Duivo Privacy Policy
Last updated: 27 September 2026
Duivo is operated by Ahmet Hakan Eroğlu ("Duivo", "we", "us"), the controller responsible for the processing described here. This notice covers the Duivo iOS app, duivo.app and our support communications. Contact: [email protected].
Your recordings stay on your device. Duivo does not upload your camera feed, recordings or teleprompter scripts to our servers. This does not mean that the app collects no data: Apple and RevenueCat handle purchases, Google Firebase handles enabled usage analysis and diagnostics, and Meta receives advertising measurement data when tracking is allowed.
This notice provides information. Reading it, using Duivo or accepting our Terms of Use does not, by itself, give consent to optional processing that requires consent.
1. Recordings, scripts and device permissions
Duivo processes camera images and microphone audio on your device for preview, photos and video. Recordings, thumbnails, capture information, teleprompter text and preferences are stored locally. Duivo does not operate a cloud media library or use your recordings to train AI models. Apple's camera focus features may operate on device; Duivo does not perform facial recognition to identify you.
- Camera: needed for live preview and capture. Denying access prevents camera features from working.
- Microphone: used to include sound in videos; access is controlled in iOS settings.
- Photos: Duivo requests permission to add exported media to Apple Photos, not to browse your existing library. Export requires Duivo Pro. Automatic export also requires the in-app automatic-save setting to be enabled.
- Motion: used locally for the camera's level indicator. Duivo does not send raw motion readings as analytics events.
- Storage: available space is checked to help manage recording. Diagnostic SDKs may separately report device storage information as described below.
Deleting a capture in Duivo removes its local files, not a copy previously exported to Photos or elsewhere. iCloud Photos, device backups and other destinations follow your settings with those services and may retain copies. Uninstalling Duivo can remove its local library and scripts. We cannot retrieve or remotely erase files held only on your device or in your personal backups.
2. Purchases and subscription access
There is no Duivo email/password account. RevenueCat, Inc. assigns an app user identifier to connect purchase records and Pro access. Although RevenueCat calls this an anonymous App User ID, it is a pseudonymous identifier, not a guarantee that the associated data is legally anonymous.
Apple and RevenueCat process product and transaction identifiers, purchase verification information, dates, price/currency information where available, subscription/renewal/refund status and entitlement history. RevenueCat also receives app/device technical information, store environment and activity timestamps. Network connections expose an IP address to the receiving service. These records support purchase validation, restoration, billing support, misuse prevention and subscription reporting.
Duivo does not receive your full payment card details or Apple Account password. We do not ask for your name, email or phone number to create a RevenueCat customer profile. Additional identifiers for consented Meta measurement are described in section 4. RevenueCat's purchase service operates independently of the Firebase and ATT preferences.
See RevenueCat's privacy information and Apple's privacy policy.
3. Firebase usage analysis and diagnostics
Duivo uses Google Analytics for Firebase and Firebase Crashlytics to understand feature use and investigate failures. In the current app, Usage and diagnostics is on by default, unless a previous off preference is saved. Turn it off in Duivo → Settings → Usage and diagnostics. There is no separate first-launch permission dialog for this setting. It is independent of Apple's tracking permission; refusing Meta tracking does not turn Firebase analysis off.
When enabled, information can include:
- App-instance/installation and session identifiers; app/OS version, device model, language and approximate location inferred from the network connection. Duivo does not request GPS location. Google states that Analytics does not log or store IP addresses, although it uses them during collection, including to derive approximate location.
- App/session activity and limited feature events: onboarding completion, camera mode, capture start/completion, output count, whether the teleprompter is enabled and Photos export outcomes.
- Paywall views and checkout attempts, cancellation or failure, with the plan, screen variant and a bounded error category. Google Analytics may also automatically collect supported App Store purchase events, separately from Duivo's checkout events.
- Crash traces, diagnostic identifiers, app/device state and technical details such as memory or storage state. Analytics breadcrumbs may help explain activity before a crash. Duivo's own non-fatal reports use fixed error categories rather than underlying error text.
Duivo does not attach recordings, microphone audio, script text, contact information, purchase receipts or local media paths to its own analytics events. It does not set a RevenueCat user ID as a Firebase user ID. The integration disables advertising and vendor identifier collection, Google advertising storage, ad personalization and ad-network registration. Firebase is used for product analysis and reliability, not to run Google Ads.
Turning the setting off stops subsequent Duivo usage-event reporting, resets local Analytics data and its app-instance identifier, and requests deletion of unsent crash reports. Events skipped while off are not replayed by Duivo later. Already received data is not automatically erased by this switch. Pending crash reports are handled using saved reporting preferences at a subsequent launch.
See Firebase privacy information, Analytics data collection and Google's privacy policy.
4. Meta advertising and attribution
Duivo uses Meta's app-event tools to measure and improve advertising for Duivo on services such as Facebook and Instagram. The app initializes Meta measurement only when Apple's App Tracking Transparency (ATT) status is authorized. Declining tracking does not remove camera functionality or purchased Pro access. Duivo does not offer Facebook Login or show third-party advertising inside the app.
When authorized, Meta can receive advertising/device identifiers, a Meta app-scoped identifier, activation/install signals, app/device/network information and paywall/checkout events. Event details can include the subscription selected, price, currency and a limited failure category. RevenueCat's Meta integration can also forward subscription events, including purchases and renewals, with matching identifiers and transaction values. A checkout-cancelled event means abandoning a purchase attempt, not cancelling an existing subscription.
Meta may match these signals with information it holds about activity on other apps or services to attribute conversions, report performance and optimize advertising. Pseudonymous identifiers can still allow matching. Duivo does not send recordings, scripts, support messages, payment credentials or Apple Account passwords in these advertising events.
Change your choice in iPhone Settings → Privacy & Security → Tracking. When Duivo next observes refusal or revocation, it stops sending new Meta events and asks RevenueCat to clear advertising matching attributes. A change made while the app is closed may not reach RevenueCat immediately; previously delivered data is not recalled automatically. Contact support for server-side data requests as well. Server-side delivery through RevenueCat must honor the tracking status synchronized from the app.
See Meta's privacy policy and RevenueCat's Meta integration information. ATT is a platform permission; it does not replace additional notice or consent required by law.
5. Support and beta feedback
If you email us, we receive your email address, message, chosen attachments and correspondence metadata. A support email draft may include app/iOS version information, which you can edit before sending. We use correspondence to answer you, investigate the issue and retain an appropriate resolution record. Emailing support does not subscribe you to marketing.
Send only what is needed. Redact private screenshots and never send passwords, payment card numbers or unrelated sensitive records. A recording deliberately attached to an email is an exception to local-only storage: it is then processed in the support mailbox.
In TestFlight testing, Apple may provide crash information and feedback you submit, including screenshots and technical details. That testing service is separate from the app's Firebase switch and is subject to Apple's TestFlight notices and settings.
6. Website visits and cookies
The website does not currently include a login, contact form, marketing pixel or website analytics script. It does not set its own advertising or analytics cookies. The app's Firebase and Meta integrations are not embedded in the website.
Hosting/network infrastructure processes connection information to deliver and secure pages, such as IP address, requested URL, time, response status and browser details. The site's App Store badges load directly from Apple's marketing service, so Apple receives that network request even before a badge is clicked. Fonts and demonstration media are served with the website.
External links open separate services with their own privacy practices. Email links open your chosen mail application and do not send automatically. If website analytics or advertising technologies are introduced, this notice and required consent controls must be updated before use.
7. Purposes and legal grounds
Where relevant data protection law applies, processing is assessed by purpose:
- Requested functionality, Pro access, restoration and related support: performance of a contract or requested steps before a contract (GDPR Article 6(1)(b); KVKK Article 5(2)(c)). Optional marketing measurement is not necessary for this contract.
- Essential service security and proportionate troubleshooting: legitimate interests in reliability and preventing misuse, where these do not override your rights (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
- Optional advertising measurement, and analytics where consent is required: consent (GDPR Article 6(1)(a); KVKK Article 5(1)), together with applicable device-access rules. Where analytics can lawfully operate without consent, the interest is understanding and improving the product, subject to the applicable conditions and your right to object. A default-on setting is not itself consent.
- Required records, lawful requests and legal claims: the applicable legal obligation or establishment, exercise or defence of rights (GDPR Article 6(1)(c) or, where applicable, 6(1)(f); KVKK Article 5(2)(a), (ç) or (e)). These grounds do not authorize unrelated uses.
Camera or Photos permission is not blanket permission for advertising or international transfers. Withholding information necessary to verify a purchase or answer a request may prevent that particular service. Optional measurement is not a condition of buying Pro. Duivo does not use these data for solely automated decisions with legal or similarly significant effects on you.
8. Recipients and their roles
Each recipient receives data for the relevant purpose, not every category:
- Apple: distribution, payments, subscriptions, refunds and beta testing where used.
- RevenueCat: purchase verification, entitlements, subscription reporting and the configured advertising-event integration.
- Google: enabled Firebase Analytics and Crashlytics services.
- Meta: authorized advertising measurement and associated advertising uses.
- Hosting, network/security and email providers: website delivery/security and support correspondence.
Providers may act on our instructions for some processing and under their own responsibility for other activities, such as Apple's payments or Meta's advertising uses. Their notices explain those activities. Necessary records may also be disclosed to professional advisers or competent authorities for legal obligations or protection of rights. A transfer of Duivo's business would require appropriate data protection and any legally required notice; it would not give access to device-only recordings.
We do not sell recordings or operate a data-broker business. However, providing identifiers/events to Meta for advertising may qualify as “sharing”, “sale” or targeted advertising under some US state laws, even without payment.
9. International processing
Providers operate internationally; subscription, measurement, technical and support data may be processed outside your country, including in the United States. This does not mean local recordings are transferred to them. RevenueCat describes US infrastructure, and Google describes global Firebase infrastructure, in their privacy information.
Transfers must meet the rules applicable to that transfer. EEA/UK mechanisms can include an applicable adequacy decision or appropriate contractual safeguards. Türkiye's KVKK Article 9 has separate requirements; an EU clause or ATT authorization is not automatically sufficient. This notice is not consent to an otherwise unlawful transfer. Contact us for information about applicable recipients/protections or a copy of applicable safeguards, subject to necessary redactions.
10. Retention
Retention depends on the record's purpose; uninstalling the app does not erase all provider-held records.
- Local media and scripts: controlled by your device storage/deletion settings. Photos exports and backups have separate retention.
- Subscription records: retained as necessary to verify/restore access, handle renewals, refunds and disputes, and meet recordkeeping obligations. Deleting data is not cancellation of an Apple subscription.
- Analytics: user/event-level records are subject to the Analytics property's retention controls; aggregated reports have different retention behavior. The in-app switch does not select a server retention period or erase past reports.
- Crash diagnostics: Google's published Crashlytics schedule is 90 days before removal from live and backup systems begins, not an immediate-deletion guarantee.
- Advertising events: subject to measurement purposes, valid deletion requests and Meta's applicable retention rules. Revocation does not erase previously delivered events.
- Support and technical records: retained only as needed for resolution, reasonable follow-up, security/reliability investigations and relevant legal or dispute requirements. A necessary legal hold may extend retention, with use limited to that purpose.
Contact us about a particular record or retention setting. Provider backup/deletion cycles may delay final removal; we will explain material limits rather than promise an instant purge.
11. Your choices and rights
You can delete local captures, edit/remove scripts, change Usage and diagnostics in Duivo, and change camera, microphone, Photos and tracking permissions in iOS. Cancellation is separate, through Apple subscription settings.
Email [email protected] for access, correction, deletion or other privacy requests, preferably with “Duivo privacy request” in the subject. Identify the app and your request. For purchase-related records, the product, approximate purchase date and a redacted Apple transaction reference, if available, may help. We will explain any additional information needed to locate the record. Do not publish transaction references or send passwords or full card details.
We may request proportionate identity verification; a government ID is not required by default. We cannot reliably find every Firebase/Meta record by email, because Duivo does not attach your email to those events. If identification is not reasonably possible, we will explain the limitation and possible provider-specific routes. We cannot access device-only recordings to provide or erase them remotely.
Depending on your location and the law's applicability:
- Türkiye: KVKK Article 11 includes rights to learn about processing, its purpose and appropriate use; know domestic/overseas recipients; request correction or lawful erasure/destruction and notice to recipients; object to adverse results of exclusively automated analysis; and seek compensation for unlawful processing. Applications are addressed as soon as possible and within 30 days, subject to statutory application/verification requirements. Where a response is absent or inadequate, the Personal Data Protection Authority provides complaint procedures.
- EEA/UK: rights may include access, correction, erasure, restriction, portability, objection (including to direct marketing) and withdrawal of consent without affecting earlier lawful processing. Requests are generally answered within one month; a lawful extension will be explained. You may complain to your competent supervisory authority.
- US states: where applicable, rights may include access, correction, deletion, a portable copy, opting out of qualifying sale/sharing/targeted advertising, use of an authorized agent and appeal of a denied request. You will not be penalized for exercising applicable rights. Refusing ATT stops Duivo's new Meta sending; contact us as well about provider-held data. The website has no advertising pixel to opt out of.
Lawful exceptions may apply, such as necessary legal recordkeeping. We will explain refusals and available review/complaint routes. Other local statutory rights remain unaffected.
12. Children
Duivo is a general-purpose camera app, not directed at children. An App Store age rating concerns content suitability; it does not establish capacity to agree to a subscription or consent to tracking. Where parental/guardian authorization is legally required, it is required for the relevant activity. Duivo does not collect a date of birth; an age rating is not age verification.
We do not knowingly collect children's personal information where parental consent is legally required without that consent. If a parent/guardian believes this has occurred through our providers or support, contact us to investigate, stop the relevant processing and arrange deletion where required. Children should not send identifying or private media to support without appropriate adult involvement.
13. Security
Duivo limits its own event payloads and uses provider connections intended to protect data in transit. Device access controls and backup settings also affect local media. Protect your device and check attachments before sending. No storage or transmission method guarantees absolute security. Report suspected Duivo-related privacy or security issues to support.
14. Changes and contact
We may update this notice for functionality, provider or legal changes. The date above identifies this version. Material changes will be brought to your attention as legally required; updating a policy does not replace a new consent where one is required.
Controller/operator: Ahmet Hakan Eroğlu. Email: [email protected]. Available in English and Turkish; neither version removes mandatory protections.