Last updated: 5 October 2026 · English translation published 29 July 2026
This policy explains how the Perlecta application processes your personal data. Perlecta is an OCR (optical character recognition) application that converts photographs of documents into tables or text.
This application ("Perlecta") is operated by Dedeyunus Keskin (sole proprietor). Contact: info@perlecta.com · Address: Kayseri, Türkiye. Under the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the data controller is Dedeyunus Keskin.
Privacy officer: Dedeyunus Keskin — info@perlecta.com. All privacy requests, including those under the New Zealand Privacy Act 2020, can be sent to this address. This person is also our Data Protection Officer under Singapore's Personal Data Protection Act and our Grievance Officer for users in India.
| Data | When | Why | Legal basis (KVKK art. 5) |
|---|---|---|---|
| E-mail, name, password (stored hashed) | Sign-up / sign-in | Creating your account and authenticating you | Establishment/performance of a contract |
| Google account identifier | Sign in with Google (optional) | Authentication | Performance of a contract |
| Extracted text/table (NOT the photograph of your document — see §4) | When you run a scan | To convert your document into a table or text; processed at that moment and not stored on our servers | Performance of a contract |
| Table layout "fingerprint" (a hash derived only from column headers — not content or values) | When you run a scan (Starter, Pro and Ultra) | Smart Template suggestions | Legitimate interest (can be turned off) |
| Usage information (number of scans, plan, credits) | While using the app | Usage limits and subscription management | Performance of a contract |
| Scan quality statistics: reading confidence counts (how many cells were read as certain or uncertain), document type (such as table or invoice), whether the document is printed or handwritten, processing time and image resolution. The content of your document (text, values, names) is NEVER written into this record. | When you run a scan | To measure and improve reading quality | Legitimate interest |
| In-app step counts: which screen of the app was reached or which button was pressed (for example "2nd page of the introduction", "continue as guest"), the app version and the country. Your account, your email address and document content are not written into this record. | While you use the app | Measuring where users struggle so we can improve the app | Legitimate interest |
| Crash reports and your feedback | If the app crashes / "Report a Problem" | To fix errors | Legitimate interest |
| Subscription / payment status | On purchase | Payment is handled by the app store; we never see your card details | Performance of a contract + legal obligation |
| Connection logs: your IP address, date/time and which address you requested. Document content is not written into this record. | Every time the app connects to our server | Security: detecting attacks and abuse, and diagnosing faults | Legitimate interest |
We do not collect advertising identifiers, location, contacts, or separate analytics tracking. We do not track you across other apps or websites, and we do not allow third parties to do so through Perlecta. Because we do not do this kind of tracking, our practices are the same whether or not your browser or device sends a "Do Not Track" signal.
Perlecta does not sell or rent user data, and does not share it with third parties for advertising purposes.
In order to provide the service, your data is sent to the following services, and only for the purposes stated:
drive.file scope).Privacy policies of these services: Google · Mistral AI · Microsoft · OpenAI · RevenueCat · Resend · Backblaze · Telegram · Expo.
Voice input: When you dictate into a cell, your voice recording is not sent to our server — your phone's own speech recognition feature is used. This feature is provided by your device's operating system (Android/iOS), and your voice may be sent to that service in accordance with the device manufacturer's own policy. Only the resulting text reaches us.
Opening on your phone: When you tap "Open", the file is handed to the app you choose on your phone (e.g. Excel, Google Sheets) inside the device; it is not sent to us or to any other server. That app's own privacy policy applies.
The servers of these services may be located abroad; document content may be transferred abroad for processing purposes, with the necessary safeguards taken under KVKK art. 9.
Perlecta uses the paid (enterprise) tier of the Google Gemini API and the Mistral AI API — not the free/trial tier. According to these providers' own current statements:
An honest limit: This is the current policy published by the providers themselves — Perlecta cannot control it and cannot guarantee the behaviour of a third party. If Perlecta moves to a different provider in the future, this section will be updated; the principle will not change: only the paid/enterprise tier is used, and content is not shared for training purposes.
Perlecta uses AI-assisted OCR services to convert your documents into text or tables. The AI output is not an automated or final decision — the result is shown to you, and you can edit and verify any cell you wish. OCR results can always contain errors; the final check belongs to the user.
You choose which document to scan. We do not inspect, classify or categorise its content, and we have no way of knowing in advance what it contains — to us a document is simply a container. Whatever is inside it is sent to the AI provider so that it can be read. That may include information which is sensitive by nature: a pharmacy receipt or a prescription (health), a payslip, a tax notice, or a bank or identity document.
Information about other people. A document may also contain information about other people — for example the name and address of the seller or buyer on an invoice. We use that information only to read the document at your request, and do not keep it beyond the periods set out in §4.
This is a consequence of how the service works, not a separate collection of that information: we do not extract it, tag it, or store it as “health data” or under any other category.
What happens to it is exactly what happens to any document (§4): the photograph is never saved, the text read from it is deleted the moment you save your result, and automatically within one hour if you abandon the scan. It is never used to train or improve any model (§3.1).
Your control. If a document contains information you would rather not send to an AI provider, do not scan it — or cover or remove that part before scanning. This is the one decision only you can make, because only you know what is on the paper.
Each step below is a separate transfer, and each one is listed in §3:
the app on your phone → our server (France — Lauterbourg, within the EU) → the AI provider that reads the document (Google Gemini / Mistral AI; on Ultra also Microsoft Azure and OpenAI) → back to your phone as the finished file.
Running alongside that, and without your document: subscription checks go to RevenueCat and the app store; verification e-mails go to Resend; encrypted nightly backups go to Backblaze (USA); app updates come from Expo; and security alerts about unusual account activity go to the operator over Telegram. None of these receive your documents or scans.
Perlecta does not store your documents on its server — but we want to tell you exactly what is kept and for how long: (1) The photograph of your document is never saved — it is deleted from server memory immediately after being sent for character recognition. (If you send a PDF, the file is written to a temporary folder for the duration of processing so that it can be split into pages, and is deleted when processing ends — even if an error occurs.) (2) The file we generate (Excel/Word/PDF) is sent to your phone; no copy is kept on the server. (3) The text read in order to generate your file is held temporarily until you press "save", and is deleted the moment you save; if you abandon a scan midway, this temporary record is deleted automatically within 1 hour at the latest (the system cleans up every 15 minutes). (4) If you have saved a template, that template's column headers remain in your account until you delete them, so that the feature can work. Apart from these, your documents stay in the app's own storage on your phone; because we do not keep them, the security and backup of that storage are your responsibility.
If you are in Germany, Austria or Luxembourg, these rights come from the EU GDPR; in Liechtenstein, from the GDPR as it applies there through the EEA Agreement; in Switzerland, from the Federal Act on Data Protection (FADP). If you are in the United Kingdom, these rights come from the UK GDPR; in Ireland or Malta, from the EU GDPR; in Gibraltar, Jersey, Guernsey or the Isle of Man, from that jurisdiction's own data protection law, which follows the GDPR. If you are in Türkiye, the equivalent rights come from KVKK art. 11. In substance they are the same, and we apply them to every user regardless of where you are:
To make a request, write to info@perlecta.com. We will respond without undue delay and within one month at the latest. Making a request is free.
To delete your account and all of your data (your scans, templates and files), you can use Settings > Delete My Account (in the app: "Ayarlar > Hesabımı Sil") — this takes effect immediately and is irreversible. Alternatively you may request it via info@perlecta.com.
Two honest notes. (1) Deletion takes effect immediately on the live system, but your data may remain in the encrypted nightly backups for about 5 more days, disappearing on its own as backups are rotated (see §4 "Backups") — these backups are kept solely for disaster recovery. (2) What remains is the irreversible digest of your e-mail address (§4) — its only purpose is to prevent the free trial entitlement from being claimed over and over with the same address.
Passwords are stored hashed; communication is encrypted with HTTPS; payment card details are not held by us. Access is granted only to authorised systems and at the minimum level necessary; our systems are maintained with regular security updates. Even so, no transmission over the internet is 100% secure.
Data breaches. If we become aware of a breach that affects your personal information and could cause you serious harm, we will notify you and the authority required by applicable law (such as the Turkish Personal Data Protection Board, the UK or Irish data protection authority, or the New Zealand Privacy Commissioner) without undue delay and, where the law requires it, within 72 hours.
Perlecta is intended for a general audience and is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from them. If we learn that we have, we will delete it; if you believe a child has given us information, write to info@perlecta.com.
We may update this policy. The date at the top always shows the latest version, and we will tell you about material changes by e-mail to the address on your account before they take effect. Questions: info@perlecta.com.
Under UK data protection law we must have a “lawful basis” for collecting and using your personal information. Ours are:
| What we do | Lawful basis | What this covers |
|---|---|---|
| Providing the service and running your account | Contract | Your e-mail address, an internal account identifier, your optional name, and — if you sign in with Google or Apple — the identifier that service gives us. Reading your document and returning the file you asked for. |
| Keeping the service available and preventing abuse | Legitimate interests | Your IP address, connection logs and usage counters. We use these to stop abuse of free scan allowances and refund abuse, and to protect accounts against takeover attempts. Document content is never written into these logs. We do not collect device identifiers. |
| Subscriptions and payments | Contract + legal obligation | Subscription status reported by the app store. Card details are handled by the store and are never visible to us. Transaction records are kept where accounting law requires it. |
| Answering questions and complaints | Contract / legitimate interests | The e-mail correspondence you send us. We do not keep your scanned documents for this purpose — document content is deleted the moment you save your result, and automatically within one hour if a scan is abandoned (§4). |
Where we rely on legitimate interests, you have the right to object (§5). We do not use your documents to train or improve any model, and we send no feedback signal to our AI providers (§3.1).
If you have a concern about how we use your personal information, please tell us first: info@perlecta.com. We will look into it and reply.
If you are still unhappy after raising it with us, you can complain to the supervisory authority.
Germany — the data protection supervisory authority of your federal state
List of state authorities at the Federal Commissioner for Data Protection and Freedom of Information (BfDI):
www.bfdi.bund.de — Landesbehörden
Austria — Datenschutzbehörde (DSB)
www.dsb.gv.at
Switzerland — Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
www.edoeb.admin.ch
Liechtenstein — Datenschutzstelle
www.datenschutzstelle.li
Luxembourg — Commission nationale pour la protection des données (CNPD)
cnpd.public.lu
United Kingdom — Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
www.ico.org.uk/make-a-complaint
Türkiye — Kişisel Verileri Koruma Kurumu (KVKK)
www.kvkk.gov.tr
Ireland — Data Protection Commission
www.dataprotection.ie
Malta — Information and Data Protection Commissioner (IDPC)
idpc.org.mt/file-a-complaint
Gibraltar — Gibraltar Regulatory Authority — Information Rights
www.gra.gi/data-protection
Jersey — Jersey Office of the Information Commissioner (JOIC)
jerseyoic.org
Guernsey — Office of the Data Protection Authority (ODPA)
www.odpa.gg
Isle of Man — Information Commissioner
www.inforights.im
Bermuda — Privacy Commissioner (PrivCom)
www.privacy.bm
Cayman Islands — Ombudsman
ombudsman.ky
Australia — Office of the Australian Information Commissioner (OAIC)
www.oaic.gov.au
New Zealand — Privacy Commissioner
www.privacy.org.nz
Singapore — Personal Data Protection Commission (PDPC)
www.pdpc.gov.sg
Hong Kong — Privacy Commissioner for Personal Data (PCPD)
www.pcpd.org.hk
Philippines — National Privacy Commission
www.privacy.gov.ph
Nigeria — Nigeria Data Protection Commission (NDPC)
ndpc.gov.ng
India — Data Protection Board of India