Last Updated: September 10, 2026
This Privacy Policy describes how Koza (the "App"), a pregnancy tracking application for iOS published by TuranliApp, collects, uses, stores, and protects your information.
This policy covers Koza only. TuranliApp publishes other applications that have different features and different data practices; those are covered by our general Privacy Policy. Where the two differ, this document governs your use of Koza.
Koza is a health application. We have written this policy to describe precisely what the App does, rather than what pregnancy apps generally do. In particular, most of the health information you enter never leaves your device, the App contains no advertising and no tracking software, and none of your health information is ever sent to an analytics or crash reporting service. The App does measure how its screens are used, within the strict limits described in Section 7.
By downloading, installing, or using Koza, you acknowledge that you have read and understood this Privacy Policy.
Data Controller: TuranliApp
Contact: ismailturanli91@gmail.com
Koza stores information in two distinct places. Understanding the difference matters, so we set it out explicitly.
The following is stored in Google Firebase (Firebase Authentication and Cloud Firestore), operated by Google LLC, under your account:
| Data | Why we store it |
|---|---|
| Email address | To create and authenticate your account |
| Name (display name) | To show who wrote an entry when a pregnancy is shared |
| Apple or Google account identifier | Only if you choose "Sign in with Apple" or "Sign in with Google" |
| Role (expectant mother / partner) | To show the correct screens for your role |
| Last menstrual period date and estimated due date | To calculate your pregnancy week and the content shown to you |
| Weight entries, and blood pressure values entered together with a weight entry, plus any note you attach | To show your weight history and share it with your family members |
| Kick counter sessions and timestamps | To show your kick history |
| Appointments (title, date, notes) | To show and remind you of appointments |
| Letters you write to your baby | To store them and, if the pregnancy is shared, show them to your family members |
| Family invite codes | To let a partner join your pregnancy |
The following is stored only in the App's local storage on your iPhone. It is not uploaded to our servers, and we cannot see it:
Because this information is held only on your device, it is removed when you delete the App, and it is included in your device backups if you have those enabled. It is not recoverable by us.
Koza can exchange data with Apple Health. This is turned off by default and only happens after you enable the Apple Health toggle in the App and grant permission in the iOS system dialog. While the toggle is off, the App neither writes to nor reads from Apple Health.
| Direction | Data |
|---|---|
| Koza writes to Apple Health | Weight, water intake, blood pressure, blood glucose |
| Koza reads from Apple Health | Step count, most recent weight |
Data read from Apple Health is used only to display information to you inside the App (for example, showing today's step count, or offering your latest weight as a suggested value). Data obtained from Apple Health is never transmitted to our servers, and never shared with any third party.
You can review and revoke Koza's Apple Health permissions at any time in the iOS Health app, under Sharing > Apps.
| Permission | What it is used for |
|---|---|
| Apple Health (read and write) | The exchange described in Section 3. Optional. |
| Calendar | To add your appointments to your own calendar. Calendar contents are not uploaded anywhere. Optional. |
| Camera | To take a pregnancy photo. Photos stay on your device. Optional. |
| Photo Library | To select or save pregnancy photos. Photos stay on your device. Optional. |
| Notifications | To show reminders. All notifications are scheduled locally on your device; we do not operate a push notification server and do not receive a device token. Optional. |
Every permission above is optional. The App remains usable if you decline any of them.
Koza lets you share a pregnancy with other people, such as your partner. This works through an invite code that you generate in the App and give to the other person.
Please read this carefully. When someone joins your pregnancy using your invite code, they become a member of that pregnancy. Members can read and write the shared information listed in Section 2.1 - including your weight entries, blood pressure values recorded with them, kick history, appointments, and letters.
Anyone who obtains your invite code can join. Share it only with people you intend to give this access to.
Access is enforced on our servers: only accounts listed as members of a pregnancy can read or write its data. Information stored only on your device (Section 2.2) is never shared with family members.
Koza includes an assistant screen where you can ask general questions about pregnancy.
Only the text you type into the assistant. Nothing else is transmitted.
Your records are never sent to the assistant, and the assistant cannot read them. We do not transmit your name, email address, account identifier, pregnancy or due dates, weight, blood pressure, blood glucose, symptoms, kick history, appointments, letters, journal entries, mood, water intake, step count, or photos. Your question travels on its own, with nothing attached that identifies you or your pregnancy.
Your message travels over an encrypted connection to two providers, in this order:
| Step | Provider | What it does |
|---|---|---|
| 1. Proxy | AIProxy (aiproxy.com) | Receives your message and forwards it to the AI provider. It exists so that our API credentials never have to be stored inside the App, where they could be extracted. |
| 2. AI provider | OpenAI, L.L.C. | Generates the reply, which is returned to your device through the same path. |
Both providers are located in the United States, so your message is processed there - see Section 12.
We ourselves do not store your messages or the replies, and we do not associate them with your account. We operate no server of our own in this path.
What AIProxy records. According to its published privacy policy, AIProxy logs the originating IP address of the request, the HTTP status code of the response, metadata about the request such as the number of input tokens, and - only when a request fails with an error - the body of the error response. Your IP address is therefore visible to AIProxy even though nothing in the message identifies you. AIProxy retains these logs for 30 days.
What OpenAI does with it. OpenAI processes content submitted through its API as a service provider acting on our behalf. Under its API terms, this content is not used to train its models, and it is retained for a limited period for abuse monitoring before being deleted.
Two cases where nothing leaves your device. First, if what you write matches a list of urgent pregnancy symptoms built into the App, the App answers immediately from that built-in list and no request is sent at all; it tells you to contact your doctor or emergency services without consulting any server. Second, if the connection or the AI provider fails, the App falls back to a fixed set of answers stored inside the App itself.
Koza contains no advertising software and no cross-app or cross-site tracking software. It does contain analytics and crash reporting, provided by Google LLC (Firebase Analytics and Firebase Crashlytics), used only to see which screens are used and to find crashes.
Separately, RevenueCat (Section 12) uses your purchase and subscription history to provide us with subscription statistics, for example how many people start, renew, or cancel a subscription. These records are tied to the anonymous identifier described in Section 12, not to your name or your account, and never include your health information or anything you type.
Your health information is never sent to these services. No event ever carries your name, email address, pregnancy or due dates, pregnancy week, weight, blood pressure, blood glucose, symptoms, kick history, appointments, letters, journal entries, mood, photos, or anything you type - including anything you type into the assistant.
What is measured:
paywall or onboarding_role.How you are identified in this data: not by your account identifier. Before any identifier is sent, it is replaced with a one-way SHA-256 hash, which cannot be reversed to recover the original. Your role (mother or partner) and whether subscriptions are enabled in your build are recorded as properties. Firebase additionally assigns its own app-instance identifier, which is reset if you delete and reinstall the App.
Koza relies on the following third-party services, and no others:
| Service | Provider | Purpose |
|---|---|---|
| Firebase Authentication | Google LLC | Account creation and sign-in |
| Cloud Firestore | Google LLC | Storing the data listed in Section 2.1 |
| Google Sign-In | Google LLC | Optional "Sign in with Google" |
| Sign in with Apple | Apple Inc. | Optional "Sign in with Apple" |
| Firebase Analytics | Google LLC | The usage measurement described in Section 7 |
| Firebase Crashlytics | Google LLC | Crash and error reporting (Section 7) |
| Assistant proxy | AIProxy (aiproxy.com) | Forwarding assistant messages to the AI provider, so that API credentials are never stored in the App (Section 6) |
| AI language model API | OpenAI, L.L.C. | Generating assistant replies (Section 6) |
| Subscription management | RevenueCat, Inc. | Checking and restoring your Koza Premium subscription, and keeping access in step with renewals, cancellations, and refunds reported by Apple (Section 12) |
These providers act as data processors on our behalf and process your data in accordance with their own terms and applicable data protection agreements. If you use "Sign in with Apple", you may choose to hide your email address; Koza works normally with a private relay address.
We do not use your information for advertising, profiling, or automated decision-making, and we do not use it to train machine learning models.
We retain the information in Section 2.1 for as long as your account exists.
Assistant messages. We keep no copy of them. Their retention is determined by the two providers in Section 6.2: OpenAI retains API content for a limited period for abuse monitoring before deleting it, and AIProxy retains the request logs described there for 30 days. Because we hold no copy and nothing in a message is linked to your account, we cannot retrieve or delete an individual message on request.
Analytics and crash reports. These are retained by Google LLC according to the retention setting of our Firebase project. Deleting your account does not delete them, because they are not linked to your account identifier - only to a one-way hash of it, as described in Section 7.
Subscription records. These are retained by RevenueCat, Inc. according to its own retention policy. Deleting your account does not delete them, because they are tied to an anonymous identifier generated on your device rather than to your account. Your subscription itself belongs to your Apple ID and is managed and cancelled through Apple.
You can delete your account from within the App, under Profile > Delete My Account. This is a permanent deletion, not a sign-out. It removes:
Deleted data cannot be recovered. Backup copies held by our infrastructure provider are overwritten in the ordinary course of their retention cycle.
Information listed in Section 2.2 is removed when you delete the App from your device.
Data that Koza has written to Apple Health remains in Apple Health after you delete the App. You control it in the iOS Health app.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Our infrastructure provider, Google LLC, operates data centres in multiple countries. Information described in Section 2.1 may therefore be stored or processed outside your country of residence, including in countries whose data protection laws differ from those of your own. Where required, such transfers rely on the safeguards offered by the provider, including Standard Contractual Clauses.
Separately, messages you send to the in-App assistant are processed in the United States by AIProxy (aiproxy.com), which forwards them, and by OpenAI, L.L.C., which generates the reply, as described in Section 6. Only the text you type is transferred; no data from your account or your records accompanies it. The connection itself carries your IP address, which AIProxy logs.
Analytics and crash reports described in Section 7 are processed by Google LLC and may also be processed outside your country of residence.
Koza Premium subscriptions are managed by RevenueCat, Inc., which processes the related data in the United States. RevenueCat receives an anonymous identifier generated on your device, your purchase and subscription history for Koza, and technical details sent with each request: your IP address, the identifier Apple assigns to apps from the same developer (identifierForVendor, which is not the advertising identifier), your device model, iOS version, app version, language preferences, and App Store country. It does not receive your name, email address, Koza account ID, payment details, or any pregnancy or health data. Where required, this transfer relies on the safeguards offered by the provider, including Standard Contractual Clauses.
Depending on where you live, you may have some or all of the following rights regarding your personal data: the right to access it, to correct it, to have it erased, to restrict or object to its processing, to receive a copy in a portable format, and to withdraw consent you have given.
You can exercise the most important of these directly in the App: you can view and edit your entries at any time, and you can permanently erase your account and all associated cloud data as described in Section 10.
For any other request, contact us at ismailturanli91@gmail.com. We will respond within 30 days.
Where the GDPR applies, our legal bases are: performance of a contract with you, for the account and tracking features you ask us to provide; your explicit consent, for health data and for optional device permissions such as Apple Health, Calendar, Camera, and Photos; and our legitimate interests in keeping the service secure and operational. You may withdraw consent at any time by disabling the relevant feature or deleting your account. You also have the right to lodge a complaint with your local supervisory authority.
Where Law No. 6698 on the Protection of Personal Data applies, health data is treated as special category personal data and is processed on the basis of your explicit consent. You hold the rights set out in Article 11 of the Law, including the right to learn whether your data is processed, to request its correction or erasure, and to object to results arising from automated analysis. Requests may be sent to the contact address above.
We do not sell or share personal information as those terms are defined under California law, and we have not done so in the preceding twelve months. California residents may exercise their rights of access and deletion through the contact address above, and will not be discriminated against for doing so.
Koza is intended for adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 16 (or under 13 where that is the applicable threshold). The App does not currently verify age at sign-up. If you believe a child has provided us with personal information, contact us at the address above and we will delete the account and its data.
Koza is an informational and record-keeping tool. It is not a medical device, and it does not provide medical advice, diagnosis, or treatment. The pregnancy weeks, articles, and assistant answers it presents are general information and are not tailored to your circumstances. Assistant answers are generated by artificial intelligence, are not reviewed by a healthcare professional, and must not be relied upon for any decision about your health or your pregnancy. Always seek the advice of your physician or midwife with any questions about your pregnancy or your health, and never disregard or delay professional medical advice because of something you read in the App. If you believe you have a medical emergency, contact your local emergency service immediately.
We may update this Privacy Policy to reflect changes in the App, in our providers, or in applicable law. When we do, we will revise the "Last Updated" date above. For material changes, including any change to what data leaves your device, we will make the updated policy available before the affected version of the App is released, and notify you in the App or by email where appropriate.
Data Controller: TuranliApp
Email: ismailturanli91@gmail.com
Application: Koza (iOS)