, including the GDPR and the Turkish Personal Data Protection Law (KVKK).

Contact: contact@lutro.app

2. PHOTO ACCESS & LOCAL PROCESSING

All photo editing operations are performed on-device. Lutro accesses only the photos selected by the user. Original full-resolution photos are not uploaded. Only content explicitly submitted to Exhibition is uploaded as reduced-size previews and edit recipes.

Only Exhibition posts that have received manual admin approval are published and viewable in the public community gallery.

3. DATA CATEGORIES WE PROCESS

We process the following categories of data in accordance with our Apple Privacy declarations:

  • Name and Email Address: Collected during Apple Sign-In or Google Sign-In.
  • User ID and Device/App Installation ID: Used for authentication and notification routing.
  • APNs/FCM token: Used to deliver functional push notifications.
  • Purchase History and Product Interaction: Processed through Apple App Store billing and RevenueCat. Purchase and entitlement records may be retained by Apple and RevenueCat according to their service, security, fraud-prevention and applicable record-retention requirements. Lutro does not collect payment card information.
  • Crash & Diagnostic Data (Consent-Gated): Processed via Firebase Crashlytics to improve reliability.
  • Approximate Location (Consent-Gated): When Firebase Analytics is enabled, approximate country or region information may be derived from network information. Lutro does not request GPS access or collect precise location.
  • Exhibition Photos/Videos, Edit Recipes and Moderation Content: Submitted voluntarily by the user to the public gallery, along with report/block records (report and block records are private moderation data processed strictly for community safety and moderation).

4. SEPARATION OF DATA STREAMS

We strictly distinguish functional data streams from optional analytics streams:

  • Push Notification Stream (Functional): Firebase Messaging tokens, APNs device tokens, and basic device environment metadata (OS version, language, time zone) are processed solely for the functional purpose of delivering app notifications. This processing operates independently of optional marketing analytics consent.
  • Analytics & Crashlytics Stream (Optional): Collection for Firebase Analytics and Firebase Crashlytics is disabled by default at app startup. Collection is activated only upon explicit consent during onboarding/login. You can toggle this consent anytime under Settings → Privacy → Share Analytics. When disabled, no new event or crash diagnostic data is transmitted to Firebase.

5. WHY WE PROCESS DATA

Data is processed to authenticate users, manage digital purchases, operate the public Exhibition feed, enforce Community Guidelines (moderation, report, and block functions), deliver push notifications, and—where consented—improve reliability and measure feature usage.

Lutro does not engage in cross-app tracking, does not sell personal data, and does not use personal data for third-party targeted advertising.

6. EXHIBITION MODERATION, REPORT & BLOCK DATA

To fulfill Apple App Store Guideline 1.2 requirements for User Generated Content:

  • Pre-Publication Review: Every submission is routed to our admin moderation panel and requires manual admin approval before public display. Apple Sensitive Content Analysis may run on-device when permitted by device policy. Regardless of whether on-device analysis runs or its outcome, every submission is sent to admin moderation for manual review. Only manually approved posts are public.
  • Reports: Both Guest and Authenticated users can report offensive posts. Submitting a report sends a moderation payload (private moderation data) to CloudKit for administrative review. Reported posts remain visible pending review unless removed by an admin decision.
  • Blocks: Both Guest and Authenticated users can block authors. Blocking an author immediately hides all of their posts on the blocking user's device without globally removing content for other users. Block lists are stored locally on the device and may sync via iCloud KVS for guests when enabled; signed-in user block lists are tied to the account hash.

7. SHARING & SERVICE PROVIDERS

Personal data is shared only with essential infrastructure providers needed to operate the service:

  • Apple Infrastructure: App Store billing, CloudKit gallery storage, APNs notification delivery, and Sign in with Apple.
  • Google / Firebase Infrastructure: Google Sign-In, Firebase Auth, Firebase Messaging, Firebase Analytics (consent-gated), and Firebase Crashlytics (consent-gated).
  • RevenueCat: Subscription entitlement verification and purchase receipt validation.
  • Revocation Backend: A limited, dedicated backend service used strictly to complete Sign in with Apple authorization token revocations upon account deletion.

Any third-party service provider we list or engage is contractually obligated to provide the same or equal protection of user data as stated in this policy.

8. DATA RETENTION & PURGE SCHEDULES

Data is retained only as long as necessary for functional, legal, and security requirements:

  • Exhibition Posts: Published Exhibition posts active in the primary public feed expire after a default window of 24 hours. Curated featured showcase posts may remain visible for longer periods.
  • Analytics & Crash Diagnostics: Retained in accordance with default Firebase/GA4 project retention settings (Crashlytics logs up to 90 days; Analytics subject to configured property retention controls).
  • Moderation & Report Records: Retained for safety, audit trails, and legal compliance.
  • Block Lists: Maintained on-device or in account state until unblocked or reset by the user.
  • Service Provider Backups: Infrastructure provider technical backups (Apple CloudKit, Firebase) follow their standard technical purge cycles.

9. ACCOUNT DELETION & DATA RESET

Authenticated users can initiate account deletion inside the app under Settings → Account → Delete Account.

Account deletion initiates a multi-step sequence: user reauthentication → Apple/Google provider unlink → purge of CloudKit Exhibition submissions → deletion of the Firebase Auth user record → RevenueCat session logout and transition to a new anonymous App User ID → local keychain and session clearance. The deletion process starts immediately. Active user records and Exhibition posts are deleted; however, limited technical backups may be subject to the retention schedules of our infrastructure providers (Apple and Google). Please note that deleting your account does not automatically cancel your active Apple subscriptions.

Guest users have no server-side Lutro account. Guest users can clear their local and iCloud-synced block list in Settings under Clear Blocked Users without impacting purchase receipts or entitlements.

10. YOUR RIGHTS & KVKK DISCLOSURES

Depending on your location, you may have rights under GDPR, KVKK, or local privacy laws to access, correct, delete, or restrict processing of your data, or withdraw consent.

Users in Türkiye may exercise rights specified in Article 11 of the KVKK (Law No. 6698) by contacting contact@lutro.app.

Contact: contact@lutro.app