This Privacy Policy explains how Gaggo Studio (“we”, “us”) handles information when you use Faturalar, an iOS app that finds purchase documents — invoices, e-archive records, receipts, bank slips and warranty certificates — in your own mailbox and organizes them into categories.
The short version: Faturalar reads your mail on your device to find purchase documents. Your email content is not sent to Gaggo Studio servers, is never sold, and is never used for advertising.
1. Connecting Your Mailbox
Faturalar can connect to Google (Gmail and Google Workspace), Microsoft (Outlook, Hotmail, Microsoft 365), iCloud Mail, Yandex Mail and other IMAP mailboxes. You connect an account yourself, through the provider’s own sign-in screen where the provider offers one. Gaggo Studio never sees or stores your email password.
Faturalar asks for read-only mail access everywhere:
- Google —
https://www.googleapis.com/auth/gmail.readonly, the single scope the App requests. It permits reading messages and attachments and nothing else: Faturalar cannot send, delete, modify or label your mail, and it cannot reach your contacts, calendar, Drive files or any Google profile data beyond the address of the account you connected. - Microsoft —
Mail.ReadandUser.Readthrough Microsoft Graph, with the same read-only limit. - iCloud, Yandex and other IMAP mailboxes— read-only IMAP commands only. The App never issues a command that moves, changes or deletes a message. iCloud and generic IMAP accounts use an app-specific password that you create at your own provider.
Credentials — access tokens and app-specific passwords alike — are held in the iOS Keychain on your device with device-only protection, and are never uploaded anywhere. You can disconnect an account inside the App at any time, and you can additionally revoke access from your Google, Microsoft or Yandex account security settings.
2. Google User Data
This section covers Google user data specifically. Throughout it, raw means message data as it arrives from the Gmail API, and aggregated or anonymized means anything derived from that data, such as counts, totals or statistics.
What we access
When you connect a Gmail account, Faturalar uses the read-only Gmail scope to:
- run Gmail’s own search to shortlist messages that could contain a purchase document;
- read the headers — sender, subject, date — of only those shortlisted messages, in order to score how likely each one is;
- download and read the attachments of the messages that pass that score, and the message body when the document is written in the body rather than attached.
Messages that are not shortlisted are never opened. Faturalar accesses no other Google user data: no contacts, no calendar, no Drive, and no Google profile information beyond the address of the connected account.
How we use it
Raw Gmail data is used for one purpose: to find, read and organize your own purchase documents inside the App, and to calculate the dates the App reminds you about, such as warranty and return windows. Aggregated or anonymized data derived from Gmail — for example how many documents were found in a scan — is used only to show you your own totals inside the App. Neither raw nor aggregated or anonymized Gmail data is used for advertising, profiling, credit or lending decisions, market research, or any purpose you cannot see in the App.
What we transfer
We do not transfer, share or sell your raw or aggregated or anonymized Gmail data to any third party. It is not sent to Gaggo Studio, to analytics providers, to advertising networks, to data brokers, or to any artificial intelligence or machine learning service. Gmail data travels from Google to your iPhone and stops there. The only exceptions are the ones the Limited Use requirements allow: with your explicit consent, to comply with applicable law, or as part of a merger or acquisition in which the receiving party is bound by this policy.
How we protect it
Gmail data is fetched over encrypted transport (TLS) directly from Google’s servers to your device and processed there. Gaggo Studio runs no server that receives, stores or processes Google user data, so there is no server-side copy to be breached. Access tokens are kept in the iOS Keychain with device-only protection; the documents themselves are protected by iOS file protection and by your device passcode, Face ID or Touch ID.
How long we keep it, and how it is deleted
Because nothing reaches our servers, retention is entirely under your control on your device:
- Disconnecting the Google account deletes the stored access token immediately and stops all further access.
- Deleting a document in the App removes it and its stored copy from the device.
- Delete my account in the App settings removes every document, every connected mailbox and every stored credential at once.
- Deleting the App removes any remaining local Faturalar data from that device.
To be thorough, also revoke Faturalar at myaccount.google.com/permissions. If you would like confirmation or help with a deletion request, write to hello@gaggostudio.com and we will respond within 30 days.
3. Google API Services — Limited Use
Faturalar’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Gmail data is used only to provide and improve the document-finding features you see in the App; it is not transferred to others except as required for those features, to comply with applicable law, or as part of a merger or acquisition; it is not used for advertising; and no human at Gaggo Studio reads your email except with your explicit permission for a support request, for security purposes, or where required by law.
Raw and aggregated or anonymized Google user data is not used to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models, and it is not transferred to any third-party service that would use it for such training. All text recognition in Faturalar runs on your device using Apple’s on-device frameworks.
4. Where Processing Happens
Mail scanning and document detection run on your device. Message text and attachments are fetched from your mail provider directly to your iPhone, analyzed locally, and the resulting documents are stored locally on the device.
Text recognition inside document images and PDFs is performed with Apple’s on-device frameworks. Faturalar does not send your email content, attachments or document images to Gaggo Studio servers or to any external AI service.
5. What Faturalar Stores
- Detected documents— document type, seller or sender, date, amount, currency, category and a copy or reference to the source attachment.
- Account connection data— the connected email address and the access token or app-specific password needed to keep the connection working.
- App settings— categories, filters, language preference and similar choices you make in the App.
This data lives on your device. If you enable iCloud backup for your iPhone, your device backup may include Faturalar data; that backup is controlled by Apple and your iCloud settings, not by Gaggo Studio.
6. What We Do Not Do
- We do not sell or rent your data.
- We do not use your mail content for advertising or profiling.
- We do not read your mailbox on our servers — we have no such server.
- We do not send, delete or modify email on your behalf.
- We do not use your mail content to train AI or machine learning models.
7. Purchases and Subscriptions
Faturalar may offer premium features through an auto-renewing subscription. Purchases are processed by Apple. We may receive subscription entitlement status and product identifiers needed to unlock premium features, restore purchases and provide support. We do not receive your full payment card details. Connecting a mailbox and scanning it does not require a purchase.
To keep subscription status reliable and measure sales, purchase and transaction information (such as the transaction identifier, product identifier, purchase date and subscription state) is also processed on our behalf by RevenueCat, our subscription infrastructure provider. RevenueCat receives no email content, no documents and no Google user data — only App Store purchase information.
8. Diagnostics
We may receive limited, aggregated crash and diagnostic information (such as device model, iOS version and error traces) through Apple, to keep the App stable. These reports contain no email content, no document contents and no Google user data.
9. Retention and Deletion
- Deleting a document in the App removes it from your device.
- Disconnecting a mail account stops further scanning and removes the stored credential.
- Delete my account in App settings removes all documents, mailboxes and credentials in one step.
- Deleting the App from your device removes locally stored Faturalar data from that device.
- After you disconnect, remember to revoke Faturalar’s access in your Google, Microsoft or Yandex account settings as well.
10. Security
Connections to mail providers use encrypted transport (TLS). Credentials are held in the iOS Keychain with device-only protection. Because processing is local, your document archive is protected by your device passcode, Face ID or Touch ID and by iOS file protection. No method of storage or transmission is completely secure, but we work to protect your information using industry-standard practices.
11. Your Rights
Depending on where you live, you may have rights to access, correct, delete or export your personal data, and to withdraw consent. Because Faturalar data is stored on your device, you can exercise most of these rights directly in the App. For anything else, contact us and we will help.
12. Children
Faturalar is not directed to children under 13, or under the minimum age required in your location. We do not knowingly collect personal information from children.
13. Changes
We may update this Privacy Policy as Faturalar evolves. Material changes will be posted on this page with an updated date.
14. Contact
Questions, deletion requests or privacy concerns: hello@gaggostudio.com.