This Privacy Policy explains how RiskDetected collects, uses, stores, discloses and deletes personal information in the RiskDetected mobile application and connected services.
Controller/service provider:
- Riskdetected
- Tax/identity number: 21832867210
- Address: Eskişehir, Türkiye
- Privacy contact: RiskDetected Privacy Team
- Email: [email protected]
- Website: https://riskdetected.com
This Policy is intended to be read together with the Terms of Use and the AI and Data Processing Notice. It does not reduce any privacy right that applies to you under mandatory law.
1. What RiskDetected does
RiskDetected provides AI-assisted workplace-safety analysis from photographs, organises findings and risk scores, generates PDF/XLSX reports, stores company and report records, manages subscriptions and notifications and provides professional-progress features.
AI output is decision support. It is not an official inspection, legal or regulatory determination, professional certification or replacement for a competent person.
2. Personal information we may process
Depending on how you use the Service, we may process:
- Account and profile information: user ID, email address, sign-in method, profile name, avatar and account status.
- Onboarding and professional context: role, qualification category, sector, workplace risk context, analysis frequency, intended use, app language, content locale and explicitly selected safety profile or work jurisdiction.
- User content: workplace photographs, annotations, earlier-version text inputs, notes, company details, logos and report-preparer information.
- Analysis information: AI findings, risk levels, scores, root causes, suggested actions, short references, summaries, selected analysis method, user edits and analysis status.
- Report and archive information: PDF/XLSX files, report type, title, company snapshot, file metadata and technical download or sharing records.
- Company information: company name, logo, address, contact person, department, responsible person, due date, risk class and archive status.
- Professional-progress information: in-app points, titles, badges, competency areas, active days, weekly tracking, finding categories and achievement messages.
- Subscription and entitlement information: Free, Plus or Pro status, quota usage, trial and renewal status, Apple product identifiers, RevenueCat entitlement and transaction events. RiskDetected does not receive or store full payment-card details.
- Notification information: permission and preference state, Apple Push Notification service device token, delivery events and errors.
- Support information: subject, message, optional attachments, preferred response language and support identifiers.
- Technical and security information: IP address where available to server infrastructure, device and operating-system information, app version/build, request and support identifiers, error codes, performance, model/provider route, token counts, fallback events and security signals.
- Legal and consent records: document set, version, checksum, acceptance, withdrawal, deletion and request timestamps.
RiskDetected does not intentionally perform facial recognition, biometric identity matching or identification of people shown in photographs.
3. Sensitive workplace content
Workplace photographs can reveal faces, injuries, health conditions, disability, personal protective equipment, religious, political or union indicators, children, vehicle plates, company signs, private premises, trade secrets or other sensitive information.
RiskDetected does not ask you to include unnecessary sensitive information. Submit only content you are lawfully authorised to process. Use cropping, annotation and camera positioning to minimise personal or confidential information where practical.
Image preparation is designed to reduce EXIF, location and camera metadata before analysis. Information that remains visibly present in the image can still be processed.
4. Sources of information
We collect information:
- directly from you when you create an account, complete onboarding, submit content, edit a finding, create a report, manage a company, contact support or choose preferences;
- automatically from the app and backend when the Service processes a request or records security, performance, entitlement and delivery events; and
- from Apple, RevenueCat, Apple or Google sign-in services and other providers you choose to use.
5. Why we process information
We process information to:
- create and secure accounts and sessions;
- provide requested photograph analysis, findings, controls and reports;
- store and manage analyses, companies, reports and user edits;
- enforce Free, Plus and Pro entitlements, quotas and trials;
- provide in-app progress features, notifications and service messages;
- answer support, access, export, correction, consent-withdrawal and deletion requests;
- prevent abuse, investigate security events, diagnose errors and maintain service continuity;
- measure technical performance and provider cost without using submitted workplace content for unrelated advertising;
- comply with legal obligations and establish, exercise or defend legal claims; and
- send marketing only where a separate valid permission or other lawful basis exists.
6. Legal bases
Where applicable law requires a legal basis, processing may rely on:
- Contract: to create an account and provide requested analyses, reports, subscriptions, storage and support.
- Consent: for AI processing of submitted content where required, for sensitive information where consent is the applicable basis, for certain international transfers and for optional marketing.
- Legal obligation: for tax, accounting, regulatory, security and lawful authority requests.
- Legitimate interests: for proportionate security, fraud and abuse prevention, fault diagnosis, service reliability, cost control and legal claims, where those interests are not overridden by your rights.
Where we rely on consent, you can withdraw it for future processing. Where we rely on legitimate interests, you may have a right to object. The available rights depend on your location and the specific processing.
7. AI processing
When you request an analysis, necessary photographs and structured context are sent through RiskDetected’s Supabase backend to configured AI providers. The provider route may use Google Gemini/Google AI and, when needed for continuity or fallback, Groq or another approved compatible provider.
We aim to send only the information needed to produce the requested result. Technical AI logs may record provider/model, route alias, token count, latency, request/support identifiers, quality validation and failure/fallback events. These logs are not intended to contain credentials or full payment information.
AI output does not make a solely automated decision that has legal or similarly significant effects on a person. A competent person must review the actual workplace and output before a safety decision is made.
8. Service providers and recipients
Information may be disclosed, to the extent necessary, to:
- Supabase: authentication, database, storage, Edge Functions and backend infrastructure.
- Google Gemini/Google AI and Groq: requested AI analysis and configured fallback.
- Apple App Store and RevenueCat: purchase, subscription, trial, entitlement and transaction verification.
- Apple Push Notification service: push-notification delivery.
- Sign in with Apple and Google Sign-In: authentication when selected.
- Resend: transactional and support email delivery.
- Vercel: hosting of RiskDetected’s public website and legal pages.
- professional security, legal, accounting or support advisers where needed; and
- courts, regulators, law-enforcement or other authorities where disclosure is lawfully required.
If you export or share a report, information is also disclosed to the person or service you select.
Service providers are authorised to process information for contracted service purposes, not to use submitted workplace content for unrelated advertising.
9. International processing and transfers
RiskDetected is based in Türkiye. Providers and their subprocessors may process information in Türkiye, the United States, the European Economic Area and other countries in which they operate. Privacy laws in those countries may differ from the laws where you live.
Where required, RiskDetected relies on an applicable adequacy decision, contractual safeguards, provider data-processing terms, statutory exception or explicit consent. You can request information about the safeguards relevant to your processing by contacting [email protected].
Provider locations and subprocessors can change as their infrastructure changes. RiskDetected reviews provider terms and will update this Policy when a material change affects the disclosures.
10. Retention
Current product retention rules are:
- Free analysis photographs: 7 days.
- Plus analysis photographs: 30 days.
- Pro analysis photographs: while the account remains active or until the user deletes them, subject to technical deletion and lawful retention.
- Raw AI responses and AI audit records: 30 days.
- Analysis results, findings, reports and professional-progress records: until the user deletes them, the account is deleted or the purpose ends.
- Profile avatars, company logos and company records: until deleted or archived by the user, the account is deleted or the purpose ends.
- Notification tokens and preferences: until disabled, invalidated, signed out or the account is deleted.
- Subscription, consent, document acceptance, support, account-deletion, security and dispute records: for the applicable legal, accounting, security, limitation and evidence periods.
When a period ends or a valid deletion request applies, information is deleted, de-identified or anonymised. Limited backups, security records and legal holds may remain for a reasonable period where necessary.
11. Account and content deletion
You can delete supported analyses, reports, company records, avatars and logos in the app.
You can start and complete account deletion through Profile > Delete Account. An email, support request or website request is not required. Account deletion removes the account and associated app data, subject to lawful retention, security, dispute and reasonable backup requirements.
Deleting a RiskDetected account does not automatically cancel an Apple subscription. Manage the subscription through Apple Account settings.
12. Sharing, sale, advertising and tracking
RiskDetected does not sell personal information to data brokers. It does not use submitted workplace content for public advertising without separate permission.
The mobile app does not currently use IDFA-based cross-company tracking or track users across other companies’ apps and websites for targeted advertising. If this changes, RiskDetected will update this Policy and request Apple App Tracking Transparency permission where required.
13. Notifications and email
Service emails may cover authentication, account security, support and requested service activity. Push notifications may cover analysis/report completion, account status, trials and progress events.
You can control push notifications in the app and iOS Settings. Optional marketing consent is separate and can be withdrawn.
14. Security
RiskDetected uses technical and organisational measures designed to protect information, including access controls, row-level security, private storage, file type and size restrictions, authenticated backend functions, log redaction, data minimisation, retention cleanup and deletion mechanisms.
No internet or cloud system can guarantee absolute security. Contact [email protected] if you believe information has been compromised.
15. Your choices and rights
Depending on applicable law, you may have rights to:
- know whether and how personal information is processed;
- access or receive a copy;
- correct inaccurate information;
- request deletion;
- restrict or object to processing;
- request portability;
- withdraw consent for future processing;
- challenge certain automated processing; and
- complain to a privacy or data-protection authority.
We may need to verify your identity and may retain or refuse certain information where an applicable exception requires or permits it. You will not be discriminated against for exercising a privacy right.
Submit a privacy request through Profile > Support or [email protected]. Account deletion remains available directly through Profile > Delete Account.
United Kingdom
Where UK data-protection law applies, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. You may complain to the UK Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/.
United States and California
Where a state privacy law applies, you may request the disclosures, access, correction, deletion, portability and opt-out rights provided by that law. RiskDetected does not currently sell personal information or share it for cross-context behavioural advertising. If California’s CCPA/CPRA applies to RiskDetected and your information, you may exercise the applicable rights through the contact methods above.
Australia
Where the Australian Privacy Act applies, you may request access or correction and submit a privacy complaint to RiskDetected first. We will investigate and respond within a reasonable period. If unresolved, you may contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints.
Canada
RiskDetected’s designated privacy contact is the RiskDetected Privacy Team at [email protected]. Where Canadian privacy law applies, you may request access or correction and challenge RiskDetected’s compliance. You may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy authority.
16. Children
RiskDetected is designed for workplace and professional use and is not directed to children. Do not submit children’s information unless you have completed all legally required notices, permissions and safeguards.
17. Website technologies
The mobile app does not require browser cookies for core use. The public website, legal pages and service-provider links may use cookies, local storage or similar technologies for security and operation. Website practices are described through the website’s cookie information where applicable.
18. Changes to this Policy
RiskDetected may update this Policy for product, provider, security, legal or App Store changes. Material changes will be communicated where required and may require renewed acknowledgement or consent. Acceptance records identify the document set, version and checksum shown to the user.
19. Contact and complaints
- Privacy contact: RiskDetected Privacy Team
- Email: [email protected]
- Address: Eskişehir, Türkiye
- Website: https://riskdetected.com
- In-app support: Profile > Support
Please describe the request and the country whose privacy law you believe applies. RiskDetected may request information needed to verify identity and respond securely.
iOS advertising and conversion measurement — 8 September 2026
RiskDetected for iOS uses Meta App Events to measure app advertising and in-app conversions. Launch, registration, completed analysis, report creation, trial and subscription events may be shared with Meta together with app/device metadata, an SDK installation identifier, product, currency and verified transaction amount. This integration does not send site photographs, analysis/report content, your name or email address. This version does not collect IDFA or request cross-app tracking permission. SDK event use is limited to analytics and conversion measurement. Apple’s privacy-preserving SKAdNetwork mechanism supports install measurement; individual cross-app advertising matching is not the intended use.