⚖︎ Legal

Milk & Spoon — KVKK Disclosure Notice

Last updated: 25 June 2026

This disclosure notice concerns the processing of personal data under Turkish data protection law and applies to users in Türkiye.

Pursuant to article 10 of Law No. 6698 on the Protection of Personal Data ("KVKK"), we wish to inform you about the processing of your personal data within the scope of the "Milk & Spoon · Baby Feeding Tracker" application (the "App").

Short summary

  • Your data stays on our servers in Türkiye.
  • Your feeding/bottle/pumping/stock/meal-plate records are lifestyle data — they are not health data.
  • Allergy records are treated as health data under KVKK art. 6 out of caution, and your explicit consent is obtained.
  • Only pseudonymous technical error logs are sent abroad (Sentry — Frankfurt). Baby name, email, record content or IP is not sent.
  • No advertising, analytics or profiling is performed.

1. Data Controller

"Milk & Spoon" is a brand operated by the natural person Turkuaz ŞENGÜL. Under KVKK, the data controller is this natural person.

  • Data controller: Turkuaz ŞENGÜL (natural person)
  • Brand / app: Milk & Spoon · Baby Feeding Tracker
  • Center of activity: Türkiye
  • Requests / contact: destek@milkandspoonapp.com — your requests under KVKK art. 11 are received and answered in writing through this address.
  • VERBİS: The data controller is exempt from the obligation to register with the Data Controllers' Registry (VERBİS) within the scope of the thresholds in the Personal Data Protection Board's decisions No. 2018/87 (as amended by 2023/1154) and 2025/1572 (annual number of employees fewer than 10 and annual financial balance sheet less than TRY 10 million). This exemption relates only to the registry-registration obligation; the obligations of disclosure, explicit consent, data security and responding to requests are applied in full.

2. Processing stages

2.1. Anonymous stage (without an account)

When you use the App without creating an account, only a random user identifier (UUID) is generated. At this stage, no email, name, phone or other information identifying you is collected. In KVKK terminology, this is a pseudonymous data regime; the personal-data quality is minimal.

2.2. After upgrade

The moment you make your account permanent via Apple Sign In or email, personal data begins to be processed and falls within the scope of this disclosure.

3. Categories of processed personal data

Category Data Nature
Identity UUID, optional email, optional Apple ID Personal data
Family Baby's optional name + date of birth Personal data
Lifestyle Feeding, bottle, pumping, milk-stock, meal/plate records Lifestyle data
Health (caution) Allergy records + severity + optional photo Health data under art. 6 out of caution — explicit consent obtained
Commercial Subscription status (Premium / Founder) Personal data
Legal evidence Consent record (UUID + approved text version + date) Record for proof purposes (art. 12)
Technical UUID + error message (sent to Sentry) Pseudonymous technical data
Purpose Legal ground
Provision of the record-keeping service art. 5/2(c) performance of a contract
Cloud backup and family sharing art. 5/2(c) performance of a contract + art. 5/1 explicit consent
Storage of allergy records art. 6/2 explicit consent
Subscription management (Apple IAP, RevenueCat) art. 5/2(c) performance of a contract
Diagnosis of app errors (Sentry) art. 5/2(f) legitimate interest
Compliance with legal obligations art. 5/2(a) expressly provided for in laws
Request and complaint management art. 5/2(c) performance of a contract

5. Parties to whom data is transferred

Recipient Purpose Data Location
Apple Account identity, App Store IAP Apple ID, subscription status Apple infrastructure
RevenueCat Subscription status sync Anonymous purchase ID, product, amount USA
Sentry Pseudonymous error tracking UUID + error message/stack trace + breadcrumb Frankfurt, EU
Family members (if you invite them) Family sharing Records within the relevant household Türkiye server
Authorized authorities Legal obligation Relevant data TR

6. Transfer of data abroad (art. 9)

The only data transferred abroad is the pseudonymous technical error log sent to Sentry. This log:

  • Contains only the random user UUID + error message/stack trace + minimum technical breadcrumb
  • Does NOT send baby name, email, record content, IP address or geographic information — the app automatically scrubs this information before sending; geographic location is not stored
  • Has a retention period of 30 days

Legal ground: this transfer relies on legitimate interest (art. 5/2-f) because it is limited solely to pseudonymous technical data and serves the purpose of app security/error diagnosis; it is carried out under the principle of data minimization, and you are informed of it by this text. A data processing agreement (DPA) with Sentry has been signed. Your right to object to this error sharing is reserved (art. 11/g).

The data sent to Apple and RevenueCat is on USA infrastructure; these services are subject to their own terms, and the app shares only the minimum data necessary for the service.

7. Method of collection

Data is obtained directly from you through forms and interactions within the app. No automated data collection (analytics, cookies, device fingerprint) is performed.

Some fields (plate name, note, allergy description) are free text; the content you enter into these fields is processed as you entered it. We recommend that you do not enter special categories of personal data (health, identity, etc.) into these fields; otherwise such content will also be deemed processed.

8. Retention periods

  • Records on the device: until you delete them or remove the app
  • Cloud backup: as long as the account is active; permanent deletion within 30 days after "Delete Account"
  • Sentry error logs: 30 days
  • Records subject to a legal retention obligation: for the period required by legislation

9. Your rights (KVKK art. 11)

  • (a) Learn whether your personal data is being processed
  • (b) Request information about it if it has been processed
  • (c) Learn the purpose of processing and whether it is used in accordance with its purpose
  • (ç) Know the third parties to whom it has been transferred, domestically or abroad
  • (d) Request correction if processed incompletely/incorrectly
  • (e) Request its deletion/destruction
  • (f) Request that the actions carried out under sub-paragraphs (d) and (e) be notified to third parties
  • (g) Object to a result against you arising from analysis by automated systems
  • (ğ) Claim compensation for damage you have suffered due to unlawful processing

Application: You may submit your requests in writing to destek@milkandspoonapp.com. Pursuant to the Communiqué on the Procedures and Principles of Application to the Data Controller, applications made with information verifying your identity are answered within 30 days.

If you are not satisfied with the outcome of your application, your right to file a complaint with the Personal Data Protection Board is reserved (art. 14).

10. Data breach

If we become aware that unauthorized access to your data has occurred, we will, pursuant to art. 12/5, notify the Board and inform you within 72 hours.


This Disclosure Notice may be updated. The current version is always published at https://milkandspoonapp.com/kvkk.

This text is governed by Turkish law.

For issues or requests: destek@milkandspoonapp.com