Privacy Policy
Last updated: 28 August 2026
This policy explains what Brainbaby Bilişim Anonim Şirketi ("Lifepack", "we", "us") does with information about you when you use the Lifepack mobile application, the website at lifepack.io, and related services (the "Service").
We are the data controller for that information. Our details are in Section 13.
Lifepack handles information about your health. That is among the most sensitive categories of personal data there is, and this policy is written to be read rather than skimmed.
1. The short version
- We collect what you give us and what the app needs to work. We do not sell your data, and we do not use it for advertising.
- Some of your most sensitive information never leaves your phone at all — your uploaded lab reports, your mood, stress and sleep entries, your cycle dates and your pregnancy records. See Section 3.
- Your health information is shared with a doctor only when you choose to consult one, and then only what that consultation needs.
- Your symptom conversations are processed by a third-party AI provider in order to answer you. See Section 5.
- You can delete your account from inside the app, and doing so deletes or irreversibly de-identifies your data. See Section 9.
2. What we collect, and why
2.1 Account and identity
| Data | Why |
|---|---|
| Email address, authentication credentials | To create and secure your account |
| Account identifier | To link your data to you and no one else |
2.2 Health profile — special category data
Sex, date of birth or age, height, weight, blood type, conditions, medications, allergies, food intolerances, family history, lifestyle answers (smoking, alcohol, activity, diet), female health answers including pregnancy status, region and city.
Why: to personalise the information the app gives you, to inform the wellness and risk features, and — where you choose to consult a clinician — to give that clinician relevant context.
2.3 Symptom conversations
What you type to Sage, and what Sage replies, together with any specialty or severity grading derived from it.
Why: to answer you, to let you review the conversation later, and — if you consult a clinician about it — to give them the summary.
2.4 Consultations
Bookings, times, mode (video, voice, chat), status, fee, the messages you exchange with a clinician, and any rating or written review you leave.
Why: to operate the consultation, to keep a record for both of you, and to handle disputes and complaints.
2.5 Wellness and activity
Daily water, steps, sleep hours, logged meals and their nutritional estimates, photographed food scans and their analysis, weight entries, reminders, streaks, experience points and level.
Why: to provide the tracking, progress and gamification features.
2.6 Clinician information
If you register as a clinician: your professional details, specialties, languages, biography, profile photo, availability, and the qualification and licence documents you upload.
Why: to verify your registration and to list you in the patient-facing directory. Your documents are stored in a private location, are not published, and are visible only to our verification staff.
2.7 Complaints
If you report a consultation or a person, we record what you reported, the category, and the outcome.
Why: to investigate, to protect patients and clinicians, and to meet our own regulatory obligations.
2.8 Location — only if you allow it
If you grant location permission, we use your device's approximate position to sort clinicians by distance. The coordinates are sent to a geocoding provider to turn them into a place name (see Section 5). We do not store a history of your movements, and refusing this permission only means the directory is not sorted by distance.
2.9 Technical data
Device and operating system information, app version, language, and diagnostic logs of errors.
Why: to keep the app working and to fix faults.
2.10 Purchases
Whether you hold a Lifepack Plus entitlement and when it expires.
Why: to unlock what you have paid for. We never receive your card number. Payment is taken by Apple or Google; see Section 5.
3. What stays on your device and is never sent to us
This is deliberate design, not an oversight, and it is worth knowing about:
- Lab and test reports you photograph or enter, including markers, values, units and reference ranges;
- Wellbeing entries — mood, stress, sleep quality, and menstrual cycle dates;
- Pregnancy records — due date, antenatal checklist and fetal movement counts;
- your locally-held health record and history.
These are stored only in the app's storage on your phone. We cannot read them. No clinician can see them. They are not backed up to us, and if you lose or reset your device without a device-level backup, they are gone.
A practical consequence: if you photograph a blood panel into Lifepack and then book a consultation, the doctor will not see it. Tell them, or show them, what is in it.
One exception, and it is yours to make. When you send a message to Sage, the values and reference ranges from your saved reports go with it as text, so that Sage can answer about your results instead of telling you it cannot see them. If you go further and ask about a particular report — by tapping "Ask Sage" on it, or by attaching a document to your message — that report's summary, findings and any medicines listed on it are sent as well. This goes only to our AI provider, exactly as anything else you type to Sage does (see Section 5), and only in a conversation you started. Nothing about your reports is sent when you are not talking to Sage, nothing is sent in guest mode, and the photographs themselves are never stored by us.
4. Our legal grounds for processing
We are established in Türkiye, so Turkish data protection law applies to everything we do. Where you are in the United Kingdom or the European Economic Area, the UK GDPR or the EU GDPR applies as well. Both are set out below.
4.1 Türkiye — Law No. 6698 (KVKK)
Under the Personal Data Protection Law No. 6698 ("KVKK") we are the veri sorumlusu (data controller). Our identity and address are in Section 13, and this policy also serves as our disclosure under Article 10 of the KVKK.
Your health data is özel nitelikli kişisel veri — special category personal data under Article 6. We process it on the basis of:
- your explicit consent (açık rıza), which you give when you choose to enter health information and, separately, when you choose to share it with a clinician; and
- for the consultation itself, Article 6(3): processing necessary for the protection of public health, preventive medicine, medical diagnosis, and the provision of treatment and care services, carried out by persons under an obligation of secrecy.
Ordinary personal data is processed under Article 5(2) — performance of a contract, compliance with a legal obligation, and our legitimate interests where these do not override your fundamental rights.
Explicit consent can be withdrawn at any time, by deleting the relevant information or your account.
4.2 UK and EU GDPR
For ordinary personal data we rely on:
- Contract (Art. 6(1)(b)) — to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent abuse, and fix faults. We have balanced these against your rights.
- Legal obligation (Art. 6(1)(c)) — where the law requires us to keep or disclose something.
- Consent (Art. 6(1)(a)) — for optional permissions such as location and notifications, which you may withdraw at any time.
For health data, which is special category data, we rely on:
- Your explicit consent (Art. 9(2)(a)) — you choose to enter health information and choose whether to share it with a clinician; and
- Provision of health or social care (Art. 9(2)(h)), where processing is carried out by or under the responsibility of a professional subject to the obligation of professional secrecy, in the context of a consultation you requested.
You may withdraw consent at any time by deleting the relevant information or your account. Withdrawal does not affect processing already carried out.
5. Who else processes your data
We use a small number of providers. Each acts on our instructions under a data processing agreement, except where noted as an independent controller.
| Provider | What it handles | Notes |
|---|---|---|
| Supabase | Authentication, database, file storage | Our primary infrastructure. Holds your account, profile, consultations, messages and scans. |
| AI provider (via the Rork toolkit) | Your symptom conversations and the text sent to Sage | Text you send to Sage is transmitted for the sole purpose of generating a reply. We instruct that it not be used to train models. Do not enter information you would not want processed by a third party. |
| Apple / Google | Payment for Lifepack Plus | Independent controllers. They process your payment; we receive only entitlement status. |
| RevenueCat | Subscription status | Receives an account identifier and purchase state, not health data. |
| BigDataCloud | Reverse geocoding | Receives approximate coordinates only if you enable location. No account identifier, no health data. |
| Open Food Facts | Public food product data | We look up products. No personal data is sent. |
| Expo (push notifications) | Delivery of notifications, where enabled | Receives a device token. Notification text is deliberately non-clinical. |
| Video/voice provider | Real-time consultation media | Carries the call. Calls are not recorded by us. |
Clinicians. When you book or message a clinician, they see the information the consultation requires — including relevant profile context. A clinician acts as an independent controller for the clinical record they keep, under their own professional and legal duties.
We do not sell your personal data, and we do not share it with advertisers or data brokers.
6. International transfers
Our providers may process data outside your country, including outside the United Kingdom and the European Economic Area. Where that happens we rely on appropriate safeguards — UK/EU Standard Contractual Clauses, the UK Addendum, or an adequacy decision — and take account of the destination country's laws.
Under the KVKK, transfer of personal data abroad is governed by Article 9 as amended in 2024. Where we transfer data outside Türkiye we do so on the basis of your explicit consent, an adequacy decision of the Personal Data Protection Board, or an appropriate safeguard permitted by that Article — in practice a standard contract notified to the Board.
You may request a copy of the safeguards for any transfer by writing to us.
7. Security
We take security seriously and design for it:
- Every request to our database is checked by row-level security, so one account cannot read another's rows even if the client asks.
- A clinician can read a patient's record only while an active consultation connects them.
- An administrator reviewing a complaint sees a restricted projection of it — deliberately not including the video room name, because complaints are filed during calls.
- Clinician identity documents are in a private store, never published.
- Data is encrypted in transit and at rest by our infrastructure providers.
- Signing in as a different account on the same device wipes the previous account's local data.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours where required, and will notify you without undue delay where the breach is likely to result in a high risk to your rights.
8. How long we keep things
| Data | Retention |
|---|---|
| Account and profile | While your account exists |
| Symptom conversations | While your account exists, unless you delete them |
| Consultation records and messages | Retained after account deletion with your identifiers severed, because they form part of a clinical record the clinician is also party to and may be required to keep |
| Complaints | Retained with identifiers severed, for regulatory and safety purposes |
| Ratings and reviews | Retained with identifiers severed — they are half of a two-way record |
| Wellness, scans, reminders, progress | Deleted with your account |
| Device-only data (Section 3) | Never held by us; removed when you delete the app or its data |
| Diagnostic logs | Short-lived |
Where the law requires us to keep something for longer, we keep it for that period and no longer.
9. Your rights
You have the right to:
- access the personal data we hold about you;
- rectify anything inaccurate — most of it you can edit directly in the app;
- erase your data ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests;
- portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Lifepack makes no such decision: nothing it produces is a diagnosis, and no clinical decision is automated.
Deleting your account. You can do this yourself in the app. It removes your profile, conversations, scans, reminders and progress, and severs your identifiers from the records described in Section 8. It is not reversible.
To exercise any other right, write to [email protected]. We respond within one month and will tell you if we need longer.
If you are in Türkiye, Article 11 of the KVKK gives you the right to learn whether we process your data; to request information about it; to learn its purpose and whether it is used consistently with that purpose; to know the third parties it is transferred to at home or abroad; to have incomplete or inaccurate data corrected; to request erasure or destruction under Article 7; to have any correction or erasure notified to third parties the data was transferred to; to object to a result produced solely by automated analysis; and to claim compensation for damage caused by unlawful processing.
Apply to us under Article 13 at [email protected]. We respond within 30 days. If you are not satisfied, you may complain to the Kişisel Verileri Koruma Kurulu (Personal Data Protection Board, kvkk.gov.tr) under Article 14.
Complaints elsewhere. If you are unhappy with how we handle your data you may also complain to your own supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority where you live or work. We would appreciate the chance to put it right first.
10. Children
The Service is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
11. Automated processing and AI
Parts of the Service use automated systems to generate text and to derive suggestions, gradings and scores.
These are informational. They are not decisions about you, and they are not diagnoses. They can be wrong. Nothing is decided about your care, your access to care, or your legal position by an automated system.
Where you consult a clinician, a human being makes every clinical judgement.
12. Changes to this policy
We may update this policy. Material changes will be notified in the app or by email before they take effect, and the "Last updated" date will change. Previous versions are available on request.
13. Contact us
Brainbaby Bilişim Anonim Şirketi Gaziosmanpaşa Mahallesi, İran Caddesi No: 55/9, Çankaya, Ankara, Türkiye
MERSIS 000018717338581 · Tax number 1871733858 (Çankaya Tax Office)
General enquiries: [email protected] Privacy and data rights: [email protected]
Data controller (veri sorumlusu): Brainbaby Bilişim Anonim Şirketi, at the address above. Written applications under Article 13 of the KVKK may be sent to that address or, by registered electronic mail or from an address already registered in your Lifepack account, to [email protected].
UK and EEA users. We have no establishment in the United Kingdom or the European Economic Area. Where we are required to designate a representative under Article 27 of the UK or EU GDPR, that representative's name and address will be published in this section. Until then, address any question or request to [email protected]; it reaches the same people and is answered to the same deadlines.
We have not appointed a Data Protection Officer. We are not required to appoint one under the KVKK, and we keep the position under review against Article 37 of the GDPR as the Service grows.
See also our Terms of Use.