Controller and KVKK notice
The data controller is Operator details will be published here, at Operator details will be published here, tax number Operator details will be published here. Ascendia is the product name. Privacy rights and support requests go to support@ascendia.day. This notice describes collection methods, purposes, recipients, legal grounds and rights. The full policy is published on the website and linked from the app. KVKK Article 10.
We collect directly from sign-up fields, entries, uploads and feature use; from a connected calendar or health source after its permission flow; from store entitlement verification; and from device/API events. Ordinary account and requested-feature processing supports the service contract; proportionate security and diagnostics may rely on legitimate interests; records required by law rely on legal obligation. Health information users enter may be stored and used for requested chat, tracking and reminders, and users can delete it. Where GDPR Article 9 or KVKK Article 6 applies to a particular health route, we must have an applicable special-category condition; general acceptance of this policy is not itself explicit health consent. KVKK Law; GDPR Article 9.
Effective 27 September 2026. Ascendia is provided by Operator details will be published here, Operator details will be published here (“we”). Privacy questions and rights requests: support@ascendia.day. This policy describes personal data handled through the app and services. It should be read with the Terms, AI Disclosure and Subprocessors.
1. Data we collect
The categories below include information you provide, data generated when you use a feature, and data returned by a source you connect. Avoid entering unnecessary sensitive information in free text.
| Category | Examples and source | Why it is handled |
| Identity, account and age | Email, name, password verifier, language, time zone, birth year, derived age band, verification and session records. Sign-up asks for a date of birth for age assessment; we retain the year and derived age band. | Register, authenticate, secure and age-restrict the account; send strictly necessary account and security messages. |
| Planning and productivity | Calendar events and connections, tasks, activities, goals, habits/rhythms, location saved for weather-based suggestions, notes and Library sources. A configured weather provider may receive saved coordinates. | Provide requested planning, reminders, organization and recommendations. |
| Private ICS/webcal calendar subscription | A user-supplied private feed URL (which may itself grant access to the calendar), its hash and label, sync status and fetch validators; fetched VEVENT identifiers, titles, locations, start/end times, time zone and recurrence fields are mirrored as read-only busy bands. The service fetches the feed on connection, on request and on a schedule. The chosen feed host receives the request, including the URL and request metadata. | Show connected-calendar availability and support requested planning, reminders and slot suggestions. |
| Body, wellness and health information | Body profile, workouts, connected steps/sleep/activity, and health information users write in chat, tasks or notes, including period or medicine reminders. A connected health source asks for its OS permissions. | Provide requested tracking, planning, answers and reminders; users can delete entries. |
| Food and nutrition | Meals, food logs, scanned numeric barcodes, photographs of meals, estimated nutrition, preferences, allergies and calorie-target inputs. Requested barcode lookup sends the code from the server to Open Food Facts and caches a product response. | Provide Kcal features and food-safety responses; the image estimate is uncertain. |
| Money | User-maintained account names, currencies, balances, transactions, bills, payment records and imported CSV data. The account record does not store banking credentials. | Display Money and calculate planning views. |
| AI interaction and memory | Prompts, chat history, model responses, agent actions, retrieved context, derived memories, feedback, briefings and usage records. | Answer requests, draft work, retrieve useful context, let you review/correct/forget memory and meter AI work. |
| Together and user content | Invites and pair links, profile/avatar image, posts, shared goals/boards, cheers, reactions, blocks and reports. Affiliate attribution can join a user ID to a referring partner; the partner can see a stable pseudonym, join date, plan type, status and commission end. | Provide sharing, relationships, community safety and moderation. |
| Purchase and entitlement | Product, store, transaction identifiers, purchase token, renewal/cancellation status and entitlement; the store holds payment-card details. | Verify and supply Pro access, handle purchase support and fraud. |
| Device, usage and operations | Device push token (FCM or conditional superseded Expo Push path), notification delivery status, app events, IP/security logs, API and rate-limit metadata, and optional crash/performance telemetry if Sentry is configured. | Deliver notices, maintain service integrity, measure product use and diagnose failures. |
2. Purposes and legal bases
We use account and requested-feature information to perform the service; proportionate security, abuse prevention and diagnostics may rely on legitimate interests; mandatory records rely on legal obligation. Health data that you choose to write in chat, tasks, notes or reminders may be stored and used for those functions. You may delete the entries or account. A connected health source also requires its OS permissions. Where GDPR Article 9 or KVKK Article 6 applies to a particular health route, an applicable special-category condition is required; this policy and general sign-up agreement alone are not explicit consent. GDPR Articles 6 and 9; KVKK Article 6.
AI processing of ordinary personal data supports the Cognito request you make. Relevant prompt, history and planning context may go to a named external model provider as described below. Feedback does not permit model training. Email is sent only when strictly necessary for account and security; we do not send email marketing. AI Disclosure.
3. AI processing and model training
To answer a request, Ascendia may send the prompt, selected history and relevant context to Google Vertex AI/Gemini; Anthropic and OpenAI may be used if their optional routes are enabled. Food photographs are an approved image purpose. Text-to-speech may send generated text to Google Cloud. Embedding is local by default; if an external embedding option is enabled, relevant text may be sent to Voyage AI.
Ascendia uses AI for suggestions and drafts. It does not intend to make a solely automated decision with legal or similarly significant effect about you. Subscription eligibility and age controls are rules-based, and the effects of a proposed AI action depend on your confirmation or separately chosen automation settings. If a material automated decision is later introduced, we will provide the notice, explanation, review and rights required by applicable law before using it. GDPR Article 22.
4. Recipients and international transfers
An optional private ICS/webcal link is different from Google/Microsoft calendar OAuth. Ascendia fetches it from the host selected by the user; that host receives the URL (potentially a bearer-like secret), request metadata and later scheduled or requested fetches. It may be Google, Microsoft or another operator. The host is a user-chosen external recipient, not a named Ascendia subprocessor without evidence of a contract. Its legal role, location and retention depend on the actual link and provider terms; Ascendia cannot erase the host’s own records.
The recipient inventory below is the same one used in Subprocessors; optional providers are used only when the corresponding feature is enabled. Google Cloud Platform includes hosted infrastructure, Vertex AI/Gemini and optional speech; Firebase Cloud Messaging handles push; the account-email provider handles account mail; Sentry, Anthropic, OpenAI, Voyage AI, OpenWeather, Google Places and superseded Expo Push fallback are conditional. Requested barcode lookup sends the barcode to Open Food Facts. Affiliate attribution links a user to a partner; that partner sees a stable pseudonym, join date, plan type, status and commission end. The pseudonym may remain personal data. MinIO, PostgreSQL and Redis are self-hosted software within the deployment, not separate outside companies. Google Play, Apple and user-connected Google/Microsoft calendar services act as independent or user-directed recipients, not Ascendia payment subprocessors.
We disclose data to service providers only for the functions described, and to people you choose to share with in Together. The named recipients, purposes, likely data and known/unknown regions are in Subprocessors. Google Play and Apple operate the payment account under their own privacy terms; optional Google/Microsoft calendar services act on a connection you authorize. We may disclose information if law requires it or to protect people or the service, subject to lawful process.
Data may be processed outside your country by the providers described in Subprocessors, subject to applicable transfer law. We use lawful transfer arrangements for actual routes and describe known recipients and purposes. The recipient inventory is not proof that every optional route is enabled. GDPR Chapter V; KVKK Law.
5. Retention and deletion
We keep account and feature records while the account is active and they are needed for the requested service, then delete or de-identify them when you remove them or delete the account, subject to legal retention, unresolved disputes and the technical backup cycle. Never keep a refused child's birth year or application merely to measure refusal.
| Detached Apple sign-in grant | Revoke the token with Apple and delete it at once. If Apple is unreachable, keep it encrypted and usable only for revocation retries for no more than seven days, then delete it. Keep a minimal hashed security event record for 30 days, then delete it. |
| Plans, goals, notes, health, food, Money, chat, memory and Together content | While needed for the account or a user-selected sharing relationship; user deletion, memory forgetting and account deletion should remove active copies, subject to another user's independent content and legal holds. |
| Private ICS/webcal subscription and mirrored events | Keep the private URL, hash, label, sync metadata and derived event/busy-band records only while that connection is needed. Disconnect deletes the subscription and cascades to its mirrored events; account deletion calls the feed purge. Backups follow their ordinary rotation. |
| Profile and chat photos | While the photo is needed; on account deletion they are deleted from storage when you confirm, and a photo still uploading is removed within about an hour. |
| Meal photos | Not kept: held only while the nutrition estimate runs, then deleted; leftovers are removed within about 2 hours. |
| Purchases and financial transaction records | For the period required by tax, consumer, accounting or fraud law, then delete or de-identify. App-store records remain subject to store policy. |
| Security, diagnostics and product events | Only as long as necessary for the stated security or measurement purpose, with access limits and removal/de-identification on account deletion unless law justifies a longer period. |
| Backups | The local script retains seven daily and four weekly snapshots; deleted data may remain in an inaccessible backup until rotation. Backup copies follow their ordinary rotation. |
Settings → Export or delete provides account export and deletion (Review account deletion); Settings → AI Memory offers individual memory controls. When you delete your account, a Google Play subscription is cancelled through the Play API on a best-effort basis, and deletion proceeds even if that cancellation fails; an Apple subscription is not cancelled and you are only warned, so cancel it in your Apple subscription settings. The mobile export may create a temporary file on your device and invoke your operating system's share sheet, which may send it to a recipient you choose. Google Play deletion rule; Apple deletion guidance.
6. Your rights
Depending on your location and the basis for processing, you may ask for access, a portable copy, correction, deletion, restriction, objection, withdrawal of consent and information about a decision. EU and UK users may complain to their supervisory authority and may request human intervention where automated-decision rules apply. Türkiye users may exercise the rights in KVKK Article 11 and apply to the competent authority after the statutory request process. California residents may request to know, access, delete and correct information, and may opt out of sale or sharing or limit certain uses of sensitive information if those practices occur. The availability of California sale, sharing and sensitive-information choices depends on the processing actually used. We will not discriminate for exercising a right where prohibited. GDPR Articles 12–22; KVKK Law; California CPPA FAQ.
Under KVKK Article 11, people in Türkiye may learn whether data is processed, request information, learn purposes and proper use, know domestic/foreign recipients, request correction or deletion and notice to recipients, object to an adverse result produced solely by automated analysis, and seek compensation for unlawful processing. Submit a request to support@ascendia.day; after the statutory process, a complaint may be made to the KVKK Board. KVKK Law.
Use Settings → Export or delete to export or delete, Settings → AI Memory to inspect/correct/forget learned items, and the relevant Together controls to end sharing. You may also write to support@ascendia.day. We may verify your identity in a proportionate manner and explain any lawful exception.
7. Children, security and incidents
Ascendia is for people aged 16 or older. Sign-up asks for a date of birth and retains the year for age assessment; if an ineligible person's account is discovered, access should be restricted while export/deletion rights are preserved. Under-18 users cannot receive adult calorie targets.
We use authentication, service access controls, scoped storage and security monitoring designed to reduce risk, but no system can promise absolute security. We evaluate suspected personal-data incidents and notify users and regulators when applicable law requires, within its required time and content rules. You should protect your device and tell us about suspected misuse at support@ascendia.day.
8. Store disclosures
9. Changes
We may update this policy to reflect practices or law. We show the new effective date and present changed Terms or Privacy Policy in a simple acceptance popup on the next app open. Where a new processing purpose needs a separate legal condition, we obtain it before that processing. Questions: support@ascendia.day.
10. Data categories and purposes
The table below details the categories above. The stated grounds apply to the described processing; neither an optional feature nor this notice creates a blanket consent. “Necessary” means for the named feature, not for a basic account. Direct fields, connected sources, store verification and device/API events are the collection methods. GDPR Article 13; KVKK Article 10.
| Data / purpose | Proposed GDPR and KVKK ground | Recipient | Required status and refusal consequence | Retention criterion and missing fact |
| Identity, birth year and authentication / account | GDPR 6(1)(b), KVKK 5/2-c; security: 6(1)(f), 5/2-f | Hosted service, verification-email provider | Required for account; refusal prevents registration | Account life; minimal lawful audit afterward |
| Plans, calendar, notes and saved weather location / requested organization | 6(1)(b), 5/2-c | Hosted service; connected Google/Microsoft calendar; conditional OpenWeather/Places | Each feature optional; refusal disables only that feature | Until item/account deletion; connected-source copies must be checked |
| Private ICS/webcal URL, label, hash, feed events and busy bands / optional calendar availability and planning | GDPR 6(1)(b), KVKK 5/2-c for the requested connection; special-category content requires an additional applicable condition | Hosted service; the user-chosen external feed host receives fetches and request metadata, as an independent recipient unless its actual terms establish another role | Optional; no feed fetch or mirror if not connected; disconnect ends future fetches | While connected; disconnect/account deletion removes active subscription and derived events from active systems; host-side retention follows the host’s policy. |
| User-written health information, Body and connected metrics / tracking, answers and reminders | 6(1)(b), 5/2-c for requested functions; an applicable GDPR Article 9/KVKK Article 6 condition for health data where those laws apply | Hosted service, connected source where selected; selected AI provider for a requested AI answer | Optional feature use; user can delete entries and disconnect source | Until entry/account deletion, subject to lawful retention and backup cycle |
| Food, allergies, meal photo and barcode / Kcal and product lookup | Requested function: 6(1)(b), 5/2-c; health content needs an applicable Article 9/KVKK Article 6 condition where those laws apply | Hosted service, selected AI model; Open Food Facts receives scanned barcode and request metadata | Optional; refusing lookup disables lookup, not account | Item and OFF cache while needed |
| Money / user planning | 6(1)(b), 5/2-c; specific mandatory records: 6(1)(c), 5/2-ç | Hosted service | Optional; refusal disables Money | Item/account life; subject to applicable statutory periods |
| AI prompts, memory and embeddings / response and retrieval | Ordinary data: 6(1)(b), 5/2-c; sensitive content needs an applicable special-category condition | Hosted service, Vertex/Gemini or conditional Anthropic/OpenAI; conditional Voyage in user writer and orchestrator; local default writer sends no text externally | Optional feature use; a requested answer may use the selected model | Item/memory deletion; provider retention follows its applicable terms |
| Together and affiliate attribution / sharing, commission and fraud control | Requested sharing: 6(1)(b), 5/2-c; documented attribution/fraud interest: balanced 6(1)(f), 5/2-f | Chosen peers; affiliate partner sees stable pseudonym, joined date, plan type, status and commission end | Optional; refusal means no sharing/referral enrollment | Share life; attribution through commission/dispute period. Pseudonym may be personal data. |
| Purchase / entitlement and accounting | 6(1)(b), 5/2-c; mandatory records: 6(1)(c), 5/2-ç | Google Play/Apple and hosted service | Required only for Pro; free account remains | Entitlement life and applicable tax/accounting periods |
| Device token, push, event and diagnostics / delivery, security and repair | Requested push: 6(1)(b), 5/2-c plus OS permission; security: balanced 6(1)(f), 5/2-f | FCM; conditional Expo Push; conditional Sentry | Push/diagnostics optional; refusal disables corresponding flow | Token until withdrawal |
The concrete legitimate interests are account/network security, abuse prevention, narrow failure diagnosis and documented referral-fraud prevention; Health information you choose to enter can be used for the requested planning and reminders, as described above. Do not reuse it for training. Retention varies by data category and applicable law. Data provision is not generally statutory; accounting/tax records arise after purchase.
11. Voice input and sign-in
Voice input. With microphone permission, Apple or Android speech recognition may process audio on the device or through its service. Interim text appears in the app; only a transcript you send enters Ascendia chat and may reach the selected AI provider. Typing remains available. Speech input differs from generated text-to-speech output.
Optional dictation uses microphone audio and an editable transcript. The operating-system recognizer may receive audio; Ascendia receives the transcript only when you send it. Applicable special-category conditions are required for health information in a submitted transcript. Sent transcripts follow the chat retention described above. Apple speech recognition; Android SpeechRecognizer.
Apple/Google sign-in. An optional provider credential or identity token is handed to Ascendia; its server verifies the identity against Apple/Google signing keys and uses a provider subject, verified email (including Apple private relay where selected) and optional name to create or link the account. Under the Apple account-linking rule, Apple sign-in may link automatically to an existing account only when Apple reports the email as verified and it is not a private-relay address. A private-relay user links Apple from Settings while already signed in. On detaching an Apple grant, the token follows the immediate-revocation, at-most-seven-day encrypted retry and 30-day hashed security-record limits in §5. The processing basis is GDPR 6(1)(b)/KVKK 5/2-c for requested authentication; the minimal hashed security record supports account security. Apple and Google are independent identity providers for their sign-in step, distinct from their app-store payment and calendar roles. Password registration is the alternative.