01. What this policy covers
Lokmia is an independently developed consumer health, nutrition and fitness product. This policy explains the public website at lokmia.com and the data flows in the current development app. The app is in active development; public downloads and a public release date have not been announced.
For privacy enquiries, contact the Lokmia operator at bozkurt@lokmia.com. The website does not register an app account or collect health information through a form. Development-app practices described below are not a promise that every feature will be available at launch.
02. Visiting this website
The website is hosted through Cloudflare Pages. Delivering and protecting it involves connection information such as IP address, browser information, request time and the page requested. Cloudflare may process this information in its infrastructure under its Privacy Policy.
This site has no advertising trackers, third-party analytics scripts or account-registration form. Its first-party scripts provide navigation, screen previews and decorative motion. They do not send your health data to us. Hosting or security services may use operational storage or cookies; no optional marketing cookies are implemented by this site.
If you email us, we receive your email address, the message and any attachments you choose to send. We use them to respond to the enquiry and, if requested, discuss early access. An early-access email is an enquiry, not enrolment in a newsletter or a guarantee of admission. Please avoid sending medical records or other unnecessary sensitive information.
03. Information in the development app
The information depends on the features you choose to use and the build’s configuration.
| Area | Information and purpose |
|---|---|
| Account | Email or supported sign-in-provider identity, an account identifier and authentication information, handled through Firebase Authentication to sign in and manage the account. |
| Profile and preferences | Display name and optional details such as height, weight, age-related inputs, goals, food preferences or a manually entered city. These support the daily experience and estimates. A city entered by you is not GPS tracking. |
| Everyday records | Meal logs, approximate nutrition, water, kitchen inventory and quantities, favourites, meal plans, activity records and, where used, fasting or medication/supplement records. These support the features you choose to use. |
| Nora | Questions, available context, selected food images and responses used to answer supported food, kitchen and meal-plan questions or estimate nutrition. |
| Optional Link sharing | Account identifiers, display names, membership, selected daily completion/progress information and preset check-ins or nudges, used to share the chosen status with members of a Link you join. |
Health-related information can be sensitive personal data. Share only information needed for the feature. The public website does not collect these app records.
04. Local records, cloud services and sharing
The current app stores many everyday records locally in account-scoped storage on the device. Signing into an enabled development build uses Firebase Authentication. Profile backup and optional Link sharing use Cloud Firestore when those services are enabled. This does not mean that every local meal, kitchen or workout record is backed up to the cloud.
Optional Link sharing makes the selected status visible to the Link’s members. Its sharing setting controls whether daily completion alone or additional progress is shared. Consider who you join or invite before using that feature.
Google’s handling of Firebase service data is described in Firebase’s privacy information. Service providers, including Cloudflare, Google and email-delivery providers, can process information in countries outside your own. The location, safeguards and service configuration for a public app release will be documented before that release; this policy does not claim a fixed data-residency region or an unverified transfer mechanism.
05. AI, photographs and voice
Supported ready questions can be answered from on-device information first. When a question or image needs the connected AI service, the current development integration sends the question, relevant available context and any selected image to Google’s Gemini API. A response may also use information returned by supported app tools. Choosing to ask Nora is not a promise that all processing happens on the device.
Google’s handling of AI requests depends on the service and billing configuration. Unpaid Gemini services can use submitted content and responses to improve products and may involve human review. Read the Gemini API terms. Do not submit sensitive personal information or identifiable medical material to a development AI service. The production AI setup and its data terms will be confirmed before public launch.
Camera, photo-library and microphone access are requested through the device when a relevant feature is used. You can decline or revoke access in device settings. Voice input uses the phone’s speech-recognition service to turn speech into text; that service’s processing depends on the operating system and its settings. The resulting question follows the same path as a typed question. Optional reminders use device notifications.
06. Purpose and legal basis
We use website connection information to deliver and protect the site, and contact information to handle an enquiry. Where applicable law permits, these purposes may rely on legitimate interests or steps you request before an agreement. A legal obligation may require limited records to be retained.
App processing must have an appropriate legal basis for the feature and location concerned. Consent, including explicit consent for sensitive data where required, must be specific and informed. Device permission or continued browsing is not blanket consent to health-data processing. The public-release registration and consent notices will set out the applicable bases before public app data collection begins.
No advertising, sale of app health records or third-party analytics SDK is implemented in the website or app dependency configuration reviewed for this notice. This is a description of the current build, not a claim about every future configuration.
07. Retention, deletion and your choices
Local records remain in the app’s device storage until changed or deleted through the relevant controls. Removing the app or clearing its storage may remove local records, but does not by itself delete a Firebase account, cloud copies or provider-held records.
The development app includes an account-deletion flow that re-authenticates the account and attempts to remove account data, including the profile’s cloud copy and account-scoped local records, before deleting the Firebase account. A failed step is not confirmation of complete deletion. Optional Link cleanup is also part of the account flow. This does not promise erasure of separate provider logs or legally retained records.
Email enquiries are retained for the time needed to respond and manage the requested follow-up, subject to applicable recordkeeping requirements. Provider logs and backups follow their applicable service configuration. No unverified fixed retention period is claimed here; public-app retention details will be specified before launch.
You can decline optional device permissions, choose what to share in Link, avoid AI submissions and contact us about records held by Lokmia. To make a request, write to bozkurt@lokmia.com with enough information to identify the relevant enquiry or account. Do not send your password. We may need a proportionate identity check before acting.
08. Your privacy rights
Depending on the law that applies, you may have rights to learn whether your data is processed, obtain access and information, correct inaccurate data, request erasure or restriction, object to certain processing, obtain portability where available, and withdraw consent for future processing. Legal exceptions can apply. Withdrawing consent does not reverse processing that was lawful before withdrawal.
You may also complain to the competent data-protection authority. In Türkiye, see the Personal Data Protection Law and KVKK. For rights in the EU where the GDPR applies, see the European Commission’s information for individuals.
09. Development status and updates
This website does not offer public app registration or intentionally solicit children’s health information. Public-release eligibility, consent, controller details, retention periods and service-provider arrangements will be specified before public registration. A development build should not be used as an undisclosed route to collect another person’s health data.
The website uses HTTPS. No network or storage method can be guaranteed completely secure. This policy does not claim clinical certification, a compliance audit or an unverified encryption architecture.
We will update this policy when practices materially change and display its revision date. Contact bozkurt@lokmia.com for privacy questions.